Network security training field construction method and system based on knowledge graph

By constructing a cybersecurity training ground based on knowledge graphs, the problem of cumbersome network range construction process is solved, achieving efficient and accurate network range construction and verification, and improving the credibility and practical effect of cybersecurity training scenarios.

CN120528692BActive Publication Date: 2025-11-25HUNAN WEIKANG INTELLIGENT TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510876801.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-06-27
Publication Date
2025-11-25
Estimated Expiration
2045-06-27

AI Technical Summary

Technical Problem

The construction of existing cyber ranges relies on manual configuration and setup, which is cumbersome and makes it difficult to respond quickly to changes in cybersecurity needs.

Method used

By adopting a knowledge graph-based approach, the network security testbed is constructed by acquiring the construction requirements and preparatory data, constructing a testbed knowledge graph, calculating relation weights, building an initial network testbed, and verifying it, ultimately forming the final network security testbed.

Benefits of technology

It improves the efficiency and accuracy of network range construction, enabling it to more realistically reflect the actual situation of network security and enhancing the credibility of range scenarios and the effectiveness of practical exercises.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120528692B_ABST
    Figure CN120528692B_ABST
Patent Text Reader

Abstract

The application discloses a network security training field construction method and system based on a knowledge graph. The network security training field construction method based on the knowledge graph comprises obtaining construction requirements of a network security target field and target field preliminary data, wherein the target field preliminary data comprises a target field preliminary data source and a target field preliminary data completeness; a target field knowledge graph is constructed based on the target field preliminary data, the target field knowledge graph comprises network entities and network entity relationships; a relationship weight is calculated based on the target field preliminary data source, the target field preliminary data completeness and the network entity relationships; an initial network target field is constructed based on the construction requirements, the network entities and the relationship weight, network security verification is performed based on an initial network target field scene and an initial network target field strategy, and a verification result is obtained; and when the verification result reaches a preset value, the initial network target field is taken as a final network security target field, thereby improving the construction efficiency and accuracy of the network target field.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of knowledge graph-based cybersecurity training ground construction, and in particular to methods and systems for constructing knowledge graph-based cybersecurity training grounds. Background Technology

[0002] Target range knowledge graph technology has developed rapidly and has already played an important role in multiple fields. A target range knowledge graph is a structured knowledge base that organizes information such as entities, concepts, and events in the form of a graph and connects them through relationships. In the field of cybersecurity, target range knowledge graphs can integrate and represent information such as network devices, attack methods, and defense strategies, providing rich knowledge support for the construction of cyber ranges.

[0003] Currently, the construction of cyber ranges relies on manual configuration and setup, a cumbersome and time-consuming process that makes it difficult to quickly respond to changes in cybersecurity needs. Summary of the Invention

[0004] This application aims to at least address the technical problems existing in the prior art. To this end, this application proposes a method and system for constructing a cybersecurity training ground based on knowledge graphs, which can improve the efficiency and accuracy of constructing cyber ranges.

[0005] The first aspect of this application provides a method for constructing a cybersecurity training ground based on knowledge graphs, comprising the following steps:

[0006] Obtain the construction requirements and preparation data for the cybersecurity test range, wherein the preparation data includes the source of the preparation data and the completeness of the preparation data;

[0007] Based on the aforementioned target range preparation data, a target range knowledge graph is constructed, which includes network entities and network entity relationships.

[0008] The relationship weight is calculated based on the source of the target range preparation data, the completeness of the target range preparation data, and the network entity relationships;

[0009] An initial network test range is constructed based on the construction requirements, the network entities, and the relationship weights, wherein the initial network test range includes an initial network test range scenario and an initial network test range strategy;

[0010] Based on the initial network test scenario and the initial network test strategy, network security verification is performed to obtain verification results;

[0011] When the verification result reaches a preset value, the initial network test range will be used as the final network security test range.

[0012] The control method according to the embodiments of this application has at least the following beneficial effects:

[0013] This method acquires the construction requirements and preliminary data for a cybersecurity test range, including the data source and completeness. Based on this data, a test range knowledge graph is constructed, containing network entities and their relationships. Relationship weights are calculated based on the data source, completeness, and relationships. An initial cybersecurity test range is then constructed based on the construction requirements, network entities, and relationship weights, including initial test range scenarios and strategies. This application utilizes knowledge graphs to provide structured representation and rapid retrieval of data in the cybersecurity field, improving the efficiency of test range construction. Based on the initial test range scenarios and strategies, cybersecurity verification is performed, yielding verification results. When the verification results reach a preset value, the initial cybersecurity test range is used as the final cybersecurity test range. The knowledge graph-based cybersecurity test range constructed in this application more realistically reflects the actual situation of cybersecurity, improving the credibility of the test range scenarios and the effectiveness of practical exercises.

[0014] According to some embodiments of this application, the calculation of relationship weights based on the source of the target range preparation data, the completeness of the target range preparation data, and the network entity relationships includes:

[0015] Obtain the results of the online entity relationship review;

[0016] Based on the target range preparation data source and the preset data source scoring criteria, the first weight is calculated;

[0017] The second weight is calculated based on the completeness of the target range preparation data and the preset completeness coefficient.

[0018] The third weight is calculated based on the target range preparation data and the second weight;

[0019] Based on the network entity relationship review results and the preset correction coefficient, the fourth weight is obtained;

[0020] The relationship weight is calculated based on the first weight, the third weight, and the fourth weight.

[0021] According to some embodiments of this application, the calculation of the third weight based on the target range preparation data and the second weight includes:

[0022] The target range preparation data is input into the trained natural language processing model to obtain the network entity relationship confidence.

[0023] The third weight is calculated based on the confidence level of the relationship between the second weight and the network entity.

[0024] According to some embodiments of this application, the relationship weight is calculated using the following formula:

[0025] W = w1*α + w2*β + w3*γ;

[0026] Where W is the relation weight, w1 is the first weight, w2 is the third weight, w3 is the fourth weight, α is the first preset coefficient, β is the second preset coefficient, and γ is the third preset coefficient.

[0027] According to some embodiments of this application, the step of constructing a target range knowledge graph based on the target range preparation data, wherein the target range knowledge graph includes network entities and network entity relationships, includes:

[0028] The target range preparation data is fused to obtain fused target range preparation data;

[0029] Based on the fused target range preparation data, the network entities, network entity attributes, and network entity relationships of the target range knowledge graph are obtained through natural language processing methods. The network entities include, but are not limited to, at least one of network assets, vulnerabilities, attack techniques, and defense measures. The network entity attributes are feature descriptions of the network entities, and the network entity relationships are descriptions of the interactions between entities.

[0030] According to some embodiments of this application, the initial network range is constructed based on the construction requirements, the network entities, and the relationship weights, wherein the initial network range includes an initial network range scenario and an initial network range strategy, including:

[0031] Based on the construction requirements, the network entities, and the relationship weights, a query is performed in the target range knowledge graph to obtain the initial network target range scenario, scenario configuration parameters, and initial network target range strategy.

[0032] According to some embodiments of this application, the knowledge graph-based cybersecurity training ground construction method further includes:

[0033] If the verification result does not reach the preset value, the target knowledge graph is iteratively optimized based on the verification result to obtain the final cybersecurity target.

[0034] A second aspect of this application provides a knowledge graph-based cybersecurity training ground construction system, which includes:

[0035] The data acquisition module is used to acquire the construction requirements and preparatory data for the cybersecurity test range, wherein the preparatory data includes the source of the preparatory data and the completeness of the preparatory data.

[0036] The target range knowledge graph construction module is used to construct a target range knowledge graph based on the target range preparation data. The target range knowledge graph includes network entities and network entity relationships.

[0037] The relationship weight calculation module is used to calculate relationship weights based on the source of the target range preparation data, the completeness of the target range preparation data, and the network entity relationships.

[0038] An initial network target range construction module is used to construct an initial network target range based on the construction requirements, the network entities, and the relationship weights, wherein the initial network target range includes an initial network target range scenario and an initial network target range strategy;

[0039] The verification module is used to perform network security verification based on the initial network range scenario and the initial network range strategy, and obtain the verification result.

[0040] The final network security target acquisition module is used to use the initial network target as the final network security target when the verification result reaches a preset value.

[0041] This system acquires the construction requirements and preliminary data for a cybersecurity test range, including the data source and completeness. Based on this data, a test range knowledge graph is constructed, containing network entities and their relationships. Relationship weights are calculated based on the data source, completeness, and relationships. An initial cybersecurity test range is then constructed based on the construction requirements, network entities, and relationship weights, including initial test range scenarios and strategies. This application utilizes knowledge graphs to provide structured representation and rapid retrieval of data in the cybersecurity field, improving the efficiency of test range construction. Based on the initial test range scenarios and strategies, cybersecurity verification is performed, yielding verification results. When the verification results reach a preset value, the initial cybersecurity test range is used as the final cybersecurity test range. The knowledge graph-based cybersecurity test range constructed in this application more realistically reflects the actual situation of cybersecurity, improving the credibility of the test range scenarios and the effectiveness of practical exercises.

[0042] A third aspect of this application provides an electronic device for constructing a knowledge graph-based cybersecurity training ground, including at least one control processor and a memory for communicatively connecting to the at least one control processor; the memory stores instructions executable by the at least one control processor, which are executed by the at least one control processor to enable the at least one control processor to execute the aforementioned knowledge graph-based cybersecurity training ground construction method.

[0043] A fourth aspect of this application provides a computer-readable storage medium storing computer-executable instructions for causing a computer to execute the aforementioned knowledge graph-based network security training ground construction method.

[0044] It should be noted that the beneficial effects of the second to fourth aspects of this application with respect to the prior art are the same as the beneficial effects of the aforementioned knowledge graph-based cybersecurity training ground construction system with respect to the prior art, and will not be elaborated here.

[0045] Additional aspects and advantages of this application will be set forth in part in the description which follows, and in part will be obvious from the description, or may be learned by practice of this application. Attached Figure Description

[0046] The above and / or additional aspects and advantages of this application will become apparent and readily understood from the description of the embodiments taken in conjunction with the following drawings, in which:

[0047] Figure 1 This is a flowchart of a knowledge graph-based network security training ground construction method according to an embodiment of this application;

[0048] Figure 2 This is a schematic diagram of the structure of an embodiment of the knowledge graph-based cybersecurity training ground construction system provided in this application;

[0049] Figure 3 This is a schematic diagram of the structure of an embodiment of the electronic device provided in this application. Detailed Implementation

[0050] The embodiments of this application are described in detail below. Examples of the embodiments are shown in the accompanying drawings, wherein the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain this application, and should not be construed as limiting this application.

[0051] In the description of this application, the use of terms such as "first," "second," etc., is for the purpose of distinguishing technical features only and should not be construed as indicating or implying relative importance or implicitly indicating the number of technical features indicated or the order of the technical features indicated.

[0052] In the description of this application, it should be understood that the orientation descriptions, such as up, down, etc., are based on the orientation or positional relationship shown in the accompanying drawings, and are only for the convenience of describing this application and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation, and therefore should not be construed as a limitation of this application.

[0053] In the description of this application, it should be noted that, unless otherwise explicitly defined, terms such as "setup," "installation," and "connection" should be interpreted broadly, and those skilled in the art can reasonably determine the specific meaning of the above terms in this application in conjunction with the specific content of the technical solution.

[0054] Target range knowledge graph technology has developed rapidly and has already played an important role in multiple fields. A target range knowledge graph is a structured knowledge base that organizes information such as entities, concepts, and events in the form of a graph and connects them through relationships. In the field of cybersecurity, target range knowledge graphs can integrate and represent information such as network devices, attack methods, and defense strategies, providing rich knowledge support for the construction of cyber ranges.

[0055] Currently, the construction of cyber ranges relies on manual configuration and setup, a cumbersome and time-consuming process that makes it difficult to quickly respond to changes in cybersecurity needs.

[0056] To address the aforementioned technical deficiencies, this application provides a method and system for constructing a cybersecurity training ground based on a knowledge graph.

[0057] Please see Figure 1 This is a flowchart illustrating a method for constructing a network security training ground based on a knowledge graph, provided in an embodiment of this application. This method is applied to electronic devices, such as servers. Figure 1 As shown, the method for constructing a knowledge graph-based cybersecurity training ground includes:

[0058] Step S101: Obtain the construction requirements and preparatory data for the cybersecurity test range, wherein the preparatory data includes the source of the preparatory data and the completeness of the preparatory data.

[0059] Step S102: Based on the target range preparation data, construct a target range knowledge graph, which includes network entities and network entity relationships;

[0060] Step S103: Calculate the relationship weights based on the source of the target range preparation data, the completeness of the target range preparation data, and the network entity relationships;

[0061] Step S104: Construct an initial network target range based on construction requirements, network entities, and relationship weights. The initial network target range includes an initial network target range scenario and an initial network target range strategy.

[0062] Step S105: Based on the initial network range scenario and initial network range strategy, perform network security verification and obtain the verification results;

[0063] Step S106: When the verification result reaches the preset value, the initial network target range is used as the final network security target range.

[0064] The above-mentioned requirements for building a cybersecurity test range can help determine the target users, usage scenarios, and functional requirements of the test range.

[0065] The completeness of the above-mentioned range preparation data is a pre-calculated indicator value. The calculation rule can be that when the time, location and scope of influence are included, it is recorded as 1, and when one of them is missing, 0.1 is deducted.

[0066] The aforementioned test range preparation data can be sourced from national standard libraries, major manufacturers, security forums, and user-generated content.

[0067] The aforementioned network entity relationships include, but are not limited to, attacks and exploitation, and each network entity relationship has a corresponding network entity relationship confidence level.

[0068] This method acquires the construction requirements and preliminary data for a cybersecurity test range, including the data source and completeness. Based on this data, a test range knowledge graph is constructed, containing network entities and their relationships. Relationship weights are calculated based on the data source, completeness, and relationships. An initial cybersecurity test range is then constructed based on the construction requirements, network entities, and relationship weights, including initial test range scenarios and strategies. This application utilizes knowledge graphs to provide structured representation and rapid retrieval of data in the cybersecurity field, improving the efficiency of test range construction. Based on the initial test range scenarios and strategies, cybersecurity verification is performed, yielding verification results. When the verification results reach a preset value, the initial cybersecurity test range is used as the final cybersecurity test range. The knowledge graph-based cybersecurity test range constructed in this application more realistically reflects the actual situation of cybersecurity, improving the credibility of the test range scenarios and the effectiveness of practical exercises.

[0069] In some embodiments, the calculation of relationship weights in step S103 based on the source of the target range preparation data, the completeness of the target range preparation data, and the network entity relationships includes:

[0070] Step S201: Obtain the network entity relationship audit results;

[0071] Step S202: Calculate the first weight based on the target range preparation data source and the preset data source scoring criteria;

[0072] Step S203: Calculate the second weight based on the completeness of the target range preparation data and the preset completeness coefficient;

[0073] Step S204: Calculate the third weight based on the target range preparation data and the second weight;

[0074] Step S205: Based on the network entity relationship review results and the preset correction coefficient, obtain the fourth weight;

[0075] Step S206: Calculate the relationship weights based on the first weight, the third weight, and the fourth weight.

[0076] The aforementioned preset data source scoring criteria can be such that when the source of the preliminary data for the test range is the national standard library, the first weight is 0.9; and so on, each source of preliminary data for the test range is given a corresponding weight.

[0077] Based on the completeness of the target range preparation data and the preset completeness coefficient, the second weight can be calculated by multiplying the completeness of the target range preparation data and the preset completeness coefficient.

[0078] The above network entity relationship review results can be empirical values ​​entered after manual review; the above preset correction coefficient can be 0.2.

[0079] In some embodiments, calculating the third weight based on the target range preparation data and the second weight in step S204 includes:

[0080] Step S301: Input the target range preparation data into the trained natural language processing model to obtain the network entity relationship confidence.

[0081] Step S302: Calculate the third weight based on the confidence of the relationship between the second weight and the network entity.

[0082] Based on the second weight and the confidence level of the network entity relationship, the third weight can be calculated by multiplying the second weight and the confidence level of the network entity relationship.

[0083] In some embodiments, the relationship weight is calculated in step S206 using the following formula:

[0084] W = w1*α + w2*β + w3*γ;

[0085] Where W is the relation weight, w1 is the first weight, w2 is the third weight, w3 is the fourth weight, α is the first preset coefficient, β is the second preset coefficient, and γ is the third preset coefficient.

[0086] This application improves data accuracy by combining multiple data weights.

[0087] In some embodiments, in step S102, a target range knowledge graph is constructed based on the target range preparation data. The target range knowledge graph includes network entities and network entity relationships, including:

[0088] Step S401: Perform data fusion on the target range preparation data to obtain fused target range preparation data;

[0089] Step S402: Based on the fused target range preparation data, obtain the network entities, network entity attributes, and network entity relationships of the target range knowledge graph through natural language processing methods. Among them, network entities include, but are not limited to, at least one of network assets, vulnerabilities, attack techniques, and defense measures. Network entity attributes are feature descriptions of network entities, and network entity relationships are descriptions of interactions between entities.

[0090] Specifically, in some embodiments, the collected data is used to construct a knowledge graph containing network entities (such as IP addresses, domain names, network devices, etc.) and security concepts (such as attack types, vulnerabilities, and defense measures). This graph is stored and managed through a graph database for easy subsequent querying and updating. Simultaneously, entities in the network testbed are identified, and their attributes are extracted. Entities include devices, services, and users in the network, while attributes include the entity's characteristics and state information. Relationships between entities are then defined in the knowledge graph, such as communication relationships, trust relationships, and attack paths. These relationships are represented by edges in the graph, enhancing the semantic connections between entities.

[0091] The process of constructing a knowledge graph for a network testbed can include:

[0092] Define the knowledge graph architecture: Design the structure of the knowledge graph, including entity types, attributes, and relationship types. Entity types may include network assets, vulnerabilities, attack techniques, and defense measures; attributes are characteristic descriptions of entities; and relationship types describe the interactions between entities.

[0093] Entity and Attribute Modeling: Based on the entities and attributes identified in the requirements analysis phase, a model is built. Each entity will be assigned a unique identifier and its attributes will be defined. For example, the attributes of an IP address may include the IP address itself, the network segment it belongs to, and the associated physical device.

[0094] Relation extraction: Using natural language processing techniques, relationships between entities are extracted from collected data. For example, the relationship "device X has vulnerability Y" can be extracted from a security report and represented as an edge in a knowledge graph.

[0095] Knowledge graph storage: Choose a suitable graph database, such as Neo4j or ArangoDB, to store the knowledge graph. Design the database schema, including node and edge types, attributes, and indexes, to optimize query efficiency.

[0096] Knowledge fusion: For data collected from different sources, knowledge fusion is performed to resolve data redundancy and inconsistency issues. Entity disambiguation technology is used to ensure that different representations of the same entity can be correctly identified and merged.

[0097] Knowledge graph updates: Establish a mechanism to update the knowledge graph, ensuring it reflects the latest cybersecurity threats and defense technologies. This may include regular data imports, incremental updates, or triggered updates.

[0098] Knowledge Graph Query and Optimization: Design efficient query strategies for rapid retrieval of information from the knowledge graph. Optimize query performance, such as by building graph indexes and using caching mechanisms.

[0099] Knowledge Graph Visualization: Develop visualization tools to help users intuitively browse and understand the structure and content of knowledge graphs. These tools can display networks of entities, attributes, and relationships, and support interactive exploration.

[0100] Knowledge graph validation: Validating the constructed knowledge graph to ensure the accuracy of the data and the logical consistency of the graph. The validation process may include automated rule checks and manual review.

[0101] Knowledge Graph Security and Access Control: Design security mechanisms to protect data in the knowledge graph from unauthorized access or tampering. Implement access control to ensure users access data according to their roles and permissions.

[0102] Through the above steps, this application constructs a structured, dynamically updated, and easily managed cybersecurity knowledge graph, providing an accurate data foundation for the further development and application of cyber ranges.

[0103] Secondly, the entity and attribute recognition process includes:

[0104] Define the entity and attribute identification objectives: Clearly define the entity types and attribute features to be extracted during the identification process. Entity types may include network devices, user accounts, files, applications, etc., while attributes cover the characteristics of these entities, such as the device's IP address, the user's permission level, and the file's creation date.

[0105] Data preprocessing: Cleaning and formatting the collected raw data to facilitate the identification of entities and attributes. This may include noise removal, data format standardization, and filling in missing values.

[0106] Applying Natural Language Processing (NLP) techniques: Utilizing NLP techniques, such as Named Entity Recognition (NER) algorithms, to identify entities and attributes in text. These techniques can help extract useful information from unstructured data.

[0107] Entity linking and disambiguation: For identified entities, entity linking is performed to ensure that different representations of the same entity can be correctly associated. Simultaneously, entity disambiguation is performed to distinguish between entities with the same name but different meanings.

[0108] Attribute value extraction: Extracting entity attribute values ​​from data based on predefined attribute templates. This may involve techniques such as regular expression matching of attribute values ​​and keyword search.

[0109] Utilizing machine learning models: Train machine learning models, such as classifiers or regression models, to automatically identify and predict attribute values ​​of entities. These models can be trained based on historical data and known attributes.

[0110] Integrating multi-source data: This involves combining entity and attribute information from different data sources to obtain a more comprehensive knowledge representation. This may require addressing data fusion and consistency issues.

[0111] Establishing relationships between entities and attributes: In the knowledge graph, establish relationships between entities and their attributes, forming a graph structure of nodes and node attributes. Each entity node is connected to its attributes through edges, and attributes are stored as features of the nodes.

[0112] Verification and quality control: Verify the identified entities and attributes to ensure the accuracy and reliability of the information. This may include quality control measures such as manual review and cross-validation.

[0113] Update the knowledge graph: Add newly identified entity and attribute information to the knowledge graph to enrich and expand the content of the knowledge base. Ensure that the knowledge graph reflects the latest cybersecurity situation.

[0114] Provide a feedback mechanism: Establish a feedback mechanism to allow users and the system to evaluate and correct the recognition results of entities and attributes, so as to continuously optimize the accuracy of the recognition process.

[0115] Through the above steps, this application can accurately identify key entities and attributes from a large amount of cybersecurity data and integrate this information into a knowledge graph, providing rich contextual information and knowledge base for building a cyber range.

[0116] In some embodiments, in step S104, an initial network target range is constructed based on construction requirements, network entities, and relationship weights. The initial network target range includes an initial network target range scenario and an initial network target range strategy, including:

[0117] Step S501: Based on the construction requirements, network entities, and relationship weights, query the target range knowledge graph to obtain the initial network target range scenario, scenario configuration parameters, and initial network target range strategy.

[0118] Specifically, scenarios are generated based on the constructed knowledge graph, and corresponding security strategies are recommended. Various scenarios for network test ranges are automatically or semi-automatically generated based on information in the knowledge graph. These scenarios can simulate normal network operations or various network attacks. Then, using security concepts and historical data from the knowledge graph, appropriate security strategies and defense measures are recommended for the network test range.

[0119] The main processes for generating scenarios based on constructed knowledge graphs include:

[0120] Scenario definition: Determine the types of scenarios that the network range needs to simulate, such as network attacks, system vulnerability exploitation, and security protection testing.

[0121] Knowledge graph query: Utilize the entities and relationships stored in a knowledge graph to query information related to a specific scenario. For example, query the vulnerabilities and attack techniques involved in a specific type of cyberattack.

[0122] Scenario parameter configuration: Based on the query results, configure the scenario parameters, such as attack targets, attack methods, and defense measures. These parameters will guide the specific implementation of the scenario.

[0123] Scene template design: Design reusable scene templates, each containing a set of predefined entities, relationships and attributes, and instructions on how to combine them into a specific scene.

[0124] Dynamic scenario building: Based on configured parameters and selected templates, dynamically build network range scenarios. This may involve configuring network topology, deploying virtual machines, and setting up network services in the virtual environment.

[0125] Scenario Verification: Verify the generated scenarios to ensure they meet the expected security testing objectives. Verification may include simulated attack tests, security policy evaluations, etc.

[0126] Scenario optimization: Based on the verification results, optimize the scenario to improve its realism and effectiveness. This may involve adjusting network configurations, increasing the complexity of attack simulations, etc.

[0127] Scene library management: Generated scenes are stored in a scene library for reuse in the network range. The scene library should support scene retrieval, updating, and deletion.

[0128] User interaction design: Design a user interface that allows users to select and customize scenarios as needed. The user interface should provide intuitive control options, such as selecting the attack type and setting the attack strength.

[0129] Scenario-based automated testing: This involves implementing automated test scripts to execute predefined test cases within generated scenarios. These scripts can simulate attack behaviors, evaluate defense effectiveness, and more.

[0130] Scenario Feedback Mechanism: Establish a feedback mechanism that allows users and automated testing tools to provide feedback on scenario performance. This feedback will be used to continuously improve the quality and relevance of the scenarios.

[0131] Security Assessment: Conduct a security assessment for each generated scenario to ensure they do not pose a security risk to a real-world network environment. This may involve checking for potential vulnerabilities in the scenarios and evaluating the feasibility of attack simulations.

[0132] Scenario documentation: Create detailed documentation for each scenario, describing its purpose, configuration, usage guidelines, and expected results. This documentation will help users understand and use the scenario.

[0133] Through the above steps, this application can efficiently generate diverse and customizable network range scenarios with the support of knowledge graphs, providing a rich environment for network security testing and training.

[0134] Furthermore, the recommended process for implementing appropriate security strategies includes:

[0135] Knowledge graph query: Search the knowledge graph for information related to security needs, such as known vulnerabilities, historical attack patterns, and effective defense measures.

[0136] Security policy template design: Design security policy templates, including recommended configurations, best practices, compliance requirements, etc., to guide the formulation of security policies.

[0137] Policy generation algorithm development: Develop algorithms to automatically generate security policies based on queried information and predefined templates. Algorithms may include rule engines, machine learning models, etc.

[0138] Personalized policy customization: The generated security policies can be customized according to the user's specific needs and network environment.

[0139] Security policy repository management: Store generated and optimized security policies in the policy repository, supporting policy retrieval, updating, and maintenance.

[0140] Policy deployment and monitoring: Deploy security policies in the network range and monitor their execution to ensure that the policies are implemented correctly.

[0141] Automated testing and verification: Use automated testing tools to verify the effectiveness of security policies, including simulated attack tests and configuration consistency checks.

[0142] Continuous learning and updating: Utilizing machine learning technology, the security policy recommendation system can be updated from new...

[0143] In some embodiments, the method for constructing a knowledge graph-based cybersecurity training ground further includes:

[0144] Step S601: If the verification result does not reach the preset value, the target knowledge graph is iteratively optimized based on the verification result to obtain the final cybersecurity target.

[0145] Specifically, this application deploys the network range both physically and virtually based on the scenarios and strategies generated in the preceding steps. It configures the network topology, including the connection and layout of network devices. Security devices, such as firewalls and intrusion detection systems, are configured to simulate security measures in a real network environment. Honeypots and other decoy techniques are deployed to attract and analyze attacker behavior.

[0146] Secondly, testing and verification primarily involve executing predefined test cases in the target environment to simulate various network attacks and security incidents. This verifies network security, checks for unidentified vulnerabilities or configuration errors, and verifies the effectiveness of deployed security policies and measures in defending against simulated attacks. The effectiveness is then evaluated and optimized. Test results are analyzed to assess the performance of the network target environment and the effectiveness of security policies. Deficiencies in the network target environment are identified, including vulnerabilities and policy flaws. Based on the evaluation results, the target environment configuration is adjusted and optimized to improve its security and efficiency.

[0147] Secondly, knowledge graph updates and maintenance involve feeding data and insights collected during testing and evaluation into the knowledge graph. This includes updating the knowledge graph with information on cybersecurity threats, vulnerabilities, attack patterns, and defense strategies. Maintaining the accuracy and up-to-dateness of the knowledge graph ensures it reflects the current cybersecurity landscape. Furthermore, continuous iterative optimization of the cyber range is performed based on feedback from testing and evaluation. This includes adjusting scenario generation algorithms and security policy recommendation algorithms to improve the range's adaptability and the targeting of strategies. It's also crucial to ensure that the range's deployment and operation comply with relevant security standards and regulations. Regular security compliance checks are conducted to ensure the range's continued compliance. A feedback mechanism allows users to report problems encountered during range usage or to provide improvement suggestions. This feedback is then used to further optimize the range's performance and user experience.

[0148] Specifically, for the convenience of those skilled in the art, a set of preferred embodiments is provided below:

[0149] I. Data Acquisition:

[0150] Obtain the construction requirements and preparation data for the cybersecurity test range, including the source and completeness of the preparation data.

[0151] II. Constructing a target range knowledge graph:

[0152] Based on the target range preparation data, a target range knowledge graph is constructed. The target range knowledge graph includes network entities and network entity relationships, specifically:

[0153] Data fusion is performed on the target range preparation data to obtain fused target range preparation data;

[0154] Based on the fused target range preparation data, network entities, network entity attributes, and network entity relationships are obtained from the target range knowledge graph through natural language processing methods. Among them, network entities include, but are not limited to, at least one of network assets, vulnerabilities, attack techniques, and defense measures. Network entity attributes are feature descriptions of network entities, and network entity relationships are descriptions of the interactions between entities.

[0155] III. Calculating Relationship Weights:

[0156] The relationship weights are calculated based on the source of the target range preparation data, the completeness of the target range preparation data, and the network entity relationships, specifically as follows:

[0157] Obtain the results of the online entity relationship review;

[0158] The first weight is calculated based on the pre-existing data source and the pre-set data source scoring criteria at the target range.

[0159] The second weight is calculated based on the completeness of the target range preparation data and the preset completeness coefficient.

[0160] The third weight is calculated based on the target range preparation data and the second weight, specifically as follows:

[0161] Input the target range preparation data into the trained natural language processing model to obtain the network entity relationship confidence score;

[0162] The third weight is calculated based on the confidence level of the relationship between the second weight and the network entity.

[0163] The fourth weight is obtained based on the network entity relationship review results and the preset correction coefficient;

[0164] Based on the first, third, and fourth weights, the relationship weights are calculated using the following formula:

[0165] W = w1*α + w2*β + w3*γ;

[0166] Where W is the relation weight, w1 is the first weight, w2 is the third weight, w3 is the fourth weight, α is the first preset coefficient, β is the second preset coefficient, and γ is the third preset coefficient.

[0167] IV. Constructing the initial network target range:

[0168] An initial network test range is constructed based on construction requirements, network entities, and relationship weights. This initial network test range includes an initial network test range scenario and an initial network test range strategy, specifically:

[0169] Based on the construction requirements, network entities, and relationship weights, a query is performed in the target range knowledge graph to obtain the initial network target range scenario, scenario configuration parameters, and initial network target range strategy.

[0170] V. Final Cybersecurity Range Selection:

[0171] Based on the initial network test range scenario and initial network test range strategy, network security verification was conducted, and the verification results were obtained.

[0172] When the verification results reach the preset value, the initial network test range will be used as the final network security test range.

[0173] If the verification result does not reach the preset value, the target range knowledge graph is iteratively optimized based on the verification result to obtain the final cybersecurity target range.

[0174] Additionally, refer to Figure 2 One embodiment of this application provides a knowledge graph-based network security training ground construction system, including a data acquisition module 1100, a target range knowledge graph construction module 1200, a relation weight calculation module 1300, an initial network target range construction module 1400, a verification module 1500, and a final network security target range acquisition module 1600, wherein:

[0175] The data acquisition module 1100 is used to acquire the construction requirements and preparatory data of the cybersecurity test range. The preparatory data includes the source of the preparatory data and the completeness of the preparatory data.

[0176] The target range knowledge graph construction module 1200 is used to construct a target range knowledge graph based on the target range preparation data. The target range knowledge graph includes network entities and network entity relationships.

[0177] The relation weight calculation module 1300 is used to calculate relation weights based on the source of the target range preparation data, the completeness of the target range preparation data, and the network entity relationships.

[0178] The initial network range construction module 1400 is used to construct an initial network range based on construction requirements, network entities, and relation weights. The initial network range includes an initial network range scenario and an initial network range strategy.

[0179] The verification module 1500 is used to perform network security verification based on the initial network range scenario and the initial network range strategy, and obtain the verification results.

[0180] The final network security target acquisition module 1600 is used to take the initial network target as the final network security target when the verification result reaches a preset value.

[0181] This system acquires the construction requirements and preliminary data for a cybersecurity test range, including the data source and completeness. Based on this data, a test range knowledge graph is constructed, containing network entities and their relationships. Relationship weights are calculated based on the data source, completeness, and relationships. An initial cybersecurity test range is then constructed based on the construction requirements, network entities, and relationship weights, including initial test range scenarios and strategies. This application utilizes knowledge graphs to provide structured representation and rapid retrieval of data in the cybersecurity field, improving the efficiency of test range construction. Based on the initial test range scenarios and strategies, cybersecurity verification is performed, yielding verification results. When the verification results reach a preset value, the initial cybersecurity test range is used as the final cybersecurity test range. The knowledge graph-based cybersecurity test range constructed in this application more realistically reflects the actual situation of cybersecurity, improving the credibility of the test range scenarios and the effectiveness of practical exercises.

[0182] It should be noted that the system embodiments described above are based on the same inventive concept as the method embodiments described above. Therefore, the relevant content of the method embodiments described above is also applicable to the system embodiments described above, and will not be repeated here.

[0183] Figure 3 This illustration shows a schematic diagram of the hardware structure for constructing a knowledge graph-based cybersecurity training ground according to an embodiment of this application.

[0184] The device for building a knowledge graph-based cybersecurity training ground may include a processor 301 and a memory 302 storing computer program instructions.

[0185] Specifically, the processor 301 may include a central processing unit (CPU), an application-specific integrated circuit (ASIC), or one or more integrated circuits that can be configured to implement the embodiments of this application.

[0186] Memory 302 may include mass storage for data or instructions. For example, and not limitingly, memory 302 may include a hard disk drive (HDD), floppy disk drive, flash memory, optical disk, magneto-optical disk, magnetic tape, or Universal Serial Bus (USB) drive, or a combination of two or more of these. Where appropriate, memory 302 may include removable or non-removable (or fixed) media. Where appropriate, memory 302 may be internal or external to the integrated gateway disaster recovery device. In a particular embodiment, memory 302 is non-volatile solid-state memory.

[0187] In some embodiments, memory 302 may include read-only memory (ROM), random access memory (RAM), disk storage media device, optical storage media device, flash memory device, electrical, optical, or other physical / tangible memory storage device. Thus, generally, memory includes one or more tangible (non-transitory) computer-readable storage media (e.g., memory devices) encoded with software including computer-executable instructions, and when the software is executed (e.g., by one or more processors), it is operable to perform the operations described with reference to the method according to one aspect of this disclosure.

[0188] The processor 301 reads and executes computer program instructions stored in the memory 302 to implement any of the knowledge graph-based network security training ground construction methods in the above embodiments.

[0189] In one example, a knowledge graph-based cybersecurity training ground construction device may further include a communication interface 303 and a bus 310. For example, Figure 3 As shown, the processor 301, memory 302, and communication interface 303 are connected through bus 310 and complete communication with each other.

[0190] The communication interface 303 is mainly used to realize communication between various modules, devices, units and / or equipment in the embodiments of this application.

[0191] Bus 310 includes hardware, software, or both, that couples components of a knowledge graph-based cybersecurity training ground building device together. For example, and not limitingly, the bus may include an Accelerated Graphics Port (AGP) or other graphics bus, an Enhanced Industry Standard Architecture (EISA) bus, a Front Side Bus (FSB), HyperTransport (HT) interconnect, an Industry Standard Architecture (ISA) bus, an Infinite Bandwidth Interconnect, a Low Pin Count (LPC) bus, a memory bus, a Microchannel Architecture (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (PCI-X) bus, a Serial Advanced Technology Attachment (SATA) bus, a Video Electronics Standards Association Local (VLB) bus, or other suitable buses, or combinations of two or more of these. Where appropriate, bus 310 may include one or more buses. While specific buses are described and illustrated in embodiments of this application, any suitable bus or interconnect is contemplated herein.

[0192] This knowledge graph-based cybersecurity training ground construction device can execute the knowledge graph-based cybersecurity training ground construction method in this application embodiment based on a 3D design model, thereby achieving a combination of... Figure 1 and Figure 2 This paper describes a method and system for constructing a cybersecurity training ground based on knowledge graphs.

[0193] Furthermore, in conjunction with the knowledge graph-based cybersecurity training ground construction method in the above embodiments, this application embodiment can provide a computer storage medium for implementation. This computer storage medium stores computer program instructions; when these computer program instructions are executed by a processor, they implement any of the knowledge graph-based cybersecurity training ground construction methods in the above embodiments.

[0194] It should be clarified that this application is not limited to the specific configurations and processes described above and shown in the figures. For the sake of brevity, detailed descriptions of known methods are omitted here. In the above embodiments, several specific steps are described and shown as examples. However, the method process of this application is not limited to the specific steps described and shown. Those skilled in the art can make various changes, modifications, and additions, or change the order of steps, after understanding the spirit of this application.

[0195] The functional blocks shown in the above block diagram can be implemented as hardware, software, firmware, or a combination thereof. When implemented in hardware, they can be, for example, electronic circuits, application-specific integrated circuits (ASICs), appropriate firmware, plug-ins, function cards, etc. When implemented in software, the elements of this application are programs or code segments used to perform the required tasks. Programs or code segments can be stored on a machine-readable medium or transmitted over a transmission medium or communication link via data signals carried on a carrier wave. "Machine-readable medium" can include any medium capable of storing or transmitting information. Examples of machine-readable media include electronic circuits, semiconductor memory devices, ROM, flash memory, erasable ROM (EROM), floppy disks, CD-ROMs, optical disks, hard disks, fiber optic media, radio frequency (RF) links, etc. Code segments can be downloaded via computer networks such as the Internet, intranets, etc.

[0196] It should also be noted that the exemplary embodiments mentioned in this application describe methods or systems based on a series of steps or apparatus. However, this application is not limited to the order of the above steps; that is, the steps can be performed in the order mentioned in the embodiments, or in a different order, or several steps can be performed simultaneously.

[0197] The aspects of this disclosure have been described above with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this disclosure. It should be understood that each block in the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce a machine such that these instructions, executable via the processor of the computer or other programmable data processing apparatus, enable the implementation of the functions / actions specified in one or more blocks of the flowchart illustrations and / or block diagrams. Such a processor can be, but is not limited to, a general-purpose processor, a special-purpose processor, a special application processor, or a field-programmable logic circuit. It is also understood that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can also be implemented by special-purpose hardware performing the specified functions or actions, or can be implemented by a combination of special-purpose hardware and computer instructions.

[0198] The above description is merely a specific implementation of this application. Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, modules, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here. It should be understood that the protection scope of this application is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in this application, and these modifications or substitutions should all be covered within the protection scope of this application.

Claims

1. A method for constructing a cybersecurity training ground based on knowledge graphs, characterized in that, The method for constructing a knowledge graph-based cybersecurity training ground includes: Obtain the construction requirements and preparation data for the cybersecurity test range, wherein the preparation data includes the source of the preparation data and the completeness of the preparation data; Based on the aforementioned target range preparation data, a target range knowledge graph is constructed, which includes network entities and network entity relationships. The relationship weight is calculated based on the source of the target range preparation data, the completeness of the target range preparation data, and the network entity relationships, specifically as follows: Obtain the results of the online entity relationship review; Based on the target range preparation data source and the preset data source scoring criteria, the first weight is calculated; The second weight is calculated based on the source of the target range preparation data, the completeness of the target range preparation data, the preset completeness coefficient, and the preset data source scoring criteria. The third weight is calculated based on the target range preparation data and the second weight, specifically as follows: The target range preparation data is input into the trained natural language processing model to obtain the network entity relationship confidence. The third weight is calculated based on the second weight and the confidence level of the relationship between the network entities; Based on the network entity relationship review results and the preset correction coefficient, the fourth weight is obtained; Based on the first weight, the third weight, and the fourth weight, the relationship weight is calculated using the following formula: ; in, For relation weights, As the first weight, As the third weight, As the fourth weight, The first preset coefficient, This is the second preset coefficient. This is the third preset coefficient; An initial network test range is constructed based on the construction requirements, the network entities, and the relationship weights, wherein the initial network test range includes an initial network test range scenario and an initial network test range strategy; Based on the initial network test scenario and the initial network test strategy, network security verification is performed to obtain verification results; When the verification result reaches a preset value, the initial network test range will be used as the final network security test range.

2. The method for constructing a cybersecurity training ground based on knowledge graphs according to claim 1, characterized in that, Based on the target range preparation data, a target range knowledge graph is constructed. This target range knowledge graph includes network entities and their relationships, including: The target range preparation data is fused to obtain fused target range preparation data; Based on the fused target range preparation data, the network entities, network entity attributes, and network entity relationships of the target range knowledge graph are obtained through natural language processing methods. The network entities include, but are not limited to, at least one of network assets, vulnerabilities, attack techniques, and defense measures. The network entity attributes are feature descriptions of the network entities, and the network entity relationships are descriptions of the interactions between entities.

3. The method for constructing a network security training ground based on knowledge graphs according to claim 1, characterized in that, The initial network test range is constructed based on the construction requirements, the network entities, and the relationship weights. The initial network test range includes an initial network test range scenario and an initial network test range strategy, including: Based on the construction requirements, the network entities, and the relationship weights, a query is performed in the target range knowledge graph to obtain the initial network target range scenario, scenario configuration parameters, and initial network target range strategy.

4. The method for constructing a cybersecurity training ground based on knowledge graphs according to claim 1, characterized in that, The knowledge graph-based cybersecurity training ground construction method also includes: If the verification result does not reach the preset value, the target knowledge graph is iteratively optimized based on the verification result to obtain the final cybersecurity target.

5. A knowledge graph-based cybersecurity training ground construction system, characterized in that, The knowledge graph-based cybersecurity training ground construction system includes: The data acquisition module is used to acquire the construction requirements and preparatory data for the cybersecurity test range, wherein the preparatory data includes the source of the preparatory data and the completeness of the preparatory data. The target range knowledge graph construction module is used to construct a target range knowledge graph based on the target range preparation data. The target range knowledge graph includes network entities and network entity relationships. The relationship weight calculation module is used to calculate relationship weights based on the source of the target range preparation data, the completeness of the target range preparation data, and the network entity relationships, specifically as follows: Obtain the results of the online entity relationship review; Based on the target range preparation data source and the preset data source scoring criteria, the first weight is calculated; The second weight is calculated based on the source of the target range preparation data, the completeness of the target range preparation data, the preset completeness coefficient, and the preset data source scoring criteria. The third weight is calculated based on the target range preparation data and the second weight, specifically as follows: The target range preparation data is input into the trained natural language processing model to obtain the network entity relationship confidence. The third weight is calculated based on the second weight and the confidence level of the relationship between the network entities; Based on the network entity relationship review results and the preset correction coefficient, the fourth weight is obtained; Based on the first weight, the third weight, and the fourth weight, the relationship weight is calculated using the following formula: ; in, For relation weights, As the first weight, As the third weight, As the fourth weight, The first preset coefficient, This is the second preset coefficient. This is the third preset coefficient; An initial network target range construction module is used to construct an initial network target range based on the construction requirements, the network entities, and the relationship weights, wherein the initial network target range includes an initial network target range scenario and an initial network target range strategy; The verification module is used to perform network security verification based on the initial network range scenario and the initial network range strategy, and obtain the verification result. The final network security target acquisition module is used to use the initial network target as the final network security target when the verification result reaches a preset value.

6. A knowledge graph-based network security training ground construction device, characterized in that, It includes at least one control processor and a memory for communicatively connecting to the at least one control processor; the memory stores instructions executable by the at least one control processor, which, when executed by the at least one control processor, enable the at least one control processor to perform a knowledge graph-based cybersecurity training ground construction method as described in any one of claims 1 to 4.

7. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer-executable instructions for causing a computer to execute a knowledge graph-based network security training ground construction method as described in any one of claims 1 to 4.

Citation Information

Patent Citations

  • Visual modeling method and device for attack surface based on knowledge graph

    CN116340414A

  • Ray-based lightweight distributed reinforcement learning training platform design method

    CN119151019A