Threat testing method and device for network security equipment and network security equipment
Through the automated testing integration architecture of cloud threat intelligence center and local custom threat intelligence configuration, the problem of insufficient detection accuracy of traditional network security devices is solved, and efficient detection and response to new types of cyber attacks is achieved.
Patent Information
- Application Number
- CN202510689415.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-27
- Publication Date
- 2025-08-29
AI Technical Summary
Traditional network security devices are difficult to effectively detect new types of cyberattacks, resulting in insufficient detection accuracy and inability to deal with complex cyber threats such as advanced continuous attacks (APTs).
Introduce cloud threat intelligence center and local custom threat intelligence configurations, integrate architecture through automated testing, and use end-system intelligence library files and custom threat intelligence rules to conduct threat testing of network security devices, and build adaptive application traffic for detection.
It realizes efficient automated threat detection of network security equipment, can keep up with the latest network attacks in a timely manner, improves detection accuracy and response speed, and ensures network security.
Smart Images

Figure CN120567477A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network security, and in particular to a threat testing method and apparatus for network security equipment, as well as network security equipment. Background Art
[0002] On the one hand, the increasing complexity and diversity of cyberattacks are constantly challenging traditional network security devices. On the other hand, a new generation of cyber attackers often launch targeted cyberattacks against businesses and organizations, also known as Advanced Persistent Threat (APT). Attackers are constantly adapting existing attack methods and developing new ones.
[0003] In the above context, it is difficult to prevent network attacks by relying solely on firewalls, intrusion prevention systems and anti-virus software. More specifically, such network attacks cannot be detected through malicious program signatures or past attack technology reports, resulting in an imbalance between offense and defense.
[0004] That is to say, for network security devices in the network architecture, traditional network attack detection solutions have certain limitations in detection accuracy because the detection logic behind them is difficult to keep up with the latest network attack situations. Summary of the Invention
[0005] This application provides a threat testing method, apparatus, and network security device for network security equipment, which are used for threat testing of network security equipment. While avoiding the original reliance on manual operations, it creates a set of efficient and large-scale testable automated testing integration architecture, and introduces a cloud-based threat intelligence center and local customized threat intelligence configuration operations. This helps to enable the threat detection logic to keep up with the latest network attacks, provide good support for the update and maintenance of network security equipment, and thus ensure the network security of the network.
[0006] In a first aspect, the present application provides a threat testing method for a network security device, the method comprising:
[0007] The network security device obtains the end system intelligence library file updated by the threat intelligence platform from the intelligence library, wherein the end system intelligence library file configured in the local intelligence library is specifically a file describing the characteristics of the corresponding threat intelligence;
[0008] The network security device constructs a first application flow adapted to the network security device and corresponding to the end system intelligence library file, and injects the first application flow into an end detection system configured in the network security device to perform a first threat test on the end detection system, wherein the end detection system is a processing system used by the network security device to detect whether the injected flow has a threatening nature;
[0009] The network security device obtains local custom threat intelligence rules, where the custom threat intelligence rules are specifically threat intelligence rules that bypass the threat intelligence platform and are configured in custom mode.
[0010] The network security device constructs a second application flow adapted to the network security device and corresponding to the customized threat intelligence rule, and injects the second application flow into the end detection system to perform a second threat test on the end detection system;
[0011] The network security device obtains test results of different threat tests, and generates corresponding test reports based on the test results of different threat tests for output.
[0012] In a second aspect, the present application provides a threat testing device for a network security device, the device comprising:
[0013] The first acquisition unit is configured to acquire an end system intelligence library file updated by the threat intelligence platform from the intelligence library, wherein the end system intelligence library file configured in the local intelligence library is specifically a file describing the characteristics of the corresponding threat intelligence;
[0014] A first testing unit is configured to construct a first application flow adapted to the network security device and corresponding to the end system intelligence library file, and inject the first application flow into an end detection system configured in the network security device to perform a first threat test on the end detection system, wherein the end detection system is a processing system used by the network security device to detect whether the injected flow has a threatening nature;
[0015] A second acquisition unit is configured to acquire a local custom threat intelligence rule, wherein the custom threat intelligence rule is a threat intelligence rule that bypasses the threat intelligence platform and is configured in a custom mode;
[0016] The second test unit is used to construct a second application traffic adapted to the network security device and corresponding to the customized threat intelligence rule, and inject it into the end detection system to perform a second threat test on the end detection system;
[0017] The generating unit is used to obtain the test results of different threat tests and generate corresponding test reports based on the test results of different threat tests for output.
[0018] In a third aspect, the present application provides a network security device comprising a processor and a memory, wherein a computer program is stored in the memory, and when the processor calls the computer program in the memory, the method provided in the first aspect of the present application or any possible implementation of the first aspect of the present application is executed.
[0019] In a fourth aspect, the present application provides a computer-readable storage medium, which stores multiple instructions, and the instructions are suitable for a processor to load to execute the method provided in the first aspect of the present application or any possible implementation of the first aspect of the present application.
[0020] From the above content, it can be concluded that this application has the following beneficial effects:
[0021] For the threat testing of network security equipment, we have created an efficient and scalable automated testing integration architecture without relying on manual operations. We have also introduced a cloud-based threat intelligence center and local customized threat intelligence configuration operations. This helps enable the threat detection logic to keep up with the latest network attacks, provides good support for the update and maintenance of network security equipment, and thus ensures the network security of the network. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For those skilled in the art, other drawings can be obtained based on these drawings without creative work.
[0023] Figure 1 A flowchart of a threat testing method for network security equipment in this application;
[0024] Figure 2 This is a schematic diagram of an example of the test results obtained in this application;
[0025] Figure 3 This is another example schematic diagram of the test results obtained in this application;
[0026] Figure 4 A schematic diagram of a structure of a threat testing device for network security equipment of this application;
[0027] Figure 5 This is a structural diagram of the network security device of this application. DETAILED DESCRIPTION
[0028] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without making creative efforts are within the scope of protection of this application.
[0029] The terms "first", "second", etc. in the specification and claims of this application and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable where appropriate so that the embodiments described herein can be implemented in a sequence other than that illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or modules is not necessarily limited to those steps or modules clearly listed, but may include other steps or modules that are not clearly listed or that are inherent to these processes, methods, products or devices. The naming or numbering of steps in this application does not mean that the steps in the method flow must be executed in the time / logical sequence indicated by the naming or numbering. The process steps that have been named or numbered can be changed in the execution order according to the technical purpose to be achieved, as long as the same or similar technical effects can be achieved.
[0030] The division of modules in this application is a logical division. In actual application, there may be other division methods. For example, multiple modules can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, and the indirect coupling or communication connection between modules can be electrical or other similar forms, which are not limited in this application. Moreover, the modules or submodules described as separate components may or may not be physically separated, may or may not be physical modules, or may be distributed into multiple circuit modules. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this application.
[0031] Before introducing the threat testing method for network security devices provided by this application, the background content involved in this application is first introduced.
[0032] The threat testing method, device and computer-readable storage medium for network security equipment provided in this application can be applied to network security equipment for threat testing of network security equipment. While avoiding the original reliance on manual operations, a set of efficient and large-scale testable automated testing integration architecture is created, and a cloud-based threat intelligence center and locally customized threat intelligence configuration operations are introduced. This is conducive to enabling the threat detection logic to keep up with the latest network attacks, providing good support for the update and maintenance of network security equipment, and thus ensuring the network security of the network.
[0033] The threat testing method for network security equipment mentioned in this application can be executed by a threat testing device for the network security equipment, or a network security equipment that integrates the threat testing device of the network security equipment. The network security equipment can also be set up in the form of a device cluster.
[0034] It can be understood that the solution of the present application is aimed at network security devices in the network architecture. Therefore, the device that executes the threat testing method of the network security device of the present application or is equipped with the application service corresponding to the threat testing method of the network security device of the present application is usually the local network security device itself. Of course, it is not ruled out that the network security device uses an agent method (such as manual remote control method) to allow other devices to execute the solution processing as the network security device itself.
[0035] In actual applications, network security devices can specifically be specific device nodes such as firewalls, intrusion detection systems, intrusion prevention systems or security gateways in the network architecture. In addition, network security devices can be dedicated nodes specifically responsible for network security services such as firewalls, intrusion detection systems, intrusion prevention systems or security gateways, or they can be nodes that provide additional network security services such as firewalls, intrusion detection systems, intrusion prevention systems or security gateways on the basis of the original functional services. The latter is also possible in some cases.
[0036] Among them, for the threat testing work involved in the normal security of network security equipment, it is understandable that the application traffic flowing through specific nodes or local nodes can be mirrored. While releasing it, threat testing can be carried out on the mirrored traffic and appropriate response operations can be performed in a timely manner.
[0037] Next, we will introduce the threat testing method for network security devices provided by this application.
[0038] First, see Figure 1 , Figure 1 A schematic diagram of a flow chart of a threat testing method for a network security device of the present application is shown. The threat testing method for a network security device provided by the present application may specifically include the following steps S101 to S105:
[0039] Step S101: The network security device obtains an end system intelligence library file updated by the threat intelligence platform from the intelligence library. The end system intelligence library file configured in the local intelligence library is specifically a file describing the characteristics of the corresponding threat intelligence.
[0040] It can be understood that this application involves the application of a threat intelligence platform, which provides centralized and unified threat intelligence update management services for different network security devices on the cloud side.
[0041] Specifically, for the threat intelligence project of the threat intelligence platform, the goal is to eliminate the imbalance between offense and defense in advanced persistent attacks as much as possible. There are many types of threat intelligence data indicators, and this project only includes IP reputation, domain name reputation, file reputation, the latest attack events, attack trends and preventive measures. It is used to improve the effectiveness and active defense capabilities of next-generation firewalls, intrusion prevention systems, security gateways and other network security technologies, implement threat detection and intelligence processing capabilities, and reduce the mean time to detect (MTTD) and the mean time to resolution (MTTR).
[0042] A Threat Intelligence Platform (TIP) is a security solution that integrates multi-source threat data and provides analysis, sharing, and collaboration capabilities. Its core features include:
[0043] 1) Multi-source intelligence aggregation and processing
[0044] Integrate multi-source data (including open source, commercial, and self-developed intelligence) such as Indicators of Compromise (IOC), IP reputation, domain names, vulnerabilities, and advanced persistent attack intelligence, support standardized formats (such as Structured Threat Information Expression (STIX)), and achieve cross-platform sharing and linkage.
[0045] 2) Intelligent analysis and correlation
[0046] Based on machine learning and threat modeling (such as Adversarial Tactics Techniques and Common Knowledge (ATT&CK)), threat classification, tracing, and attack chain analysis are performed to provide a three-dimensional portrait of IP / domain names (depth, breadth, and activity), with a noise reduction rate of up to 80% (such as the Next Generation Threat Intelligence Platform (NGTIP product)), and to correlate vulnerability intelligence to form a closed-loop vulnerability operation (acquisition, assessment, disposal, and verification).
[0047] 3) Threat response and linkage
[0048] It connects to Security Operations Center / Security Information and Event Management (SOC / SIEM), Endpoint Detection and Response (EDR) and other devices, implements real-time detection and blocking through the Application Programming Interface (API), and supports cloud-local collaboration.
[0049] 4) Scenario-based applications
[0050] Email detection: Integrate engines (such as OWL / RAS) to detect phishing emails and APT attacks.
[0051] Vulnerability management: Provide vulnerability patches, mitigation measures and network-wide scanning verification (NGTIP).
[0052] Situational awareness: Visualize global threat distribution and industry attack trends.
[0053] When a threat intelligence platform is involved, the network security device can be configured with an intelligence library to store the end system intelligence library files updated by the threat intelligence platform. The end system intelligence library files are specifically files that describe the corresponding threat intelligence characteristics and can also be understood using threat intelligence rules.
[0054] Correspondingly, as an exemplary embodiment, the method of the present application further includes:
[0055] Network security devices periodically connect with the threat intelligence platform to update the end system intelligence library files;
[0056] Alternatively, the network security device updates the end system intelligence library file under the active triggering of the threat intelligence platform.
[0057] It is understandable that for the update of the end system intelligence library files, the network security device can be updated regularly or actively triggered by the threat intelligence platform.
[0058] Of course, in some cases, the network security device may proactively contact the threat intelligence platform to try to obtain the latest system intelligence library files from the threat intelligence platform, but in actual situations it is generally done manually.
[0059] In step S102, the network security device constructs a first application flow adapted to the network security device and corresponding to the end system intelligence library file, and injects the first application flow into an end detection system configured in the network security device to perform a first threat test on the end detection system. The end detection system is a processing system used by the network security device to detect whether the injected flow is threatening in nature.
[0060] In the previous step, the end system intelligence library file stored in the intelligence library was extracted locally (that is, the threat intelligence rules updated by the threat intelligence platform). Therefore, the end system intelligence library file can be used as a benchmark to construct application traffic that is adapted to the application scenarios involved in the local network security device. The application traffic can also be understood by restoring the application traffic that the local network security device will face in the actual working process. For the sake of convenience, this application will use "first", "second" and even "third" to make a more convenient distinction between the application traffic involved in different stages.
[0061] In addition, it can be understood that on the network security device side, corresponding to the solution of the present application, an end detection system is pre-configured, which is used to detect whether the injected application traffic has a threatening nature and whether it is threatening / malicious traffic.
[0062] The processing of this link can be referred to as threat testing or test processing, and similar to the naming of application traffic above, prefixes are also used to distinguish them.
[0063] For the threat detection operation within the end detection system, it involves the corresponding rule feature matching operation to determine whether there is a threat feature targeted by the corresponding threat intelligence rule.
[0064] As an example, after collecting traffic, the end detection system can decode it through Deep Packet Inspection (DPI), and then perform specific rule feature matching through methods such as Hyperscan. When one of the rules is matched, a threat is identified.
[0065] Step S103: The network security device obtains a local custom threat intelligence rule, wherein the custom threat intelligence rule is a threat intelligence rule that bypasses the threat intelligence platform and is configured in a custom mode.
[0066] It can be understood that in addition to the end system intelligence library files corresponding to the overall level and common to multiple network security devices, this application also involves threat intelligence rules that are highly adapted to the local area, that is, locally customized, namely customized threat intelligence rules.
[0067] The customized threat intelligence rules are usually manually configured by the staff responsible for updating and maintaining the local network security equipment according to the working status of the local network security equipment and the work conditions it faces. Therefore, the adapted and latest threat intelligence rules can be directly configured for the local network security equipment without waiting for the update of the cloud-based threat intelligence platform. At the same time, it is also understandable that the customized threat intelligence rules of the local network security equipment may not necessarily be applicable to other network security equipment. Therefore, even if the threat intelligence platform notices or considers the customized threat intelligence rules configured by the local network security equipment, it may not necessarily synchronize the updates of the rules between the network security devices.
[0068] Of course, in addition to manual operation, it is also possible that in some cases, local network security devices may autonomously generate customized threat intelligence rules under preset autonomous generation strategies.
[0069] At the detail level, as an exemplary embodiment, the front-end system intelligence library file and the rule content of the customized threat intelligence rules here can be configured specifically with IOC information including malicious IP, domain name, email, URL, vulnerability characteristics and MD5 value.
[0070] It is understandable that specific threat intelligence rules can be configured from many dimensions to be more specific and correspond to different directions to achieve comprehensive threat testing results.
[0071] The MD5 value is a unique value encrypted by the MD5 hash algorithm. In specific operations, unique values encrypted by other types of hash algorithms may also be involved, such as the SHA series, HMAC, bcrypt, and other algorithms.
[0072] Step S104: The network security device constructs a second application flow adapted to the network security device and corresponding to the customized threat intelligence rule, and injects the second application flow into the end detection system to perform a second threat test on the end detection system.
[0073] Similar to the first application traffic mentioned above, after obtaining the customized threat intelligence rules, the corresponding second application traffic can be constructed and injected into the pre-configured end detection system of the network security device to perform a second threat test.
[0074] Furthermore, as an exemplary embodiment, in the application traffic construction process based on the corresponding threat intelligence rules, the network security device may specifically include the following processing contents:
[0075] 1. If the traffic to be generated is the traffic of IP type IOC rule, then at least one of ordinary Transmission Control Protocol (TCP) traffic and ordinary User Datagram Protocol (UDP) traffic is specifically constructed;
[0076] 2. If the traffic to be generated is the domain name IOC rule, then the Domain Name System (DNS) request packet and DNS response packet are constructed;
[0077] 3. If the current traffic to be generated is the mailbox IOC rule traffic, then specifically construct at least one of the Simple Mail Transfer Protocol (SMTP) mail sending and receiving traffic, the Post Office Protocol Version 3 (POP3) mail sending and receiving traffic, and the Internet Message Access Protocol (IMAP) mail sending and receiving traffic.
[0078] As you can understand, this article provides a very specific implementation plan for how to build the corresponding application traffic.
[0079] In step S105 , the network security device obtains test results of different threat tests, and generates corresponding test reports based on the test results of the different threat tests for output.
[0080] It can be understood that after obtaining the threat tests in the previous two aspects, the specific response results or test results of the network security equipment during the test process can be collected. At this time, these test results can continue to be processed into a test report for the threat test of the network security equipment in accordance with the result output requirements, and then output.
[0081] As an example of test results, you can refer to Figure 2 and Figure 3 An example schematic diagram of the test results obtained in this application is shown.
[0082] In addition, it should be understood that the test report does not necessarily only involve the results of threat testing, that is, the processing of application traffic. It can also involve the corresponding system status as a reference, such as CPU utilization and memory utilization. In this regard, the test results can also involve the content of the corresponding system status parameters.
[0083] Furthermore, in terms of a specific acquisition method, as an exemplary embodiment, the network security device may obtain the test results of different threat tests, which may specifically include:
[0084] The network security device extracts the test results of different threat tests through the API interface preset by the end detection system.
[0085] It is understandable that compared to extracting the test results of threat testing from the end detection system from the outside through the corresponding data capture tools or monitoring tools from the background, directly using the preset API interface of the end detection system itself, the end detection system will independently generate the test results in the corresponding format for extraction, which will have better processing efficiency and simplicity.
[0086] Specifically, in actual applications, the threat testing and processing for network security devices is usually initiated in the form of a task. To this end, the acquisition and processing of threat testing tasks directed to local network security devices can also be involved. Specifically, it can be manual entry, or it can be initiated autonomously by the network security device itself under a preset autonomous initiation strategy, or it can be a task forwarded from other devices. These are all possible.
[0087] At the same time, the report format of the test report is relatively flexible and can be flexibly adjusted according to subsequent application requirements. For example, if it directly involves presentation to staff, it can be in common document formats such as doc, docx, pdf, ppt, pptx, etc. For example, if it involves background software or code-level applications, it can involve formats such as html, and even custom formats. These are all possible.
[0088] The output of the test report is also highly flexible. For example, it can involve local storage, remote storage, result push (such as emailing to the person in charge), result display, output of prompts for completed tests, etc. Similar to many of the above links, it can be adaptively adjusted with pre-configuration and real-time configuration.
[0089] In addition, in addition to the application traffic configured by the two rules mentioned above, namely the end system intelligence library file updated by the threat intelligence platform and the local custom threat intelligence rules, this application can also continue to construct another aspect of application traffic to promote better threat testing effects on local network security devices.
[0090] Specifically, as an exemplary embodiment, after performing the second threat test of the terminal detection system, the method of the present application may further include:
[0091] The network security device constructs a whitelist of application traffic that does not match the end system intelligence library file and custom threat intelligence rules, and injects it into the end detection system to perform a third threat test on the end detection system.
[0092] It is easy to see that in the settings here, this application is based on whitelist considerations, and constructs application traffic that does not match the two threat intelligence rules of the previous end system intelligence library file and custom threat intelligence rules at the rule level. This traffic does not mean that the end detection system will not identify it as a threat or that there is no threat form when performing corresponding threat detection by loading the end system intelligence library file and custom threat intelligence rules. In actual situations, there is the possibility of false alarms or detection anomalies, which can also reflect the threat detection performance of local network security devices in new aspects.
[0093] In this way, similar to the processing of the first and second application traffic above, a whitelist application traffic is constructed and a third threat test is performed, and corresponding test results can be obtained for use in generating a test report.
[0094] In actual operations, the specific construction and processing of application traffic can also be implemented by corresponding traffic processing tools. During the processing process, existing or self-developed traffic processing tools need to input corresponding traffic construction rules, such as the traffic characteristics of threat intelligence rules, the amount of traffic required to be generated, etc.
[0095] As an example, the Scapy tool can be used. Scapy is an interactive packet processing tool based on Python that allows users to construct, send, capture and analyze network packets, supporting a complete protocol stack from low-level protocols (such as Ethernet frames) to high-level protocols (such as HTTP).
[0096] In addition, it is easy to see that the application traffic construction processing mentioned above is mainly explained from the perspective of a single traffic. At the macro level or the overall level, it is mainly constrained by the number of traffic required to be constructed. Corresponding to deeper threat testing, this application can also make more adaptive constraints or controls.
[0097] Specifically, in the overall application traffic construction process, the concept of user traffic development trend can also be introduced. For example, the traffic surge time period, the main traffic initiating user area, the main traffic forwarding node, the main traffic type, the main traffic access target, etc. can be used to achieve a more delicate application traffic configuration effect. It is helpful to combine the basic application traffic content with the higher-level development trend structure to make a new dimension of threat testing effect, and better test the threat response performance of network security equipment.
[0098] Among them, this application can further involve the simulation setting of virtual hacker attacks, by simulating the application traffic that hackers of different attack types / styles will initiate under specific attack targets (not specific attack objects), to further enhance the more targeted threat testing effect.
[0099] It is understandable that this application believes that for some hacker teams, if they launch a cyber attack, they may have a specific type / style. On the one hand, this may be affected by different regions, and on the other hand, it may be influenced by the team itself or the leader behind the team. Therefore, by further considering the style influence of human factors, we can imagine and simulate cyber attacks that may occur in actual situations, and thus complete better threat testing.
[0100] Similarly, when configuring the custom threat intelligence rules mentioned above, you can also involve the simulation settings of the virtual hacker attack here, especially the in-depth style configuration, to achieve better threat intelligence rule configuration effects, which can provide more delicate rule supplements in subtle aspects for network security devices.
[0101] At the same time, corresponding to the previous rounds of threat testing, it is understandable that based on the reuse and backtracking requirements of work, the preservation and processing of application traffic may also be involved.
[0102] In this regard, as an exemplary embodiment, the method of the present application may further include:
[0103] Network security devices save the corresponding application traffic of different threat tests for secondary reuse and retrospective evidence storage.
[0104] Among them, the storage process is usually saved locally. Of course, it is not ruled out that in some cases it may be saved in a different place, such as the cloud or other devices.
[0105] It can also be seen that for the construction and processing of application traffic, this application does not mean that all construction and processing are real-time. It may also use pre-constructed historical application traffic. This is also possible in some cases, especially for some special or complicated application traffic.
[0106] Corresponding to the settings here, it can be understood that the solution of the present application can further continue to involve the application traffic of all threat tests in all saved tasks, all threat tests in individual (one or more) tasks, threat tests at specific stages in all tasks, or threat tests at specific stages in individual tasks, and perform corresponding backtracking processing according to specific application requirements.
[0107] The above is an introduction to the threat testing method for network security equipment provided in this application. In order to facilitate better implementation of the threat testing method for network security equipment provided in this application, this application also provides a threat testing device for network security equipment from the perspective of functional modules.
[0108] See Figure 4 , Figure 4 This is a schematic diagram of a structure of a threat testing device for a network security device of the present application. In the present application, the threat testing device 400 for a network security device may specifically include the following structure:
[0109] The first acquisition unit 401 is configured to acquire an end system intelligence library file updated by the threat intelligence platform from the intelligence library, wherein the end system intelligence library file configured in the local intelligence library is specifically a file describing the characteristics of the corresponding threat intelligence;
[0110] A first testing unit 402 is configured to construct a first application flow adapted to the network security device and corresponding to the end system intelligence library file, and inject the first application flow into an end detection system configured in the network security device to perform a first threat test on the end detection system, wherein the end detection system is a processing system of the network security device used to detect whether the injected flow has a threatening nature;
[0111] A second acquisition unit 403 is configured to acquire a local custom threat intelligence rule, wherein the custom threat intelligence rule is a threat intelligence rule that bypasses the threat intelligence platform and is configured in a custom mode;
[0112] The second testing unit 404 is configured to construct a second application flow adapted to the network security device and corresponding to the customized threat intelligence rule, and inject the second application flow into the end detection system to perform a second threat test on the end detection system;
[0113] The generating unit 405 is configured to obtain test results of different threat tests, and generate corresponding test reports based on the test results of the different threat tests for output.
[0114] In an exemplary embodiment, the end system intelligence library file and the rule content of the custom threat intelligence rule are specifically configured with IOC information including malicious IP, domain name, email address, URL, vulnerability characteristics and MD5 value.
[0115] In another exemplary embodiment, the application traffic construction process includes the following processing contents:
[0116] If the traffic to be generated is the traffic of IP type IOC rule, then at least one of normal TCP traffic and normal UDP traffic is constructed;
[0117] If the traffic to be generated is the domain name IOC rule traffic, then specifically construct the DNS request packet and DNS response packet;
[0118] If the traffic to be generated currently is the traffic of the mailbox IOC rule, then at least one of the SMTP mail sending and receiving traffic, the POP3 mail sending and receiving traffic, and the IMAP mail sending and receiving traffic is specifically constructed.
[0119] In another exemplary embodiment, the generating unit 405 is specifically configured to:
[0120] Extract the test results of different threat tests through the preset API interface of the end detection system.
[0121] In another exemplary embodiment, the apparatus further includes an updating unit 406, configured to:
[0122] Update the end system intelligence library files through periodic connection with the threat intelligence platform;
[0123] Alternatively, under the active triggering of the threat intelligence platform, the end system intelligence library file is updated.
[0124] In another exemplary embodiment, the apparatus further includes a third testing unit 407, configured to, after performing the second threat test of the end detection system, perform:
[0125] Construct whitelist application traffic that does not match the end system intelligence library file and customized threat intelligence rules, and inject it into the end detection system to perform a third threat test on the end detection system.
[0126] In another exemplary embodiment, the apparatus further includes a storing unit 408, configured to:
[0127] Save the corresponding application traffic of different threat tests for secondary reuse and retrospective evidence storage.
[0128] This application also provides a network security device from the perspective of hardware structure, see Figure 5 , Figure 5 The present invention shows a schematic diagram of a network security device. Specifically, the network security device may include a processor 501, a memory 502, and an input / output device 503. The processor 501 is configured to execute a computer program stored in the memory 502. Figure 1 Each step of the threat testing method for a network security device in the corresponding embodiment; or, when the processor 501 is used to execute the computer program stored in the memory 502, the following is implemented Figure 4 The memory 502 is used to store the functions of each unit in the embodiment, and the processor 501 executes the above Figure 1 The computer program required by the threat testing method for network security devices in the corresponding embodiment.
[0129] For example, the computer program may be divided into one or more modules / units, one or more of which are stored in the memory 502 and executed by the processor 501 to complete the present application. One or more modules / units may be a series of computer program instruction segments capable of performing specific functions, and the instruction segments are used to describe the execution process of the computer program in a computer device.
[0130] The network security device may include, but is not limited to, a processor 501, a memory 502, and an input / output device 503. Those skilled in the art will appreciate that the diagram is merely an example of a network security device and does not limit the network security device. The network security device may include more or fewer components than shown, or a combination of certain components, or different components. For example, the network security device may also include a network access device, a bus, etc., and the processor 501, the memory 502, the input / output device 503, etc. are connected via the bus.
[0131] The processor 501 may be a central processing unit (CPU), or other general-purpose processors, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor. The processor is the control center of the network security device and connects various parts of the entire device using various interfaces and lines.
[0132] The memory 502 can be used to store computer programs and / or modules. The processor 501 implements various functions of the computer device by running or executing the computer programs and / or modules stored in the memory 502 and accessing the data stored in the memory 502. The memory 502 may mainly include a program storage area and a data storage area. The program storage area may store an operating system, at least one application required for a function, etc.; the data storage area may store data generated based on the use of the network security device, etc. In addition, the memory may include high-speed random access memory and non-volatile memory, such as a hard disk, internal memory, a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, at least one disk storage device, a flash memory device, or other volatile solid-state storage device.
[0133] When the processor 501 is used to execute the computer program stored in the memory 502, it can specifically implement the following functions:
[0134] Obtaining the end system intelligence library file updated by the threat intelligence platform from the intelligence library, wherein the end system intelligence library file configured in the local intelligence library is specifically a file describing the corresponding threat intelligence characteristics;
[0135] Constructing a first application flow adapted to the network security device and corresponding to the end system intelligence library file, and injecting the first application flow into an end detection system configured in the network security device to perform a first threat test on the end detection system, wherein the end detection system is a processing system used by the network security device to detect whether the injected flow has a threatening nature;
[0136] Obtain local custom threat intelligence rules, where custom threat intelligence rules are specifically threat intelligence rules that bypass the threat intelligence platform and are configured in custom mode;
[0137] Constructing a second application flow adapted to network security devices and corresponding to customized threat intelligence rules, and injecting it into the end detection system to conduct a second threat test on the end detection system;
[0138] Obtain the test results of different threat tests, and generate corresponding test reports based on the test results of different threat tests for output.
[0139] Those skilled in the art will clearly understand that for the convenience and brevity of description, the threat testing device for network security equipment, network security equipment and the specific working process of the corresponding units described above can refer to the following. Figure 1 The description of the threat testing method for the network security device in the corresponding embodiment will not be repeated here.
[0140] Those skilled in the art will appreciate that all or part of the steps in the various methods of the above embodiments may be accomplished by instructions, or by controlling related hardware through instructions. The instructions may be stored in a computer-readable storage medium and loaded and executed by a processor.
[0141] To this end, the present application provides a computer-readable storage medium, which stores a plurality of instructions, which can be loaded by a processor to execute the present application as follows: Figure 1 For the steps of the threat testing method for network security equipment in the corresponding embodiment, the specific operations can be referred to as follows: Figure 1 The description of the threat testing method for the network security device in the corresponding embodiment will not be repeated here.
[0142] The computer-readable storage medium may include a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, etc.
[0143] Due to the instructions stored in the computer readable storage medium, the present application can be executed as follows: Figure 1 The steps of the threat testing method for network security equipment in the corresponding embodiment, therefore, the present application can be implemented as follows Figure 1 The beneficial effects that can be achieved by the threat testing method for network security devices in the corresponding embodiments are detailed in the previous description and will not be repeated here.
[0144] The above is a detailed introduction to the threat testing method, device, network security device and computer-readable storage medium for the network security device provided by this application. Specific examples are used in this article to illustrate the principles and implementation methods of this application. The description of the above embodiments is only used to help understand the core idea of this application; at the same time, for technical personnel in this field, based on the ideas of this application, there will be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as a limitation on this application.
Claims
1. A threat testing method for network security equipment, characterized in that: The method comprises: The network security device obtains an end system intelligence library file updated by the threat intelligence platform from the intelligence library, wherein the end system intelligence library file configured in the local intelligence library is specifically a file describing the characteristics of the corresponding threat intelligence; The network security device constructs a first application flow adapted to the network security device and corresponding to the end system intelligence library file, and injects the first application flow into an end detection system configured in the network security device to perform a first threat test on the end detection system, wherein the end detection system is a processing system used by the network security device to detect whether the injected flow has a threatening nature; The network security device obtains a local custom threat intelligence rule, wherein the custom threat intelligence rule is a threat intelligence rule that bypasses the threat intelligence platform and is configured in a custom mode; The network security device constructs a second application flow adapted to the network security device and corresponding to the custom threat intelligence rule, and injects the second application flow into the end detection system to perform a second threat test on the end detection system; The network security device obtains test results of different threat tests, and generates corresponding test reports based on the test results of the different threat tests for output.
2. The method according to claim 1, characterized in that The end system intelligence library file and the rule content of the custom threat intelligence rule are specifically configured with IOC information including malicious IP, domain name, email address, URL, vulnerability characteristics and MD5 value.
3. The method according to claim 1, characterized in that During the application traffic construction process, the network security device includes the following processing contents: If the traffic to be generated is the traffic of IP type IOC rule, then at least one of normal TCP traffic and normal UDP traffic is constructed; If the traffic to be generated is the domain name IOC rule traffic, then specifically construct the DNS request packet and DNS response packet; If the traffic to be generated currently is the traffic of the mailbox IOC rule, then at least one of the SMTP mail sending and receiving traffic, the POP3 mail sending and receiving traffic, and the IMAP mail sending and receiving traffic is specifically constructed.
4. The method according to claim 1, wherein The network security device obtains test results of different threat tests, including: The network security device extracts the test results of the different threat tests through the API interface preset by the end detection system.
5. The method according to claim 1, wherein The method further comprises: The network security device updates the end system intelligence library file by periodically connecting with the threat intelligence platform; Alternatively, the network security device updates the end system intelligence library file under the active triggering of the threat intelligence platform.
6. The method according to claim 1, characterized in that After performing the second threat test of the end detection system, the method further includes: The network security device constructs a whitelist application traffic that does not match the end system intelligence library file and the custom threat intelligence rule, and injects it into the end detection system to perform a third threat test on the end detection system.
7. The method according to claim 1, characterized in that The method further comprises: The network security device stores the corresponding application traffic of the different threat tests for secondary reuse and retrospective evidence storage.
8. A threat testing device for network security equipment, characterized in that: The device comprises: A first acquisition unit is configured to acquire an end system intelligence library file updated by the threat intelligence platform from the intelligence library, wherein the end system intelligence library file configured in the local intelligence library is specifically a file describing the characteristics of the corresponding threat intelligence; a first testing unit, configured to construct a first application flow adapted to the network security device and corresponding to the end system intelligence library file, and inject the first application flow into an end detection system configured in the network security device to perform a first threat test on the end detection system, wherein the end detection system is a processing system of the network security device used to detect whether the injected flow has a threatening nature; A second acquisition unit is configured to acquire a local custom threat intelligence rule, wherein the custom threat intelligence rule is a threat intelligence rule that bypasses the threat intelligence platform and is configured in a custom mode; A second testing unit is configured to construct a second application traffic adapted to the network security device and corresponding to the custom threat intelligence rule, and inject the second application traffic into the end detection system to perform a second threat test on the end detection system; The generating unit is used to obtain the test results of different threat tests, and generate corresponding test reports based on the test results of the different threat tests for output.
9. A network security device, characterized in that: The method comprises a processor and a memory, wherein a computer program is stored in the memory, and when the processor calls the computer program in the memory, the method according to any one of claims 1 to 7 is executed.
10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a plurality of instructions, and the instructions are suitable for being loaded by a processor to execute the method according to any one of claims 1 to 7.