Network attack and defense simulation early warning method based on endpoint perception

Through the endpoint-aware network attack and defense simulation method, the problems of low data acquisition efficiency and poor simulation warning accuracy are solved, and efficient and accurate security vulnerability warning and optimization are achieved.

CN120455045APending Publication Date: 2025-08-08李子涵 +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510489921.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-18
Publication Date
2025-08-08

AI Technical Summary

Technical Problem

In the existing network attack and defense simulation methods, the data acquisition efficiency of application scenarios is low and the difference is large from the actual application scenarios, resulting in low warning accuracy.

Method used

The application scenario information is collected through endpoint perception, and through the first and second types of endpoint real-time perception of application scenarios and network defense technology, a network attack and defense demonstration scenario is established, and a network attack type is simulated to conduct security vulnerabilities analysis and early warning.

Benefits of technology

It improves the efficiency of application scenario information collection, reduces the delay of network offensive and defense simulation warnings, enhances the accuracy and comprehensiveness of simulation results, promptly conducts security vulnerability warnings, and reduces the risk of security vulnerabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120455045A_ABST
    Figure CN120455045A_ABST
Patent Text Reader

Abstract

The invention provides a network attack and defense simulation early warning method based on endpoint sensing, which comprises the following steps: determining an application scene of network attack and defense, and carrying out application scene information acquisition through endpoint sensing to obtain application scene acquisition information; establishing a network attack and defense demonstration scene according to the application scene acquisition information; performing network attack and defense simulation based on the network attack and defense demonstration scene in combination with the network attack type to obtain network attack and defense simulation information; performing security vulnerability analysis on the network attack and defense simulation information to obtain a network attack and defense simulation result; and performing security vulnerability early warning according to a network attack and defense simulation result. The application scene acquisition information is acquired in an endpoint sensing mode, so that when the application scene information is acquired, the influence of the application scene information acquisition on the application scene is reduced, the application scene information acquisition efficiency is improved, the error between a network attack and defense demonstration scene and an actual application scene is reduced, and the network attack and defense demonstration effect is improved. And the network attack and defense simulation early warning accuracy is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of network monitoring, and in particular to a network attack and defense simulation early warning method based on endpoint perception. Background Art

[0002] In recent years, with the rapid development of computer network communication technology, network security and reliability have become a common concern of current network users. In order to improve network security, defense technologies based on various network attacks have also emerged. Network attack and defense have gradually become an important direction for the development of network information security.

[0003] Network attack and defense protects computer networks and their components from malicious attacks and damage, and is the core of network security. Normally, network attack and defense simulation is used to evaluate and improve network attack and defense, and network attack and defense simulation is used to enhance security awareness, improve protection capabilities, and promote network security construction. However, at present, during network attack and defense simulation, the efficiency of data collection for application scenarios is low, and the deviation between the network attack and defense demonstration scenario and the actual application scenario is large, resulting in low accuracy of network attack and defense simulation warning. Therefore, the present invention proposes a network attack and defense simulation warning method based on endpoint perception, which adopts endpoint perception to obtain application scenario collection information, so that when collecting application scenario information, the impact of application scenario information collection on the application scenario itself is reduced, the efficiency of application scenario information collection is improved, the error between the network attack and defense demonstration scenario and the actual application scenario is reduced, and the accuracy of network attack and defense simulation warning is improved. Summary of the Invention

[0004] The purpose of the present invention is to provide a network attack and defense simulation early warning method based on endpoint perception to solve the problems raised in the above background technology.

[0005] To achieve the above objectives, the present invention provides the following technical solution: a network attack and defense simulation early warning method based on endpoint perception, comprising:

[0006] Determine the application scenarios of network attack and defense, and collect application scenario information through endpoint perception to obtain application scenario collection information;

[0007] Collect information based on application scenarios to establish network attack and defense demonstration scenarios;

[0008] Conduct network attack and defense simulation based on network attack and defense demonstration scenarios and network attack types to obtain network attack and defense simulation information;

[0009] Conduct security vulnerability analysis on network attack and defense simulation information to obtain network attack and defense simulation results;

[0010] Issue security vulnerability warnings based on network attack and defense simulation results.

[0011] Furthermore, the endpoints include: first-class endpoints and second-class endpoints, wherein the first-class endpoints are information collection endpoints determined according to application scenarios, and real-time information perception and collection are performed for the application scenarios through the first-class endpoints to obtain first perception and collection information; the second-class endpoints are information collection endpoints determined according to network defense technology, and real-time information perception and collection are performed for network defense technology through the second-class endpoints to obtain second perception and collection information.

[0012] Furthermore, based on the application scenario, information is collected to establish a network attack and defense demonstration scenario, including:

[0013] Perform application scenario architecture analysis on the first perception collected information to determine the target application scenario architecture information;

[0014] Create a simulation model according to the target application scenario architecture information to obtain an application scenario model;

[0015] Supplementing the application scenario model with first information based on the first perception-collected information to obtain an initial application scenario;

[0016] Supplementing the initial application scenario with second information based on the second perception-collected information to obtain a network attack and defense demonstration scenario;

[0017] At the same time, real-time information analysis is performed on the first perception collected information and the second perception collected information to determine whether information needs to be updated for the network attack and defense demonstration scenario, and obtain real-time information analysis results;

[0018] According to the real-time information analysis results, when information needs to be updated for the network attack and defense demonstration scenario, the updated information is determined based on the first perception collection information and the second perception collection information, and matched and updated in the network attack and defense demonstration scenario according to the updated information.

[0019] Furthermore, network attack and defense simulations are conducted based on network attack and defense demonstration scenarios and network attack types, including:

[0020] Conduct scenario operation simulation for network attack and defense demonstration scenarios to obtain application scenarios under operation status;

[0021] Obtaining a network attack virtual instruction according to the network attack type, and obtaining an attack simulation signal based on the network attack virtual instruction;

[0022] In the application scenario under the operating state, the attack simulation signal is used to carry out a network attack, and the network defense demonstration is carried out based on the network defense technology in the network attack and defense demonstration scenario to obtain the network attack and defense simulation information.

[0023] Furthermore, attack simulation signals are used to carry out network attacks, including:

[0024] Obtain the network attack type of the attack simulation signal;

[0025] Determine the location of network attacks in network attack and defense demonstration scenarios based on the type of network attacks;

[0026] Analyze the number of cyber attack locations;

[0027] When the number of network attack locations is one, an attack simulation signal is invaded at the network attack location, and the attack simulation signal is used to conduct a network attack in the network attack and defense demonstration scenario;

[0028] When the number of network attack positions is two or more, the network attack positions are arranged and combined to obtain multiple groups of network attack combination positions. The network attack combination positions are used as target attack positions, and then attack simulation signal invasion is carried out on the target attack positions. The attack simulation signal is used to carry out network attacks in the network attack and defense demonstration scenario.

[0029] Furthermore, security vulnerability analysis is conducted based on the network attack and defense simulation information, including:

[0030] In the network attack and defense demonstration scenario, information is obtained on network defense technology to obtain current network defense information;

[0031] Determine security vulnerability analysis indicators based on current network defense information, and identify and extract related information from network attack and defense simulation information based on security vulnerability analysis indicators to obtain security vulnerability analysis indicator related information;

[0032] Perform security vulnerability analysis indicator data analysis and calculation based on security vulnerability analysis indicator correlation information to obtain security vulnerability analysis indicator information;

[0033] Combined with the target defense standards, security situation analysis is performed on the security vulnerability analysis indicator information to obtain security situation analysis data;

[0034] Based on the security situation analysis data, determine whether there are security loopholes in the current network defense and obtain the network attack and defense simulation results.

[0035] Furthermore, the target defense standard is determined based on current network defense information, including:

[0036] Obtain security defense standards for security defense technologies;

[0037] Perform security defense feature analysis based on current network defense information to obtain security defense features of the current network defense;

[0038] Determine the security defense type of the current network defense technology based on the security defense characteristics of the current network defense;

[0039] The security defense types of current network defense technologies are used to screen and adjust the security defense standards to obtain the target security defense standards.

[0040] Furthermore, after obtaining the target security defense standard, the target security defense standard is also verified, including:

[0041] Conduct idealized defense performance analysis based on current network defense information to determine idealized defense information for current network defense;

[0042] Verify the target security defense standard in combination with the idealized defense information of the current network defense to determine whether the idealized defense information of the current network defense is consistent with the target security defense standard, and obtain verification analysis results;

[0043] The target security defense standard is corrected based on the verification analysis results. When the idealized defense information of the current network defense is inconsistent with the target security defense standard, the difference information between the idealized defense information of the current network defense and the target security defense standard is analyzed to obtain the difference analysis data. The target security defense standard is corrected and modified according to the difference analysis data to obtain the final target security defense standard.

[0044] Furthermore, when issuing a security vulnerability warning according to the network attack and defense simulation results, when the network attack and defense simulation results show that there is no security vulnerability in the current network defense, the security situation analysis data is summarized to obtain a summary result, and the summary result is used to issue a network attack and defense simulation result warning according to the security vulnerability first warning method; when the network attack and defense simulation results show that there is a security vulnerability in the current network defense, security vulnerability data information is obtained from the security situation analysis data, and a security vulnerability impact analysis is performed based on the security vulnerability data information to determine the impact type of the security vulnerability, and then the warning setting is matched in the security vulnerability first warning method according to the impact type of the security vulnerability to obtain a target security vulnerability warning, thereby issuing a network attack and defense simulation result warning according to the target security vulnerability warning.

[0045] Furthermore, after obtaining the network attack and defense simulation results, the current network defense is optimized according to the network attack and defense simulation results, including:

[0046] When the network attack and defense simulation results show that there are security vulnerabilities in the current network defense, a fault analysis is performed on the security vulnerabilities to obtain security vulnerability analysis data;

[0047] Combine the current network defense information with the security vulnerability analysis data to optimize the analysis, determine the improvement plan for the current network defense, and obtain the current network defense optimization information;

[0048] Optimize network defense for network attack and defense demonstration scenarios based on current network defense optimization information;

[0049] Based on the optimized network defense, the network attack and defense simulation is performed again in the network attack and defense demonstration scenario to obtain the optimized network attack and defense simulation information;

[0050] Conduct security vulnerability analysis on the optimized network attack and defense simulation information to obtain the network attack and defense simulation results;

[0051] According to the results of the network attack and defense simulation, the current network defense optimization information is adjusted, and the adjusted current network defense optimization information is used to perform network defense optimization and network attack and defense simulation for the network attack and defense demonstration scenario until the network attack and defense simulation results show that there are no security vulnerabilities in the current network defense. At this time, the current network defense optimization information is obtained, the target network defense optimization information is obtained, and security vulnerability revision prompts are provided for the target network defense optimization information.

[0052] The present invention adopts an endpoint perception method to obtain application scenario collection information, so that when the application scenario information is collected, the application scenario information collection will not affect the normal operation of the application scenario, and the impact of the application scenario information collection on the application scenario itself is reduced. Moreover, the efficiency of the application scenario information collection is high, and the application scenario information collection can be obtained in a relatively short time, so that network attack and defense simulation can be carried out in time for the application scenario collection information, reducing the delay of the network attack and defense simulation warning, and then timely issuing security vulnerability warnings, so that relevant personnel can optimize the network attack and defense according to the security vulnerabilities in time, reduce the risk of security vulnerabilities in the application scenario, and improve security protection capabilities.

[0053] Other features and advantages of the present invention will be described in the following description, and in part will become apparent from the description, or will be understood by practicing the present invention. The purpose and other advantages of the present invention can be realized and obtained by the structures particularly pointed out in the written description and the accompanying drawings.

[0054] The technical solution of the present invention is further described in detail below through the accompanying drawings and embodiments. BRIEF DESCRIPTION OF THE DRAWINGS

[0055] The accompanying drawings are used to provide a further understanding of the present invention and constitute a part of the specification. Together with the embodiments of the present invention, they are used to explain the present invention and do not constitute a limitation of the present invention. In the accompanying drawings:

[0056] Figure 1 This is a schematic diagram of the steps of the network attack and defense simulation early warning method according to the present invention;

[0057] Figure 2 This is a schematic diagram of step three in the network attack and defense simulation early warning method of the present invention;

[0058] Figure 3 This is a schematic diagram of step four in the network attack and defense simulation early warning method described in the present invention. DETAILED DESCRIPTION

[0059] The preferred embodiments of the present invention are described below with reference to the accompanying drawings. It should be understood that the preferred embodiments described herein are only used to illustrate and explain the present invention, and are not used to limit the present invention.

[0060] like Figure 1 As shown, an embodiment of the present invention provides a network attack and defense simulation early warning method based on endpoint perception, including:

[0061] Step 1: Determine the application scenario of network attack and defense, and collect application scenario information through endpoint perception to obtain application scenario collection information;

[0062] Step 2: Collect information based on the application scenario and establish a network attack and defense demonstration scenario;

[0063] Step 3: Perform network attack and defense simulation based on the network attack and defense demonstration scenario and the network attack type to obtain network attack and defense simulation information;

[0064] Step 4: Perform security vulnerability analysis on the network attack and defense simulation information in combination with the network defense type to obtain the network attack and defense simulation results;

[0065] Step 5: Issue security vulnerability warnings based on the network attack and defense simulation results.

[0066] In the above technical solution, the endpoint for perception is an information collection node determined in advance based on an analysis of application scenarios in combination with network attack and defense.

[0067] In the above technical solution, the network attack and defense demonstration scenario is consistent with the application scenario of network attack and defense.

[0068] In the above technical solution, network attack types include: password intrusion, Trojan horse attack, hacker software attack, etc.

[0069] In the above technical solution, when performing network attack and defense simulation based on the network attack and defense demonstration scenario combined with the network attack type, attack simulation information is determined for each network attack type and a network attack and defense demonstration is performed in the network attack and defense demonstration scenario.

[0070] In the above technical solution, when collecting application scenario information through endpoint perception, the endpoint perceives the information of the application scenario in real time and obtains real-time application scenario collection information.

[0071] The above technical solution uses endpoint perception to obtain application scenario collection information, so that when collecting application scenario information, the application scenario information collection will not affect the normal operation of the application scenario, reducing the impact of the application scenario information collection on the application scenario itself. In addition, the efficiency of application scenario information collection is high, and the application scenario information collection can be obtained in a relatively short time, so that network attack and defense simulation can be carried out in a timely manner based on the application scenario collection information, reducing the delay of network attack and defense simulation warning, and then timely issuing security vulnerability warnings, so that relevant personnel can optimize network attack and defense according to security vulnerabilities in a timely manner, reducing the risk of security vulnerabilities in application scenarios, and improving security protection capabilities. Moreover, when conducting network attack and defense simulations, combined with network attack types, a comprehensive demonstration of network attack and defense is achieved, improving the comprehensiveness of network attack and defense simulations, reducing the errors in network attack and defense simulation results, and making security vulnerability warnings more accurate.

[0072] In one embodiment provided by the present invention, the endpoints include: a first type of endpoint and a second type of endpoint, wherein the first type of endpoint is an information collection endpoint determined according to an application scenario, and real-time information perception and collection is performed for the application scenario through the first type of endpoint to obtain first perception and collection information; the second type of endpoint is an information collection endpoint determined according to network defense technology, and real-time information perception and collection is performed for the network defense technology through the second type of endpoint to obtain second perception and collection information.

[0073] In the above technical solution, the first type of endpoint usually refers to the host device, router, switch, etc. in the application scenario.

[0074] In the above technical solution, the second type of endpoint is an information collection point determined based on the deployment of network defense technology, and the number can be one or more.

[0075] In the above technical solution, the application scenario collection information includes: first perception collection information and second perception collection information.

[0076] The above technical solution realizes information perception and collection of application scenarios and network defense technologies through the first type of endpoints and the second type of endpoints respectively, so that information perception and collection can be comprehensively carried out for the application scenarios of network attack and defense, thereby improving the comprehensiveness of information collected in application scenarios, and thus being able to simulate more accurately during network attack and defense simulation warnings, thereby reducing the errors of simulation warnings.

[0077] In one embodiment provided by the present invention, a network attack and defense demonstration scenario is established based on information collected from an application scenario, including:

[0078] Perform application scenario architecture analysis on the first perception collected information to determine the target application scenario architecture information;

[0079] Create a simulation model according to the target application scenario architecture information to obtain an application scenario model;

[0080] Supplementing the application scenario model with first information based on the first perception-collected information to obtain an initial application scenario;

[0081] Supplementing the initial application scenario with second information based on the second perception-collected information to obtain a network attack and defense demonstration scenario;

[0082] At the same time, real-time information analysis is performed on the first perception collected information and the second perception collected information to determine whether information needs to be updated for the network attack and defense demonstration scenario, and obtain real-time information analysis results;

[0083] According to the real-time information analysis results, when information needs to be updated for the network attack and defense demonstration scenario, the updated information is determined based on the first perception collection information and the second perception collection information, and matched and updated in the network attack and defense demonstration scenario according to the updated information.

[0084] In the above technical solution, when the first information is supplemented for the application scenario model based on the first perception collection information, the first information is supplemented based on the initial first perception collection information.

[0085] In the above technical solution, when the second information is supplemented in the initial application scenario based on the second perception collection information, the second information is supplemented based on the initial second perception collection information.

[0086] In the above technical solution, the first information refers to operational information about the application scenario, such as information transmission, information processing, etc.

[0087] In the above technical solution, the second information refers to the deployment information about the network defense technology.

[0088] In the above technical solution, determining the update information according to the first sensed collected information and the second sensed collected information includes:

[0089] Determine first perception collection current information and second perception collection current information according to the first perception collection information and the second perception collection information;

[0090] Preliminarily comparing the first perception collection current information and the second perception collection current information with the first perception collection information and the second perception collection information at the previous moment, respectively, to obtain first perception collection change information and second perception collection change information;

[0091] Performing position determination on the first perception collection change information and the second perception collection change information, determining a position area corresponding to the first perception collection change information and a position area corresponding to the second perception collection change information, and obtaining a positioning result of the first perception collection change information and a positioning result of the second perception collection change information;

[0092] Performing location expansion based on the positioning result of the first perception collection change information and the positioning result of the second perception collection change information, obtaining the size of the location area corresponding to the first perception collection change information and the size of the location area corresponding to the second perception collection change information, and expanding them in combination with the expansion ratio to obtain the updated target area of the first perception collection information and the updated target area of the second perception collection information;

[0093] The update target area of the first perception collection information and the update target area of the second perception collection information are respectively combined with the first perception collection change information and the second perception collection change information to determine the update information of the first perception collection information and the update information of the second perception collection information.

[0094] In the above technical solution, when matching and updating are performed in the network attack and defense demonstration scenario according to the updated information, feature extraction is performed on the updated target area of the first perception collection information and the updated target area of the second perception collection information to obtain the updated target area features of the first perception collection information and the updated target area features of the second perception collection information; feature matching is performed in the network attack and defense demonstration scenario according to the updated target area features of the first perception collection information and the updated target area features of the second perception collection information to determine the matching result, and then information is updated according to the first perception collection change information and the second perception collection change information based on the matching result combined with the expansion ratio.

[0095] The above technical solution realizes the conversion between the application scenario of network attack and defense and the network attack and defense demonstration scenario, so that the network attack and defense demonstration scenario can replicate the application scenario of network attack and defense, and then perform simulation demonstration based on the network attack and defense demonstration scenario without affecting the application scenario of network attack and defense, providing convenience for network attack and defense simulation warning. Moreover, by supplementing the first information, the application scenario model is provided with an application environment, and by supplementing the second information, the network defense technology is replicated to the initial application scenario, so that the network attack and defense demonstration scenario matches the application scenario of network attack and defense, and by judging whether it is necessary to update the information for the network attack and defense demonstration scenario, when the application scenario of network attack and defense changes, the network attack and defense demonstration scenario can be updated in time, reducing the difference between the network attack and defense demonstration scenario and the actual application scenario of network attack and defense, ensuring the timeliness of network attack and defense simulation warning, and improving the timeliness of network attack and defense simulation warning. In addition, when the update information is determined based on the first perception collection information and the second perception collection information, and matching and updating are performed in the network attack and defense demonstration scenario according to the updated information, the location area corresponding to the first perception collection change information and the location area corresponding to the second perception collection change information are determined and then expanded using the expansion ratio. This not only allows adaptive expansion based on the size of the location area to avoid the impact of a large expansion range on the update efficiency, thereby ensuring the effectiveness of the update, but also provides a guarantee for matching, avoiding the impact of regional information changes on inaccurate matching and affecting the matching results, thereby improving the effectiveness of matching. Moreover, based on the matching results combined with the expansion ratio, information is updated according to the first perception collection change information and the second perception collection change information, so that only the first perception collection change information and the second perception collection change information need to be updated according to the matching results, thereby eliminating the impact of proportional expansion on information updating, avoiding updating of unchanged information, and completing information updates faster.

[0096] like Figure 2 As shown, in one embodiment provided by the present invention, a network attack and defense simulation is performed based on a network attack and defense demonstration scenario combined with a network attack type, including:

[0097] S31. Perform scenario operation simulation for the network attack and defense demonstration scenario to obtain an application scenario in the operating state;

[0098] S32. Obtain a network attack virtual instruction according to the network attack type, and obtain an attack simulation signal based on the network attack virtual instruction;

[0099] S33. In an application scenario under operation, a network attack is carried out using an attack simulation signal, and a network defense demonstration is carried out based on the network defense technology in the network attack and defense demonstration scenario to obtain network attack and defense simulation information.

[0100] In the above technical solution, different network attack types correspond to different network attack virtual instructions, and there is also a mapping relationship between the network attack virtual instructions and the attack simulation signals.

[0101] In the above technical solution, when using attack simulation signals to carry out network attacks, corresponding attack simulation signal network attacks are carried out for all types of network attacks.

[0102] The above technical solution performs scenario operation simulation on the network attack and defense demonstration scenario to restore the actual situation of the application scenario in the network attack and defense demonstration scenario, thereby reducing the error between the network attack and defense demonstration scenario and the actual application scenario, and obtains network attack virtual instructions according to the type of network attack and obtains attack simulation signals based on the network attack virtual instructions, thereby achieving comprehensive consideration of network attacks, so that when using attack simulation signals to carry out network attacks, comprehensive network attack and defense demonstrations and network defense demonstrations are carried out, thereby improving the comprehensiveness of network attack and defense simulation information.

[0103] In one embodiment provided by the present invention, using an attack simulation signal to conduct a network attack includes:

[0104] Obtain the network attack type of the attack simulation signal;

[0105] Determine the location of network attacks in network attack and defense demonstration scenarios based on the type of network attacks;

[0106] Analyze the number of cyber attack locations;

[0107] When the number of network attack locations is one, an attack simulation signal is invaded at the network attack location, and the attack simulation signal is used to conduct a network attack in the network attack and defense demonstration scenario;

[0108] When the number of network attack positions is two or more, the network attack positions are arranged and combined to obtain multiple groups of network attack combination positions. The network attack combination positions are used as target attack positions, and then attack simulation signal invasion is carried out on the target attack positions. The attack simulation signal is used to carry out network attacks in the network attack and defense demonstration scenario.

[0109] In the above technical solution, when the network attack positions are arranged and combined, each network attack position is used as a target attack position respectively. At the same time, when two or more combinations are made, the network attack positions in the combination are used as target attack positions together.

[0110] In the above technical solution, when the network attack combination position is used as the target attack position, the network attack position is used as the target attack position in turn, and the attack simulation signal is invaded at the target attack position, and then the attack simulation signal is used to carry out a network attack in the network attack and defense demonstration scenario, and the network attack position is combined to obtain an attack combination result, and the attack combination result is used as the target attack position, and then the attack simulation signal is used to invade the network attack position in the attack combination result at the same time in the network attack and defense demonstration scenario.

[0111] The above technical solution obtains the network attack type of the attack simulation signal so that when using the attack simulation signal to carry out a network attack, different methods of demonstration simulation are adopted according to the different attack simulation signals, thereby improving the comprehensiveness of the network defense demonstration, reducing the one-sided error of the network defense demonstration, and thus improving the accuracy of the network attack and defense simulation early warning method.

[0112] like Figure 3 As shown, in one embodiment provided by the present invention, security vulnerability analysis is performed on network attack and defense simulation information, including:

[0113] S41. In the network attack and defense demonstration scenario, obtain information on network defense technology to obtain current network defense information;

[0114] S42. Determine security vulnerability analysis indicators for the current network defense information, and identify and extract related information from the network attack and defense simulation information according to the security vulnerability analysis indicators to obtain security vulnerability analysis indicator related information;

[0115] S43. Analyze and calculate security vulnerability analysis indicator data based on the security vulnerability analysis indicator correlation information to obtain security vulnerability analysis indicator information.

[0116] S44. Perform security situation analysis on the security vulnerability analysis indicator information in combination with the target defense standard to obtain security situation analysis data;

[0117] S45. Determine whether there are security loopholes in the current network defense based on the security situation analysis data, and obtain the network attack and defense simulation results.

[0118] In the above technical solution, security vulnerability analysis indicators include: confidentiality, integrity and availability.

[0119] In the above technical solution, when performing security vulnerability analysis indicator data analysis and calculation based on security vulnerability analysis indicator correlation information, security vulnerability analysis indicator influence analysis and calculation are performed on the security vulnerability.

[0120] In the above technical solution, the security situation analysis data is a fuzzy analysis result, including three levels: high, medium and low.

[0121] The above technical solution realizes the quantification of network attack and defense simulation information, enables quantitative calculation according to security vulnerability analysis indicators, provides intuitive data support for security vulnerability analysis, and uses fuzzy analysis results to summarize security situation analysis data, ensuring the comprehensiveness and accuracy of security situation analysis data while reducing the complexity of security situation analysis data, improving the analysis efficiency of security vulnerability analysis, and obtaining network attack and defense simulation results in a shorter time, reducing the time consumption of network attack and defense simulation warning, and thus timely issuing security vulnerability warnings, so that relevant personnel can optimize network attack and defense according to security vulnerabilities in a timely manner, reduce the risk of security vulnerabilities in application scenarios, and improve security protection capabilities.

[0122] In one embodiment of the present invention, the target defense standard is determined based on current network defense information and includes:

[0123] Obtain security defense standards for security defense technologies;

[0124] Perform security defense feature analysis based on current network defense information to obtain security defense features of the current network defense;

[0125] Determine the security defense type of the current network defense technology based on the security defense characteristics of the current network defense;

[0126] The security defense types of current network defense technologies are used to screen and adjust the security defense standards to obtain the target security defense standards.

[0127] In the above technical solution, the security defense features include: local area network defense technology, wide area network defense technology, etc.

[0128] In the above technical solution, the security defense standard obtained for security defense technology is a universal security defense standard.

[0129] In the above technical solution, when the security defense type of the current network defense technology is used to screen and adjust the security defense standard, the security defense standard is screened in combination with the security defense type of the current network defense technology, including: conducting a preliminary analysis of the security defense standard to determine the basic security defense standard and the characteristic security defense standard; matching the characteristic security defense standard according to the security defense type of the current network defense technology, and screening the corresponding characteristic security defense standard according to the matching result to obtain the target characteristic security defense standard; analyzing whether the target characteristic security defense standard needs to be adjusted in combination with the security defense characteristics of the current network defense, and when adjustment is required, making micro-adjustments to the target characteristic security defense standard according to the security defense characteristics of the current network defense to obtain the adjusted target characteristic security defense standard; combining the basic security defense standard with the target characteristic security defense standard or the adjusted target characteristic security defense standard to obtain the target security defense standard.

[0130] The above technical solution fully considers the differences between security defense types. This allows for the determination of target security defense standards by utilizing the security defense types of current network defense technologies to screen and adjust the security defense standards. This takes into account the differences between different security defense types within the security defense standards, thereby reducing errors in the security defense standards and improving the accuracy of the target security defense standards. Furthermore, when utilizing the security defense types of current network defense technologies to screen and adjust the security defense standards, a preliminary analysis of the security defense standards is conducted, dividing them into basic security defense standards and characteristic security defense standards. This allows for direct matching and adjustment of the characteristic security defense standards during screening and adjustment, improving the efficiency of determining the target security defense standards and ensuring the adaptability of the target characteristic security defense standards.

[0131] In one embodiment provided by the present invention, after obtaining the target security defense standard, the target security defense standard is further verified, including:

[0132] Conduct idealized defense performance analysis based on current network defense information to determine idealized defense information for current network defense;

[0133] Verify the target security defense standard in combination with the idealized defense information of the current network defense to determine whether the idealized defense information of the current network defense is consistent with the target security defense standard, and obtain verification analysis results;

[0134] The target security defense standard is corrected based on the verification analysis results. When the idealized defense information of the current network defense is inconsistent with the target security defense standard, the difference information between the idealized defense information of the current network defense and the target security defense standard is analyzed to obtain the difference analysis data. The target security defense standard is corrected and modified according to the difference analysis data to obtain the final target security defense standard.

[0135] In the above technical solution, when the idealized defense information of the current network defense is consistent with the target security defense standard, there is no need to make corrections based on the target security defense standard.

[0136] The above technical solution verifies the target security defense standard by combining the idealized defense information of the current network defense, clarifies the difference between the idealized defense situation of the current network defense and the target security defense standard, and improves the adaptability of the target security defense standard to the current network defense by correcting the target security defense standard, reduces the error of the target security defense standard, and thus provides a guarantee for conducting security situation analysis based on security vulnerability analysis indicator information in combination with the target defense standard.

[0137] In one embodiment provided by the present invention, when a security vulnerability warning is performed according to a network attack and defense simulation result, when the network attack and defense simulation result shows that there is no security vulnerability in the current network defense, the security situation analysis data is summarized to obtain a summary result, and the summary result is used to perform a network attack and defense simulation result warning according to a first security vulnerability warning method; when the network attack and defense simulation result shows that there is a security vulnerability in the current network defense, security vulnerability data information is obtained from the security situation analysis data, and a security vulnerability impact analysis is performed based on the security vulnerability data information to determine the impact type of the security vulnerability, and then a warning setting match is performed in the first security vulnerability warning method according to the impact type of the security vulnerability to obtain a target security vulnerability warning, thereby performing a network attack and defense simulation result warning according to the target security vulnerability warning.

[0138] In the above technical solution, the first warning method of security vulnerabilities is different from the second warning method of security vulnerabilities. Among them, the first warning method of security vulnerabilities is usually a notification-type warning, and the second warning method of security vulnerabilities is usually a vigilance warning. Moreover, in the second warning method of security vulnerabilities, the warning settings such as the vigilance frequency and sound for different impact types are different.

[0139] The above technical solution uses different security vulnerability warning methods to provide different security vulnerability warnings in different situations, making the security vulnerability warnings have distinct characteristics. This allows relevant personnel to directly understand the general situation of the security vulnerability based on the security vulnerability warning, providing psychological preparation for relevant personnel to respond to the security vulnerability. The first security vulnerability warning method allows security situation analysis data to be provided even when no security vulnerability exists, allowing relevant personnel to understand the network attack and defense simulation situation through the summary results. The second security vulnerability warning method uses different warning settings to increase the vigilance of relevant personnel.

[0140] In one embodiment provided by the present invention, after obtaining the network attack and defense simulation results, current network defense optimization is performed based on the network attack and defense simulation results, including:

[0141] When the network attack and defense simulation results show that there are security vulnerabilities in the current network defense, a fault analysis is performed on the security vulnerabilities to obtain security vulnerability analysis data;

[0142] Combine the current network defense information with the security vulnerability analysis data to optimize the analysis, determine the improvement plan for the current network defense, and obtain the current network defense optimization information;

[0143] Optimize network defense for network attack and defense demonstration scenarios based on current network defense optimization information;

[0144] Based on the optimized network defense, the network attack and defense simulation is performed again in the network attack and defense demonstration scenario to obtain the optimized network attack and defense simulation information;

[0145] Conduct security vulnerability analysis on the optimized network attack and defense simulation information to obtain the network attack and defense simulation results;

[0146] According to the results of the network attack and defense simulation, the current network defense optimization information is adjusted, and the adjusted current network defense optimization information is used to perform network defense optimization and network attack and defense simulation for the network attack and defense demonstration scenario until the network attack and defense simulation results show that there are no security vulnerabilities in the current network defense. At this time, the current network defense optimization information is obtained, the target network defense optimization information is obtained, and security vulnerability revision prompts are provided for the target network defense optimization information.

[0147] In the above technical solution, when adjusting the current network defense optimization information according to the network attack and defense simulation results, if the network attack and defense simulation results show that there are no security vulnerabilities in the current network defense, there is no need to adjust the current network defense optimization information. At this time, the current network defense optimization information is the target network defense optimization information.

[0148] In the above technical solution, when using the adjusted current network defense optimization information to perform network defense optimization and network attack and defense simulation for the network attack and defense demonstration scenario, the network defense optimization and network attack and defense simulation are repeated multiple times until the network attack and defense simulation result shows that there are no security vulnerabilities in the current network defense.

[0149] In the above technical solution, the security vulnerability revision prompt can be carried out simultaneously with the security vulnerability warning, or the security vulnerability revision prompt can be carried out within a preset time after the security vulnerability warning.

[0150] The above technical solution optimizes and analyzes the security vulnerability analysis data in combination with the current network defense information, so as to clarify how the current network defense can be improved based on the security vulnerability, so that the current network defense optimization information can repair the security vulnerability. In addition, by re-simulating the network attack and defense in the network attack and defense demonstration scenario based on the optimized network defense, the credibility of the current network defense optimization information is improved. By adjusting the current network defense optimization information according to the network attack and defense simulation results, the accuracy of the target network defense optimization information is improved, and the deviation of the target network defense optimization information is reduced. In addition, by providing security vulnerability revision prompts for the target network defense optimization information, relevant personnel can directly revise the security vulnerability according to the security vulnerability revision prompts, thereby providing convenience for revising the security vulnerability.

[0151] Those skilled in the art should understand that the first and second in the present invention merely refer to different application stages.

[0152] Other embodiments of the present disclosure will readily occur to those skilled in the art after considering the specification and practicing the disclosure herein. This application is intended to cover any variations, uses, or adaptations of the present disclosure that follow from the general principles of the present disclosure and include common knowledge or customary techniques in the art not disclosed herein. The description and examples are to be considered as exemplary only, with the true scope and spirit of the present disclosure being indicated by the following claims.

[0153] It should be understood that the present disclosure is not limited to the exact structures that have been described above and shown in the drawings, and that various modifications and changes can be made without departing from the scope thereof. The scope of the present disclosure is limited only by the appended claims.

Claims

1. A network attack and defense simulation early warning method based on endpoint perception, characterized in that: include: Determine the application scenarios of network attack and defense, and collect application scenario information through endpoint perception to obtain application scenario collection information; Collect information based on application scenarios to establish network attack and defense demonstration scenarios; Conduct network attack and defense simulation based on network attack and defense demonstration scenarios and network attack types to obtain network attack and defense simulation information; Conduct security vulnerability analysis on network attack and defense simulation information to obtain network attack and defense simulation results; Issue security vulnerability warnings based on network attack and defense simulation results.

2. The network attack and defense simulation early warning method according to claim 1, characterized in that: The endpoints include: first-class endpoints and second-class endpoints, wherein the first-class endpoints are information collection endpoints determined according to application scenarios, and real-time information perception and collection is performed for the application scenarios through the first-class endpoints to obtain first perception and collection information; the second-class endpoints are information collection endpoints determined according to network defense technology, and real-time information perception and collection is performed for the network defense technology through the second-class endpoints to obtain second perception and collection information.

3. The network attack and defense simulation early warning method according to claim 2, characterized in that: Collect information based on the application scenario to establish a network attack and defense demonstration scenario, including: Perform application scenario architecture analysis on the first perception collected information to determine the target application scenario architecture information; Create a simulation model according to the target application scenario architecture information to obtain an application scenario model; Supplementing the application scenario model with first information based on the first perception-collected information to obtain an initial application scenario; Supplementing the initial application scenario with second information based on the second perception-collected information to obtain a network attack and defense demonstration scenario; At the same time, real-time information analysis is performed on the first perception collected information and the second perception collected information to determine whether information needs to be updated for the network attack and defense demonstration scenario, and obtain real-time information analysis results; According to the real-time information analysis results, when information needs to be updated for the network attack and defense demonstration scenario, the updated information is determined based on the first perception collection information and the second perception collection information, and matched and updated in the network attack and defense demonstration scenario according to the updated information.

4. The network attack and defense simulation early warning method according to claim 1, characterized in that: Conduct network attack and defense simulations based on network attack and defense demonstration scenarios and network attack types, including: Conduct scenario operation simulation for network attack and defense demonstration scenarios to obtain application scenarios under operation status; Obtaining a network attack virtual instruction according to the network attack type, and obtaining an attack simulation signal based on the network attack virtual instruction; In the application scenario under the operating state, the attack simulation signal is used to carry out a network attack, and the network defense demonstration is carried out based on the network defense technology in the network attack and defense demonstration scenario to obtain the network attack and defense simulation information.

5. The network attack and defense simulation early warning method according to claim 4, characterized in that: Using attack simulation signals to carry out network attacks, including: Obtain the network attack type of the attack simulation signal; Determine the location of network attacks in network attack and defense demonstration scenarios based on the type of network attacks; Analyze the number of cyber attack locations; When the number of network attack locations is one, an attack simulation signal is invaded at the network attack location, and the attack simulation signal is used to conduct a network attack in the network attack and defense demonstration scenario; When the number of network attack positions is two or more, the network attack positions are arranged and combined to obtain multiple groups of network attack combination positions. The network attack combination positions are used as target attack positions, and then attack simulation signal invasion is carried out on the target attack positions. The attack simulation signal is used to carry out network attacks in the network attack and defense demonstration scenario.

6. The network attack and defense simulation early warning method according to claim 1, characterized in that: Conduct security vulnerability analysis based on network attack and defense simulation information, including: In the network attack and defense demonstration scenario, information is obtained on network defense technology to obtain current network defense information; Determine security vulnerability analysis indicators based on current network defense information, and identify and extract related information from network attack and defense simulation information based on security vulnerability analysis indicators to obtain security vulnerability analysis indicator related information; Perform security vulnerability analysis indicator data analysis and calculation based on security vulnerability analysis indicator correlation information to obtain security vulnerability analysis indicator information; Combined with the target defense standards, security situation analysis is performed on the security vulnerability analysis indicator information to obtain security situation analysis data; Based on the security situation analysis data, determine whether there are security loopholes in the current network defense and obtain the network attack and defense simulation results.

7. The network attack and defense simulation early warning method according to claim 6, characterized in that: The target defense criteria are determined based on current network defense information and include: Obtain security defense standards for security defense technologies; Perform security defense feature analysis based on current network defense information to obtain security defense features of the current network defense; Determine the security defense type of the current network defense technology based on the security defense characteristics of the current network defense; The security defense types of current network defense technologies are used to screen and adjust the security defense standards to obtain the target security defense standards.

8. The network attack and defense simulation early warning method according to claim 7, characterized in that: After obtaining the target security defense standards, the target security defense standards are also verified, including: Conduct idealized defense performance analysis based on current network defense information to determine idealized defense information for current network defense; Verify the target security defense standard in combination with the idealized defense information of the current network defense to determine whether the idealized defense information of the current network defense is consistent with the target security defense standard, and obtain verification analysis results; The target security defense standard is corrected based on the verification analysis results. When the idealized defense information of the current network defense is inconsistent with the target security defense standard, the difference information between the idealized defense information of the current network defense and the target security defense standard is analyzed to obtain the difference analysis data. The target security defense standard is corrected and modified according to the difference analysis data to obtain the final target security defense standard.

9. The network attack and defense simulation early warning method according to claim 6, characterized in that: When issuing a security vulnerability warning based on the network attack and defense simulation results, if the network attack and defense simulation results indicate that there are no security vulnerabilities in the current network defense, the security situation analysis data is summarized to obtain a summary result, and the summary result is used to issue a network attack and defense simulation result warning based on the security vulnerability first warning method; When the network attack and defense simulation result shows that there is a security vulnerability in the current network defense, security vulnerability data information is obtained based on the security situation analysis data, and security vulnerability impact analysis is performed based on the security vulnerability data information to determine the impact type of the security vulnerability. Then, according to the impact type of the security vulnerability, the warning setting is matched in the first warning mode of the security vulnerability to obtain the target security vulnerability warning, and the network attack and defense simulation result warning is performed according to the target security vulnerability warning.

10. The network attack and defense simulation early warning method according to claim 6, characterized in that: After obtaining the network attack and defense simulation results, the current network defense is optimized based on the network attack and defense simulation results, including: When the network attack and defense simulation results show that there are security vulnerabilities in the current network defense, a fault analysis is performed on the security vulnerabilities to obtain security vulnerability analysis data; Combine the current network defense information with the security vulnerability analysis data to optimize the analysis, determine the improvement plan for the current network defense, and obtain the current network defense optimization information; Optimize network defense for network attack and defense demonstration scenarios based on current network defense optimization information; Based on the optimized network defense, the network attack and defense simulation is performed again in the network attack and defense demonstration scenario to obtain the optimized network attack and defense simulation information; Conduct security vulnerability analysis on the optimized network attack and defense simulation information to obtain the network attack and defense simulation results; According to the results of the network attack and defense simulation, the current network defense optimization information is adjusted, and the adjusted current network defense optimization information is used to perform network defense optimization and network attack and defense simulation for the network attack and defense demonstration scenario until the network attack and defense simulation results show that there are no security vulnerabilities in the current network defense. At this time, the current network defense optimization information is obtained, the target network defense optimization information is obtained, and security vulnerability revision prompts are provided for the target network defense optimization information.