Computer network experiment environment dynamic construction method based on virtual simulation

Through demand-driven instructional orchestration and virtual resource pooling scheduling technology, the virtual computer network experimental environment is automatically built, which solves the problems of high costs and low resource utilization in the existing technology, and realizes flexible and efficient experimental environment management.

CN120277743AInactive Publication Date: 2025-07-08Chaoyang Normal University
View PDF 0 Cites 3 Cited by

Patent Information

Application Number
CN202510768208.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-10
Publication Date
2025-07-08
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The existing computer network experimental environment has high cost to build and manage, and the hardware equipment is quickly updated, making it difficult to meet the diverse and flexible personalized experimental needs, and the resource utilization rate is low.

Method used

Using demand-driven instructional orchestration, virtual resource pooling scheduling and multi-layer automated configuration technology, a virtual computer network experimental environment is dynamically built, including the automated generation and management of virtual hosts, network topology and configuration instructions.

Benefits of technology

It significantly improves the resource utilization rate and scenario construction efficiency of online experimental teaching, reduces operation and maintenance costs, and supports the rapid construction of diversified experimental environments and personalized teaching.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120277743A_ABST
    Figure CN120277743A_ABST
Patent Text Reader

Abstract

The invention discloses a computer network experiment environment dynamic construction method based on virtual simulation, which belongs to the field of computer network experiment teaching and virtual simulation technology application, and comprises the following steps: analyzing experiment scene description to generate a modular construction instruction; creating and initializing a virtual machine instance and a basic network; generating a required virtual network device and constructing a corresponding virtual connection; configuration parameters, service scripts and security policies are comprehensively applied to the virtual machine and the network equipment; and integrally outputting the experimental environment to a user interaction interface. According to the method, the demand-driven instruction arrangement, virtual resource pooling scheduling and multi-layer automatic configuration technologies are adopted, so that a diversified and deeply interactive virtual computer network experiment environment can be quickly and flexibly constructed according to specific experiment demands of a user; and the resource utilization rate, the scene construction efficiency and the flexibility of the teaching mode of network experiment teaching are obviously improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer network experimental teaching and virtual simulation technology applications, and particularly to a method for dynamically constructing a computer network experimental environment based on virtual simulation. Background Art

[0002] Computer network is a core component of information technology, and related courses play an important role in higher education and vocational and technical training. As a key link in cultivating students' practical ability and innovative thinking, network experimental teaching aims to enable students to master core skills such as network device configuration, network interconnection, network service deployment, and security protection by operating in a simulated real network environment, which is of great significance for improving their professional ability and the quality of solving practical problems.

[0003] However, in the provision and management of computer network experimental environments, existing methods often face some common problems. For example, the cost of building and maintaining a large-scale physical experimental platform is relatively high, and the performance iteration and technology update speed of hardware devices are fast, resulting in existing facilities being prone to obsolescence. At the same time, there are still certain limitations in the current commonly used experimental conditions and management models in ensuring that each learner has sufficient and flexible personalized experimental opportunities and quickly responding to the construction requirements of diverse and repeatable experimental scenarios. Summary of the Invention

[0004] To solve the above problems, the present invention provides a method for dynamically constructing a computer network experimental environment based on virtual simulation, which adopts demand-driven instruction-based orchestration, virtual resource pooling and scheduling, and multi-layer automated configuration technologies, and can quickly and flexibly construct a diverse and deeply interactive virtual computer network experimental environment according to the specific experimental needs of users, significantly improving the resource utilization rate, scenario construction efficiency, and flexibility of the teaching mode of network experimental teaching.

[0005] The above object can be achieved through the following solutions: A method for dynamically constructing a computer network experimental environment based on virtual simulation, including receiving an experimental scenario description input by a user, parsing the experimental scenario description to generate a dynamic construction instruction sequence, where the dynamic construction instruction sequence includes virtual host instructions, network topology instructions, and configuration instructions; creating virtual machine instances according to the virtual host instructions, and loading a system image and configuring network connections for the virtual machine instances; generating virtual network devices according to the network topology instructions, and constructing virtual connections between the virtual network devices, between the virtual machine instances and the virtual network devices; loading and running network configuration parameters, service configuration scripts, and security policies for the virtual machine instances and the virtual network devices according to the configuration instructions and the virtual connections to obtain configured virtual machine instances and configured virtual network devices; connecting the configured virtual machine instances and the configured virtual network devices as a whole and outputting them to a user interaction interface.

[0006] Optionally, generating the dynamic construction instruction sequence includes: receiving an initial experimental request, and constructing a digital experimental blueprint based on the initial experimental request; performing a verification process on the digital experimental blueprint, and if the verification process is passed, converting the digital experimental blueprint into a dynamic construction instruction sequence.

[0007] Optionally, constructing the digital experimental blueprint based on the initial experimental request further includes: forming an experimental design template according to the version identifier and experimental scenario classification label of the initial experimental request, in combination with the digital experimental blueprint, and archiving the experimental design template to a preset shared template repository; responding to a template query condition submitted by a user, matching a corresponding experimental design template from the shared template repository, and copying and generating a copy of a new digital experimental blueprint for a derived design solution.

[0008] Optionally, loading the system image and configuring the network connection for the virtual machine instance includes: allocating computing processing power and storage capacity for the virtual machine instance according to the virtual host instructions, and instantiating the virtual machine instance; selecting a preset operating system image based on the instantiated virtual machine instance, loading it into the virtual machine instance, and establishing an operating system running environment; configuring a network connection mode and a link layer address for the virtual machine instance based on the operating system running environment.

[0009] Optionally, constructing the virtual connections between the virtual network devices, between the virtual machine instances and the virtual network devices includes: selecting and instantiating virtual network devices from a preset virtual device model library according to the network topology instructions, and configuring virtual network interfaces for the virtual network devices; creating and configuring multiple virtual links using the configured virtual network interfaces and the network interfaces of the virtual machine instances to form virtual connections.

[0010] Optionally, the security policy includes: matching and extracting basic security control components from a preset security rule policy library based on the configuration instructions; applying the basic security control components to the virtual machine instance and the virtual network device, generating a collaborative routing adjustment instruction, and using the collaborative routing adjustment instruction to correct the network configuration parameters.

[0011] Optionally, obtaining the configured virtual machine instance and the configured virtual network device includes: configuring corresponding network layer addresses and link layer addresses for the virtual machine instance and the virtual network device based on the configuration-related instructions to form an addressed network interface; performing a partitioning process on the virtual network device based on the configuration-related instructions and the addressed network interface to obtain a logical network area; using the logical network area and the addressed network interface to construct a data packet forwarding path to obtain the configured virtual machine instance and the configured virtual network device.

[0012] Optionally, outputting to the user interface includes: generating a visual unified operation view using the configured virtual machine instance and the configured virtual network device; analyzing the network traffic of the virtual connection based on the visual unified operation view and recording the experimental process log.

[0013] Optionally, the method further includes: performing an association analysis based on the experimental process log to generate experimental process performance indicators; generating personalized experimental guidance feedback according to the experimental process performance indicators.

[0014] Optionally, the method further includes: generating experimental design iteration parameters by integrating the experimental process log and the experimental process performance indicators; updating the corresponding experimental design template in the shared template repository based on the experimental design iteration parameters.

[0015] Compared with the prior art, the present invention has the following advantages: 1. It improves the automation degree and deployment flexibility of building a network experiment environment. The present invention analyzes user requirements to generate instructions, realizing the automatic dynamic construction of virtual machines, networks, and configurations. This method significantly shortens the time for building complex scenarios, supports the rapid generation and adjustment of diverse network experiment environments on demand, and efficiently meets personalized teaching and research needs.

[0016] 2. It significantly reduces the construction and operation and maintenance costs of the experiment platform and optimizes resource utilization. This method uses virtualization technology to generate an experiment environment on demand and dynamically schedules a shared resource pool, greatly reducing the dependence on and maintenance of dedicated physical devices. This significantly saves the platform cost and improves the overall utilization efficiency of hardware facilities through efficient resource reuse and on-demand allocation.

[0017] 3. Expand the customization depth of the experimental scenario and the intelligent level of teaching support. This method supports the rapid construction of customized scenarios containing specific network services or security elements through blueprint templates. Optional intelligent analysis, personalized feedback, and environment adaptability capabilities can effectively enrich the experimental content and improve the learning interaction experience and skill mastery efficiency.

[0018] Other features and advantages of the present invention will be described in the following specification, and partly will become apparent from the specification, or will be understood by implementing the present invention. The objectives and other advantages of the present invention can be achieved and obtained by the structures pointed out in the specification, claims, and drawings. Brief Description of the Drawings

[0019] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or in the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0020] Figure 1 It is a flowchart of a method for dynamically constructing a computer network experimental environment based on virtual simulation according to an embodiment of the present invention.

[0021] Figure 2 It is a heat map of instruction composition weights according to an embodiment of the present invention.

[0022] Figure 3 It is a bar chart of template matching scores according to an embodiment of the present invention.

[0023] Figure 4 It is a radar chart of experimental process performance indicators according to an embodiment of the present invention. Detailed Embodiments

[0024] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.

[0025] Refer to Figure 1, an embodiment of the present invention proposes a method for dynamically constructing a computer network experimental environment based on virtual simulation. By adopting requirement-driven instruction-based orchestration, virtual resource pooling and scheduling, and multi-layer automated configuration technologies, it can quickly and flexibly construct a diverse and deeply interactive virtual computer network experimental environment according to the specific experimental requirements of users, significantly improving the resource utilization rate, scenario construction efficiency, and flexibility of teaching models in network experimental teaching.

[0026] The system of this embodiment specifically includes: Receiving an experimental scenario description input by a user, parsing the experimental scenario description to generate a dynamic construction instruction sequence, where the dynamic construction instruction sequence includes virtual host instructions, network topology instructions, and configuration instructions; According to the virtual host instructions, creating virtual machine instances and loading system images and configuring network connections for the virtual machine instances; According to the network topology instructions, generating virtual network devices and constructing virtual connections between the virtual network devices, between the virtual machine instances and the virtual network devices; According to the configuration instructions and the virtual connections, loading and running network configuration parameters, service configuration scripts, and security policies for the virtual machine instances and the virtual network devices to obtain configured virtual machine instances and configured virtual network devices; Taking the configured virtual machine instances and the configured virtual network device connections as a whole and outputting them to a user interaction interface.

[0027] Through requirement-driven instruction-based orchestration, virtual resource pooling and scheduling, and multi-layer automated configuration technologies, it can quickly and flexibly construct a diverse and deeply interactive virtual computer network experimental environment according to the specific experimental requirements of users, significantly improving the resource utilization rate, scenario construction efficiency, and flexibility of teaching models in network experimental teaching.

[0028] Optionally, the generating of the dynamic construction instruction sequence includes: Receiving an initial experimental request and constructing a digital experimental blueprint based on the initial experimental request; Specifically, in the stage of receiving an initial experiment request and constructing a digital experiment blueprint, the user submits their experiment requirements through a user interaction interface in the form of, for example, a graphical user interface or a command line. These requirements are captured as an initial experiment request, which contains information such as the number of virtual machines required, the number of central processing unit cores, memory size, storage space, the type of operating system expected to be loaded, and a summary of the virtual network topology structure expected to be constructed, such as which types of virtual network devices, such as virtual routers or virtual switches, are included, and approximate initialization configurations, such as specific network service startup requirements. An experiment blueprint construction module is responsible for parsing this initial experiment request, extracting and structuring the various requirement information therein to form a digital experiment blueprint in a standard format. This digital experiment blueprint precisely describes all the constituent elements and their target states of the virtual experiment environment to be constructed in a machine-readable manner.

[0029] Perform a verification process on the digital experiment blueprint. If the verification process is passed, convert the digital experiment blueprint into a dynamic construction instruction sequence.

[0030] Specifically, perform a verification process on the formed digital experiment blueprint and convert it. This verification process aims to ensure the technical feasibility, resource satisfiability, and compliance with preset teaching or safety specifications of the digital experiment blueprint. For example, a quantitative verification evaluation model can be adopted to calculate a comprehensive effectiveness score of a digital experiment blueprint. This score can be obtained by weighted averaging multiple independent verification items: , wherein, represents the total number of verification items; is the preset weight factor corresponding to the i-th verification item; is the compliance function of the digital experiment blueprint with respect to the i-th verification item, and its output value is, for example, between 0 and 1, where 1 represents full compliance and 0 represents full non-compliance. The calculated comprehensive effectiveness score will be compared with a preset passing threshold. Only when the comprehensive effectiveness score is greater than or equal to the passing threshold is the digital experiment blueprint considered to have passed the verification process. The digital experiment blueprint that has passed the verification is then mapped and decomposed by an instruction generation module according to predefined conversion logic into a series of specific, ordered, and directly executable dynamic construction instructions by the underlying virtualization and simulation platform, forming a dynamic construction instruction sequence for the subsequent automated construction process, as Figure 2 shown.

[0031] Exemplarily, a user wants to build a simple client-server test environment containing two Linux virtual machines and one Windows virtual machine, which are connected to the same IP subnet through a virtual switch. The user submits this initial experiment request through the user interface. The method first constructs a digital experiment blueprint based on the request information, which records in detail the CPU, memory, disk specifications, specified Linux and Windows operating system image information, the type of virtual switch, and the connection relationship between them and the preliminary planning of IP addresses of the three virtual machines. Next, the verification processing module evaluates this blueprint, such as checking whether the current resource pool can meet the resource requirements of the three virtual machines, and calculates its comprehensive effectiveness score. If this comprehensive effectiveness score reaches the preset pass threshold, the digital experiment blueprint is converted into a series of dynamic construction instructions, as well as subsequent instructions for configuring IP addresses and services.

[0032] Optionally, constructing a digital experiment blueprint according to the initial experiment request further includes: According to the version identifier and the experimental scenario classification label of the initial experimental request, combined with the digital experimental blueprint, an experimental design template is formed, and the experimental design template is archived to a preset shared template repository; Specifically, in the stage of converting the digital experiment blueprint into a reusable template, the method first uses the administrative metadata provided in the initial experiment request or supplemented by the user when saving the blueprint. These metadata mainly include version identifiers and a set of experimental scenario classification tags. The version identifier, such as "v1.0", "Teaching Edition-2025", is used to distinguish different revision states or specific purpose versions of the experimental blueprint, which is convenient for tracking and backtracking. The experimental scenario classification tags, such as "Basics of Routing Protocols", "Network Service Construction", "Introduction to Information Security Attack and Defense", etc., are used to annotate the experimental blueprint from multiple dimensions such as functions, technical points or applicable courses, so as to facilitate subsequent classification management and precise retrieval. These version identifiers and experimental scenario classification tags are combined with the technical specifications contained in the digital experiment blueprint itself, and after a preset packaging process, a structured experimental design template is formed. The formed experimental design template is assigned a globally unique identifier and stored in a centralized shared template repository. The shared template repository supports indexing and permission management of templates, such as Figure 3 shown.

[0033] In response to the template query condition submitted by the user, the corresponding experimental design template is matched from the shared template repository, and a copy of a new digital experimental blueprint is generated to derive a design plan.

[0034] Specifically, when a user needs to reuse an existing experimental design template to construct a new digital experimental blueprint or perform derivative design, the user submits a set of template query conditions through the user interface. The template query conditions can be a set of free text keywords, a selection for a preset classification tag system, or a combination of both. After receiving the template query conditions, a template retrieval and matching module performs a retrieval operation on the shared template repository. To improve the accuracy and relevance of the retrieval, a similarity matching algorithm based on the vector space model can be used. For example, the user's template query conditions and the metadata of each experimental design template in the template repository can be respectively converted into high-dimensional feature vectors. The matching degree or similarity between vectors can be obtained by calculating their cosine similarity: , wherein, represents the query vector and the template vector 's dot product; and respectively represent the L2 norms of the query vector and the template vector. The calculated similarity value ranges between 0 and 1, and the higher the value, the higher the matching degree. The method will return a list of experimental design templates whose similarity values exceed the preset retrieval threshold for the user to select. After the user selects an experimental design template from the list, the method will copy the core technical content of the selected template and quickly generate an initial copy of a new, editable digital experimental blueprint. This copy can then be directly used by the user to generate a dynamic construction instruction sequence, or modified and extended on this basis to form a derivative design solution that meets specific new requirements.

[0035] Exemplarily, a network course teacher completed the construction of a digital experimental blueprint for a complex BGP protocol routing experimental scenario that includes three virtual machines, two virtual routers, and one virtual switch. When saving it as an experimental design template, a version identifier "BGP interconnection - v1.1" and experimental scenario classification tags "Advanced Routing", "BGP", "Backbone Network Simulation" were added to it. Another teacher hopes to conduct a similar experiment. He can submit template query conditions through the user interface, such as the keyword "BGP" and the classification tag "Advanced Routing". The template retrieval and matching module calculates the similarity using the formula and finds the above "BGP interconnection - v1.1" template. After the teacher selects this template, the system generates a new copy of the digital experimental blueprint for him. Based on this copy, for example, the autonomous system numbers of some routers can be adjusted or a client virtual machine for testing can be added, so as to quickly derive a new experimental design solution that meets his specific teaching purpose.

[0036] Optionally, loading the system image and configuring the network connection for the virtual machine instance includes: Allocate computing processing power and storage capacity to the virtual machine instance according to the virtual host instruction, and instantiate the virtual machine instance; Specifically, in the stage of allocating resources to the virtual machine instance according to the virtual host instruction and instantiating it, the method first parses the specification requirements for each virtual machine instance specified in the virtual host instruction. These specification requirements usually include the number of central processing unit cores required, the minimum and maximum memory allocation ranges, as well as the capacity size of the virtual disk and the desired I / O performance level. A resource scheduling module queries the available status of various resources in the virtualized resource pool according to these specification requirements, and executes a resource allocation algorithm to reserve or allocate specific computing processing units, memory segments and storage spaces for the virtual machine instance. After the allocation is completed, by calling the management interface of the underlying virtualization platform, a container or hardware abstraction layer of the virtual machine instance is created and initialized according to the allocated resources and virtual machine definition metadata. At this time, the virtual machine instance is in the state of being instantiated but not yet installed with an operating system.

[0037] Based on the instantiated virtual machine instance, select a preset operating system image, load it into the virtual machine instance, and establish an operating system running environment; Specifically, in the stage of selecting and loading the operating system image based on the instantiated virtual machine instance to establish the operating system running environment, the method selects the most suitable operating system image from an image repository containing multiple operating system images or pre-configured templates according to the operating system type, version or specific experimental scenario requirements specified in the virtual host instruction. To achieve intelligent selection, a set of attributes describing its characteristics can be assigned to each operating system image or template At the same time, the actual requirements for the operating system environment contained in the virtual host instruction can be extracted as a set of requirement attributes Then the matching degree score between the operating system image and the requirements can be calculated through a weighted matching function. For example: , In the formula, is the number of key attributes of the operating system template; is the matching weight of the kth attribute, reflecting the importance of this attribute for meeting the overall requirements; is a function used to evaluate the kth attribute of the template and the requirement set The degree of compliance with relevant requirements, and its return value is, for example, between 0 and 1. The method will select the operating system image with the highest matching score and meeting the lowest acceptance threshold. After the operating system image is selected, the automated deployment module is responsible for loading the content of the operating system image into the allocated storage capacity of the virtual machine instance, and performing necessary installation boot and first startup configuration, and finally establishing a fully functional operating system running environment.

[0038] Based on the operating system running environment, configure the network connection mode and link layer address for the virtual machine instance.

[0039] Specifically, in the stage of configuring the network connection mode and link layer address for the virtual machine instance based on the established operating system running environment, the method first determines the type of virtual network or physical network that the virtual machine instance needs to access, and this information usually also comes from the overall planning of the network connection scheme in the virtual host instruction. Subsequently, configure the unique link layer address required for the virtual network interface of the virtual machine instance in the second-layer network communication, such as a MAC address generated automatically or allocated from an address pool. At the same time, according to the parsed network connection requirements, such as whether the virtual machine instance needs an independent IP to directly communicate with the external network, whether it only needs to communicate in the internal virtual network, or whether it needs to access the external network through network address translation, adaptively set a host network connection mode for its virtual network interface. The host network connection mode usually includes the bridge mode, which makes the virtual machine interface directly connected to the physical network; the network address translation mode, which makes the virtual machine access the external network through the IP sharing of the host; or the host-only mode, which makes the virtual machine only able to communicate with the host and other virtual machines in the same host-only network.

[0040] Exemplarily, if a virtual host instruction requires creating a virtual machine instance for Web server development and testing in a Linux environment and requires it to be directly accessible from the developer's physical host. After instantiating the virtual machine and allocating, for example, 2 cores of CPU, 4GB of memory, and 50GB of disk space, in the operating system loading stage, according to the requirement information such as "Linux" and "Web development", calculate the matching degree through a formula, and may select an optimized template of Ubuntu Server pre-installed with Apache, PHP, and MySQL environments from the operating system template library for automated deployment. After the deployment is completed, when configuring the network connection properties, to meet the requirement of direct access from the physical host, the virtual network interface of the virtual machine instance will be adaptively configured to the bridge mode, and a unique MAC address will be allocated to it, so that it can obtain an IP address and provide services like an independent host in the physical network.

[0041] Optionally, the establishment of virtual connections between the virtual network devices, and between the virtual machine instances and the virtual network devices includes: Select and instantiate virtual network devices from a preset virtual device model library according to the network topology instruction, and configure virtual network interfaces for the virtual network devices; Specifically, in the stage of selecting, instantiating virtual network devices and configuring their virtual network interfaces according to the network topology instruction, the method first parses a specific list of required virtual network devices from the network topology instruction. This list details the type of each virtual network device, such as whether it is a virtual router, virtual switch or virtual firewall; its specified simulation model, which, if applicable, may correspond to a specific product series of a real network device manufacturer, such as the Cisco Catalyst series switches or the ISR series routers, which helps to improve the authenticity of the simulation; and a set of virtual interface specifications required for each device, which defines the number, type and its initial state of the interfaces. Based on this information, a device management module queries and selects a matching device model from a preset virtual device model library containing various instantiable device images or models. After selection, the device management module starts the instantiation process of the selected model in the simulation environment to create a logical instance of the virtual network device. Immediately afterwards, for each instantiated virtual network device, the required multiple virtual network interfaces are automatically configured according to its corresponding virtual interface specifications, ensuring that these interfaces are ready for subsequent link establishment.

[0042] Create and configure multiple virtual links using the configured virtual network interfaces and the network interfaces of the virtual machine instances to form a virtual connection.

[0043] Specifically, in the stage of creating and configuring multiple virtual links using the configured virtual network interfaces and the network interfaces of virtual machine instances to form a virtual connection, the method first obtains the connection topology information between nodes clearly defined in the network topology instruction. This information usually exists in the form of a connection list or an adjacency matrix, indicating which network interface of which virtual machine instance needs to be connected to which virtual network interface of which virtual network device, as well as the interconnection relationship between the interfaces of different virtual network devices. In addition, the network topology instruction may also include a set of optional link characteristic parameters used to define specific attributes of the created virtual links, such as the desired link bandwidth, propagation delay, bit error rate, or a specific link encapsulation type. A link construction and configuration module automatically creates multiple virtual links in the simulation environment based on this connection topology information and link characteristic parameters. For each virtual link to be created, if the desired bandwidth is specified in its link characteristic parameters and the simulation environment allows for the simulation configuration of virtual link bandwidth, its actual configured bandwidth may need to be adjusted and set according to the resource status of the current simulation platform or a preset bandwidth allocation policy. For example, if there is a total available bandwidth pool and M links share it, it may be allocated proportionally or according to priority. A simplified allocation example is as follows: , wherein, is the simulated bandwidth finally configured for the j-th virtual link; is the requested bandwidth of this link; is the total resource available for simulating link bandwidth in the simulation environment; is the priority of this link or other allocation reference factor; represents the bandwidth allocation function or algorithm adopted. By creating these virtual links with specific configurations, independent virtual machine instances and virtual network devices are interconnected, and finally a complete virtual connection topology that meets the requirements of the experimental scenario is formed.

[0044] Exemplarily, if the network topology instruction requires creating a scenario that includes two virtual machines VM1 and VM2, a virtual router R1, and a virtual switch SW1, where VM1 and VM2 are respectively connected to ports 1 and 2 of SW1, one interface G0 / 0 of R1 is connected to port 3 of SW1, and another interface G0 / 1 of R1 is simulated to be connected to an external network. First, the method instantiates R1 and SW1 from the virtual device model library and configures virtual network interfaces such as G0 / 0, G0 / 1, ports 1, 2, 3, etc. for them. Subsequently, the link construction and configuration module creates three virtual links: the network card of VM1 is connected to port 1 of SW1; the network card of VM2 is connected to port 2 of SW1; the G0 / 0 interface of R1 is connected to port 3 of SW1. If the network topology instruction also stipulates that the expected bandwidth of the link between VM1 and SW1 is 100 Mbps, then when creating this link, the corresponding simulated bandwidth parameters may be configured for this virtual link according to the bandwidth allocation policy in the formula, in combination with the resources of the current simulation environment. Thus, the required virtual connection is formed.

[0045] Optionally, the security policy includes: Based on the configuration instruction, match and extract basic security control components from a preset security rule policy library; Specifically, when matching and extracting basic security control components from the security rule policy library based on the configuration instruction, the configuration instruction is first parsed to identify a specific target security scenario. Multiple modular basic security control components corresponding to different security scenarios are preset in the security rule policy library. A policy matching module selects a group of functionally most relevant basic security control components from the library according to the parsed target security scenario. These components can be a specific firewall rule set, the policy configuration of an intrusion detection system, or a configuration template for deploying a "honeypot" virtual machine.

[0046] Apply the basic security control components to the virtual machine instance and the virtual network device, generate a collaborative routing adjustment instruction, and use the collaborative routing adjustment instruction to correct the network configuration parameters.

[0047] Specifically, when applying the extracted set of basic security control components to virtual machine instances and virtual network devices and generating collaborative routing adjustment instructions to correct network configuration parameters, this process reflects the intelligent linkage between security configuration and network configuration. First, the deployment module applies the set of basic security control components to a specified virtual machine instance or virtual network device. For example, a virtual machine acting as a "honeypot" is instantiated in the network. Subsequently, a collaborative analysis engine evaluates the specific requirements generated by the deployment of the security component on the existing network data flow path. For example, the purpose of deploying a "honeypot" is to induce attack traffic, so the routing needs to be adjusted to make the path to the "honeypot" more attractive to specific traffic. The collaborative analysis engine generates a set of collaborative routing adjustment instructions for this purpose, and the instructions may include quantified adjustment values for the cost of specific routing paths. The adjustment value can be calculated by the following function: , wherein, represents the type of security scenario currently deployed, such as entrapment type or isolation type; represents the basic routing cost or metric value of the current path; represents the security attribute of the target node pointed to by this path. The adjustment function calculates a positive or negative cost adjustment value based on these inputs. For example, for an entrapment scenario, the function may calculate a negative adjustment value for the path pointing to the "honeypot" to reduce its routing cost. Finally, the method uses the generated set of collaborative routing adjustment instructions to automatically modify the set or to-be-set network configuration parameters. For example, the calculated routing cost adjustment value is applied to the routing table of the virtual router, thereby completing the correction of the data packet forwarding path.

[0048] Exemplarily, if the configuration instruction requires deploying a "honeypot" virtual machine for capturing internal network scanning behavior. The method first extracts and applies the deployment components of the "honeypot" virtual machine from the security rule policy library and creates the "honeypot" instance in the network. Subsequently, the collaborative analysis engine identifies that this is an entrapment security scenario with the "honeypot" virtual machine as the target. The engine then calculates a negative cost adjustment value for all routing paths pointing to the "honeypot" using the formula and generates a collaborative routing adjustment instruction. When this instruction is executed, it automatically modifies the routing table of the core virtual router in the network, reducing the metric value of the routing entry to the "honeypot" and making it a more preferred path, thereby more effectively guiding suspicious traffic to the "honeypot" and achieving the collaborative optimization of security policies and network routing configurations.

[0049] Optionally, the obtaining of the configured virtual machine instance and the configured virtual network device includes: Based on the configuration-related instructions, configure corresponding network layer addresses and link layer addresses for the virtual machine instance and the virtual network device to form an addressed network interface; Specifically, when configuring network layer addresses and link layer addresses for the virtual machine instance and the virtual network device to form an addressed network interface, the method first parses the addressing requirements for each network interface from the configuration instructions. The addressing requirements usually specify the desired network layer addresses, such as IPv4 addresses, subnet masks, default gateway addresses, or IPv6 addresses and prefix lengths. At the same time, for Ethernet-type interfaces, a globally unique or locally unique link layer hardware address, i.e., a MAC address, is assigned to them. These address information are accurately applied to the corresponding network interface configurations, enabling each network interface to have the basis for unique identification and communication addressing in the network, thus forming multiple addressed network interfaces.

[0050] Based on the configuration-related instructions and the addressed network interface, perform a partitioning process on the virtual network device to obtain logical network regions; Specifically, when performing a network partitioning process on the virtual network device based on the configuration instructions and the addressed network interface to obtain logical network regions, this step mainly targets virtual network devices with network segmentation capabilities, such as virtual switches or virtual routers. The configuration instructions will contain definitions on how to partition the logical network regions, such as specifying the VLAN IDs, names, and which addressed network interfaces should belong to which VLAN. A network configuration module creates corresponding VLANs on the virtual network device according to these definitions and configures the specified addressed network interfaces as member ports of the corresponding VLANs. Through this partitioning process, multiple mutually isolated or controllably interconnected logical network regions can be created on a physical or virtual network infrastructure, and each logical network region constitutes an independent broadcast domain.

[0051] Utilize the logical network regions and the addressed network interface to construct a packet forwarding path to obtain a configured virtual machine instance and a configured virtual network device.

[0052] Specifically, when constructing a data packet forwarding path on a virtual network device using a logical network area and an addressed network interface, this step mainly ensures that data packets can be correctly routed between different logical network areas and with possible external networks. The configuration instructions will include routing-related rules, such as the definition of static routing entries or the enabling instructions for dynamic routing protocols. A routing configuration module establishes the routing information required for data packet forwarding decisions on the virtual network device based on these rules. For example, to enable communication between different logical network areas, routing entries pointing to each area need to be configured. If the experimental scenario involves multiple possible forwarding paths, a path selection metric can be introduced to assist in constructing the optimal data packet forwarding path. For a candidate path from the source network to the target network, its path selection metric can be comprehensively calculated based on various factors such as the number of links, bandwidth, latency, or administrative cost on the path: , wherein, , , , respectively represent the bandwidth, latency, hop count contribution, and administrative cost of the l-th link in the path; , , are the weight factors for the corresponding indicators, reflecting the preference of path selection. The method will select or configure the data packet forwarding path with the minimum path selection metric. By constructing these data packet forwarding paths, the expected connectivity between the configured logical network areas and with external networks is ensured, thus finally obtaining virtual machine instances and virtual network devices that are completely configured at the network parameter level.

[0053] Exemplarily, assume that IP addresses have been configured for a virtual machine instance VM_Web serving as a Web server and a virtual machine instance VM_DB serving as a database server respectively, and they are located in different logical network areas, such as VLAN10 and VLAN20. These two VLANs are interconnected by a virtual router R1. To enable VM_Web to access VM_DB, a data packet forwarding path needs to be constructed on R1. The configuration instructions may specify a static route connecting VLAN10 and VLAN20 through R1. The routing configuration module will add the corresponding routing entry on R1. If there are multiple redundant paths, such as through different links or intermediate devices, a path selection metric similar to a formula can be used to determine the primary forwarding path, and the path information can be configured into the routing table of R1. In this way, the data packets sent from VM_Web to VM_DB can be correctly forwarded by R1, indicating that VM_Web and VM_DB have been configured as required at the network level.

[0054] Optionally, the output to the user interaction interface includes: Generating a visual unified operation view by using the configured virtual machine instance and the configured virtual network device; Specifically, when generating a visual unified operation view by using the configured virtual machine instance and the virtual network device, an environment rendering engine is responsible for collecting the status information, configuration summaries of all configured and running virtual machine instances and virtual network devices, and the real-time network topology formed by virtual connections between them. The environment rendering engine uses a preset layout algorithm or a user-defined view template to integrate and render this information into a graphical and interactive visual unified operation view. This view is usually presented on the display interface of a user terminal, enabling the user to intuitively perceive the composition and current running status of the entire experimental environment. For example, it can clearly show the logical positions, connection relationships, key performance indicators of each virtual node, and the active status of network interfaces.

[0055] Analyzing the network traffic of the virtual connection based on the visual unified operation view, and recording the experimental process log.

[0056] Specifically, when analyzing the network traffic of the virtual connection based on this visual unified operation view and recording the experimental process log, the method integrates a lightweight network traffic capture and analysis module. This module can selectively monitor the data packets passing through one or more specified virtual connections, or obtain real-time interface traffic statistics from the virtual network device. The obtained raw traffic data or statistical data can be used for preliminary automated analysis. For example, calculating the real-time throughput of key links, the packet loss rate, or identifying abnormal network behaviors. To achieve intelligent analysis of network behaviors, a network state anomaly metric function can be introduced. This function calculates an anomaly score by comparing the feature vector of the currently observed network traffic with the feature vector of the benchmark network behavior pattern or the expected traffic template: , where is the dimension of the traffic feature vector; and are the values of the currently observed traffic and the benchmark pattern in the i-th feature dimension respectively; is the weight coefficient for the i-th feature dimension, which is used to adjust the importance of different features in anomaly measurement. The value of the calculated network state anomaly measurement function can be used to trigger an alarm or be recorded as part of the experimental process log. At the same time, all key interaction operations performed by all users through this visual unified operation view and the key analysis results generated by the network traffic analysis module are structuredly recorded by a log recording module to form an experimental process log. This experimental process log can include timestamps, operating subjects, operating objects, operation contents, and corresponding environmental feedback or analysis data, providing a basis for subsequent experimental review, problem diagnosis, or teaching evaluation.

[0057] Exemplarily, in an experimental scenario simulating a network attack, the visual unified operation view clearly shows the topology including a virtual machine of an attacked server, a virtual machine of an attacker, and the virtual network devices they are connected to. When the attacker virtual machine launches a distributed denial-of-service attack on the server virtual machine, for example, the network traffic analysis module will detect a sharp increase in traffic on the virtual link connecting the server. At this time, the anomaly degree of the traffic characteristics on this link relative to the normal reference mode can be calculated using a formula. If this anomaly degree exceeds a preset threshold, the system can highlight the abnormal link on the view and record this event and related traffic data in the experimental process log. Subsequent defense operations performed by users, such as configuring rules on the virtual firewall to block attack traffic, will also be recorded in this experimental process log.

[0058] Optionally, the method further includes: Performing correlation analysis based on the experimental process log to generate experimental process performance indicators; Specifically, when performing correlation analysis based on the experimental process log to generate experimental process performance indicators, a log analysis and evaluation module first extracts structured user operation sequences, key system events, and network state data that the network traffic analysis module may record from this experimental process log. This user operation sequence includes, for example, each configuration command executed by the user, operation behaviors on virtual devices, etc. This correlation analysis process aims to compare and quantitatively evaluate these original log data with preset experimental objectives, standard operation procedures, or expected behavior patterns. For example, a comprehensive experimental task completion degree indicator can be defined. If an experiment contains M key task points, each task point is assigned a weight according to its importance, and the completion situation of the user for this task point reflected in the log is evaluated as an achievement value, then the experimental task completion degree indicator can be calculated as follows: , In the formula, is the calculated experimental task completion degree indicator, and its value ranges between 0 and 1; M is the total number of key task points; is the weight of the j-th key task point; It is the actual achievement value of the user for the j-th key task point. In addition to the task completion rate, other performance indicators during the experiment can also be generated, such as operation efficiency indicators, frequency of incorrect operations, mastery of specific skill points, etc. These together constitute a set of multi-dimensional indicators reflecting the user's experimental performance.

[0059] Generate personalized experimental guidance feedback according to the experimental process performance indicators.

[0060] Specifically, when generating personalized experimental guidance feedback based on the generated experimental process performance indicators, a feedback generation module receives a set of such experimental process performance indicators output by the log analysis and evaluation module. A set of feedback rule knowledge bases or a machine learning-based recommendation model is configured inside the feedback generation module. Based on the input set of experimental process performance indicators, such as the experimental task completion rate indicator calculated previously, and other indicators such as operation efficiency and error types, the module matches or infers possible knowledge blind spots, skill deficiencies, or problems in operation habits of the current user during the experiment. Based on these analyses, the feedback generation module automatically organizes the language to generate a personalized experimental guidance feedback that includes an objective evaluation of the user's current experimental performance, analysis and correction tips for specific incorrect operations, and recommendations for targeted learning resources or suggestions for the next steps. This feedback can be presented to the user in real-time or after the experiment through the user interface to help the user consolidate what they have learned and improve their deficiencies, as Figure 4 shown.

[0061] Exemplarily, in an experiment of configuring VLANs, the experimental process log records that a student tried to configure the switch ports but used incorrect commands multiple times, and finally the communication test between VLANs failed. Based on these records, the log analysis and evaluation module calculates that the experimental task completion rate indicator of this student may be relatively low and identifies specific performance indicators such as "unfamiliar use of switch commands" and "misunderstanding of VLAN configuration logic". Subsequently, based on these indicators, the feedback generation module can generate the following personalized experimental guidance feedback: "Your task completion rate for this VLAN configuration experiment is 40%. In the port configuration section, it is detected that you tried invalid commands multiple times. It is recommended to learn the correct configuration method for switch port modes. The failure of communication between VLANs may be related to the three-layer routing settings. Please check whether the sub-interface configuration of the router or the IP address of the SVI interface is correct.

[0062] Optionally, the method further includes: Generate experimental design iteration parameters by integrating the experimental process log and the experimental process performance indicators; Specifically, when generating the iterative parameters for experimental design, a template optimization analysis engine aggregates the experimental process logs and the performance metrics of multiple similar experiments. Through statistical analysis of this aggregated data, the engine can identify common design challenges in a specific experimental design template that lead to generally inefficient user operations or a high error rate. To quantify the revision priority of the template, a template revision recommendation index can be calculated: , wherein, is the experimental design template to be evaluated; is the number of user samples for analysis; , , are respectively the critical error rate, experimental time consumption, and task completion score of a single user; , , are the preset weights for each performance metric. The calculated index and the specific problem points located together constitute the iterative parameters for experimental design.

[0063] Based on the iterative parameters for experimental design, update the corresponding experimental design template in the shared template repository.

[0064] Specifically, when updating the experimental design template based on the iterative parameters for experimental design, an automated template maintenance module compares the template revision recommendation index included in the iterative parameters for experimental design with a preset automatic update threshold. If the index exceeds the threshold, the module automatically modifies the corresponding experimental design template according to the specific adjustment suggestions in the iterative parameters, such as simplifying the configuration of a certain step, adding default parameters, or updating its version identifier. If it does not exceed the threshold, only an optimization recommendation report is generated for manual review by the administrator.

[0065] Exemplarily, if the analysis shows that a large number of users have a high error rate in a certain configuration step of the multi - area OSPF configuration template, resulting in the template revision recommendation index exceeding the preset threshold after public calculation. The system can automatically add more explicit configuration prompt text to the description of this step of the template according to the generated iterative parameters for experimental design, and update the template version number from v2.0 to v2.1.

[0066] It should be noted that for the formulas mentioned above, through the principle of dimensional consistency and mathematical standardization means (such as normalization, dimensionless parameter conversion, or unit system unification), physical quantities with different attributes can be translated into unitless standard values or superposable parameters of the same dimension, so as to eliminate the interference of different dimensions on the operation logic, and make the formulas have mathematical operation rationality and objective law adaptability while retaining the characteristics of the original data distribution. This is a conventional technical means and will not be elaborated here. The electrical connections between the above-mentioned various units do not necessarily represent direct connections of the circuits. Indirect connection methods can be applied to the embodiments of the present invention as long as the purpose of the present invention is achieved. The above-mentioned are only exemplary embodiments of the present invention, and the scope of the present invention cannot be limited thereby.

[0067] That is, any equivalent changes and modifications made in accordance with the teachings of the present invention still fall within the scope covered by the present invention. After considering the specification and the disclosure of the practice, those skilled in the art will easily think of other implementation schemes of the present invention. This application aims to cover any variations, uses, or adaptive changes of the present invention, and these variations, uses, or adaptive changes follow the general principles of the present invention and include common general knowledge or conventional technical means in the technical field not recorded in the present invention.

Claims

1. A method for dynamically constructing a computer network experimental environment based on virtual simulation, characterized in that The method includes: Receiving an experimental scenario description input by a user, parsing the experimental scenario description to generate a dynamic construction instruction sequence, where the dynamic construction instruction sequence includes virtual host instructions, network topology instructions, and configuration instructions; According to the virtual host instructions, creating a virtual machine instance and loading a system image and configuring a network connection for the virtual machine instance; According to the network topology instructions, generating virtual network devices and constructing virtual connections between the virtual network devices, between the virtual machine instance and the virtual network devices; According to the configuration instructions and the virtual connections, loading and running network configuration parameters, service configuration scripts, and security policies for the virtual machine instance and the virtual network devices to obtain a configured virtual machine instance and configured virtual network devices; Taking the configured virtual machine instance and the configured virtual network device connection as a whole and outputting it to a user interaction interface.

2. A method for dynamically constructing a computer network experimental environment based on virtual simulation according to claim 1, characterized in that, The generating the dynamic construction instruction sequence includes: Receiving an initial experiment request and constructing a digital experiment blueprint based on the initial experiment request; Performing a verification process on the digital experiment blueprint, and if the verification process is passed, converting the digital experiment blueprint into a dynamic construction instruction sequence.

3. A method for dynamically constructing a computer network experimental environment based on virtual simulation according to claim 2, characterized in that, The constructing the digital experiment blueprint based on the initial experiment request further includes: According to the version identifier and experimental scenario classification label of the initial experiment request, combining with the digital experiment blueprint to form an experiment design template, and archiving the experiment design template into a preset shared template repository; Responding to the template query conditions submitted by the user, matching the corresponding experiment design template from the shared template repository, and copying to generate a copy of a new digital experiment blueprint for derivative design solutions.

4. A method for dynamically constructing a computer network experimental environment based on virtual simulation according to claim 1, wherein, The loading the system image and configuring the network connection for the virtual machine instance includes: According to the virtual host instructions, allocating computing processing power and storage capacity for the virtual machine instance and instantiating the virtual machine instance; Based on the instantiated virtual machine instance, selecting a preset operating system image and loading it into the virtual machine instance to establish an operating system running environment; Based on the operating system running environment, configuring a network connection mode and a link layer address for the virtual machine instance.

5. A method for dynamically constructing a computer network experimental environment based on virtual simulation according to claim 1, characterized in that, The constructing the virtual connections between the virtual network devices, between the virtual machine instance and the virtual network devices includes: According to the network topology instructions, selecting and instantiating virtual network devices from a preset virtual device model library and configuring virtual network interfaces for the virtual network devices; Using the configured virtual network interfaces and the network interfaces of the virtual machine instance to create and configure multiple virtual links to form virtual connections.

6. A method for dynamically constructing a computer network experimental environment based on virtual simulation according to claim 1, wherein, The security policy includes: Based on the configuration instructions, matching and extracting basic security control components from a preset security rule policy library; Applying the basic security control components to the virtual machine instance and the virtual network devices to generate a collaborative routing adjustment instruction, and using the collaborative routing adjustment instruction to correct the network configuration parameters.

7. A method for dynamically constructing a computer network experimental environment based on virtual simulation according to claim 1, characterized in that The obtaining the configured virtual machine instance and configured virtual network devices includes: Based on the configuration-related instructions, configure corresponding network layer addresses and link layer addresses for the virtual machine instance and the virtual network device to form an addressed network interface; Based on the configuration-related instructions and the addressed network interface, perform partitioning processing on the virtual network device to obtain logical network regions; Utilize the logical network regions and the addressed network interface to construct a data packet forwarding path to obtain a configured virtual machine instance and a configured virtual network device.

8. A method for dynamically constructing a computer network experimental environment based on virtual simulation according to claim 1, characterized in that, The output to the user interface includes: Generate a visual unified operation view using the configured virtual machine instance and the configured virtual network device; Based on the visual unified operation view, analyze the network traffic of the virtual connection and record the experimental process log.

9. A method for dynamically constructing a computer network experimental environment based on virtual simulation according to claim 8, characterized in that, The method further includes: Perform correlation analysis based on the experimental process log to generate experimental process performance indicators; Generate personalized experimental guidance feedback according to the experimental process performance indicators.

10. A method for dynamically constructing a computer network experimental environment based on virtual simulation according to claim 9, characterized in that, The method further includes: Integrate the experimental process log and the experimental process performance indicators to generate experimental design iteration parameters; Based on the experimental design iteration parameters, update the corresponding experimental design template in the shared template repository.

Citation Information

Cited By

  • Hidden security detection method and device based on virtual machine and virtual link

    CN120874043A

  • Virtual machine template library construction method and system for active medical instrument software detection

    CN121996357A

  • A method and system for constructing a virtual machine template library for active medical device software testing

    CN121996357B