Network anti-attack performance evaluation method and device, computer equipment and storage medium
By simulating network attacks on a detailed simulated system and comparing pre- and post-attack metrics, the method addresses the limitations of traditional single-node evaluation, enhancing the accuracy and comprehensiveness of network resilience assessment and defense strategies.
Patent Information
- Application Number
- CN202510805993.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-17
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2045-06-17
AI Technical Summary
In the prior art, the network attack performance evaluation method only relies on a single node removal operation, and cannot comprehensively and accurately evaluate the network system's attack resistance ability, resulting in the evaluation results being incomplete and accurate enough.
By establishing a simulation network system of the target network system, multiple simulation indicator objects are determined, the first evaluation indicator set is obtained, the second evaluation indicator set is obtained after simulating the attack, and the index difference is calculated, the anti-attack performance score of the network system is determined, and the attack process is used to simulate the attack process, comprehensively consider the changes of multiple indicator objects before and after the attack.
It realizes a comprehensive and accurate evaluation of the network system in complex attack scenarios, breaks through the limitations of single-time node removal, improves the comprehensiveness and accuracy of network attack resistance performance evaluation, identifies system vulnerabilities and optimizes defense strategies.
Smart Images

Figure CN120321047A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security technology, and in particular, to a method, device, computer device and storage medium for evaluating the anti-attack performance of a network. Background Art
[0002] A network attack refers to an act of invading or destroying a target system through attack means (such as vulnerability exploitation, data tampering, service denial, etc.) to steal sensitive information, paralyze critical services or disrupt business continuity. The threat characteristics it constitutes are diverse and complex. With the intelligent and stealthy evolution of network attack technologies, traditional defense systems are difficult to comprehensively cope with unknown attack chains, exposing deficiencies in aspects such as abnormal traffic identification, service resilience maintenance, and rapid recovery capabilities. Therefore, it is necessary to conduct an anti-attack performance evaluation on the network system to reveal the blind spots of defense strategies, verify the behavioral consistency between the simulation environment and the real system in attack response, optimize the security architecture design, and ensure the continuous reliability of core services in an adversarial environment.
[0003] In related technologies, a static analysis method is generally used to evaluate the anti-attack ability of a network. For example, first, based on graph theory, the degree centrality or betweenness centrality of network nodes is calculated, and the core nodes with dense topological connections are selected as preset attack targets; then, the attack behavior is simulated through a single node removal operation, such as directly deleting the top 10% of the high-degree nodes; finally, the anti-attack performance of the network is evaluated based on the remaining network state after the attack. However, this method only relies on a single node removal operation and cannot evaluate the anti-attack performance of the entire network system, and the evaluation results are often not comprehensive and accurate enough. Summary of the Invention
[0004] Embodiments of this application propose a method, device, computer device and storage medium for evaluating the anti-attack performance of a network, which can improve the comprehensiveness and accuracy of the evaluation of network anti-attack performance.
[0005] To achieve the above object, the first aspect of the embodiments of this application proposes a method for evaluating the anti-attack performance of a network, the method including: Establish a simulation network system corresponding to the target network system, and determine multiple simulation index objects in the simulation network system; For multiple simulation index objects in the simulation network system, obtain a corresponding first evaluation index set; Perform a simulated attack on at least one simulation index object in the simulation network system to obtain an analyzed simulation network system after the simulated attack; Obtain a second evaluation index set corresponding to multiple simulation index objects in the analyzed simulation network system; Determine the anti - attack performance score of the target network system according to the index difference degree between the first evaluation index set and the second evaluation index set.
[0006] Correspondingly, a second aspect of the embodiments of the present application proposes a network anti - attack performance evaluation device, and the device includes: A building module, configured to build a simulation network system corresponding to the target network system and determine a plurality of simulation index objects in the simulation network system; A first obtaining module, configured to obtain a corresponding first evaluation index set for a plurality of simulation index objects in the simulation network system; An attack module, configured to perform a simulated attack on at least one simulation index object in the simulation network system to obtain an analyzed simulation network system after the simulated attack; A second obtaining module, configured to obtain a second evaluation index set corresponding to a plurality of simulation index objects in the analyzed simulation network system; A determining module, configured to determine the anti - attack performance score of the target network system according to the index difference degree between the first evaluation index set and the second evaluation index set.
[0007] In some embodiments, the first evaluation index set includes a first function index subset, a first performance index subset, and a first robustness index subset, the second evaluation index set includes a second function index subset, a second performance index subset, and a second robustness index subset, and the determining module is further configured to: For each simulation index object, respectively based on the first function index subset and the second function index subset, the first performance index subset and the second performance index subset, and the first robustness index subset and the second robustness index subset, determine the function difference value, the performance difference value, and the robustness difference value between each simulation index object corresponding to the simulation network system and the analyzed simulation network system; Sequentially based on the function difference value, the performance difference value, and the robustness difference value associated with each simulation index object, determine the anti - attack performance score of the target network system.
[0008] In some embodiments, the plurality of simulation index objects include the network topology structure, the server, and the application firewall corresponding to the application layer of the simulation network system, and the communication line and the router corresponding to the network layer of the simulation network system, and the determining module is further configured to: For the network topology structure in the simulation network system, obtain the degree distribution and clustering coefficient corresponding to the network topology structure in the dimension of functional indicators to obtain the corresponding first functional index subset, and the average shortest path length between any two network nodes in the dimension of performance indicators to obtain the corresponding first performance index subset, and the number of cascading failure nodes and network communication efficiency in the dimension of robustness indicators to obtain the corresponding first robustness index subset; Obtain the proportion of normal operation time of the server in the dimension of functional indicators to obtain the corresponding first functional index subset, and the number of transactions processed per unit time, system response time, and system load in the dimension of performance indicators to obtain the corresponding first performance index subset, and the usage rates of the central processing unit, memory, and hard disk in the dimension of robustness indicators to obtain the corresponding first robustness index subset; Obtain the attack detection rate, attack false alarm rate, and attack missed alarm rate of the application firewall in the dimension of functional indicators to obtain the corresponding first functional index subset, and the maximum concurrent connection number, maximum new connection rate, and maximum throughput in the dimension of performance indicators to obtain the corresponding first performance index subset, and the attack response index in the dimension of robustness indicators to obtain the corresponding first robustness index subset; Obtain the device connectivity of the communication line in the dimension of functional indicators to obtain the corresponding first functional index subset, and the network throughput in the dimension of performance indicators to obtain the corresponding first performance index subset, and the transmission error rate in the dimension of robustness indicators to obtain the corresponding first robustness index subset; Obtain the correct packet forwarding rate and path optimization index of the router in the dimension of functional indicators to obtain the corresponding first functional index subset, and the network throughput, routing table capacity, packet loss rate, and input / output delay time in the dimension of performance indicators to obtain the corresponding first performance index subset, and the system stability in the dimension of robustness indicators to obtain the corresponding first robustness index subset.
[0009] In some embodiments, the determining module is further configured to: For each simulation index object, input the corresponding first functional index subset and second functional index subset, the first performance index subset and second performance index subset, and the first robustness index subset and second robustness index subset into a preset algorithm mapping model to determine the corresponding algorithm type; Calculate the functional difference value, performance difference value, and robustness difference value between each simulation index object through the corresponding algorithm type.
[0010] In some embodiments, the network anti-attack performance evaluation device further includes a determining module, which is further configured to: Taking the simulation network system as the first root node, constructing first sub-nodes corresponding to multiple simulation index objects, and taking the simulation network system to be analyzed as the second root node, constructing second sub-nodes corresponding to the multiple simulation index objects, wherein each first sub-node is associated with a corresponding first functional index subset, a first performance index subset, and a first robustness index subset, and each second sub-node is associated with a corresponding second functional index subset, a second performance index subset, and a second robustness index subset; Based on the functional difference value, the performance difference value, and the robustness difference value between each simulation index object corresponding to the simulation network system and the simulation network system to be analyzed respectively as the difference connection edges between the first sub-node and the second sub-node corresponding to each simulation index object; Based on any of the first sub-nodes, the corresponding second sub-nodes, and the corresponding difference connection edges, perform global difference conduction to determine the anti-attack performance score of the target network system.
[0011] In some embodiments, the network anti-attack performance evaluation device further includes an identification module, which is used for: Obtain the attack traffic initiated against the simulation network system, and identify the attack type of the attack traffic through a variational autoencoder to obtain the target attack type; According to the target attack type, determine the functional difference weight, the performance difference weight, and the robustness difference weight corresponding to each simulation index object; Based on the functional difference weight, the performance difference weight, and the robustness difference weight respectively, adjust the functional difference value, the performance difference value, and the robustness difference value of each simulation index object to obtain the target functional difference value, the target performance difference value, and the target robustness difference value; Then the step of determining the anti-attack performance score of the target network system based on the functional difference value, the performance difference value, and the robustness difference value associated with each simulation index object in sequence includes: Based on the target functional difference value, the target performance difference value, and the target robustness difference value associated with each simulation index object in sequence, determine the anti-attack performance score of the target network system.
[0012] In some embodiments, the network anti-attack performance evaluation device further includes a comparison module, which is used for: Compare the anti-attack performance score with a preset performance evaluation standard to obtain a comparison result; Based on the comparison result, determine the target simulation index object to be adjusted and the adjustment scheme from the multiple simulation index objects of the simulation network system to be analyzed; According to the adjustment scheme, adjust the target simulation index object for the index object corresponding to the target network system.
[0013] Correspondingly, a third aspect of the embodiments of the present application proposes a computer device, which includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, it implements the network anti-attack performance evaluation method according to any one of the embodiments of the first aspect of the present application.
[0014] Correspondingly, a fourth aspect of the embodiments of the present application proposes a computer-readable storage medium, which stores a computer program, and when the computer program is executed by a processor, it implements the network anti-attack performance evaluation method according to any one of the embodiments of the first aspect of the present application.
[0015] In the embodiments of the present application, a simulation network system corresponding to the target network system is established, and multiple simulation index objects in the simulation network system are determined; for multiple simulation index objects in the simulation network system, a corresponding first evaluation index set is obtained; at least one simulation index object in the simulation network system is simulatedly attacked to obtain an analyzed simulation network system after the simulated attack; a second evaluation index set corresponding to multiple simulation index objects in the analyzed simulation network system is obtained; according to the index difference degree between the first evaluation index set and the second evaluation index set, the anti-attack performance score of the target network system is determined. In this way, it is possible to dynamically simulate the attack process, comprehensively consider the changes of multiple simulation index objects before and after the attack, quantify the behavior deviation of the network system in complex attack scenarios, break through the limitation of only relying on single-node removal, and realize the comprehensive evaluation of the dynamic defense ability, behavior consistency verification and recovery efficiency of the system under unknown attack chains, so as to more accurately and comprehensively evaluate the network anti-attack performance of the network system. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] Figure 1 is a schematic diagram of the architecture of the network anti-attack performance evaluation system provided by the embodiments of the present application; Figure 2 is a flowchart of the network anti-attack performance evaluation method provided by the embodiments of the present application; Figure 3 is a schematic diagram of the functional modules of the network anti-attack performance evaluation device provided by the embodiments of the present application; Figure 4 is a schematic diagram of the hardware structure of the computer device provided by the embodiments of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0017] In order to make the objectives, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0018] It should be noted that although the functional modules are divided in the schematic diagram of the device and the logical sequence is shown in the flowchart, in some cases, the steps shown or described can be executed in a different module division in the device or a different sequence in the flowchart. Terms such as "first" and "second" in the description, claims and the above-mentioned drawings are used to distinguish similar objects and do not necessarily have to be used to describe a specific order or sequence.
[0019] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which this application belongs. The terms used herein are only for the purpose of describing the embodiments of this application and are not intended to limit this application.
[0020] A network attack refers to an act of invading or destroying a target system through attack means (such as vulnerability exploitation, data tampering, service denial, etc.) to steal sensitive information, paralyze key services or disrupt business continuity. The threat characteristics it constitutes are diverse and complex. With the intelligent and stealthy evolution of network attack technologies, traditional defense systems are difficult to comprehensively cope with unknown attack chains, exposing deficiencies in aspects such as abnormal traffic identification, service resilience maintenance, and rapid recovery capabilities. Therefore, it is necessary to conduct anti-attack performance evaluation on network systems to reveal the blind spots of defense strategies, verify the behavioral consistency between the simulation environment and the real system in attack response, optimize the security architecture design, and ensure the continuous reliability of core services in an adversarial environment.
[0021] In related technologies, a static analysis method is generally used to evaluate the anti-attack ability of a network. For example, first, based on graph theory, the degree centrality or betweenness centrality of network nodes is calculated, and the core nodes with dense topological connections are selected as preset attack targets; then, the attack behavior is simulated through a single node removal operation, such as directly deleting the top 10% of the high-degree nodes; finally, the anti-attack performance of the network is evaluated based on the remaining network state after the attack. However, this method only relies on a single node removal operation and cannot evaluate the anti-attack performance of the entire network system, and the evaluation results are often not comprehensive and accurate enough.
[0022] Based on this, the embodiments of this application provide a method, device, computer device and storage medium for network anti-attack performance evaluation, which can improve the comprehensiveness and accuracy of network anti-attack performance evaluation.
[0023] The method, device, computer device and storage medium for network anti-attack performance evaluation provided by the embodiments of this application are specifically described through the following embodiments. First, the network anti-attack performance evaluation system in the embodiments of this application is described.
[0024] Please refer to Figure 1, in some embodiments, the embodiments of the present application provide a network anti - attack performance evaluation system, including a terminal 11 and a server - side 12.
[0025] Exemplarily, the terminal 11 can be a personal computer, a mobile device (such as a tablet computer, a smart phone, etc.). The terminal 11 can provide a user interface, enabling technicians to initiate simulation attack requests, detect the simulation process, and view the evaluation results of the network anti - attack performance.
[0026] Furthermore, the server - side 12 can be a high - performance computing server, a cloud computing cluster, etc. It can be used to run the core logic of the simulation network system, including relevant components of the application layer and the network layer, and process various index extraction and comparison calculations from before the attack to after the attack.
[0027] Furthermore, the terminal 11 sends instructions to the server - side 12 through a network connection, such as starting a new attack simulation or requesting the latest simulation result report. After receiving the instructions sent by the terminal 11, the server - side 12 can perform corresponding simulation tasks based on the preset simulation network system to be analyzed, compare the index data after the attack with the attack data before the attack, generate an anti - attack performance score, and return the processed result to the terminal 11 for display.
[0028] The network anti - attack performance evaluation method in the embodiments of the present application can be illustrated by the following embodiments.
[0029] It should be noted that in each specific embodiment of the present application, when it comes to performing relevant processing based on data related to the user's identity or characteristics, such as user information, user behavior data, user historical data, and user location information, the user's permission or consent will be obtained first. Moreover, the collection, use, and processing of these data will comply with relevant laws, regulations, and standards. In addition, when the embodiments of the present application need to obtain the user's sensitive personal information, the user's separate permission or separate consent will be obtained through methods such as pop - up windows or redirecting to a confirmation page. After clearly obtaining the user's separate permission or separate consent, the necessary user - related data for the normal operation of the embodiments of the present application will be obtained.
[0030] In the embodiments of the present application, a description will be made from the dimension of a network anti - attack performance evaluation device, and this network anti - attack performance evaluation device can be specifically integrated in a computer device. Refer to Figure 2 , Figure 2 is the step flow chart of the network anti - attack performance evaluation method provided by the embodiments of the present application. Taking the case where the network anti - attack performance evaluation device is specifically integrated in a terminal or a server as an example, when the processor on the terminal or the server executes the program instructions corresponding to the network anti - attack performance evaluation method, the specific process is as follows: Step 101: Establish a simulation network system corresponding to the target network system and determine multiple simulation metric objects in the simulation network system.
[0031] In some embodiments, to enable researchers to comprehensively and meticulously analyze and test the anti-attack performance of the network system without affecting the operation of real services, a simulation network system highly similar to the actual target network system can be created for network security attack simulation and evaluation on the simulation network system.
[0032] Among them, the target network system can be the actual network system to be evaluated in the real network environment, including the complete architectures of the application layer (such as servers, user behavior protocols, etc.) and the network layer (such as routers, switches, etc.), and it is the prototype object replicated by the network range (i.e., the simulation network system).
[0033] Among them, the simulation network system can be a digital mapping system constructed through virtualization technology on the network range platform, which is highly consistent with the target network system in structure and function. It can be composed of dynamically configurable simulation components such as the application layer (such as simulating network topology structures, Hypertext Transfer Protocol (HTTP) interaction behaviors) and the network layer (such as virtual router packet forwarding rules), and can accurately reproduce the protocol interaction logic and data transmission mechanism in the real network environment.
[0034] Among them, the simulation metric objects can be various parameters selected in the simulation network system for quantitatively evaluating the system performance.
[0035] Exemplarily, the topology structure, protocol interaction rules, hardware parameters, etc. of the target network system can be extracted through traffic mirroring and configuration capture. In the network range platform, a logical topology consistent with the target network system can be created using Kernel-based Virtual Machine (KVM) virtualization technology, application layer components and network layer components can be deployed, and finally adjustable parameters (such as dynamically increasing or decreasing the number of server nodes, simulating link bandwidth fluctuations) can be implanted to ensure that the simulation network system has the ability of elastic expansion.
[0036] In some embodiments, the simulation metric objects can be the network topology structure, servers, Intrusion Detection System (IDS), Web Application Firewall (WAF), application firewalls, etc. corresponding to the application layer of the simulation network system, as well as communication lines, layer-3 switches, routers, etc. corresponding to the network layer of the simulation network system.
[0037] Specifically, since network attacks usually prioritize damaging critical nodes (such as nodes with high centrality and large betweenness), the changes in their degree distribution and clustering coefficient directly reflect the structural resilience of the system. Therefore, the network topology structure can be used as the object of simulation indicators; servers and application firewalls, as the bearers of application-layer services and security boundaries, are the most sensitive to indicators such as detection rates in terms of attack response. Thus, servers and application firewalls are used as the objects of simulation indicators; while routers and communication lines, as the basic settings at the network layer, their performance determines the scope of attack propagation. For example, a routing table overflow can cause a network-wide paralysis. Therefore, routers and communication lines are used as the objects of simulation indicators. Thus, it is possible to focus on service availability and security protection capabilities after an attack at the application layer, and focus on the reliability of data transmission and the robustness of devices (such as the correct forwarding rate of routers, etc.) after an attack at the network layer, thereby improving the accuracy and comprehensiveness of network anti-attack performance evaluation.
[0038] Through the above methods, a simulation network system corresponding to the target network system can be established, and multiple simulation indicator objects therein can be determined, achieving a high degree of simulation of the real network environment, so as to facilitate subsequent comprehensive evaluation of the changes in the simulation network system before and after being attacked without affecting the actual business operation.
[0039] Step 102: For multiple simulation indicator objects in the simulation network system, obtain the corresponding first evaluation indicator set.
[0040] In some embodiments, in order to provide an original reference for subsequent dynamic difference analysis after attack simulation, the baseline data (the first evaluation indicator set) of each simulation indicator object in the simulation network system when not under attack can be systematically collected to establish an indicator baseline data to support the quantitative comparison of the system state changes before and after the attack, so as to accurately evaluate the anti-attack ability of the target network system.
[0041] Among them, the first evaluation indicator set can be the first function indicator set, the first performance indicator set, and the first robustness indicator set collected for each simulation indicator object in the application layer and the network layer under the baseline state of the simulation network system before the attack.
[0042] In some embodiments, each simulation metric object corresponds to a first evaluation metric set. That is to say, each simulation metric object corresponds to a first function index subset, a first performance index subset, and a first robustness index subset. Taking the simulation metric object as the network topology as an example, for the network topology, the degree distribution corresponding to the network topology in the functional metric dimension (i.e., the distribution of the number of connections of each node in the network topology, which can be expressed as the probability of the number of connections of each node) and the clustering coefficient (which can be used to represent the average clustering degree of the entire network topology) can be obtained to obtain the corresponding first function index subset, and the average shortest path length between any two network nodes in the performance metric dimension (which can be the average of the shortest path lengths between any two nodes in the network topology) can be obtained to obtain the corresponding first performance index subset, and the number of cascading failure nodes in the robustness metric dimension (which can be the number of other nodes that will fail subsequently when each node in the network topology is attacked and fails) and the network communication efficiency (which can be the ability of the remaining network to maintain a certain level of information exchange when some nodes or links in the network fail) can be obtained to obtain the corresponding first robustness index subset.
[0043] By obtaining the first evaluation metric sets corresponding to multiple simulation metric objects, a comprehensive and detailed quantitative analysis of the functions, performance, and robustness of the network system before being attacked can be realized. Thereby, not only is the baseline data provided for subsequent attack simulations, ensuring an accurate comparison of the changes before and after the attack, but also the initial state and potential vulnerabilities of the system can be effectively identified, thus providing solid data support for further optimizing the network security protection strategy and significantly improving the accuracy and reliability of the overall network security assessment.
[0044] In some embodiments, in order to provide comprehensive and fine-grained baseline data for the dynamic difference analysis after subsequent attack simulations, the functions, performance, and robustness metrics of each simulation metric object in the simulation network system before the attack can be collected through stratification (application layer, network layer) to construct a multi-dimensional baseline data set (the first evaluation metric set), thereby supporting the authenticity and accuracy of the evaluation of the resilience (attack resistance performance) of the network range simulation system. For example, step 102 may include: (102.1) For the network topology in the simulation network system, obtain the degree distribution and clustering coefficient corresponding to the network topology in the functional metric dimension to obtain the corresponding first function index subset, and the average shortest path length between any two network nodes in the performance metric dimension to obtain the corresponding first performance index subset, and the number of cascading failure nodes and the network communication efficiency in the robustness metric dimension to obtain the corresponding first robustness index subset; (102.2) Obtain the uptime ratio of the server in the dimension of functional metrics to get the corresponding first subset of functional indices, and the number of transactions processed per unit time, system response time, and system load in the dimension of performance metrics to get the corresponding first subset of performance indices, and the usage rates of the central processing unit, memory, and hard disk in the dimension of robustness metrics to get the corresponding first subset of robustness indices; (102.3) Obtain the attack detection rate, false alarm rate of attacks, and missed alarm rate of attacks of the application firewall in the dimension of functional metrics to get the corresponding first subset of functional indices, and the maximum concurrent connection number, maximum new connection rate, and maximum throughput in the dimension of performance metrics to get the corresponding first subset of performance indices, and the attack response index in the dimension of robustness metrics to get the corresponding first subset of robustness indices; (102.4) Obtain the device connectivity of the communication line in the dimension of functional metrics to get the corresponding first subset of functional indices, and the network throughput in the dimension of performance metrics to get the corresponding first subset of performance indices, and the transmission error rate in the dimension of robustness metrics to get the corresponding first subset of robustness indices; (102.5) Obtain the correct packet forwarding rate and path optimization index of the router in the dimension of functional metrics to get the corresponding first subset of functional indices, and the network throughput, routing table capacity, packet loss rate, and input / output delay time in the dimension of performance metrics to get the corresponding first subset of performance indices, and the system stability in the dimension of robustness metrics to get the corresponding first subset of robustness indices.
[0045] Among them, the application layer can be the layer in the network model facing users and upper-layer services, including simulation index objects such as network topology structure, servers, and application firewalls, and is used to simulate real business scenarios.
[0046] Among them, the network topology structure can be the connection relationship and layout model of nodes (such as servers, clients) in the simulation network system, and is used to reflect the communication paths and dependencies between nodes.
[0047] Among them, the degree distribution can be the distribution of the number of connections of each node in the network topology structure.
[0048] Among them, the clustering coefficient can be the ability of nodes in the network topology structure to form tight clusters.
[0049] Among them, the server can be a simulation device providing computing, storage, or application services, simulating the hardware resources (central processing unit / memory / hard disk) and service running status of a real server.
[0050] Among them, the application firewall can be a security device deployed at the application layer, simulating protection rules (such as HTTP request filtering, etc.) and attack response behaviors.
[0051] Among them, the network layer can be the layer responsible for packet routing and forwarding, including devices such as communication lines, routers, and layer-3 switches, used to simulate the transmission and switching functions of the physical network.
[0052] Among them, the communication line can be the transmission medium in the emulated network (such as optical fiber, twisted pair), simulating link connectivity and transmission characteristics (speed, bit error rate).
[0053] Among them, the router can be a network layer device, simulating packet forwarding, routing table management, and path optimization functions.
[0054] Among them, the functional metric dimension can be a set of metrics for measuring the core function integrity of the emulated metric object, such as the degree distribution of the network topology, the effectiveness of firewall rules, and so on.
[0055] Among them, the performance metric dimension can be a set of metrics for quantifying the service efficiency of the emulated metric object, such as the server transaction processing rate, network throughput.
[0056] Among them, the network node can be a terminal or intermediate device in the network topology (such as a server, router).
[0057] Among them, the average shortest path length can be the average of the shortest communication path lengths between any two nodes in the network topology structure, used to reflect the network communication efficiency.
[0058] Among them, the robustness metric dimension can be a set of metrics for evaluating the system's anti-destruction and recovery capabilities, such as the cascading failure impact range, link fault tolerance.
[0059] Among them, the number of cascading failure nodes can be the total number of nodes affected by the cascading failure caused by node attacks.
[0060] Among them, the network communication efficiency can be the overall network communication efficiency index calculated based on the path length and transmission quality.
[0061] Among them, the normal operation time ratio can be the proportion of time that the server can provide services normally within the statistical period.
[0062] Among them, the number of transactions processed per unit time can be the number of transaction requests that the server can process per second.
[0063] Among them, the system response time can be the time delay from when the server receives a request to when it returns a result.
[0064] Among them, the system load can be a comprehensive indicator of the current resource occupancy rate of the server (central processing unit / memory / hard disk).
[0065] Among them, the CPU usage rate can be the percentage of resource occupancy of the server's central processing unit (CPU).
[0066] Among them, the memory usage rate can be the percentage of resource occupancy of the server's memory.
[0067] Among them, the hard disk usage rate can be the percentage of resource occupancy of the server's storage.
[0068] Among them, the attack detection rate can be the proportion of the application firewall correctly identifying attack behaviors.
[0069] Among them, the attack false alarm rate can be the proportion of the application firewall misjudging normal traffic as attack traffic.
[0070] Among them, the attack missed alarm rate can be the proportion of the application firewall failing to identify attack behaviors.
[0071] Among them, the maximum concurrent connection number can be the maximum number of connections that the application firewall can maintain simultaneously.
[0072] Among them, the maximum new connection rate can be the upper limit of the number of new connections that the application firewall can establish per second.
[0073] Among them, the maximum throughput can be the maximum data transmission volume that the application firewall can process within a unit time, which can be measured by the data volume transmitted per second and is used to reflect the maximum network traffic that the application firewall can handle without losing data packets.
[0074] Among them, the attack response index can be a comprehensive score of the interception efficiency and response speed of the application firewall for attack behaviors. Specifically, the attack response index can include the detection time (the time required from the start of the attack to being detected by the application firewall), the blocking efficiency (the proportion of the application firewall successfully blocking the attack, that is, the ability to successfully identify and block the attack), the recovery time (the time required for the simulated network system to recover to normal operation from the impact of the attack), and the resource occupancy (the change situation of the application firewall's own resources, such as CPU usage rate, memory usage rate, etc. during the attack, which is used to reflect the stability of the application firewall under high pressure).
[0075] Among them, the device connectivity can be the physical connection status (connected / interrupted) of the communication line or network device.
[0076] Among them, the network throughput of the communication line can be the data volume successfully transmitted by the communication line within a unit time.
[0077] Among them, the transmission error rate can be the proportion of data errors occurring during the transmission process of the communication line.
[0078] Among them, the correct packet forwarding rate can be the proportion of the router correctly forwarding packets.
[0079] Among them, the path optimization index can be the efficiency score (such as minimizing latency) of the router in selecting the optimal path.
[0080] Among them, the network throughput of the router can be the total amount of effective data successfully transmitted through network devices such as the router per unit time (usually in seconds), and the unit can be Mbps (megabits per second) or Gbps (gigabits per second). The network throughput can be used to quantify the data transmission efficiency of network layer devices and reflect their performance under attack pressure.
[0081] Among them, the routing table capacity can be the maximum value of the routing entries that the router can store.
[0082] Among them, the packet loss rate can be the proportion of packets lost by the router during network transmission.
[0083] Among them, the input-output delay time can be the time difference between the router port receiving and forwarding a packet.
[0084] Among them, the system stability can be the proportion of the time that the router maintains normal operation under load or attack.
[0085] In some embodiments, for the convenience of understanding the above solution, an example is given for the process of obtaining the first evaluation index set corresponding to each simulation index object. It should be noted that the calculation method may vary in actual situations, and the specific values may also vary, and can be flexibly adjusted according to the actual situation.
[0086] Exemplarily, for the network topology structure in the simulation network system, in the dimension of functional indicators, when calculating the degree distribution, for example, the degree distribution corresponding to the network topology structure has 10 nodes, and the number of connections of each node is [3, 4, 2, 5, 3, 4, 2, 1, 3, 2] respectively. The degree distribution can be expressed as the frequency distribution of these values; when calculating the clustering coefficient, for each node in the network topology structure, calculate the connection proportion between its neighbor nodes. For example, if node A has three neighbors B, C, and D, and there are edges between BC, BD, and CD, then the clustering coefficient of node A is 1; otherwise, it is the corresponding connection proportion. In this way, the first functional index subset corresponding to the network topology structure can be obtained: Degree distribution: {3: 3 times, 4: 2 times, 2: 3 times, 5: 1 time, 1: 1 time}; Clustering coefficient: [0.67, 0.5, 0.67, 1.0, 0.67, 0.5, 0.67, 0.0, 0.67, 0.67].
[0087] Furthermore, for the performance metric dimension of the network topology structure, when calculating the average shortest path length, the shortest path length between any two nodes can be calculated and its average value can be obtained. For example, in the above network topology structure, the average shortest path length can be obtained by dividing the sum of the shortest path lengths between all node pairs by the number of node pairs. For example, the first subset of performance indices can be obtained: average shortest path length: 2.5 (assuming the calculation result).
[0088] Furthermore, for the robustness metric dimension of the network topology structure, when calculating the number of cascading failure nodes, it can be obtained by simulating the number of other affected nodes after critical nodes are attacked. For example, after removing the node with the highest degree, it is observed that 3 nodes lose all connections with other nodes; for network communication efficiency, it can be obtained by calculating the size of the remaining connected components. For example, the first subset of robustness indices obtained is: number of cascading failure nodes: 3; network communication efficiency: 0.8 (assuming the calculation result).
[0089] Exemplarily, for the functional metric dimension of the server, when calculating the proportion of normal running time, if the normal running time of the server in the past month (the time metric is determined according to the actual situation) is 720 hours and the total time is 744 hours, then the first subset of functional indices: proportion of normal running time: 720 / 744 = 96.77%.
[0090] Furthermore, for the performance metric dimension of the server, when calculating the number of transactions processed per unit time, the number of transactions processed per unit time (the specific unit time can be determined according to the actual situation) can be directly obtained. For example, the server can process 1000 transactions per second; when calculating the system response time, if the time required from sending a request to the system making a response is 50 milliseconds, then the system response time is 50; when calculating the system load, the current system load can be directly obtained as CPU usage rate 60% and memory usage rate 40%. Then, the first subset of performance indices corresponding to the server is: number of transactions processed per unit time: 1000 TPS; system response time: 50 ms; system load: CPU 60%, memory 40%.
[0091] Furthermore, for the robustness metric dimension of the server, the CPU usage rate can be 60%, the memory usage rate can be 40%, and the hard disk usage rate can be 50%. Then the first subset of robustness indices is: CPU usage rate: 60%; memory usage rate: 40%; hard disk usage rate: 50%.
[0092] Exemplarily, for the functional metric dimension of the application firewall, if the proportion of attacks correctly detected by the firewall is 95%, then the attack detection rate is 95%; if the proportion of normal traffic wrongly marked as an attack by the firewall is 1%, then the attack false alarm rate is 1%; if the proportion of attacks that actually occurred but were not detected by the firewall is 2%, then the attack missed alarm rate is 2%. Then the corresponding first sub - set of functional indices is: attack detection rate: 95%; attack false alarm rate: 1%; attack missed alarm rate: 2%.
[0093] Furthermore, for the performance metric dimension of the application firewall, if the maximum number of concurrent connections that the application firewall can handle simultaneously is 10,000, then the maximum concurrent connection number is 10,000; if the number of new connections that the application firewall can establish per unit time is 5,000 times per second, then the maximum new connection rate is 5,000 new connections per second; if the maximum data transmission volume that the application firewall can handle per unit time is 1 Gbps, then the maximum throughput is 1 Gbps. Then, the corresponding first sub - set of performance indices is: maximum concurrent connection number: 10,000; maximum new connection rate: 5,000 new connections / second; maximum throughput: 1 Gbps.
[0094] Furthermore, the value of the robustness metric dimension of the application firewall can be calculated using the attack response index. Specifically, the attack response index includes detection time, blocking efficiency, recovery time, and resource occupancy. For example, the detection time is 10 milliseconds, the blocking efficiency is 98%, the recovery time is 20 milliseconds, and the resource occupancy is CPU usage 30% and memory usage 20%. Then the corresponding first sub - set of robustness indices is: detection time: 10 ms; blocking efficiency: 98%; recovery time: 20 ms; resource occupancy: CPU 30%, memory 20%.
[0095] Exemplarily, for the functional metric dimension of the communication line, if the connectivity between all communication line devices is 100%, then the device connectivity is 100%. Then, the corresponding first sub - set of functional indices is: device connectivity: 100%.
[0096] Furthermore, for the performance metric dimension of the communication line, if the network throughput of the communication line is 10 Gbps, then the corresponding network throughput is 10 Gbps. Then, the corresponding first sub - set of performance indices is: network throughput: 10 Gbps.
[0097] Furthermore, for the robustness metric dimension of the communication line, if the proportion of transmission errors during communication is 0.01%, then the transmission error rate is 0.01%. Then, the corresponding first sub - set of robustness indices is: transmission error rate: 0.01%.
[0098] Exemplarily, for the functional metric dimension of a router, if the proportion of correctly forwarded data packets by the router is 99.9%, then the data packet forwarding accuracy rate is 99.9%; if the ability score of the router to select the optimal path is 85 points (out of 100), then the path optimization index is 85 points. Then, the corresponding first functional index subset is: data packet forwarding accuracy rate: 99.9%; path optimization index: 85.
[0099] Further, for the performance metric dimension of a router, if the network throughput of the router is 100 Gbps, then the network throughput is 100 Gbps; if the number of routing information that the router can store is 100,000 entries, then the routing table capacity is 100,000 entries; if the proportion of lost data packets during network transmission is 0.001%, then the packet loss rate is 0.001%; if the delay time for a data packet to pass through the router is 1 microsecond, then the input / output delay time is 1 microsecond. Then, the corresponding first performance index subset is: network throughput: 100 Gbps; routing table capacity: 100,000 entries; packet loss rate: 0.001%; input / output delay time: 1 μs.
[0100] Further, for the robustness metric dimension of a router, if the ability score of the router to maintain stable operation under high load or abnormal conditions is 90 points (out of 100), then the system stability is 90 points. Then, the corresponding first robustness index subset is: system stability: 90.
[0101] Through the above method, the functions, performances, and robustness of the components in the simulation network system before being attacked can be comprehensively evaluated, so as to better understand the anti-attack ability and overall health status of the entire system.
[0102] Step 103, perform a simulated attack on at least one simulated metric object in the simulation network system to obtain the simulation network system to be analyzed after the simulated attack.
[0103] In some embodiments, in order to provide a benchmark object in the attacked state for the subsequent quantitative analysis of the differences in metrics before and after the attack, by simulating real network attack behaviors (such as node removal, malicious traffic injection, etc.), attack loads are applied to specific simulated metric objects (such as application layer servers, network layer routers) in the simulation network system, and a system state image after the attack (i.e., the simulation network system to be analyzed) is dynamically generated to accurately capture dynamic change data such as functional anomalies, performance degradation, and robustness decline caused by the attack.
[0104] Among them, the simulation network system to be analyzed can be a dynamic simulation system instance formed after applying a simulated attack to at least one simulated metric object (such as an application layer server, a network topology node, a network layer router) in the simulation network system.
[0105] Exemplarily, various attack methods can be used to simulate attacks on the simulation network system. For example, 10,000 Transmission Control Protocol (TCP) half-connection requests with forged source Internet Protocol (IP) addresses can be sent to the application firewall within 10 seconds through range tools, triggering its maximum concurrent connection threshold (preset to 5,000); or, 10,000 HyperText Transfer Protocol (HTTP) requests per second can be initiated to the target server within 5 minutes through range traffic generation tools (the normal baseline is 500 requests per second) to simulate a botnet attack scenario; or, a common Distributed Denial of Service (DDoS) attack simulation can be deployed to test the network's anti-pressure ability, etc. It should be noted that the simulation attack method can be determined according to the actual situation, and the embodiments of the present application do not make specific limitations on this.
[0106] Through the above methods, it is convenient to effectively evaluate the response ability and recovery ability of the network when suffering from different types of attacks subsequently, identify the vulnerable points and potential risks of the system, and provide data support for optimizing the defense strategy.
[0107] Step 104, obtain a second evaluation index set corresponding to multiple simulation index objects in the simulation network system to be analyzed.
[0108] In some embodiments, for the quantitative evaluation of the anti-attack ability and behavior consistency of the simulation network system, and thus the quantitative evaluation of the anti-attack ability and behavior consistency of the target network system, the real-time data of the functions, performances, and robustness of each simulation index object (such as application layer servers and network layer routers) in the simulation network system to be analyzed after being attacked can be collected to form a second evaluation index set, so as to provide a complete data set in the attacked state for the dynamic difference analysis of the system state after the attack, and then be combined with the first evaluation index set for accurate evaluation.
[0109] Among them, the second evaluation index set can be a second function index set, a second performance index set, and a second robustness index set collected for each simulation index object in the application layer and the network layer after a simulated attack is applied to the simulation network system.
[0110] In some embodiments, each simulation metric object corresponds to a second evaluation metric set. That is to say, each simulation metric object corresponds to a second functional index subset, a second performance index subset, and a second robustness index subset. Taking the simulation metric object as the network topology structure as an example, for the network topology structure, the degree distribution corresponding to the functional metric dimension can be obtained (that is, the connection number distribution of each node in the network topology structure, which can be expressed as the probability of the connection number of each node), and the clustering coefficient (which can be used to represent the average clustering degree of the entire network topology structure), to obtain the corresponding second functional index subset, and the average shortest path length between any two network nodes in the performance metric dimension (which can be the average of the shortest path lengths between any two nodes in the network topology structure), to obtain the corresponding second performance index subset, and the number of cascading failure nodes in the robustness metric dimension (which can be the number of other nodes that will fail subsequently when each node in the network topology structure is attacked and fails), and the network communication efficiency (which can be the ability of the remaining network to maintain a certain level of information exchange when some nodes or links in the network fail), to obtain the corresponding second robustness index subset.
[0111] In some embodiments, obtaining the second evaluation metric sets corresponding to multiple simulation metric objects in the simulation network system to be analyzed is the same as the process of obtaining the corresponding first evaluation metric sets for multiple simulation metric objects in the simulation network system introduced above. The only difference is that the first evaluation metric set is obtained based on the data of the simulation network system before the attack, and the second evaluation metric set is obtained based on the data of the simulation network system to be analyzed after the attack. The embodiments of the present application will not elaborate on this one by one.
[0112] By obtaining the second evaluation metric sets corresponding to multiple simulation metric objects, a comprehensive and detailed quantitative analysis of the functions, performance, and robustness of the network system before being attacked can be realized. Thereby, not only benchmark data for subsequent attack simulations is provided, ensuring an accurate comparison of the changes before and after the attack, but also the initial state and potential vulnerability points of the system can be effectively identified, thus providing solid data support for further optimizing the network security protection strategy and significantly improving the accuracy and reliability of the overall network security assessment.
[0113] Step 105: Determine the anti-attack performance score of the target network system according to the metric difference degree between the first evaluation metric set and the second evaluation metric set.
[0114] In some embodiments, in order to systematically evaluate the resilience performance of the simulation network system under attack scenarios, the multi-dimensional differences (function, performance, robustness) between the first evaluation metric set and the second evaluation metric set before and after the attack can be calculated. Thus, the changes in the network system before and after being attacked can be quantified, revealing the actual attack resistance and recovery capabilities of the system.
[0115] Among them, the metric difference degree can be the dynamic deviation degree between the first evaluation metric set (benchmark data before the attack) and the second evaluation metric set (state data after the attack) calculated by mathematical methods (such as KL divergence, mean square error, etc.).
[0116] Among them, the attack resistance performance score can be a normalized quantization value generated based on the metric difference degree, or the attack resistance performance score can also be the total score obtained by fusing and calculating based on the metric difference degree.
[0117] In some embodiments, various statistical methods can be used to quantify the changes between the first evaluation metric set and the second evaluation metric set. For example, according to the characteristics of the data of each metric corresponding to each simulation metric object, the calculation method of the corresponding metric difference degree can be determined. For example, if the simulation metric object is the network topology structure, then for the degree distribution, based on the degree distribution of the simulation network system and the degree distribution of the simulation network system to be analyzed, the corresponding difference calculation method can be determined as the Kullback-Leibler (KL) divergence or the Jensen-Shannon (JS) divergence as the calculation method for calculating the difference in the degree distribution before and after the attack, and the corresponding result can be calculated.
[0118] Exemplarily, the calculation method may further include Mean Squared Error (MSE), Root Mean Squared Error (RMSE), Mean Absolute Error (MAE), Mean Absolute Percentage Error (MAPE), Symmetric Mean Absolute Percentage Error (SMAPE), Pearson correlation coefficient, Spearman correlation coefficient (Spearman rank correlation coefficient), Kendall correlation coefficient (Kendall rank correlation coefficient), Wasserstein distance, Total Variation, Kolmogorov-Smirnov (KS) distance, etc. The calculation methods for the difference degrees of each index before and after the attack of each index corresponding to each simulation index object may be the same or different, and the corresponding calculation method is specifically selected according to the actual situation.
[0119] In some embodiments, after calculating the difference degree of the indicators between the first evaluation indicator set and the second evaluation indicator set, the indicator threshold corresponding to each indicator may be obtained, and the indicator threshold is compared with the difference degree of the indicator to obtain a comparison result, and an indicator score value is obtained by assigning a value to the corresponding indicator according to the comparison result. Taking the degree distribution of one of the indicators of the simulation index object as an example, if the difference degree of the indicators before and after the attack calculated by the KL divergence method is 0.036 and the indicator threshold of the degree distribution is 0.05, and the difference degree of the indicators is less than the indicator threshold, then at this time, a value of 10 can be assigned, that is, the indicator score value corresponding to the degree distribution is 10. Further, the indicator score value can also be calculated by the distance between the difference degree of the indicator and the indicator threshold. When the gap is a positive gap, that is, when the indicator threshold is greater than the difference degree of the indicator, the greater the gap, the higher the indicator score value; when the gap is a negative gap, that is, when the indicator threshold is less than the difference degree of the indicator, the smaller the gap, the higher the indicator score value.
[0120] Furthermore, after obtaining the index score values of all indexes of each simulation index object, the index score values corresponding to all simulation index objects can be added together to obtain a total difference value as the anti-attack performance score of the target network system. For example, when the simulation index object is the network topology structure, the index score value of the corresponding degree distribution is 10, the index score value of the clustering coefficient is 5, the index score value of the average shortest path length between any two network nodes is 8, the index score value of the number of cascading failure nodes is 20, the index score value of the network communication efficiency is 15, and so on. By adding the index score values of multiple indexes such as network topology structure, server, application firewall, communication line, router, etc., the anti-attack performance score of the target network system can be obtained.
[0121] In some embodiments, the index weight of each index included in each simulation index object can be obtained, and the corresponding index score value can be adjusted by the index weight, and then the adjusted index score values of multiple indexes such as network topology structure, server, application firewall, communication line, router, etc. are added together to obtain the anti-attack performance score of the target network system. The index weight corresponding to each index can be set according to the actual situation. For example, the index weight corresponding to the degree distribution is set to 0.08, and the sum of all index weights of all indexes is 1.
[0122] Furthermore, by mapping the anti-attack performance score to a preset resilience level interval, the system resilience can be intuitively evaluated. For example: the score interval definition can be: 0 - 50 points is low resilience (severe function degradation, system paralysis, infrastructure reconstruction required); 51 - 150 points is medium resilience (partial performance decline, but core services are available, manual intervention for recovery required); greater than 150 points is high resilience (minimal difference before and after the attack, key functions intact, rapid recovery).
[0123] In the embodiments of the present application, a simulation network system corresponding to the target network system is established, and multiple simulation index objects in the simulation network system are determined; for the multiple simulation index objects in the simulation network system, a corresponding first evaluation index set is obtained; at least one simulation index object in the simulation network system is simulatedly attacked to obtain an analyzed simulation network system after the simulated attack; a second evaluation index set corresponding to the multiple simulation index objects in the analyzed simulation network system is obtained; according to the index difference degree between the first evaluation index set and the second evaluation index set, the anti-attack performance score of the target network system is determined. In this way, it is possible to dynamically simulate the attack process, comprehensively consider the changes of multiple simulation index objects before and after the attack, quantify the behavior deviation of the network system in complex attack scenarios, break through the limitation of only relying on single-node removal, and realize the comprehensive evaluation of the dynamic defense ability, behavior consistency verification and recovery efficiency of the system under unknown attack chains, so as to more accurately and comprehensively evaluate the network anti-attack performance of the network system.
[0124] In some embodiments, the first evaluation index set includes a first function index subset, a first performance index subset, and a first robustness index subset, and the second evaluation index set includes a second function index subset, a second performance index subset, and a second robustness index subset; in order to quantitatively evaluate the dynamic resilience performance of the network range simulation system under attack and identify key vulnerability points, by comparing the function, performance, and robustness index subsets of each simulation index object before and after the attack layer by layer, calculating multi-dimensional difference values and weighted fusion, an anti-attack performance score is generated to achieve an accurate and comprehensive network anti-attack performance evaluation of the target network system. For example, step 105 may include: (105.1) For each simulation index object, based on the first function index subset and the second function index subset, the first performance index subset and the second performance index subset, and the first robustness index subset and the second robustness index subset respectively, determine the function difference value, performance difference value, and robustness difference value between each simulation index object corresponding to the simulation network system and the analyzed simulation network system; (105.2) Based on the function difference value, performance difference value, and robustness difference value associated with each simulation index object in sequence, determine the anti-attack performance score of the target network system.
[0125] Among them, the first function index subset may be a data set of each index of each simulation index object in the function dimension before the simulation attack on the simulation network system. Taking the simulation index object as the network topology structure as an example, the corresponding first function index subset includes the values of degree distribution and clustering coefficient.
[0126] Among them, the first set of performance index subsets can be the data sets of each index of each simulation index object in the performance dimension before a simulation attack on the simulation network system. Taking the simulation index object as the network topology structure as an example, the corresponding first set of performance index subsets includes the numerical values of the average shortest path length between any two network nodes.
[0127] Among them, the first set of robustness index subsets can be the data sets of each index of each simulation index object in the robustness dimension before a simulation attack on the simulation network system. Taking the simulation index object as the network topology structure as an example, the corresponding first set of robustness index subsets includes the numerical values of the number of cascading failure nodes and the network communication efficiency.
[0128] Among them, the second set of function index subsets can be the data sets of each index of each simulation index object in the function dimension after a simulation attack on the simulation network system.
[0129] Among them, the second set of performance index subsets can be the data sets of each index of each simulation index object in the performance dimension after a simulation attack on the simulation network system.
[0130] Among them, the second set of robustness index subsets can be the data sets of each index of each simulation index object in the robustness dimension after a simulation attack on the simulation network system.
[0131] Among them, the function difference value can be the distribution difference of the function indexes before and after the attack calculated by the corresponding calculation method based on the first and second sets of function index subsets, and is used for the dynamic deviation degree of the indexes in the function dimension. Specifically, the corresponding calculation method can be the KL divergence, JS divergence or mean square error, etc., which is specifically determined according to the actual situation, and the present application does not make specific limitations.
[0132] Among them, the performance difference value can be the value calculated based on the first and second sets of performance index subsets for each index of each simulation index object before and after the attack.
[0133] Among them, the robustness difference value can be the value calculated based on the first and second sets of robustness index subsets for each index of each simulation index object before and after the attack.
[0134] Exemplarily, for each index in the first set of function index subsets and the second set of function index subsets, the corresponding numerical value can be obtained to calculate the function difference value of this index. Similarly, for each index in the first set of performance index subsets and the second set of performance index subsets, the corresponding numerical value can be obtained to calculate the performance difference value of this index, and for each index in the first set of robustness index subsets and the second set of robustness index subsets, the corresponding numerical value can be obtained to calculate the robustness difference value of this index.
[0135] In some embodiments, the changes in each index before and after an attack can be quantified by selecting an appropriate calculation method, and the anti-attack performance of the target network system can be comprehensively evaluated. For example, for an index of the probability distribution type such as degree distribution, KL divergence or JS divergence can be selected to calculate the difference before and after the attack; while for a numerical index such as the average shortest path length, methods such as MAE, MSE or RMSE can be selected to calculate the difference before and after the attack. In this way, basic data can be provided for subsequent scoring and comprehensive analysis, which helps to identify potential vulnerabilities and optimize defense strategies. Taking the degree distribution included in the functional index dimension of the simulation index object network topology structure as an example, the index difference degree of the degree distribution can be calculated by KL divergence. : ; Among them, is the network topology structure of the simulation network system before the attack, is the network topology structure of the simulation network system after the attack, is the degree distribution of the network topology structure before the attack, is the degree distribution of the network topology structure after the attack. The smaller it is, the more similar the degree distributions of the network topology structures before and after the attack are.
[0136] In some embodiments, for each simulation index object, the index difference degrees of multiple indexes it includes can be summarized to obtain corresponding functional difference values, performance difference values and robustness difference values. Taking the network topology structure as an example of the simulation index object, in the dimension of functional indexes, according to the first functional index subset and the second functional index subset, the index difference degree corresponding to the degree distribution and the index difference degree corresponding to the clustering coefficient can be calculated; in the dimension of performance indexes, according to the first functional index subset and the second functional index subset, the index difference degree of the average shortest path length between any two network nodes can be calculated; in the dimension of robustness indexes, according to the first robustness index subset and the second robustness index subset, the index difference degree of the number of cascading failure nodes and the index difference degree of network communication efficiency can be calculated, and the calculation method can be flexibly selected according to the actual situation. For example, the index difference degree corresponding to the degree distribution can be calculated by KL divergence.
[0137] In some embodiments, after calculating the metric difference degree between each metric (such as the degree distribution of the network topology structure) of each simulation metric object included in the first evaluation metric set and the second evaluation metric set, the metric threshold corresponding to each metric can be obtained, and the metric threshold is compared with the metric difference degree to obtain a comparison result, and the corresponding metric is assigned a value according to the comparison result to obtain a metric score value. Taking one of the metrics of the simulation metric object, i.e., the degree distribution, as an example, if the metric difference degree before and after the attack calculated by the KL divergence method is 0.036, and the metric threshold of the degree distribution is 0.05, and the metric difference degree is less than the metric threshold, then at this time, a value of 10 can be assigned, that is, the metric score value corresponding to the degree distribution is 10. Further, the metric score value can also be calculated by the distance between the metric difference degree and the metric threshold. When the gap is a positive gap, that is, when the metric threshold is greater than the metric difference degree, the greater the gap, the higher the metric score value; when the gap is a negative gap, that is, when the metric threshold is less than the metric difference degree, the smaller the gap, the higher the metric score value. It can be understood that the assignment rule can be set according to the actual situation.
[0138] Further, after obtaining the metric score values of all metrics of each simulation metric object in the functional metric dimension, performance metric dimension, and robustness metric dimension, the metric score values included can be added respectively in the functional metric dimension, performance metric dimension, and robustness metric dimension to obtain the functional difference value, performance difference value, and robustness difference value corresponding to the functional metric dimension, performance metric dimension, and robustness metric dimension. Taking the network topology structure as an example of the simulation metric object, if the metric score value of the degree distribution is 10 and the metric score value of the clustering coefficient is 12, then the functional difference value of the network topology structure is 22. Similarly, the performance difference value and the robustness difference value can be calculated, which will not be listed one by one here.
[0139] Further, the functional difference values, performance difference values, and robustness difference values corresponding to all simulation metric objects can be added together, and the sub-performance scores corresponding to each simulation metric object can be added together. By adding the multiple sub-performance scores corresponding to all simulation metric objects, the anti-attack performance score of the target network system can be obtained. For example, when the simulation metric object is the network topology structure, the corresponding functional difference value is 22, the performance difference value is 18, and the robustness difference value is 5. Then, the corresponding sub-performance score is 45. By adding the sub-performance scores corresponding to the network topology structure, server, application firewall, communication line, and router, the anti-attack performance score of the target network system can be obtained.
[0140] In some embodiments, instead of comprehensively calculating the anti-attack performance score, the score values of each metric can be directly output, so that technicians can directly analyze the changes in each metric (such as degree distribution, etc.) before and after being attacked based on the corresponding metric score values, thereby improving the accuracy and comprehensiveness of the evaluation.
[0141] Through the above methods, the changes in the target network system before and after being attacked can be comprehensively quantified, and potential vulnerabilities can be identified. In this way, not only the accuracy and comprehensiveness of the evaluation are improved, but also solid data support is provided for subsequent security improvements.
[0142] In some embodiments, to avoid evaluation biases caused by a single algorithm, through a preset algorithm mapping model, the data characteristics of each metric before and after the attack of each simulation metric object can be dynamically matched, and the optimal difference calculation algorithm type can be adaptively selected to improve the accuracy and adaptability of the difference value calculation. (105.1) may include: (105.1.1) For each simulation metric object, input the corresponding first functional index subset and second functional index subset, first performance index subset and second performance index subset, and first robustness index subset and second robustness index subset into the preset algorithm mapping model to determine the corresponding algorithm type; (105.1.2) Through the corresponding algorithm type, calculate the functional difference value, performance difference value, and robustness difference value between each simulation metric object.
[0143] Among them, the algorithm mapping model can be a decision model based on rules or machine learning, which can automatically match the applicable difference calculation algorithm type according to the type of input metric data (such as discrete distribution, continuous time series), statistical characteristics (such as normality, sparsity), and business scenarios (such as network topology difference analysis, server performance decay evaluation).
[0144] Among them, the algorithm type can refer to the specific mathematical methods used to calculate the metric differences before and after the attack, including but not limited to KL divergence, JS divergence, Wasserstein distance, mean squared error (MSE), mean absolute error (MAE), symmetric mean absolute percentage error (SMAPE), Pearson correlation coefficient, Spearman rank correlation coefficient, chi-square test, t-test, and other methods.
[0145] Furthermore, the metrics of each simulation metric object in the first functional index subset and the second functional index subset, the first performance index subset and the second performance index subset, and the first robustness index subset and the second robustness index subset can be input into the algorithm mapping model. The algorithm mapping model can identify the metric data characteristics of each metric and determine the algorithm types of multiple metrics corresponding to each simulation metric object. Taking the degree distribution as an example, the algorithm mapping model can map the corresponding JS divergence algorithm as the algorithm type and calculate the degree distribution before and after the attack through the JS divergence algorithm to obtain the corresponding metric difference degree. Furthermore, the method for calculating the corresponding functional difference value, performance difference value, and robustness difference value based on the metric difference degree corresponding to the metric has been elaborated above and will not be repeated here.
[0146] After that, the first functional index subset and the second calculate the functional difference value, performance difference value, and robustness difference value between each simulation metric object through the corresponding algorithm types.
[0147] Exemplarily, for discrete distribution metrics such as degree distribution and clustering coefficient included in the simulation metric object, the algorithm mapping model can be mapped to the KL divergence or JS divergence algorithm according to the metric data characteristics; for continuous numerical metrics such as the number of transactions processed per unit time and input / output delay time, the algorithm mapping model can be mapped to the mean square error or Pearson correlation coefficient according to the metric data characteristics; for count metrics such as the number of cascading failure nodes, the algorithm mapping model can be mapped to the chi-square test or Poisson distribution difference algorithm according to the metric data characteristics.
[0148] By automatically matching the algorithm type through the algorithm mapping model and selecting different algorithm types for different metrics, the evaluation deviation caused by a single algorithm can be avoided, effectively reducing the trial-and-error cost of manually selecting algorithms and greatly improving the calculation speed and calculation accuracy.
[0149] In some embodiments, in order to break through the limitations of traditional single-point difference analysis, the hierarchical graph structure (root node - child node) and difference connection edges of the pre-attack and post-attack simulation network systems can be constructed to achieve global difference conduction and aggregation across simulation metric objects, so as to quantify the coupling impact of the attack on the components of each layer of the system and accurately and comprehensively evaluate the overall anti-attack ability of the network system. Exemplarily, (105.2) may include: (105.2.1)Construct the first - level sub - nodes corresponding to multiple simulation - metric objects with the simulation network system as the first root node, and construct the second - level sub - nodes corresponding to multiple simulation - metric objects with the simulation network system to be analyzed as the second root node. Among them, each first - level sub - node is associated with a corresponding first - level functional - index subset, first - level performance - index subset, and first - level robustness - index subset, and each second - level sub - node is associated with a corresponding second - level functional - index subset, second - level performance - index subset, and second - level robustness - index subset; (105.2.2)Based on the functional - difference value, performance - difference value, and robustness - difference value between each simulation - metric object corresponding to the simulation network system and the simulation network system to be analyzed respectively, use them as the difference connection edges between the first - level sub - node and the second - level sub - node corresponding to each simulation - metric object; (105.2.3)Conduct global - difference conduction based on any first - level sub - node, the corresponding second - level sub - node, and the corresponding difference connection edge to determine the anti - attack performance score of the target network system.
[0150] Among them, the first root node can be a global entity node representing the original simulation network system, serving as an abstract carrier of the system state before the attack, and associating with the sub - nodes of all simulation - metric objects before the attack.
[0151] Among them, the first - level sub - node can be a simulation - metric object node subordinate to the first root node (such as servers at the application layer, network topology structures, etc.). Each first - level sub - node binds its first - level functional, performance, and robustness - index subsets before the attack, which are used to characterize the benchmark state of the object when it is not under attack.
[0152] Among them, the second root node can be a global entity node representing the simulation network system to be analyzed after being attacked, serving as an abstract carrier of the system state after the attack, and associating with the sub - nodes of all simulation - metric objects after the attack.
[0153] Among them, the second - level sub - node can be a simulation - metric object node subordinate to the second root node, corresponding one - to - one with the first - level sub - node, and binding its second - level functional, performance, and robustness - index subsets after the attack, which are used to characterize the dynamic state of the object after the attack.
[0154] Among them, the difference connection edge can be a directed edge connecting the first - level sub - node and the second - level sub - node of the same simulation - metric object, and the weight value is the difference value of the object in the dimensions of function, performance, and robustness, which characterizes the local influence intensity of the attack on the object.
[0155] In some embodiments, through hierarchical modeling techniques, the metric data of the simulation network system (the first root node) and the simulation network system to be analyzed (the second root node) can be transformed into a tree structure. Each root node contains multiple child nodes, and each child node corresponds to a simulation metric object (such as network topology, user behavior, server performance, etc.), and is associated with its function, performance, and robustness metric sets. Exemplarily, assume that the first root node contains the following child nodes (for illustration purposes only, the actual situation may contain more or fewer child nodes): Network topology structure: Function metrics: degree distribution, clustering coefficient; Performance metrics: average shortest path length; Robustness metrics: proportion of the largest connected component. Server: Function metrics: CPU usage threshold; Performance metrics: Transactions Per Second (TPS); Robustness metrics: load balancing recovery time. Further, the second root node constructs child nodes according to the same structure to form a symmetric tree model.
[0156] Further, the differential connection edges represent the difference values between the simulation network system and the simulation network system to be analyzed on the same simulation metric object. The specific calculation methods of the functional difference value, performance difference value, and robustness difference value have been elaborated above and will not be repeated here.
[0157] Further, through the differential connection edges of the tree structure, a weight assignment and conduction algorithm can be used to aggregate local differences into a global anti-attack score. For example, if the simulation metric objects include network topology structure and server, the functional difference value in the corresponding network topology differential edge is 0.35, the performance difference value is 1.7, and the robustness difference value is 0.2. The functional difference value in the server differential edge is 0.15, the performance difference value is 0.9, and the robustness difference value is 0.1. When performing global conduction, weight assignment can be carried out first. For example, the network topology weight is 40% (function 30%, performance 40%, robustness 30%), and the server weight is 30% (function 20%, performance 50%, robustness 30%). Aggregate calculations are performed to obtain the comprehensive network topology difference = 0.35×30% + 1.7×40% + 0.2×30% = 0.815, and the weighted contribution value = 0.815×40% = 0.326; the comprehensive server difference = 0.15×20% + 0.9×50% + 0.1×30% = 0.51, and the weighted contribution value = 0.51×30% = 0.153; finally, based on the sum of the contribution values corresponding to the network topology structure and the server, the total difference value = 0.326 + 0.153 = 0.479 is obtained. Based on the total difference value, an anti-attack performance score conversion is performed, and the anti-attack performance score = (1 - 0.479)×100% = 52.1 points, indicating that the anti-attack ability of the target network system is medium.
[0158] In the above way, based on the difference transfer model, the multi-level index differences can be dynamically aggregated into a single score, capturing the cross-layer chain effect caused by attacks, realizing accurate and efficient quantitative evaluation of the anti-attack performance, and significantly improving the systematicness and interpretability of the network anti-attack performance evaluation in complex attack scenarios, providing reliable technical support for the construction of a multi-level security defense system.
[0159] In some embodiments, in order to improve the pertinence and credibility of the scoring results, the weight ratios of the functional, performance, and robustness difference values of each simulation index object can be dynamically adjusted by identifying the specific type of attack traffic, so that the anti-attack performance score is more in line with the impact characteristics of the real attack scenario and the accuracy of the evaluation is improved. For example, before (105.2), that is, before "determining the anti-attack performance score of the target network system based on the functional difference value, performance difference value, and robustness difference value associated with each simulation index object in sequence", it further includes: (A.1) Obtain the attack traffic initiated against the simulation network system, and identify the attack type of the attack traffic through a variational autoencoder to obtain the target attack type; (A.2) Determine the functional difference weight, performance difference weight, and robustness difference weight corresponding to each simulation index object according to the target attack type; (A.3) Adjust the functional difference value, performance difference value, and robustness difference value of each simulation index object based on the functional difference weight, performance difference weight, and robustness difference weight respectively to obtain the target functional difference value, target performance difference value, and target robustness difference value; Then, determining the anti-attack performance score of the target network system based on the functional difference value, performance difference value, and robustness difference value associated with each simulation index object in sequence includes: Determining the anti-attack performance score of the target network system based on the target functional difference value, target performance difference value, and target robustness difference value associated with each simulation index object in sequence.
[0160] Among them, the attack traffic can be a simulated attack data stream initiated against the simulation network system, including attack payloads (such as malicious data packets, vulnerability exploitation codes) and behavior characteristics (such as request frequency, protocol type), and is used to reproduce real network attack behaviors.
[0161] Among them, the attack type can be a classification label of attack behaviors, such as Distributed Denial of Service (DDoS), Advanced Persistent Threat (APT), Structured Query Language (SQL) injection, port scanning, etc., which characterize the differences in the targets and means of attacks.
[0162] Among them, the target attack type can be the specific attack type determination result output after feature extraction and pattern recognition of the attack traffic through a Variational Autoencoder (VAE) (such as being recognized as a "DDoS attack").
[0163] Among them, the functional difference weight can be the influence weight of the functional difference value (such as network topology structure damage) set according to the target attack type in the anti-attack performance score. For example, APT attacks pay more attention to the damage of functional concealment, and the weight is higher than the performance difference.
[0164] Among them, the performance difference weight can be the proportion of the performance difference value (such as server response latency) set for the target attack type in the score. For example, DDoS attacks focus on performance degradation, and the performance difference weight is increased to 60%.
[0165] Among them, the robustness difference weight can be the importance coefficient of the robustness difference value (such as the cascading failure range) set according to the attack type in the score. For example, for physical layer damage attacks, the robustness weight is higher than function / performance.
[0166] Among them, the target functional difference value can be the weighted value obtained by adjusting the original functional difference value according to the functional difference weight, reflecting the contribution degree of functional damage under this attack type.
[0167] Among them, the target performance difference value can be the value obtained by adjusting the original performance difference value by the performance difference weight, characterizing the emphasis on performance degradation by the attack type.
[0168] Among them, the target robustness difference value can be the value obtained by correcting the original robustness difference value (such as the number of cascading failure nodes) according to the robustness difference weight, used to quantify the degree of damage of the attack type to the system resilience.
[0169] Exemplarily, a pre-trained variational autoencoder can be used to analyze the attack traffic in a simulated network system. For example, a distributed denial of service attack scenario is simulated. By using the variational autoencoder to perform feature extraction and pattern recognition on the attack traffic, it can be determined that the target attack type corresponding to this attack traffic is a DDoS attack. Alternatively, the attack type of the corresponding attack traffic can also be directly obtained from the data side.
[0170] Further, according to the identified target attack type (such as DDoS attack), the functional difference weight, performance difference weight, and robustness difference weight corresponding to each simulation metric object can be determined. For example, for a DDoS attack, since DDoS mainly affects the performance of the system and has little impact on the function, a relatively low functional difference weight can be set, such as 15%; since a DDoS attack aims to exhaust bandwidth or resources, the performance difference weight is relatively high, set to 50%; since a DDoS attack may cause problems such as cascading failures, a relatively high robustness difference weight can also be set, for example, it can be set to 35%.
[0171] Further, based on the determined functional difference weight, performance difference weight, and robustness difference weight above, the functional difference value, performance difference value, and robustness difference value of each simulation metric object can be adjusted. The specific formulas are as follows: Target functional difference value = Functional difference value * Functional difference weight; Target performance difference value = Performance difference value * Performance difference weight; Target robustness difference value = Robustness difference value * Robustness difference weight.
[0172] In some embodiments, the functional difference weight, performance difference weight, and robustness difference weight corresponding to each simulation metric object can be flexibly set according to the actual situation, and the present application does not make specific limitations on this.
[0173] Through the above method, it is possible to more accurately quantify the specific impacts of different types of attacks on each dimension of the target network system, making the evaluation results more in line with the characteristics of the actual attack scenario. In this way, not only the accuracy and reliability of the evaluation are improved, but also the misjudgment problem caused by traditional static weight allocation can be effectively avoided.
[0174] In some embodiments, in order to dynamically optimize the security and behavior authenticity of the target network, the anti-attack performance score can be compared with a preset standard to identify the weak links of the simulation network system and generate a targeted adjustment plan, and then identify the weak links of the target network system and generate a targeted adjustment plan to improve the defense ability of the target network system in complex attack scenarios and the consistency with the real system. For example, after step 105, that is, "According to the index difference degree between the first evaluation index set and the second evaluation index set, determine the anti-attack performance score of the target network system", it further includes: (B.1) Compare the anti-attack performance score with a preset performance evaluation standard to obtain a comparison result; (B.2) Based on the comparison result, determine the target simulation metric object to be adjusted and the adjustment plan from multiple simulation metric objects of the simulation network system to be analyzed; (B.3) According to the adjustment plan, adjust the index object corresponding to the target simulation metric object in the target network system.
[0175] Among them, the performance evaluation criteria can be a pre-set qualified threshold for anti-attack ability and a scoring rule.
[0176] Among them, the comparison result can be the conclusion after comparing the anti-attack performance score with the performance evaluation criteria.
[0177] Among them, the adjustment plan can be an improvement strategy for the target simulation index object, such as improving the server CPU / memory configuration, increasing network bandwidth, adding backup nodes to reduce the risk of cascading failures, updating the firewall detection rule library, adjusting the router routing table update frequency to reduce latency, and so on.
[0178] Exemplarily, if the pre-set performance evaluation criteria is that the anti-attack performance score is greater than or equal to 70 points: the system resilience is qualified; when the anti-attack performance score is between 60 and 70 points, high-weight indicators (such as network throughput) need to be optimized; if the attack performance score is less than 60 points, then the multi-index object needs to be adjusted comprehensively.
[0179] Exemplarily, first, the target simulation index object to be adjusted can be located from multiple simulation index objects. Specifically, for each index of the simulation index object (such as degree distribution, clustering coefficient, etc.), the index score values before and after the attack calculated in advance are compared with the corresponding score thresholds one by one. When the proportion of the index score values of each simulation index object that are less than the score threshold is greater than the pre-set proportion, the simulation index object is determined as the target simulation index object. Taking the simulation index object as the network topology structure as an example, if among the multiple indexes it contains, the index score value corresponding to the degree distribution is 3, the score threshold is 10; the index score value corresponding to the clustering coefficient is 12, the score threshold is 10; the index score value corresponding to the average shortest path length between any two network nodes is 15, the score threshold is 10; the index score value corresponding to the cascading failure node is 7, the score threshold is 5; the index score value corresponding to the network communication efficiency is 5, the score threshold is 10. Then the number of indexes with index score values less than the score threshold is 2, and the proportion of the index score values of the simulation index object that are less than the score threshold is 2 / 5 = 0.4. If the pre-set proportion is 0.2, then the network topology structure can be determined as the target simulation index object, and the network topology structure corresponding to the target network system is adjusted. For example, a Content Delivery Network (CDN) can be deployed to divert the attack traffic, and the bandwidth is expanded to 10 Gbps (gigabits per second). Further, the score threshold can be set according to the actual situation, and the embodiments of the present application do not impose too many restrictions on this.
[0180] In some implementations, a network repair table may be pre-stored, and the network repair table may record corresponding adjustment plans when problems occur with different simulation indicator objects (corresponding to indicator objects of the target network system), thereby improving the efficiency and accuracy of network services.
[0181] By comparing the anti-attack performance score with the preset performance evaluation criteria, the target simulation indicator objects (such as degree distribution, average shortest path length, and number of cascading failure nodes, etc.) that exceed the deviation tolerance in the simulated network system can be accurately identified. Based on these comparison results, targeted adjustment plans are formulated, such as enhancing topology redundancy design, optimizing routing algorithms, or improving detection mechanisms. Finally, specific adjustments are made to the target simulation indicator objects according to these adjustment plans, thereby significantly improving the system's anti-attack capability and recovery efficiency, ensuring that it can maintain high stability and security when attacked. In this way, not only the accuracy and comprehensiveness of the evaluation are improved, but also a scientific basis is provided for subsequent security reinforcement, enhancing the effectiveness of overall network security protection.
[0182] See also Figure 3 The embodiment of the present application further provides a network anti-attack performance evaluation device, which can implement the above-mentioned network anti-attack performance evaluation method. The network anti-attack performance evaluation device includes: An establishing module 31 is used to establish a simulated network system corresponding to the target network system and determine a plurality of simulation indicator objects in the simulated network system; A first acquisition module 32 is used to acquire a corresponding first evaluation indicator set for a plurality of simulation indicator objects in the simulation network system; An attack module 33 is used to perform a simulated attack on at least one simulation indicator object in the simulated network system to obtain a simulated network system to be analyzed after the simulated attack; A second acquisition module 34 is used to acquire a second evaluation index set corresponding to a plurality of simulation index objects in the simulation network system to be analyzed; The determination module 35 is used to determine the anti-attack performance score of the target network system according to the indicator difference between the first evaluation indicator set and the second evaluation indicator set.
[0183] The specific implementation of the network anti-attack performance evaluation device is basically the same as the specific implementation of the network anti-attack performance evaluation method described above, and will not be repeated here. On the premise of meeting the requirements of the embodiment of the present application, the network anti-attack performance evaluation device can also be provided with other functional modules to implement the network anti-attack performance evaluation method in the above embodiment.
[0184] The embodiment of the present application also provides a computer device, which includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the above-mentioned network anti-attack performance evaluation method is implemented. The computer device can be any intelligent terminal including a tablet computer, an in-vehicle computer, etc.
[0185] Please refer to Figure 4 , Figure 4 which schematically shows the hardware structure of the computer device according to another embodiment. The computer device includes: A processor 41, which can be implemented in ways such as a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided by the embodiments of the present application; A memory 42, which can be implemented in forms such as a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM). The memory 42 can store an operating system and other application programs. When implementing the technical solutions provided by the embodiments of this specification through software or firmware, the relevant program codes are stored in the memory 42 and are called by the processor 41 to execute the network anti-attack performance evaluation method of the embodiments of the present application; An input / output interface 43, which is used to implement information input and output; A communication interface 44, which is used to implement communication interaction between this device and other devices, and can implement communication through a wired method (such as USB, communication lines, etc.) or through a wireless method (such as a mobile network, WIFI, Bluetooth, etc.); A bus 45, which transmits information between various components of the device (such as the processor 41, the memory 42, the input / output interface 43, and the communication interface 44); Among them, the processor 41, the memory 42, the input / output interface 43, and the communication interface 44 are communicatively connected to each other inside the device through the bus 45.
[0186] The embodiment of the present application also provides a computer-readable storage medium, which stores a computer program, and when the computer program is executed by a processor, the above-mentioned network anti-attack performance evaluation method is implemented.
[0187] The memory, as a non-transitory computer-readable storage medium, can be used to store non-transitory software programs and non-transitory computer-executable programs. In addition, the memory may include high-speed random access memory, and may also include non-transitory memory, such as at least one magnetic disk storage device, a flash memory device, or other non-transitory solid-state storage devices. In some embodiments, the memory optionally includes a memory remotely located relative to the processor, and these remote memories can be connected to the processor through a network. Examples of the above network include but are not limited to the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0188] The embodiments described in the embodiments of the present application are for more clearly illustrating the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided by the embodiments of the present application. Those skilled in the art will know that with the evolution of technology and the emergence of new application scenarios, the technical solutions provided by the embodiments of the present application are equally applicable to similar technical problems.
[0189] Those skilled in the art can understand that the technical solutions shown in the figures do not constitute a limitation on the embodiments of the present application, and may include more or fewer steps than shown in the figures, or combine certain steps, or different steps.
[0190] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0191] Those of ordinary skill in the art can understand that all or some of the steps in the methods disclosed above, and the functional modules / units in the systems and devices, can be implemented as software, firmware, hardware, and appropriate combinations thereof.
[0192] The terms "first", "second", "third", "fourth", etc. (if any) in the specification of the present application and the above drawings are used to distinguish similar objects, and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present application described here can be implemented in an order other than those illustrated or described here. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products, or devices.
[0193] It should be understood that in this application, "at least one (item)" and "several" mean one or more, and "multiple" means two or more. "And / or" is used to describe the association relationship of associated objects, indicating that there can be three relationships. For example, "A and / or B" can mean: only A exists, only B exists, and both A and B exist at the same time. Among them, A and B can be singular or plural. The character " / " generally indicates that the associated objects before and after are in an "or" relationship. "At least one (one) of the following" or its similar expression refers to any combination of these items, including any combination of single item (one) or plural items (ones). For example, at least one (one) of a, b, or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, c can be single or multiple.
[0194] In several embodiments provided in this application, it should be understood that the disclosed systems and methods can be implemented in other ways. For example, the system embodiments described above are only illustrative. For example, the above division of units is only a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection between each other can be through some interfaces, and the indirect coupling or communication connection of devices or units can be in electrical, mechanical or other forms.
[0195] The units described above as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they can be located in one place, or they can be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0196] In addition, each functional unit in each embodiment of this application can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above integrated unit can be implemented in the form of hardware or in the form of a software functional unit.
[0197] When an integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes multiple instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods of various embodiments of this application. The aforementioned storage medium includes: various media that can store programs, such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs.
[0198] The preferred embodiments of the embodiments of this application have been described above with reference to the accompanying drawings. However, this does not limit the scope of the rights of the embodiments of this application. Any modifications, equivalent replacements, and improvements made by those skilled in the art without departing from the scope and essence of the embodiments of this application shall fall within the scope of the rights of the embodiments of this application.
Claims
1. A method for evaluating the network anti - attack performance, characterized in that, The method includes: establishing a simulation network system corresponding to the target network system, and determining a plurality of simulation index objects in the simulation network system; obtaining a corresponding first evaluation index set for the plurality of simulation index objects in the simulation network system; performing a simulated attack on at least one simulation index object in the simulation network system to obtain an analyzed simulation network system after the simulated attack; obtaining a corresponding second evaluation index set for the plurality of simulation index objects in the analyzed simulation network system; determining an anti-attack performance score of the target network system according to an index difference degree between the first evaluation index set and the second evaluation index set.
2. The network anti-attack performance evaluation method according to claim 1, characterized in that The first evaluation index set includes a first function index subset, a first performance index subset, and a first robustness index subset, and the second evaluation index set includes a second function index subset, a second performance index subset, and a second robustness index subset; The determining an anti-attack performance score of the target network system according to an index difference degree between the first evaluation index set and the second evaluation index set includes: for each simulation index object, respectively determining a function difference value, a performance difference value, and a robustness difference value between the simulation network system and each simulation index object corresponding to the analyzed simulation network system based on the first function index subset and the second function index subset, the first performance index subset and the second performance index subset, and the first robustness index subset and the second robustness index subset; sequentially determining an anti-attack performance score of the target network system based on the function difference value, the performance difference value, and the robustness difference value associated with each simulation index object.
3. The network anti-attack performance evaluation method according to claim 2, characterized in that The plurality of simulation index objects include a network topology structure, a server, and an application firewall corresponding to the application layer of the simulation network system, and a communication line and a router corresponding to the network layer of the simulation network system; The obtaining a corresponding first evaluation index set for the plurality of simulation index objects in the simulation network system includes: for the network topology structure in the simulation network system, obtaining a degree distribution and a clustering coefficient corresponding to the network topology structure in the dimension of function indexes to obtain a corresponding first function index subset, and obtaining an average shortest path length between any two network nodes in the dimension of performance indexes to obtain a corresponding first performance index subset, and obtaining the number of cascaded failure nodes and network communication efficiency in the dimension of robustness indexes to obtain a corresponding first robustness index subset; obtaining a normal operation time ratio of the server in the dimension of function indexes to obtain a corresponding first function index subset, and obtaining the number of transactions processed per unit time, system response time, and system load in the dimension of performance indexes to obtain a corresponding first performance index subset, and obtaining the usage rates of a central processing unit, a memory, and a hard disk in the dimension of robustness indexes to obtain a corresponding first robustness index subset; Obtain the attack detection rate, attack false alarm rate, and attack missed alarm rate of the application firewall in the dimension of functional indicators to obtain the corresponding first functional index subset, and the maximum concurrent connection number, maximum new connection rate, and maximum throughput in the dimension of performance indicators to obtain the corresponding first performance index subset, and the attack response index in the dimension of robustness indicators to obtain the corresponding first robustness index subset; Obtain the device connectivity of the communication line in the dimension of functional indicators to obtain the corresponding first functional index subset, and the network throughput in the dimension of performance indicators to obtain the corresponding first performance index subset, and the transmission error rate in the dimension of robustness indicators to obtain the corresponding first robustness index subset; Obtain the packet forwarding correctness rate and path optimization index of the router in the dimension of functional indicators to obtain the corresponding first functional index subset, and the network throughput, routing table capacity, packet loss rate, and input / output delay time in the dimension of performance indicators to obtain the corresponding first performance index subset, and the system stability in the dimension of robustness indicators to obtain the corresponding first robustness index subset.
4. The network anti-attack performance evaluation method according to claim 2, wherein For each simulation index object, respectively based on the first functional index subset and the second functional index subset, the first performance index subset and the second performance index subset, and the first robustness index subset and the second robustness index subset, determine the functional difference value, performance difference value, and robustness difference value between the simulation network system and each simulation index object of the simulation network system to be analyzed, including: For each simulation index object, input the corresponding first functional index subset and second functional index subset, first performance index subset and second performance index subset, and first robustness index subset and second robustness index subset into a preset algorithm mapping model to determine the corresponding algorithm type; Through the corresponding algorithm type, calculate the functional difference value, performance difference value, and robustness difference value between each simulation index object.
5. The network anti-attack performance evaluation method according to claim 2, characterized in that The method for determining the anti-attack performance score of the target network system based on the functional difference value, performance difference value, and robustness difference value associated with each simulation index object in sequence includes: By using the simulation network system as the first root node, construct the first sub-nodes corresponding to multiple simulation index objects, and use the simulation network system to be analyzed as the second root node to construct the second sub-nodes corresponding to the multiple simulation index objects, where each first sub-node is associated with the corresponding first functional index subset, first performance index subset, and first robustness index subset, and each second sub-node is associated with the corresponding second functional index subset, second performance index subset, and second robustness index subset; Based on the functional difference value, performance difference value, and robustness difference value between each simulation index object corresponding to the simulation network system and the simulation network system to be analyzed, respectively, as the difference connection edges between the first child node and the second child node corresponding to each simulation index object; Based on any of the first child nodes, the corresponding second child nodes, and the corresponding difference connection edges, perform global difference conduction to determine the anti-attack performance score of the target network system.
6. The network anti-attack performance evaluation method according to claim 2, characterized in that Before determining the anti-attack performance score of the target network system based on the functional difference value, the performance difference value, and the robustness difference value associated with each simulation index object in sequence, it further includes: Obtain the attack traffic initiated against the simulation network system, and identify the attack type of the attack traffic through a variational autoencoder to obtain the target attack type; According to the target attack type, determine the functional difference weight, performance difference weight, and robustness difference weight corresponding to each simulation index object; Based on the functional difference weight, the performance difference weight, and the robustness difference weight respectively, adjust the functional difference value, performance difference value, and robustness difference value of each simulation index object to obtain the target functional difference value, target performance difference value, and target robustness difference value; Then, determining the anti-attack performance score of the target network system based on the functional difference value, the performance difference value, and the robustness difference value associated with each simulation index object in sequence includes: Determine the anti-attack performance score of the target network system based on the target functional difference value, the target performance difference value, and the target robustness difference value associated with each simulation index object in sequence.
7. The network anti-attack performance evaluation method according to claim 1, wherein After determining the anti-attack performance score of the target network system according to the index difference degree between the first evaluation index set and the second evaluation index set, it further includes: Compare the anti-attack performance score with a preset performance evaluation criterion to obtain a comparison result; Based on the comparison result, determine the target simulation index object to be adjusted and the adjustment plan from multiple simulation index objects of the simulation network system to be analyzed; According to the adjustment plan, adjust the index object corresponding to the target simulation index object in the target network system.
8. A network anti-attack performance evaluation device, characterized in that The device includes: A establishment module, configured to establish a simulation network system corresponding to the target network system, and determine multiple simulation index objects in the simulation network system; A first acquisition module, configured to acquire a corresponding first evaluation index set for multiple simulation index objects in the simulation network system; An attack module, configured to perform a simulation attack on at least one simulation index object in the simulation network system to obtain the simulation network system to be analyzed after the simulation attack; A second acquisition module, configured to acquire a corresponding second evaluation index set for multiple simulation index objects in the simulation network system to be analyzed; A determination module, configured to determine the anti-attack performance score of the target network system according to the index difference degree between the first evaluation index set and the second evaluation index set.
9. A computer device, characterized in that, The computer device includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, it implements the network anti-attack performance evaluation method according to any one of claims 1 to 7.
10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, it implements the network anti-attack performance evaluation method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Network attack data set construction method and device, electronic equipment and storage medium
CN116074105A
Attack traffic generation method and device based on network target range and related equipment
CN118300834A
Power system attack and defense simulation method and equipment based on abstract topological structure
CN119026317A
Method and system for analyzing cybersecurity threats and improving defensive intelligence
US20220019674A1
Cited By
Simulation topology node evaluation method and device, computer equipment and storage medium
CN120768790A