Defense efficiency verification method and verification system for series-connection multi-safety equipment

By sending test vectors to multiple security devices in series and analyzing logs, the problem that the existing technology cannot evaluate the defense situation of each device is solved, and the precise positioning of attack blocking positions and accurate determination of equipment performance is achieved, and the optimization of security policies and device configuration is supported.

CN120389875APending Publication Date: 2025-07-29BEIJING HUAYUNAN INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510306371.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-14
Publication Date
2025-07-29

AI Technical Summary

Technical Problem

Existing security effectiveness verification techniques can only verify the defense capabilities of the entire link and cannot evaluate the defense status of each device in it.

Method used

Through the attack simulation module, multiple test vectors are sent to the attack receiving module, so that they are processed in sequence through series multiple security devices, obtain the logs of each module, and use the PTP protocol to time stamp the logs, calculate the global interception rate and the independent detection rate of a single device to determine the overall defense performance of the series multiple security devices and the defense performance of a single security device.

Benefits of technology

It realizes precise positioning of the attack blocking position, and while determining the overall defense effectiveness of series multi-security devices, it accurately determines the actual interception effect of each security device in the series link, supporting the optimization of security policies and the adjustment of equipment configuration.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120389875A_ABST
    Figure CN120389875A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a defense efficiency verification method and verification system for serial multi-security equipment, and is applied to the technical field of network security. The method comprises the following steps: sending a plurality of test vectors to the attack receiving module based on the attack simulation module, so that the plurality of test vectors are sequentially processed by the serial multi-security equipment; and acquiring logs of the attack simulation module, the serial multi-security device and the attack receiving module, and determining the overall defense efficiency of the serial multi-security device and the defense efficiency of a single security device. In this way, the problem that the existing security validity verification technology can only verify the defense capability of the whole link and cannot evaluate the defense condition of each device can be solved, so that the attack blocking position can be accurately positioned, and the defense efficiency of the serial multi-security device can be further improved while the overall defense efficiency of the serial multi-security device is determined. And the actual interception effect of each safety device in the series link is accurately judged.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of network security technologies, and in particular, to a method and system for verifying the defense effectiveness of a series of multiple security devices. Background Art

[0002] Security effectiveness verification is to construct various types of actual attack methods through intrusion and attack simulation technologies, conduct comprehensive simulation attack verification on various security protection measures and rule strategies deployed by enterprises, and evaluate the protection effect of the network security in-depth protection system through the collection and analysis of attack results, making the security protection visible.

[0003] Generally, security protection devices such as firewalls, IPSs, and WAFs are connected in series at the enterprise network boundary. The current security effectiveness verification technology can only verify the defense capabilities of the entire link and cannot evaluate the defense situation of each device therein. Therefore, a method that can analyze the defense situation of each security device while verifying the defense capabilities of the link is needed. Summary of the Invention

[0004] The present disclosure provides a method and system for verifying the defense effectiveness of a series of multiple security devices, which solves the technical problem that the existing security effectiveness verification technology can only verify the defense capabilities of the entire link and cannot evaluate the defense situation of each device therein.

[0005] According to a first aspect of the present disclosure, there is provided a method for verifying the defense effectiveness of a series of multiple security devices, wherein the series of multiple security devices are located between an attack simulation module and an attack receiving module. The method includes:

[0006] Sending a plurality of test vectors from the attack simulation module to the attack receiving module, so that the plurality of test vectors are sequentially processed by the series of multiple security devices;

[0007] Obtaining the logs of the attack simulation module, the series of multiple security devices, and the attack receiving module, and determining the overall defense effectiveness of the series of multiple security devices and the defense effectiveness of a single security device.

[0008] As described above in the aspect and any possible implementation manner, a further implementation manner is provided, where the step of sequentially processing the plurality of test vectors by the series of multiple security devices includes:

[0009] The series of multiple security devices process the plurality of test vectors based on a preset security policy. If an interception is triggered, the reason for the interception is determined, the corresponding test vector information and interception keywords are recorded in the log, and an HTTP response packet containing the device interception feature is generated and fed back to the attack simulation module; if no interception is triggered, the test vector is allowed to continue to be forwarded to the downstream device.

[0010] For the aspects and any possible implementation manners described above, a further implementation manner is provided. The obtaining of the logs of the attack simulation module, the series-connected multiple security devices, and the attack receiving module includes:

[0011] Based on the PTP protocol, perform timestamp alignment on the obtained logs of the attack simulation module, the series-connected multiple security devices, and the attack receiving module, and associate the sending, interception, and capture records of the same test vector.

[0012] For the aspects and any possible implementation manners described above, a further implementation manner is provided. The determining of the overall defense effectiveness of the series-connected multiple security devices includes:

[0013] Based on the logs of the attack simulation module and the logs of the attack receiving module, obtain the total number of test vectors sent by the attack simulation module and the number of un-intercepted test vectors captured by the attack receiving module, and then calculate the global interception rate.

[0014] For the aspects and any possible implementation manners described above, a further implementation manner is provided. The determining of the defense effectiveness of a single security device includes:

[0015] Based on the logs of the series-connected multiple security devices, obtain the total number of valid test vectors reaching each security device and the number of test vector interceptions of each security device, and then calculate the independent detection rate of a single security device.

[0016] For the aspects and any possible implementation manners described above, a further implementation manner is provided. The obtaining of the number of test vector interceptions of each security device includes:

[0017] Based on the logs of the series-connected multiple security devices, determine whether there are interception keywords corresponding to multiple test vector identifiers in the logs of each security device. If so, further determine whether the HTTP response packets received by the attack simulation module contain features generated by the corresponding security device interception. If so, determine that the test vector is successfully intercepted by the security device, and then obtain the number of test vector interceptions of each security device.

[0018] According to the second aspect of the present disclosure, a defense effectiveness verification system for series-connected multiple security devices is provided, wherein the series-connected multiple security devices are located between the attack simulation module and the attack receiving module. The system includes:

[0019] A defense effectiveness test module, configured to send multiple test vectors from the attack simulation module to the attack receiving module, so that the multiple test vectors are sequentially processed by the series-connected multiple security devices;

[0020] A defense effectiveness evaluation module, configured to obtain the logs of the attack simulation module, the series-connected multiple security devices, and the attack receiving module, and determine the overall defense effectiveness of the series-connected multiple security devices and the defense effectiveness of a single security device.

[0021] According to a third aspect of the present disclosure, there is provided an electronic device. The electronic device includes: a memory and a processor, where a computer program is stored on the memory, and when the processor executes the program, the methods described above are implemented.

[0022] According to a fourth aspect of the present disclosure, there is provided a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, the methods according to the first aspect and / or the second aspect of the present disclosure are implemented.

[0023] In the embodiments of the present disclosure, by sending a plurality of test vectors from the attack simulation module to the attack receiving module, the plurality of test vectors are sequentially processed by the series-connected multiple security devices; the logs of the attack simulation module, the series-connected multiple security devices, and the attack receiving module are obtained, and the overall defense effectiveness of the series-connected multiple security devices and the defense effectiveness of a single security device are determined. In this way, the problem that the existing security effectiveness verification technology can only verify the defense ability of the entire link and cannot evaluate the defense situation of each device therein can be solved, so that it can not only accurately locate the attack blocking position, but also accurately determine the actual interception effect of each security device in the series link while determining the overall defense effectiveness of the series-connected multiple security devices.

[0024] It should be understood that the content described in the summary of the invention is not intended to limit the key or important features of the embodiments of the present disclosure, nor is it used to limit the scope of the present disclosure. Other features of the present disclosure will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] In combination with the drawings and with reference to the following detailed description, the above and other features, advantages, and aspects of the embodiments of the present disclosure will become more apparent. The drawings are used to better understand the solution and do not constitute a limitation to the present disclosure. In the drawings, the same or similar reference numerals denote the same or similar elements, where:

[0026] Figure 1 shows a flowchart of a method for verifying the defense effectiveness of a series-connected multiple security devices provided by an embodiment of the present disclosure;

[0027] Figure 2 shows Figure 1 a schematic diagram of an interaction method between the attack simulation module, the series-connected multiple security devices, and the attack receiving module shown in

[0028] Figure 3Shows a structural diagram of a defense effectiveness verification system for a series of multiple security devices provided by an embodiment of the present disclosure;

[0029] Figure 4 Shows a structural diagram of an exemplary electronic device capable of implementing an embodiment of the present disclosure. Detailed implementation manners

[0030] To make the objectives, technical solutions, and advantages of the embodiments of the present disclosure clearer, the technical solutions in the embodiments of the present disclosure will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present disclosure. Apparently, the described embodiments are some but not all of the embodiments of the present disclosure. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present disclosure without creative efforts shall fall within the protection scope of the present disclosure.

[0031] In addition, the term "and / or" in this document merely describes an association relationship between associated objects, indicating that three relationships may exist. For example, A and / or B may represent: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " in this document generally represents an "or" relationship between the associated objects before and after.

[0032] In the embodiments of the present disclosure, by sending a plurality of test vectors from the attack simulation module to the attack receiving module, the plurality of test vectors are sequentially processed by the series of multiple security devices; the logs of the attack simulation module, the series of multiple security devices, and the attack receiving module are obtained, and the overall defense effectiveness of the series of multiple security devices and the defense effectiveness of each individual security device are determined. In this way, the problem that the existing security effectiveness verification technology can only verify the defense ability of the entire link and cannot evaluate the defense situation of each device therein can be solved, so that it can not only accurately locate the attack blocking position, but also accurately determine the actual interception effect of each security device in the series link while determining the overall defense effectiveness of the series of multiple security devices.

[0033] Figure 1 Shows a flowchart of a defense effectiveness verification method for a series of multiple security devices provided by an embodiment of the present disclosure. As Figure 1 shown, a defense effectiveness verification method 100 for a series of multiple security devices may include the following steps:

[0034] S110, based on the attack simulation module, send a plurality of test vectors to the attack receiving module, so that the plurality of test vectors are sequentially processed by the series of multiple security devices.

[0035] Exemplarily, first, the attack simulation module generates a series of test vectors with specific characteristics and behavior patterns based on preset attack scenarios and test targets. Each test vector contains a specific attack payload and a corresponding identifier to accurately identify and track in subsequent processes.

[0036] Secondly, the attack simulation module sends multiple test vectors to the attack receiving module in a certain order and time interval. During the sending process, the sending time, content, and relevant status information of each test vector are recorded to form detailed log data, providing a basis for subsequent effectiveness evaluation.

[0037] Finally, the attack simulation module receives the HTTP response packets generated when the series of security devices intercept the test vectors, parses and processes these feedback messages, extracts key information such as device interception characteristics and interception reasons, and associates them with the corresponding test vectors to further improve the log record of the attack simulation module.

[0038] Exemplarily, the attack simulation module can dynamically generate test vectors based on the Markov chain model to simulate the randomness and complexity of real attack traffic. Among them, the types of the test vectors can include basic web security protection, vulnerability virtual patching, sensitive information leakage protection, CC malicious attack protection, crawler protection, etc.

[0039] Exemplarily, a series of security devices are connected in series according to the actual network architecture, and parameters such as device names, IP addresses, access data sources, log parsing rules, and interception keywords are configured.

[0040] Exemplarily, the attack receiving module is mainly used to receive the test vectors that are not intercepted after being processed by the series of security device protection systems. When an un-intercepted test vector arrives, the attack receiving module immediately captures and records the detailed information of the test vector, including the receiving time, content, source IP address, etc., to form a complete capture record log.

[0041] S111, in some embodiments, the step of making the series of security devices process the multiple test vectors in sequence includes:

[0042] The series of security devices process the multiple test vectors based on preset security policies. If an interception is triggered, the interception reason is determined, the corresponding test vector information and interception keywords are recorded in the log, and an HTTP response packet containing device interception characteristics is generated and fed back to the attack simulation module; if no interception is triggered, the test vector is allowed to continue forwarding to downstream devices.

[0043] Exemplarily, before the series-connected multiple security devices process multiple test vectors based on a preset security policy, the method further includes: for each security device, parsing the generated alarm and interception log formats, and then identifying the fields recording the interception behavior, so as to determine specific interception keywords based on the feature fields in the logs.

[0044] S120, obtain the logs of the attack simulation module, the series-connected multiple security devices, and the attack receiving module, and determine the overall defense effectiveness of the series-connected multiple security devices and the defense effectiveness of a single security device.

[0045] Exemplarily, a defense effectiveness verification platform can be set up to obtain the logs of the attack simulation module, the series-connected multiple security devices, and the attack receiving module, and in the defense effectiveness verification platform, configure the corresponding interception keywords and associated fields for each device separately. For example, if the interception behavior in the device log is represented by the reject value of the action field, then the field action = reject needs to be configured as the interception rule for this device.

[0046] Exemplarily, based on the upstream and downstream relationships of the security devices, specify the access data sources and parsing rules of the device logs, and calibrate the time deviation to ensure that the log timestamps are consistent with the attack test time and avoid misjudgment.

[0047] S121, in some embodiments, the obtaining the logs of the attack simulation module, the series-connected multiple security devices, and the attack receiving module includes:

[0048] Perform timestamp alignment on the obtained logs of the attack simulation module, the series-connected multiple security devices, and the attack receiving module based on the PTP protocol, and associate the sending, interception, and capture records of the same test vector.

[0049] Exemplarily, deploy a PTP (Precision Time Protocol) master clock server in the network to ensure that the attack simulation module, the series-connected multiple security devices (such as firewalls, IPSs, WAFs), and the attack receiving module are all connected to the same PTP domain, and enable the PTP protocol for each device to calibrate the hardware clock to ensure that the timestamp error of each device is less than 1 millisecond.

[0050] Exemplarily, when the attack simulation module sends a test vector, it will record the sending timestamp and the unique test vector identifier (TestID). When each security device generates a log, it automatically attaches the local timestamp after PTP synchronization and records the associated TestID. After the attack receiving module captures the test vector, it records the receiving timestamp and the corresponding TestID.

[0051] After the defense effectiveness verification platform aggregates all the above logs, it groups them by TestID and aligns the sending, interception (device logs of each device), and receiving records of the same test vector in chronological order using the PTP timestamp. If the time deviation is found to exceed the preset threshold (such as ±5 milliseconds), an alarm is triggered and the device clock configuration is manually verified.

[0052] S122, in some embodiments, the determining the overall defense effectiveness of the series-connected multiple security devices includes:

[0053] Based on the logs of the attack simulation module and the logs of the attack receiving module, obtain the total number of test vectors sent by the attack simulation module and the number of un-intercepted test vectors captured by the attack receiving module, and then calculate the global interception rate.

[0054] Exemplarily, extract all the sent test vectors from the logs of the attack simulation module, count the total number, denoted as: N total ; extract all the successfully arrived test vectors (i.e., not intercepted by any device) from the logs of the attack receiving module, count their number, denoted as: N breached Then the formula for calculating the global interception rate is as follows:

[0055]

[0056] S123, in some embodiments, the determining the defense effectiveness of a single security device includes:

[0057] Based on the logs of the series-connected multiple security devices, obtain the total number of effective test vectors arriving at each security device and the number of test vector interceptions of each security device, and then calculate the independent detection rate of each security device.

[0058] In some embodiments, the obtaining the number of test vector interceptions of each security device includes:

[0059] Based on the logs of the series-connected multiple security devices, determine whether there are interception keywords corresponding to multiple test vector identifiers in the logs of each security device. If so, further determine whether the HTTP response packet received by the attack simulation module contains the characteristics generated by the corresponding security device interception. If so, determine that the test vector is successfully intercepted by the security device, and then obtain the number of test vector interceptions of each security device.

[0060] Exemplarily, for each security device (such as device A), screen out all the test vectors passing through the security device from the logs, count the number and denote it as: N A_input; If the log of device A contains records with intercepted keywords (such as action=reject), and the HTTP response packet received by the attack simulation module contains the interception feature generated by device A, then it is determined that the test vector is successfully intercepted by device A, and the number of test vectors that meet the above conditions simultaneously is counted and denoted as: N A_blocked ; Then the calculation formula for the independent detection rate is as follows:

[0061]

[0062] In the embodiments of the present disclosure, by sending multiple test vectors from the attack simulation module to the attack receiving module, the multiple test vectors are sequentially processed by the series-connected multiple security devices; the logs of the attack simulation module, the series-connected multiple security devices, and the attack receiving module are obtained to determine the overall defense effectiveness of the series-connected multiple security devices and the defense effectiveness of each individual security device. In this way, the problem that the existing security effectiveness verification technology can only verify the defense ability of the entire link and cannot evaluate the defense situation of each device therein can be solved, so that it can not only accurately locate the attack blocking position, but also accurately determine the actual interception effect of each security device in the series link while determining the overall defense effectiveness of the series-connected multiple security devices.

[0063] The following combines a specific embodiment, such as Figure 2 shown, to elaborate in detail on a defense effectiveness verification method 100 for series-connected multiple security devices provided by the embodiments of the present disclosure, specifically as follows:

[0064] In an actual application scenario, an enterprise deployed multiple security devices, including a firewall, an intrusion detection system (IDS), and a web application firewall (WAF), etc., to protect the security of its network system. These devices are connected in series at the boundary of the enterprise network and are located between the attack simulation module and the attack receiving module. Among them, the attack simulation module is a security test server within the enterprise, and the attack receiving module is a target machine server within the enterprise.

[0065] The defense effectiveness verification platform controls the attack simulation module to send multiple test vectors to the attack receiving module according to a preset test plan. These test vectors cover common network attack types, such as SQL injection, cross-site scripting attack (XSS), port scanning, etc. The multiple test vectors are sequentially processed by the series-connected firewall, IDS, and WAF. Among them,

[0066] First, the firewall performs preliminary traffic filtering on multiple test vectors according to the preset security policies. For test vectors that do not conform to the rules allowing passage, such as access requests from malicious IP addresses, they are directly intercepted, and the reasons for interception, the corresponding test vector information, and interception keywords such as "illegal IP address" are recorded in the log. At the same time, an HTTP response packet containing the device interception characteristics is generated and fed back to the attack simulation module.

[0067] Secondly, the IDS performs in-depth detection on the test vectors passing through the firewall, analyzing abnormal behaviors and potential threats in the traffic. For example, if a test vector with port scanning characteristics is detected, an interception operation is triggered, and relevant log information is recorded, including the characteristics of the test vector and the reason for interception (port scanning behavior). At the same time, an HTTP response packet containing the device interception characteristics is generated and fed back to the attack simulation module.

[0068] Finally, the WAF focuses on protecting test vectors at the web application layer. When attack test vectors targeting web applications such as SQL injection and XSS are detected, they are intercepted according to the security policies, and detailed logs are recorded, indicating the reasons for interception (such as SQL injection attack or XSS attack), and an HTTP response packet is fed back to the attack simulation module. If the test vector is not intercepted by any of the above security devices, it is allowed to continue forwarding to downstream devices and finally reach the attack receiving module.

[0069] The defense effectiveness verification platform collects the log information of the attack simulation module, firewall, IDS, WAF, and attack receiving module through network protocols, and uses the PTP protocol to align the timestamps of the obtained logs to ensure that the sending, interception, and capture records of the same test vector between different devices or modules can be accurately correlated.

[0070] First, the defense effectiveness verification platform can obtain the total number of sent test vectors based on the log of the attack simulation module, assumed to be 1000; at the same time, obtain the number of un-intercepted test vectors captured from the log of the attack receiving module, such as 100; and then the global interception rate can be calculated, that is This is used to measure the overall defense effectiveness of cascaded multiple security devices.

[0071] Secondly, the defense effectiveness verification platform can determine its defense effectiveness by analyzing the log of a certain security device, specifically as follows: The defense effectiveness verification platform obtains the total number of valid test vectors reaching the firewall by viewing the log of the firewall, assumed to be 1000 (since the firewall is the first security device, the total number of valid test vectors reaching is the same as the total number sent by the attack simulation module), and the number of test vectors intercepted by the firewall, such as 200, and then calculates the

[0072] Finally, the defense effectiveness verification platform can determine the interception device of a certain test vector based on the device logs of security devices and the features generated by the interception of corresponding security devices contained in the HTTP response packets received by the attack simulation module.

[0073] Based on the above detection results, enterprise security managers can have a clear understanding of the defense effectiveness of multiple serially-connected security devices. If the global interception rate fails to reach the expected target, or if it is found that the detection rate of a single security device is too low, the reasons can be further analyzed, such as unreasonable security policy configuration, insufficient device performance, etc. Then, the security policy can be adjusted, the device configuration can be optimized, or the device can be upgraded accordingly to enhance the defense ability of the entire network system.

[0074] According to the embodiments of the present disclosure, the following technical effects are achieved:

[0075] (1) Through the verification of the defense effectiveness of multiple serially-connected security devices, the protection effects of different devices at different positions can be understood, providing a reference for optimizing the deployment scheme of security devices. For example, it can be determined which devices need to be deployed closer to the attack source and which devices are more suitable for deployment closer to the protected resources.

[0076] (2) Not only can the overall defense effectiveness of multiple serially-connected security devices be determined, but also the actual interception effects of each security device in the serial link can be accurately judged. Moreover, by analyzing the independent detection rate and global interception rate of a single security device, problems existing in the security policy can be discovered, providing a basis for adjusting the security policy and making the policy adjustment more targeted.

[0077] (3) By calculating the independent detection rate of a single security device, not only can the weak protection links in multiple serially-connected security devices be accurately located, but also the attack blocking position of a certain test vector can be accurately located.

[0078] It should be noted that for the foregoing method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that the present disclosure is not limited by the described action sequence, because according to the present disclosure, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all optional embodiments, and the actions and modules involved are not necessarily essential to the present disclosure.

[0079] The above is the introduction of the method embodiments. The following further illustrates the solution of the present disclosure through device embodiments.

[0080] Figure 3 The structure diagram of a defense effectiveness verification system for multiple serially-connected security devices provided by the embodiments of the present disclosure is shown asFigure 3 As shown in Figure 3 , a defense effectiveness verification system 300 for a series of multiple security devices may include:

[0081] A defense effectiveness test module 310, configured to send multiple test vectors to the attack receiving module based on the attack simulation module, so that the multiple test vectors are sequentially processed by the series of multiple security devices;

[0082] A defense effectiveness evaluation module 320, configured to obtain the logs of the attack simulation module, the series of multiple security devices, and the attack receiving module, and determine the overall defense effectiveness of the series of multiple security devices and the defense effectiveness of a single security device.

[0083] It can be understood that Figure 3 each module in the defense effectiveness verification system 300 for a series of multiple security devices shown in Figure 3 has the functions of implementing Figure 1 each step in the defense effectiveness verification method 100 for a series of multiple security devices shown in Figure 1 , and can achieve its corresponding technical effects. For the sake of brevity, details are not described herein again.

[0084] Figure 4 The figure shows a structural diagram of an exemplary electronic device capable of implementing the embodiments of the present disclosure. The electronic device 400 is intended to represent various forms of digital computers, such as, a laptop computer, a desktop computer, a workbench, a personal digital assistant, a server, a blade server, a mainframe computer, and other suitable computers. The electronic device 400 may also represent various forms of mobile devices, such as, a personal digital processor, a cellular phone, a smart phone, a wearable device, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples, and are not intended to limit the implementation of the present disclosure described and / or claimed herein.

[0085] As Figure 4 shown in Figure 4 , the electronic device 400 may include a computing unit 401, which may perform various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) 402 or a computer program loaded from a storage unit 408 into a random access memory (RAM) 403. In the RAM 403, various programs and data required for the operation of the electronic device 400 may also be stored. The computing unit 401, the ROM 402, and the RAM 403 are connected to each other through a bus 404. An input / output (I / O) interface 405 is also connected to the bus 404.

[0086] Multiple components in the electronic device 400 are connected to the I / O interface 405, including: an input unit 406, such as a keyboard, a mouse, etc.; an output unit 407, such as various types of displays, speakers, etc.; a storage unit 408, such as a disk, an optical disc, etc.; and a communication unit 409, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 409 allows the electronic device 400 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.

[0087] The computing unit 401 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 401 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The computing unit 401 executes the various methods and processes described above, such as method 100. For example, in some embodiments, method 400 can be implemented as a computer program product, including a computer program, which is tangibly contained in a computer-readable medium, such as the storage unit 408. In some embodiments, part or all of the computer program can be loaded and / or installed onto the electronic device 400 via the ROM 402 and / or the communication unit 409. When the computer program is loaded into the RAM 403 and executed by the computing unit 401, one or more steps of the method 100 described above can be executed. Alternatively, in other embodiments, the computing unit 401 can be configured to execute method 100 in any other suitable manner (e.g., by means of firmware).

[0088] The various embodiments described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-chip (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: being implemented in one or more computer programs, which can be executed and / or interpreted on a programmable system including at least one programmable processor, the programmable processor can be a dedicated or general-purpose programmable processor, can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit the data and instructions to the storage system, the at least one input device, and the at least one output device.

[0089] The program code for implementing the methods of the present disclosure can be written in any combination of one or more programming languages. These program codes can be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the program codes are executed by the processor or controller, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The program codes can be executed entirely on the machine, partially on the machine, executed partially on the machine as an independent software package and partially on a remote machine, or executed entirely on a remote machine or server.

[0090] In the context of the present disclosure, a computer-readable medium can be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. A computer-readable medium can be a computer-readable signal medium or a computer-readable storage medium. A computer-readable medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of a computer-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0091] It should be noted that the present disclosure also provides a non-transitory computer-readable storage medium storing computer instructions, wherein the computer instructions are used to cause a computer to execute method 100 and achieve the corresponding technical effects achieved by the embodiments of the present disclosure in executing their methods. For the sake of brevity of description, it will not be elaborated herein.

[0092] In addition, the present disclosure also provides a computer program product, which includes a computer program that implements method 100 when executed by a processor.

[0093] In order to provide interaction with a user, the above-described embodiments can be implemented on a computer having: a display device for displaying information to the user (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor); and a keyboard and a pointing device (e.g., a mouse or a trackball) through which the user can provide input to the computer. Other kinds of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and the input received from the user can be in any form (including acoustic input, voice input, or tactile input).

[0094] The embodiments described above can be implemented in a computing system including backend components (e.g., as a data server), or a computing system including middleware components (e.g., an application server), or a computing system including frontend components (e.g., a user computer having a graphical user interface or a web browser through which a user can interact with embodiments of the systems and techniques described herein), or a computing system including any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected to each other by digital data communication in any form or medium (e.g., a communication network). Examples of communication networks include: local area network (LAN), wide area network (WAN), and the Internet.

[0095] The computer system can include a client and a server. The client and the server are generally far from each other and typically interact through a communication network. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, or a server of a distributed system, or a server incorporating blockchain.

[0096] It should be understood that various forms of the processes shown above can be used, with steps reordered, added, or deleted. For example, the steps recited in this disclosure can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solutions disclosed in this disclosure can be achieved, and this is not limited herein.

[0097] The above specific embodiments do not constitute a limitation on the protection scope of this disclosure. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this disclosure shall be included within the protection scope of this disclosure.

Claims

1. A defense effectiveness verification method for series-connected multiple security devices, wherein, The series multi-security device is located between the attack simulation module and the attack receiving module, and is characterized by including: Based on the attack simulation module sending multiple test vectors to the attack receiving module, enabling the multiple test vectors to be sequentially processed by the series multi-security device; Obtaining the logs of the attack simulation module, the series multi-security device, and the attack receiving module, and determining the overall defense effectiveness of the series multi-security device and the defense effectiveness of a single security device.

2. The method according to claim 1, wherein The enabling the multiple test vectors to be sequentially processed by the series multi-security device includes: The series multi-security device processes the multiple test vectors based on a preset security policy. If an interception is triggered, the reason for the interception is determined, the corresponding test vector information and interception keyword are recorded in the log, and an HTTP response packet containing the device interception feature is generated and fed back to the attack simulation module; if an interception is not triggered, the test vector is allowed to continue to be forwarded to the downstream device.

3. The method according to claim 2, wherein The obtaining the logs of the attack simulation module, the series multi-security device, and the attack receiving module includes: Based on the PTP protocol, timestamp alignment is performed on the obtained logs of the attack simulation module, the series multi-security device, and the attack receiving module, and the sending, interception, and capture records of the same test vector are associated.

4. The method according to claim 3, characterized in that, The determining the overall defense effectiveness of the series multi-security device includes: Based on the logs of the attack simulation module and the logs of the attack receiving module, obtaining the total number of test vectors sent by the attack simulation module and the number of un-intercepted test vectors captured by the attack receiving module, and then calculating the global interception rate.

5. The method according to claim 4, wherein The determining the defense effectiveness of a single security device includes: Based on the logs of the series multi-security device, obtaining the total number of valid test vectors reaching each security device and the number of test vector interceptions of each security device, and then calculating the independent detection rate of a single security device.

6. The method according to claim 5, characterized in that, The obtaining the number of test vector interceptions of each security device includes: Based on the logs of the series multi-security device, determining whether there is an interception keyword corresponding to multiple test vector identifiers in the logs of each security device. If so, further determining whether the HTTP response packet received by the attack simulation module contains the feature generated by the interception of the corresponding security device. If it contains, it is determined that the test vector is successfully intercepted by the security device, and then the number of test vector interceptions of each security device is obtained.

7. A defense effectiveness verification system for series-connected multiple security devices, wherein, The series multi-security device is located between the attack simulation module and the attack receiving module, and is characterized by including: A defense effectiveness test module for sending multiple test vectors to the attack receiving module based on the attack simulation module, enabling the multiple test vectors to be sequentially processed by the series multi-security device; A defense effectiveness evaluation module for obtaining the logs of the attack simulation module, the series multi-security device, and the attack receiving module, and determining the overall defense effectiveness of the series multi-security device and the defense effectiveness of a single security device.

8. An electronic device, including: At least one processor; And A memory communicatively connected to the at least one processor; wherein, The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the method according to any one of claims 1-6.

9. A non-transitory computer-readable storage medium storing computer instructions, wherein, The computer instructions are for causing the computer to execute the method according to any one of claims 1 to 6.