Method and system for flow replay automatic addressing in network security verification system
Through packet capture and connectivity test of the entire network port, the source IP and destination MAC addresses are automatically extracted, which solves the accuracy and efficiency of traffic playback in complex network environments, and realizes automated traffic playback operations.
Patent Information
- Application Number
- CN202510593148.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-09
- Publication Date
- 2025-07-29
AI Technical Summary
In complex network environments, the prior art cannot accurately select network interface cards and configure switches, resulting in traffic replay failure, affecting attack effect and efficiency.
By starting the full network packet capture task on the attacker simulator, sending connectivity test HTTP requests, parsing response messages, and automatically extracting the source IP and destination MAC addresses to achieve automatic addressing of traffic playback.
Improves the accuracy and efficiency of traffic playback, simplifies the operation process, avoids manual configuration errors, and is suitable for complex network scenarios.
Smart Images

Figure CN120389966A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a method and system for automatic addressing of traffic replay in a network security verification system, belonging to the technical field of network security. Background Art
[0002] The traffic replay technology is an attack means in the BAS security verification system. Based on the original traffic replay technology, it is extended and upgraded to enable security testing of any environment. For example, a method for execution and judgment of traffic replay in a network security verification system disclosed in patent document CN202311298175.0 can improve the efficiency of network environment security testing, increase the diversity and effectiveness of attack simulation of the BAS security verification system, as well as the scalability and usability of the system by not relying on the corresponding service and not requiring the construction of a dedicated test environment through the traffic replay technology.
[0003] The traffic replay technology relies on accurately modifying the source IP, destination IP, source MAC address, and destination MAC address in the traffic packet to ensure that the traffic can be accurately delivered to the attacker simulator end. When the attacker simulator executes a task, the received destination IP and destination MAC address are usually provided by the server, and these information are based on the MAC address reported during simulator registration. However, in an actual network environment, especially when there are multiple switches and firewalls, directly using the MAC address stored by the server for traffic replay may encounter challenges.
[0004] Due to the complexity of the network environment, the switch or firewall may not be able to find an entry in its address table that matches the MAC address in the traffic, resulting in the discarding of this traffic and thus affecting the success rate of traffic replay. To solve this problem, it is necessary to manually configure the MAC address for communication between the attacker simulator and the attacked simulator.
[0005] Specifically, the destination MAC address that the attacker simulator needs to configure should be the MAC address of the network interface corresponding to the first switch on the communication path between it and the attacked simulator. In this way, the attacker simulator first replays the traffic to this switch, and then the switch forwards the traffic according to the target address and finally delivers it to the attacked simulator. However, in a complex network environment where an attacker simulator may correspond to multiple attacked simulators, manually configuring the target MAC address each time is not only extremely difficult but also inefficient. In addition, this operation requires relevant personnel to have professional knowledge of switch configuration, firewall configuration, and other traffic forwarding tool configurations, which undoubtedly increases the complexity and difficulty of the operation.
[0006] In summary, the existing solutions have two problems when facing a complex network scenario as Figure 1 shown:
[0007] The primary problem lies in the insufficient specificity in specifying the target network card for traffic replay. In actual operations, traffic replay requires precisely selecting a specific network interface card (NIC) to perform the replay task. However, attacker simulators typically default to using their built-in NICs for traffic replay, and this behavior is particularly limited in complex network environments. When the attacker simulator is equipped with multiple NICs, and these NICs are respectively connected to different victim simulators through specific network connections, the problem becomes prominent. Due to the lack of a flexible and precise NIC selection mechanism, it is difficult for attackers to ensure that traffic can be accurately sent to the target victim simulator, which may lead to a significant reduction in the attack effect or even complete failure.
[0008] Secondly, the switch configuration in the network architecture poses another obstacle to traffic replay. Between the attacker simulator and the victim simulator, if there is a complex network topology composed of multiple switches, traffic must rely on the switch for correct routing and forwarding during transmission. However, when the switch cannot find an effective transmission path based on the target address of the traffic, this part of the traffic will be discarded by the switch and will not continue to be transmitted. This situation is particularly common in large or dynamically changing network environments, which directly results in the loss of attack traffic, thereby causing the simulated attack to fail to reach the expected target, and the attack thus fails. Summary of the Invention
[0009] Object of the Invention: Aiming at the problems existing in the above-mentioned prior art, the object of the present invention is to provide a method and system for automatic addressing of traffic replay in a network security verification system, so as to solve the problem that traffic replay in the BAS security verification system fails due to inaccurate address positioning in the face of complex network scenarios, thereby improving the accuracy and efficiency of traffic replay.
[0010] Technical Solution: To achieve the above object of the invention, the present invention adopts the following technical solutions:
[0011] In the first aspect, the present invention provides a method for automatic addressing of traffic replay in a network security verification system, including the following steps:
[0012] Start a full-network interface packet capture task on the attacker simulator;
[0013] The attacker simulator sends an HTTP request for connectivity test containing a random number parameter to the victim simulator;
[0014] After receiving the HTTP request for connectivity test, the victim simulator parses out the random number parameter and fills it into the response message and returns it to the attacker simulator;
[0015] The attacker simulator determines the connectivity test result according to the received response message;
[0016] After the connectivity test is successful, the attacker simulator stops the local packet capture task, parses the packet capture file, and finds the corresponding connectivity test packet according to the IP address of the attacked simulator and / or the random number parameter; extracts the source IP address from the connectivity test packet as the IP address of the network card for communication between the attacker simulator and the attacked simulator; traverses the local network cards according to the source IP address to obtain the corresponding network card name and source MAC address; extracts the destination MAC address from the connectivity test packet as the MAC address of the network port of the first switch or firewall through which the attacker simulator traffic passes.
[0017] Perform a traffic replay operation based on the obtained network card name, source IP address, source MAC address, and destination MAC address.
[0018] Preferably, the HTTP request type for the connectivity test is the GET type, and accesses a specified method on a specified port of the IP address of the attacked simulator with a random number parameter; the IP address of the attacked simulator is obtained from the server.
[0019] Preferably, the attacker simulator determines the connectivity test result according to the received response packet, including: first, judging whether the content of the response packet is empty. If it is empty, it is judged that the connectivity test fails, stops the local packet capture and deletes the packet capture file, and returns the result to the server; if it is not empty, it is judged whether the response body content of the response packet is consistent with the random number carried in the request packet. If it is inconsistent, it is also judged that the connectivity test fails, stops the local packet capture and deletes the packet capture file, and returns the result to the server; if it is consistent, it is judged that the connectivity test is successful.
[0020] Preferably, the source IP address extracted from the connectivity test packet is the source IP address in the request packet; the destination MAC address extracted from the connectivity test packet is the source MAC address in the response packet.
[0021] Preferably, the performing the traffic replay operation based on the obtained network card name, source IP address, source MAC address, and destination MAC address is to modify the SOURCE_IP, TARGET_IP, and the corresponding IP's MAC address in the traffic packet to the source IP address, the IP address of the attacked simulator, the source MAC address, and the destination MAC address, and send the traffic at the network port corresponding to the network card name.
[0022] In a second aspect, the present invention provides a system for automatic addressing of traffic replay in a network security verification system, including:
[0023] The full-network port packet capture module is used to start the full-network port packet capture task on the attacker simulator before the connectivity test; and stop the local packet capture task after the connectivity test is successful;
[0024] The connectivity test module is used for the attacker simulator to send an HTTP request for connectivity test containing a random number parameter to the attacked simulator; after receiving the HTTP request for connectivity test, the attacked simulator parses out the random number parameter and fills it into the response message and returns it to the attacker simulator; and the attacker simulator determines the connectivity test result according to the received response message;
[0025] The automatic extraction module is used to parse the packet capture file after the connectivity test is successful, find the corresponding connectivity test message according to the IP address of the attacked simulator and / or the random number parameter; extract the source IP address from the connectivity test message as the IP address of the network card for communication between the attacker simulator and the attacked simulator; traverse the local network cards according to the source IP address to obtain the corresponding network card name and source MAC address; extract the destination MAC address from the connectivity test message as the network port MAC address of the first switch or firewall through which the attacker simulator traffic passes;
[0026] The traffic replay module is used to perform traffic replay operations based on the obtained network card name, source IP address, source MAC address, and destination MAC address.
[0027] In a third aspect, the present invention provides a network security verification system, including a server, an attacker simulator, and an attacked simulator. The attacker simulator and the attacked simulator are used to perform traffic replay security verification tasks. The attacker simulator is further used to start the full-network port packet capture task before the connectivity test; send an HTTP request for connectivity test containing a random number parameter to the attacked simulator; determine the connectivity test result according to the received response message; and after the connectivity test is successful, stop the local packet capture task, parse the packet capture file, find the corresponding connectivity test message according to the IP address of the attacked simulator and / or the random number parameter; extract the source IP address from the connectivity test message as the IP address of the network card for communication between the attacker simulator and the attacked simulator; traverse the local network cards according to the source IP address to obtain the corresponding network card name and source MAC address; extract the destination MAC address from the connectivity test message as the network port MAC address of the first switch or firewall through which the attacker simulator traffic passes; perform traffic replay operations based on the obtained network card name, source IP address, source MAC address, and destination MAC address; the attacked simulator is further used to parse out the random number parameter and fill it into the response message and return it to the attacker simulator after receiving the HTTP request for connectivity test.
[0028] Further, an attacker simulator is respectively connected to different attacked simulator through multiple network cards on the host.
[0029] Beneficial effects: Through an accurate automatic addressing method, the present invention effectively solves the problem that traffic replay fails due to inaccurate address positioning in the face of complex network scenarios in the BAS security verification system, thereby significantly improving the accuracy and efficiency of traffic replay. Specifically, it is reflected in the following four points: 1. Automatic detection: Automatically detect the connectivity between the attacker simulator and the attacked simulator by sending connectivity test requests and capturing responses. 2. Whole-network port monitoring: Start the whole-network port packet capture task to ensure that all possible communication traffic can be captured, providing accurate data for subsequent network card selection and destination MAC address extraction. 3. Precise matching: By parsing the connectivity test packets, accurately extract the IP address of the communication network card and the destination MAC address, avoiding errors that may be caused by manual configuration. 4. Process simplification: The optimized solution aggregates steps such as connectivity test, network card selection, and destination MAC address extraction into an automated process, improving efficiency and accuracy. BRIEF DESCRIPTION OF THE DRAWINGS
[0030] Figure 1 It is a scenario diagram applicable to the embodiment of the present invention.
[0031] Figure 2 It is a schematic diagram of the processing flow at the attacker simulator end in the embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0032] Next, the technical solution of the present invention will be clearly and completely described in conjunction with the accompanying drawings and specific embodiments.
[0033] The embodiment of the present invention discloses a method for automatic addressing of traffic replay in a network security verification system, which optimizes the existing traffic replay technology. Through automatic addressing, the workload of manual configuration is reduced, and the convenience and efficiency of operation are improved. The automatic addressing in the embodiment of the present invention is a process of automatically parsing and determining the target address and source address of data packets according to specific algorithms and rules during the traffic replay process to achieve correct data transmission of traffic replay.
[0034] Specifically, aiming at the problems of traffic replay failure caused by the multi-network card problem of the attacker simulator and the manual configuration problem of the destination MAC address in the traffic replay technology, as Figure 2 shown, the method for automatic addressing of traffic replay in a network security verification system described in the embodiment of the present invention has the following detailed steps:
[0035] S101. Packet capture for all network interfaces. Before the attacker simulator sends a connectivity test HTTP request, the attacker simulator starts a packet capture task locally to capture the traffic packets of all network interfaces. After starting the packet capture task, it then sends a connectivity test HTTP request to the attacked simulator.
[0036] S102. Connectivity test. Before performing a traffic replay attack, the attacker simulator sends a connectivity test HTTP request (e.g., http: / / ip:port / ping?flag = <random number>) to the attacked simulator. Exemplarily, the type of this HTTP request is GET, the method name is ping, and it carries a random number between 1 and 1000 as the flag parameter.
[0037] S103. Response processing. After the attacked simulator receives the connectivity test HTTP request sent by the attacker, it determines whether the request method is ping. If it is, it parses the flag parameter and returns the flag parameter value as the response message body to the attacker simulator; if it is not a ping request, it executes other corresponding business logics.
[0038] S104. Packet verification. After the attacker simulator sends a connectivity test HTTP request, it receives the returned packet from the attacked simulator. First, it determines whether the content of the returned packet is empty. If it is empty, it determines that the connectivity test fails, stops the local packet capture and deletes the packet capture file, and returns the result to the server; if it is not empty, it determines whether the response body content of the response message is consistent with the flag value. If it is inconsistent, it also determines that the connectivity test fails, stops the local packet capture and deletes the packet capture file, and returns the result to the server; if they are consistent, it determines that the connectivity test is successful.
[0039] S105. Extract packets. After the connectivity test is successful, the attacker simulator stops the local packet capture and parses the packet capture file (tools such as PCAP4J can be used) to find the corresponding HTTP packet for the connectivity test. Specifically, packet matching can be performed according to the IP address of the attacked simulator and the flag parameter value.
[0040] S106. Determine the communication network card. According to the connectivity test packet, extract the source IP address in the request packet, and the extracted source IP address is the IP address of the network card through which the attacker simulator communicates with the attacked simulator.
[0041] S107. Network card name matching. According to the extracted source IP address, traverse the local network cards to find the network card name and the source MAC address corresponding to the IP.
[0042] S108. Extract the destination MAC address. Extract the source MAC address in the response packet according to the connectivity test packet as the destination MAC address. The extracted MAC address is the MAC address of the network interface of the first switch or firewall through which the attacker simulator traffic passes.
[0043] S109. According to the extracted network card name, source IP address, source MAC address, and destination MAC address, perform traffic replay.
[0044] Based on the above method for automatic addressing in traffic replay of a network security verification system, the execution steps of the traffic replay task in the network security verification system are as follows:
[0045] S201. Design the plan, and design the installation and deployment plan and the simulated attack plan according to the customer's protection strategy;
[0046] S202. Install and deploy, install and deploy the BAS system server and simulators (including the attacker simulator and the attacked simulator) in the specified network area;
[0047] S203. Configure the simulator roles, configure the simulator roles according to the attack plan and the network area where the simulator is located. The configurable roles are: attacker, attacked, asset protection detection, core data, mail application, etc. Different roles correspond to different installation verification directions and functions. The traffic replay script only needs to specify the roles of the attacker simulator and the attacked simulator;
[0048] S204. Create a task, select the traffic replay script, and select the attacker simulator and the attacked simulator;
[0049] S205. Assemble parameters, and assemble the script execution parameters according to the selected traffic replay script;
[0050] S206. Task dispatch, the attacker simulator periodically sends a task request to the server automatically. The server determines whether there is a task that needs to be executed by this simulator. If so, it returns the corresponding script information and execution parameter information;
[0051] S207. Task execution, after the attacker receives the traffic replay script task, the execution steps are as follows:
[0052] The first step: The attacker simulator starts the network interface packet capture task locally.
[0053] Step 2: The attacker simulator sends a connectivity test HTTP request http: / / ip:port / ping?flag=<random number> to the attacked simulator, where ip:port is the IP and port of the attacked simulator obtained from the server. The method name is ping, and a random number between 1 and 1000 is carried as the flag parameter.
[0054] Step 3: After receiving the connectivity test HTTP request sent by the attacker, the attacked simulator determines whether the request method is ping. If it is, it parses the flag parameter and returns the flag parameter value as the response body to the attacker simulator; if it is not a ping request, it executes other corresponding business logics.
[0055] Step 4: After sending the connectivity test HTTP request, the attacker simulator receives the response packet from the attacked simulator. First, it determines whether the content of the response packet is empty. If it is empty, it determines that the connectivity test fails, stops local packet capture and deletes the packet capture file, and returns the result to the server; if it is not empty, it determines whether the response body content of the response message is the same as the flag value. If they are not the same, it also determines that the connectivity test fails, stops local packet capture and deletes the packet capture file, and returns the result to the server; if they are the same, it determines that the connectivity test is successful.
[0056] Step 5: After the connectivity test is successful, the attacker simulator stops local packet capture and parses the packet capture file to find the corresponding HTTP request message for the connectivity test.
[0057] Step 6: Extract the source IP address in the HTTP request message as the IP address of the network card for communication between the attacker simulator and the attacked simulator.
[0058] Step 7: According to the extracted source IP address, traverse the local network cards to find the network card name and source MAC address corresponding to the IP.
[0059] Step 8: Extract the source MAC address in the HTTP response message as the destination MAC address.
[0060] Step 9: The attacker simulator modifies the traffic packets based on the extracted source IP address, source MAC address, and destination MAC address. It modifies the SOURCE_IP, TARGET_IP, and the MAC address of the corresponding IP in the traffic packets. After the modification, a new traffic packet file (hereinafter referred to as: execution packet) is generated. Based on the TCPREPLAY traffic tool and the PACP4J library in Java, the execution packet is split into attack traffic packet A and response traffic packet B (the advantage of splitting the traffic packet is that it can simplify the data processing of the traffic packet and improve the processing efficiency; the other is that it is convenient for filtering and selection, and the required packets can be quickly selected when in use).
[0061] Step 10: The attacker simulator uses Socket to send a notification to the attacked simulator and encrypts and sends the response traffic packet B to the attacked simulator, notifying the attacked simulator to start the packet capture task. The attacked simulator decrypts the encrypted file locally and starts the packet capture service to prepare to receive the attack traffic packets sent by the attacker simulator (the attacked simulator only captures the attack traffic sent by the attacker simulator to avoid redundant traffic data from slowing down the execution efficiency). After the packet capture service starts successfully, it notifies the attacker simulator that it is ready and the attack task can be executed.
[0062] Step 11: After receiving the notification that the attacked simulator is ready, the attacker simulator starts the local packet capture service (only captures the traffic packets of the attacked simulator) and starts to send the attack traffic packet A to the attacked simulator.
[0063] Step 12: The attacked simulator obtains the attack traffic packet A from the attacker simulator, obtains the response packet of the traffic, and sends the corresponding response traffic packet B to the attacker simulator. If no match is found, no operation is performed.
[0064] Step 13: After the attacker simulator finishes executing the attack task, it notifies the attacked simulator to end the packet capture, return the packet file C, and delete the local response traffic packet B. After receiving the packet file C returned by the attacked simulator, the attacker simulator stops the local packet capture, generates the packet file D, and deletes the attack traffic packet A.
[0065] Step 14: Result judgment. The attacker simulator compares the attacker simulator packet file and the attacked simulator packet file based on the execution packet, which is divided into several scenarios:
[0066] a. If all the content of the packet sending and packet returning in the execution packet matches the attacker simulator in the packet file D, that is, the attack is successful, and the result is judged as not intercepted;
[0067] b. If the execution message matches the packet - sending content of the attacker simulator in message file D and fails to match the packet - returning content, then match the attacker simulator message file C. If the execution message matches the packet - sending content of the attacker simulator in message file C, it is determined that the attack traffic message A has reached the attacked simulator, but the response traffic message B fails to return a packet, and the result is determined as a warning.
[0068] c. If the execution message A matches the packet - sending content of the attacker simulator in message file D and fails to match the packet - returning content, then match the attacker simulator of message file C. If the execution message A fails to match the packet - sending content of the attacker simulator in message file C, it is determined that the attack traffic message A cannot reach the attacked simulator, and the result is determined as a block.
[0069] Step 16: The result judgment is completed, and the execution result, as well as the attacker simulator message files C and D of the attacker simulator, are returned to the security verification system (the purpose of returning the messages during the execution process of the attacker simulator and the attacked simulator to the security verification system is to corroborate the script execution result and provide a basis for result judgment).
[0070] S208. The task execution is completed, and a test report is generated.
[0071] Based on the same inventive concept, a system for automatic addressing of traffic replay in a network security verification system disclosed in an embodiment of the present invention includes:
[0072] A full - network - port packet - capturing module, which is used to start a full - network - port packet - capturing task on the attacker simulator before the connectivity test; and stop the local packet - capturing task after the connectivity test is successful;
[0073] A connectivity test module, which is used for the attacker simulator to send an HTTP request for connectivity test containing a random - number parameter to the attacked simulator; after receiving the HTTP request for connectivity test, the attacked simulator parses out the random - number parameter and fills it into the response message and returns it to the attacker simulator; and the attacker simulator determines the connectivity test result according to the received response message;
[0074] An automatic extraction module, which is used to parse the packet - capturing file after the connectivity test is successful, find the corresponding connectivity test message according to the IP address of the attacked simulator and / or the random - number parameter; extract the source IP address from the connectivity test message as the IP address of the network card for communication between the attacker simulator and the attacked simulator; traverse the local network cards according to the source IP address to obtain the corresponding network card name and source MAC address; extract the destination MAC address from the connectivity test message as the network - port MAC address of the first switch or firewall through which the attacker simulator traffic passes;
[0075] A traffic replay module for performing traffic replay operations based on the obtained network card name, source IP address, source MAC address, and destination MAC address.
[0076] On the basis of the foregoing embodiments, an embodiment of the present invention further discloses a network security verification system, including a server, an attacker simulator, and a victim simulator. The attacker simulator and the victim simulator are used to perform traffic replay security verification tasks. The attacker simulator is further configured to start a full-network interface packet capture task before the connectivity test; send an HTTP request for connectivity test containing a random number parameter to the victim simulator; determine the connectivity test result according to the received response message; and after the connectivity test is successful, stop the local packet capture task, parse the packet capture file, find the corresponding connectivity test message according to the victim simulator IP address and / or random number parameter; extract the source IP address from the connectivity test message as the IP address of the network card for communication between the attacker simulator and the victim simulator; traverse the local network cards according to the source IP address to obtain the corresponding network card name and source MAC address; extract the destination MAC address from the connectivity test message as the network interface MAC address of the first switch or firewall through which the attacker simulator traffic passes; perform traffic replay operations based on the obtained network card name, source IP address, source MAC address, and destination MAC address; the victim simulator is further configured to, after receiving the HTTP request for connectivity test, parse out the random number parameter and fill it into the response message and return it to the attacker simulator.
[0077] In a complex scenario, an attacker simulator in the network security verification system is connected to different victim simulators through multiple network cards on the host.
Claims
1. A method for automatic addressing of traffic replay in a network security verification system, characterized in that, It includes the following steps: Start a full-network interface packet capture task on the attacker simulator; The attacker simulator sends an HTTP request for connectivity test containing a random number parameter to the attacked simulator; After receiving the HTTP request for connectivity test, the attacked simulator parses out the random number parameter and fills it into the response message and returns it to the attacker simulator; The attacker simulator determines the connectivity test result according to the received response message; After the connectivity test is successful, the attacker simulator stops the local packet capture task, parses the packet capture file, and finds the corresponding connectivity test message according to the IP address of the attacked simulator and / or the random number parameter; Extract the source IP address from the connectivity test message as the IP address of the network card for communication between the attacker simulator and the attacked simulator; Traverse the local network cards according to the source IP address to obtain the corresponding network card name and source MAC address; Extract the destination MAC address from the connectivity test message as the network port MAC address of the first switch or firewall through which the attacker simulator traffic passes; Perform a traffic replay operation based on the obtained network card name, source IP address, source MAC address, and destination MAC address.
2. The method for automatic addressing of traffic replay in the network security verification system according to claim 1, characterized in that, The HTTP request type for the connectivity test is the GET type, carrying a random number parameter to access the specified method of the specified port on the IP address of the attacked simulator; the IP address of the attacked simulator is obtained from the server.
3. The method for automatic addressing of traffic replay in the network security verification system according to claim 1, wherein The attacker simulator determines the connectivity test result according to the received response message, including: first, judge whether the content of the response message is empty. If it is empty, it is judged that the connectivity test fails, stop the local packet capture and delete the packet capture file, and return the result to the server; if it is not empty, judge whether the response body content of the response message is consistent with the random number carried in the request message. If it is inconsistent, it is also judged that the connectivity test fails, stop the local packet capture and delete the packet capture file, and return the result to the server; if it is consistent, it is judged that the connectivity test is successful.
4. The method for automatic addressing of traffic replay in the network security verification system according to claim 1, characterized in that The source IP address extracted from the connectivity test message is the source IP address in the request message; The destination MAC address extracted from the connectivity test message is the source MAC address in the response message.
5. The method for automatic addressing of traffic replay in the network security verification system according to claim 1, wherein The performing a traffic replay operation based on the obtained network card name, source IP address, source MAC address, and destination MAC address is to modify the SOURCE_IP, TARGET_IP, and the MAC address of the corresponding IP in the traffic message to the source IP address, the IP address of the attacked simulator, the source MAC address, and the destination MAC address, and send the traffic at the network port corresponding to the network card name.
6. A system for automatic addressing of traffic replay in a network security verification system, characterized in that, It includes: A full-network interface packet capture module, which is used to start a full-network interface packet capture task on the attacker simulator before the connectivity test; And after the connectivity test is successful, stop the local packet capture task; A connectivity test module, which is used for the attacker simulator to send an HTTP request for connectivity test containing a random number parameter to the attacked simulator; After the attacked simulator receives an HTTP request for connectivity testing, it parses out the random number parameter and fills it into the response message to return to the attacker simulator; And the attacker simulator determines the connectivity test result according to the received response message; An automatic extraction module, which is used to parse the packet capture file after the connectivity test is successful, and find the corresponding connectivity test message according to the IP address of the attacked simulator and / or the random number parameter; Extract the source IP address from the connectivity test message as the IP address of the network card for communication between the attacker simulator and the attacked simulator; Traverse the local network cards according to the source IP address to obtain the corresponding network card name and source MAC address; Extract the destination MAC address from the connectivity test message as the network port MAC address of the first switch or firewall through which the attacker simulator traffic passes; A traffic repetition module, which is used to perform traffic replay operations based on the obtained network card name, source IP address, source MAC address, and destination MAC address.
7. The system for automatic addressing of traffic replay in the network security verification system according to claim 6, characterized in that, The HTTP request type for connectivity testing is the GET type, which carries a random number parameter to access a specified method on a specified port of the attacked simulator IP address; the attacked simulator IP address is obtained from the server.
8. The system for automatic addressing of traffic replay in the network security verification system according to claim 6, characterized in that, The source IP address extracted from the connectivity test message is the source IP address in the request message; The destination MAC address extracted from the connectivity test message is the source MAC address in the response message.
9. A network security verification system, including a server, an attacker simulator, and a victim simulator. The attacker simulator and the victim simulator are used to perform traffic replay security verification tasks, and is characterized in that, The attacker simulator is also used to start a full-network port packet capture task before the connectivity test; send an HTTP request for connectivity testing containing a random number parameter to the attacked simulator; determine the connectivity test result according to the received response message; And after the connectivity test is successful, stop the local packet capture task, parse the packet capture file, and find the corresponding connectivity test message according to the IP address of the attacked simulator and / or the random number parameter; Extract the source IP address from the connectivity test message as the IP address of the network card for communication between the attacker simulator and the attacked simulator; Traverse the local network cards according to the source IP address to obtain the corresponding network card name and source MAC address; Extract the destination MAC address from the connectivity test message as the network port MAC address of the first switch or firewall through which the attacker simulator traffic passes; Perform traffic replay operations based on the obtained network card name, source IP address, source MAC address, and destination MAC address; The attacked simulator is also used to parse out the random number parameter and fill it into the response message to return to the attacker simulator after receiving the HTTP request for connectivity testing.
10. The network security verification system according to claim 9, wherein, An attacker simulator is connected to different attacked simulators through multiple network cards on the host.
Citation Information
Patent Citations
Method and system for executing, studying and judging traffic replay in network security verification system
CN117375905A