Network security test method, device and equipment applied to aviation oil control system

Through customized network security testing methods, network address attacks, service attacks and protocol tampering attacks are carried out against different devices in the airport fuel supply automatic simulation system, solving the problem of unconsidered equipment differences and improving the effectiveness and coverage of network security testing.

CN120301644APending Publication Date: 2025-07-11CIVIL AVIATION UNIV OF CHINA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510439253.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-09
Publication Date
2025-07-11

AI Technical Summary

Technical Problem

In the network security test of airport fuel supply automatic control simulation systems, the network security test effect is poor due to equipment differences not being considered.

Method used

By obtaining the target LAN configuration information, updating the local network address, conducting network address attacks, network service attacks and network protocol tampering attacks, testing the protection capabilities of oil tank group control equipment, operator equipment and oil supply control equipment, and recording the attack results.

Benefits of technology

It improves the effectiveness and pertinence of network security testing and improves the overall network security testing effect of airport fuel supply automatic simulation system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120301644A_ABST
    Figure CN120301644A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a network security test method and device, electronic equipment and a computer readable medium. A specific embodiment of the method comprises the following steps: acquiring target local area network configuration information; according to the target local area network configuration information, updating a local network address to obtain an updated local network address; performing network address attack on the oil tank group control equipment and the operator equipment according to the updated local network address to obtain a network address attack result; performing network service attack on a switch included in the network communication equipment to obtain a network service attack result; performing network protocol tampering attack on the oil supply control equipment to obtain a network protocol tampering attack result; and storing the network address attack result, the network service attack result and the network protocol tampering attack result. According to the embodiment, the network testing method for the airport fuel supply automatic control simulation system can be provided, and the network security testing effect on the fuel supply simulation system is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present disclosure relate to the field of computer technologies, and particularly to a network security testing method, apparatus, and device applied to an aviation fuel control system. Background Art

[0002] The airport fuel supply automatic control simulation system is a simulation system constructed for the real airport fuel supply automatic control system, and is used to simulate and evaluate the network protection ability of the real airport fuel supply automatic control system. Currently, when testing the airport fuel supply automatic control simulation system, the commonly used method is to test each system device included in the airport fuel supply automatic control simulation system through the same network security testing method.

[0003] However, when the above method is used to perform network testing on the simulation system, the following technical problems often exist: Since there are many system devices in the fuel supply automatic control simulation system and their respective network protection means are different, when using a unified network attack testing method, the differences of different devices are not considered for effective network attacks, resulting in poor network security testing effects.

[0004] The above information disclosed in this background art section is only used to enhance the understanding of the background of the inventive concept, and thus, it may include information that does not form the prior art known to those of ordinary skill in the art in this country. Summary of the Invention

[0005] This summary part of the present disclosure is used to briefly introduce the concepts, which will be described in detail in the following detailed implementation part. This summary part of the present disclosure is not intended to identify the key features or essential features of the claimed technical solution, nor is it intended to be used to limit the scope of the claimed technical solution.

[0006] Some embodiments of the present disclosure propose a network security testing method, apparatus, electronic device, and computer-readable medium to solve one or more of the technical problems mentioned in the above background art section.

[0007] In a first aspect, some embodiments of the present disclosure provide a network security testing method, the method comprising: obtaining network configuration information of a target local area network as target local area network configuration information, wherein the system devices in the above-mentioned airport fuel supply automatic control simulation system include oil tank group control devices, operator devices, fuel supply control devices and a target server, and network communication is carried out between the above-mentioned operator devices, the above-mentioned oil tank group control devices, the above-mentioned fuel supply control devices and the above-mentioned target server through network communication devices; updating the local network address according to the above-mentioned target local area network configuration information to obtain an updated local network address, wherein the above-mentioned updated network address and the network addresses of the above-mentioned oil tank group control devices, the above-mentioned operator devices and the above-mentioned fuel supply control devices are under the above-mentioned target local area network; carrying out a network address attack on the above-mentioned oil tank group control devices and the above-mentioned operator devices according to the above-mentioned updated local network address to obtain a network address attack result; carrying out a network service attack on the switch included in the above-mentioned network communication devices to obtain a network service attack result; carrying out a network protocol tampering attack on the above-mentioned fuel supply control devices to obtain a network protocol tampering attack result; storing the above-mentioned network address attack result, the above-mentioned network service attack result and the above-mentioned network protocol tampering attack result as network security testing information.

[0008] In a second aspect, some embodiments of the present disclosure provide a network security testing device, the device comprising: an obtaining unit configured to obtain network configuration information of a target local area network as target local area network configuration information, wherein the system devices in the airport fuel supply automatic control simulation system include oil tank group control devices, operator devices, fuel supply control devices and a target server, and network communication is carried out between the above-mentioned operator devices, the above-mentioned oil tank group control devices, the above-mentioned fuel supply control devices and the above-mentioned target server through network communication devices; an updating unit configured to update the local network address according to the above-mentioned target local area network configuration information to obtain an updated local network address, wherein the above-mentioned updated network address and the network addresses of the above-mentioned oil tank group control devices, the above-mentioned operator devices and the above-mentioned fuel supply control devices are under the above-mentioned target local area network; a network address attack unit configured to carry out a network address attack on the above-mentioned oil tank group control devices and the above-mentioned operator devices according to the above-mentioned updated local network address to obtain a network address attack result; a network service attack unit configured to carry out a network service attack on the switch included in the above-mentioned network communication devices to obtain a network service attack result; a network protocol tampering unit configured to carry out a network protocol tampering attack on the above-mentioned fuel supply control devices to obtain a network protocol tampering attack result; a storage unit configured to store the above-mentioned network address attack result, the above-mentioned network service attack result and the above-mentioned network protocol attack result as network security testing information.

[0009] In a third aspect, some embodiments of the present disclosure provide an electronic device, including: one or more processors; a storage device storing one or more programs thereon, and when the one or more programs are executed by the one or more processors, the one or more processors implement the method described in any implementation manner of the first aspect above.

[0010] In a fourth aspect, some embodiments of the present disclosure provide a computer-readable medium storing a computer program thereon, wherein when the program is executed by a processor, the method described in any implementation manner of the first aspect above is implemented.

[0011] The above-mentioned various embodiments of the present disclosure have the following beneficial effects: The network security testing method of some embodiments of the present disclosure provides a network testing method for the airport fuel supply automatic control simulation system, improving the network security testing effect of the fuel supply simulation system. Specifically, the reason for the poor network security testing effect of the fuel supply simulation system is that: since there are many system devices in the fuel supply automatic control simulation system and each uses different network protection means, when using a unified network attack testing method, the differences of different devices are not considered for effective network attacks, resulting in a poor network security testing effect. Based on this, the network security testing method of some embodiments of the present disclosure first obtains the network configuration information of the target local area network as the target local area network configuration information. Among them, the system devices in the above-mentioned airport fuel supply automatic control simulation system include oil tank group control devices, operator devices, fuel supply control devices, and target servers. The above-mentioned operator devices, the above-mentioned oil tank group control devices, the above-mentioned fuel supply control devices, and the above-mentioned target servers conduct network communication through network communication devices. Thus, each system device and its corresponding network address under the above-mentioned target local area network can be determined through the target local area network configuration information. Then, according to the above-mentioned target local area network configuration information, the local network address is updated to obtain the updated local network address. Among them, the above-mentioned updated network address and the network addresses of the above-mentioned oil tank group control devices, the above-mentioned operator devices, and the above-mentioned fuel supply control devices are within the above-mentioned target local area network. Thus, by updating the local network address, the attack host and each system device in the above-mentioned airport fuel supply automatic control simulation system are both within the scope of the above-mentioned target local area network, facilitating subsequent network security testing. After that, according to the above-mentioned updated local network address, network address attacks are carried out on the above-mentioned oil tank group control devices and the above-mentioned operator devices to obtain network address attack results. Thus, by simulating the attack methods of illegal visitors, the protection capabilities of the oil tank group control devices and operator devices in terms of address spoofing and illegal access can be tested. Secondly, network service attacks are carried out on the switches included in the above-mentioned network communication devices to obtain network service attack results. Thus, by conducting network service tests on network communication devices such as switches, the stability and security of network communication devices when processing abnormal data can be evaluated. Then, network protocol tampering attacks are carried out on the above-mentioned fuel supply control devices to obtain network protocol tampering attack results. Thus, by tampering with the data packets of the network protocol, the protection capabilities of the fuel supply control devices when facing network protocol tampering (such as command hijacking, data tampering) can be tested. Finally, the above-mentioned network address attack results, the above-mentioned network service attack results, and the above-mentioned network protocol tampering attack results are stored as network security testing information. Thus, the results and intermediate data of the above-mentioned various network security attacks can be recorded and stored, facilitating subsequent analysis.Also, through the method of customizing attack tests on devices, it has been noticed that the unified test method ignores the protection characteristics of different devices, thereby improving the effectiveness and pertinence of network security tests, and further enhancing the overall network security test effect. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] In combination with the accompanying drawings and with reference to the following specific embodiments, the above and other features, advantages and aspects of the various embodiments of the present disclosure will become more apparent. Throughout the drawings, the same or similar reference numerals denote the same or similar elements. It should be understood that the drawings are schematic and the elements and elements are not necessarily drawn to scale.

[0013] Figure 1 is a flowchart of some embodiments of a network security test method according to the present disclosure;

[0014] Figure 2 is a schematic structural diagram of some embodiments of a network security test device according to the present disclosure;

[0015] Figure 3 is a schematic structural diagram of an electronic device suitable for implementing some embodiments of the present disclosure. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0016] Embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although some embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. On the contrary, these embodiments are provided to more thoroughly and completely understand the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are only for exemplary purposes and are not used to limit the protection scope of the present disclosure.

[0017] In addition, it should be noted that only parts related to the relevant invention are shown in the drawings for the sake of convenience of description. Without conflict, the embodiments in the present disclosure and the features in the embodiments can be combined with each other.

[0018] It should be noted that the concepts such as "first" and "second" mentioned in the present disclosure are only used to distinguish different devices, modules or units, and are not used to limit the order of functions performed by these devices, modules or units or their interdependent relationships.

[0019] It should be noted that the modifications of "one" and "plural" mentioned in the present disclosure are illustrative rather than restrictive. Those skilled in the art should understand that unless otherwise clearly specified in the context, it should be understood as "one or more".

[0020] The names of the messages or information exchanged between multiple devices in the embodiments of the present disclosure are only for illustrative purposes and are not used to limit the scope of these messages or information.

[0021] The present disclosure will be described in detail below with reference to the accompanying drawings and in conjunction with embodiments.

[0022] Figure 1 Flow 100 of some embodiments of the network security testing method according to the present disclosure is shown. The network security testing method includes the following steps:

[0023] Step 101, obtain the network configuration information of the target local area network as the target local area network configuration information.

[0024] In some embodiments, the execution subject (such as a computing device) of the network security testing method can obtain the network configuration information of the target local area network as the target local area network configuration information through system instructions (such as the ipconfig instruction in the Windows system). Among them, the above execution subject can be an attack device. The system devices in the above airport fuel supply automatic control simulation system include oil tank group control devices, operator devices, fuel supply control devices, and target servers. Network communication is carried out among the above operator devices, the above oil tank group control devices, the above fuel supply control devices, and the above target servers through network communication devices. The above oil tank group control device can be a terminal device for managing the oil tank group. The above fuel supply control device can be a terminal device for controlling oil discharge or oil receipt. The above network communication device can be a switch or a router. The above operator device can be a terminal device (such as a computer) used by system operators. The above target local area network can be the local area network where the above airport fuel supply automatic control simulation system is located. In practice, the above execution subject can obtain the network configuration information of the target local area network as the target local area network configuration information through system instructions (such as the ipconfig instruction in the Windows system). The above target local area network configuration information includes but is not limited to the IP address of the operator device, the IP address of the oil tank group control device, and the IP address of the fuel supply control device. For example, the IP address of the operator device can be 192.168.1.21), and the IP address of the oil tank group control device can be 192.168.1.32.

[0025] The above-mentioned airport fuel supply automatic control simulation system includes a field device layer, a field control layer, a process monitoring layer, and a production management layer. The above-mentioned production management layer has control and management functions, and can issue instructions such as oil receiving, oil sending, and tank inversion to the field device layer and the field control layer through the process monitoring layer to realize the data information management of the tank group. The above-mentioned production management layer has a target server for reading and controlling production data in the network. The above-mentioned operator device and engineer device are located in the above-mentioned process monitoring layer. The above-mentioned process monitoring layer uses the TCP / IP protocol to realize the communication between the engineer device and the operator device. In addition, the above-mentioned process monitoring layer also adopts the advanced configuration software IFIX and the powerful programming software UnityPro. The operator device can provide real-time monitoring and control functions, enabling the operator to quickly understand the status of the airport fuel supply system and make necessary adjustments. The engineering station computer, by installing software such as IFIX and UnityPro, has the ability to configure the system, perform programming, and conduct deeper-level system management.

[0026] The above-mentioned fuel supply control equipment is located in the above-mentioned field control layer. The above-mentioned field control layer uses the Modbus protocol for data transmission between the fuel supply control equipment and uses the CAN bus protocol to effectively support the serial communication network of the test platform DCS. The fuel supply control equipment located in the field control layer includes a PLC cabinet, a redundant PLC of the Schneider 140 system, and an IO station system. The redundant PLC of the Schneider 140 system plays a role of standby and redundancy, ensuring the high availability of the system in the face of potential failures. At the same time, the IO station system is responsible for processing inputs and outputs, working in coordination with other components to achieve precise monitoring and effective control of all aspects of the fuel storage tank simulation system. The oil tank circulation simulation system in the field control layer consists of a Schneider M221 PLC and a button box, and is used to simulate and control the circulation process of the oil tank. The PLC is responsible for executing program logic, monitoring sensor inputs, and taking corresponding measures according to preset conditions to ensure the normal operation of the oil tank. The field control layer also has an indicator light circulation simulation system, which consists of a Siemens S7-200 PLC and a button box. The S7-200 PLC acts as a key controller, responsible for coordinating and executing various operations.

[0027] The oil tank group control equipment located in the above-mentioned field device layer includes at least two rheostats, at least two water tanks, water pumps, and oil tank sensors. The oil tank sensors include temperature sensors, pressure sensors, and liquid level sensors. The above-mentioned at least two rheostats are used to simulate the oil sending pressure setting and the oil receiving pressure value. The above-mentioned at least two water tanks, water pumps, and oil tank sensors are used to simulate the process of oil tank inversion. This combination, through the cyclic operation of the water tanks, combined with the coordinated action of the water pumps and sensors, effectively simulates the movement and transfer of the liquid in the oil tank, realizing the comprehensive simulation and monitoring of the inversion process.

[0028] It should be noted that the above wireless connection methods may include, but are not limited to, 3G / 4G / 5G connections, WiFi connections, Bluetooth connections, WiMAX connections, Zigbee connections, UWB (ultra wideband) connections, and other wireless connection methods known now or developed in the future.

[0029] It should be noted that the above computing device can be hardware or software. When the computing device is hardware, it can be implemented as a distributed cluster composed of multiple servers or terminal devices, or as a single server or a single terminal device. When the computing device is embodied as software, it can be installed in the above-listed hardware devices. It can be implemented as, for example, multiple software or software modules for providing distributed services, or as a single software or software module. No specific limitation is made here. It should be understood that the number of computing devices can be arbitrary according to the implementation requirements.

[0030] Step 102: Update the local network address according to the target local area network configuration information to obtain the updated local network address.

[0031] In some embodiments, the above execution entity can update the local network address according to the above target local area network configuration information to obtain the updated local network address. Among them, the above updated network address, the network address of the above oil tank group control device (i.e., the IP address of the oil tank group control device), the network address of the above operator device (the IP address of the operator device), and the network address of the above oil supply control device (the IP address of the oil supply control device) are under the above target local area network.

[0032] In some optional implementation manners of some embodiments, the above execution entity can update the local network address according to the above target local area network configuration information through the following steps to obtain the updated local network address:

[0033] First step: Parse the above target local area network configuration information to obtain the target local area network segment information. In practice, the above execution entity can parse the above target local area network configuration information by extracting JSON attributes to obtain the target local area network segment information. As an example, the above target local area network segment information can be the segment range of the above target local area network. For example, if the above target local area network segment information is "192.168.1.0 / 24", it can represent the segment range of the above target local area network.

[0034] Step 2: Use a network address scanning tool to perform a network address scan on the target local area network segment represented by the above target local area network segment information, to obtain the network address information of the oil tank group control device, the network address information of the operator device, and the network address information of the oil supply control device. As an example, the above network address scanning tool can be an nmap network mapper. The above network address information of the oil tank group control device can be the IP address of the oil tank group control device. The above network address information of the operator device can be the IP address of the operator device. The above network address information of the oil supply control device can be the IP address of the oil supply control device. In practice, the above execution entity can perform a network address scan on the target local area network segment represented by the above target local area network segment information through the above network address scanning tool, and identify the IP address of the operator device, the IP address of the oil tank group control device, and the IP address of the oil supply control device.

[0035] Step 3: Obtain the local network configuration information. Among them, the above local network configuration information includes the local network address and the local subnet mask. In practice, the above execution entity can obtain the local network configuration information under the local area network where it is located through system instructions (such as the ipconfig instruction in Windows). The local network address can be the IP address of the execution entity. For example, the above local network address can be 192.168.0.123, and the local subnet mask can be 255.255.255.0.

[0036] Step 4: Update the local network address according to the above network address information of the oil tank group control device, the above network address information of the operator device, the above network address information of the oil supply control device, and the above target local area network segment information, to obtain the updated local network address. In practice, the above execution entity can select an IP address different from the above network address information of the oil tank group control device, the above network address information of the operator device, and the above network address information of the oil supply control device within the range of the target local area network segment represented by the above target local area network segment information as the local network address, so as to modify the local network address and obtain the updated local network address.

[0037] Step 103: Perform a network address attack on the oil tank group control device and the operator device according to the updated local network address, to obtain a network address attack result.

[0038] In some embodiments, the above execution entity can perform a network address attack on the above oil tank group control device and the above operator device according to the above updated local network address, to obtain a network address attack result.

[0039] In the process of adopting technical solutions to solve the problems mentioned in the background art, the following problems often arise: In the traditional network security testing process, it is difficult to simulate the attack paths (attack methods) of real attackers to disguise, intercept, and tamper with data instructions inside the target control system. Therefore, it is difficult to systematically verify the security performance of the control system under the conditions of disguise and instruction tampering at the communication link layer, resulting in relatively low system network security.

[0040] In the face of the above technical problems, the inventor decided to adopt the following solutions:

[0041] In some optional implementation manners of some embodiments, the above execution subject may perform a network address attack on the above oil tank group control device and the above operator device according to the above updated local network address through the following steps to generate a network address attack result:

[0042] The first step is to send a spoofed response packet to the above oil tank group control device according to the above operator device network address to obtain the communication data packet of the oil tank group control device. In practice, the above execution subject may use an ARP spoofing tool to disguise as the operator device network address (operator device IP address), that is, send a forged ARP response message to the oil tank group control device, stating that the MAC address corresponding to the operator device IP address is the MAC address of the execution subject. Then, after receiving the ARP response, the above oil tank group control device updates its ARP cache, so that the data it subsequently sends to the operator device is forwarded to the execution subject. Finally, the above execution subject intercepts the data through a packet capture tool to obtain the communication data packet of the oil tank group control device. As an example, the above ARP spoofing tool may be an arpspoof tool or an ettercap tool. The above packet capture tool may be a Scapy packet capture tool or a mitmproxy packet capture tool.

[0043] The second step is to send a spoofed response packet to the above operator device according to the above oil tank group control device network address to obtain the communication data packet of the operator device. In practice, the above execution subject may use an ARP spoofing tool to disguise as the network address of the oil tank group control device (oil tank group control device IP address), that is, send a forged ARP response message to the operator device, stating that the MAC address corresponding to the oil tank group control device IP address is the MAC address of the execution subject. Then, after receiving the ARP response, the above operator device updates its ARP cache, so that the data it subsequently sends to the oil tank group control device is forwarded to the execution subject. Finally, the above execution subject intercepts the data through the above packet capture tool to obtain the communication data packet of the operator device.

[0044] Step 3: According to the updated local network address above, tamper with the obtained communication data packets of the oil tank group control equipment to obtain the tampered communication data packets of the oil tank group control equipment. In practice, the above-mentioned execution entity can tamper with the key fields (such as function codes or control command values) in the communication data packets of the oil tank group control equipment through the communication protocol used by the updated local network address above (such as Modbus protocol, TCP protocol, etc.) to obtain the tampered communication data packets of the oil tank group control equipment. For example, the communication data packet of the oil tank group control equipment obtained by the above-mentioned execution entity is "TX:01 05 00 10FF00 8C 3A". Among them, the function code part "FF 00" indicates writing data (that is, indicating "on" or "starting the pump"). The function code part in the tampered communication data packet of the oil tank group control equipment is "00 00", indicating "off" (that is, stopping the pump).

[0045] Step 4: According to the updated local network address above, tamper with the obtained communication data packets of the operator equipment to obtain the tampered communication data packets of the operator equipment. In practice, the above-mentioned execution entity can tamper with the key fields (such as Modbus function codes) in the communication data packets of the operator equipment through the communication protocol used by the updated local network address above (such as Modbus protocol) to obtain the tampered communication data packets of the operator equipment.

[0046] Step 5: Send the above-mentioned tampered communication data packets of the operator equipment to the above-mentioned oil tank group control equipment. In practice, the above-mentioned execution entity can send the above-mentioned tampered communication data packets of the operator equipment to the above-mentioned oil tank group control equipment.

[0047] Step 6: Send the above-mentioned tampered communication data packets of the oil tank group control equipment to the above-mentioned operator equipment. In practice, the above-mentioned execution entity can send the above-mentioned tampered communication data packets of the oil tank group control equipment to the above-mentioned operator equipment.

[0048] Step 7: Determine the above-mentioned tampered communication data packets of the operator equipment and the above-mentioned tampered communication data packets of the oil tank group control equipment as the network address attack results. In practice, the above-mentioned execution entity can determine the above-mentioned tampered communication data packets of the operator equipment and the above-mentioned tampered communication data packets of the oil tank group control equipment as the network address attack results.

[0049] The above first step to the seventh step are an inventive point of the embodiments of the present disclosure, which solve the technical problem that "in the traditional network security testing process, it is difficult to simulate the attack path (attack method) of a real attacker to disguise, intercept, and tamper with data instructions inside the target control system, making it difficult to systematically verify the security performance of the control system under the condition of disguise and instruction tampering in the communication link layer. In the traditional network security testing process, it is difficult to simulate the attack path (attack method) of a real attacker to disguise, intercept, and tamper with data instructions inside the target control system, making it difficult to systematically verify the security performance of the control system under the condition of disguise and instruction tampering in the communication link layer, resulting in a relatively low system network security." The factors leading to relatively low system network security are often as follows: In the traditional network security testing process, it is difficult to simulate the attack path (attack method) of a real attacker to disguise, intercept, and tamper with data instructions inside the target control system, making it difficult to systematically verify the security performance of the control system under the condition of disguise and instruction tampering in the communication link layer, resulting in a relatively low system network security. If the above factors are solved, the effect of improving the system network communication security can be achieved. To achieve this effect, in this application, a man-in-the-middle attack link based on ARP spoofing is adopted to precisely tamper with the industrial protocol level (such as the Modbus protocol), thereby simulating the attack methods of disguising, intercepting, and tampering with data instructions inside the target control system, improving the network test depth and the type of network attack methods for the airport fuel supply automatic control simulation system, and thus improving the system network security.

[0050] Step 104: Perform a network service attack on the switch included in the network communication device to obtain a network service attack result.

[0051] In some embodiments, the above execution subject may perform a network service attack on the switch included in the above network communication device to obtain a network service attack result. In practice

[0052] In the process of adopting technical solutions to solve the problems mentioned in the background art, the following problems often arise: Network service attack testing usually performs attack testing by forging a large number of source MAC addresses and sending broadcast data frames to the target switching device, often relying on the accumulation of the number of data frames. Therefore, the attack behavior is single and easily limited by the network rate, making it difficult to perform deeper network service attack testing on complex systems such as the airport fuel supply automatic control simulation system, resulting in a decrease in the system network test coverage rate.

[0053] Facing the above technical problems, the inventor decides to adopt the following solution:

[0054] In some alternative implementation manners of some embodiments, the above-mentioned execution entity may perform a network service attack on the switch included in the above-mentioned network communication device according to the above-mentioned updated network address through the following steps to obtain a network service attack result:

[0055] First step, perform address resolution on the above-mentioned target local area network through a network sniffing tool to obtain a set of device address mapping information. In practice, the above-mentioned execution entity may perform ARP detection on each device under the above-mentioned target local area network through the above-mentioned network sniffing tool to obtain the IP addresses and corresponding MAC addresses of each device under the target local area network, and construct an IP-MAC mapping table for each device as the address mapping information of each device. As an example, the above-mentioned network sniffing tool may be an arp-scan tool or a Netdiscover tool. The device address mapping information in the above-mentioned set of device address mapping information may be the IP-MAC mapping table of the corresponding device. For example, the device address mapping information may be, but is not limited to, the operator device IP-MAC mapping table, the oil tank group control device IP-MAC mapping table, or the oil supply control device IP-MAC mapping table.

[0056] Second step, generate each random physical address. Among them, the above-mentioned random physical address may be a randomly generated MAC address. In practice, the above-mentioned execution entity may randomly generate a large number of random MAC addresses as each random physical address according to the MAC address format through relevant library functions (such as the random.randint() function in Python).

[0057] Third step, generate a set of forged source physical addresses according to the above-mentioned set of address mapping information and each generated random physical address. In practice, first, the above-mentioned execution entity may randomly extract MAC addresses from each device address mapping information included in the above-mentioned set of device address mapping information as each random physical address. Then, each extracted random physical address and each generated random physical address may be determined as the set of forged source physical addresses.

[0058] Step 4: Generate each forged data frame according to the network service attack tool and the above-mentioned forged source physical address set to obtain a forged data frame set. Among them, the forged data frames in the above-mentioned forged data frame set contain the generated forged source physical addresses. In practice, the above-mentioned execution entity can use a network service attack tool (such as the macof-i eth0 instruction in the macof tool) to construct an Ethernet data frame starting from the forged source physical address as the forged data frame to obtain a forged data frame set. The number of forged data frames in the above-mentioned forged data frame set is greater than or equal to the preset frame number. The frame content of the constructed forged data frame can be empty, a TCP pseudo-header, or a broadcast frame, and the destination MAC address can be set as the broadcast address or the MAC address of a certain device under the above-mentioned target local area network. As an example, the above-mentioned network service attack tool can be the hping3 tool or the macof tool in the Dsniff tool set. The above-mentioned preset frame number can be 5000.

[0059] Step 5: Generate a network address response packet set according to the above-mentioned forged source physical address set. Among them, the network address response packets in the above-mentioned network address response packet set correspond to the forged source physical addresses in the above-mentioned forged source physical address set. In practice, first, the above-mentioned execution entity can generate each ARP response data packet greater than or equal to the above-mentioned preset number as the network address response packet set. Then, the above-mentioned execution entity can randomly bind the ARP response data packets in the ARP response data packet set (network address response packet set) to the forged source physical addresses in the above-mentioned forged source physical address set to update the network address response packet set.

[0060] Step 6: Randomly generate an attack cycle time. In practice, the above-mentioned execution entity can randomly generate a time as the attack cycle time. As an example, the above-mentioned attack cycle time can be 0.1s.

[0061] Step 7: According to the above attack cycle time, send the above network address response packet set and the above forged data frame set to the switch included in the above network communication device to perform a network service attack on the above switch. In practice, first, the above execution entity can determine the switch port to which the above operator device is connected through the above operator device network address and network topology. Then, the above execution entity can use a network service attack tool (such as the macof tool or a custom script based on Scapy) to broadcast or forge the target address (directional mode), and take the above attack cycle time as the period to alternately send each network address response packet included in the above network address response packet set and each forged data frame included in the above forged data frame set to the switch included in the above network communication device. Since each forged data frame points to the same port of the switch or is in the same broadcast domain, the switch needs to establish a CAM mapping for each new source MAC address after receiving these frames, which ultimately causes the overflow of the switch's CAM address table, thereby triggering broadcast flooding or forwarding anomalies, and realizing network service interference on the switch.

[0062] Step 8: Determine the above attack cycle time, the above network address response packet set, and the above forged data frame set as the network service attack result. In practice, the above execution entity can perform a network protocol tampering attack on the above attack cycle time, the above network address response packet set, and the above forged data frame set device to obtain the network protocol tampering attack result.

[0063] The above Steps 1 to 8 are an inventive point of an embodiment of the present disclosure, which solves the technical problem that "network service attack tests usually use the method of forging a large number of source MAC addresses and sending broadcast data frames to the target switching device for attack testing, often relying on the accumulation of the number of data frames. Therefore, the attack behavior is single and is easily limited by the network rate, making it difficult to perform deeper network service attack tests on complex systems such as the airport fuel supply automatic control simulation system, resulting in a decrease in the system network test coverage rate". The factors leading to the decrease in the system network test coverage rate are often as follows: Network service attack tests usually use the method of forging a large number of source MAC addresses and sending broadcast data frames to the target switching device for attack testing, often relying on the accumulation of the number of data frames. Therefore, the attack behavior is single and is easily limited by the network rate, making it difficult to perform deeper network service attack tests on complex systems such as the airport fuel supply automatic control simulation system. To achieve this effect, in this application, the address mapping relationship of each device under the target local area network can be actively identified, so as to dynamically construct a large number of forged physical addresses. The interference intensity can also be increased by combining ARP spoofing and MAC conflicts, and the attack behavior type can be increased by using a time period, so as to perform deeper network service attack tests on complex systems such as the airport fuel supply automatic control simulation system, thereby improving the system network test coverage rate.

[0064] In some embodiments, the above-mentioned execution entity may perform a network protocol tampering attack on the above-mentioned fuel supply control device to obtain the result of the network protocol tampering attack.

[0065] In some optional implementation manners of some embodiments, the above-mentioned execution entity may perform a network protocol tampering attack on the above-mentioned fuel supply control device through the following steps to obtain the result of the network protocol tampering attack:

[0066] First step, use a port scanning tool to perform a port scan on the network address information of the above-mentioned fuel supply control device to determine the network port of the fuel supply control device. As an example, the above-mentioned port scanning tool may be an nmap port scanning tool. In practice, the above-mentioned execution entity may use a port scanning tool to perform a TCP port scan operation on the network address information of the fuel supply control device (the IP address of the fuel supply control device) (for example, using SYN scan (TCP SYN scan) or service identification scan mode (-sV)) to determine the currently open port number of the fuel supply control device as the network port of the fuel supply control device and the service type corresponding to the network port of the fuel supply control device. For example, the above-mentioned execution entity may perform a TCP port scan operation through the instruction "nmap -sS -sV -p 1-1024 192.168.1.30". The scan result shows that port 502 is in the open state and the service identifier is the Modbus-TCP protocol. Then the above-mentioned execution entity may determine that the fuel supply control device is running a Modbus communication service and the network port of the fuel supply control device is port 502.

[0067] Second step, use a network protocol attack tool and the above-mentioned network port of the fuel supply control device to establish a communication session with the above-mentioned fuel supply control device. Among them, the established communication session uses a preset network communication protocol. The above-mentioned preset network communication protocol may be the Modbus communication protocol. In practice, the above-mentioned execution entity may establish a TCP communication session with the target device through a Modbus protocol communication library or an attack tool (such as the pymodbus tool, the modpol tool, or the Scapy tool). Thus, the above-mentioned execution entity may establish a communication connection with the fuel supply control device through the Modbus-TCP protocol and send arbitrarily constructed Modbus commands to the fuel supply control device through the established connection.

[0068] Step 3: Send a preset tampered data packet to the above-mentioned fuel supply control device through the established communication session to receive the data packet feedback information sent by the above-mentioned fuel supply control device. Among them, the above-mentioned preset tampered data packet contains preset malicious instruction information. Among them, the above-mentioned preset malicious instruction information may be a malicious Modbus command. In practice, the above-mentioned execution entity may send a preset tampered data packet containing a malicious Modbus command to the above-mentioned fuel supply control device through the established Modbus communication session. As an example, the above-mentioned malicious Modbus commands may include, but are not limited to, illegal writing to registers, function code tampering (such as forging function codes 0x06, 0x10, etc. for forced writing), unauthorized commands (such as write operations for read-only areas), commands that trigger buffer overflows or out-of-bounds accesses. Then, the above-mentioned execution entity may receive the data packet feedback information sent by the above-mentioned fuel supply control device. The above-mentioned data packet feedback information may be the data packet returned by the above-mentioned fuel supply control device.

[0069] Step 4: Determine the above-mentioned data packet feedback information as the result of network protocol tampering attack. In practice, the above-mentioned execution entity may determine the above-mentioned data packet feedback information as the result of network protocol tampering attack.

[0070] Step 106: Store the network address attack result, the network service attack result, and the network protocol tampering attack result as network security test information.

[0071] In some embodiments, the above-mentioned execution entity may store the above-mentioned network address attack result, the above-mentioned network service attack result, and the above-mentioned network protocol tampering attack result as network security test information.

[0072] In some optional implementation manners of some embodiments, the above-mentioned execution entity may store the above-mentioned network address attack result, the above-mentioned network service attack result, and the above-mentioned network protocol tampering attack result as network security test information through the following steps:

[0073] Step 1: Determine the above-mentioned network address attack result, the above-mentioned network service attack result, and the above-mentioned network protocol tampering attack result as network security test information. In practice, the above-mentioned execution entity may determine the above-mentioned network address attack result, the above-mentioned network service attack result, and the above-mentioned network protocol tampering attack result as network security test information.

[0074] Step 2: Perform encryption processing on the above-mentioned network security test information to obtain encrypted network security test information. In practice, the above-mentioned execution entity may perform encryption processing on the above-mentioned network security test information through a preset encryption algorithm and a preset encryption key corresponding to the preset encryption algorithm to obtain encrypted network security test information. As an example, the above-mentioned preset encryption algorithm may be a symmetric encryption algorithm (such as the RSA encryption algorithm).

[0075] In the third step, store the encrypted network security test information in a storage device. In practice, the above-mentioned execution entity may store the encrypted network security test information in a storage device. The storage device may be a solid-state drive or a buffer.

[0076] The above-mentioned various embodiments of the present disclosure have the following beneficial effects: The network security testing method of some embodiments of the present disclosure provides a network testing method for an airport fuel supply automatic control simulation system, improving the network security testing effect of the fuel supply simulation system. Specifically, the reason for the poor network security testing effect of the fuel supply simulation system is that: since there are many system devices in the fuel supply automatic control simulation system and each uses different network protection means, when using a unified network attack testing method, the differences of different devices are not considered for effective network attacks, resulting in a poor network security testing effect. Based on this, the network security testing method of some embodiments of the present disclosure, first, obtains the network configuration information of the target local area network as the target local area network configuration information. Among them, the system devices in the above-mentioned airport fuel supply automatic control simulation system include oil tank group control devices, operator devices, fuel supply control devices, and target servers. The above-mentioned operator devices, the above-mentioned oil tank group control devices, the above-mentioned fuel supply control devices, and the above-mentioned target servers communicate with each other through network communication devices. Thus, each system device and its corresponding network address under the above-mentioned target local area network can be determined through the target local area network configuration information. Then, according to the above-mentioned target local area network configuration information, the local network address is updated to obtain the updated local network address. Among them, the above-mentioned updated network address is in the above-mentioned target local area network with the network address of the oil tank group control device, the network address of the operator device, and the network address of the fuel supply control device. Thus, by updating the local network address, the attack host and each system device in the above-mentioned airport fuel supply automatic control simulation system are both in the above-mentioned target local area network range, facilitating subsequent network security testing. After that, according to the above-mentioned updated local network address, a network address attack is carried out on the above-mentioned oil tank group control device and the above-mentioned operator device to obtain a network address attack result. Thus, by simulating the attack method of an illegal visitor, the protection capabilities of the oil tank group control device and the operator device in aspects such as address spoofing and illegal access can be tested. Secondly, a network service attack is carried out on the switch included in the above-mentioned network communication device to obtain a network service attack result. Thus, by conducting a network service test on network communication devices such as switches, the stability and security of network communication devices in processing abnormal data can be evaluated. Then, a network protocol tampering attack is carried out on the above-mentioned fuel supply control device to obtain a network protocol tampering attack result. Thus, by tampering with the data packets of the network protocol, the protection capabilities of the fuel supply control device when facing network protocol tampering (such as command hijacking, data tampering) can be tested. Finally, the above-mentioned network address attack result, the above-mentioned network service attack result, and the above-mentioned network protocol tampering attack result are stored as network security testing information. Thus, the results and intermediate data of the above-mentioned various network security attacks can be recorded and stored, facilitating subsequent analysis.Also, through the method of customized attack testing on devices, it has been noticed that the unified testing method ignores the protection characteristics of different devices, thus improving the effectiveness and pertinence of network security testing, and further enhancing the overall network security testing effect.

[0077] For further reference Figure 2 , as an implementation of the methods shown in the above figures, the present disclosure provides some embodiments of a network security testing device. These device embodiments correspond to Figure 1 the method embodiments shown, and the network security testing device can be specifically applied to various electronic devices.

[0078] As Figure 2 shown, the network security testing device 200 of some embodiments includes: an acquisition unit 201, an update unit 202, a network address attack unit 203, a network service attack unit 204, a network protocol tampering unit 205, and a storage unit 206. Among them, the acquisition unit 201 is configured to acquire the network configuration information of the target local area network as the target local area network configuration information. Among them, the system devices in the airport fuel supply automatic control simulation system include an oil tank group control device, an operator device, a fuel supply control device, and a target server. Network communication is carried out between the above operator device, the above oil tank group control device, the above fuel supply control device, and the above target server through network communication devices; the update unit 202 is configured to update the local network address according to the above target local area network configuration information to obtain the updated local network address, where the above updated network address is under the above target local area network with the network addresses of the above oil tank group control device, the above operator device, and the above fuel supply control device; the network address attack unit 203 is configured to perform a network address attack on the above oil tank group control device and the above operator device according to the above updated local network address to obtain a network address attack result; the network service attack unit 204 is configured to perform a network service attack on the switch included in the above network communication device to obtain a network service attack result; the network protocol tampering unit 205 is configured to perform a network protocol tampering attack on the above fuel supply control device to obtain a network protocol tampering attack result; the storage unit 206 is configured to store the above network address attack result, the above network service attack result, and the above network protocol attack result as network security testing information.

[0079] It can be understood that the various units described in the network security testing device 200 correspond to the respective steps in the method described with reference to Figure 1 the above. Therefore, the operations, features, and beneficial effects described above for the method also apply to the network security testing device 200 and the units included therein, and will not be repeated here.

[0080] For the following referenceFigure 3 , which shows a schematic structural diagram of an electronic device 300 suitable for implementing some embodiments of the present disclosure. Figure 3 The illustrated electronic device is merely an example and should not impose any limitations on the functions and usage scope of the embodiments of the present disclosure.

[0081] As Figure 3 shown, the electronic device 300 may include a processing device (such as a central processing unit, a graphics processing unit, etc.) 301, which may perform various appropriate actions and processes according to the program stored in the read-only memory 302 or the program loaded from the storage device 308 into the random access memory 303. In the random access memory 303, various programs and data required for the operation of the electronic device 300 are also stored. The processing device 301, the read-only memory 302, and the random access memory 303 are connected to each other through a bus 304. The input / output interface 305 is also connected to the bus 304.

[0082] Generally, the following devices may be connected to the I / O interface 305: an input device 306 including, for example, a touch screen, a touchpad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; an output device 307 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 308 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 309. The communication device 309 may allow the electronic device 300 to communicate with other devices wirelessly or wiredly to exchange data. Although Figure 3 the electronic device 300 with various devices is shown, it should be understood that it is not required to implement or have all the shown devices. More or fewer devices may be alternatively implemented or had. Figure 3 Each block shown in

[0083] may represent a device or, according to needs, multiple devices.

[0084] It should be noted that the computer-readable medium described in some embodiments of the present disclosure may be a computer-readable signal medium, a computer-readable storage medium, or any combination of the two. A computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In some embodiments of the present disclosure, a computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In some embodiments of the present disclosure, a computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. A computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on a computer-readable medium may be transmitted using any appropriate medium, including but not limited to: wires, optical cables, RF (radio frequency), etc., or any suitable combination of the above.

[0085] In some embodiments, the client and the server may communicate using any currently known or future-developed network protocol such as HTTP (Hyper Text Transfer Protocol), and may be interconnected with digital data communication in any form or medium (e.g., a communication network). Examples of communication networks include local area networks ("LAN"), wide area networks ("WAN"), the Internet (e.g., the Internet), and end-to-end networks (e.g., ad hoc end-to-end networks), as well as any currently known or future-developed networks.

[0086] The above computer-readable medium may be included in the above electronic device; or may exist separately without being assembled into the electronic device. The above computer-readable medium carries one or more programs. When the one or more programs are executed by the electronic device, the electronic device is caused to: obtain network configuration information of a target local area network as target local area network configuration information, wherein the system devices in the above airport fuel supply automatic control simulation system include oil tank group control devices, operator devices, fuel supply control devices, and a target server, and network communication is performed between the above operator devices, the above oil tank group control devices, the above fuel supply control devices, and the above target server through network communication devices; update the local network address according to the above target local area network configuration information to obtain an updated local network address, wherein the above updated network address and the network addresses of the above oil tank group control devices, the above operator devices, and the above fuel supply control devices are under the above target local area network; perform a network address attack on the above oil tank group control devices and the above operator devices according to the above updated local network address to obtain a network address attack result; perform a network service attack on the switch included in the above network communication device to obtain a network service attack result; perform a network protocol tampering attack on the above fuel supply control device to obtain a network protocol tampering attack result; and store the above network address attack result, the above network service attack result, and the above network protocol tampering attack result as network security test information.

[0087] Computer program code for performing the operations of some embodiments of the present disclosure may be written in one or more programming languages or combinations thereof. The above programming languages include object-oriented programming languages - such as Java, Smalltalk, C++; and also include conventional procedural programming languages - such as the "C" language or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, executed as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network - including a local area network (LAN) or a wide area network (WAN) - or may be connected to an external computer (e.g., connected through the Internet using an Internet service provider).

[0088] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flowchart or block diagram may represent a module, a segment of a program, or a part of code that contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than that marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, as well as the combinations of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system that performs the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.

[0089] The units described in some embodiments of the present disclosure can be implemented in software or in hardware. The described units can also be provided in a processor. For example, it can be described as: a processor includes an acquisition unit, an update unit, a network address attack unit, a network service attack unit, a network protocol tampering unit, and a storage unit. Among them, the names of these units do not constitute a limitation on the unit itself in some cases. For example, the acquisition unit can also be described as "a unit that acquires the network configuration information of the target local area network as the target local area network configuration information".

[0090] The functions described above can be at least partially performed by one or more hardware logic components. For example, without limitation, exemplary types of hardware logic components that can be used include: field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on a chip (SOCs), complex programmable logic devices (CPLDs), and so on.

[0091] The above description is only some preferred embodiments of the present disclosure and an explanation of the technical principles applied. Those skilled in the art should understand that the scope of the invention involved in the embodiments of the present disclosure is not limited to the technical solutions formed by the specific combination of the above technical features, but should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the above inventive concept. For example, technical solutions formed by mutually replacing the above features with technical features (but not limited to) having similar functions disclosed in the embodiments of the present disclosure.

Claims

1. A network security testing method applied to an aviation fuel control system, comprising: Obtaining network configuration information of a target local area network as target local area network configuration information, wherein the system devices in the aviation fuel control system include an oil tank group control device, an operator device, a fuel supply control device, and a target server, and network communication is performed between the operator device, the oil tank group control device, the fuel supply control device, and the target server through a network communication device; Updating the local network address according to the target local area network configuration information to obtain an updated local network address, wherein the updated network address is under the target local area network and is the same as the network addresses of the oil tank group control device, the operator device, and the fuel supply control device; Performing a network address attack on the oil tank group control device and the operator device according to the updated local network address to obtain a network address attack result; Performing a network service attack on the switch included in the network communication device to obtain a network service attack result; Performing a network protocol tampering attack on the fuel supply control device to obtain a network protocol tampering attack result; Storing the network address attack result, the network service attack result, and the network protocol tampering attack result as network security test information.

2. The method according to claim 1, wherein The step of updating the local network address according to the target local area network configuration information to obtain an updated local network address includes: Parsing the target local area network configuration information to obtain target local area network segment information; Performing a network address scan on the target local area network segment represented by the target local area network segment information through a network address scanning tool to obtain the network address information of the oil tank group control device, the network address information of the operator device, and the network address information of the fuel supply control device; Obtaining local network configuration information, wherein the local network configuration information includes a local network address and a local subnet mask; Updating the local network address according to the network address information of the oil tank group control device, the network address information of the operator device, the network address information of the fuel supply control device, and the target local area network segment information to obtain an updated local network address.

3. The method according to claim 2, wherein The step of performing a network protocol tampering attack on the fuel supply control device to obtain a network protocol tampering attack result includes: Performing a port scan on the network address information of the fuel supply control device through a port scanning tool to determine the network ports of the fuel supply control device; Establishing a communication session with the fuel supply control device through a network protocol attack tool and the network ports of the fuel supply control device, wherein the established communication session uses a preset network communication protocol; Sending a preset tampering data packet to the fuel supply control device through the constructed communication session to receive data packet feedback information sent by the fuel supply control device, wherein the preset tampering data packet contains preset malicious instruction information; Determining the data packet feedback information as the network protocol tampering attack result.

4. The method according to claim 1, wherein, The step of storing the network address attack result, the network service attack result, and the network protocol tampering attack result as network security test information includes: Determine the network address attack result, the network service attack result, and the network protocol tampering attack result as network security test information; Perform encryption processing on the network security test information to obtain encrypted network security test information; Store the encrypted network security test information in a storage device.

5. A network security test device, comprising: An acquisition unit, configured to acquire network configuration information of a target local area network as target local area network configuration information. Among them, the system devices in the airport fuel supply automatic control simulation system include oil tank group control devices, operator devices, fuel supply control devices, and target servers. The operator devices, the oil tank group control devices, the fuel supply control devices, and the target servers perform network communication through network communication devices; An update unit, configured to update the local network address according to the target local area network configuration information to obtain an updated local network address. Among them, the updated network address is under the target local area network with the network addresses of the oil tank group control devices, the operator devices, and the fuel supply control devices; A network address attack unit, configured to perform a network address attack on the oil tank group control devices and the operator devices according to the updated local network address to obtain a network address attack result; A network service attack unit, configured to perform a network service attack on the switch included in the network communication device to obtain a network service attack result; A network protocol tampering unit, configured to perform a network protocol tampering attack on the fuel supply control device to obtain a network protocol tampering attack result; A storage unit, configured to store the network address attack result, the network service attack result, and the network protocol attack result as network security test information.

6. An electronic device, comprising: One or more processors; A storage device, on which one or more programs are stored; When the one or more programs are executed by the one or more processors, the one or more processors implement the method according to any one of claims 1 to 4.

7. A computer-readable medium having a computer program stored thereon, wherein, The computer program, when executed by a processor, implements the method according to any one of claims 1 to 4.