IPS escape attack defense capability test method and system
By collecting business scenarios and building hybrid traffic in IPS escape attack defense capability test, the problem of poor universality of evaluation solutions in the existing technology is solved, and more accurate test results are achieved.
Patent Information
- Application Number
- CN202510794157.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-13
- Publication Date
- 2025-08-01
AI Technical Summary
In the prior art, the IPS escape attack defense capability evaluation scheme is not universal and cannot accurately reflect the actual traffic differences deployed by different enterprises, resulting in poor test results.
Before testing, collect business scenarios of the defense system to be tested, generate background traffic and attack data sets, build mixed traffic based on actual business scenarios, adjust the attack data set through multiple test requirements to form test traffic, and conduct mixed traffic testing.
It improves the accuracy of IPS escape attack defense capability testing, makes the test results more in line with the actual situation, and can better evaluate the performance of the defense system.
Smart Images

Figure CN120415892A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of intrusion prevention, and particularly relates to a method and system for testing the IPS escape attack defense ability. Background Art
[0002] IPS, i.e., Intrusion Prevention System, is a network security device or software system used to actively detect and prevent intrusion behaviors in a network. The IPS is deployed in the network, usually in series after the firewall and before the internal network, or deployed at key nodes of the network. It will capture network packets passing by in real time and check the packets, including parsing the protocol headers and protocol fields, and then compare them one by one with a pre-configured signature library. If it is found that the characteristics of a packet exactly match an attack signature in the signature library, it indicates that the packet may be attack traffic, and then the packet is blocked or access restrictions are imposed on the associated connection, etc. With the development of computer systems and the increase in network traffic, there are extremely high requirements for the parallel processing ability and high-load coping ability of the IPS system on network nodes. As the input traffic increases, some IPSs may fail to accurately match the characteristics of attack traffic within a limited time frame, resulting in the escape of attack traffic, which will greatly weaken the effectiveness of the IPS.
[0003] In this regard, it is usually necessary to evaluate the anti-escape ability of the IPS in the prior art.
[0004] For example, the patent document CN201710976993.X provides a method, device and test machine for testing the anti-escape ability of a network intrusion prevention system. The method includes: determining whether there is an un-traversed escape combination that matches the protocol of the attack traffic. If not, counting and outputting the number of generated escape combinations, the number of successes and failures; if there is an un-traversed escape combination, generating an un-traversed single escape combination; based on a self-built protocol stack, encapsulating and mutating the attack code layer by layer according to the single escape combination to generate test attack traffic data; using a target machine to test the attack traffic data and determining the test result. If the escape fails, performing the action of determining whether there is an un-traversed escape combination and its subsequent actions. If the escape is successful, generating and outputting the minimum escape combination, and performing the action of determining whether there is an un-traversed escape combination and its subsequent actions. It realizes the automatic detection of anti-escape testing of the IPS, improves the testing efficiency, and reduces the testing cost.
[0005] However, during the actual implementation process, the inventor found that such technical solutions are usually designed for fixed scenarios. During the actual evaluation process, there are significant differences in the actual traffic received by IPS systems deployed by different enterprises. A single evaluation method cannot analyze the actual situation well. Summary of the Invention
[0006] In view of the above problems existing in the prior art, a method for testing the IPS evasion attack defense ability is provided;
[0007] On the other hand, a test system for implementing the test method is also provided.
[0008] The specific technical solution is as follows:
[0009] A method for testing the IPS evasion attack defense ability includes:
[0010] Step S1: Collect business scenarios for the defense system to be tested, generate corresponding background traffic according to the business scenarios, and screen an attack data set according to the defense system to be tested;
[0011] Step S2: Obtain test requirements, adjust the attack data set according to the test requirements to obtain test traffic, and mix the background traffic and the test traffic to obtain mixed traffic;
[0012] The test requirements include at least one of: interception rate baseline test, network layer protocol evasion test, transport layer protocol evasion test, HTTP protocol evasion test, attack payload evasion test
[0013] Step S3: Test the defense system to be tested based on the mixed traffic.
[0014] On the other hand, step S1 includes:
[0015] Step S11: Collect business scenarios for the defense system to be tested;
[0016] Step S12: Obtain business applications according to the business scenarios, and obtain a set of common vulnerabilities according to the defense system to be tested;
[0017] Step S13: Construct example traffic and corresponding composition ratios according to the business applications respectively, and screen the attack data set according to the set of common vulnerabilities;
[0018] Step S14: Generate the background traffic according to the example traffic and the composition ratios.
[0019] On the other hand, in step S2, when the test requirement is the interception rate baseline test, the test traffic is directly generated according to the attack data set;
[0020] When the test requirement is the network layer protocol escape test, reduce the MTU parameter for the attack data set to trigger IP fragmentation and control the fragmentation content to overlap to form the test traffic;
[0021] When the test requirement is the transport layer protocol escape test, reduce the MSS parameter of the TCP protocol in the attack data set to trigger attack data segmentation, then set out-of-order transmission, confuse the TCP connection state, and redefine the destination port to form the test traffic;
[0022] When the test requirement is the HTTP protocol escape test, modify the HTTP request header and request method in the attack data set, and construct an abnormal protocol to form the test traffic;
[0023] When the test requirement is the attack payload escape test, perform load encoding and load compression modification on the attack data set, and add random data to form the test traffic.
[0024] On the other hand, the step S3 includes:
[0025] Step S31: Perform tests based on the mixed traffic and count the number of interceptions of the defense system to be tested;
[0026] During the test process, gradually increase the mixed traffic per unit time to increase the load of the defense system to be tested
[0027] Step S32: Generate an interception decline rate and an average decline rate respectively according to the number of interceptions;
[0028] Step S33: Generate an evaluation result based on the interception decline rate and the average decline rate.
[0029] On the other hand, after executing the step S3, it further includes:
[0030] Step S4: Select multiple types of the mixed traffic to construct a combined test, and perform a combined test on the defense system to be tested to obtain a combined test result.
[0031] An IPS escape attack defense ability test system for performing the above IPS escape attack defense ability test method;
[0032] The IPS escape attack defense ability test system includes:
[0033] A configuration module, which collects service scenarios for the defense system to be tested, generates corresponding background traffic according to the service scenarios, and filters out an attack data set according to the defense system to be tested;
[0034] A traffic construction module, which is connected to the configuration module;
[0035] The traffic construction module obtains the test requirements, adjusts the attack data set according to the test requirements to obtain test traffic, and mixes the background traffic and the test traffic to obtain mixed traffic;
[0036] The test requirements include at least one of the following: interception rate baseline test, network layer protocol escape test, transport layer protocol escape test, HTTP protocol escape test, and attack payload escape test
[0037] A test module, which is connected to the traffic construction module;
[0038] The test module tests the defense system under test based on the mixed traffic.
[0039] On the other hand, the configuration module includes:
[0040] A scenario collection module, which collects business scenarios for the defense system under test;
[0041] A first processing module, which is connected to the scenario collection module;
[0042] The first processing module obtains business applications according to the business scenarios, and obtains a set of common vulnerabilities according to the defense system under test;
[0043] A data set generation module, which constructs example traffic and corresponding composition ratios according to the business applications respectively, and filters the attack data set according to the set of common vulnerabilities;
[0044] A second processing module, which is connected to the data set generation module;
[0045] The second processing module generates the background traffic according to the example traffic and the composition ratio.
[0046] On the other hand, the traffic construction module includes:
[0047] A third processing module, which directly generates the test traffic according to the attack data set when the test requirement is the interception rate baseline test;
[0048] A fourth processing module, which reduces the MTU parameter of the attack data set to trigger IP fragmentation and controls the overlap of the fragmented content to form the test traffic when the test requirement is the network layer protocol escape test;
[0049] A fifth processing module, which, when the test requirement is the transport layer protocol escape test, reduces the MSS parameter of the TCP protocol in the attack dataset to trigger attack data segmentation, and then sets out-of-order transmission, confuses the TCP connection status, and redefines the destination port to form the test traffic;
[0050] A sixth processing module, which, when the test requirement is the HTTP protocol escape test, modifies the HTTP request headers and request methods in the attack dataset and constructs an abnormal protocol to form the test traffic;
[0051] A seventh processing module, which, when the test requirement is the attack payload escape test, modifies the load encoding and load compression of the attack dataset and adds random data to form the test traffic.
[0052] On the other hand, the test module includes:
[0053] A quantity statistics module, which tests based on the mixed traffic and counts the number of interceptions of the defense system to be tested;
[0054] During the test process, gradually increase the mixed traffic per unit time to increase the load of the defense system to be tested
[0055] An interception rate calculation module, which is connected to the quantity statistics module;
[0056] The interception rate calculation module respectively generates an interception decline rate and an average decline rate according to the number of interceptions;
[0057] An evaluation result generation module, which is connected to the interception rate calculation module;
[0058] The evaluation result generation module generates an evaluation result based on the interception decline rate and the average decline rate.
[0059] On the other hand, it further includes:
[0060] A combined test module, which selects multiple types of the mixed traffic to construct a combined test and performs a combined test on the defense system to be tested to obtain a combined test result.
[0061] The above technical solution has the following advantages or beneficial effects:
[0062] Aiming at the problems that the existing solutions for evaluating the defense ability against IPS evasion attacks have poor universality and unsatisfactory effects, in this solution, a data collection process for the business scenarios of the defense system to be tested is introduced before the test starts, and combined with the actual business scenarios to form background traffic simulated by multiple different data sources. Vulnerabilities that are likely to occur in the defense system to be tested are selected and an attack data set is constructed. On this basis, the construction and testing of mixed traffic are carried out, making the test results more in line with the actual situation. BRIEF DESCRIPTION OF THE DRAWINGS
[0063] Referring to the accompanying drawings, the embodiments of the present invention will be described more fully. However, the accompanying drawings are only for illustration and explanation and do not constitute a limitation on the scope of the present invention.
[0064] Figure 1 Schematic diagram of the whole of the embodiment of the present invention;
[0065] Figure 2 Schematic diagram of step S1 in the embodiment of the present invention;
[0066] Figure 3 Schematic diagram of step S3 in the embodiment of the present invention;
[0067] Figure 4 Schematic diagram of step S4 in the embodiment of the present invention;
[0068] Figure 5 Schematic diagram of the system in the embodiment of the present invention;
[0069] Figure 6 Schematic diagram of the configuration module in the embodiment of the present invention;
[0070] Figure 7 Schematic diagram of the traffic construction module in the embodiment of the present invention;
[0071] Figure 8 Schematic diagram of the test module in the embodiment of the present invention;
[0072] Figure 9 Schematic diagram of the combined test module in the embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0073] The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0074] It should be noted that, without conflict, the embodiments in the present invention and the features in the embodiments may be combined with each other.
[0075] The present invention will be further described below in conjunction with the accompanying drawings and specific embodiments, but it is not intended to limit the present invention.
[0076] The present invention includes:
[0077] A method for testing the IPS escape attack defense ability, as Figure 1 shown, includes:
[0078] Step S1: Collect business scenarios for the defense system to be tested, generate corresponding background traffic according to the business scenarios, and screen and obtain an attack data set according to the defense system to be tested;
[0079] Step S2: Obtain test requirements, adjust the attack data set according to the test requirements to obtain test traffic, and mix the background traffic and the test traffic to obtain mixed traffic;
[0080] The test requirements include at least one of the following: interception rate baseline test, network layer protocol escape test, transport layer protocol escape test, HTTP protocol escape test, and attack payload escape test
[0081] Step S3: Test the defense system to be tested based on the mixed traffic.
[0082] Specifically, for the problem that the existing solutions for evaluating the IPS escape attack defense ability have poor universality and unsatisfactory effects, in this solution, a process of collecting the business scenarios of the defense system to be tested is introduced before the test starts, and the background traffic simulated by multiple different data sources is formed in combination with the actual business scenarios, and the vulnerabilities that are likely to occur in the defense system to be tested are selected and an attack data set is constructed. On this basis, the construction and testing of the mixed traffic are carried out, so that the test results are more in line with the actual situation.
[0083] Specifically, the defense system to be tested refers to an IPS (Intrusion Prevention System) system that needs to be evaluated, which may be deployed in various environments according to the actual scenario, such as on the network nodes of an enterprise, a streaming media platform, a school, etc. In different environments, due to different production systems running, the types of incoming and outgoing traffic that may be generated will also vary, which leads to differences in the attack test traffic configured for a fixed scenario in different actual scenarios and cannot accurately test the defense performance.
[0084] For this purpose, for the defense system to be tested, first collect the business scenarios where the defense system to be tested is deployed, such as in a campus network system, a small IT enterprise, etc. According to different business scenarios, obtain the typical background traffic composition ratio, and then simulate the corresponding background traffic. Here, the background traffic refers to the normal access traffic that does not involve the attack process, and is used to simulate the normal communication process and the process of increasing load.
[0085] The defense system to be tested itself may vary according to different platforms, etc. After collecting the relevant information of the defense system to be tested, the common vulnerabilities of the corresponding operating system, database, application program and components of the defense system to be tested and the corresponding attack methods can be found to form an initial attack data set.
[0086] On this basis, according to the required test requirements, namely interception rate baseline test, network layer protocol escape test, transport layer protocol escape test, HTTP protocol escape test, attack load escape test, etc., adjust the attack data set, mainly including setting the corresponding parameters for the attack packets, so as to realize different attack methods for penetrating the IPS to form test traffic. Output the test traffic and the background traffic in proportion respectively to obtain the mixed traffic for testing. This mixed traffic can simulate the attack traffic mixed in the background traffic when the system is running normally.
[0087] Finally, conduct the corresponding item attack test based on this mixed traffic, so as to realize a more accurate evaluation process.
[0088] In one embodiment, as Figure 2 shown, step S1 includes:
[0089] Step S11: Collect the business scenario for the defense system to be tested;
[0090] Step S12: Obtain the business applications according to the business scenario, and obtain the set of common vulnerabilities according to the defense system to be tested;
[0091] Step S13: Construct the example traffic and the corresponding composition ratio respectively according to the business application, and screen the attack data set according to the set of common vulnerabilities;
[0092] Step S14: Generate the background traffic according to the example traffic and the composition ratio.
[0093] Specifically, to realize a more accurate evaluation process, in this embodiment, first collect the business scenario where the defense system to be tested is deployed and the relevant information of the defense system to be tested. Subsequently, according to different business scenarios, obtain the business applications that need to be deployed in the system and the typical composition ratio of the traffic generated by each business application.
[0094] Based on business applications, sample traffic and corresponding composition ratios can be constructed respectively, and finally the corresponding background traffic can be simulated.
[0095] Two network traffic models for typical scenarios are provided here:
[0096] 1. A typical campus network traffic model is as follows:
[0097] Video streaming media (such as Tencent Video, iQIYI, etc.): accounting for 30% of the bandwidth;
[0098] Online education platforms (such as China University MOOC, school self-built teaching platforms, etc.): accounting for 20% of the bandwidth;
[0099] Web browsing (such as accessing various websites through a browser): accounting for 15% of the bandwidth;
[0100] Instant messaging tools (such as WeChat, QQ, DingTalk, etc.): accounting for 10% of the bandwidth;
[0101] P2P downloads (such as Thunder, BitTorrent): accounting for 8% of the bandwidth;
[0102] Cloud storage services (such as Baidu Cloud, Tencent Weiyun, etc.): accounting for 7% of the bandwidth;
[0103] Online games (such as Honor of Kings, Peacekeeper Elite): accounting for 5% of the bandwidth;
[0104] Email systems (such as NetEase enterprise email, school email): accounting for 2% of the bandwidth;
[0105] Online music (such as NetEase Cloud Music, QQ Music, etc.): accounting for 2% of the bandwidth;
[0106] Others (such as DNS, NTP, SNMP): accounting for 1% of the bandwidth.
[0107] 2. A typical IT company network traffic model is as follows:
[0108] Code hosting platforms (such as GitHub, GitLab, etc.): accounting for 25% of the bandwidth;
[0109] Online office software (such as Feishu, DingTalk, Enterprise WeChat, etc.): accounting for 20% of the bandwidth;
[0110] Cloud service API calls (such as AWS API, Alibaba Cloud SDK): accounting for 15% of the bandwidth;
[0111] Instant messaging and conferencing systems (such as Enterprise WeChat, Zoom, Microsoft Teams): accounting for 12% of the bandwidth;
[0112] Database access (such as MySQL, PostgreSQL, MongoDB): accounts for 10% of the bandwidth; Web browsing (such as blogs, news websites, etc.): accounts for 8% of the bandwidth;
[0113] Security scanning and monitoring traffic (such as Nessus, Nmap, Zabbix): accounts for 5% of the bandwidth; Virtual Private Network (VPN) connection (such as CiscoVPN, etc.): accounts for 3% of the bandwidth;
[0114] Operation and maintenance management protocols (such as SSH, Telnet, RDP, Syslog): accounts for 1% of the bandwidth;
[0115] Others (such as OA, printing, etc.): accounts for 1% of the bandwidth.
[0116] Set the background traffic bandwidth to 75% of the line speed of the tested IPS test interface. (For example, if the tested IPS is a gigabit interface, the traffic is set to 750 Mbps).
[0117] Correspondingly, according to the relevant information of the defense system to be tested, the common vulnerabilities of the operating system, database, application programs and components corresponding to the defense system to be tested and the corresponding attack methods can be found to form an initial attack data set.
[0118] In one embodiment, in step S2, when the test requirement is the interception rate baseline test, test traffic is directly generated according to the attack data set;
[0119] When the test requirement is the network layer protocol escape test, the MTU parameter of the attack data set is reduced to trigger IP fragmentation and control the overlap of the fragmented content to form test traffic;
[0120] When the test requirement is the transport layer protocol escape test, the MSS parameter of the TCP protocol in the attack data set is reduced to trigger the segmentation of the attack data, and then out-of-order sending is set, the TCP connection state is confused, and the destination port is redefined to form test traffic;
[0121] When the test requirement is the HTTP protocol escape test, the HTTP request headers and request methods in the attack data set are modified, and an abnormal protocol is constructed to form test traffic;
[0122] When the test requirement is the attack payload escape test, the attack data set is modified by load encoding and load compression, and random data is added to form test traffic.
[0123] Specifically, to achieve a better attack test effect, in this embodiment, different adjustment methods are constructed around different test requirements to simulate the corresponding attack means.
[0124] Among them, for the basic interception rate baseline test, the test traffic can be directly simulated according to the attack dataset.
[0125] When the test requirement is a network layer protocol escape test, for the attack dataset, first reduce the MTU parameter (such as 20 bytes) to trigger IP fragmentation; then set the fragmentation offset and fragmentation length to make the fragmented content overlap, thereby forming the test traffic.
[0126] When the test requirement is a transport layer protocol escape test, for the attack dataset, reduce the MSS parameter of the TCP protocol (such as 20 bytes) to trigger attack data segmentation; set to send fragmented data packets out of order; modify flags such as SYN and ACK to confuse the TCP connection state; redefine the protocol destination port, such as setting it to a random number or a fixed value, to form the test traffic.
[0127] When the test requirement is an HTTP protocol escape test, for the attack dataset, set the chunked size of the HTTP request header to segment the protocol data packets; modify the HTTP request method, such as changing GET to POST; construct an abnormal protocol, such as setting an overly long URL, constructing out-of-order and malformed HTTP protocol headers, to form the test traffic.
[0128] When the test requirement is an attack payload escape test, for the attack dataset, modify the payload encoding, such as changing sensitive attack features to Base64, Unicode encoding, or a mixture of multiple encodings; set payload compression and transmit the attack payload after compression; add useless or random data to the payload to form the test traffic.
[0129] In one embodiment, as Figure 3 shown, step S3 includes:
[0130] Step S31: Conduct a test based on the mixed traffic and count the number of interceptions of the defense system to be tested.
[0131] During the test process, gradually increase the mixed traffic per unit time to increase the load of the defense system to be tested.
[0132] Step S32: Generate an interception decline rate and an average decline rate respectively according to the number of interceptions.
[0133] Step S33: Generate an evaluation result based on the interception decline rate and the average decline rate.
[0134] Specifically, to achieve a better evaluation effect, in this embodiment, after forming the corresponding mixed traffic according to different attack methods, conduct a test based on the mixed traffic and count the number of interceptions of the defense system to be tested. At the same time, during the test process, gradually increase the mixed traffic per unit time to increase the load of the defense system to be tested.
[0135] Then, calculate the decline rate of attack interception relative to the baseline under each escape setting, with the formula as follows:
[0136] Decline rate
[0137] where Y0 is the baseline attack interception number based on the interception rate baseline test, and Y is the attack interception number under the i-th escape setting;
[0138] And calculate the average decline rate:
[0139] Average decline rate
[0140] Based on the above process, the evaluation result can be obtained through testing.
[0141] In one embodiment, as Figure 4 shown, after executing step S3, it further includes:
[0142] Step S4: Select multiple mixed traffic to construct a combined test, and conduct a combined test on the defense system to be tested to obtain a combined test result.
[0143] Specifically, based on the above tests, by selecting multiple mixed traffic to construct a combined test and comparing it with the baseline test, the test result in the case of the combined test can be evaluated.
[0144] An IPS escape attack defense ability test system is used to execute the above IPS escape attack defense ability test method;
[0145] As Figure 5 shown, the IPS escape attack defense ability test system includes:
[0146] Configuration module 1, which collects the service scenario for the defense system to be tested, generates the corresponding background traffic according to the service scenario, and filters the attack data set according to the defense system to be tested;
[0147] Traffic construction module 2, which is connected to configuration module 1;
[0148] Traffic construction module 2 obtains the test requirements, adjusts the attack data set according to the test requirements to obtain the test traffic, and mixes the background traffic and the test traffic to obtain the mixed traffic;
[0149] The test requirements include at least one of the following: interception rate baseline test, network layer protocol escape test, transport layer protocol escape test, HTTP protocol escape test, attack payload escape test
[0150] Test module 3, which is connected to traffic construction module 2;
[0151] The test module 3 tests the defense system under test based on mixed traffic.
[0152] Specifically, aiming at the problems of poor universality and ineffective evaluation schemes for IPS evasion attack defense capabilities in the prior art, in this solution, a process of collecting the business scenarios of the defense system under test is introduced before the test starts, and the actual business scenarios are combined to form background traffic simulated by multiple different data sources. Vulnerabilities that are likely to occur in the defense system under test are selected and an attack data set is constructed. On this basis, the construction and testing of mixed traffic are carried out, making the test results more in line with the actual situation.
[0153] Specifically, the defense system under test refers to an IPS (Intrusion Prevention System) system that needs to be evaluated. It may be deployed in various environments according to the actual scenario, such as on enterprise network nodes, streaming media platforms, schools, etc. In different environments, due to different production systems in operation, the types of incoming and outgoing traffic that may be generated will also vary. This results in differences in the attack test traffic configured for fixed scenarios in different actual scenarios and cannot accurately test the defense performance.
[0154] In response to this, for the defense system under test, first collect the business scenarios where the defense system under test is deployed. For example, the defense system under test is deployed in a campus network system, a small IT enterprise, etc. According to different business scenarios, obtain the typical background traffic composition ratio, and then simulate the corresponding background traffic. Here, the background traffic refers to the normal access traffic that does not involve the attack process and is used to simulate the normal communication process and the process of increasing load.
[0155] The defense system under test itself may vary according to different platforms, etc. After collecting the relevant information of the defense system under test, the common vulnerabilities of the corresponding operating system, database, application program, and components of the defense system under test and the corresponding attack methods can be found to form an initial attack data set.
[0156] On this basis, according to the required test requirements, that is, interception rate baseline test, network layer protocol evasion test, transport layer protocol evasion test, HTTP protocol evasion test, attack load evasion test, etc., the attack data set is adjusted, mainly including setting the corresponding parameters for the attack packets, so as to realize different attack methods for penetrating the IPS to form test traffic. Output the test traffic and the background traffic in proportion respectively to obtain the mixed traffic for testing. This mixed traffic can simulate the attack traffic mixed in the background traffic when the system is running normally.
[0157] In one embodiment, as Figure 6 shown, the configuration module 1 includes:
[0158] Scenario collection module 11, the scenario collection module 11 collects the business scenario for the defense system to be tested;
[0159] First processing module 12, the first processing module 12 is connected to the scenario collection module 11;
[0160] The first processing module 12 obtains business applications according to the business scenario, and obtains a set of common vulnerabilities according to the defense system to be tested;
[0161] Dataset generation module 13, the dataset generation module 13 constructs example traffic and corresponding composition ratios respectively according to the business application, and filters the attack dataset according to the set of common vulnerabilities;
[0162] Second processing module 14, the second processing module 14 is connected to the dataset generation module 13;
[0163] The second processing module 14 generates background traffic according to the example traffic and the composition ratio.
[0164] Specifically, to achieve a more accurate evaluation process, in this embodiment, first, the business scenario deployed for the defense system to be tested and the relevant information of the defense system to be tested are collected. Subsequently, according to different business scenarios, the business applications to be deployed in the system and the typical composition ratios of the traffic generated by each business application are obtained.
[0165] Based on the business application, example traffic and corresponding composition ratios can be constructed respectively, and finally the corresponding background traffic is simulated.
[0166] Correspondingly, according to the relevant information of the defense system to be tested, the common vulnerabilities and corresponding attack methods of the operating system, database, application program and components corresponding to the defense system to be tested can be found to form an initial attack dataset.
[0167] In one embodiment, as Figure 7 shown, the traffic construction module 2 includes:
[0168] Third processing module 21, the third processing module 21 directly generates test traffic according to the attack dataset when the test requirement is the interception rate baseline test;
[0169] Fourth processing module 22, when the test requirement is the network layer protocol escape test, the fourth processing module 22 reduces the MTU parameter of the attack dataset to trigger IP fragmentation and controls the fragmentation content overlap to form test traffic;
[0170] Fifth processing module 23, when the test requirement is the transport layer protocol escape test, the fifth processing module 23 reduces the MSS parameter of the TCP protocol in the attack dataset to trigger attack data segmentation, then sets out-of-order sending and confuses the TCP connection state and redefines the destination port to form test traffic;
[0171] The sixth processing module 24, when the test requirement is an HTTP protocol escape test, modifies the HTTP request headers and request methods in the attack dataset and constructs an abnormal protocol to form test traffic;
[0172] The seventh processing module 25, when the test requirement is an attack payload escape test, modifies the attack dataset by performing payload encoding and payload compression, and adds random data to form test traffic.
[0173] Specifically, to achieve a better attack test effect, in this embodiment, different adjustment methods are constructed around different test requirements to simulate corresponding attack means.
[0174] Among them, for the basic interception rate baseline test, test traffic can be directly simulated according to the attack dataset.
[0175] When the test requirement is a network layer protocol escape test, for the attack dataset, first reduce the MTU parameter (such as 20 bytes) to trigger IP fragmentation; then set the fragmentation offset and fragmentation length so that the fragmented content overlaps, thereby forming test traffic;
[0176] When the test requirement is a transport layer protocol escape test, for the attack dataset, reduce the MSS parameter of the TCP protocol (such as 20 bytes) to trigger attack data segmentation; set out-of-order sending of fragmented packets; modify flags such as SYN and ACK to confuse the TCP connection state; redefine the protocol destination port, such as setting it to a random number or a fixed value, to form test traffic;
[0177] When the test requirement is an HTTP protocol escape test, for the attack dataset, set the chunked size of the HTTP request header to segment the protocol packets; modify the HTTP request method, such as changing GET to POST; construct an abnormal protocol, such as setting an extremely long URL, constructing out-of-order and deformed HTTP protocol headers, to form test traffic;
[0178] When the test requirement is an attack payload escape test, for the attack dataset, modify the payload encoding, such as changing sensitive attack features to Base64, Unicode encoding, or a mixture of multiple encodings; set payload compression to transmit the attack payload after compression; add useless or random data to the payload to form test traffic.
[0179] In one embodiment, as Figure 8 shown, the test module 3 includes:
[0180] The number statistics module 31, which performs tests based on the mixed traffic and counts the number of interceptions of the defense system to be tested;
[0181] During the test process, gradually increase the mixed traffic per unit time to increase the load on the defense system under test.
[0182] An interception rate calculation module 32, the interception rate calculation module 32 is connected to the connection number statistics module 31;
[0183] The interception rate calculation module 32 generates an interception decline rate and an average decline rate respectively according to the number of intercepted attacks;
[0184] An evaluation result generation module 33, the evaluation result generation module 33 is connected to the interception rate calculation module 32;
[0185] The evaluation result generation module 33 generates an evaluation result based on the interception decline rate and the average decline rate.
[0186] Specifically, to achieve a better evaluation effect, in this embodiment, after forming the corresponding mixed traffic according to different attack methods, perform tests based on the mixed traffic and count the number of intercepted attacks of the defense system under test. At the same time, during the test process, gradually increase the mixed traffic per unit time to increase the load on the defense system under test.
[0187] Then, calculate the decline rate of attack interception relative to the baseline under each escape setting, and the formula is as follows:
[0188] Decline rate
[0189] Among them, Y0 is the baseline attack interception number based on the interception rate baseline test, and Y i is the attack interception number under the i-th escape setting;
[0190] And calculate the average decline rate:
[0191] Average decline rate
[0192] Based on the above process, the evaluation result can be obtained through testing.
[0193] In one embodiment, as Figure 9 shown, it further includes:
[0194] A combined test module 4, the combined test module 4 selects a variety of mixed traffic to construct a combined test, and performs a combined test on the defense system under test to obtain a combined test result.
[0195] Specifically, on the basis of the above tests, by selecting a variety of mixed traffic to construct a combined test and comparing it with the baseline test, the test result in the case of the combined test can be evaluated.
[0196] Those of ordinary skill in the art will understand that various aspects of the present invention, or possible implementations of various aspects, can be embodied as a system, method, or computer program product. Therefore, various aspects of the present invention, or possible implementations of various aspects, can take the form of a complete hardware embodiment, a complete software embodiment (including firmware, resident software, etc.), or an embodiment combining software and hardware aspects, all of which are collectively referred to herein as "circuitry", "module", or "system". In addition, various aspects of the present invention, or possible implementations of various aspects, can take the form of a computer program product, which refers to computer instructions stored in a memory.
[0197] The memory can be a computer-readable signal medium or a computer-readable storage medium. A computer-readable storage medium includes, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or apparatuses, or any suitable combination of the foregoing, such as random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable read-only memory (CD-ROM).
[0198] The processor in the computer reads the computer instructions stored in the memory, enabling the processor to perform the functional actions specified in each step, or combinations of steps, in the flowchart; generating means for performing the functional actions specified in each block, or combinations of blocks, in the block diagram.
[0199] It should be understood that the processor in the computer can be understood as being implemented by one or more application-specific integrated circuits (ASICs), DSPs, programmable logic devices (PLDs), complex programmable logic devices (CPLDs), field-programmable gate arrays (FPGAs), general-purpose processors, controllers, microcontrollers (MCUs), microprocessors, or other electronic components for executing the aforementioned computer instructions.
[0200] The computer instructions can be executed entirely on the user's local computer, partially on the user's local computer, as a separate software package, partially on the user's local computer and partially on a remote computer, or entirely on a remote computer or server. It should also be noted that in certain alternative embodiments, the functions noted in each step in the flowchart, or each block in the block diagram, may not occur in the order noted in the figure. For example, depending on the functions involved, two consecutive steps, or two blocks shown in succession, may actually be executed substantially simultaneously, or these blocks may sometimes be executed in the reverse order.
[0201] Of course, in practical applications, each component in a computer system is coupled together through a bus system. It can be understood that the bus system is used to achieve connection and communication between these components. In addition to the data bus, the bus system also includes a power bus, a control bus, and a status signal bus.
[0202] The above are only preferred embodiments of the present invention, and do not limit the implementation manners and protection scope of the present invention. For those skilled in the art, it should be realized that all equivalent replacements and obvious changes made by using the description and illustrations of the present invention should be included in the protection scope of the present invention.
Claims
1. A test method for the defense ability against IPS evasion attacks, characterized in that Including: Step S1: Collect business scenarios for the defense system to be tested, generate corresponding background traffic according to the business scenarios, and screen out an attack dataset according to the defense system to be tested; Step S2: Obtain test requirements, adjust the attack dataset according to the test requirements to obtain test traffic, and mix the background traffic and the test traffic to obtain mixed traffic; The test requirements include at least one of an interception rate baseline test, a network layer protocol escape test, a transport layer protocol escape test, an HTTP protocol escape test, and an attack payload escape test Step S3: Test the defense system to be tested based on the mixed traffic.
2. The IPS escape attack defense ability test method according to claim 1, wherein The step S1 includes: Step S11: Collect business scenarios for the defense system to be tested; Step S12: Obtain business applications according to the business scenarios, and obtain a set of common vulnerabilities according to the defense system to be tested; Step S13: Construct example traffic and corresponding composition ratios respectively according to the business applications, and screen out the attack dataset according to the set of common vulnerabilities; Step S14: Generate the background traffic according to the example traffic and the composition ratio.
3. The IPS escape attack defense ability test method according to claim 1, wherein In the step S2, when the test requirement is the interception rate baseline test, the test traffic is directly generated according to the attack dataset; When the test requirement is the network layer protocol escape test, the MTU parameter of the attack dataset is reduced to trigger IP fragmentation and the fragmented content is controlled to overlap to form the test traffic; When the test requirement is the transport layer protocol escape test, the MSS parameter of the TCP protocol in the attack dataset is reduced to trigger attack data segmentation, and then out-of-order sending is set, the TCP connection state is confused, and the destination port is redefined to form the test traffic; When the test requirement is the HTTP protocol escape test, the HTTP request header and request method in the attack dataset are modified, and an abnormal protocol is constructed to form the test traffic; When the test requirement is the attack payload escape test, the attack dataset is modified by load encoding and load compression, and random data is added to form the test traffic.
4. The IPS escape attack defense ability test method according to claim 1, characterized in that The step S3 includes: Step S31: Test based on the mixed traffic and count the number of interceptions of the defense system to be tested; During the test process, gradually increase the mixed traffic per unit time to increase the load of the defense system to be tested Step S32: Generate an interception decline rate and an average decline rate respectively according to the number of interceptions; Step S33: Generate an evaluation result based on the interception decline rate and the average decline rate.
5. The IPS escape attack defense ability test method according to claim 1, wherein After executing the step S3, it further includes: Step S4: Select multiple types of the mixed traffic to construct a combined test, and perform a combined test on the defense system to be tested to obtain a combined test result.
6. An IPS escape attack defense ability test system, characterized in that For performing the IPS escape attack defense ability test method according to any one of claims 1-5; The IPS escape attack defense ability test system includes: Configuration module, which collects service scenarios for the defense system to be tested, generates corresponding background traffic according to the service scenarios, and filters out an attack dataset based on the defense system to be tested; Traffic construction module, which is connected to the configuration module; The traffic construction module obtains test requirements, adjusts the attack dataset according to the test requirements to obtain test traffic, and mixes the background traffic and the test traffic to obtain mixed traffic; The test requirements include at least one of the following: interception rate baseline test, network layer protocol escape test, transport layer protocol escape test, HTTP protocol escape test, attack payload escape test Test module, which is connected to the traffic construction module; The test module tests the defense system to be tested based on the mixed traffic.
7. The IPS escape attack defense ability test system according to claim 6, wherein The configuration module includes: Scenario collection module, which collects service scenarios for the defense system to be tested; First processing module, which is connected to the scenario collection module; The first processing module obtains service applications according to the service scenarios, and obtains a set of common vulnerabilities according to the defense system to be tested; Dataset generation module, which constructs example traffic and corresponding composition ratios according to the service applications respectively, and filters out the attack dataset based on the set of common vulnerabilities; Second processing module, which is connected to the dataset generation module; The second processing module generates the background traffic according to the example traffic and the composition ratio.
8. The IPS escape attack defense ability test system according to claim 6, characterized in that The traffic construction module includes: Third processing module, which directly generates the test traffic according to the attack dataset when the test requirement is the interception rate baseline test; Fourth processing module, which reduces the MTU parameter of the attack dataset to trigger IP fragmentation and controls the fragmentation content to overlap to form the test traffic when the test requirement is the network layer protocol escape test; Fifth processing module, which reduces the MSS parameter of the TCP protocol in the attack dataset to trigger attack data segmentation, then sets out-of-order sending, confuses the TCP connection state, and redefines the destination port to form the test traffic when the test requirement is the transport layer protocol escape test; Sixth processing module, which modifies the HTTP request headers and request methods in the attack dataset and constructs an abnormal protocol to form the test traffic when the test requirement is the HTTP protocol escape test; Seventh processing module, which performs load encoding and load compression modification on the attack dataset and adds random data to form the test traffic when the test requirement is the attack payload escape test.
9. The IPS escape attack defense ability test system according to claim 6, characterized in that, The test module includes: Counting module, which tests based on the mixed traffic and counts the number of interceptions of the defense system to be tested; During the testing process, gradually increase the mixed flow rate per unit time to increase the load of the defense system under test. An interception rate calculation module, which is connected to the quantity statistics module. The interception rate calculation module generates an interception decline rate and an average decline rate respectively according to the number of intercepted items. An evaluation result generation module, which is connected to the interception rate calculation module. The evaluation result generation module generates an evaluation result based on the interception decline rate and the average decline rate.
10. The IPS escape attack defense ability test system according to claim 6, characterized in that, It further includes: A combined test module, which selects multiple mixed flow rates to construct a combined test, and performs a combined test on the defense system under test to obtain a combined test result.
Citation Information
Patent Citations
Testing system and testing bed for network security monitor equipment
CN107332731A
Test system and method for intrusion prevention equipment
CN111490986A
Background flow network topology convergence method and device
CN116708258A
Cited By
WAF defense capability test method and device based on protocol analysis difference
CN121727861A
WAF defense capability test method and device based on protocol analysis difference
CN121727861B