Graph storage method, device and equipment based on network target range and readable storage medium
By configuring different weights in the network topology map and storing them in order of the total weight, and adopting a chain storage method, the problems of low network topology storage efficiency and poor editing flexibility are solved, and efficient and flexible topology map management is achieved.
Patent Information
- Application Number
- CN202510864588.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-25
- Publication Date
- 2025-09-23
- Estimated Expiration
- 2045-06-25
AI Technical Summary
Existing technologies have low efficiency and poor editing flexibility when storing network topology, making it difficult to meet the rapid iteration requirements in dynamic network environments.
By obtaining the network topology, traversing and reading the attack path, configuring different weights, sorting and storing them according to the total weight, using chain storage, prioritizing the storage of high-frequency access paths, and locally adjusting and editing.
It improves the storage efficiency and editing flexibility of network topology diagrams, can quickly respond to the needs of high-frequency access paths, and adapt to the rapid iteration of dynamic network environments.
Smart Images

Figure CN120692169A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of graph data processing, and in particular to a graph storage method, apparatus, device and readable storage medium based on a network target range. Background Art
[0002] The cyber range is a highly simulated virtualized network environment that can dynamically construct complex network scenarios to provide a controllable experimental platform for network security research, equipment testing, and personnel training, helping researchers to deeply understand network behavior, discover potential security vulnerabilities, and develop effective defense strategies.
[0003] Network topology is the core part of the network target range. It intuitively reflects the connection relationship and data flow between various nodes in the network (such as servers, routers, switches, terminal devices, etc.). Therefore, it is necessary to construct an accurate and reasonable network topology to ensure that the network target range can truly simulate the expected network environment and behavior, thereby providing a reliable foundation for subsequent network attack and defense experiments, performance testing, etc.
[0004] In related technologies, when storing network topology, manual storage is often relied upon. Specifically, operators need to manually label each node according to business needs, and then drag the nodes one by one through the graphical interface, draw directed edges, etc., resulting in low storage efficiency; on the other hand, when this storage method needs to be adjusted or edited later, it is often necessary to perform a global traversal of the entire topology structure to locate and modify the relevant nodes or edges, resulting in poor overall editing flexibility and difficulty in meeting the rapid iteration requirements in a dynamic network environment. Summary of the Invention
[0005] This application proposes a network range-based graph storage method, device, equipment and readable storage medium, which can improve the storage efficiency and editing flexibility of network topology graphs.
[0006] To achieve the above objectives, a first aspect of an embodiment of the present application proposes a graph storage method based on a network range, the method comprising:
[0007] Obtaining a network topology graph to be stored, the network topology graph comprising a plurality of topology nodes, any two topology nodes having a connection edge, the plurality of topology nodes comprising at least one attack initiating node and at least one target node;
[0008] From the network topology graph, traverse and read at least one attack path formed by the connection edges between each topology node and the target node;
[0009] Assigning a first weight to a target connection edge directly connected to the attack initiating node, and assigning a first weight to a target connection edge directly connected to the target node, and assigning a second weight to other connection edges in the network topology graph except the target connection edge, to obtain a sum of weights of attack paths from each topological node to the target node, wherein the first weight is greater than the second weight;
[0010] Determine a target maximum weight sum from each topological node to the target node based on the weight sum of the attack paths from each topological node to the target node;
[0011] Sorting the multiple topological nodes in descending order according to the target maximum weight sum to obtain a node sorting relationship, and determining a storage level of each topological node in the storage area according to the node sorting relationship;
[0012] According to the storage level of each topology node in the storage area, the attack path associated with each topology node is chain-stored to obtain the graph storage data corresponding to the network topology graph.
[0013] Accordingly, a second aspect of an embodiment of the present application proposes a graph storage device based on a network range, the device comprising:
[0014] An acquisition module, configured to acquire a network topology graph to be stored, wherein the network topology graph includes a plurality of topology nodes, wherein any two topology nodes have a connection edge, and wherein the plurality of topology nodes include at least one attack initiating node and at least one target node;
[0015] A reading module, configured to traverse and read at least one attack path formed by connecting edges between each topological node and the target node from the network topology graph;
[0016] a configuration module, configured to configure a target connection edge directly connected to the attack initiating node with a first weight, configure a target connection edge directly connected to the target node with a first weight, and configure other connection edges in the network topology graph except the target connection edge with a second weight, to obtain a sum of weights of attack paths between each topological node and the target node, wherein the first weight is greater than the second weight;
[0017] A determination module, configured to determine a target maximum weight sum from each topological node to the target node based on the weight sum of the attack paths from each topological node to the target node;
[0018] A sorting module is used to sort the multiple topological nodes in descending order according to the target maximum weight sum to obtain a node sorting relationship, and determine the storage level of each topological node in the storage area according to the node sorting relationship;
[0019] The storage module is used to chain-store the attack path associated with each topology node according to the storage level of each topology node in the storage area, and obtain the graph storage data corresponding to the network topology graph.
[0020] In some embodiments, the network range-based graph storage device further includes a query module for:
[0021] In response to the attack path query request, and based on the attack path analysis request, determining query information, wherein the query information includes at least one query topology node;
[0022] Based on the query information, each storage level in the graph storage data is queried in sequence according to the query order from high to low to obtain corresponding query results.
[0023] In some embodiments, the network range-based graph storage device further includes an adding module for:
[0024] When there is at least one newly added topological node, query each storage level in the network topological map in descending order to determine at least one first attack path to be adjusted corresponding to the newly added topological node;
[0025] Adding the newly added topological node to the first attack path to be adjusted to obtain a first target attack path, and calculating a first weight sum of each first target attack path;
[0026] re-determining a first maximum weight sum of a first topological node of each first target attack path based on the first weight sum, and determining a first storage level for storing data of the first topological node in the graph based on the first maximum weight sum;
[0027] In the first storage layer, the attack path corresponding to the first topological node is updated.
[0028] In some embodiments, the network range-based graph storage device further includes a deletion module configured to:
[0029] When there is at least one topology node to be deleted, query each storage level in the network topology map in descending order to determine at least one second attack path to be adjusted corresponding to the topology node to be deleted;
[0030] Deleting the to-be-deleted topological node in the second to-be-adjusted attack path to obtain a second target attack path, and calculating a second weight sum of each second target attack path;
[0031] re-determining a second maximum weight sum of a first topological node of each second target attack path based on the second weight sum, and determining a second storage level for storing data of the first topological node in the graph based on the second maximum weight sum;
[0032] In the second storage level, the attack path corresponding to the first topological node is updated.
[0033] In some embodiments, the network range-based graph storage device further includes a summation module configured to:
[0034] For each network topology graph, obtaining a first access frequency of the corresponding attack initiating node in all attack paths, and obtaining a second access frequency of the target node in all attack paths;
[0035] Performing a weighted sum based on the first access frequency and the second access frequency to obtain a first weight;
[0036] A preset weight scaling factor is obtained, and the first weight is adjusted based on the weight scaling factor to obtain a second weight.
[0037] In some embodiments, the network range-based graph storage device further includes a second determination module configured to:
[0038] When there are at least two target topological nodes corresponding to the same target maximum weight sum, obtaining the target attack path corresponding to the target maximum weight sum of each target topological node and the last modification timestamp of each target attack path;
[0039] Based on the order of the last modification timestamps, target storage tiers of the at least two target topology nodes are determined from a plurality of storage tiers.
[0040] In some embodiments, the network range-based graph storage device further includes a storage module for:
[0041] Sequentially in each storage level, create a vertex table entry for each topological node in at least one attack path included in each corresponding topological node, wherein the vertex table entry includes a node identifier, an outgoing edge head pointer, and an incoming edge head pointer of each topological node;
[0042] For the at least one attack path, create arc nodes for connecting edges between adjacent topological nodes, and link the arc nodes in a path order to obtain chain storage data of the at least one attack path, wherein the arc nodes include an arc tail vertex index, an arc head vertex index, a same arc tail pointer, and a same arc head pointer;
[0043] Based on a plurality of chain storage data corresponding to a plurality of storage levels, graph storage data corresponding to the network topology graph is generated.
[0044] Correspondingly, the third aspect of the embodiments of the present application proposes a computer device, which includes a memory and a processor, the memory stores a computer program, and when the processor executes the computer program, it implements the network target range-based graph storage method of any one of the embodiments of the first aspect of the present application.
[0045] Correspondingly, the fourth aspect of the embodiments of the present application proposes a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, it implements the network target range-based graph storage method of any one of the embodiments of the first aspect of the present application.
[0046] An embodiment of the present application obtains a network topology graph to be stored, where the network topology graph includes multiple topology nodes, and there is a connection edge between any two topology nodes, and the multiple topology nodes include at least one attack initiation node and at least one target node; from the network topology graph, traverse and read at least one attack path formed by the connection edge between each topology node and the target node; configure a first weight for the target connection edge directly connected to the attack initiation node, and configure a first weight for the target connection edge directly connected to the target node, and configure a second weight for other connection edges in the network topology graph except the target connection edge, to obtain the sum of the weights of the attack paths between each topology node and the target node, where the first weight is greater than the second weight; based on the sum of the weights of the attack paths between each topology node and the target node, determine the target maximum weight sum from each topology node to the target node; sort the multiple topology nodes in descending order according to the target maximum weight sum to obtain a node sorting relationship, and determine the storage level of each topology node in the storage area according to the node sorting relationship; according to the storage level of each topology node in the storage area, chain store the attack path associated with each topology node to obtain graph storage data corresponding to the network topology graph. In this way, on the one hand, by adopting chain storage, graph data can be automatically recorded and accessed in a more compact and orderly manner, effectively improving the storage efficiency of the network topology map; on the other hand, the present application can assign different weights to connections associated with the attack initiating node or the target node, quickly divide the critical paths with higher access frequencies (i.e., the paths with the largest total weight), and give priority to storing the paths with high frequency access in a high storage level, so that when editing or updating is required, the high-frequency access paths can be accessed first, without the need to traverse the topology globally, thereby improving the efficiency of the search, and when editing, only the relevant links need to be adjusted locally, without the need to traverse and reconstruct the entire topology in an all-round way, which greatly enhances the flexibility of editing and can better adapt to the rapid iteration requirements in a dynamic network environment. In summary, the present application can improve the storage efficiency and editing flexibility of the network topology map. BRIEF DESCRIPTION OF THE DRAWINGS
[0047] Figure 1 This is a schematic diagram of the architecture of a network range-based graph storage system provided in an embodiment of the present application;
[0048] Figure 2 This is a flowchart of a network range-based graph storage method provided in an embodiment of the present application;
[0049] Figure 3 This is an example diagram of a network topology diagram provided in an embodiment of the present application;
[0050] Figure 4 This is an example diagram of the structure of graph storage data provided by an embodiment of the present application;
[0051] Figure 5 This is a schematic diagram of the functional modules of a network range-based graph storage device provided in an embodiment of the present application;
[0052] Figure 6 This is a schematic diagram of the hardware structure of the computer device provided in the embodiment of the present application. DETAILED DESCRIPTION
[0053] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.
[0054] It should be noted that although the device schematics illustrate functional module divisions and the flowcharts illustrate logical sequences, in certain circumstances, the steps shown or described may be performed in a sequence that differs from the module divisions in the device or the sequence in the flowcharts. The terms "first," "second," and so on, in the specification, claims, and drawings, are used to distinguish similar items and are not necessarily used to describe a specific sequence or precedence.
[0055] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the art to which this application pertains. The terms used herein are for the purpose of describing the embodiments of this application only and are not intended to limit this application.
[0056] The cyber range is a highly simulated virtualized network environment that can dynamically construct complex network scenarios to provide a controllable experimental platform for network security research, equipment testing, and personnel training, helping researchers to deeply understand network behavior, discover potential security vulnerabilities, and develop effective defense strategies.
[0057] Network topology is the core part of the network target range. It intuitively reflects the connection relationship and data flow between various nodes in the network (such as servers, routers, switches, terminal devices, etc.). Therefore, it is necessary to construct an accurate and reasonable network topology to ensure that the network target range can truly simulate the expected network environment and behavior, thereby providing a reliable foundation for subsequent network attack and defense experiments, performance testing, etc.
[0058] In related technologies, when storing network topology, manual storage is often relied upon. Specifically, operators need to manually label each node according to business needs, and then drag the nodes one by one through the graphical interface, draw directed edges, etc., resulting in low storage efficiency; on the other hand, when this storage method needs to be adjusted or edited later, it is often necessary to perform a global traversal of the entire topology structure to locate and modify the relevant nodes or edges, resulting in poor overall editing flexibility and difficulty in meeting the rapid iteration requirements in a dynamic network environment.
[0059] Based on this, the embodiments of the present application provide a network range-based graph storage method, apparatus, device, and readable storage medium, which can improve the storage efficiency and editing flexibility of network topology graphs.
[0060] The network range-based graph storage method, apparatus, device, and readable storage medium provided in the embodiments of the present application are specifically illustrated through the following embodiments. First, the network range-based graph storage system in the embodiments of the present application is described.
[0061] Please refer to Figure 1 In some implementations, an embodiment of the present application provides a graph storage system based on a network range.
[0062] In some implementations, the graph storage system may include a terminal 11 and a server 12. For example, terminal 11 may be a personal computer, workstation, or mobile terminal such as a tablet computer or smartphone. Users perform configuration operations on terminal 11 using a graphical user interface or command line tool. The user's operation instructions are then packaged into a request message and sent to server 12 via the network.
[0063] Furthermore, the server side 12 can be a general-purpose server, a high-performance computing server, a storage server, and the like. After receiving the request message sent by the terminal 11, the server side 12 parses the request and extracts key information therein, such as the network topology, attack path, and the like. Then, the server side 12 processes the graph data according to the graph storage method. For example, the server side 12 can calculate the weight of the edge according to the formula, generate graph storage data, and perform operations such as insertion, query, or deletion, and save the processed graph storage data in a storage device, such as a hard disk, solid-state drive, or distributed storage system. At the same time, the server side 12 will also manage and maintain the stored graph storage data, including operations such as data backup, recovery, and index optimization, to ensure data integrity and efficient access.
[0064] Furthermore, after the server 12 completes the storage operation of the graph storage data, it can encapsulate the operation results into a response message and send it back to the terminal 11 through the network. The terminal 11 displays the query results returned by the server 12 to the user in a graphical manner, making it convenient for the user to view and analyze the storage status and graph flow information of the network topology map.
[0065] The network range-based graph storage method in the embodiments of the present application can be illustrated by the following embodiments.
[0066] It should be noted that in each specific embodiment of the present application, when it comes to the need to perform relevant processing based on data related to user identity or characteristics such as user information, user behavior data, user historical data, and user location information, the user's permission or consent will be obtained first. Moreover, the collection, use, and processing of these data will comply with relevant laws, regulations, and standards. In addition, when the embodiment of the present application needs to obtain the user's sensitive personal information, the user's separate permission or consent will be obtained through a pop-up window or by jumping to a confirmation page. After clearly obtaining the user's separate permission or consent, the necessary user-related data for the normal operation of the embodiment of the present application will be obtained.
[0067] In the embodiment of the present application, the diagram storage device based on the network range will be described from the perspective of the network range-based diagram storage device, which can be integrated into a computer device. Figure 2 , Figure 2 This is a flowchart of the steps of the network range-based graph storage method provided in an embodiment of the present application. In the embodiment of the present application, a network range-based graph storage device is specifically integrated on a terminal or server as an example. When the processor on the terminal or server executes the program instructions corresponding to the network range-based graph storage method, the specific process is as follows:
[0068] Step 101: Obtain a network topology graph to be stored. The network topology graph includes multiple topology nodes. There is a connection edge between any two topology nodes. The multiple topology nodes include at least one attack initiating node and at least one target node.
[0069] In some implementations, in order to provide structured input for subsequent graph storage, a network topology graph containing attack path logic can be obtained, thereby laying a data foundation for weight-optimized storage of dynamic attack paths.
[0070] Among them, the network topology diagram can be a logical directed graph structure, consisting of topological nodes (network entities) and connection edges (flow relationships between nodes), which is used to describe the accessible paths and attack behavior flows of the simulated network in the software-defined target range.
[0071] Among them, the topology node can be a logical entity in the network topology diagram, representing the simulated network devices such as servers, core routers, switches, etc. in the software-defined target range. It has a unique identification attribute and can carry roles in the attack path (attack source, target, etc.).
[0072] Among them, the connection edge can be a directed connection relationship between topological nodes, representing the feasible path direction of network traffic or attack behavior (such as from the attack end to the intermediate node A), and its weight can be differentiated according to whether it contains high-frequency access nodes (attacker end / target).
[0073] The attack initiating node may be a special node (such as a user terminal) marked as the source of the attack behavior in the network topology diagram.
[0074] The target node may be a special node (such as a key server) marked as an attack target in the network topology diagram, which may serve as the calculation end point of the reachable path weight.
[0075] For example, the network topology diagram can be generated by manual drawing by a user, generated based on a network scanning tool, obtained based on a configuration file, obtained based on a user-defined script, etc. It can be a tree-structured diagram or a mesh diagram, etc.
[0076] Furthermore, topology nodes can be physical devices, such as firewalls, routers, etc.; they can also be virtual devices, such as Docker containers, attack virtual machines, etc.
[0077] Please refer to Figure 3 The network topology graph can be a directed graph structure, and the topological nodes can be various devices in the network, such as user computers (laptops), routers, servers, and firewalls. The connection edge represents the network connection between these devices, which is a data transmission path or communication link. For example, the edge between the core router and the aggregation switch can be a connection edge.
[0078] exist Figure 3 In the included network topology diagram, the attack initiator node is a device that may launch a network attack, which can be an unprotected or improperly configured computer; while the target node is the attacker's goal, which can be a server that stores sensitive data or provides important services.
[0079] Through the above methods, accurate basic data can be provided for subsequent graph storage and analysis, thereby improving the management and analysis efficiency of the network target range and enhancing the simulation and research capabilities of network attack behaviors.
[0080] Step 102: From the network topology graph, traverse and read at least one attack path formed by the connection edges between each topology node and the target node.
[0081] In some embodiments, in order to optimize the graph storage structure and improve the efficiency of graph storage, at least one attack path formed by the connecting edges between each topological node and the target node can be read to obtain a comprehensive and accurate data foundation, and then perform efficient and accurate storage.
[0082] The attack path can be a sequence of edges from any topological node (including the attack initiating node or the intermediate topological node) to the target node in the network topology graph, which is used to characterize the feasible propagation direction of the attack behavior in the network (such as Figure 3 The attack path in the example is 1→2→3→5).
[0083] For example, the attack path from all topological nodes (including the attack initiating node) to the target node can be read. Figure 3 In the figure, at least one attack path formed by the connecting edges between topological node 1 and target node 5 can be 1→2→3→5, 1→2→3→4→5, and so on; at least one attack path formed by the connecting edges between topological node 2 and target node 5 can be 2→3→5, 2→3→4→5, and so on; at least one attack path formed by the connecting edges between topological node 3 and target node 5 can be 3→5, 3→4→5, and so on.
[0084] Furthermore, in addition to the attack path, branch paths can also be extracted, such as the branch path formed between 3 and 6, and the branch path formed between 3 and 7.
[0085] Through the above methods, potential routes in the network can be quickly identified, ensuring a fast response when graph storage is performed, and providing a data foundation for subsequent weight calculation and graph storage.
[0086] In step 103, a first weight is configured for the target connection edge directly connected to the attack initiating node, and a first weight is configured for the target connection edge directly connected to the target node, and a second weight is configured for other connection edges in the network topology graph except the target connection edge, to obtain the sum of the weights of the attack path between each topological node and the target node, where the first weight is greater than the second weight.
[0087] In some embodiments, in order to support the priority storage and rapid retrieval access of high-frequency attack paths in the shooting range, the connection edges directly associated with special nodes (attack initiation nodes / target nodes) can be identified and assigned higher priority weights, while lower weights can be assigned to ordinary connection edges. Finally, the sum of the weights of each attack path is calculated to highlight the critical attack paths and provide a quantitative basis for the storage priority of each subsequent path.
[0088] The target connection edge can be a directed edge directly connecting the attack initiating node in the network topology graph (such as Figure 3 1→2, where 1 is the attack initiating node), and directed edges directly connecting target nodes (such as Figure 3 Middle edge 3→5, where 5 is the target node).
[0089] Among them, the first weight can be a high priority weight value configured for the target connection edge, which can be used to quantify the criticality of the special node-related edge in the attack path, and give priority to storing paths containing such edges when driving the graph storage.
[0090] Among them, other connection edges can be connection edges in the network topology that are not directly associated with the attack initiating node or the target node (such as Figure 3 The middle edges (2→3, 2→4) represent the intermediate jump relationship, and their weight configuration is lower than the target connection edge.
[0091] The second weight may be a basic weight value configured for other connecting edges, and is used to quantify the weight contribution of non-critical path segments.
[0092] The sum of the weights can be the cumulative value of the weights of all connecting edges in the attack path formed from any topological node (excluding the target node) to the target node. For example, the weight of the attack path 1→2→3→5 is w1+w2+w1. The larger the sum of the weights, the higher the path priority.
[0093] Exemplarily, the first weight and the second weight may be set to be the same for all attack paths in all network topology diagrams.
[0094] In some implementations, different first and second weights can be set for different network topologies according to specific circumstances. Figure 1, set the first weight to 0.8, set the second weight to 0.4; for network topology Figure 2 , set the first weight to 0.9, set the second weight to 0.3, and so on. Furthermore, the target connection edge directly connected to the attack initiating node can be assigned a first weight, the target connection edge directly connected to the target node can be assigned a second weight, and the other connection edges in the network topology except the target connection edge can be assigned a third weight. The weight configuration of each connection edge can be adjusted, but it is necessary to ensure that the weight of the target connection edge is higher than the weights of other connection edges.
[0095] In some embodiments, the first weight and the second weight can be manually configured by a technician, or determined by a basic attack value. For example, for each network topology diagram, the first basic attack value index of the corresponding attack initiating node and the second basic attack value index of the target node can be obtained, and a weighted sum is performed based on the first basic attack value index and the second basic attack value index to obtain the first weight; a preset weight proportional factor is obtained, and the first weight is adjusted based on the weight proportional factor to obtain the second weight. For example, if the first basic attack value index is 0.8, the corresponding weight is 0.6, and the second basic attack value index is 0.6, and the corresponding weight is 0.4, then after weighted summation, the first weight is 0.72. If the weight proportional factor is 0.5, then the second weight is the product of the first weight and the weight proportional factor, which is 0.36.
[0096] In some embodiments, for a target connection edge associated with an attack-initiating node, its first basic attack value index can be determined by the vulnerability threat level and port threat coefficient (i.e., the proportion of high-risk ports) of the attack-initiating node. For example, if the vulnerability threat level is 9.0 and the port threat coefficient is 0.7, the first basic attack value index can be calculated as follows: First Basic Attack Value Index = [Vulnerability Threat Level × (1 + Port Threat Coefficient)] / 2 = (9 × 1.7) / 2 = 7.65.
[0097] Furthermore, for the target edge associated with the target node, its second basic attack value index can be determined by multiplying the business importance level and the data sensitivity. For example, if the business importance level is 5 and the data sensitivity is 0.9, the second basic attack value index can be calculated as follows: Second basic attack value index = business importance level × data sensitivity = 5 × 0.9 = 4.5.
[0098] In this way, the first weight can be the sum of the first basic attack value index and the second basic attack value index, that is, 12.15, or the two can be weighted and summed, with a weight of 0.6 assigned to the first basic attack value index and a weight of 0.4 assigned to the second basic attack value index, and so on.
[0099] Furthermore, after labeling any two connecting edges in each attack path with the first weight or the second weight, the weights of all connecting edges can be added together to obtain the total weight corresponding to the attack path. Taking the attack path 1→2→3→5 as an example, if the attack initiating node is node 1 and the target node is node 5, the first weight is 0.8, and the second weight is 0.4, then the weight of 1→2 is 0.8, the weight of 2→3 is 0.4, and the weight of 3→5 is 0.8. The total weight of the attack path 1→2→3→5 is 0.8+0.4+0.8=2. Similarly, the algorithms for other attack paths are the same as above and are not listed here.
[0100] Through the above method, the importance of key attack paths can be effectively highlighted, which is conducive to the subsequent rapid storage of network topology diagrams based on importance.
[0101] In some embodiments, in order to prioritize the identification of attack paths with high frequency editing in the target range, the access frequency of the attack initiating node and the target node in the attack path can be counted (reflecting the user editing frequency), and the weight proportional factor can be combined to dynamically generate differentiated weights to dynamically quantify the interactive value of key nodes in the attack path, facilitating the subsequent optimization of resource allocation and response speed. For example, before step 103, it can also include:
[0102] (A.1) For each network topology graph, obtain the first access frequency of the corresponding attack initiator node in all attack paths, and obtain the second access frequency of the target node in all attack paths;
[0103] (A.2) performing a weighted sum based on the first access frequency and the second access frequency to obtain a first weight;
[0104] (A.3) Obtain a preset weight scaling factor, and adjust the first weight based on the weight scaling factor to obtain a second weight.
[0105] The first access frequency may be a ratio of attack and defense events in which the attack initiating node is successfully activated within a preset time window.
[0106] The second access frequency may be the probability that the target node is taken as the final target in the attack path.
[0107] Among them, the weight proportional factor can be an adjustment coefficient that is dynamically adjusted based on the current attack and defense situation of the shooting range. The weight proportional factor can be determined based on topological complexity, attack threat level and business priority. The specific value can be set according to actual conditions.
[0108] Exemplarily, the first access frequency can be calculated in the following way:
[0109] First access frequency = number of valid attack chains triggered by the attack initiating node / total number of attack and defense events in the shooting range;
[0110] Furthermore, the second access frequency can be calculated as follows:
[0111] The second access frequency = the number of attack paths ending at the target node / the total number of paths that can reach the target node.
[0112] For example, if the preset time window is the past 7 days, and if, for network topology A, there have been 50 attack and defense events in the target range in the past 7 days, of which 15 effective attack chains were triggered by attack-initiating node 1 (10 of which compromised node 5), there are 8 reachable paths from node 1, 5 of which target node 5, and the current situation parameters include topological complexity of 0.65, attack threat level of 0.9, and service priority of 0.8. Therefore, the first access frequency = 15 / 50 = 0.3, meaning that attack-initiating node 1 played a key role in 30% of the attack and defense events; the second access frequency = 5 / 8 = 0.625, meaning that target node 5 was the target node in 62.5% of the reachable paths.
[0113] Furthermore, the weight coefficient corresponding to the first access frequency is 0.7, and the weight coefficient corresponding to the second access frequency is 0.3. Then, the first weight is: 0.7 × 0.3 + 0.3 × 0.625 = 0.3975. If the weight scaling factor is set to 0.4, then the second weight is the product of the first weight and the weight scaling factor, specifically 0.159.
[0114] Through the above method, weight calculation can be used to ensure that in the subsequent graph storage process, the key paths that users frequently edit are always focused on, so as to meet the adaptive, automated, efficient and accurate storage requirements of dynamic topology.
[0115] Step 104 : determining a target maximum weight sum from each topological node to the target node based on the weight sum of the attack paths from each topological node to the target node.
[0116] In some embodiments, in order to ensure that the attack path with the largest total weight is stored at the top of the stack, the target maximum weight sum of the current topology node can be determined based on the weight sum of at least one attack path between each topology node value and the target node, so as to facilitate the subsequent comparison of the target maximum weight sum of all topology nodes, and then determine the storage level of each topology node, thereby improving the efficiency of storage and subsequent query and editing.
[0117] Among them, the target maximum weight sum can be the maximum value of the weight sum among all reachable attack paths from any topological node in the network topology graph to the target node, which is used to characterize the priority of the most critical attack path from the topological node to the target node and is the basis for determining the storage location of the topological node in subsequent sorting storage.
[0118] In some embodiments, in order to determine the weight sum of the highest-value attack paths from each topological node to the target node, the corresponding weight sum can be obtained based on all possible attack paths from the topological node to the target node, and the weight sums of all possible attack paths can be compared. The largest weight sum can be used as the target maximum weight sum to determine the most threatening attack path of the topological node, and then compared with the most threatening attack paths of other topological nodes to quickly and accurately determine the storage level of the attack path corresponding to each topological node.
[0119] For example, if there are three attack paths between topological node A and the target node, namely attack paths 1 to 3, where the total weight of attack path 1 (the calculation method has been expanded above and will not be repeated here) is 5, the total weight of attack path 2 is 7, and the total weight of attack path 3 is 9. Then, by comparing the total weights of the three attack paths, it can be determined that the largest total weight is 9, and 9 can be used as the target maximum total weight of topological node A.
[0120] Through the above method, it is convenient to subsequently determine the storage level of each topological node based on the target maximum weight sum, and then store the attack path that the user is most likely to access (with the largest weight sum) at the top, which facilitates efficient storage, fast access and efficient editing for users.
[0121] Step 105 , sorting the multiple topological nodes in descending order according to the target maximum weight sum to obtain a node sorting relationship, and determining the storage level of each topological node in the storage area according to the node sorting relationship.
[0122] In some embodiments, in order to ensure that the most threatening attack path-related information is processed and stored first, the topological nodes can be sorted in descending order according to the total maximum target weight (reflecting the priority of attack path storage and access), and a node sorting relationship can be generated. The storage area hierarchy of each topological node is divided accordingly, so that the weighted cross-linked list proposed in this application can prioritize the storage of nodes of high-frequency attack paths in high-speed access areas (i.e., the top of the heap), thereby improving the real-time storage, query, and editing efficiency of dynamic topologies in software-defined target ranges.
[0123] Among them, the node sorting relationship can be a sorting relationship obtained by sorting the topological nodes according to the sum of the maximum target weights (from large to small), which is used to characterize the priority of the node-associated attack path. The higher the ranking, the more critical the attack path is and the greater the possibility of being accessed.
[0124] The storage area may be a physical memory partition area based on a weighted cross linked list (WCLL).
[0125] The storage level can be the hierarchical index of data stored in the entire graph for each topological node in the storage area. For example, if the attack path related to topological node a is stored in the topmost layer, then the storage level of topological node a1 is layer 0 (if counting from 1, it is layer 1).
[0126] In some embodiments, the topological nodes can be sorted according to the target maximum weight sum of each topological node to identify the attack paths that are most likely to be accessed frequently in the network topology diagram. Specifically, each topological node can be sorted from large to small according to the target maximum weight sum, thereby obtaining a node sorting relationship. Then, based on the node sorting relationship, the topological node corresponding to the largest target maximum weight sum is assigned to the top layer (first layer), the topological node corresponding to the second largest target maximum weight sum is assigned to the second layer, and so on. In this way, it can be ensured that key topological nodes and their related attack paths can be accessed and processed faster, which not only optimizes the use of storage resources, but also enhances the ability to respond quickly to potential security threats.
[0127] For example, if there are four topological nodes A, B, C, and D (D is the target node) in a network topology diagram, after calculation, the target maximum weight sums of each topological node to D are: A is 30, B is 45, and C is 20. First, sort them from large to small according to the target maximum weight sums, and the order is B (45) > A (30) > C (20). Then, based on this sorting relationship, the storage level of topological nodes A, B, and C in the storage area is determined, for example, B is at level 0 (the highest query priority), A is at level 1, and C is at level 2. This means that when the system needs to query or edit a path, it will give priority to querying and processing data related to topological node B, because it is considered to be the most likely part of the attack path and the most frequently accessed part. In this way, information can be processed most quickly and accurately.
[0128] Through the above method, the paths corresponding to the topological nodes with higher importance can be effectively identified, so as to facilitate subsequent priority storage and thus improve the response speed of the system.
[0129] In some embodiments, in order to solve the storage conflict problem of topological nodes with the same total weight, when there are at least two target topological nodes with the same target maximum weight sum among multiple topological nodes, by introducing the last modified timestamp of the target attack path as the secondary sorting basis, the size of the corresponding target topological node is dynamically determined to ensure that the high-frequency attack path recently edited by the user can be preferentially stored in the low-level area (such as the top of the stack), thereby optimizing the storage efficiency of real-time topology updates in the software-defined range. For example, the graph storage method based on the network range may also include:
[0130] (B.1) When there are at least two target topological nodes with the same target maximum weight sum, obtain the target attack path corresponding to the target maximum weight sum of each target topological node and the last modification timestamp of each target attack path;
[0131] (B.2) Determine target storage tiers of at least two target topology nodes from the plurality of storage tiers based on the order of the last modification timestamps.
[0132] The target topology node can be a set of topology nodes with the same target maximum weight sum and to which storage tiers are assigned. For example, if topology nodes A and B both have a target maximum weight sum of 8, and if these two topology nodes are directly assigned to the same storage tier, then both topology nodes A and B are target topology nodes.
[0133] The target attack path may be an attack path with the largest total weight from the target topological node to the target node.
[0134] The last modification timestamp may be a time mark of the last time the user edited the target attack path, and is used to indicate the activity of the path. The newer the timestamp, the higher the priority.
[0135] The target storage tier may be a storage tier allocated to target topology nodes with the same weight based on the last modification timestamp.
[0136] In some embodiments, when the target maximum weight sum of at least two topological nodes is the same, the attack paths corresponding to them are sorted in descending order according to the last modification time (most recently modified first) to ensure that nodes with high frequency updates are stored first. For example, if there are target topological nodes X and Y in the network topology, the maximum weight sum of each of them to the target node is 50. At this time, by checking the target attack paths corresponding to the maximum weight sum of 50 in these two target topological nodes, it is detected that the target attack path of target topological node X was last modified on June 8, 2025, while the target attack path of target topological node Y was last modified on June 6, 2025. Based on the order of the last modification time, target topological node X is considered to be more active or more relevant. Therefore, target topological node X and the attack path with target topological node X as the first topological node are assigned to a lower target storage level (for example, storage level 7) and enjoy a higher access priority; while target topological node Y and the attack path with target topological node Y as the first topological node are assigned to a slightly higher target storage level (for example, storage level 8).
[0137] In some embodiments, a node activity index can be introduced as a criterion for distinguishing target topological nodes. The node activity index can comprehensively consider factors such as the historical activity frequency of the target topological node in the historical time window, the number of interactions in the current time window, and the level of security events involved, and calculate a weighted score accordingly. Since the weighted scores of nodes with frequent recent activities and high-risk security events are higher, nodes with higher weighted scores can be assigned a lower target storage level (such as storage level 7), while nodes with the second lowest weighted scores can be assigned the second lowest target storage level (such as storage level 8), and so on. In this way, the efficiency of subsequent storage and access can be improved.
[0138] Through the above method, it can be ensured that when the weights are the same, newer or more timely paths are stored first according to the timestamp, thereby effectively improving the scientificity and rationality of data storage.
[0139] Step 106 : According to the storage level of each topology node in the storage area, the attack path associated with each topology node is chain-stored to obtain graph storage data corresponding to the network topology graph.
[0140] In some embodiments, in order to meet the requirements of software-defined target ranges for automatic, accurate, and efficient storage of dynamic topologies, the attack paths associated with each topological node can be chained according to the storage hierarchy (determined by the sum of the maximum target weights) to build a weight-driven hierarchical chain storage structure, thereby improving the efficiency, organization, and practicality of graph storage.
[0141] Among them, the graph storage data can be a dynamic data structure based on the weighted cross linked list proposed in this application, which can store the attack path of the corresponding node through chain storage according to the storage level corresponding to each node.
[0142] It can be understood that the low level and the high level are relative. For example, the top level can be called the low level, such as level 0, or the top level can be called the high level, such as level 100, as long as the storage does not deviate from the concept of this application.
[0143] In some implementations, topological nodes with higher priorities and their associated attack paths can be placed in more accessible storage tiers based on their storage tiers within the storage area, thereby constructing a hierarchical graph storage data. This not only optimizes data organization but also improves query and editing efficiency.
[0144] For example, if there are three topology nodes A, B, and C in the network topology diagram, they are assigned to storage levels 0, 1, and 2, respectively. For topology node A (level 0), it is associated with two attack paths P1 and P2; topology node B (level 1) is associated with path P3; and topology node C (level 2) is associated with path P4. Then, in the storage area, topology node A and its associated P1 and P2 can first be stored in a chain structure at the highest priority position, that is, storage level 0 (storage level 0 is at the top), and then topology node B and its path P3 are stored in sequence, and finally topology node C and its path P4. In this way, when the system needs to quickly respond to query or edit operation requests, it can give priority to accessing key nodes and path information at higher levels to ensure efficient data processing.
[0145] An embodiment of the present application obtains a network topology graph to be stored, where the network topology graph includes multiple topology nodes, and there is a connection edge between any two topology nodes, and the multiple topology nodes include at least one attack initiation node and at least one target node; from the network topology graph, traverse and read at least one attack path formed by the connection edge between each topology node and the target node; configure a first weight for the target connection edge directly connected to the attack initiation node, and configure a first weight for the target connection edge directly connected to the target node, and configure a second weight for other connection edges in the network topology graph except the target connection edge, to obtain the sum of the weights of the attack paths between each topology node and the target node, where the first weight is greater than the second weight; based on the sum of the weights of the attack paths between each topology node and the target node, determine the target maximum weight sum from each topology node to the target node; sort the multiple topology nodes in descending order according to the target maximum weight sum to obtain a node sorting relationship, and determine the storage level of each topology node in the storage area according to the node sorting relationship; according to the storage level of each topology node in the storage area, chain store the attack path associated with each topology node to obtain graph storage data corresponding to the network topology graph. In this way, on the one hand, by adopting chain storage, graph data can be automatically recorded and accessed in a more compact and orderly manner, effectively improving the storage efficiency of the network topology map; on the other hand, the present application can assign different weights to connections associated with the attack initiating node or the target node, quickly divide the critical paths with higher access frequencies (i.e., the paths with the largest total weight), and give priority to storing the paths with high frequency access in a high storage level, so that when editing or updating is required, the high-frequency access paths can be accessed first, without the need to traverse the topology globally, thereby improving the efficiency of the search, and when editing, only the relevant links need to be adjusted locally, without the need to traverse and reconstruct the entire topology in an all-round way, which greatly enhances the flexibility of editing and can better adapt to the rapid iteration requirements in a dynamic network environment. In summary, the present application can improve the storage efficiency and editing flexibility of the network topology map.
[0146] In some implementations, to optimize the efficiency of data storage and access, the attack paths in the network topology graph can be chained and stored in combination with weight information to accurately record the topological relationships of the attack paths and ensure that any attack path maintains logical continuity in heterogeneous storage media. For example, step 106 may include:
[0147] (106.1) sequentially creating a vertex table entry for each topological node in at least one attack path included in each corresponding topological node in each storage level, wherein the vertex table entry includes a node identifier, an outgoing edge head pointer, and an incoming edge head pointer of each topological node;
[0148] (106.2) For at least one attack path, create arc nodes for the connecting edges between adjacent topological nodes, and link each arc node in the order of the path to obtain chain storage data of at least one attack path, where the arc node includes the arc tail vertex index, arc head vertex index, same arc tail pointer, and same arc head pointer;
[0149] (106.3) Based on the multiple chain storage data corresponding to the multiple storage levels, generate graph storage data corresponding to the network topology graph.
[0150] Among them, the vertex table entry can be a physical storage unit of a topological node in the storage hierarchy, which includes a node identifier, an outgoing edge head pointer (pointing to the outgoing edge arc node with the highest weight of the node), and an incoming edge head pointer (pointing to the incoming edge arc node with the highest weight of the node), which is used to quickly locate key connecting edges.
[0151] The node identifier may be a unique identity code (such as an IP hash value) of a topological node in the range network, which is used to accurately identify the topological node in the vertex table entry.
[0152] Among them, the outgoing edge first pointer can be a pointer in the vertex table entry pointing to the first outgoing edge arc node of the topological node, and the outgoing edges of the same topological node are linked in descending order of weight (connected edges with higher weight are given priority).
[0153] The first incoming edge pointer may be a pointer in the vertex table entry pointing to the first incoming edge arc node of the topological node, and the incoming edges pointing to the topological node are linked in descending order of weight.
[0154] Among them, the arc node can be a directed edge storage unit connecting two topological nodes in the attack path, which includes the arc tail vertex index (starting node ID), arc head vertex index (target node ID), same arc tail pointer (linking the next connecting edge of the same arc tail), and same arc head pointer (linking the next connecting edge of the same arc head). In this way, the core structure of the graph storage data can be constructed.
[0155] Among them, the chain storage data can be a sequence of arc nodes linked in the order of attack paths (such as the arc node chain of attack path 1→2→3→5), which can be traversed in both directions through the same arc tail / same arc head pointer and stored in a specified level (the top level 0 of the stack is the high-weight attack path).
[0156] The arc tail vertex index may be the edge start node identifier recorded in the arc node, which is used to associate the vertex table entry.
[0157] The arc head vertex index may be the edge target node identifier recorded in the arc node, which is used to locate the path in reverse.
[0158] The same arc tail pointer may be a pointer to the next edge in the arc node pointing to the same arc tail vertex (same starting node), forming a horizontal linked list.
[0159] The same arc head pointer may be a pointer to the next edge in the arc node pointing to the same arc head vertex (the same target node), forming a vertical linked list.
[0160] Please refer to Figure 4 For example, if the network topology includes topological nodes V0, V1, V2, and V3, and two attack paths P1 and P2, where P1 is V0→V1→V2 and P2 is V0→V3, after sorting by the sum of the maximum target weights, the resulting storage levels are V0 at storage level 0, V1 at storage level 1, V2 at storage level 2, and V3 at storage level 3.
[0161] Furthermore, for each topological node in the storage level, a vertex table entry is created. Taking V0 as an example, its vertex table entry includes: node identifier: V0; outgoing edge head pointer: pointing to the first arc node of all arc nodes starting from V0; incoming edge head pointer: pointing to the first arc node of all arc nodes of V0.
[0162] Furthermore, for each attack path, arc nodes can be created for the connecting edges between adjacent nodes, and each arc node can be linked in the order of the path. For example, for the arc node 1 of the attack path P1: it represents the connecting edge from V0 to V1, including: arc tail vertex index: 0 (V0); arc head vertex index: 1 (V1); same arc tail pointer: points to the next arc node with V0 as the arc tail (if any); same arc head pointer: points to the next arc node with V1 as the arc head (if any). For the arc node 2 of the attack path P1: it represents the connecting edge from V1 to V2, including: arc tail vertex index: 1 (V1); arc head vertex index: 2 (V2); same arc tail pointer: points to the next arc node with V1 as the arc tail (if any); same arc head pointer: points to the next arc node with V2 as the arc head (if any), so that the following can be generated. Figure 4 The links of the arc nodes of the attack path P1 are shown.
[0163] Furthermore, for the arc node 3 of the attack path P2, it can represent the connection edge from V0 to V3, including: arc tail vertex index: 0 (V0); arc head vertex index: 3 (V3); arc tail pointer: points to the next arc node with V0 as the arc tail (if any); arc head pointer: points to the next arc node with V3 as the arc head (if any). In this way, the following can be generated: Figure 4 The links of the arc nodes of the attack path P2 are shown.
[0164] Based on the chained storage data corresponding to all storage layers, a graph storage data representing the entire network topology is ultimately generated. This effectively organizes and stores each attack path, facilitating rapid query and analysis. Furthermore, because the multiple attack paths corresponding to each topological node are stored based on the sum of the target's maximum weight, subsequent searches and edits can quickly and efficiently identify frequently accessed and important attack paths.
[0165] In some embodiments, in order to solve the real-time bottleneck of large-scale topology path queries in software-defined target ranges, the query topology node (such as the attack initiator) and other information in the attack path query request can be parsed and searched from high to low in each storage layer in the graph storage data (top layer first). In this way, the core attack path frequently accessed by users can be guaranteed to respond in milliseconds, thereby avoiding global disordered traversal searches and effectively saving resources. Exemplarily, after step 106, the following may also be included:
[0166] (C.1) responding to the attack path query request and determining query information based on the attack path analysis request, wherein the query information includes at least one query topology node;
[0167] (C.2) Based on the query information, query each storage level in the graph storage data in order from high to low query order to obtain the corresponding query results.
[0168] The attack path query request may be a user-initiated retrieval instruction for a specific attack behavior flow, including the range of topological nodes to be analyzed and path constraints.
[0169] The query information can be key retrieval parameters extracted from the query request, including at least one query topology node (e.g., attack initiation node 1) and path query attributes (e.g., path weight threshold), used to locate the attack path in the graph storage data. The content of the query information can be customized based on actual circumstances.
[0170] The query topology node may be a topology node specified in the query information, serving as a starting point for attack path retrieval.
[0171] The query result may be an attack path matched in the graph storage data and meeting the query information requirements.
[0172] For example, in a software-defined range environment, a network topology graph contains multiple topology nodes (V0, V1, V2, V3, etc.) and the edges connecting these topology nodes, and the graph storage data for the network topology graph has been stored. If a user sends an attack path query request, the request requests all attack paths starting from topology node V0.
[0173] If the attack path corresponding to each topological node in the graph storage data is stored with the target maximum weight sum of the related topological nodes, storage level 0: contains V0 and related attack paths; storage level 1: contains V1 and V3 and related attack paths; storage level 2: contains V2 and related attack paths.
[0174] When the system receives a request to query all attack paths starting from node V0, it searches each storage level in the graph storage data, in descending order, based on the query information, to obtain the corresponding query results. Since V0 is located at level 0, the highest priority, it is queried here first. Assuming the query results show that V0 is directly connected to both V1 and V3, V0 has been located. Next, all attack paths from V0 to the target node are located. Parts of these two attack paths are recorded: V0→V1 and V0→V3. Next, the query continues at the next-level storage level, level 1. Since both V1 and V3 exist at level 1, each can be queried for further connections. Assuming V1 is found to be connected to V2, this path is completed: V0→V1→V2. Meanwhile, if V3 has no further connections, only V0→V3 is retained as the complete attack path.
[0175] Afterwards, the remaining possible attack paths are queried in the lowest level storage level 2. Since only V2 is present at this level and it has already been included in the previous path V0→V1→V2, no additional processing is required.
[0176] The above query method allows us to quickly locate the query topology node, specifically V0, and further query all attack paths from V0: V0→V1→V2 and V0→V3. This ensures that the most relevant and important paths are accessed first, improving query efficiency and accuracy while also making the entire query process more organized and manageable.
[0177] Through the above method, high-level nodes that are most likely to contain critical attack paths can be preferentially accessed and analyzed, allowing for rapid positioning. This not only improves query efficiency and accuracy, but also optimizes resource usage, ensuring that query tasks can be completed quickly and accurately even in complex network environments.
[0178] In some implementations, in order to quickly and accurately implement dynamic incremental updates of attack paths in scenarios where new topological nodes are added, the affected paths can be located by querying in descending order of storage levels, incrementally adding new topological nodes to generate new attack paths, and recalculating weights. Ultimately, only the storage levels associated with the new topological nodes need to be adjusted, avoiding global traversal or reconstruction of graph storage data, thus meeting the efficiency requirements of real-time topology editing in software-defined ranges. Exemplarily, after step 106, the following steps may also be included:
[0179] (D.1) When there is at least one newly added topological node, query each storage layer in the network topological graph in descending order to determine at least one first attack path to be adjusted corresponding to the newly added topological node;
[0180] (D.2) Adding the newly added topological node to the first attack path to be adjusted to obtain a first target attack path, and calculating the sum of the first weights of each first target attack path;
[0181] (D.3) re-determining a first maximum weight sum of a first topological node of each first target attack path based on the first weight sum, and determining a first storage level of the graph storage data of the first topological node based on the first maximum weight sum;
[0182] (D.4) In the first storage level, the attack path corresponding to the first topological node is updated.
[0183] Among them, the newly added topology node can be a simulation node dynamically added in the network topology diagram, and the weight of its associated attack path needs to be recalculated and the storage level assigned.
[0184] The query order may be a priority retrieval order from high to low (top to bottom) of the storage hierarchy, ensuring that high-weight paths (such as top-of-heap paths) are located first, and the attack paths to be adjusted are quickly screened.
[0185] Among them, the first attack path to be adjusted can be an attack path in the storage layer that has a reachable association with the newly added node. For example, the original attack path 1→2→3→5 needs to be expanded to 1→2→6→3→5 after adding node 6 at the corresponding position.
[0186] Among them, the first target attack path can be an updated attack path generated after inserting a new node in the first attack path to be adjusted, such as 1→2→6→3→5, and its weight needs to be recalculated to ensure that the first topological node is stored according to the weight.
[0187] The first weight sum may be the accumulated value of the weights of all connecting edges of the first target attack path.
[0188] The first topological node may be the topological node at the starting position of the first target attack path, for example, the first topological node of the attack path 1→2→6→3→5 is node 1.
[0189] The first storage level may be a storage area priority level reallocated based on the updated target maximum weight sum of the first topological node (from level 1 to level 0 if the weight increases).
[0190] For example, in a software-defined range environment, there is a network topology A, and a new topology node V4 is added to the network topology A.
[0191] Furthermore, the first attack path to be adjusted that includes V4 can be determined based on V4 (the newly added topological node). For example, V4 can be inserted between the first attack path to be adjusted, V2→V5, to obtain the first target attack path V2→V4→V5. Then, with V4 as the first topological node, the first weight sum of the first target attack path corresponding to V4 is determined. If the first weight sum of V4→V5 is 8, since only the first target attack path V4→V5 is included when V4 is the first topological node, the first maximum weight sum of V4 is 8, and the first storage tier of V4 is determined based on the first maximum weight sum.
[0192] Furthermore, based on V4 as the intermediate topological node (not the first topological node), the first attack path to be adjusted containing V4 can be located, such as V1→V2→V5 is adjusted to obtain the first target attack path V1→V2→V4→V5, and V2→V5 is adjusted to obtain the first target attack path V2→V4→V5. Then, in order to sort and store according to the weight, the first weight sum of the first topological node of each first target attack path can be calculated, and the first maximum weight sum of the first topological node can be finally determined. Taking the first topological node V1 in V1→V2→V5 as an example, the weight sum of V1→V2→V5 is 10. If the original target maximum weight sum of V1 is 8, then the first maximum weight sum of V1 can be updated to 10, and the first storage level of V1 and all attack paths with V1 as the first topological node can be re-determined based on the first maximum weight sum.
[0193] Furthermore, in the original graph storage data, the first storage level of V4 can be determined according to the first maximum weight sum of V4 (newly added topological node), and V4 and related attack paths can be stored. In addition, the corresponding first storage level can be determined according to the first maximum weight sum of the first topological node updated above (if the storage level does not change, there is no need to move it), and the corresponding storage update can be performed. Similarly, in the process of updating according to the first topological node, the graph storage data can be queried in descending order according to the weight, and the paths with higher access frequency can be found first (for example, V1 is stored at the top level, and V1 can be directly found first for editing and storage without global traversal), thereby improving the efficiency of editing.
[0194] By pre-sorting attack paths by weight and managing them hierarchically, during subsequent editing, only the attack paths related to the newly added topological nodes need to be edited, reducing unnecessary global scans. At the same time, since the paths related to the topological nodes with the highest weight (most frequent use) are stored at the top of the heap, the query and editing speeds can be greatly accelerated, ensuring the real-time and accuracy of editing.
[0195] In some implementations, to quickly and accurately implement dynamic incremental updates of attack paths in node deletion scenarios, the paths associated with the node to be deleted can be located by querying in descending order of storage tiers. After deleting the node, the path weights are recalculated, and only the storage tiers of the affected nodes are adjusted. This avoids global traversal or reconstruction of graph storage data, thus meeting the efficiency requirements of real-time topology editing in software-defined ranges. For example, after step 106, the following steps may also be included:
[0196] (E.1) When there is at least one topology node to be deleted, query each storage layer in the network topology graph in descending order to determine at least one second attack path to be adjusted corresponding to the topology node to be deleted;
[0197] (E.2) deleting the to-be-deleted topological nodes in the second attack path to be adjusted to obtain a second target attack path, and calculating a second weight sum of each second target attack path;
[0198] (E.3) re-determining a second maximum weight sum of the first topological node of each second target attack path based on the second weight sum, and determining a second storage level of the graph storage data of the first topological node based on the second maximum weight sum;
[0199] (E.4) In the second storage level, the attack path corresponding to the first topological node is updated.
[0200] The topology node to be deleted may be a simulation node that needs to be dynamically removed from the graph storage data. Its associated topology path needs to be cleared and the storage level with the topology node to be deleted as the first topology node needs to be deleted.
[0201] The second attack path to be adjusted may be an attack path in the storage layer that includes a node to be deleted (eg, the original attack path 1→2→3→5 requires the removal of node 3).
[0202] The second target attack path may be an attack path (eg, 1→2→5) generated after deleting the topological node to be deleted from the second attack path to be adjusted.
[0203] The second weight sum may be the accumulated value of the weights of all connecting edges of the second target attack path.
[0204] The second maximum weight sum may be the maximum value of the path weight from the first topological node to the target node of the second target attack path, and is used to determine the storage level of the first topological node.
[0205] The second storage tier may be a storage area priority reallocated based on the second maximum weight sum.
[0206] In some embodiments, if it is necessary to delete the topological node V4 to be deleted in the graph storage data, it has been predetermined that the attack paths related to V4 are V1→V2→V4→V5 and V4→V5 (which can also be determined by subsequent query in the graph storage data). First, a hierarchical query is performed from high to low according to the storage level. For example, in the top level of the heap L0, the attack path with the highest weight can be queried to obtain V1→V2→V4→V5. If it is confirmed that the attack path contains V4, V1→V2→V4→V5 is marked as the second attack path to be adjusted; then, a query is performed in the secondary level L1 to obtain the attack path V4→V5. If it is confirmed that the attack path contains V4, V4→V5 is marked as the second attack path to be adjusted. In this way, the entire graph scan can be avoided and the path that needs to be adjusted can be quickly found.
[0207] Furthermore, the second path to be adjusted V1→V2→V4→V5 is degraded to V1→V2→V5 after V4 is deleted, and the second weight sum is 8. After V4 is deleted from V4→V5, the path becomes invalid, and the attack path is removed from the graph storage data.
[0208] Furthermore, the second weight sum of the first topological node of each second attack path to be adjusted can be recalculated based on the first topological node of each second target attack path, and the second maximum weight sum of the first topological node can be determined based on the second weight sum of at least one attack path corresponding to the first topological node, so as to relocate the storage level of each first topological node, and after determining the second storage level of each first topological node, each first topological node and the associated path are updated and stored.
[0209] Through the above-mentioned hierarchical, priority-driven approach to node deletion in the network topology, only the affected paths are processed, avoiding full-graph scans, significantly improving query efficiency, and enabling efficient maintenance and dynamic updates of attack paths. This structured, hierarchical execution mechanism not only effectively reduces redundant calculations and invalid paths, but also ensures that attack path analysis results remain consistent with the current network state, improving the software-defined range's responsiveness to topology changes, resource utilization efficiency, and overall system stability.
[0210] See also Figure 5 The embodiment of the present application further provides a network range-based graph storage device, which can implement the above-mentioned network range-based graph storage method. The network range-based graph storage device includes:
[0211] An acquisition module 51 is configured to acquire a network topology graph to be stored, wherein the network topology graph includes a plurality of topology nodes, wherein any two topology nodes have a connection edge, and wherein the plurality of topology nodes include at least one attack initiating node and at least one target node;
[0212] A reading module 52 is configured to traverse and read at least one attack path formed by the connection edges between each topological node and the target node from the network topology graph;
[0213] a configuration module 53 configured to configure a first weight for a target connection edge directly connected to the attack initiating node, configure a first weight for a target connection edge directly connected to the target node, and configure a second weight for all connection edges in the network topology graph except the target connection edge, thereby obtaining a sum of weights of attack paths from each topological node to the target node, wherein the first weight is greater than the second weight;
[0214] A determination module 54 is configured to determine a target maximum weight sum from each topological node to the target node based on the weight sum of the attack paths from each topological node to the target node;
[0215] A sorting module 55 is used to sort the multiple topological nodes in descending order according to the sum of the target maximum weights to obtain a node sorting relationship, and determine the storage level of each topological node in the storage area according to the node sorting relationship;
[0216] The storage module 56 is used to chain-store the attack paths associated with each topology node according to the storage level of each topology node in the storage area, and obtain graph storage data corresponding to the network topology graph.
[0217] The specific implementation of the network range-based graph storage device is basically the same as the specific embodiment of the network range-based graph storage method described above, and will not be repeated here. On the premise of meeting the requirements of the embodiment of this application, the network range-based graph storage device can also be provided with other functional modules to implement the network range-based graph storage method in the above embodiment.
[0218] The present application also provides a computer device comprising a memory and a processor. The memory stores a computer program, and the processor executes the computer program to implement the aforementioned network range-based graph storage method. The computer device can be any intelligent terminal, including a tablet computer and an in-vehicle computer.
[0219] See also Figure 6 , Figure 6 The hardware structure of a computer device according to another embodiment is shown. The computer device includes:
[0220] The processor 61 may be implemented as a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of the present application.
[0221] The memory 62 can be implemented in the form of a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM). The memory 62 can store an operating system and other application programs. When the technical solutions provided in the embodiments of this specification are implemented by software or firmware, the relevant program codes are stored in the memory 62, and the processor 61 calls and executes the network range-based graph storage method of the embodiments of this application.
[0222] Input / output interface 63, used to implement information input and output;
[0223] Communication interface 64, used to implement communication interaction between this device and other devices, which can be achieved through wired means (such as USB, network cable, etc.) or wireless means (such as mobile network, WiFi, Bluetooth, etc.);
[0224] bus 65 , which transmits information between the various components of the device (e.g., processor 61 , memory 62 , input / output interface 63 , and communication interface 64 );
[0225] The processor 61 , the memory 62 , the input / output interface 63 and the communication interface 64 are connected to each other in communication within the device via a bus 65 .
[0226] An embodiment of the present application also provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, it implements the above-mentioned network range-based graph storage method.
[0227] The memory, as a non-transient computer-readable storage medium, can be used to store non-transient software programs and non-transient computer executable programs. In addition, the memory may include a high-speed random access memory and may also include a non-transient memory, such as at least one disk storage device, a flash memory device, or other non-transient solid-state storage device. In some embodiments, the memory may optionally include a memory remotely arranged relative to the processor, and these remote memories may be connected to the processor via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0228] The embodiments described in the embodiments of this application are intended to more clearly illustrate the technical solutions of the embodiments of this application and do not constitute a limitation on the technical solutions provided by the embodiments of this application. Those skilled in the art will appreciate that with the evolution of technology and the emergence of new application scenarios, the technical solutions provided in the embodiments of this application are also applicable to similar technical problems.
[0229] Those skilled in the art will understand that the technical solutions shown in the figures do not constitute a limitation on the embodiments of the present application, and may include more or fewer steps than shown in the figures, or a combination of certain steps, or different steps.
[0230] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, i.e., they may be located in one place or distributed across multiple network units. Some or all of the modules may be selected based on actual needs to achieve the objectives of this embodiment.
[0231] Those skilled in the art will appreciate that all or some of the steps in the methods, systems, and functional modules / units in the devices disclosed above may be implemented as software, firmware, hardware, or appropriate combinations thereof.
[0232] The terms "first", "second", "third", "fourth", etc. (if any) in the specification of the present application and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequential order. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0233] It should be understood that in this application, "at least one (item)" and "several" refer to one or more, and "plurality" refers to two or more. "And / or" is used to describe the association relationship of associated objects, indicating that three relationships may exist. For example, "A and / or B" can mean: only A exists, only B exists, and A and B exist at the same time, where A and B can be singular or plural. The character " / " generally indicates that the previous and next associated objects are in an "or" relationship. "At least one of the following items" or similar expressions refers to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, c can be single or multiple.
[0234] In the several embodiments provided in this application, it should be understood that the disclosed systems and methods can be implemented in other ways. For example, the system embodiments described above are merely illustrative. For example, the division of the above units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces, devices or units, which can be electrical, mechanical or other forms.
[0235] The units described above as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0236] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0237] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product, which is stored in a storage medium and includes multiple instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of various embodiments of the present application. The aforementioned storage medium includes: various media that can store programs, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
[0238] The preferred embodiments of the present invention are described above with reference to the accompanying drawings, but are not intended to limit the scope of the present invention. Any modifications, equivalent substitutions, and improvements made by those skilled in the art without departing from the scope and essence of the present invention should be within the scope of the present invention.
Claims
1. A graph storage method based on a network range, characterized in that: The method comprises: Obtaining a network topology graph to be stored, the network topology graph comprising a plurality of topology nodes, any two topology nodes having a connection edge, the plurality of topology nodes comprising at least one attack initiating node and at least one target node; From the network topology graph, traverse and read at least one attack path formed by the connection edges between each topology node and the target node; Assigning a first weight to a target connection edge directly connected to the attack initiating node, and assigning a first weight to a target connection edge directly connected to the target node, and assigning a second weight to other connection edges in the network topology graph except the target connection edge, to obtain a sum of weights of attack paths from each topological node to the target node, wherein the first weight is greater than the second weight; Determine a target maximum weight sum from each topological node to the target node based on the weight sum of the attack paths from each topological node to the target node; Sorting the multiple topological nodes in descending order according to the target maximum weight sum to obtain a node sorting relationship, and determining a storage level of each topological node in the storage area according to the node sorting relationship; According to the storage level of each topology node in the storage area, the attack path associated with each topology node is chain-stored to obtain the graph storage data corresponding to the network topology graph.
2. The network range-based graph storage method according to claim 1, characterized in that: After chain-storing the attack paths associated with each topology node according to the storage level of each topology node in the storage area to obtain the graph storage data corresponding to the network topology graph, the method further includes: In response to the attack path query request, and based on the attack path analysis request, determining query information, wherein the query information includes at least one query topology node; Based on the query information, each storage level in the graph storage data is queried in sequence according to the query order from high to low to obtain corresponding query results.
3. The network range-based graph storage method according to claim 1, characterized in that: After chain-storing the attack paths associated with each topology node according to the storage level of each topology node in the storage area to obtain the graph storage data corresponding to the network topology graph, the method further includes: When there is at least one newly added topological node, query each storage level in the network topological map in descending order to determine at least one first attack path to be adjusted corresponding to the newly added topological node; Adding the newly added topological node to the first attack path to be adjusted to obtain a first target attack path, and calculating a first weight sum of each first target attack path; re-determining a first maximum weight sum of a first topological node of each first target attack path based on the first weight sum, and determining a first storage level for storing data of the first topological node in the graph based on the first maximum weight sum; In the first storage layer, the attack path corresponding to the first topological node is updated.
4. The network range-based graph storage method according to claim 1, characterized in that: After chain-storing the attack paths associated with each topology node according to the storage level of each topology node in the storage area to obtain the graph storage data corresponding to the network topology graph, the method further includes: When there is at least one topology node to be deleted, query each storage level in the network topology map in descending order to determine at least one second attack path to be adjusted corresponding to the topology node to be deleted; Deleting the to-be-deleted topological node in the second to-be-adjusted attack path to obtain a second target attack path, and calculating a second weight sum of each second target attack path; re-determining a second maximum weight sum of a first topological node of each second target attack path based on the second weight sum, and determining a second storage level for storing data of the first topological node in the graph based on the second maximum weight sum; In the second storage level, the attack path corresponding to the first topological node is updated.
5. The network range-based graph storage method according to claim 1, characterized in that: Before configuring the first weight for the target connection edge directly connected to the attack initiating node and configuring the first weight for the target connection edge directly connected to the target node, the method further includes: For each network topology graph, obtaining a first access frequency of the corresponding attack initiating node in all attack paths, and obtaining a second access frequency of the target node in all attack paths; Performing a weighted sum based on the first access frequency and the second access frequency to obtain a first weight; A preset weight scaling factor is obtained, and the first weight is adjusted based on the weight scaling factor to obtain a second weight.
6. The network range-based graph storage method according to claim 1, characterized in that: The method further comprises: When there are at least two target topological nodes corresponding to the same target maximum weight sum, obtaining the target attack path corresponding to the target maximum weight sum of each target topological node and the last modification timestamp of each target attack path; Based on the order of the last modification timestamps, target storage tiers of the at least two target topology nodes are determined from a plurality of storage tiers.
7. The network range-based graph storage method according to claim 1, characterized in that: The attack paths associated with each topology node are chain-stored according to the storage level of each topology node in the storage area to obtain graph storage data corresponding to the network topology graph, including: Sequentially in each storage level, create a vertex table entry for each topological node in at least one attack path included in each corresponding topological node, wherein the vertex table entry includes a node identifier, an outgoing edge head pointer, and an incoming edge head pointer of each topological node; For the at least one attack path, create arc nodes for connecting edges between adjacent topological nodes, and link the arc nodes in a path order to obtain chain storage data of the at least one attack path, wherein the arc nodes include an arc tail vertex index, an arc head vertex index, a same arc tail pointer, and a same arc head pointer; Based on a plurality of chain storage data corresponding to a plurality of storage levels, graph storage data corresponding to the network topology graph is generated.
8. A graph storage device based on a network range, characterized in that: The device comprises: An acquisition module, configured to acquire a network topology graph to be stored, wherein the network topology graph includes a plurality of topology nodes, wherein any two topology nodes have a connection edge, and wherein the plurality of topology nodes include at least one attack initiating node and at least one target node; A reading module, configured to traverse and read at least one attack path formed by connecting edges between each topological node and the target node from the network topology graph; a configuration module, configured to configure a target connection edge directly connected to the attack initiating node with a first weight, configure a target connection edge directly connected to the target node with a first weight, and configure other connection edges in the network topology graph except the target connection edge with a second weight, to obtain a sum of weights of attack paths between each topological node and the target node, wherein the first weight is greater than the second weight; A determination module, configured to determine a target maximum weight sum from each topological node to the target node based on the weight sum of the attack paths from each topological node to the target node; A sorting module is used to sort the multiple topological nodes in descending order according to the target maximum weight sum to obtain a node sorting relationship, and determine the storage level of each topological node in the storage area according to the node sorting relationship; The storage module is used to chain-store the attack path associated with each topology node according to the storage level of each topology node in the storage area, and obtain the graph storage data corresponding to the network topology graph.
9. A computer device, characterized in that: The computer device includes a memory and a processor, the memory stores a computer program, and the processor implements the network range-based graph storage method described in any one of claims 1 to 7 when executing the computer program.
10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the network range-based graph storage method according to any one of claims 1 to 7 is implemented.
Citation Information
Patent Citations
Network information analysis method, device, equipment and medium
CN115242614A
Depth-first search attack graph generation method and system based on node asset weight
CN119210809A
Concluding customer social network construction and expansion method and system
CN119578422A
Network attack tracing method and device based on internal and external network topology node analysis
CN119996004A
Storage and calculation integrated parallel processing system and method
CN120179606A