Gateway test method, system and equipment based on artificial intelligence

Through the reinforcement learning attack model based on artificial intelligence, targeted DDoS attack solutions are generated and target gateways are tested, which solves the problem that diversified and highly realistic DDoS attack testing cannot be carried out in the existing technology, and realizes intelligent defense evaluation and optimization of complex network environments.

CN120455312APending Publication Date: 2025-08-08SICHUAN TIANYI COMHEART TELECOM
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510654642.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-21
Publication Date
2025-08-08

AI Technical Summary

Technical Problem

The existing technology lacks diversified and highly authentic DDoS attack testing methods and cannot conduct intelligent defense evaluations for complex network environments.

Method used

Using a reinforcement learning attack model based on artificial intelligence, a targeted DDoS attack scheme is generated by establishing and training a reinforcement learning attack model, a target gateway is tested, and analyzing the test data to evaluate its defense capabilities.

Benefits of technology

It realizes diversified DDoS attack testing for complex network environments, can dynamically adapt to the configuration and defense strategies of the target gateway, provide comprehensive evaluation and optimization suggestions, and improves testing efficiency and accuracy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120455312A_ABST
    Figure CN120455312A_ABST
Patent Text Reader

Abstract

The invention discloses a gateway test method, system and equipment based on artificial intelligence, and the method comprises the steps: building and training a reinforcement learning attack model according to a test demand, and enabling the reinforcement learning attack model to take a test target as input and a DDoS attack scheme for the test target as output; according to a received DDoS defense test request of a target gateway, obtaining a target DDoS attack scheme for the target gateway through the reinforcement learning attack model; performing a DDoS attack test on the target gateway according to the target DDoS attack scheme to obtain test data of the target gateway; and analyzing the test data according to the test data to obtain a test result of the target gateway. The problems that in the prior art, diversified and highly-real DDoS attack testing means are lacked, and more intelligent defense evaluation cannot be carried out for a complex network environment are at least solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of Internet of Things technology, and in particular to an artificial intelligence-based gateway testing method, system, and device. Background Art

[0002] With the rapid development of information technology and the widespread use of the internet, network security issues are becoming increasingly serious, especially for government and enterprise network systems. As crucial equipment for ensuring network security, information flow, and communication isolation, the safety and stability of government and enterprise gateways are directly related to national and enterprise information security. However, with the increasing sophistication of attack methods, traditional network security defense methods face unprecedented challenges. Distributed denial of service (DDoS) attacks, in particular, overwhelm target systems with massive amounts of false traffic or requests, causing network congestion and even paralysis. These attacks not only threaten the normal operation of systems but also cause immeasurable economic losses.

[0003] Existing network security testing methods mostly rely on manually configured attack samples and rules to simulate known attack methods. While these testing methods can verify the basic functionality of defense systems, they have certain limitations. First, traditional test cases are mostly fixed samples with relatively simple attack types, which cannot effectively simulate complex and changing attack scenarios. This makes defense solutions easy for attackers to predict and design targeted circumvention strategies. Second, traditional testing methods lack the ability to simulate unknown attack behaviors, making it impossible to comprehensively evaluate the defense system's ability to respond to various new attacks.

[0004] Current defense testing often focuses on simulating a single attack vector, lacking comprehensive consideration of multiple attack combinations or attack evolution processes. Consequently, existing technologies haven't fully exploited the diversity of test cases and the complexity of attack scenarios, making defense solutions vulnerable to being bypassed by a single attack pattern and failing to fully and effectively enhance defense capabilities.

[0005] Therefore, how to conduct diversified and highly realistic DDoS attack tests and perform more intelligent defense assessments for complex network environments has become an important direction of current research. Summary of the Invention

[0006] The present invention provides an artificial intelligence-based gateway testing method, system, and device, and provides a gateway testing solution, which at least solves the problem in the prior art of lacking diversified and highly realistic DDoS attack testing methods and being unable to perform more intelligent defense assessments for complex network environments.

[0007] This application provides an artificial intelligence-based gateway testing method, including: Establish and train a reinforcement learning attack model based on test requirements. The reinforcement learning attack model is configured to take a test target as input and output a DDoS attack scenario targeting the test target. According to the DDoS defense test request received from the target gateway, a target DDOS attack plan for the target gateway is obtained through the reinforcement learning attack model; Performing a DDoS attack test on the target gateway according to the target DDoS attack scenario to obtain test data of the target gateway; According to the test data, the test data is analyzed to obtain a test result of the target gateway.

[0008] Optionally, the reinforcement learning attack model includes a state space, an action space, and a reward function; The state in the state space is configured to include at least one network state parameter of the target gateway; The actions in the action space are configured to include at least one DDoS attack strategy parameter; The reward function is configured to include at least one of a positive reward, a negative reward, and a continuous negative reward; According to the test requirements, the reinforcement learning attack model is established and trained, including: According to the test requirements, establish a simulated network environment and configure at least one training gateway; Performing a DDoS attack on at least one of the training gateways using the reinforcement learning attack model; Record the response of at least one of the training gateways to the DDoS attack, and optimize the attack strategy of the reinforcement learning attack model based on the feedback until a preset training termination condition is met.

[0009] Optionally, the positive reward is configured as at least one of the following: When the network status parameters of the target gateway deteriorate, a positive reward is given; When the target gateway experiences a service interruption, a positive reward is given; When the target gateway is blocked by mistake, a positive reward will be given; The negative reward is configured as at least one of the following: When the network status parameters of the target gateway improve, a negative reward is given; When the target gateway identifies the attack source, a negative reward is given; The continuous negative reward is configured as at least one of the following: When the DDoS attack strategy parameters are enhanced, continuous rewards are given.

[0010] Optionally, establishing a simulated network environment and configuring at least one training gateway according to test requirements includes: Constructing a simulated network environment according to test requirements, wherein the simulated network environment includes at least one training gateway; According to the at least one training gateway, a different defense mechanism is configured for each training gateway.

[0011] Optionally, obtaining a target DDOS attack scenario for the target gateway by using the reinforcement learning attack model according to the received DDoS defense test request from the target gateway includes: According to the DDoS defense test request received from the target gateway, the gateway information and defense mechanism of the target gateway are obtained; Obtain the attack intensity limit of the DDoS defense test based on the DDoS defense test request received from the target gateway; The gateway information and defense mechanism of the target gateway and the attack intensity limit of the DDoS defense test are input into the reinforcement learning attack model to obtain a target DDOS attack plan for the target gateway.

[0012] Optionally, inputting the gateway information and defense mechanism of the target gateway and the attack intensity limit of the DDoS defense test into the reinforcement learning attack model to obtain a target DDOS attack plan for the target gateway includes: Configuring an attack target for the reinforcement learning attack model according to the gateway information of the target gateway; Configuring an attack strategy for the reinforcement learning attack model based on the defense mechanism of the target gateway; According to the attack intensity limit of the DDoS defense test, action limits are configured for the action space of the reinforcement learning attack model.

[0013] Optionally, performing a DDoS attack test on the target gateway according to the target DDoS attack scenario to obtain test data of the target gateway includes: According to the target gateway, obtaining normal traffic data corresponding to the target gateway; A DDoS attack test is performed on the target gateway according to the target DDoS attack scenario and the normal traffic data to obtain test data of the target gateway.

[0014] In yet another aspect, an artificial intelligence-based gateway testing system includes a testing platform and at least one target gateway; The test platform is configured as follows: Establish and train a reinforcement learning attack model based on test requirements. The reinforcement learning attack model is configured to take a test target as input and output a DDoS attack scenario targeting the test target. According to the DDoS defense test request received from the target gateway, a target DDOS attack plan for the target gateway is obtained through the reinforcement learning attack model; Performing a DDoS attack test on the target gateway according to the target DDoS attack scenario to obtain test data of the target gateway; According to the test data, the test data is analyzed to obtain a test result of the target gateway.

[0015] Optionally, the reinforcement learning attack model includes a state space, an action space, and a reward function; The state in the state space is configured to include at least one network state parameter of the target gateway; The actions in the action space are configured to include at least one DDoS attack strategy parameter; The reward function is configured to include at least one of a positive reward, a negative reward, and a continuous negative reward; According to the test requirements, the reinforcement learning attack model is established and trained, including: According to the test requirements, establish a simulated network environment and configure at least one training gateway; Performing a DDoS attack on at least one of the training gateways using the reinforcement learning attack model; Record the response of at least one of the training gateways to the DDoS attack, and optimize the attack strategy of the reinforcement learning attack model based on the feedback until a preset training termination condition is met.

[0016] On the other hand, an embodiment of the present application further provides a device, which includes a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the above method.

[0017] On the other hand, an embodiment of the present application further provides a computer-readable storage medium, on which a computer program is stored, and a processor executes the computer program to implement the above method.

[0018] Compared with the prior art, the present invention has the following advantages and beneficial effects: The present invention provides an artificial intelligence-based gateway testing method, system, and device, including establishing and training a reinforcement learning attack model based on test requirements, wherein the reinforcement learning attack model is configured to take a test target as input and output a DDoS attack scenario for the test target; upon receiving a DDoS defense test request from a target gateway, obtaining a target DDOS attack scenario for the target gateway through the reinforcement learning attack model; performing a DDoS attack test on the target gateway according to the target DDoS attack scenario to obtain test data for the target gateway; and analyzing the test data based on the test data to obtain a test result for the target gateway. This method at least solves the problem in the prior art of lacking diversified and highly realistic DDoS attack testing methods and being unable to perform more intelligent defense assessments for complex network environments. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] To more clearly illustrate the specific embodiments of this application or the technical solutions in the prior art, the following briefly describes the drawings required for the specific embodiments or the description of the prior art. Similar elements or parts are generally identified by similar reference numerals throughout the drawings. Elements or parts in the drawings are not necessarily drawn to scale.

[0020] Figure 1 A flowchart of an artificial intelligence-based gateway testing method in this application; Figure 2 A schematic structural diagram of a device in this application; Markings in the figure: 101 - processor, 102 - communication bus, 103 - network interface, 104 - user interface, 105 - memory.

[0021] The realization of the objectives, functional features and advantages of this application will be further explained in conjunction with embodiments and with reference to the accompanying drawings. DETAILED DESCRIPTION

[0022] In order to enable those skilled in the art to better understand the present invention, the following will provide a clear and complete description of the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative work should fall within the scope of protection of the present invention.

[0023] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequential order. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in a sequence other than those illustrated or described herein. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0024] Example 1 like Figure 1 As shown, a gateway testing method based on artificial intelligence includes: S1. Build and train a reinforcement learning attack model based on test requirements.

[0025] The reinforcement learning attack model is configured to take the test target as input and output the DDoS attack plan against the test target.

[0026] Optionally, the reinforcement learning attack model takes as input the target gateway's configuration information, such as network bandwidth, hardware performance, and defense mechanisms. Its output is a generated DDoS attack scenario, specifically including attack type (e.g., UDP Flood, SYN Flood, DNS Amplification), attack traffic intensity, attack duration, attack source configuration, and attack frequency. To train the model, multiple experiments are conducted in a simulated network environment, allowing the model to optimize its strategies through continuous iteration and gradually generate attack traffic that can effectively penetrate the target gateway's defenses.

[0027] Optionally, the reinforcement learning model can adopt methods such as Actor-Critic and DQN. The model learns and optimizes the strategy by rewarding and punishing the feedback of each attack test.

[0028] S2. Based on the DDoS defense test request received from the target gateway, a target DDOS attack plan for the target gateway is obtained through reinforcement learning attack model.

[0029] Optionally, the target gateway is a government and enterprise gateway. The government and enterprise gateway is a high-performance, highly secure, and highly manageable network access device designed specifically for government agencies, enterprises, and other organizations. It is mainly used to build stable and secure intranet and extranet communication hubs. Its core positioning is to meet the multi-service carrying, security protection, and centralized management needs of government and enterprise customers in complex network environments.

[0030] Optionally, when a user or product manufacturer wishes to evaluate the defense capabilities of a target gateway, they can initiate a DDoS defense test request through the test platform. The test request includes information such as the gateway configuration file, the desired attack type, and the test time window. Upon receiving the request, the system provides the required gateway information to the reinforcement learning attack model and begins generating a corresponding attack plan.

[0031] S3. Perform a DDoS attack test on the target gateway according to the target DDoS attack plan to obtain test data of the target gateway.

[0032] Optionally, after receiving the test request, the reinforcement learning attack model generates a targeted DDoS attack plan based on the configuration information of the target gateway. The attack plan includes the attack traffic type, attack traffic intensity, attack duration, and distribution of attack source IP addresses.

[0033] Optionally, the generated DDoS attack scenario will be carried out by controlling network traffic. The attack process can include multiple stages, such as traffic growth stage, attack peak stage, and attack decline stage. The attack intensity and attack strategy of each stage can be dynamically adjusted by the reinforcement learning attack model according to the real-time defense response of the target gateway.

[0034] S4. Analyze the test data based on the test data to obtain the test results of the target gateway.

[0035] Optionally, during DDoS attack testing, the system continuously monitors and records gateway response data, including gateway processing capacity, throughput, packet loss rate, latency, and triggering of defense measures. By analyzing this data, you can evaluate the gateway's performance under different attack intensities and identify weaknesses in its defense capabilities.

[0036] Optionally, the test data will be fed into the data analysis module, where the results will be further analyzed using machine learning algorithms. This module will ultimately generate a DDoS defense test report for the gateway. The report will include a detailed analysis of various defense indicators, such as the gateway's attack resistance, stress resistance, and resource usage, and provide targeted optimization suggestions.

[0037] This solution offers the following advantages: It generates targeted attack scenarios through a reinforcement learning model, dynamically adapting to the target gateway's configuration and defense strategy, avoiding the limitations of traditional fixed attack models. The automated attack generation and execution process reduces manual intervention, improves testing efficiency, and provides comprehensive evaluations under varying test conditions. Through in-depth analysis of test data, it comprehensively assesses the target gateway's DDoS defense capabilities and generates detailed reports, providing a basis for optimizing gateway defense strategies. Through continuous optimization, the reinforcement learning model can generate attack scenarios capable of defeating different defense strategies, demonstrating excellent adaptability and flexibility. This solution addresses the existing problem of a lack of diversified, highly realistic DDoS attack testing methods, hindering intelligent defense assessments for complex network environments.

[0038] Example 2 This embodiment, based on the first embodiment, provides an artificial intelligence-based gateway testing method, including: S1. Build and train a reinforcement learning attack model based on test requirements.

[0039] The reinforcement learning attack model is configured to take the test target as input and output the DDoS attack plan against the test target.

[0040] Optionally, the reinforcement learning attack model takes as input the target gateway's configuration information, such as network bandwidth, hardware performance, and defense mechanisms. Its output is a generated DDoS attack scenario, specifically including attack type (e.g., UDP Flood, SYN Flood, DNS Amplification), attack traffic intensity, attack duration, attack source configuration, and attack frequency. To train the model, multiple experiments are conducted in a simulated network environment, allowing the model to optimize its strategies through continuous iteration and gradually generate attack traffic that can effectively penetrate the target gateway's defenses.

[0041] Optionally, the reinforcement learning attack model can adopt methods such as Actor-Critic and DQN. The model learns and optimizes the strategy by rewarding and punishing the feedback of each attack test.

[0042] Optionally, the reinforcement learning attack model includes a state space, an action space, and a reward function; The state in the state space is configured to include at least one network state parameter of the target gateway; The actions in the action space are configured to include at least one DDoS attack strategy parameter; The reward function is configured to include at least one of a positive reward, a negative reward, and a continuous negative reward; According to the test requirements, build and train the reinforcement learning attack model, including: According to the test requirements, establish a simulated network environment and configure at least one training gateway; Perform a DDoS attack on at least one training gateway using a reinforcement learning attack model; Record the response of at least one training gateway to DDoS attacks, and optimize the attack strategy of the reinforcement learning attack model based on the feedback until the preset training termination conditions are met.

[0043] Optionally, the state space may include network state parameters of the target gateway, which are used to describe the current network status.

[0044] Specifically, the main components of the state space can include: Bandwidth usage rate: Bandwidth usage rate is used to characterize the bandwidth utilization of the target gateway, and the unit is percentage; Response time: Response time is used to characterize the response delay of the target gateway in processing the request; Network traffic, which is used to represent the number of data packets received by the target gateway; Error rate, which is used to characterize the number of error packets received by the target gateway or the packet loss rate; The number of connections is used to indicate the number of concurrent connections currently being processed by the target gateway; Specifically, the status can be expressed as: status = [bandwidth utilization = 85%, response time = 150ms, error rate = 2%, number of connections = 500].

[0045] Optionally, the action space is a set of actions that can be selected in the reinforcement learning model. For DDoS attacks, the actions in the action space involve selecting different attack strategies.

[0046] Specifically, the actions in the action space include: Changing attack traffic, that is, changing the traffic attack on the target gateway; Changing the attack source IP, that is, circumventing the IP blocking of the target gateway by changing the source IP; Adding attack source IP addresses to evade detection by the target gateway; Change the attack type, that is, select different types of attacks, such as SYNFlood, UDPFlood, HTTPFlood, etc.

[0047] Specifically, an action in the action space can be expressed as: action = [increase attack traffic = 10 Gbps].

[0048] Optionally, positive rewards are configured as at least one of the following: When the network status parameters of the target gateway deteriorate, positive rewards are given; When the target gateway experiences a service outage, positive rewards will be given; When the target gateway is blocked by mistake, positive rewards will be given; Negative rewards are configured as at least one of the following: When the network status parameters of the target gateway improve, negative rewards are given; When the target gateway identifies the attack source, a negative reward is given; Continuous negative rewards are configured as at least one of the following: When the DDoS attack strategy parameters are enhanced, continuous rewards will be given.

[0049] Optionally, the positive reward can be adjusted based on changes in the target gateway's network status. Specifically: When the network status parameters of the target gateway deteriorate, positive rewards are given. For example, if the first parameter is a parameter whose larger value indicates a worse network status parameter, when the first parameter rises above the first threshold P1, a positive reward of +A1 is given; when the first parameter rises above the second threshold P2, a positive reward of +A2 is given; when the first parameter rises above the third threshold P3, a positive reward of +A3 is given; when the first parameter rises above the fourth threshold P4, a positive reward of +A4 is given, and so on; When the target gateway experiences a service interruption, a positive reward is given. For example, when the target gateway detects a DDoS attack and causes service interruption, the positive reward is +B1. When the target gateway blocks an IP address by mistake, a positive reward will be given. For example, when the target gateway blocks the first preset number of legitimate IP addresses by mistake, the positive reward will be +1.

[0050] Optionally, negative rewards are usually used to punish invalid behaviors of the model, such as invalid attacks, network status recovery, etc. Specifically: When the network status parameters of the target gateway improve, negative rewards are given. For example, when the first parameter of the target gateway drops below the fifth threshold P5, a negative reward of -A5 is given; when the first parameter drops above the sixth threshold P6, a negative reward of -A6 is given; when the first parameter drops above the seventh threshold P7, a negative reward of -A7 is given; when the first parameter drops above the eighth threshold P8, a negative reward of -A8 is given, and so on; When the target gateway identifies the attack source, a negative reward will be given. For example, if the target gateway detects the IP source and blocks it, the negative reward will be -5 for each preset number of attack source IPs blocked.

[0051] Specifically, continuous rewards can motivate the reinforcement learning attack model to adopt a more aggressive attack strategy and drive rapid model iteration. Specifically, they can include at least one of the following continuous rewards: When the attack traffic increases by a preset value or a preset ratio, the continuous positive reward is +1; When the attack source IP increases by a preset value or a preset ratio, the continuous positive reward is +1; When the attack frequency increases by a preset value or a preset ratio, the continuous positive reward is +1.

[0052] Optionally, generally speaking, P4>P3>P2>P1>P5>P6>P7>P8, and P2-P1>P3-P2>P4-P3, and P5-P6>P6-P7>P7-P8, and A4≥A3≥A2≥A1, and A8≥A7≥A6≥A5.

[0053] Optionally, for different network state parameters, the selection of the threshold and the selection of the reward value may be the same or different.

[0054] By configuring the reward function using the above method, the reinforcement learning attack model can be made more aggressive and more in line with the attack strategy of network attacks.

[0055] Specifically, the positive reward can be adjusted according to the changes in the network status of the target gateway. Specifically: When the network status parameters of the target gateway deteriorate, positive rewards will be given. For example, when the bandwidth utilization rate of the target gateway rises to 50%, a positive reward of +5 will be given; when the utilization rate rises to 70%, a positive reward of +15 will be given; when the utilization rate rises to 80%, a positive reward of +25 will be given; when the utilization rate rises to 85%, a positive reward of +25 will be given, etc. When the target gateway experiences a service interruption, a positive reward will be given. For example, when the target gateway detects a DDoS attack and causes service interruption, the positive reward is +100. When the target gateway mistakenly blocks an IP address, a positive reward will be given. For example, for every 10 legitimate IP addresses mistakenly blocked by the target gateway, the positive reward will be +1.

[0056] Specifically, negative rewards are usually used to punish invalid behaviors of the model, such as invalid attacks, network status recovery, etc. Specifically: When the network status parameters of the target gateway improve, negative rewards will be given. For example, when the bandwidth utilization rate of the target gateway drops to 45%, a negative reward of -5 will be given; when the utilization rate drops to 40%, a negative reward of -15 will be given; when the utilization rate drops to 35%, a negative reward of -25 will be given; when the utilization rate drops to 30%, a negative reward of -25 will be given, and so on; When the target gateway identifies the attack source, a negative reward will be given. For example, if the target gateway detects the IP source and blocks it, the negative reward will be -5 for every 100 attack source IPs blocked.

[0057] Specifically, continuous rewards can motivate the reinforcement learning attack model to adopt a more aggressive attack strategy and drive rapid model iteration. Specifically, they can include at least one of the following continuous rewards: When the attack traffic increases by 10Gbp, the continuous positive reward is +1; When the number of attack source IPs increases by 100, the continuous positive reward is +1; When the attack frequency increases by 1 per second, the continuous positive reward is +1.

[0058] Optionally, based on test requirements, establish a simulated network environment and configure at least one training gateway, including: According to the test requirements, a simulation network environment is constructed, wherein the simulation network environment includes at least one training gateway; According to at least one training gateway, a different defense mechanism is configured for each training gateway.

[0059] The above scheme can configure different defense mechanisms for each training gateway. The purpose is to simulate multiple defense mechanisms through this diverse configuration and improve the adaptability of the reinforcement learning attack model to different defense mechanisms.

[0060] S2. Based on the DDoS defense test request received from the target gateway, a target DDOS attack plan for the target gateway is obtained through reinforcement learning attack model.

[0061] Optionally, the target gateway is a government and enterprise gateway. The government and enterprise gateway is a high-performance, highly secure, and highly manageable network access device designed specifically for government agencies, enterprises, and other organizations. It is mainly used to build stable and secure intranet and extranet communication hubs. Its core positioning is to meet the multi-service carrying, security protection, and centralized management needs of government and enterprise customers in complex network environments.

[0062] Optionally, when a user or product manufacturer wishes to evaluate the defense capabilities of a target gateway, they can initiate a DDoS defense test request through the test platform. The test request includes information such as the gateway configuration file, the desired attack type, and the test time window. Upon receiving the request, the system provides the required gateway information to the reinforcement learning attack model and begins generating a corresponding attack plan.

[0063] Optionally, based on the DDoS defense test request received from the target gateway, a target DDOS attack scenario for the target gateway is obtained through reinforcement learning of the attack model, including: According to the DDoS defense test request received from the target gateway, the gateway information and defense mechanism of the target gateway are obtained; Obtain the attack intensity limit of the DDoS defense test based on the DDoS defense test request received from the target gateway; The gateway information and defense mechanism of the target gateway and the attack intensity limit of the DDoS defense test are input into the reinforcement learning attack model to obtain the target DDOS attack plan for the target gateway.

[0064] Optionally, the gateway information and defense mechanism of the target gateway, as well as the attack intensity limit of the DDoS defense test, are input into the reinforcement learning attack model to obtain a targeted DDOS attack scenario for the target gateway, including: Configure the attack target for the reinforcement learning attack model based on the gateway information of the target gateway; Configure attack strategies for the reinforcement learning attack model based on the target gateway's defense mechanisms; Configure action limits for the action space of the reinforcement learning attack model based on the attack intensity limit of the DDoS defense test.

[0065] By adopting the above method, the current defense mechanism of the target gateway is input into the reinforcement learning attack model, and a more targeted attack strategy can be output.

[0066] Optionally, in order to avoid overfitting that may cause the adaptability of the reinforcement learning attack model to deteriorate, data dimensionality reduction of the defense mechanism may be performed during training and testing. The data dimensionality reduction method may be PCA, LDA, or MDS.

[0067] S3. Perform a DDoS attack test on the target gateway according to the target DDoS attack plan to obtain test data of the target gateway.

[0068] Optionally, after receiving the test request, the reinforcement learning attack model generates a targeted DDoS attack plan based on the configuration information of the target gateway. The attack plan includes the attack traffic type, attack traffic intensity, attack duration, and distribution of attack source IP addresses.

[0069] Optionally, the generated DDoS attack scenario will be carried out by controlling network traffic. The attack process can include multiple stages, such as traffic growth stage, attack peak stage, and attack decline stage. The attack intensity and attack strategy of each stage can be dynamically adjusted by the reinforcement learning attack model according to the real-time defense response of the target gateway.

[0070] Optionally, perform a DDoS attack test on the target gateway according to the target DDoS attack scenario to obtain test data for the target gateway, including: According to the target gateway, obtain the normal traffic data corresponding to the target gateway; Perform a DDoS attack test on the target gateway based on the target DDoS attack scenario and normal traffic data to obtain test data of the target gateway.

[0071] By adopting the above method, the test can be closer to the actual usage scenario and the accuracy of the test results can be higher.

[0072] Specifically, a DDoS attack test is performed on the target gateway according to the target DDoS attack plan to obtain test data of the target gateway, including: According to the target gateway, obtain the normal traffic data corresponding to the target gateway; Generate simulated traffic time series data based on normal traffic data; Input traffic to the target gateway based on the simulated traffic time series data; At a random time after the target gateway inputs traffic according to the simulated traffic timing data, a DDoS attack test is performed on the target gateway according to the target DDoS attack plan to obtain test data of the target gateway.

[0073] S4. Analyze the test data based on the test data to obtain the test results of the target gateway.

[0074] Optionally, during DDoS attack testing, the system continuously monitors and records gateway response data, including gateway processing capacity, throughput, packet loss rate, latency, and triggering of defense measures. By analyzing this data, you can evaluate the gateway's performance under different attack intensities and identify weaknesses in its defense capabilities.

[0075] Optionally, the test data will be fed into the data analysis module, where the results will be further analyzed using machine learning algorithms. This module will ultimately generate a DDoS defense test report for the gateway. The report will include a detailed analysis of various defense indicators, such as the gateway's attack resistance, stress resistance, and resource usage, and provide targeted optimization suggestions.

[0076] Example 4 An artificial intelligence-based gateway testing system includes a test platform and at least one target gateway; The test platform is configured as follows: Based on the test requirements, a reinforcement learning attack model is established and trained. The reinforcement learning attack model is configured to take the test target as input and output a DDoS attack plan targeting the test target. Based on the DDoS defense test request received from the target gateway, the target DDOS attack plan for the target gateway is obtained through reinforcement learning attack model; Perform a DDoS attack test on the target gateway according to the target DDoS attack plan and obtain test data of the target gateway; Based on the test data, the test data is analyzed to obtain the test results of the target gateway.

[0077] Optionally, the reinforcement learning attack model includes a state space, an action space, and a reward function; The state in the state space is configured to include at least one network state parameter of the target gateway; The actions in the action space are configured to include at least one DDoS attack strategy parameter; The reward function is configured to include at least one of a positive reward, a negative reward, and a continuous negative reward; According to the test requirements, build and train the reinforcement learning attack model, including: According to the test requirements, establish a simulated network environment and configure at least one training gateway; Perform a DDoS attack on at least one training gateway using a reinforcement learning attack model; Record the response of at least one training gateway to DDoS attacks, and optimize the attack strategy of the reinforcement learning attack model based on the feedback until the preset training termination conditions are met.

[0078] Optionally, positive rewards are configured as at least one of the following: When the network status parameters of the target gateway deteriorate, positive rewards are given; When the target gateway experiences a service outage, positive rewards will be given; When the target gateway is blocked by mistake, positive rewards will be given; Negative rewards are configured as at least one of the following: When the network status parameters of the target gateway improve, negative rewards are given; When the target gateway identifies the attack source, a negative reward is given; Continuous negative rewards are configured as at least one of the following: When the DDoS attack strategy parameters are enhanced, continuous rewards will be given.

[0079] Optionally, based on test requirements, establish a simulated network environment and configure at least one training gateway, including: According to the test requirements, a simulation network environment is constructed, wherein the simulation network environment includes at least one training gateway; According to at least one training gateway, a different defense mechanism is configured for each training gateway.

[0080] Optionally, based on the DDoS defense test request received from the target gateway, a target DDOS attack scenario for the target gateway is obtained through reinforcement learning of the attack model, including: According to the DDoS defense test request received from the target gateway, the gateway information and defense mechanism of the target gateway are obtained; Obtain the attack intensity limit of the DDoS defense test based on the DDoS defense test request received from the target gateway; The gateway information and defense mechanism of the target gateway and the attack intensity limit of the DDoS defense test are input into the reinforcement learning attack model to obtain the target DDOS attack plan for the target gateway.

[0081] Optionally, the gateway information and defense mechanism of the target gateway, as well as the attack intensity limit of the DDoS defense test, are input into the reinforcement learning attack model to obtain a targeted DDOS attack scenario for the target gateway, including: Configure the attack target for the reinforcement learning attack model based on the gateway information of the target gateway; Configure attack strategies for the reinforcement learning attack model based on the target gateway's defense mechanisms; Configure action limits for the action space of the reinforcement learning attack model based on the attack intensity limit of the DDoS defense test.

[0082] Optionally, perform a DDoS attack test on the target gateway according to the target DDoS attack scenario to obtain test data for the target gateway, including: According to the target gateway, obtain the normal traffic data corresponding to the target gateway; Perform a DDoS attack test on the target gateway based on the target DDoS attack scenario and normal traffic data to obtain test data of the target gateway.

[0083] Example 4 This embodiment provides a device, which includes a memory and a processor. The memory stores a computer program, and the processor executes the computer program to implement any of the above methods.

[0084] Specifically, such as Figure 2 As shown, Figure 2This is a schematic diagram of the device structure of the hardware operating environment involved in the embodiment of the present application. The device is an electronic device and may include: a processor 101, such as a central processing unit (CPU), a communication bus 102, a user interface 104, a network interface 103, and a memory 105. Among them, the communication bus 102 is used to realize the connection and communication between these components. The user interface 104 may include a display screen (Display), an input unit such as a keyboard (Keyboard), and the user interface 104 may also include a standard wired interface and a wireless interface. The network interface 103 may optionally include a standard wired interface and a wireless interface (such as a wireless fidelity (WIreless-FIdelity, WI-FI) interface). The memory 105 may optionally be a storage device independent of the aforementioned processor 101. The memory 105 may be a high-speed random access memory (RAM) memory, or a stable non-volatile memory (NVM), such as at least one disk memory. The processor 101 may be a general-purpose processor, including a central processing unit, a network processor, etc., or may be a digital signal processor, an application-specific integrated circuit, a field programmable gate array or other programmable logic device, a discrete gate or transistor logic device, or a discrete hardware component.

[0085] Those skilled in the art will understand that Figure 2 The structure shown in the figure does not constitute a limitation to the electronic device, and may include more or fewer components than shown in the figure, or combine certain components, or arrange the components differently.

[0086] like Figure 2 As shown, the memory 105 as a storage medium may include an operating system, a network communication module, a user interface module, and an application program for implementing an artificial intelligence-based gateway testing method.

[0087] exist Figure 2 In the electronic device shown, the network interface 103 is mainly used for data communication with the network server; the user interface 104 is mainly used for data interaction with the user; the processor 101 and the memory 105 in this application can be set in the electronic device, and the electronic device calls the application stored in the memory 105 for implementing an artificial intelligence-based gateway testing method through the processor 101 to implement the above method.

[0088] Example 5 This embodiment provides a computer-readable storage medium, on which a computer program is stored. A processor executes the computer program to implement any of the above methods.

[0089] In some embodiments, the computer-readable storage medium may be a memory device such as FRAM, ROM, PROM, EPROM, EEPROM, flash memory, magnetic surface mount memory, optical disk, or CD-ROM; or various devices including any one or any combination of the above memories. The computer may be various computing devices including smart terminals and servers.

[0090] In the above embodiments of the present disclosure, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0091] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only schematic. For example, the division of units can be a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of units or modules, which can be electrical or other forms.

[0092] Units described as separate components may or may not be physically separate, and components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple units. Some or all of the units may be selected to achieve the purpose of the present embodiment according to actual needs.

[0093] In addition, the functional units in the various embodiments of the present disclosure may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.

[0094] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable non-volatile storage medium. Based on this understanding, the technical solution of the present invention is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a non-volatile storage medium, including a number of instructions for enabling a device (which can be a personal computer, server or network device, etc.) to execute all or part of the steps of the various embodiments of the present invention. The aforementioned non-volatile storage medium includes: U disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), mobile hard disk, magnetic disk or optical disk and other media that can store program code.

[0095] The above is only a preferred embodiment of the present disclosure. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present disclosure. These improvements and modifications should also be regarded as within the scope of protection of the present disclosure.

Claims

1. The gateway testing method based on artificial intelligence is characterized by: include: Establish and train a reinforcement learning attack model based on test requirements. The reinforcement learning attack model is configured to take a test target as input and output a DDoS attack scenario targeting the test target. According to the DDoS defense test request received from the target gateway, a target DDOS attack plan for the target gateway is obtained through the reinforcement learning attack model; Performing a DDoS attack test on the target gateway according to the target DDoS attack scenario to obtain test data of the target gateway; According to the test data, the test data is analyzed to obtain a test result of the target gateway.

2. The artificial intelligence-based gateway testing method according to claim 1, characterized in that: The reinforcement learning attack model includes a state space, an action space and a reward function; The state in the state space is configured to include at least one network state parameter of the target gateway; The actions in the action space are configured to include at least one DDoS attack strategy parameter; The reward function is configured to include at least one of a positive reward, a negative reward, and a continuous negative reward; According to the test requirements, the reinforcement learning attack model is established and trained, including: According to the test requirements, establish a simulated network environment and configure at least one training gateway; Performing a DDoS attack on at least one of the training gateways using the reinforcement learning attack model; Record the response of at least one of the training gateways to the DDoS attack, and optimize the attack strategy of the reinforcement learning attack model based on the feedback until a preset training termination condition is met.

3. The artificial intelligence-based gateway testing method according to claim 2, characterized in that: The positive reward is configured as at least one of the following: When the network status parameters of the target gateway deteriorate, a positive reward is given; When the target gateway experiences a service interruption, a positive reward is given; When the target gateway is blocked by mistake, a positive reward will be given; The negative reward is configured as at least one of the following: When the network status parameters of the target gateway improve, a negative reward is given; When the target gateway identifies the attack source, a negative reward is given; The continuous negative reward is configured as at least one of the following: When the DDoS attack strategy parameters are enhanced, continuous rewards are given.

4. The artificial intelligence-based gateway testing method according to claim 2, characterized in that: The step of establishing a simulated network environment and configuring at least one training gateway according to test requirements includes: Constructing a simulated network environment according to test requirements, wherein the simulated network environment includes at least one training gateway; According to the at least one training gateway, a different defense mechanism is configured for each training gateway.

5. The artificial intelligence-based gateway testing method according to claim 4, characterized in that: The method of obtaining a target DDOS attack solution for the target gateway by using the reinforcement learning attack model according to the DDoS defense test request received from the target gateway includes: According to the DDoS defense test request received from the target gateway, the gateway information and defense mechanism of the target gateway are obtained; Obtain the attack intensity limit of the DDoS defense test based on the DDoS defense test request received from the target gateway; The gateway information and defense mechanism of the target gateway and the attack intensity limit of the DDoS defense test are input into the reinforcement learning attack model to obtain a target DDOS attack plan for the target gateway.

6. The artificial intelligence-based gateway testing method according to claim 5, characterized in that: The step of inputting the gateway information and defense mechanism of the target gateway and the attack intensity limit of the DDoS defense test into the reinforcement learning attack model to obtain a target DDOS attack plan for the target gateway includes: Configuring an attack target for the reinforcement learning attack model according to the gateway information of the target gateway; Configuring an attack strategy for the reinforcement learning attack model based on the defense mechanism of the target gateway; According to the attack intensity limit of the DDoS defense test, action limits are configured for the action space of the reinforcement learning attack model.

7. The artificial intelligence-based gateway testing method according to claim 1, characterized in that: The performing a DDoS attack test on the target gateway according to the target DDoS attack scenario to obtain test data of the target gateway includes: According to the target gateway, obtaining normal traffic data corresponding to the target gateway; A DDoS attack test is performed on the target gateway according to the target DDoS attack scenario and the normal traffic data to obtain test data of the target gateway.

8. The artificial intelligence-based gateway testing system is characterized by: including a test platform and at least one target gateway; The test platform is configured as follows: Establish and train a reinforcement learning attack model based on test requirements. The reinforcement learning attack model is configured to take a test target as input and output a DDoS attack scenario targeting the test target. According to the DDoS defense test request received from the target gateway, a target DDOS attack plan for the target gateway is obtained through the reinforcement learning attack model; Performing a DDoS attack test on the target gateway according to the target DDoS attack scenario to obtain test data of the target gateway; According to the test data, the test data is analyzed to obtain a test result of the target gateway.

9. The artificial intelligence-based gateway testing system according to claim 8, characterized in that: The reinforcement learning attack model includes a state space, an action space and a reward function; The state in the state space is configured to include at least one network state parameter of the target gateway; The actions in the action space are configured to include at least one DDoS attack strategy parameter; The reward function is configured to include at least one of a positive reward, a negative reward, and a continuous negative reward; According to the test requirements, the reinforcement learning attack model is established and trained, including: According to the test requirements, establish a simulated network environment and configure at least one training gateway; Performing a DDoS attack on at least one of the training gateways using the reinforcement learning attack model; Record the response of at least one of the training gateways to the DDoS attack, and optimize the attack strategy of the reinforcement learning attack model based on the feedback until a preset training termination condition is met.

10. A device, characterized in that The device includes a memory and a processor, wherein a computer program is stored in the memory, and the processor executes the computer program to implement the method according to any one of claims 1 to 7.

Citation Information

Cited By

  • Security gateway management method and device, equipment and medium

    CN121547270A