Security assessment method and device for network target range and related equipment

By injecting simulated attack data flow into the network shooting range, the availability, integrity and service quality of the service system are evaluated, and the problem of insufficient accuracy of evaluation results in the prior art is solved, and more accurate security assessment and optimization guidance are achieved.

CN120358099AActive Publication Date: 2025-07-22CHINA MOBILE GROUP DESIGN INST +1
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510847431.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-24
Publication Date
2025-07-22
Estimated Expiration
2045-06-24

AI Technical Summary

Technical Problem

The accuracy of the security assessment results of existing network shooting ranges is mainly because the evaluation method focuses on technical indicators rather than actual business performance.

Method used

By injecting a first stream of data that simulates a variety of preset attack information into the service system, the service completion degree, including availability, integrity and quality of service indicators, is obtained based on these indicators to evaluate the security of the network shooting range.

Benefits of technology

It improves the accuracy of security assessment results, can provide more realistic feedback on the actual protection effect of the network shooting range, and provides business-level optimization guidance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120358099A_ABST
    Figure CN120358099A_ABST
Patent Text Reader

Abstract

The invention provides a security assessment method and device for a network target range and related equipment, and relates to the technical field of security, and the method comprises the steps: injecting a first data stream into a service system deployed in the network target range, the first data stream being obtained after expansion processing is carried out according to threat information and a second data stream, the second data stream is a corresponding data stream when the service system normally executes the target service, and the threat information comprises at least one type of preset attack information; obtaining a service completion degree of executing the target service by the service system based on the first data stream, wherein the service completion degree is used for representing a damage degree of the target service attacked based on preset attack information corresponding to the threat information; and performing security assessment on the network target range based on the service completion assessment. The performance of the service system when the service system is attacked is evaluated from the service level, and the limitation of the prior art is broken through; and the actual protection effect of the network target range can be fed back more truly and completely, so that the accuracy of a safety evaluation result is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of security technologies, and in particular, to a security assessment method, device, and related equipment for a network range. Background Art

[0002] The security assessment of a network range comprehensively examines a system by simulating real attack scenarios, and can discover potential security vulnerabilities in advance and verify the effectiveness of defense strategies. It is a core link to enhance network security protection capabilities and ensure the security of critical information infrastructure.

[0003] The existing security assessment solutions for network ranges generally evaluate according to a preset defense assessment framework and predetermined operation information of users on nodes in the network range. However, this method often focuses on technical indicators and only analyzes the target, resulting in poor accuracy of the assessment results. Summary of the Invention

[0004] Embodiments of this application provide a security assessment method, device, and related equipment for a network range to solve the problem of poor accuracy of security assessment results in existing technologies for network ranges.

[0005] To solve the above technical problems, this application is implemented as follows: In a first aspect, embodiments of this application provide a security assessment method for a network range. The method includes: Inject a first data stream into a business system deployed in a network range. The first data stream is obtained after being extended according to threat information and a second data stream. The second data stream is the data stream corresponding to the normal execution of a target service by the business system, and the threat information includes at least one type of preset attack information; Obtain the service completion degree of the business system for executing the target service based on the first data stream. The service completion degree is used to represent the damaged degree of the target service attacked based on the preset attack information corresponding to the threat information; Based on the service completion degree, perform a security assessment on the network range.

[0006] Optionally, the obtaining the service completion degree of the business system for executing the target service based on the first data stream includes: Traverse target nodes based on the first data stream to determine the availability index of the target service. The target nodes are the nodes associated with the target service, and the availability index is used to represent the success rate of executing the target service based on the first data stream; Determine the integrity index of the target service based on the frequency of data inconsistency occurring during the transmission of the first data stream from the first node to the second node, where the first node is the starting point of the target service in the target nodes, and the second node is the ending point of the target service in the target nodes; Determine the service quality index of the target service based on the frequency of service anomalies occurring during the transmission of the first data stream from the first node to the second node; Obtain the service completion degree based on the availability index, the integrity index, and the service quality index.

[0007] Optionally, the first data stream includes first attack data corresponding to each type of preset attack information, the first attack data includes first attack information and the second data stream, and the first attack information is any one of the preset attack information; determining the availability index of the target service based on traversing the target nodes according to the first data stream includes: For each piece of the first attack data, obtain the first defense result of the first attack data, where the first defense result includes the first status of each target node, and the first status is used to indicate whether the corresponding target node successfully defends against the first attack information; where, when there is at least one target node whose first status indicates that the corresponding target node successfully defends against the first attack information, the first defense result indicates that the business system successfully executes the target service, and when the first status of all target nodes indicates that the corresponding target node fails to successfully defend against the first attack information, the first defense result indicates that the business system fails to successfully execute the target service; Construct a threat defense matrix based on the first defense results corresponding to each type of preset attack information and the first attack data corresponding to each type of preset attack information; Determine the availability index of the target service according to the threat defense matrix.

[0008] Optionally, before injecting the first data stream into the business system deployed in the network range, the method further includes: Deploy the business system in the network model of the network range based on virtualization technology, and define the processing rules of the physical layer, the processing rules of the network layer, and the processing rules of the data stream layer in the network model. The network model includes the physical layer, the network layer, and the data stream layer. The physical layer is used to establish a physical connection channel between the target nodes, the network layer is used to connect the physical layer and the data stream layer, and the data stream layer is used to process data streams; Derive the second data stream according to the processing rules of the physical layer, the processing rules of the network layer, the processing rules of the data flow layer, and the target service.

[0009] Optionally, obtaining the service completion degree based on the availability index, the integrity index, and the service quality index includes: Determine weight information, where the weight information includes a first weight corresponding to the availability index, a second weight corresponding to the integrity index, and a third weight corresponding to the service quality index; Obtain the service completion degree according to the weight information, the availability index, the integrity index, and the service quality index.

[0010] Optionally, after obtaining the service completion degree based on the availability index, the integrity index, and the service quality index, it further includes: Determine the first contribution degree of each target node among the target nodes based on the availability index. The first contribution degree of the third node is proportional to the defense ability of the third node against the preset attack information; Determine the second contribution degree of each target node among the target nodes based on the integrity index. The second contribution degree of the third node is proportional to the integrity of the target service when the third node processes the target service; Determine the second contribution degree of each target node among the target nodes based on the service quality index. The third contribution degree of the third node is proportional to the service quality of the target service when the third node processes the target service; Wherein, the third node is any node among the target nodes.

[0011] In a second aspect, an embodiment of the present application provides a security evaluation device for a network range, and the device includes: An injection module, configured to inject a first data stream into a service system deployed in a network range. The first data stream is obtained after being extended according to threat information and a second data stream, and the second data stream is the data stream corresponding to the normal execution of the target service by the service system. The threat information includes at least one type of preset attack information; An acquisition module, configured to acquire the service completion degree of the service system for executing the target service based on the first data stream. The service completion degree is used to represent the damaged degree of the target service under the attack of the preset attack information corresponding to the threat information; An evaluation module, configured to perform a security evaluation on the network range based on the service completion degree.

[0012] In a third aspect, an embodiment of the present application provides an electronic device, including a transceiver and a processor, The processor is configured to inject a first data stream into a business system deployed in a network range. The first data stream is obtained after being extended based on threat information and a second data stream. The second data stream is the data stream corresponding to the normal execution of a target service by the business system, and the threat information includes at least one type of preset attack information. The transceiver is configured to obtain the service completion degree of the business system for executing the target service based on the first data stream. The service completion degree is used to represent the degree of damage to the target service caused by the preset attack information corresponding to the threat information. The processor is further configured to perform a security assessment of the network range based on the service completion degree evaluation.

[0013] In a fourth aspect, an embodiment of the present application provides an electronic device, including: a processor, a memory, and a program stored on the memory and executable on the processor. When the program is executed by the processor, the steps of the security assessment method of the network range as described in the first aspect are implemented.

[0014] In a fifth aspect, an embodiment of the present application provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the security assessment method of the network range as described in the first aspect are implemented.

[0015] In the embodiments of the present application, a first data stream is injected into a business system deployed in a network range to simulate attacks on the business system by various different types of preset attack information; the service completion degree of the business system for executing the target service based on the first data stream is obtained, and the performance of the business system when under attack is evaluated from the business level, breaking through the limitations of the prior art; a security assessment of the network range is performed based on the service completion degree evaluation from the business perspective, which can more truly and completely reflect the actual protection effect of the network range, thereby improving the accuracy of the security assessment result. Description of the Drawings

[0016] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings required for use in the embodiments or the description of the prior art. Obviously, the following drawings are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0017] Figure 1 is one of the flowcharts of a security assessment method of a network range provided by an embodiment of the present application; Figure 2 is another flowchart of a security assessment method of a network range provided by an embodiment of the present application; Figure 3 It is a schematic structural diagram of a security evaluation device for a network range provided by an embodiment of the present application; Figure 4 It is a schematic structural diagram of an electronic device provided by an embodiment of the present application. Detailed implementation manners

[0018] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application without creative efforts shall fall within the protection scope of the present application.

[0019] See Figure 1 , Figure 1 It is a flowchart of a security evaluation method for a network range provided by an embodiment of the present application. As Figure 1 shown, the method includes the following steps: Step 101: Inject a first data stream into a business system deployed in a network range. The first data stream is obtained after being extended according to threat information and a second data stream. The second data stream is the data stream corresponding to the normal execution of the target business by the business system. The threat information includes at least one type of preset attack information; In this step, the second data stream can be the legitimate data stream when the business system normally executes the target business (such as e-commerce payment business, including processes such as user login, product browsing, placing an order, and payment), and can include six-tuple elements (initiator network address, source network port, recipient network address, destination network address, communication protocol, permission credentials, etc.); the first data stream is obtained after being extended according to threat information and the second data stream. Among them, the threat information can include at least one type of preset attack information, and the preset attack information can be SQL injection, Cross-Site Scripting (XSS), Distributed Denial-of-Service (DDoS), and other types of attack information in the MITRE ATT&CK framework. The impact of real threats on the business is simulated through the first data stream.

[0020] Among them, the reachable path of the second data stream can be reused by the first data stream through the business data stream derivation algorithm, so that the first data stream (i.e., the attack stream) propagates along the real business path, such as user terminal → firewall → Web server → database. Thus, it is convenient to subsequently evaluate the defense performance of the network range and the first data stream carrying threat information.

[0021] Step 102: Obtain the business completion degree of the target business executed by the business system based on the first data stream. The business completion degree is used to represent the degree of damage to the target business caused by an attack corresponding to the threat information according to the preset attack information. In this step, a real business system is simulated through a network range, and the first data stream simulates various types of attacks, so as to evaluate the protection effect of different attack defense systems on the business system. Among them, both the business system and the defense system are deployed in the network range. The transmission process of the first data stream between target nodes is disassembled into a chain structure of "starting point → intermediate node → end point", and the abnormal frequency of the business system executing the target business based on the first data stream in each link is counted respectively, and finally aggregated into the business completion degree, so as to comprehensively evaluate the performance of the business system when under attack and improve the accuracy of the security evaluation result.

[0022] Compared with the evaluation methods focusing on detection efficiency and response efficiency in the related art, the evaluation method based on the business completion degree in this application is closer to the actual application, and can comprehensively evaluate the performance of the business system when under attack from three dimensions of business availability, data integrity and service quality.

[0023] Step 103: Perform a security evaluation on the network range based on the evaluation of the business completion degree.

[0024] In this step, performing a security evaluation on the network range based on the evaluation of the business completion degree realizes the innovation of the evaluation paradigm from a technology efficiency orientation to an actual business orientation, realizes the evaluation upgrade from "meeting technical standards" to "business availability", is closer to the real network security requirements, can more truly and completely reflect the actual protection effect of the network range, and provides accurate business-level guidance for the optimization of the defense system.

[0025] In the embodiment of this application, the first data stream is injected into the business system deployed in the network range to simulate the attack of various types of preset attack information on the business system; the business completion degree of the business system executing the target business based on the first data stream is obtained, and the performance of the business system when under attack is evaluated from the business level, breaking through the limitations of the prior art; performing a security evaluation on the network range based on the business completion degree evaluation from the business perspective can more truly and completely reflect the actual protection effect of the network range, thereby improving the accuracy of the security evaluation result.

[0026] Optionally, before the step 101: Inject the first data stream into the business system deployed in the network range, the method further includes: Deploy the business system in the network model of the network range based on virtualization technology, and define the processing rules for the physical layer, the network layer, and the data flow layer in the network model. The network model includes the physical layer, the network layer, and the data flow layer. The physical layer is used to establish physical connection channels between target nodes. The network layer is used to connect the physical layer and the data flow layer. The data flow layer is used to process data streams. Derive the second data stream according to the processing rules of the physical layer, the processing rules of the network layer, the processing rules of the data flow layer, and the target service.

[0027] In this embodiment, as Figure 2 shown, first, construct CyberBusiness. CyberBusiness is a complete simulation system that can simulate several business systems and user information. User information includes various common operations such as complete voice calls, website browsing, video calls, and online payments, so as to simulate real business operations. In addition, CyberBusiness also contains multiple "persons" with email accounts, work passwords, and bank deposits, enhancing the authenticity of the virtual environment.

[0028] Exemplarily, take "evaluating the defense effectiveness of the network range in the e-commerce payment business scenario" as an example. Set the evaluation scenario: According to the evaluation target, design or select a practical business scenario, including business types, business processes, data flows, etc., to ensure that the evaluation results are representative and practical. Design an e-commerce payment business scenario, including processes such as user login, product browsing, placing an order, and payment. Define the expected behaviors and abnormal behaviors (such as attack behaviors) of the normal business process.

[0029] Use virtualization technologies (such as Docker, VMware) to build a network range environment. Create virtual nodes in the network range, including: business nodes (such as Web servers, databases, user terminals), security nodes (such as firewalls, Web Application Firewalls (WAF), Intrusion Detection Systems (IDS)), network nodes (such as switches, routers), and configure the corresponding network topologies and security policies, and assign a unique identifier to each node ( DevId), the security domain to which it belongs (such as the demilitarized zone (DMZ), production network), and hardware resources (CPU / memory / network interface). Deploy a complete business system in the network model of the network range, including front-end applications, back-end services, databases, etc., to ensure that the business system can operate normally and simulate real business scenarios. And according to the business scenario, configure the corresponding business traffic, including normal traffic and abnormal traffic (such as simulated attack traffic), to simulate network activities in real business scenarios.

[0030] Among them, the network model includes the physical layer, network layer, and data flow layer. The formal description of the network model can be expressed by the following formula: DevInfo = (Devld, DevName, DevType, area) ; Among them, the basic information of the node can include the node number Devld , the node name DevName , the node type DevTpe , the network security domain where the node is located area . Among them, the node type can be divided into office equipment, business equipment, security equipment, and network equipment. The network security domain can be divided into the production network area, office network area, and DMZ area.

[0031] The formal description of the physical layer can be expressed by the following formula: Devlf=(If ld ,address,netmask) ; PhyConnectLayer=(Devld,Devlf,Peer Devld ,Peer Devlf ) ; Among them, Devlf represents the physical interface information of the node, If ld represents the physical interface number, address represents the network address of the interface, netmask represents the subnet mask of the interface. One PhyConnectLayer represents DevId and Peer Devld Between two nodes, through Devlf and Peer Devld physically connected.

[0032] The formal description of the network layer can be expressed by the following formula: NetworkLayer=(D addr ,genmask, gateway addr , Devlf) ; Among them, each physical interface has a corresponding network address, and nodes communicate through network addresses. Each NetworkLayer unit represents a network layer processing rule. When the data stream with the destination address of D' addr passes through this node, it will D' addr be operated with genmask . If the operation result is equal to D addr , the next-hop address of the data stream is the gateway address gatewayaddr , and the data stream is transmitted through the Devlf wide physical interface of this node.

[0033] The formal description of the data stream layer can be expressed by the following formula: DataFlowLayer=(Type, Pre DataFlow , New DataFlow ) ; Among them, Type represents that the processing method for DataFlow can take values of Trans , accept , deny . When the value is Trans , it means that the data stream value is converted from Pre DataFlow to the corresponding value of New DataFlow . In the threat defense model, Type will also be extended.

[0034] In addition, the formal description of the system environment layer can be expressed by the following formula: ServiceLayer=(service, port, protocol, E ser ,P(U)) ; The system environment layer represents the application service information provided by the node. Each ServiceLayer represents an application service provided by the node and the corresponding permissions. por represents the port number occupied by the service. protocol represents the communication protocol used by the service. E ser represents the operating environment corresponding to the service. P(U) represents E ser the service permissions provided.

[0035] The physical layer is at the bottom layer of the network model. The physical layer is used to establish the physical interface connection relationship between nodes, such as "server eth0 interface → firewall ge0 / 1 interface", to form a physical connection channel. The transfer of data flow between physical interfaces only involves the change of physical location and does not involve the change of the data flow state. After receiving the information of the physical interface specified by the network layer DevIf it enters the physical layer processing rule matching process, and queries the DevIf peer device Peer DevId and the peer physical interface Peer DevIf through the node physical connection information, and transfers the current data flow to the peer node. After the peer device Peer DevIf receives the data flow through the physical interface, it immediately performs logical processing on the data flow at the current node.

[0036] The network layer determines the data flow forwarding logic (such as forwarding to the firewall when the destination address matches 10.0.0.0 / 24) by configuring routing rules (subnet mask, gateway), thus connecting the physical layer and the data flow layer. The network layer is responsible for receiving the data flow processed by the data flow layer upwards, querying the network layer rules of the current node, calculating the D addr operation with the subnet mask of the current data flow, querying the corresponding next-hop network address and the specified node physical interface DevIf and passing the information to the physical layer interface for processing.

[0037] The data flow layer is the top layer of the network model, which formulates traffic processing policies (allow / block / transform), such as "the firewall performs NAT transformation on HTTP / HTTPS traffic on ports 80 / 443" "WAF intercepts requests with SQL injection characteristics", etc. When the rule Type is Trans it transforms the data flow that matches the specified six-tuple state, modifies it to a new six-tuple state, and then passes the new data flow state DataFlow' to the network layer for processing. The formal description of the processing process is as follows: DataFlow→DataFlow'(S' addr ,S' sport , D' addr , D' aport , protocol', P(U)'),Type = Trans .

[0038] In this way, based on the processing rules defined for the physical layer, network layer, and data flow layer, all business device nodes and office device nodes in the system are regarded as the source addresses of the data flow, with all business device nodes as the destination nodes and the service ports of the system environment layer as the destination ports, forming an initial DataFlow . Then, based on the node reachability judgment algorithm, the reachability of DataFlow is deduced, and the data flow path carrying the target business behavior in the business system, that is, the second data flow, can be obtained. Exemplarily, after expansion processing according to the threat information and the second data flow, the attack vector can be combined into the second data flow to obtain the first data flow. The first data flow is forwarded through various network devices inside the business system, and the business service is attacked using the same path as the second data flow. When there is a vulnerability in the service, the attacker can succeed in the attack and thus elevate privileges, obtain information, etc.

[0039] The formal description of the first data flow is as follows: AtackFlow=(S addr ,S sport ,D addr ,D dport ,protocol,t, P(U); Among them, AtackFlow is the first data flow, which is an expansion of the second data flow DataFlow . S addr represents the originating network address of the data flow; S sport represents the source port of the data flow; D addr represents the corresponding target network address in the data flow; D dport represents the corresponding target service port in the data flow; protocol represents the protocol used by the data flow; t represents the threat classification corresponding to the attack vector in the attack flow, P(U) represents the privilege credentials carried by the data flow.

[0040] Among them, the second data flow DataFlow is expressed as: DataFlow = ( S addr ,S sport ,D addr ,D dport ,protocal, P(U) ).

[0041] Optionally, step 102, obtaining the business completion degree of the target business executed by the business system based on the first data stream, includes: Traversing target nodes based on the first data stream to determine the availability metric of the target business, where the target nodes are the nodes associated with the target business, and the availability metric is used to represent the success rate of executing the target business based on the first data stream; Determining the integrity metric of the target business based on the frequency of data inconsistency during the transmission of the first data stream from a first node to a second node, where the integrity metric is used to represent the probability that the data remains consistent during the transmission of the first data stream from the first node to the second node, the first node is the starting point of the target business among the target nodes, and the second node is the ending point of the target business among the target nodes; Determining the service quality metric of the target business based on the frequency of service exceptions during the transmission of the first data stream from the first node to the second node; Obtaining the business completion degree based on the availability metric, the integrity metric, and the service quality metric.

[0042] In this embodiment, the target nodes may include all key nodes involved in the target business (such as user terminals, Web servers, databases, etc.), constituting the physical / logical path of business execution (such as user terminal → payment gateway → database). The transmission process of the first data stream between the target nodes is disassembled into a chain structure of "starting point → intermediate node → ending point", and the exception frequencies of each link are respectively counted. Finally, the availability metric, the integrity metric, and the service quality metric are aggregated to obtain the business completion degree, which can comprehensively evaluate the performance of the business system under attack from three dimensions: business availability, data integrity, and service quality.

[0043] Among them, the availability metric can be expressed as S ServiceAvailability , that is, the defense effectiveness against business availability; the integrity metric can be expressed as S DataIntegrity , that is, the defense effectiveness against data integrity; the service quality metric can be expressed as S ServiceQuality , that is, the defense effectiveness against service quality. The business completion degree data before and after the attack simulation can be compared to analyze the effect of the defense device on business protection; according to the performance of the defense device and the change of the business completion degree, the defense effectiveness of the network range can be comprehensively evaluated.

[0044] In an implementation manner, traversing target nodes based on the first data stream to determine the availability metric of the target business can be specifically referred to the following description: Optionally, the first data stream includes first attack data corresponding to each type of preset attack information. The first attack data includes first attack information and the second data stream, and the first attack information is any one of the preset attack information. Determining the availability metric of the target service based on traversing the target nodes in the first data stream includes: For each piece of the first attack data, obtain a first defense result of the first attack data. The first defense result includes a first status of each target node, and the first status is used to indicate whether the corresponding target node successfully defends against the first attack information. Wherein, when there is at least one target node whose first status indicates that the corresponding target node successfully defends against the first attack information, the first defense result indicates that the service system successfully executes the target service; when the first status of all target nodes indicates that the corresponding target node does not successfully defend against the first attack information, the first defense result indicates that the service system does not successfully execute the target service; Construct a threat defense matrix based on the first defense results corresponding to each type of preset attack information and the first attack data corresponding to each type of preset attack information; Determine the availability metric of the target service according to the threat defense matrix.

[0045] Wherein, in the first data stream, that is AtackFlow in the data stream path, traverse the security functions of each target node. For each piece of the first attack data, obtain the first defense result of the first attack data. The first defense result can be expressed as r i : ; r i being 1 indicates that the i-th target node successfully defends against the first attack information, that is, there is a defense mapping relationship for the i-th target node; r i being 0 indicates that the i-th target node does not successfully defend against the first attack information, that is, there is no defense mapping relationship for the i-th target node.

[0046] Then, construct a threat defense matrix based on the first defense results corresponding to each type of preset attack information and the first attack data corresponding to each type of preset attack information; determine the availability metric of the target service according to the threat defense matrix. In this way, the working state of the defense system is abstracted into one or several groups of quantifiable availability metrics, and the availability metrics are used to intuitively reflect the defense effectiveness of the defense system, improving the accuracy of the evaluation results.

[0047] Wherein, the total defense effectiveness of the defense system can be expressed as S total : ; The optimal defense efficiency goal of the defense system is that all AttackFlow can be successfully defended by security devices, that is, the defense system targets all AttackFlow r i (0 < i < count( AttackFlow ) takes a value of 1. By calculating the proportion of the number of r i = 1 in n, the defense efficiency provided by the defense system is obtained S total , where n is the AttackFlow total number.

[0048] Exemplarily, based on the first data stream traversing the target node, by counting the AttackFlow proportion of r i = 1 in it, the availability metric of the target service can be determined. The following formula can be referred to: ; Among them, S ServiceAvailability is the availability metric, n0 is the AttackFlow total number, and the number of n0 is determined according to the type of preset attack information ( ThreatClass ).

[0049] Exemplarily, based on the frequency of data inconsistency during the transmission of the first data stream from the first node to the second node, the integrity metric of the target service can be determined. The following formula can be referred to: ; Among them, S DataIntegrity is the integrity metric. By counting the AttackFlow proportion of those that satisfy S addr ∈ eareax,D addr ∈ eareay and r i = 1, the defense efficiency of the defense system for the area between areax →> areay can be calculated, that is, the integrity metric of the target service can be determined, and Sareax - areay can discover the weak points of inter - area threat defense.

[0050] Exemplarily, based on the frequency of service anomalies during the transmission of the first data stream from the first node to the second node, the service quality metric of the target service can be determined. The following formula can be referred to: ; Among them, represents S ServiceQualityThat is, the quality of service indicator is determined by counting the abnormal event P(U x ) during the transmission of the attack flow from the "first node → second node".

[0051] In this way, the availability indicator from the business perspective S ServiceAvailability , the integrity indicator S DataIntegrity and the quality of service indicator S ServiceQuality perform multi-dimensional security assessment on the network range, which can more truly and comprehensively reflect the actual protection effect of the network range, thus improving the accuracy of the security assessment results.

[0052] Optionally, obtaining the business completion degree based on the availability indicator, the integrity indicator, and the quality of service indicator includes: Determine the weight information, where the weight information includes the first weight corresponding to the availability indicator, the second weight corresponding to the integrity indicator, and the third weight corresponding to the quality of service indicator; Obtain the business completion degree according to the weight information, the availability indicator, the integrity indicator, and the quality of service indicator.

[0053] In this embodiment, weights can be assigned to the three indicators according to the business priority (for example, in the financial business, the integrity weight is 40%, the availability is 30%, and the quality of service is 30%), and the comprehensive business completion degree is generated through linear combination: business completion degree = α·availability indicator + β·integrity indicator + γ·quality of service indicator (α + β + γ = 1, and the weights can be dynamically adjusted). α is the first weight, β is the second weight, and γ is the third weight. In this way, inject the first data stream into the business system deployed in the network range, simulate the attacks of various different types of preset attack information on the business system; obtain the business completion degree of the business system executing the target business based on the first data stream, evaluate the performance of the business system when being attacked from the business level, breaking through the limitations of the prior art; perform multi-dimensional security assessment on the network range based on the availability indicator, integrity indicator, and quality of service indicator from the business perspective, which can more truly and comprehensively reflect the actual protection effect of the network range, thus improving the accuracy of the security assessment results.

[0054] Optionally, after obtaining the business completion degree based on the availability indicator, the integrity indicator, and the quality of service indicator, it further includes: Determine the first contribution degree of each target node in each target node based on the availability indicator. The first contribution degree of the third node is proportional to the defense ability of the third node against the preset attack information; Determine the second contribution degree of each target node among the target nodes based on the integrity index, and the second contribution degree of the third node is proportional to the integrity of the target service when the third node processes the target service; Determine the second contribution degree of each target node among the target nodes based on the service quality index, and the third contribution degree of the third node is proportional to the service quality of the target service when the third node processes the target service; Wherein, the third node is any node among the target nodes.

[0055] In this embodiment, based on three types of indicators: availability, integrity, and service quality, the defense capability contribution degree (first contribution degree), data protection contribution degree (second contribution degree), and performance guarantee contribution degree (third contribution degree) of the nodes are respectively defined, forming a three-dimensional evaluation system covering defense effectiveness, data security, and service stability, avoiding the limitations of a single indicator. Moreover, through the proportional relationship between the contribution degree and the node defense capability and business processing quality, the nodes that have the greatest impact on business damage can be quickly identified.

[0056] Among the first contribution degree, the second contribution degree, and the third contribution degree, the calculation formula for any one of the contribution degrees is as follows: ; The threat defense matrix only retains SecDev the defense results, and then recalculates the system defense effectiveness S include (SecDev) , by calculating S include (SecDev) and S toial the ratio of SecDev to calculate the contribution degree Contribution SecDev of the node. By calculating the contribution degree of the security device node, the importance of the security device node can be ranked.

[0057] For example, if the target node Xi has n threats and the target node Xi + 1 has m threats, a total of z AttackFlow are generated. Based on the first defense result corresponding to each type of preset attack information and the first attack data corresponding to each type of preset attack information, a threat defense matrix is constructed as follows: ; For the effectiveness evaluation index results of the defense system application example, as shown in the following table:

[0058] Combined with business availability, data integrity, and service quality, the comprehensive effectiveness score is calculated through the weighted average method to provide a quantitative comprehensive effectiveness assessment, providing a scientific basis for the optimization of the defense system. The accuracy of the assessment results is improved.

[0059] See Figure 3 , Figure 3 FIG. is a schematic structural diagram of a security assessment device for a network range provided by an embodiment of the present application. As Figure 3 shown, the security assessment device 300 for the network range includes: An injection module 301, configured to inject a first data stream into a business system deployed in the network range. The first data stream is obtained after being extended based on threat information and a second data stream. The second data stream is the data stream corresponding to the normal execution of the target business by the business system, and the threat information includes at least one type of preset attack information; An acquisition module 302, configured to acquire the business completion degree of the business system for executing the target business based on the first data stream. The business completion degree is used to represent the damaged degree of the target business attacked by the preset attack information corresponding to the threat information; An evaluation module 303, configured to perform a security assessment on the network range based on the business completion degree.

[0060] Optionally, the acquisition module 302 is specifically configured to: Traverse target nodes based on the first data stream to determine the availability index of the target business. The target nodes are the nodes associated with the target business, and the availability index is used to represent the success rate of executing the target business based on the first data stream; Determine the integrity index of the target business based on the frequency of data inconsistency during the transmission of the first data stream from a first node to a second node. The first node is the starting point of the target business among the target nodes, and the second node is the ending point of the target business among the target nodes; Determine the service quality index of the target business based on the frequency of service exceptions during the transmission of the first data stream from the first node to the second node; Obtain the business completion degree based on the availability index, the integrity index, and the service quality index.

[0061] Optionally, the first data stream includes first attack data corresponding to each type of preset attack information. The first attack data includes first attack information and the second data stream, and the first attack information is any one of the preset attack information. The traversing the target nodes based on the first data stream to determine the availability index of the target business includes: For each of the first attack data, obtain the first defense result of the first attack data, where the first defense result includes the first status of each target node, and the first status is used to indicate whether the corresponding target node successfully defends the first attack information; wherein, when there is at least one target node whose first status indicates that the corresponding target node successfully defends the first attack information, the first defense result indicates that the business system successfully executes the target business, and when the first status of all target nodes indicates that the corresponding target node does not successfully defend the first attack information, the first defense result indicates that the business system does not successfully execute the target business; Construct a threat defense matrix based on the first defense result corresponding to each type of preset attack information and the first attack data corresponding to each type of preset attack information; Determine the availability index of the target business according to the threat defense matrix.

[0062] Optionally, the device further includes: A deployment module, configured to deploy the business system in the network model of the network range based on virtualization technology, and define the processing rules of the physical layer, the processing rules of the network layer, and the processing rules of the data flow layer in the network model. The network model includes the physical layer, the network layer, and the data flow layer. The physical layer is used to establish a physical connection channel between the target nodes, the network layer is used to connect the physical layer and the data flow layer, and the data flow layer is used to process data streams; Derive the second data stream according to the processing rules of the physical layer, the processing rules of the network layer, the processing rules of the data flow layer, and the target business.

[0063] Optionally, the obtaining module 302 is specifically further configured to: Determine weight information, where the weight information includes a first weight corresponding to the availability index, a second weight corresponding to the integrity index, and a third weight corresponding to the service quality index; Obtain the business completion degree according to the weight information, the availability index, the integrity index, and the service quality index.

[0064] Optionally, the obtaining module 302 is specifically further configured to: Determine the first contribution degree of each target node among the target nodes based on the availability index, and the first contribution degree of the third node is proportional to the defense ability of the third node against the preset attack information; Determine the second contribution degree of each target node among the target nodes based on the integrity index, and the second contribution degree of the third node is proportional to the integrity of the target business when the third node processes the target business; Determine the second contribution degree of each target node based on the service quality index, and the third contribution degree of the third node is proportional to the service quality of the target service when the third node processes the target service; Wherein, the third node is any one of the target nodes.

[0065] The security evaluation device 300 of the network range can implement each process of the above-mentioned embodiments of the security evaluation method of the network range. The technical features correspond one by one and can achieve the same technical effects. To avoid repetition, they will not be elaborated here.

[0066] An embodiment of the present application further provides an electronic device, including: a processor, a memory, and a program stored on the memory and executable on the processor. When the program is executed by the processor, it implements each process of the above-mentioned embodiment of the security evaluation method of the network range and can achieve the same technical effects. To avoid repetition, they will not be elaborated here.

[0067] Specifically, referring to Figure 4 , an embodiment of the present application further provides an electronic device, including a bus 401, a transceiver 402, an antenna 403, a bus interface 404, a processor 405, and a memory 406.

[0068] Wherein, the processor 405 is used to inject a first data stream into the service system deployed in the network range, and the first data stream is obtained after being extended and processed according to threat information and a second data stream. The second data stream is the data stream corresponding to the normal execution of the target service by the service system, and the threat information includes at least one type of preset attack information; The transceiver 402 is used to obtain the service completion degree of the service system for executing the target service based on the first data stream, and the service completion degree is used to represent the damaged degree of the target service attacked by the preset attack information corresponding to the threat information; The processor 405 is further used to perform a security evaluation on the network range based on the service completion degree.

[0069] Optionally, the obtaining the service completion degree of the service system for executing the target service based on the first data stream includes: Traverse the target nodes based on the first data stream to determine the availability index of the target service. The target nodes are the nodes associated with the target service, and the availability index is used to represent the success rate of executing the target service based on the first data stream; Determine the integrity index of the target service based on the frequency of data inconsistency that occurs during the transmission of the first data stream from the first node to the second node, where the first node is the starting point of the target service among the target nodes, and the second node is the ending point of the target service among the target nodes; Determine the service quality index of the target service based on the frequency of service exceptions that occur during the transmission of the first data stream from the first node to the second node; Obtain the service completion degree based on the availability index, the integrity index, and the service quality index.

[0070] Optionally, the first data stream includes first attack data corresponding to each type of preset attack information, the first attack data includes first attack information and the second data stream, and the first attack information is any one of the preset attack information; determining the availability index of the target service based on traversing the target nodes according to the first data stream includes: For each piece of the first attack data, obtain the first defense result of the first attack data, where the first defense result includes the first status of each target node, and the first status is used to indicate whether the corresponding target node successfully defends against the first attack information; where, when there is at least one target node whose first status indicates that the corresponding target node successfully defends against the first attack information, the first defense result indicates that the business system successfully executes the target service, and when the first status of all target nodes indicates that the corresponding target node does not successfully defend against the first attack information, the first defense result indicates that the business system does not successfully execute the target service; Construct a threat defense matrix based on the first defense results corresponding to each type of preset attack information and the first attack data corresponding to each type of preset attack information; Determine the availability index of the target service according to the threat defense matrix.

[0071] Optionally, the processor 405 is further configured to deploy the business system in the network model of the network range based on virtualization technology, and define the processing rules of the physical layer, the processing rules of the network layer, and the processing rules of the data stream layer in the network model, where the network model includes the physical layer, the network layer, and the data stream layer, the physical layer is used to establish a physical connection channel between the target nodes, the network layer is used to connect the physical layer and the data stream layer, and the data stream layer is used to process data streams; The processor 405 is further configured to derive the second data stream according to the processing rules of the physical layer, the processing rules of the network layer, the processing rules of the data stream layer, and the target service.

[0072] Optionally, obtaining the service completion degree based on the availability metric, the integrity metric, and the quality of service metric includes: Determining weight information, where the weight information includes a first weight corresponding to the availability metric, a second weight corresponding to the integrity metric, and a third weight corresponding to the quality of service metric; Obtaining the service completion degree according to the weight information, the availability metric, the integrity metric, and the quality of service metric.

[0073] Optionally, the processor 405 is further configured to: Determine a first contribution degree of each target node among the target nodes based on the availability metric, where the first contribution degree of the third node is proportional to the defense capability of the third node against the preset attack information; Determine a second contribution degree of each target node among the target nodes based on the integrity metric, where the second contribution degree of the third node is proportional to the integrity of the target service when the third node processes the target service; Determine a second contribution degree of each target node among the target nodes based on the quality of service metric, where the third contribution degree of the third node is proportional to the quality of service of the target service when the third node processes the target service; Wherein, the third node is any node among the target nodes.

[0074] In Figure 4 it, the bus architecture (represented by bus 401), bus 401 may include any number of interconnected buses and bridges. Bus 401 links together various circuits including one or more processors represented by processor 405 and a memory represented by memory 406. Bus 401 may also link together various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art, and thus will not be further described herein. Bus interface 404 provides an interface between bus 401 and transceiver 402. Transceiver 402 may be one element or multiple elements, such as multiple receivers and transmitters, providing units for communicating with various other devices over a transmission medium. Data processed by processor 405 is transmitted over a wireless medium via antenna 403. Further, antenna 403 also receives data and transmits the data to processor 405.

[0075] Processor 405 is responsible for managing bus 401 and general processing, and may also provide various functions including timing, peripheral interface, voltage regulation, power management, and other control functions. And memory 406 may be used to store data used by processor 405 when performing operations.

[0076] Optionally, the processor 405 can be a Central Processing Unit (CPU), an Application Specific Integrated Circuit (ASIC), a Field Programmable Gate Array (FPGA), or a Complex Programmable Logic Device (CPLD).

[0077] The embodiments of the present application also provide a computer-readable storage medium. A computer program is stored on the computer-readable storage medium. When the computer program is executed by a processor, it implements each process of the above-mentioned embodiments of the security assessment method for the network range, and can achieve the same technical effects. To avoid repetition, it will not be elaborated here. Among them, the computer-readable storage medium is, for example, a Read-Only Memory (ROM), a Random Access Memory (RAM), a magnetic disk, or an optical disc, etc.

[0078] It should be noted that in this article, the terms "including", "comprising", or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article, or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed, or further includes elements inherent to such process, method, article, or device. Without more limitations, an element defined by the statement "including a..." does not exclude the existence of additional identical elements in the process, method, article, or device including that element. In addition, it should be pointed out that the scope of the methods and devices in the embodiments of the present application is not limited to performing functions in the order discussed, and may also include performing functions in a substantially simultaneous manner or in a reverse order according to the functions involved. For example, the described methods may be performed in an order different from that described, and various steps may be added, omitted, or combined. Additionally, features described with reference to certain examples may be combined in other examples.

[0079] Through the description of the above embodiments, those skilled in the art can clearly understand that the above method of the embodiments can be implemented by means of software plus a necessary general hardware platform. Of course, it can also be implemented by hardware, but in many cases the former is a better implementation. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes several instructions for causing a terminal (which can be a mobile phone, a computer, a server, an air conditioner, or a network device, etc.) to execute the methods described in the various embodiments of the present application.

[0080] The embodiments of the present application have been described above with reference to the accompanying drawings. However, the present application is not limited to the above specific embodiments. The above specific embodiments are merely illustrative rather than restrictive. Under the inspiration of the present application, those of ordinary skill in the art can also make many forms without departing from the purpose of the present application and the scope protected by the claims, and all of them belong to the protection scope of the present application.

Claims

1. A security assessment method for a network range, characterized in that The method includes: Injecting a first data stream into a business system deployed in a network range, where the first data stream is obtained after being extended based on threat information and a second data stream, the second data stream being the data stream corresponding to the normal execution of a target service by the business system, and the threat information including at least one type of preset attack information; Obtaining the service completion degree of the business system for executing the target service based on the first data stream, where the service completion degree is used to represent the damaged degree of the target service attacked by the preset attack information corresponding to the threat information; Performing a security assessment on the network range based on the service completion degree assessment.

2. The method according to claim 1, wherein The obtaining the service completion degree of the business system for executing the target service based on the first data stream includes: Traversing target nodes based on the first data stream to determine the availability index of the target service, where the target nodes are the nodes associated with the target service, and the availability index is used to represent the success rate of executing the target service based on the first data stream; Determining the integrity index of the target service based on the frequency of data inconsistency during the transmission of the first data stream from a first node to a second node, where the first node is the starting point of the target service among the target nodes, and the second node is the ending point of the target service among the target nodes; Determining the service quality index of the target service based on the frequency of service exception during the transmission of the first data stream from the first node to the second node; Obtaining the service completion degree based on the availability index, the integrity index, and the service quality index.

3. The method according to claim 2, wherein The first data stream includes first attack data corresponding to each type of preset attack information, where the first attack data includes first attack information and the second data stream, and the first attack information is any one of the preset attack information; The traversing target nodes based on the first data stream to determine the availability index of the target service includes: For each piece of the first attack data, obtaining a first defense result of the first attack data, where the first defense result includes the first status of each target node, and the first status is used to represent whether the corresponding target node successfully defends against the first attack information; where, when there is at least one target node whose first status indicates that the corresponding target node successfully defends against the first attack information, the first defense result indicates that the business system successfully executes the target service, and when the first status of all target nodes indicates that the corresponding target nodes do not successfully defend against the first attack information, the first defense result indicates that the business system does not successfully execute the target service; Constructing a threat defense matrix based on the first defense results corresponding to each type of preset attack information and the first attack data corresponding to each type of preset attack information; Determining the availability index of the target service according to the threat defense matrix.

4. The method according to claim 2, wherein Before injecting the first data stream into the business system deployed in the network range, the method further includes: Deploy the service system in the network model of the network range based on virtualization technology, and define the processing rules of the physical layer, the network layer, and the data flow layer in the network model. The network model includes the physical layer, the network layer, and the data flow layer. The physical layer is used to establish a physical connection channel between the target nodes. The network layer is used to connect the physical layer and the data flow layer. The data flow layer is used to process data streams; Derive the second data stream according to the processing rules of the physical layer, the processing rules of the network layer, the processing rules of the data flow layer, and the target service.

5. The method according to claim 2, wherein The obtaining of the service completion degree based on the availability index, the integrity index, and the service quality index includes: Determine weight information, where the weight information includes a first weight corresponding to the availability index, a second weight corresponding to the integrity index, and a third weight corresponding to the service quality index; Obtain the service completion degree according to the weight information, the availability index, the integrity index, and the service quality index.

6. The method according to claim 2, characterized in that, After obtaining the service completion degree based on the availability index, the integrity index, and the service quality index, it further includes: Determine the first contribution degree of each target node among the target nodes based on the availability index. The first contribution degree of the third node is proportional to the defense ability of the third node against the preset attack information; Determine the second contribution degree of each target node among the target nodes based on the integrity index. The second contribution degree of the third node is proportional to the integrity of the target service when the third node processes the target service; Determine the second contribution degree of each target node among the target nodes based on the service quality index. The third contribution degree of the third node is proportional to the service quality of the target service when the third node processes the target service; Wherein, the third node is any one of the target nodes.

7. A security assessment device for a network range, characterized in that The device includes: An injection module, configured to inject a first data stream into a service system deployed in a network range. The first data stream is obtained after being extended based on threat information and a second data stream. The second data stream is the data stream corresponding to the normal execution of the target service by the service system. The threat information includes at least one type of preset attack information; An acquisition module, configured to acquire the service completion degree of the service system for executing the target service based on the first data stream. The service completion degree is used to represent the damaged degree of the target service under the attack of the preset attack information corresponding to the threat information; An evaluation module, configured to perform a security evaluation on the network range based on the service completion degree.

8. An electronic device, characterized in that, Includes a transceiver and a processor, The processor is configured to inject a first data stream into a service system deployed in a network range. The first data stream is obtained after being extended based on threat information and a second data stream. The second data stream is the data stream corresponding to the normal execution of the target service by the service system. The threat information includes at least one type of preset attack information; The transceiver is used to obtain the service completion degree of the target service executed by the service system based on the first data stream, and the service completion degree is used to represent the damage degree of the target service attacked by the preset attack information corresponding to the threat information; The processor is further used to perform a security assessment of the network range based on the service completion degree assessment.

9. An electronic device, characterized in that, It includes: A processor, a memory, and a program stored on the memory and executable on the processor. When the program is executed by the processor, the steps of the security assessment method of the network range according to any one of claims 1 to 6 are implemented.

10. A computer-readable storage medium, characterized in that, A computer program is stored on the computer-readable storage medium. When the computer program is executed by the processor, the steps of the security assessment method of the network range according to any one of claims 1 to 6 are implemented.

Citation Information

Patent Citations

  • Shoot range attack behavior simulation method, system and device and storage medium

    CN111212064A

  • Network security evaluation system

    CN117061257A

  • Network attack defense method, network element equipment and computer readable storage medium

    CN118413335A

  • Data security assessment method and system based on application scene

    CN119293782A

  • System and method for managing and evaluating security in industry control network

    KR1020170091989A