Communication address banning capability assessment method and device, storage medium and terminal
Through the automated evaluation method, the problem of inefficient evaluation of communication address ban capability in the prior art is solved, more efficient and comprehensive security equipment evaluation is achieved, and network security policies are optimized.
Patent Information
- Application Number
- CN202510887323.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-27
- Publication Date
- 2025-08-08
AI Technical Summary
The existing method of evaluating communication address ban capability relies on manual operation, is inefficient and has limited coverage, making it difficult to adapt to the increasingly complex security threat environment.
It provides an automated communication address blocking capability evaluation method, determines the target access system and test execution methods through the terminal, and uses simulated attack systems to automatically evaluate the blocking capability of security equipment, and obtains access response results for evaluation.
It improves the efficiency and coverage of the evaluation, can accurately identify the shortcomings of security equipment, optimize security policies, and improve network security protection level.
Smart Images

Figure CN120455162A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer security, and in particular to a method, device, storage medium, and terminal for evaluating the blocking capability of a communication address. Background Art
[0002] With the development of the Internet, network security threats are becoming increasingly severe. Attackers such as hackers and malware try to use various means to destroy systems or steal data. Network communication addresses, such as Internet Protocol (IP) addresses, as the basic identifier of network communication, often become the entry point or attack source of these attackers. Therefore, by blocking known malicious network communication addresses through security devices, the back-end system can be protected from access and potential attacks by malicious communication addresses. On this basis, evaluating the communication address blocking capability of security devices can confirm whether the security devices can correctly identify and block access to malicious communication addresses as expected. Existing communication address blocking capability assessments usually rely on manual work, which can, to a certain extent, discover configuration defects in security devices and optimize communication address blocking strategies to ensure the effective operation of network security defense systems. However, traditional security device communication address blocking capability assessment methods still have problems such as low efficiency and limited coverage, and are difficult to adapt to the increasingly complex security threat environment. Summary of the Invention
[0003] The present application provides a method, device, storage medium and terminal for evaluating the blocking capability of a communication address, so as to solve the problems of low efficiency and limited coverage existing in the above-mentioned manual blocking capability evaluation.
[0004] In a first aspect, an embodiment of the present application provides a method for evaluating communication address blocking capability, the method comprising:
[0005] In response to an execution request for a target assessment task, determining a target access system corresponding to the target assessment task, wherein the target access system includes a target security device for performing communication security protection;
[0006] Determine a test execution means and at least one test communication address corresponding to the target assessment task, and access the target access system according to the test execution means through each test communication address;
[0007] Obtain the access response result of the target access system and evaluate the communication address blocking capability of the target security device based on the access response result.
[0008] In a second aspect, an embodiment of the present application provides a device for evaluating communication address blocking capability, the device comprising:
[0009] a target determination module, configured to determine, in response to an execution request for a target assessment task, a target access system corresponding to the target assessment task, wherein the target access system contains a target security device for performing communication security protection;
[0010] An access module is used to determine a test execution means and at least one test communication address corresponding to a target assessment task, and to access a target access system according to the test execution means through each test communication address;
[0011] The result determination module is used to obtain the access response result of the target access system and evaluate the communication address blocking capability of the target security device based on the access response result.
[0012] In a third aspect, an embodiment of the present application provides a computer storage medium, wherein the computer storage medium stores a plurality of instructions, and the instructions are suitable for being loaded by a processor and executing the steps of the above method.
[0013] In a fourth aspect, an embodiment of the present application provides a terminal comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program is suitable for being loaded by the processor and executing the steps of the above method.
[0014] The beneficial effects of the technical solutions provided by some embodiments of the present application include at least:
[0015] The present application provides a method for evaluating the communication address blocking capability. In response to an execution request for a target evaluation task, a target access system corresponding to the target evaluation task is determined, and a target security device for communication security protection exists in the target access system; a test execution means and at least one test communication address corresponding to the target evaluation task are determined, and the target access system is accessed according to the test execution means through each test communication address; an access response result of the target access system is obtained, and the communication address blocking capability of the target security device is evaluated based on the access response result. When it is necessary to execute a target assessment task, first, by responding to a specific execution request, the target access system corresponding to the target assessment task can be accurately identified and located, ensuring the pertinence and accuracy of the assessment process. At the same time, each assessment task can also select different target access systems according to different assessment requirements, enhancing the scope of application of the method; next, by clarifying the test execution means and multiple test communication addresses, and accessing the target access system based on this, it can automatically simulate actual attack scenarios from different angles, thereby triggering the communication address blocking mechanism of the target security device in the target access system under different circumstances, thereby improving the execution efficiency and coverage of the blocking capability assessment; finally, the communication address blocking capability of the target security device is evaluated through the access response result of the target access system, which can test the response capability and blocking effect of the target security device when facing different potential threats, thereby identifying the shortcomings of the target security device in communication address blocking, helping to optimize the security policy of the target security device, and improving the security protection level of the target access system. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present application. For those skilled in the art, other drawings can be obtained based on these drawings without paying any creative work.
[0017] Figure 1 An exemplary system architecture diagram of a method for evaluating communication address blocking capability provided in an embodiment of the present application;
[0018] Figure 2 A flowchart of a method for evaluating communication address blocking capability provided in an embodiment of the present application;
[0019] Figure 3 A flowchart of a method for evaluating communication address blocking capability provided in an embodiment of the present application;
[0020] Figure 4A schematic diagram of a simulated attack task creation interface for a method for evaluating communication address blocking capability provided in an embodiment of the present application;
[0021] Figure 5 A flowchart of a method for evaluating communication address blocking capability provided in an embodiment of the present application;
[0022] Figure 6 A schematic diagram of a verification task creation interface for a method for evaluating communication address blocking capability provided in an embodiment of the present application;
[0023] Figure 7 A structural block diagram of a communication address blocking capability evaluation device provided in an embodiment of the present application;
[0024] Figure 8 A schematic diagram of the structure of a terminal provided in an embodiment of the present application. DETAILED DESCRIPTION
[0025] To make the features and advantages of this application more obvious and easy to understand, the technical solutions in the embodiments of this application will be clearly and completely described below in conjunction with the drawings in the embodiments of this application. Obviously, the described embodiments are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without making creative efforts shall fall within the scope of protection of this application.
[0026] When the following description refers to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present application. Instead, they are merely examples of devices and methods consistent with certain aspects of the present application, as detailed in the appended claims.
[0027] With the rapid development of the internet, the threats facing network security are becoming increasingly severe. Various cyber attackers, including hackers and malware, attempt to compromise system integrity or steal sensitive data through various means, such as Structured Query Language Injection (SQLi) and Cross-Site Scripting (XSS). In network communications, communication addresses (such as Internet Protocol (IP) addresses) serve as basic identifiers and often serve as entry points or attack sources for these attackers. To protect back-end systems from access and potential attacks from malicious communication addresses, security devices typically implement blocking policies for known malicious network communication addresses. Therefore, evaluating the communication address blocking capabilities of security devices is particularly important. Existing communication address blocking capability assessments typically rely on manual operations, which can, to a certain extent, verify whether security devices can accurately identify and effectively block access requests from malicious communication addresses, thereby optimizing the communication address blocking policies to ensure the robustness and effectiveness of network security defense systems.
[0028] However, manual assessments are cumbersome, time-consuming, and lack repeatability, making it difficult to quickly complete large-scale, high-intensity testing tasks or conduct long-term, continuous security monitoring. This results in inflexible and inefficient assessments. Furthermore, manual assessments often fail to cover all possible attack scenarios and communication addresses, easily missing potential security vulnerabilities and threats, and questioning the comprehensiveness and accuracy of assessment results. Given these issues, manual assessments of security devices' communication address blocking capabilities are struggling to cope with the increasingly complex security threat landscape.
[0029] Therefore, an embodiment of the present application provides a method for evaluating the blocking capability of a communication address to solve the problems of low efficiency and limited coverage in the above-mentioned manual blocking capability evaluation.
[0030] See also Figure 1 , Figure 1 An exemplary system architecture diagram of a method for evaluating communication address blocking capability provided in an embodiment of the present application.
[0031] like Figure 1As shown, the system architecture may include a terminal 101, a network 102, and a server 103. The network 102 is used to provide a medium for a communication link between the terminal 101 and the server 103. The network 102 may include various types of wired communication links or wireless communication links, for example, a wired communication link may include an optical fiber, a twisted pair, or a coaxial cable, and a wireless communication link may include a Bluetooth communication link, a Wireless-Fidelity (Wi-Fi) communication link, or a microwave communication link.
[0032] The terminal 101 can interact with the server 103 via the network 102 to receive messages from the server 103 or send messages to the server 103. Alternatively, the terminal 101 can interact with the server 103 via the network 102 to receive messages or data sent to the server 103 by other users. The user starts an assessment task on the terminal 101 and selects the target access system to be assessed. For example, when a target assessment task needs to be executed, the terminal 101 generates an execution request for the target assessment task and sends the request to the server 103 via the network 102. After receiving the execution request from the terminal 101, the server 103 parses the request content and determines the target access system corresponding to the target assessment task and the target security device within it.
[0033] Terminal 101 may be hardware or software. When terminal 101 is hardware, it may be various electronic devices, including but not limited to tablet computers, laptop computers, and desktop computers. When terminal 101 is software, it may be installed in the electronic devices listed above. It may be implemented as multiple software or software modules (for example, to provide distributed services) or as a single software or software module, without specific limitation herein.
[0034] In an embodiment of the present application, the terminal 101 first responds to the execution request for the target assessment task, determines the target access system corresponding to the target assessment task, and the target access system contains a target security device for communication security protection; then, the terminal 101 determines the test execution means and at least one test communication address corresponding to the target assessment task, and accesses the target access system according to the test execution means through each test communication address; finally, the terminal 101 obtains the access response result of the target access system, and evaluates the communication address blocking capability of the target security device based on the access response result.
[0035] The server 103 may be a business server that provides various services. It should be noted that the server 103 may be hardware or software. When the server 103 is hardware, it may be implemented as a distributed server cluster consisting of multiple servers, or it may be implemented as a single server. When the server 103 is software, it may be implemented as multiple software or software modules (for example, for providing distributed services), or it may be implemented as a single software or software module, which is not specifically limited herein.
[0036] Alternatively, the system architecture may also not include the server 103. In other words, the server 103 may be an optional device in the embodiments of this specification, that is, the method provided in the embodiments of this specification may be applied to a system structure that only includes the terminal 101, and the embodiments of this application do not limit this.
[0037] It should be understood that Figure 1 The number of terminals, networks, and servers in the figure is only for illustration and any number of terminals, networks, and servers may be used according to implementation requirements.
[0038] See also Figure 2 , Figure 2 A flowchart of a method for evaluating communication address blocking capability provided in an embodiment of the present application. The execution subject of an embodiment of the present application can be a terminal that performs the evaluation of communication address blocking capability, a processor in a terminal that performs the method for evaluating communication address blocking capability, or a communication address blocking capability evaluation service in a terminal that performs the method for evaluating communication address blocking capability. For ease of description, the specific execution process of the method for evaluating communication address blocking capability is described below, taking the execution subject as a processor in a terminal as an example.
[0039] like Figure 2 As shown, the evaluation method of the communication address blocking capability may at least include:
[0040] S202: In response to an execution request for a target assessment task, determine a target access system corresponding to the target assessment task, where a target security device for communication security protection exists in the target access system.
[0041] Optionally, each security device, such as a firewall, intrusion detection system (IDS), or intrusion prevention system (IPS), provides security protection services for a specific access system. They monitor, analyze, and filter network traffic to identify and block potential malicious activity and block malicious communication addresses (e.g., IP addresses) that initiate attacks, thereby protecting the access system from various network attacks and threats. To verify the blocking capabilities of these security devices, their blocking policies must be triggered and tested by actually accessing the access system they protect.
[0042] Based on this, when a target assessment task is required, the target access system corresponding to the task must first be identified and determined. This allows for the ability to launch a simulated attack against the target access system to verify whether the target security device in that system can perform communication address blocking operations as expected. For example, if the abnormal behavior threshold or attack signature is correctly set, when the simulated attack traffic meets these conditions, the target security device should automatically initiate the blocking mechanism.
[0043] Optionally, in the field of simulated attacks, the Breach and Attack Simulation (BAS) system can evaluate the overall security effectiveness of security devices by continuously and automatically simulating various types of attack scenarios. The method of the embodiment of the present application can use this feature of the BAS system to evaluate the blocking capabilities of security devices. The BAS system supports the automated creation and execution of evaluation tasks. When executing the method of the embodiment of the present application through the BAS system, we can pre-set the evaluation scenarios, trigger conditions, blocking strategies, etc., and then let the BAS system automatically execute these tasks, thereby triggering the communication address blocking strategy of the security device and observing its response.
[0044] S204: Determine a test execution means and at least one test communication address corresponding to the target assessment task, and access the target access system according to the test execution means through each test communication address.
[0045] Optionally, a real malicious communication address attack may include a variety of execution methods, covering a wider range of attack types and scenarios. In order to ensure that the simulated attack matches the actual application scenario of the target security device and accurately evaluate the performance of the device in the face of a specific type of threat, in addition to determining the object of the simulated attack (target access system), it is also necessary to further determine the means of simulated attack (test execution means) and the initiator of the attack (test communication address). Specifically, the test execution means is directly related to the specific behavior pattern of the simulated attack, which includes at least specific test behavior types (such as abnormal traffic blocking, malicious scanning blocking, etc.) and corresponding test behavior thresholds (such as attack frequency, duration, etc.). These means are intended to trigger the IP blocking policy of the target security device by simulating real-world network attack scenarios; the test communication address is the specific communication address used to initiate the simulated attack, which can be a single communication address or an address pool consisting of multiple communication addresses.
[0046] Optionally, after determining the various simulated attack items corresponding to the target assessment task, you can try to access the target access system through the selected test communication address according to the predetermined test execution method. In order to facilitate the subsequent evaluation of the simulated attack results, you can monitor the response of the target access system in real time during the execution of the task, and record the detailed parameters of each access (such as time, communication address, access port, test behavior type, etc.) and the immediate response of the target access system (such as blocking status, response time, returned status code, etc.). Furthermore, if it is found that some malicious requests are not correctly blocked, you can also dynamically adjust the attack parameters based on the preliminary results, such as increasing the request frequency or changing the content of the request.
[0047] S206: Obtain an access response result of the target access system, and evaluate the communication address blocking capability of the target security device based on the access response result.
[0048] Optionally, after accessing the target access system through each test communication address in accordance with the preset test execution means, the simulated attack behavior against the target access system has been completed. At this time, it is also necessary to further verify whether the target assessment system has banned the malicious communication address in this process, so as to evaluate whether the target security device has played a due security protection role for the target assessment system. Based on this, after the simulated attack behavior is completed, the method of the embodiment of the present application will also obtain and record the access response data returned by the target access system for this target assessment task through methods such as connectivity detection or log analysis. These data are the access response results of the target access system for the target assessment task, which include but are not limited to key information such as HyperText Transfer Protocol (HTTP) response status code, response content, and response time.
[0049] Furthermore, in-depth analysis of the collected access response results will directly reflect whether the target security device successfully identified and blocked illegal or potentially malicious communication attempts. For example, it checks whether a specific status code (such as 403 Forbidden) indicates that access is denied, or whether the response content contains specific blocking prompt information. In addition, the response differences between different test communication addresses can be compared to identify which addresses were successfully blocked and which were not effectively blocked.
[0050] In an embodiment of the present application, a method for evaluating the communication address blocking capability is provided. In response to an execution request for a target evaluation task, a target access system corresponding to the target evaluation task is determined, and a target security device for communication security protection exists in the target access system; a test execution means and at least one test communication address corresponding to the target evaluation task are determined, and the target access system is accessed according to the test execution means through each test communication address; an access response result of the target access system is obtained, and the communication address blocking capability of the target security device is evaluated based on the access response result. When it is necessary to execute a target assessment task, first, by responding to a specific execution request, the target access system corresponding to the target assessment task can be accurately identified and located, ensuring the pertinence and accuracy of the assessment process. At the same time, each assessment task can also select different target access systems according to different assessment requirements, enhancing the scope of application of the method; next, by clarifying the test execution means and multiple test communication addresses, and accessing the target access system based on this, it can automatically simulate actual attack scenarios from different angles, thereby triggering the communication address blocking mechanism of the target security device in the target access system under different circumstances, thereby improving the execution efficiency and coverage of the blocking capability assessment; finally, the communication address blocking capability of the target security device is evaluated through the access response result of the target access system, which can test the response capability and blocking effect of the target security device when facing different potential threats, thereby identifying the shortcomings of the target security device in communication address blocking, helping to optimize the security policy of the target security device, and improving the security protection level of the target access system.
[0051] See also Figure 3 , Figure 3 A flowchart of a method for evaluating communication address blocking capability provided in an embodiment of the present application.
[0052] like Figure 3 As shown, the evaluation method of the communication address blocking capability may at least include:
[0053] S302. In response to a configuration request for a target evaluation task, obtain the target test behavior type and target test behavior threshold input and / or selected by the user for the target evaluation task; and configure the test execution means corresponding to the target evaluation task according to the target test behavior type and target test behavior threshold.
[0054] Optionally, security devices usually have different defense mechanisms for different types of attacks. For example, when data transmission behaviors that are obviously beyond the normal range are identified, such as a sudden increase in request frequency, abnormally high data transmission volume and other attack behaviors, the security device may set threshold-based rules to limit the number of requests from malicious communication addresses (for example, if a certain IP address sends more than 1,000 requests to the server within one minute, it triggers a ban); and when hackers use automated tools to perform port scans on the network or system in an attempt to find existing vulnerabilities or unauthorized access points, the security device can identify rapid and continuous port scanning attempts and adopt a ban strategy according to preset rules. Based on this, when you need to configure a target assessment task, you first need to configure the target test behavior type that the task needs to simulate and its corresponding target test behavior threshold.
[0055] Specifically, Figure 4 This is a schematic diagram of a simulated attack task creation interface for a communication address blocking capability evaluation method provided in an embodiment of the present application, in which an example of a target evaluation task configuration interface is given. Figure 4 As shown, when a configuration request for a target assessment task is received, a configuration interface or process is first launched for the user to enter or select relevant configuration parameters. These parameters are used to accurately simulate actual attack scenarios and ensure that the assessment process accurately reflects the performance of security devices under specific conditions. First, users can enter or select the target test behavior type through this interface, such as abnormal traffic blocking, malicious scanning blocking, specific attack type blocking, etc. Each test behavior type corresponds to a different simulated attack scenario; further, for the determined target test behavior type, the user needs to set specific target test behavior thresholds, that is, execution policies. These thresholds may include judgment criteria such as traffic anomalies, frequency anomalies, and behavior pattern anomalies. For example, "accessing the same interface more than 1,000 times within 1 minute" may be abnormal traffic.
[0056] Optionally, the method of the embodiment of the present application will configure the corresponding test execution method for the user based on the target test behavior type and target test behavior threshold provided by the user, and automatically adjust the test execution strategy when executing the task. For example, if "abnormal traffic detection" is selected as the target test behavior type and the target test behavior threshold of "more than 1000 requests per minute" is set, a specific attack pattern and rules will be generated accordingly, and when the task is executed, traffic requests that exceed the normal range will be simulated.
[0057] It should be noted that in addition to the target test behavior type and target test behavior threshold, when creating a task, the user also needs to determine some basic information corresponding to the task, such as the test communication address for launching the simulated attack, the target security device to be evaluated and the target access system it protects (such as Figure 4 The information is used to accurately locate the specific environment involved in the target assessment task and ensure the effectiveness of subsequent tests. The embodiment of this application does not specifically limit the information category of basic information.
[0058] S304: In response to an execution request for the target assessment task, determine a target access system corresponding to the target assessment task, where a target security device for communication security protection exists in the target access system.
[0059] Optionally, regarding step S304, please refer to the detailed description in step S202, which will not be repeated here.
[0060] S306. Determine the target test behavior type, target test behavior threshold, and at least one test communication address corresponding to the target assessment task, and perform access behavior corresponding to the target test behavior type on the target access system according to the target test behavior threshold through each test communication address; the test communication address is a virtual test communication address configured according to the preset request header type.
[0061] Optionally, in order to ensure that the simulated attack matches the actual application scenario of the target security device and accurately evaluate the performance of the device when facing a specific type of threat, in addition to determining the target access system, it is also necessary to further determine the target test behavior type, target test behavior threshold and test communication address corresponding to the target assessment task.
[0062] Optionally, considering the large-scale blocking capability assessment, the virtual test communication address can simulate access requests from different sources or types to fully test the blocking capability of the target security device. Figure 4 The following diagram shows the interface for creating a simulated attack task. The test communication addresses here can be virtual test communication addresses dynamically generated based on preset request header types (such as X-Forwarded-For). These virtual addresses are implemented through internal simulation, eliminating the need to allocate or purchase additional real communication addresses. This reduces the demand for external network resources, thereby reducing bandwidth consumption and associated costs. Furthermore, virtual communication addresses allow for the simulation of virtually any possible communication address. This flexibility greatly expands the scope of the assessment, ensuring coverage of all potential attack scenarios.
[0063] Furthermore, the method of the embodiment of the present application will send simulated attack traffic to the target access system through each test communication address according to the predetermined target test behavior type and target test behavior threshold. For example, assuming that the test behavior type configured in the current target assessment task is "abnormal traffic blocking", it specifically includes detecting and blocking high-frequency communication requests from a single source communication address; the test behavior threshold is "the same interface is accessed more than 1,000 times within 1 minute and lasts for two minutes", then when the target assessment task is specifically executed, the method of the embodiment of the present application will perform an access operation of the test behavior type of "abnormal traffic blocking" on the target access system according to the test behavior threshold of "the same interface is accessed more than 1,000 times within 1 minute and lasts for two minutes".
[0064] S308. Obtain an access response result of the target access system, determine multiple quantitative evaluation indicators of the target security device's ability to block communication addresses based on the access response result, and generate a blocking capability evaluation report for the target security device based on each quantitative evaluation indicator.
[0065] Optionally, after completing the simulated attack, the method of the embodiment of the present application will obtain the access response result from the target access system, which includes but is not limited to key information such as the HTTP response status code, response content, response time, etc. This data reflects whether the target security device successfully identified and blocked the malicious communication address when facing a specific type of attack.
[0066] Furthermore, in order to more objectively and accurately measure the blocking capabilities of the target security device, after obtaining the access response results of the target access system, it is first necessary to analyze these results to determine multiple quantitative evaluation indicators of the target security device in terms of communication address blocking. These indicators may include but are not limited to: blocking success rate, that is, the proportion of test communication addresses successfully blocked by the target security device; blocking response time, that is, the time required from the initiation of malicious behavior to the actual execution of the blocking operation by the target security device; false blocking rate, that is, the proportion of legitimate communication addresses mistakenly blocked during the blocking process; resource consumption, that is, the computing resources and memory resources required by the target security device to perform the blocking operation; unblocking accuracy rate, that is, the proportion of addresses that can be accurately unblocked after the set blocking period, etc.
[0067] Optionally, the method of the embodiment of the present application can also generate a visual blocking capability assessment report for the target security device based on the above-mentioned collected data and the calculated quantitative evaluation indicators. Specifically, the report content includes but is not limited to the following parts: assessment task information, that is, an overview of the assessment scenario, trigger conditions, blocking strategy and other task configuration details; attack execution log, which records the specific execution process and results of each simulated attack for easy tracing and analysis; blocking verification results, which lists the blocking status of each test communication address, such as whether it is successfully blocked, whether the blocking duration meets expectations, etc.; quantitative evaluation conclusions, which summarize the results of various quantitative evaluation indicators, such as blocking success rate, average blocking effective time, false alarm rate, etc.; improvement suggestions, which make targeted optimization suggestions based on the evaluation results to help users adjust the configuration or strategy of the target security device to improve the security protection effectiveness. Among them, charts or other visualization tools can also be used to display the evaluation results so that users can intuitively understand the performance of the security device. For example, a bar chart can be used to compare the changing trend of the blocking success rate under different types of attacks, or a line chart can be used to show the relationship between the average blocking effective time and the attack frequency.
[0068] In an embodiment of the present application, a method for evaluating the communication address blocking capability is provided. By allowing users to customize the target test behavior type and the target test behavior threshold to flexibly configure the test execution means, it is possible to accurately test specific types of attack behaviors, thereby being able to more comprehensively and accurately simulate and evaluate the security protection capabilities of the target security device under different behavior modes; by using a virtual test communication address configured according to a preset request header type, it is possible to flexibly simulate any communication address and different types of network requests, thereby increasing the evaluation coverage and improving the complexity of the test, while also avoiding dependence on real communication address resources and reducing the evaluation cost; further, by determining multiple quantitative evaluation indicators and generating a blocking capability evaluation report, the communication address blocking capability of the target security device can be objectively and comprehensively measured, which is convenient for users to intuitively understand the performance and potential problems of the security device, and provide a scientific basis for performance optimization and policy adjustment of the security device.
[0069] See also Figure 5 , Figure 5 A flowchart of a method for evaluating communication address blocking capability provided in an embodiment of the present application.
[0070] like Figure 5 As shown, the evaluation method of the communication address blocking capability may at least include:
[0071] S502: In response to an execution request for a target assessment task, determine a target access system corresponding to the target assessment task, where a target security device for communication security protection exists in the target access system.
[0072] Optionally, regarding step S502, please refer to the detailed description in step S202, which will not be repeated here.
[0073] S504: Determine a test execution means corresponding to the target assessment task and at least one test communication address; the test communication address is a communication address where a real communication device is located.
[0074] Optionally, in order to ensure that the simulated attack matches the actual application scenario of the target security device and accurately evaluate the performance of the device in the face of a specific type of threat, in addition to determining the target access system, it is also necessary to further determine the test execution means and test communication address corresponding to the target assessment task. Among them, considering that the use of real communication addresses for testing can ensure that the simulated attack is as close as possible to the communication behavior in the actual network environment, the test communication address can also be the communication address where the real communication device is located. At the same time, selecting different types of real communication addresses for testing will help to comprehensively evaluate the performance of the target security device under different conditions. For example, by using communication addresses that have historically had security issues, real attack scenarios can be simulated to evaluate the effectiveness of the target security device in dealing with known threats; and known safe addresses can test the false alarm rate of the target security device under normal communication conditions to ensure that it does not mistakenly block legitimate communication addresses.
[0075] S506: Send the test execution means corresponding to the target evaluation task to each real communication device, and instruct each real communication device to access the target access system according to the test execution means.
[0076] Alternatively, if the test communication address is the communication address of a real communication device, when executing the target assessment task, the method of the embodiment of the present application will send the configured test execution means to each selected real communication device. These devices will launch a simulated attack on the target access system in a predetermined manner according to the received task instructions. For example, a server may send requests to the target access system at a frequency of 1000 times per second for two minutes.
[0077] S508. Perform at least one verification access operation on the target access system according to the expected blocking strategy corresponding to the target assessment task, and determine the access response result of the target access system for each verification access operation. The expected blocking strategy at least includes the expected blocking duration of each test communication address by the target security device; compare the access response result with the expected blocking strategy, and evaluate the communication address blocking capability of the target security device based on the comparison result.
[0078] Optionally, after the simulated attack behavior ends, the method of the embodiment of the present application will perform connectivity detection, that is, according to the expected blocking policy, perform at least one access verification operation on the target access system, and compare the actual access response result with the expected blocking policy, so as to comprehensively evaluate the communication address blocking capability of the target security device.
[0079] Specifically, Figure 4 This is a schematic diagram of a simulated attack task creation interface for a communication address blocking capability evaluation method provided in an embodiment of the present application, in which an example of a target evaluation task configuration interface is given. Figure 4 As shown in the figure, when creating a target assessment task, users need to set specific expected blocking policies, which are the benchmarks for security assessments and clarify how the target security device should respond to different types of test communication addresses. These policies include but are not limited to: expected blocking duration, for example, after a communication address is blocked, it is expected that the protected resource will not be accessible within 2 hours; the status code returned when blocked, such as 403Forbidden; and the unblocking mechanism, such as automatic unblocking upon expiration or manual unblocking conditions. Similarly, Figure 6 This is a schematic diagram of a verification task creation interface for a communication address blocking capability evaluation method provided in an embodiment of the present application, wherein an example configuration interface for a validity verification task is given. The validity verification task is a task for verifying the results of a target evaluation task. Figure 6 As shown, when creating a validity verification task, relevant information of the expected blocking policy will also be configured so that targeted access can be performed on the target access system based on the expected blocking policy of the target assessment task.
[0080] Exemplarily, the specific steps of connectivity detection can be as follows: first, perform an initial verification, and immediately try to initiate a request from the blocked test communication address again after the simulated attack is completed to confirm whether it is correctly blocked (such as returning a 403 Forbidden status code); then if the expected blocking time is long (such as several hours), you can initiate a verification request again in the middle to check the response of the target access system and verify whether the blocking is still effective; after the expected blocking time is over, try to access again to confirm whether the blocking has been lifted and the target access system can be accessed normally.
[0081] S510, or query the access response result of the target access system through the log system and / or preset interface of the target security device; compare the access response result with the expected blocking policy corresponding to the target evaluation task, and evaluate the communication address blocking capability of the target security device based on the comparison result.
[0082] Optionally, after the simulated attack behavior is completed, the relevant access response results can also be queried through the log system or preset interface of the target security device to verify whether there are log records related to the communication address ban and to analyze whether the banned content meets expectations. For example, relevant information can be directly extracted from the log file of the target security device, such as the specific time when the ban was triggered, the banned communication address, the ban duration, etc.; or detailed access response data can be retrieved in real time through the application programming interface (Application Programming Interface, API) or other preset interfaces of the target security device, including HTTP response status code, response time and response content, etc. Furthermore, the access response results obtained above are compared with the expected ban policy to confirm whether key information such as the time of occurrence and duration of the ban action meets the expected ban policy, and the communication address ban capability of the target security device is evaluated based on this.
[0083] In an embodiment of the present application, a method for evaluating the communication address blocking capability is provided. By directly using the communication addresses of real communication devices for testing, and utilizing these devices to access the target access system according to predetermined test execution means, the communication behavior in the actual network environment can be more realistically simulated, thereby more accurately evaluating the communication address blocking capability of the target security device when facing real threats; by performing at least one verification access operation on the target access system according to the expected blocking strategy, and comparing the actual access response results with the expected blocking strategy, it is possible to more comprehensively and accurately verify whether the communication address blocking strategy of the target security device under different blocking conditions is continuously effective, thereby ensuring the effectiveness and accuracy of the security protection strategy; and utilizing the log system or preset interface of the target security device to query the access response results of the target access system, and comparing these actual response results with the expected blocking strategy in detail, it is also possible to comprehensively and objectively evaluate the communication address blocking capability of the target security device, thereby ensuring the effective implementation of the security protection strategy.
[0084] See also Figure 7 , Figure 7 This is a structural block diagram of a communication address blocking capability evaluation device provided in an embodiment of the present application. Figure 7 As shown, the communication address blocking capability evaluation device 700 includes:
[0085] A target determination module 710 is configured to determine, in response to an execution request for a target assessment task, a target access system corresponding to the target assessment task, wherein the target access system contains a target security device for performing communication security protection;
[0086] An access module 720 is configured to determine a test execution means and at least one test communication address corresponding to a target assessment task, and to access a target access system according to the test execution means through each test communication address;
[0087] The result determination module 730 is used to obtain the access response result of the target access system and evaluate the communication address blocking capability of the target security device based on the access response result.
[0088] In some possible embodiments, the communication address blocking capability evaluation device 700 further includes: a task configuration module for obtaining the target test behavior type and target test behavior threshold input and / or selected by the user for the target evaluation task in response to a configuration request for the target evaluation task; configuring the test execution means corresponding to the target evaluation task according to the target test behavior type and the target test behavior threshold; an access module 720 for determining the target test behavior type, target test behavior threshold and at least one test communication address corresponding to the target evaluation task, and performing access behavior corresponding to the target test behavior type on the target access system according to the target test behavior threshold through each test communication address.
[0089] In some possible embodiments, the test communication address is the communication address of the real communication device, and the access module 720 is also used to send the test execution means corresponding to the target evaluation task to each real communication device, instructing each real communication device to access the target access system according to the test execution means.
[0090] In some possible embodiments, the test communication address is a virtual test communication address configured according to a preset request header type.
[0091] In some possible embodiments, the result determination module 730 is also used to perform at least one verification access operation on the target access system according to the expected blocking policy corresponding to the target assessment task, and determine the access response result of the target access system for each verification access operation, where the expected blocking policy at least includes the expected blocking duration of each test communication address by the target security device; the access response result is compared with the expected blocking policy, and the communication address blocking capability of the target security device is evaluated based on the comparison result.
[0092] In some possible embodiments, the result determination module 730 is also used to query the access response result of the target access system through the log system and / or preset interface of the target security device; compare the access response result with the expected blocking policy corresponding to the target evaluation task, and evaluate the communication address blocking capability of the target security device based on the comparison result.
[0093] In some possible embodiments, the result determination module 730 is further used to determine multiple quantitative evaluation indicators of the target security device's communication address blocking capability based on the access response result; and generate a blocking capability evaluation report of the target security device based on each quantitative evaluation indicator.
[0094] In an embodiment of the present application, a device for evaluating the communication address blocking capability is provided, wherein a target determination module is used to determine a target access system corresponding to a target evaluation task in response to an execution request for a target evaluation task, wherein the target access system contains a target security device for performing communication security protection; an access module is used to determine a test execution means and at least one test communication address corresponding to the target evaluation task, and access the target access system according to the test execution means through each test communication address; and a result determination module is used to obtain an access response result of the target access system, and evaluate the communication address blocking capability of the target security device based on the access response result. When it is necessary to execute a target assessment task, the target determination module first responds to a specific execution request, which can accurately identify and locate the target access system corresponding to the target assessment task, ensuring the pertinence and accuracy of the assessment process. At the same time, each assessment task can also select different target access systems according to different assessment requirements, enhancing the scope of application of the method; next, the access module clarifies the test execution means and multiple test communication addresses, and based on this, accesses the target access system, which can automatically simulate actual attack scenarios from different angles, thereby triggering the communication address blocking mechanism of the target security device in the target access system under different circumstances, improving the execution efficiency and coverage of the blocking capability assessment; finally, the result determination module evaluates the communication address blocking capability of the target security device through the access response result of the target access system, which can test the response capability and blocking effect of the target security device when facing different potential threats, thereby identifying the shortcomings of the target security device in communication address blocking, helping to optimize the security policy of the target security device, and improving the security protection level of the target access system.
[0095] An embodiment of the present application further provides a computer storage medium, which can store multiple instructions, and the instructions are suitable for being loaded by a processor and executing the steps of any method in the above embodiments.
[0096] See Figure 8 , Figure 8 This is a schematic diagram of the structure of a terminal provided in an embodiment of the present application. Figure 8 As shown, the terminal 800 may include: at least one terminal processor 801 , at least one network interface 804 , a user interface 803 , a memory 805 , and at least one communication bus 802 .
[0097] The communication bus 802 is used to implement the connection and communication between these components.
[0098] The user interface 803 may include a display screen (Display) and a camera (Camera). Optionally, the user interface 803 may also include a standard wired interface and a wireless interface.
[0099] The network interface 804 may optionally include a standard wired interface or a wireless interface (such as a WI-FI interface).
[0100] The terminal processor 801 may include one or more processing cores. The terminal processor 801 utilizes various interfaces and circuits to connect various components within the terminal 800. It executes instructions, programs, code sets, or instruction sets stored in the memory 805, and accesses data stored in the memory 805 to perform various functions and process data for the terminal 800. Optionally, the terminal processor 801 may be implemented using at least one of the following hardware forms: a digital signal processing (DSP), a field-programmable gate array (FPGA), or a programmable logic array (PLA). The terminal processor 801 may integrate one or a combination of a central processing unit (CPU), a graphics processing unit (GPU), and a modem. The CPU primarily processes the operating system, user interface, and application programs; the GPU is responsible for rendering and drawing the content displayed on the display screen; and the modem handles wireless communications. It is understood that the modem may not be integrated into the terminal processor 801 and may be implemented as a separate chip.
[0101] Among them, the memory 805 may include a random access memory (RAM) or a read-only memory (ROM). Optionally, the memory 805 includes a non-transitory computer-readable storage medium. The memory 805 can be used to store instructions, programs, codes, code sets or instruction sets. The memory 805 may include a program storage area and a data storage area, wherein the program storage area may store instructions for implementing an operating system, instructions for at least one function (such as a touch function, a sound playback function, an image playback function, etc.), instructions for implementing the above-mentioned various method embodiments, etc.; the data storage area may store data involved in the above-mentioned various method embodiments, etc. The memory 805 may also be optionally at least one storage device located away from the aforementioned terminal processor 801. As Figure 8 As shown, the memory 805 as a computer storage medium may include an operating system, a network communication module, a user interface module, and a communication address blocking capability evaluation program.
[0102] exist Figure 8 In the terminal 800 shown, the user interface 803 is mainly used to provide an input interface for the user and obtain user input data; and the terminal processor 801 can be used to call the communication address blocking capability evaluation program stored in the memory 805 and specifically perform the following operations:
[0103] In response to an execution request for a target assessment task, determining a target access system corresponding to the target assessment task, wherein the target access system includes a target security device for performing communication security protection;
[0104] Determine a test execution means and at least one test communication address corresponding to the target assessment task, and access the target access system according to the test execution means through each test communication address;
[0105] Obtain the access response result of the target access system and evaluate the communication address blocking capability of the target security device based on the access response result.
[0106] In some possible embodiments, the terminal processor 801 further specifically performs the following steps: in response to a configuration request for a target evaluation task, obtains the target test behavior type and target test behavior threshold input and / or selected by the user for the target evaluation task; configures the test execution means corresponding to the target evaluation task based on the target test behavior type and the target test behavior threshold; when the terminal processor 801 determines the test execution means and at least one test communication address corresponding to the target evaluation task, and accesses the target access system according to the test execution means through each test communication address, the terminal processor 801 specifically performs the following steps: determines the target test behavior type, target test behavior threshold and at least one test communication address corresponding to the target evaluation task, and performs access behavior corresponding to the target test behavior type on the target access system according to the target test behavior threshold through each test communication address.
[0107] In some possible embodiments, the test communication address is the communication address of the real communication device. When the terminal processor 801 executes the test communication address and accesses the target access system according to the test execution means, it specifically performs the following steps: sending the test execution means corresponding to the target evaluation task to each real communication device, instructing each real communication device to access the target access system according to the test execution means.
[0108] In some possible embodiments, the test communication address is a virtual test communication address configured according to a preset request header type.
[0109] In some possible embodiments, when the terminal processor 801 obtains the access response result of the target access system and evaluates the communication address blocking capability of the target security device based on the access response result, it specifically performs the following steps: performing at least one verification access operation on the target access system according to the expected blocking strategy corresponding to the target evaluation task, and determining the access response result of the target access system for each verification access operation, the expected blocking strategy at least includes the expected blocking duration of each test communication address by the target security device; comparing the access response result with the expected blocking strategy, and evaluating the communication address blocking capability of the target security device based on the comparison result.
[0110] In some possible embodiments, when the terminal processor 801 obtains the access response result of the target access system and evaluates the communication address blocking capability of the target security device based on the access response result, it specifically performs the following steps: querying the access response result of the target access system through the log system and / or preset interface of the target security device; comparing the access response result with the expected blocking policy corresponding to the target evaluation task, and evaluating the communication address blocking capability of the target security device based on the comparison result.
[0111] In some possible embodiments, when the terminal processor 801 evaluates the communication address blocking capability of the target security device based on the access response result, it specifically performs the following steps: determining multiple quantitative evaluation indicators of the target security device for the communication address blocking capability based on the access response result; and generating a blocking capability evaluation report for the target security device based on each quantitative evaluation indicator.
[0112] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of modules is only a logical function division. In actual implementation, there may be other division methods, such as multiple modules or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or modules, which can be electrical, mechanical or other forms.
[0113] Modules described as separate components may or may not be physically separate, and components shown as modules may or may not be physical modules, that is, they may be located in one place or distributed across multiple network modules. Some or all of these modules may be selected to achieve the purpose of this embodiment based on actual needs.
[0114] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When software is used for implementation, it can be implemented in whole or in part in the form of a computer program product. The above-mentioned computer program product includes one or more computer instructions. When the above-mentioned computer program instructions are loaded and executed on a computer, the above-mentioned process or function according to the embodiment of this specification is generated in whole or in part. The above-mentioned computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The above-mentioned computer instructions can be stored in a computer-readable storage medium or transmitted by the above-mentioned computer-readable storage medium. The above-mentioned computer instructions can be transmitted from a website, computer, server or data center to another website, computer, server or data center by wired (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (such as infrared, wireless, microwave, etc.). The above-mentioned computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more available media integrations. The above-mentioned available media can be magnetic media (for example, floppy disks, hard disks, tapes), optical media (for example, digital versatile discs (DVDs)), or semiconductor media (for example, solid state disks (SSDs)).
[0115] It should be noted that for the aforementioned method embodiments, for ease of description, they are all expressed as a series of action combinations, but those skilled in the art should be aware that this application is not limited by the order of the actions described, because according to this application, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in this specification are all preferred embodiments, and the actions and modules involved are not necessarily required by this application.
[0116] In the above embodiments, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0117] The above is a description of the communication address blocking capability evaluation method, device, storage medium and terminal provided in this application. For those skilled in the art, based on the ideas of the embodiments of this application, there may be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as limiting this application.
Claims
1. A method for evaluating communication address blocking capability, characterized in that: The method comprises: In response to an execution request for a target assessment task, determining a target access system corresponding to the target assessment task, wherein the target access system includes a target security device for performing communication security protection; Determining a test execution means and at least one test communication address corresponding to the target assessment task, and accessing the target access system according to the test execution means through each test communication address; An access response result of the target access system is obtained, and a communication address blocking capability of the target security device is evaluated based on the access response result.
2. The method according to claim 1, characterized in that The method further comprises: In response to a configuration request for the target assessment task, obtaining a target test behavior type and a target test behavior threshold input and / or selected by a user for the target assessment task; Configuring a test execution means corresponding to the target assessment task according to the target test behavior type and the target test behavior threshold; The determining of the test execution means and at least one test communication address corresponding to the target assessment task, and accessing the target access system according to the test execution means through each test communication address, includes: Determine the target test behavior type, target test behavior threshold and at least one test communication address corresponding to the target assessment task, and through each test communication address, perform access behavior corresponding to the target test behavior type on the target access system according to the target test behavior threshold.
3. The method according to claim 1, characterized in that The test communication address is a communication address where a real communication device is located, and accessing the target access system according to the test execution means through each test communication address includes: The test execution means corresponding to the target evaluation task is sent to each real communication device, instructing each real communication device to access the target access system according to the test execution means.
4. The method according to claim 1, wherein The test communication address is a virtual test communication address configured according to a preset request header type.
5. The method according to claim 1, wherein The obtaining of the access response result of the target access system and evaluating the communication address blocking capability of the target security device based on the access response result includes: Perform at least one verification access operation on the target access system according to the expected blocking policy corresponding to the target assessment task, and determine an access response result of the target access system for each verification access operation, wherein the expected blocking policy includes at least an expected blocking duration of each test communication address by the target security device; The access response result is compared with the expected blocking policy, and the communication address blocking capability of the target security device is evaluated based on the comparison result.
6. The method according to claim 1, characterized in that The obtaining of the access response result of the target access system and evaluating the communication address blocking capability of the target security device based on the access response result includes: Querying the access response result of the target access system through the log system and / or preset interface of the target security device; The access response result is compared with the expected blocking policy corresponding to the target assessment task, and the communication address blocking capability of the target security device is evaluated based on the comparison result.
7. The method according to claim 1, characterized in that The evaluating the communication address blocking capability of the target security device based on the access response result includes: Determining, based on the access response result, a plurality of quantitative evaluation indicators of the target security device's communication address blocking capability; Generate a blocking capability assessment report for the target security device based on each quantitative assessment indicator.
8. A communication address blocking capability evaluation device, characterized in that: The device comprises: a target determination module, configured to determine, in response to an execution request for a target assessment task, a target access system corresponding to the target assessment task, wherein the target access system includes a target security device for performing communication security protection; an access module, configured to determine a test execution means and at least one test communication address corresponding to the target assessment task, and access the target access system according to the test execution means through each test communication address; The result determination module is configured to obtain an access response result of the target access system and evaluate the communication address blocking capability of the target security device based on the access response result.
9. A computer storage medium, characterized in that The computer storage medium stores a plurality of instructions, and the instructions are suitable for being loaded by a processor and executing the steps of the method according to any one of claims 1 to 7.
10. A terminal, characterized in that: The method comprises a memory, a processor and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the method according to any one of claims 1 to 7 when executing the program.