A security assessment method, device and related equipment for a network range

By simulating multiple attacks in a network target range and obtaining the business completion degree of the business system, the problem of insufficient accuracy of security assessment in existing technologies is solved, and more accurate security assessment and optimization guidance are achieved.

CN120358099BActive Publication Date: 2025-10-03CHINA MOBILE GROUP DESIGN INST +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510847431.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-06-24
Publication Date
2025-10-03
Estimated Expiration
2045-06-24

AI Technical Summary

Technical Problem

The accuracy of security assessment results of existing network target ranges is relatively poor, mainly because existing technologies focus on technical indicators and fail to fully reflect the actual protection effects.

Method used

By injecting the first data stream into the business system in the network target range, simulating multiple preset attack information, the business completion degree of the business system under attack is obtained, including availability, integrity and service quality indicators, and the security of the network target range is evaluated based on these indicators.

Benefits of technology

It achieves more realistic and complete feedback on the actual protection effect of the network target range, improves the accuracy of security assessment results, and provides business-level optimization guidance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120358099B_ABST
    Figure CN120358099B_ABST
Patent Text Reader

Abstract

The present application provides a method, apparatus, and related equipment for security assessment of a network range, relating to the field of security technology. The method comprises: injecting a first data stream into a business system deployed in the network range, the first data stream being obtained by performing expansion processing based on threat information and a second data stream, the second data stream being the data stream corresponding to the normal execution of the target business by the business system, the threat information including at least one type of preset attack information; obtaining the business completion degree of the business system executing the target business based on the first data stream, the business completion degree being used to indicate the degree of damage to the target business caused by the attack based on the preset attack information corresponding to the threat information; and performing a security assessment of the network range based on the business completion degree assessment. Assessing the performance of the business system when attacked from a business perspective breaks through the limitations of existing technologies and can provide more realistic and complete feedback on the actual protection effect of the network range, thereby improving the accuracy of the security assessment results.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of security technology, and in particular to a security assessment method, apparatus, and related equipment for a network target range. Background Art

[0002] The security assessment of the cyber target range conducts a comprehensive inspection of the system by simulating real attack scenarios. It can discover potential security vulnerabilities in advance and verify the effectiveness of defense strategies. It is a core link in improving network security protection capabilities and ensuring the security of critical information infrastructure.

[0003] Existing cyber range security assessment solutions typically rely on a pre-defined defense assessment framework and user-defined operational information on nodes within the range. However, this approach often focuses on technical indicators and analyzes only the target, resulting in poorly accurate assessment results. Summary of the Invention

[0004] The embodiments of the present application provide a network range security assessment method, apparatus, and related equipment to solve the problem of poor accuracy of network range security assessment results in the prior art.

[0005] To solve the above technical problems, this application is implemented as follows:

[0006] In a first aspect, an embodiment of the present application provides a method for security assessment of a network range, the method comprising:

[0007] Injecting a first data stream into a business system deployed in a network target range, the first data stream being obtained by performing expansion processing based on threat information and a second data stream, the second data stream being a data stream corresponding to when the business system normally executes the target business, the threat information including at least one type of preset attack information;

[0008] Obtaining a service completion degree of the target service executed by the service system based on the first data flow, where the service completion degree is used to indicate a degree of damage to the target service caused by the attack based on the preset attack information corresponding to the threat information;

[0009] A security assessment is performed on the network range based on the business completion assessment.

[0010] Optionally, obtaining a service completion degree of the target service executed by the service system based on the first data flow includes:

[0011] Determining an availability index of the target service based on the first data flow traversing a target node, where the target node is a node associated with the target service, and the availability index is used to represent a success rate of executing the target service based on the first data flow;

[0012] determining an integrity indicator of the target service based on a frequency of data inconsistency occurring during transmission of the first data stream from a first node to a second node, where the first node is a starting point of the target service in the target node and the second node is an end point of the target service in the target node;

[0013] determining a quality of service indicator of the target service based on a frequency of service anomalies occurring during transmission of the first data stream from the first node to the second node;

[0014] The service completion degree is obtained based on the availability indicator, the integrity indicator and the service quality indicator.

[0015] Optionally, the first data stream includes first attack data corresponding to each type of preset attack information, the first attack data includes the first attack information and the second data stream, and the first attack information is any type of the preset attack information; and determining the availability indicator of the target service based on traversing the target node by the first data stream includes:

[0016] For each first attack data, obtaining a first defense result of the first attack data, the first defense result including a first status of each target node, the first status being used to indicate whether the corresponding target node successfully defends against the first attack information; wherein, if the first status of at least one target node indicates that the corresponding target node successfully defends against the first attack information, the first defense result indicates that the business system successfully executes the target business; and if the first status of all target nodes indicates that the corresponding target nodes fail to successfully defend against the first attack information, the first defense result indicates that the business system fails to successfully execute the target business.

[0017] Building a threat defense matrix based on the first defense result corresponding to each type of preset attack information and the first attack data corresponding to each type of preset attack information;

[0018] An availability indicator of the target service is determined according to the threat defense matrix.

[0019] Optionally, before injecting the first data stream into the business system deployed in the network range, the method further includes:

[0020] Deploying the business system in a network model of the network range based on virtualization technology, and defining processing rules for a physical layer, a network layer, and a data flow layer in the network model, wherein the network model includes the physical layer, the network layer, and the data flow layer, the physical layer is used to establish a physical connection channel between the target nodes, the network layer is used to connect the physical layer and the data flow layer, and the data flow layer is used to process data flows;

[0021] The second data flow is derived according to the processing rules of the physical layer, the processing rules of the network layer, the processing rules of the data flow layer, and the target service.

[0022] Optionally, obtaining the service completion degree based on the availability indicator, the integrity indicator, and the service quality indicator includes:

[0023] Determining weight information, the weight information including a first weight corresponding to the availability indicator, a second weight corresponding to the integrity indicator, and a third weight corresponding to the service quality indicator;

[0024] The service completion degree is obtained according to the weight information, the availability index, the integrity index and the service quality index.

[0025] Optionally, after obtaining the service completion degree based on the availability indicator, the integrity indicator, and the service quality indicator, the method further includes:

[0026] determining a first contribution of each target node in each target node based on the availability index, wherein the first contribution of a third node is proportional to a defense capability of the third node against the preset attack information;

[0027] determining a second contribution of each target node in each target node based on the integrity index, wherein the second contribution of the third node is proportional to the integrity of the target service when the third node processes the target service;

[0028] determining a third contribution of each target node in each target node based on the service quality indicator, where the third contribution of the third node is proportional to the service quality of the target service when the third node processes the target service;

[0029] The third node is any one of the target nodes.

[0030] In a second aspect, an embodiment of the present application provides a security assessment device for a network range, the device comprising:

[0031] An injection module is configured to inject a first data stream into a business system deployed in a network range, the first data stream being obtained by performing extended processing based on threat information and a second data stream, the second data stream being a data stream corresponding to the business system normally executing a target business, the threat information including at least one type of preset attack information;

[0032] an acquisition module, configured to acquire a service completion degree of the target service executed by the service system based on the first data flow, wherein the service completion degree is used to indicate a degree of damage to the target service caused by the attack based on the preset attack information corresponding to the threat information;

[0033] An evaluation module is used to perform a security evaluation on the network range based on the business completion evaluation.

[0034] In a third aspect, an embodiment of the present application provides an electronic device, including a transceiver and a processor.

[0035] The processor is configured to inject a first data stream into a business system deployed in a network target range, the first data stream being obtained by performing expansion processing based on threat information and a second data stream, the second data stream being a data stream corresponding to when the business system normally executes a target business, the threat information including at least one type of preset attack information;

[0036] The transceiver is configured to obtain a service completion degree of the target service executed by the service system based on the first data flow, wherein the service completion degree is used to indicate a degree of damage to the target service caused by the attack based on the preset attack information corresponding to the threat information;

[0037] The processor is further configured to perform a security assessment on the network range based on the business completion assessment.

[0038] In a fourth aspect, an embodiment of the present application provides an electronic device, comprising: a processor, a memory, and a program stored on the memory and executable on the processor, wherein when the program is executed by the processor, the steps of the network target range security assessment method as described in the first aspect are implemented.

[0039] In a fifth aspect, an embodiment of the present application provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the network target range security assessment method as described in the first aspect are implemented.

[0040] In an embodiment of the present application, a first data stream is injected into a business system deployed in a network target range to simulate attacks on the business system by various types of preset attack information; the business completion degree of the business system in executing the target business based on the first data stream is obtained, and the performance of the business system when attacked is evaluated from a business level, breaking through the limitations of the existing technology; a security assessment of the network target range is performed based on the business completion assessment from a business perspective, which can provide more realistic and complete feedback on the actual protection effect of the network target range, thereby improving the accuracy of the security assessment results. BRIEF DESCRIPTION OF THE DRAWINGS

[0041] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following briefly introduces the drawings required for use in the embodiments or descriptions of the prior art. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0042] Figure 1 This is one of the flow charts of a security assessment method for a network range provided in an embodiment of the present application;

[0043] Figure 2 This is the second flowchart of a security assessment method for a network range provided in an embodiment of the present application;

[0044] Figure 3 This is a schematic diagram of the structure of a security assessment device for a network range provided in an embodiment of the present application;

[0045] Figure 4 This is a structural diagram of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0046] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are part of the embodiments of this application, not all of them. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.

[0047] See also Figure 1 , Figure 1 This is a flow chart of a security assessment method for a network range provided by an embodiment of the present application. Figure 1 As shown, the method includes the following steps:

[0048] Step 101: inject a first data stream into a business system deployed in a network target range, the first data stream being obtained by performing expansion processing based on threat information and a second data stream, the second data stream being a data stream corresponding to the business system normally executing a target business, the threat information including at least one type of preset attack information;

[0049] In this step, the second data stream can be a legitimate data stream when the business system normally executes the target business (such as e-commerce payment business, including processes such as user login, product browsing, ordering, and payment), and can include a six-tuple element (initiator network address, source network port, receiver network address, destination network address, communication protocol, permission credentials, etc.); the first data stream is obtained by expanding and processing the second data stream based on the threat information, where the threat information can include at least one type of preset attack information, which can be SQL injection, cross-site scripting (XSS), distributed denial-of-service (DDoS), or other types of attack information in the MITRE ATT&CK framework. The impact of real threats on the business is simulated through the first data stream.

[0050] Using a service data flow derivation algorithm, the first data flow can be multiplexed onto the reachable path of the second data flow, allowing the first data flow (i.e., the attack flow) to propagate along the actual service path, such as user terminal → firewall → web server → database. This facilitates subsequent evaluation of the defense performance of the network target range and the first data flow carrying threat information.

[0051] Step 102: Obtain a service completion degree of the target service executed by the service system based on the first data flow, where the service completion degree is used to indicate the degree of damage to the target service caused by the preset attack information corresponding to the threat information.

[0052] In this step, a real business system is simulated in a cyber range, and the first data stream simulates various types of attacks. This allows evaluation of the effectiveness of the defense system against different attack scenarios. Both the business system and the defense system are deployed in the cyber range. The transmission of the first data stream between target nodes is broken down into a chain structure of "starting point → intermediate node → end point." The frequency of abnormalities in the business system executing the target business based on the first data stream at each stage is counted, and finally aggregated into the business completion rate. This allows for a comprehensive assessment of the business system's performance under attack, improving the accuracy of security assessment results.

[0053] Compared with the evaluation methods in related technologies that focus on detection efficiency and response efficiency, the evaluation method based on business completion in this application is closer to practical applications and can comprehensively evaluate the performance of the business system when attacked from three dimensions: business availability, data integrity and service quality.

[0054] Step 103: Perform a security assessment on the network range based on the business completion assessment.

[0055] In this step, a security assessment of the network target range is conducted based on the business completion assessment, realizing an innovation in the assessment paradigm from a technical effectiveness orientation to an actual business orientation, and realizing an assessment upgrade from "technical compliance" to "business availability". It is closer to the actual network security needs, and can provide more realistic and complete feedback on the actual protection effect of the network target range, providing accurate business-level guidance for defense system optimization.

[0056] In an embodiment of the present application, a first data stream is injected into a business system deployed in a network target range to simulate attacks on the business system by various types of preset attack information; the business completion degree of the business system in executing the target business based on the first data stream is obtained, and the performance of the business system when attacked is evaluated from a business level, breaking through the limitations of the existing technology; a security assessment of the network target range is performed based on the business completion assessment from a business perspective, which can provide more realistic and complete feedback on the actual protection effect of the network target range, thereby improving the accuracy of the security assessment results.

[0057] Optionally, before step 101, injecting the first data stream into the business system deployed in the network range, the method further includes:

[0058] Deploying the business system in a network model of the network range based on virtualization technology, and defining processing rules for a physical layer, a network layer, and a data flow layer in the network model, wherein the network model includes the physical layer, the network layer, and the data flow layer, the physical layer is used to establish a physical connection channel between the target nodes, the network layer is used to connect the physical layer and the data flow layer, and the data flow layer is used to process data flows;

[0059] The second data flow is derived according to the processing rules of the physical layer, the processing rules of the network layer, the processing rules of the data flow layer, and the target service.

[0060] In this embodiment, Figure 2As shown, first, we built CyberBusiness, a complete simulation system that simulates multiple business systems and user information. This includes complete voice calls, website browsing, video calls, online payments, and other common operations, simulating real business operations. Furthermore, CyberBusiness includes multiple "people" with email accounts, work passwords, and bank deposits, enhancing the realism of the virtual environment.

[0061] For example, consider "Evaluating the defensive effectiveness of a cyber target range in an e-commerce payment business scenario." Setting the evaluation scenario: Based on the evaluation objectives, design or select realistic business scenarios, including business types, business processes, and data flows, to ensure the representativeness and practicality of the evaluation results. Design an e-commerce payment business scenario, including user login, product browsing, order placement, and payment processes. Define expected and abnormal behaviors (such as attack behaviors) within normal business processes.

[0062] Use virtualization technologies (such as Docker and VMware) to build a network range environment. Create virtual nodes within the network range, including business nodes (e.g., web servers, databases, user terminals), security nodes (e.g., firewalls, Web Application Firewalls (WAFs), Intrusion Detection Systems (IDSs)), and network nodes (e.g., switches and routers). Configure the corresponding network topology and security policies, assigning each node a unique identifier (DevId), its security domain (e.g., demilitarized zone (DMZ), production network), and hardware resources (CPU / memory / network interface). Deploy a complete business system within the network model of the network range, including front-end applications, back-end services, and databases, to ensure the normal operation of the business system and simulate real-world business scenarios. Configure the appropriate business traffic based on the business scenario, including both normal and abnormal traffic (e.g., simulated attack traffic), to simulate network activity in real-world business scenarios.

[0063] The network model includes the physical layer, network layer, and data flow layer. The formal description of the network model can be expressed as the following formula:

[0064] DevInfo=(Devld,DevName,DevType,area);

[0065] The basic node information includes the node ID (Devld), node name (DevName), node type (DevTpe), and the network security zone (area) in which the node is located. Node types can be categorized as office equipment, business equipment, security equipment, and network equipment. Network security zones can be categorized as production network, office network, and DMZ.

[0066] The physical layer formal description can be expressed as the following formula:

[0067] Devlf=(If ld ,address,netmask);

[0068] PhyConnectLayer=(Devld,Devlf,Peer Dev ld,Peer Dev lf);

[0069] Among them, Devlf represents the physical interface information of the node, If ld Indicates the physical interface number, address indicates the network address of the interface, and netmask indicates the subnet code of the interface. A PhyConnectLayer indicates DevId and Peer Devld Between two nodes, through Devlf and Peer Devld Physical interface connection.

[0070] The formal description of the network layer can be expressed as the following formula:

[0071] NetworkLayer=(D addr ,genmask,gateway a ddr,Devlf);

[0072] Each physical interface has a corresponding network address, and nodes communicate through network addresses. Each NetworkLayer unit represents a network layer processing rule. When the destination address is D' addr When the data flow passes through this node, D' addr Operate with genmask, if the result is the same as D addr If they are equal, the next hop address of the data flow is the gateway address gatewayaddr, and the data flow is transmitted through the Devlf wide physical interface of the node.

[0073] The formal description of the data flow layer can be expressed as the following formula:

[0074] DataFlowLayer=(Type,Pre DataF low,New DataFlow);

[0075] Type indicates the processing mode of DataFlow, which can be Trans, accept, or deny. Trans indicates that the data flow value is changed from Pre DataFlow Convert to New DataFlow The corresponding value of Type will also be expanded in the threat defense model.

[0076] In addition, the formal description of the system environment layer can be expressed as the following formula:

[0077] ServiceLayer=(service,port,protocol,E ser ,P(U));

[0078] The system environment layer represents the application service information provided by the node. Each ServiceLayer represents an application service provided by the node and the corresponding permissions. por represents the port number occupied by the service, protocol represents the communication protocol used by the service, and E ser Indicates the operating environment corresponding to the service, P(U) represents E ser The service permissions provided.

[0079] The physical layer is the lowest layer of the network model. It is used to establish the physical interface connection relationship between nodes, such as "server eth0 interface → firewall ge0 / 1 interface", forming a physical connection channel. The transmission of data flow between physical interfaces only involves the change of physical location, and does not involve the change of data flow state. After receiving the information of the physical interface DevIf specified by the network layer, it enters the physical layer processing rule matching process and queries the peer device connected to DevIf through the node physical connection information. DevId and the peer physical interface DevIf , passing the current data stream to the peer node. DevIf After receiving the data stream through the physical interface, the data stream is logically processed at the current node.

[0080] The network layer connects the physical layer and the data flow layer by configuring routing rules (subnet mask, gateway) and determining the data flow forwarding logic (such as forwarding to the firewall when the destination address matches 10.0.0.0 / 24). The network layer is responsible for receiving the data flow processed by the data flow layer, querying the network layer rules of the current node, and calculating the D of the current data flow. addr Calculate the value with the subnet mask to query the corresponding next-hop network address and the physical interface DevIf of the specified node, and pass the information to the physical layer interface for processing.

[0081] At the top of the data flow network model, traffic handling policies (allow / block / convert) are defined, such as "firewall performs NAT on HTTP / HTTPS traffic on ports 80 / 443" and "WAF intercepts requests containing SQL injection signatures." When the rule type is Trans, data flows matching the specified six-tuple state are converted to a new six-tuple state, and the new data flow state, DataFlow, is then passed to the network layer for processing. The processing process is formally described as follows:

[0082] DataFlow→DataFlow'(S' addr , S' sport ,D' addr ,D' aport ,protocol',P(U)'),Type=Trans.

[0083] In this way, based on the defined processing rules of the physical layer, the network layer, and the data flow layer, all business device nodes and office device nodes in the system are regarded as the source addresses of the data flow, all business device nodes are used as destination nodes, and the service port of the system environment layer is used as the destination port to form the initial DataFlow. Then, based on the inter-node reachability judgment algorithm, the reachability of the DataFlow is deduced, and the data flow path carrying the target business behavior in the business system, that is, the second data flow, can be obtained. Exemplarily, after expansion processing based on threat information and the second data flow, the attack vector can be combined into the second data flow to obtain the first data flow. The first data flow is forwarded through various network devices within the business system, and uses the same path as the second data flow to attack the business service. When there is a vulnerability in the service, the attacker can successfully attack and thereby elevate permissions, obtain information, etc.

[0084] The formal description of the first data stream is as follows:

[0085] AtackFlow=(S addr ,S sport ,D addr ,D dport ,protocol,t,P(U);

[0086] Among them, AtackFlow is the first data flow, which is an extension of the second data flow DataFlow. addr Indicates the network address where the data flow originates; S sport Indicates the source port of the data flow; D addr Indicates the corresponding target network address in the data stream; D dportIndicates the corresponding target service port in the data flow; protocol indicates the protocol used by the data flow; t indicates the threat classification corresponding to the attack vector in the attack flow; P(U) indicates the permission certificate carried by the data flow.

[0087] The second data flow DataFlow is represented as: DataFlow=(S addr ,S sport ,D addr ,D dport ,protocal,P(U)).

[0088] Optionally, step 102 of obtaining a degree of completion of the target business executed by the business system based on the first data flow includes:

[0089] Determining an availability index of the target service based on the first data flow traversing a target node, where the target node is a node associated with the target service, and the availability index is used to represent a success rate of executing the target service based on the first data flow;

[0090] Determining, based on a frequency of data inconsistency occurring during transmission of the first data stream from a first node to a second node, an integrity index for the target service, the integrity index being used to indicate a probability that data remains consistent during transmission of the first data stream from the first node to the second node, the first node being a starting point of the target service in the target node, and the second node being an end point of the target service in the target node;

[0091] determining a quality of service indicator of the target service based on a frequency of service anomalies occurring during transmission of the first data stream from the first node to the second node;

[0092] The service completion degree is obtained based on the availability indicator, the integrity indicator and the service quality indicator.

[0093] In this embodiment, the target nodes may include all key nodes involved in the target business (such as user terminals, web servers, databases, etc.), forming the physical / logical path of business execution (such as user terminal → payment gateway → database). The transmission process of the first data stream between target nodes is disassembled into a chain structure of "starting point → intermediate node → end point", and the abnormal frequency of each link is counted separately. Finally, the availability index, the integrity index and the service quality index are aggregated to obtain the business completion degree. The business completion degree can comprehensively evaluate the performance of the business system when it is attacked from the three dimensions of business availability, data integrity and service quality.

[0094] Among them, the availability index can be expressed as S ServiceAvailability, that is, the defense effectiveness for business availability; the integrity index can be expressed as S DataIntegrity , that is, the defense effectiveness for data integrity; the service quality index can be expressed as S ServiceQuality , specifically the effectiveness of defenses targeting service quality. Service completion data before and after attack simulations can be compared to analyze the effectiveness of defense devices in protecting services. Based on the performance of defense devices and changes in service completion, a comprehensive assessment of the network range's defense effectiveness can be conducted.

[0095] In one embodiment, based on the first data flow traversing the target node, the availability index of the target service is determined, which may be specifically described as follows:

[0096] Optionally, the first data stream includes first attack data corresponding to each type of preset attack information, the first attack data includes the first attack information and the second data stream, and the first attack information is any type of the preset attack information; and determining the availability indicator of the target service based on traversing the target node by the first data stream includes:

[0097] For each first attack data, obtaining a first defense result of the first attack data, the first defense result including a first status of each target node, the first status being used to indicate whether the corresponding target node successfully defends against the first attack information; wherein, if the first status of at least one target node indicates that the corresponding target node successfully defends against the first attack information, the first defense result indicates that the business system successfully executes the target business; and if the first status of all target nodes indicates that the corresponding target nodes fail to successfully defend against the first attack information, the first defense result indicates that the business system fails to successfully execute the target business.

[0098] Building a threat defense matrix based on the first defense result corresponding to each type of preset attack information and the first attack data corresponding to each type of preset attack information;

[0099] An availability indicator of the target service is determined according to the threat defense matrix.

[0100] Among them, in the data flow path of the first data flow, that is, AtackFlow, the security function of the node is traversed for each target node, and the first defense result of the first attack data is obtained for each first attack data. The first defense result can be expressed as r i :

[0101]

[0102] r iFor 1, it indicates that the i-th target node successfully defends against the first attack information, that is, there is a defense mapping relationship for the i-th target node; r i For 0, it indicates that the i-th target node fails to successfully defend against the first attack information, that is, there is no defense mapping relationship for the i-th target node.

[0103] Then, based on the first defense result corresponding to each type of preset attack information and the first attack data corresponding to each type of preset attack information, a threat defense matrix is constructed; the availability metric of the target service is determined according to the threat defense matrix. In this way, the working state of the defense system is abstracted into one or several sets of quantifiable availability metrics, and the defense effectiveness of the defense system is intuitively reflected by the availability metrics, improving the accuracy of the evaluation results.

[0104] Among them, the total defense effectiveness of the defense system can be expressed as S total :

[0105]

[0106] The optimal defense effectiveness goal of the defense system is that all AttackFlows can be successfully defended by the security device, that is, the r i (0 < i < count(AttackFlow)) values for all AttackFlows are 1. By calculating the proportion of the number of r i = 1 in n, the defense effectiveness S provided by the defense system is obtained total , where n is the total number of AttackFlows.

[0107] Exemplarily, traversing the target nodes based on the first data stream, by counting the proportion of r i = 1 in AttackFlow to determine the availability metric of the target service, the following formula can be referred to:

[0108]

[0109] Among them, S ServiceAvailability is the availability metric, n0 is the total number of AttackFlows, and the number of n0 is determined according to the type (ThreatClass) of the preset attack information.

[0110] Exemplarily, based on the frequency of data inconsistency during the transmission of the first data stream from the first node to the second node, to determine the integrity metric of the target service, the following formula can be referred to:

[0111]

[0112] Among them, S DataIntegrityAs the integrity indicator, the S addr ∈eareax,D addr ∈eareay and r i =1, the defense effectiveness of the defense system for the areaax→>areay region can be calculated, that is, the integrity index of the target business can be determined. Sareax-areay can discover the weak points of threat defense between regions.

[0113] Exemplarily, based on the frequency of service anomalies occurring during the transmission of the first data stream from the first node to the second node, the service quality indicator of the target service is determined, as shown in the following formula:

[0114]

[0115] in, Indicates S ServiceQuality That is, the service quality indicator, which is calculated by counting the abnormal events P(U x )Sure.

[0116] In this way, the availability indicator S based on the business perspective ServiceAvailability , integrity index S DataIntegrity and service quality index S ServiceQuality Conducting multi-dimensional security assessments on cyber target ranges can provide more realistic and complete feedback on the actual protection effects of the cyber target ranges, thereby improving the accuracy of security assessment results.

[0117] Optionally, obtaining the service completion degree based on the availability indicator, the integrity indicator, and the service quality indicator includes:

[0118] Determining weight information, the weight information including a first weight corresponding to the availability indicator, a second weight corresponding to the integrity indicator, and a third weight corresponding to the service quality indicator;

[0119] The service completion degree is obtained according to the weight information, the availability index, the integrity index and the service quality index.

[0120] In this embodiment, weights can be assigned to the three indicators according to business priorities (such as 40% integrity weight, 30% availability, and 30% service quality weight in financial business), and a comprehensive business completion degree can be generated through linear combination: business completion degree = α·availability index + β·integrity index + γ·service quality index (α+β+γ=1, weights can be adjusted dynamically). α is the first weight, β is the second weight, and γ is the third weight. In this way, the first data stream is injected into the business system deployed in the network target range to simulate attacks on the business system by various different types of preset attack information; the business completion degree of the business system executing the target business based on the first data stream is obtained, and the performance of the business system when attacked is evaluated from the business level, breaking through the limitations of existing technologies; a multi-dimensional security assessment of the network target range is performed based on availability indicators, integrity indicators, and service quality indicators from a business perspective, which can more realistically and completely feedback the actual protection effect of the network target range, thereby improving the accuracy of the security assessment results.

[0121] Optionally, after obtaining the service completion degree based on the availability indicator, the integrity indicator, and the service quality indicator, the method further includes:

[0122] determining a first contribution of each target node in each target node based on the availability index, wherein the first contribution of a third node is proportional to a defense capability of the third node against the preset attack information;

[0123] determining a second contribution of each target node in each target node based on the integrity index, wherein the second contribution of the third node is proportional to the integrity of the target service when the third node processes the target service;

[0124] determining a third contribution of each target node in each target node based on the service quality indicator, where the third contribution of the third node is proportional to the service quality of the target service when the third node processes the target service;

[0125] The third node is any one of the target nodes.

[0126] In this embodiment, based on the three indicators of availability, integrity, and service quality, the node's defense capability contribution (first contribution), data protection contribution (second contribution), and performance assurance contribution (third contribution) are defined. This forms a three-dimensional evaluation system covering defense effectiveness, data security, and service stability, avoiding the limitations of a single indicator. Furthermore, the proportional relationship between contribution and node defense capability and service processing quality can quickly identify the nodes that have the greatest impact on service damage.

[0127] The calculation formula for any of the first contribution, second contribution, and third contribution is as follows:

[0128]

[0129] The threat defense matrix only retains the defense results of SecDev and recalculates the system defense effectiveness S include (SecDev), by calculating S include (SecDev) and S toial Calculate the contribution of the SecDev node SecDev ,The importance of security device nodes can be ranked by calculating ,their contribution.

[0130] For example, if there are n threats to the target node Xi and m threats to the target node Xi+1, a total of z AttackFlows are generated. Based on the first defense result corresponding to each type of preset attack information and the first attack data corresponding to each type of preset attack information, a threat defense matrix is ​​constructed as follows:

[0131]

[0132] The results of the effectiveness evaluation indicators for the defense system application example are shown in the following table:

[0133] Performance evaluation indicators Indicator symbols result Total defense effectiveness <![CDATA[S total ]]> XX% Defense effectiveness for business availability <![CDATA[S ServiceAvailability ]]> XX% Defense effectiveness against data integrity <![CDATA[S DataIntegrity ]]> XX% Defensive effectiveness for quality of service <![CDATA[S ServiceQuality ]]> XX% Contribution of single function node <![CDATA[Contribution SecDevi ]]> XX%

[0134] Combining business availability, data integrity, and service quality, the system calculates a comprehensive performance score using a weighted average method, providing a quantitative comprehensive performance evaluation and a scientific basis for defense system optimization. This improves the accuracy of the evaluation results.

[0135] See also Figure 3 , Figure 3 This is a schematic diagram of the structure of a security assessment device for a network range provided in an embodiment of the present application. Figure 3 As shown, the network range security assessment device 300 includes:

[0136] Injection module 301 is configured to inject a first data stream into a business system deployed in a network range, the first data stream being obtained by performing expansion processing based on threat information and a second data stream, the second data stream being a data stream corresponding to the business system normally executing a target business, the threat information including at least one type of preset attack information;

[0137] An acquisition module 302 is configured to acquire a service completion degree of the target service executed by the service system based on the first data flow, wherein the service completion degree is used to indicate a degree of damage to the target service caused by the attack based on the preset attack information corresponding to the threat information;

[0138] The evaluation module 303 is used to perform a security evaluation on the network range based on the business completion evaluation.

[0139] Optionally, the acquisition module 302 is specifically configured to:

[0140] Determining an availability index of the target service based on the first data flow traversing a target node, where the target node is a node associated with the target service, and the availability index is used to represent a success rate of executing the target service based on the first data flow;

[0141] determining an integrity indicator of the target service based on a frequency of data inconsistency occurring during transmission of the first data stream from a first node to a second node, where the first node is a starting point of the target service in the target node and the second node is an end point of the target service in the target node;

[0142] determining a quality of service indicator of the target service based on a frequency of service anomalies occurring during transmission of the first data stream from the first node to the second node;

[0143] The service completion degree is obtained based on the availability indicator, the integrity indicator and the service quality indicator.

[0144] Optionally, the first data stream includes first attack data corresponding to each type of preset attack information, the first attack data includes the first attack information and the second data stream, and the first attack information is any type of the preset attack information; and determining the availability indicator of the target service based on traversing the target node by the first data stream includes:

[0145] For each first attack data, obtaining a first defense result of the first attack data, the first defense result including a first status of each target node, the first status being used to indicate whether the corresponding target node successfully defends against the first attack information; wherein, if the first status of at least one target node indicates that the corresponding target node successfully defends against the first attack information, the first defense result indicates that the business system successfully executes the target business; and if the first status of all target nodes indicates that the corresponding target nodes fail to successfully defend against the first attack information, the first defense result indicates that the business system fails to successfully execute the target business.

[0146] Building a threat defense matrix based on the first defense result corresponding to each type of preset attack information and the first attack data corresponding to each type of preset attack information;

[0147] An availability indicator of the target service is determined according to the threat defense matrix.

[0148] Optionally, the device further comprises:

[0149] a deployment module, configured to deploy the service system in a network model of the network range based on virtualization technology, and define processing rules for a physical layer, a network layer, and a data flow layer in the network model, wherein the network model includes the physical layer, the network layer, and the data flow layer, the physical layer is configured to establish a physical connection channel between the target nodes, the network layer is configured to connect the physical layer and the data flow layer, and the data flow layer is configured to process data flows;

[0150] The second data flow is derived according to the processing rules of the physical layer, the processing rules of the network layer, the processing rules of the data flow layer, and the target service.

[0151] Optionally, the acquisition module 302 is further configured to:

[0152] Determining weight information, the weight information including a first weight corresponding to the availability indicator, a second weight corresponding to the integrity indicator, and a third weight corresponding to the service quality indicator;

[0153] The service completion degree is obtained according to the weight information, the availability index, the integrity index and the service quality index.

[0154] Optionally, the acquisition module 302 is further configured to:

[0155] determining a first contribution of each target node in each target node based on the availability index, wherein the first contribution of a third node is proportional to a defense capability of the third node against the preset attack information;

[0156] determining a second contribution of each target node in each target node based on the integrity index, wherein the second contribution of the third node is proportional to the integrity of the target service when the third node processes the target service;

[0157] determining a third contribution of each target node in each target node based on the service quality indicator, where the third contribution of the third node is proportional to the service quality of the target service when the third node processes the target service;

[0158] The third node is any one of the target nodes.

[0159] The network target range security assessment device 300 is capable of implementing each process of each embodiment of the above-mentioned network target range security assessment method. The technical features correspond one to one and can achieve the same technical effects. To avoid repetition, they will not be described here.

[0160] An embodiment of the present application also provides an electronic device, including: a processor, a memory, and a program stored in the memory and runnable on the processor. When the program is executed by the processor, the various processes of the above-mentioned network target range security assessment method embodiment are implemented, and the same technical effect can be achieved. To avoid repetition, it will not be repeated here.

[0161] For details, see Figure 4 An embodiment of the present application further provides an electronic device, including a bus 401 , a transceiver 402 , an antenna 403 , a bus interface 404 , a processor 405 and a memory 406 .

[0162] The processor 405 is configured to inject a first data stream into a business system deployed in the network target range, the first data stream being obtained by performing expansion processing based on threat information and a second data stream, the second data stream being a data stream corresponding to the business system normally executing the target business, the threat information including at least one type of preset attack information;

[0163] The transceiver 402 is configured to obtain a service completion degree of the target service executed by the service system based on the first data flow, wherein the service completion degree is used to indicate a degree of damage to the target service caused by the preset attack information corresponding to the threat information;

[0164] Processor 405 is further configured to perform a security assessment on the network range based on the business completion assessment.

[0165] Optionally, obtaining a service completion degree of the target service executed by the service system based on the first data flow includes:

[0166] Determining an availability index of the target service based on the first data flow traversing a target node, where the target node is a node associated with the target service, and the availability index is used to represent a success rate of executing the target service based on the first data flow;

[0167] determining an integrity indicator of the target service based on a frequency of data inconsistency occurring during transmission of the first data stream from a first node to a second node, where the first node is a starting point of the target service in the target node and the second node is an end point of the target service in the target node;

[0168] determining a quality of service indicator of the target service based on a frequency of service anomalies occurring during transmission of the first data stream from the first node to the second node;

[0169] The service completion degree is obtained based on the availability indicator, the integrity indicator and the service quality indicator.

[0170] Optionally, the first data stream includes first attack data corresponding to each type of preset attack information, the first attack data includes the first attack information and the second data stream, and the first attack information is any type of the preset attack information; and determining the availability indicator of the target service based on traversing the target node by the first data stream includes:

[0171] For each first attack data, obtaining a first defense result of the first attack data, the first defense result including a first status of each target node, the first status being used to indicate whether the corresponding target node successfully defends against the first attack information; wherein, if the first status of at least one target node indicates that the corresponding target node successfully defends against the first attack information, the first defense result indicates that the business system successfully executes the target business; and if the first status of all target nodes indicates that the corresponding target nodes fail to successfully defend against the first attack information, the first defense result indicates that the business system fails to successfully execute the target business.

[0172] Building a threat defense matrix based on the first defense result corresponding to each type of preset attack information and the first attack data corresponding to each type of preset attack information;

[0173] An availability indicator of the target service is determined according to the threat defense matrix.

[0174] Optionally, the processor 405 is further configured to deploy the business system in a network model of the network range based on virtualization technology, and define processing rules for a physical layer, a network layer, and a data flow layer in the network model, wherein the network model includes the physical layer, the network layer, and the data flow layer, the physical layer is configured to establish a physical connection channel between the target nodes, the network layer is configured to connect the physical layer and the data flow layer, and the data flow layer is configured to process data flows;

[0175] The processor 405 is further configured to derive the second data flow according to the processing rules of the physical layer, the processing rules of the network layer, the processing rules of the data flow layer, and the target service.

[0176] Optionally, obtaining the service completion degree based on the availability indicator, the integrity indicator, and the service quality indicator includes:

[0177] Determining weight information, the weight information including a first weight corresponding to the availability indicator, a second weight corresponding to the integrity indicator, and a third weight corresponding to the service quality indicator;

[0178] The service completion degree is obtained according to the weight information, the availability index, the integrity index and the service quality index.

[0179] Optionally, the processor 405 is further configured to:

[0180] determining a first contribution of each target node in each target node based on the availability index, wherein the first contribution of a third node is proportional to a defense capability of the third node against the preset attack information;

[0181] determining a second contribution of each target node in each target node based on the integrity index, wherein the second contribution of the third node is proportional to the integrity of the target service when the third node processes the target service;

[0182] determining a third contribution of each target node in each target node based on the service quality indicator, where the third contribution of the third node is proportional to the service quality of the target service when the third node processes the target service;

[0183] The third node is any one of the target nodes.

[0184] exist Figure 4 In the embodiment, the bus architecture (represented by bus 401) is shown. Bus 401 may include any number of interconnected buses and bridges. Bus 401 links together various circuits including one or more processors represented by processor 405 and memory represented by memory 406. Bus 401 may also link together various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and are therefore not described further herein. Bus interface 404 provides an interface between bus 401 and transceiver 402. Transceiver 402 may be one element or multiple elements, such as multiple receivers and transmitters, providing a unit for communicating with various other devices on a transmission medium. Data processed by processor 405 is transmitted on a wireless medium via antenna 403. Furthermore, antenna 403 receives data and transmits the data to processor 405.

[0185] Processor 405 is responsible for managing bus 401 and general processing, and may also provide various functions, including timing, peripheral interfaces, voltage regulation, power management, and other control functions. Memory 406 may be used to store data used by processor 405 when performing operations.

[0186] Optionally, the processor 405 may be a central processing unit (CPU), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), or a complex programmable logic device (CPLD).

[0187] The present application also provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, the computer program implements the various processes of the above-mentioned network range security assessment method embodiment and can achieve the same technical effect. To avoid repetition, the details are not described here. The computer-readable storage medium is, for example, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.

[0188] It should be noted that, in this article, the terms "comprise", "include" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, an element defined by the sentence "comprises a ..." does not exclude the presence of other identical elements in the process, method, article or device comprising the element. In addition, it should be pointed out that the scope of the methods and devices in the embodiments of the present application is not limited to performing the functions in the order discussed, but may also include performing the functions in a substantially simultaneous manner or in the opposite order according to the functions involved. For example, the described method may be performed in an order different from that described, and various steps may also be added, omitted, or combined. In addition, the features described with reference to certain examples may be combined in other examples.

[0189] Through the description of the above implementation methods, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus the necessary general hardware platform, and of course can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes a number of instructions for enabling a terminal (which can be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in each embodiment of the present application.

[0190] The embodiments of the present application are described above in conjunction with the accompanying drawings, but the present application is not limited to the above-mentioned specific implementation methods. The above-mentioned specific implementation methods are merely illustrative and not restrictive. Under the guidance of this application, ordinary technicians in this field can also make many forms without departing from the purpose of this application and the scope of protection of the claims, all of which are within the protection of this application.

Claims

1. A security assessment method for a network range, characterized in that: The method comprises: Injecting a first data stream into a business system deployed in a network target range, the first data stream being obtained by performing expansion processing based on threat information and a second data stream, the second data stream being a data stream corresponding to when the business system normally executes the target business, the threat information including at least one type of preset attack information; Obtaining a service completion degree of the target service executed by the service system based on the first data flow, where the service completion degree is used to indicate a degree of damage to the target service caused by the attack based on the preset attack information corresponding to the threat information; Performing a security assessment on the network range based on the business completion assessment; The obtaining of the service completion degree of the target service executed by the service system based on the first data flow includes: Determining an availability index of the target service based on the first data flow traversing a target node, where the target node is a node associated with the target service, and the availability index is used to represent a success rate of executing the target service based on the first data flow; determining an integrity indicator of the target service based on a frequency of data inconsistency occurring during transmission of the first data stream from a first node to a second node, where the first node is a starting point of the target service in the target node and the second node is an end point of the target service in the target node; determining a quality of service indicator of the target service based on a frequency of service anomalies occurring during transmission of the first data stream from the first node to the second node; The service completion degree is obtained based on the availability indicator, the integrity indicator and the service quality indicator.

2. The method according to claim 1, characterized in that The first data stream includes first attack data corresponding to each type of preset attack information, the first attack data includes first attack information and the second data stream, and the first attack information is any type of the preset attack information; The determining the availability index of the target service based on the first data flow traversing the target node includes: For each first attack data, obtaining a first defense result of the first attack data, the first defense result including a first status of each target node, the first status being used to indicate whether the corresponding target node successfully defends against the first attack information; wherein, if the first status of at least one target node indicates that the corresponding target node successfully defends against the first attack information, the first defense result indicates that the business system successfully executes the target business; and if the first status of all target nodes indicates that the corresponding target nodes fail to successfully defend against the first attack information, the first defense result indicates that the business system fails to successfully execute the target business. Building a threat defense matrix based on the first defense result corresponding to each type of preset attack information and the first attack data corresponding to each type of preset attack information; An availability indicator of the target service is determined according to the threat defense matrix.

3. The method according to claim 1, characterized in that Before injecting the first data stream into the business system deployed in the network target range, the method further includes: Deploying the business system in a network model of the network range based on virtualization technology, and defining processing rules for a physical layer, a network layer, and a data flow layer in the network model, wherein the network model includes the physical layer, the network layer, and the data flow layer, the physical layer is used to establish a physical connection channel between the target nodes, the network layer is used to connect the physical layer and the data flow layer, and the data flow layer is used to process data flows; The second data flow is derived according to the processing rules of the physical layer, the processing rules of the network layer, the processing rules of the data flow layer, and the target service.

4. The method according to claim 1, wherein The obtaining of the service completion degree based on the availability indicator, the integrity indicator, and the service quality indicator includes: Determining weight information, the weight information including a first weight corresponding to the availability indicator, a second weight corresponding to the integrity indicator, and a third weight corresponding to the service quality indicator; The service completion degree is obtained according to the weight information, the availability index, the integrity index and the service quality index.

5. The method according to claim 1, wherein After obtaining the service completion degree based on the availability indicator, the integrity indicator, and the service quality indicator, the method further includes: determining a first contribution of each target node in each target node based on the availability index, wherein the first contribution of a third node is proportional to a defense capability of the third node against the preset attack information; determining a second contribution of each target node in each target node based on the integrity index, wherein the second contribution of the third node is proportional to the integrity of the target service when the third node processes the target service; determining a third contribution of each target node in each target node based on the service quality indicator, where the third contribution of the third node is proportional to the service quality of the target service when the third node processes the target service; The third node is any one of the target nodes.

6. A security assessment device for a network range, characterized in that: The device comprises: An injection module is configured to inject a first data stream into a business system deployed in a network range, the first data stream being obtained by performing extended processing based on threat information and a second data stream, the second data stream being a data stream corresponding to the business system normally executing a target business, the threat information including at least one type of preset attack information; an acquisition module, configured to acquire a service completion degree of the target service executed by the service system based on the first data flow, wherein the service completion degree is used to indicate a degree of damage to the target service caused by the attack based on the preset attack information corresponding to the threat information; An evaluation module, configured to perform a security evaluation on the network range based on the business completion evaluation; The acquisition module is specifically used to: Determining an availability index of the target service based on the first data flow traversing a target node, where the target node is a node associated with the target service, and the availability index is used to represent a success rate of executing the target service based on the first data flow; determining an integrity indicator of the target service based on a frequency of data inconsistency occurring during transmission of the first data stream from a first node to a second node, where the first node is a starting point of the target service in the target node and the second node is an end point of the target service in the target node; determining a quality of service indicator of the target service based on a frequency of service anomalies occurring during transmission of the first data stream from the first node to the second node; The service completion degree is obtained based on the availability indicator, the integrity indicator and the service quality indicator.

7. An electronic device, characterized in that: Including transceiver and processor, The processor is configured to inject a first data stream into a business system deployed in a network target range, the first data stream being obtained by performing expansion processing based on threat information and a second data stream, the second data stream being a data stream corresponding to when the business system normally executes a target business, the threat information including at least one type of preset attack information; The transceiver is configured to obtain a service completion degree of the target service executed by the service system based on the first data flow, wherein the service completion degree is used to indicate a degree of damage to the target service caused by the attack based on the preset attack information corresponding to the threat information; The processor is further configured to perform a security assessment on the network range based on the business completion assessment; The obtaining of the service completion degree of the target service executed by the service system based on the first data flow includes: Determining an availability index of the target service based on the first data flow traversing a target node, where the target node is a node associated with the target service, and the availability index is used to represent a success rate of executing the target service based on the first data flow; determining an integrity indicator of the target service based on a frequency of data inconsistency occurring during transmission of the first data stream from a first node to a second node, where the first node is a starting point of the target service in the target node and the second node is an end point of the target service in the target node; determining a quality of service indicator of the target service based on a frequency of service anomalies occurring during transmission of the first data stream from the first node to the second node; The service completion degree is obtained based on the availability indicator, the integrity indicator and the service quality indicator.

8. An electronic device, characterized in that: include: A processor, a memory, and a program stored in the memory and executable on the processor, wherein when the program is executed by the processor, the steps of the network range security assessment method according to any one of claims 1 to 5 are implemented.

9. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, which, when executed by a processor, implements the steps of the network range security assessment method according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Data security assessment method and system based on application scene

    CN119293782A

  • System and method for managing and evaluating security in industry control network

    KR1020170091989A