Multi-dimensional network security test identification system and method based on virtual-real fusion and dynamic guidance

The multi-dimensional cybersecurity testing and evaluation system, which integrates virtual and real environments and features dynamic guidance, solves the problems of fragmentation between virtual and real environments, rigid task guidance, and insufficient intelligent evaluation. It achieves highly realistic and flexible cybersecurity testing, improving the accuracy and efficiency of test results.

CN120915587APending Publication Date: 2025-11-07BEIJING AEROSPACE WANYUAN TECH CO LTD

Patent Information

Application Number
CN202511267943.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-05
Publication Date
2025-11-07

AI Technical Summary

Technical Problem

Existing network range technologies suffer from problems such as the disconnect between virtual and real environments, rigid task guidance, and insufficient intelligent evaluation, resulting in high misjudgment rates, low testing efficiency, and poor evaluation accuracy.

Method used

A multi-dimensional cybersecurity testing and evaluation system based on virtual-real fusion and dynamic guidance is adopted. By constructing a test standard tree, generating an evaluation model, dynamically arranging virtual and real target range scenarios, monitoring resource utilization in real time, and adjusting task priorities, it combines virtualized devices with real physical devices to achieve high simulation and flexibility.

Benefits of technology

It improves the credibility and accuracy of test results, enhances testing efficiency and flexibility, and provides a more reliable basis for cybersecurity assessment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120915587A_ABST
    Figure CN120915587A_ABST
Patent Text Reader

Abstract

The invention discloses a multi-dimensional network security test identification system and method based on virtual-real fusion and dynamic guidance, and belongs to the technical field of network security test. The system comprises a test standard management module, a test script arrangement module, a scenario scheme generation module, a task dynamic guidance module and the like. Test standards, dimensions and types are managed in order through a tree structure, and a virtual-real fusion target range environment is constructed by utilizing a virtualization technology and real equipment, so that main tasks and sub-tasks can be dynamically added, and the utilization rate of host resources can be monitored in real time and displayed in a broken line graph. An evaluation model is generated by means of an artificial intelligence technology, and automatic scoring and deep analysis of test results are achieved. According to the method, collaborative execution, dynamic guidance and real-time situation awareness of multi-dimensional test tasks are creatively achieved, and the automation level, the scene coverage rate and the result credibility of network security testing are greatly improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application belongs to the technical field of network security testing and evaluation, and specifically relates to a multi-dimensional network security test identification system and method based on virtual-real fusion and dynamic guidance, which is suitable for network security performance verification in military equipment, industrial control system and other scenarios, and can also be applied to the fields of evaluation of enterprise network security protection capability and testing of network security products. BACKGROUND

[0002] With the rapid development of network technology, network security problems are becoming increasingly serious, and the requirements for network security testing and evaluation are also increasing. The existing network target field technology has many defects in actual application:

[0003] Virtual-real environment is split: Most of the current network target field technology focuses on large-scale node simulation, mainly relying on virtualization technology to build a test environment, and lacks support for real device integration. This makes the test environment and the actual network environment have a large difference, and the test results are difficult to accurately reflect the network security status in the real scene, resulting in a high misjudgment rate.

[0004] Task guidance is rigid: Traditional test standard management usually adopts a static configuration method, which is difficult to dynamically adjust according to different test scenarios and requirements. The task guidance function is also relatively single, lacking the ability to adjust the priority of sub-tasks in real time, and cannot adapt to complex and variable network attack and defense scenarios. When unexpected situations or resource shortages occur during testing, the task execution order cannot be optimized in a timely manner, affecting the testing efficiency and effectiveness.

[0005] Evaluation is not intelligent enough: The existing evaluation model is mostly based on fixed rules, with low intelligence. When faced with diversified network attack methods and complex network environments, it is difficult to accurately evaluate network security performance. For example, the security verification platform of the China Electronics Technology Group has deficiencies in dynamic task guidance and multi-dimensional coordination, and cannot fully utilize artificial intelligence and machine learning technology to improve the accuracy and flexibility of evaluation.

[0006] In summary, the existing technology cannot meet the growing demand for network security testing, and there is an urgent need for a network security test identification system and method that supports virtual-real fusion, dynamic guidance and intelligent evaluation to improve the quality and efficiency of network security testing. SUMMARY

[0007] In view of the problems of virtual-real environment split, task guidance rigidity and evaluation intelligence deficiency in the existing network target field technology, the present application proposes a multi-dimensional network security test identification system and method based on virtual-real fusion and dynamic guidance, aiming to improve the authenticity of the test scene, the flexibility of task execution and the accuracy of the evaluation results, and to provide more reliable protection for network security protection.

[0008] The technical solutions are as follows:

[0009] A multi-dimensional network security test and evaluation system based on virtual-real fusion and dynamic task scheduling, comprising: a test standard subsystem for creating and managing test standards, test dimensions and test types based on a tree structure, supporting standard import, export and state management;

[0010] A test script subsystem for arranging test cases and evaluation models, supporting dynamic replication, import and export of scripts, and AI-driven model optimization;

[0011] A scenario subsystem that generates network target scene through virtual-real combination technology, configures traffic simulation strategy and test seats, and realizes dynamic arrangement of scene topology;

[0012] A task scheduling subsystem that supports dynamic task scheduling, suspension, resumption and real-time monitoring, and displays CPU, memory and hard disk utilization changes through a line chart.

[0013] A multi-dimensional network security test and evaluation method based on virtual-real fusion and dynamic task scheduling, based on the above multi-dimensional network security test and evaluation system based on virtual-real fusion and dynamic task scheduling, comprising the following steps:

[0014] Constructing a test standard tree, defining multi-dimensional test indicators, and adding corresponding test dimensions and test types at different levels of the test standard tree according to different test targets and scenarios;

[0015] Generating an evaluation model based on artificial intelligence, associating test cases and rules in the test script, and using machine learning algorithms to learn historical test data and related security knowledge to generate a targeted evaluation model;

[0016] Dynamically arranging virtual-real fusion target scene, configuring traffic simulation strategy, selecting appropriate virtualization devices and real physical devices for combination according to test requirements, and setting corresponding traffic simulation parameters;

[0017] Task scheduling and real-time monitoring of resource utilization and adjustment of task priority, during task execution, according to real-time monitoring of resource utilization, automatically improving or reducing the priority of certain tasks;

[0018] Generating a test report automatically according to the evaluation model, analyzing network security performance, and comprehensively evaluating the test results to generate a detailed test report for network security improvement.

[0019] A computer readable storage medium storing computer instructions for causing a processor to implement a multi-dimensional network security test and evaluation method based on virtual-real fusion and dynamic task scheduling.

[0020] Advantages:

[0021] The complete architecture including four subsystems of test standards, test scripts, scenario and task guidance is constructed, the whole process management from test standard definition, test script arrangement, scenario generation to task execution and monitoring is realized, the subsystems are closely cooperated to ensure the efficient test work.

[0022] The virtualization devices (such as containers, virtual machines) and real physical devices are innovatively combined to construct a highly simulated network attack and defense scene. The virtualization devices can quickly build large-scale and diversified network nodes to meet different test requirements; the real physical devices simulate key real environment components such as hardware firewall, intrusion detection system, etc., so that the test environment is closer to the actual network, and the credibility of the test result is effectively improved.

[0023] A dynamic guidance mechanism supporting dynamic addition, suspension and resumption of main tasks and subtasks is designed. During the task execution process, the host resource utilization rate such as CPU, memory, hard disk, etc. is monitored in real time, and is visually displayed through a broken line chart. According to the real-time monitoring data and task priority, the task execution order and resource allocation are automatically adjusted to ensure the efficiency and flexibility of task execution. At the same time, the Gantt chart is used to compare the planned and actual task progress, so that the management personnel can timely find and solve problems.

[0024] An intelligent evaluation model based on machine learning algorithm is introduced, which automatically generates evaluation rules and optimizes the scoring logic of test cases through learning and analysis of a large number of historical test data. The model can dynamically adjust the evaluation strategy according to different test scenarios and target systems to improve the accuracy and pertinence of the evaluation result.

[0025] Through the virtual-real fusion technology, the virtualization devices and the real physical devices are combined to simulate a more realistic network environment, which effectively reduces the misjudgment rate of the test result and provides a more reliable basis for network security decision-making.

[0026] The dynamic task guidance mechanism enables the test process to adjust the task priority and resource allocation in real time according to the actual situation, adapts to complex and variable attack and defense scenes, and improves the test efficiency and effect.

[0027] The tree-shaped standard management facilitates the creation, management and query of test standards, the intelligent evaluation model reduces manual intervention, realizes the automatic scoring and analysis of test results, and greatly improves the test efficiency and accuracy. BRIEF DESCRIPTION OF DRAWINGS

[0028] Figure 1 The technical architecture diagram of the multi-dimensional network security test and evaluation system based on virtual-real fusion and dynamic guidance of the application;

[0029] Figure 2 A design flowchart example of a test standard subsystem of an embodiment of the present application;

[0030] Figure 3 A design flowchart example of a test scenario subsystem of an embodiment of the present application;

[0031] Figure 4 A design flowchart example of a scenario assumption subsystem of an embodiment of the present application;

[0032] Figure 5 A design flowchart example of a task steering subsystem of an embodiment of the present application;

[0033] Figure 6 A design flowchart example of a virtual-real combination of an embodiment of the present application;

[0034] Figure 7 A design flowchart example of an artificial intelligence generated evaluation model of an embodiment of the present application. DETAILED DESCRIPTION

[0035] The present application will be further described below in conjunction with the accompanying drawings and embodiments. It can be understood that the specific embodiments described herein are only for the purpose of explaining the present application, and not limiting the present application. In addition, it should be noted that, for the purpose of description, only the parts related to the present application are shown in the drawings, not all the structures.

[0036] Figure 1 A multi-dimensional network security test and evaluation system architecture diagram based on virtual-real fusion and dynamic steering of an embodiment of the present application, comprising:

[0037] A test standard subsystem for creating and managing test standards, test dimensions and test types based on a tree structure, supporting standard import, export and state management;

[0038] A test scenario subsystem for arranging test cases and evaluation models, supporting dynamic duplication, import and export of scenarios, and artificial intelligence driven model optimization;

[0039] A scenario assumption subsystem for generating network target scene through virtual-real combination technology, configuring traffic simulation strategy and test seat, and realizing dynamic arrangement of scene topology;

[0040] A task steering subsystem supporting dynamic issuance, suspension, resumption and real-time monitoring of main tasks and subtasks, and displaying CPU, memory and hard disk utilization changes of the host through a line chart.

[0041] The test standard subsystem adopts a tree structure to display the hierarchical relationship of test standards, test dimensions and test types, supports state switching of draft state, available state and used state, and changes from the draft state to the available state when the standard meets preset integrity and accuracy requirements, and enters the used state when the standard has been used.

[0042] Figure 2 A test standard subsystem design flowchart provided by the embodiment of the application is shown in FIG. Figure 2 The process includes the following steps.

[0043] S21, creating a test standard: the system provides an online adding and editing interface. A user fills in basic information such as a standard name, a standard number, an applicable object, a standard description and the like in the interface, and simultaneously specifies test dimensions and test types. For example, in a network security test scenario, the applicable object can be a certain type of weapon command system, the test dimensions can include network communication security and data storage security, and the test types correspond to specific manners such as vulnerability scanning and penetration testing. The test standard subsystem supports association and mapping with international and domestic commonly used network security standards when creating a test standard, and ensures the universality and compliance of the test standard.

[0044] S22, submitting after filling in, and judging whether preset requirements are met: the system performs preliminary format checking on the input content, such as whether the standard number format conforms to the specification, whether there is omission of a required item and the like; when performing standard integrity and accuracy checking, in addition to format checking, the system further checks the logical rationality of the test dimensions and test types. For example, whether a specific test type matches the selected test dimensions, such as selecting a port scanning type for the network communication security dimension, which is reasonable, but selecting a file integrity detection type is not quite matched.

[0045] S23, if the checking fails, the system prompts the user with specific error information, guides the user to return to the editing page for modification, until the preset requirements are met, and the standard state changes from the draft state to the available state.

[0046] S24, after the standard enters the available state, if it is selected by a test script, the system automatically marks its state as the used state. At the same time, the system records the use record of the standard, including which test scripts are referenced, the use time and the like information. For the used state standard, if the user attempts to perform a deletion or modification operation, the system pops up a prompt box to inform the user that the used state standard cannot be changed at will, so as to ensure the coherence and accuracy of the test data. If modification is indeed required, a specific approval process is needed, and the editing permission is unlocked after the approval is passed.

[0047] S25, design standard query function: provide a variety of query methods, including by inputting standard name fuzzy query, according to the creator name accurate search. Query results in the form of list display, convenient for users to browse. In addition to the display standard name, creator, also show standard number, state (available state, used state, etc.) and other key information. Click on the list of specific standards, you can view detailed information, including test dimensions, test type and other content, in tree structure display, so that the hierarchical relationship is self-evident.

[0048] S26, design standard import and export function: when exporting, the system supports the selected test standard data to be exported as a specific format file, such as XML or JSON format, convenient for data backup and migration between different systems. The file contains all the relevant information of the standard, such as name, number, applicable object, test dimension and type, etc. When importing, the user selects the file that meets the format requirements to upload, and the system checks the format and content of the imported data to ensure data accuracy. After passing the verification, the data is imported into the system, completing the migration or new operation of the standard.

[0049] Figure 3 The test script subsystem design process provided by the embodiment of the application is shown in the figure. Figure 3 As shown in the figure, the design process includes:

[0050] S31, new test script: the system guides the user to select the applicable test standard from the test standard subsystem, ensuring that the design of the test script conforms to the corresponding specification. After selecting the standard, the user starts to add test cases, and fills in the name, test type, test tool, case description and case document and other information for each case. For example, in the script for testing the network security of an enterprise, the case name can be set as "detecting enterprise mail system vulnerabilities", the test type is selected as "vulnerability scanning", the test tool is selected as a professional vulnerability scanning software, the case description describes the scanning range, the key check items, etc., and the case document can upload relevant technical documents or operation guidelines. After adding a case, the system asks whether to continue adding, if the user chooses to continue, repeat the process of adding cases; if you choose to end, enter the creation of the evaluation model section.

[0051] S32, create evaluation model: the system provides a visual operation interface to facilitate user configuration of evaluation model parameters. Users can perform model generation and update operations, such as learning a large amount of historical test data based on deep learning algorithms, automatically adjusting the weights and parameters of the evaluation model according to different test scenarios and target systems, and adapting to different test scenarios and target systems. At the same time, users need to set the calculation type of the evaluation model, such as selecting a calculation method based on index weights or an automatic scoring method based on machine learning algorithms. When setting the score calculation rules, the score interval and calculation method corresponding to different test results are clearly defined, for example, deducting 20 points for high-risk vulnerabilities found by vulnerability scanning and 10 points for medium-risk vulnerabilities. After completing the settings, save the test script and store the test cases and evaluation model data together for easy subsequent use.

[0052] S33, design test script replication function: when the user selects to copy the script, the system not only copies the basic information of the script, but also copies all the test cases and evaluation model data it contains. The newly copied script can be independently edited, and users can modify the case content and adjust the evaluation model parameters according to new test requirements, saving time and effort in creating a new script. In terms of import and export functions, when exporting, the system packages the test script and its related test cases and evaluation model data into a specific format file, such as a ZIP format, for easy transmission between different environments or systems. When importing, the system checks the format and content of the imported file to ensure data integrity and accuracy, and after passing the verification, the data is imported into the system to complete the migration or reuse of the script.

[0053] S33, design test script editing function: users can modify the script name, reselect the test standard, or add, delete, or modify existing test cases. For example, if the test tool of a certain case is found to be inappropriate, it can be replaced directly in the editing interface; if a test scenario changes, a new case can be added. At the same time, users can also adjust the evaluation model, such as modifying the calculation type of the model and optimizing the score calculation rules, to adapt to different test requirements. When deleting a script, the system will prompt the user to confirm the deletion, and if the script has been used or associated with important test data, the system will further prompt the user of the potential impact of deletion to avoid accidental deletion.

[0054] S34, ensure the quality and accuracy of the test script, and set up version management function. Every time an important modification is made to the test script, such as adding a new test case or adjusting the evaluation model, the system automatically records version change information, including modification time, modifier, and modification content. Users can view historical versions and compare differences between different versions to facilitate tracing and managing the evolution of the test script, and quickly locate and solve problems when they occur.

[0055] Figure 4The scheme provided by the embodiment of the application conceives a subsystem design flowchart. The scheme conceiving subsystem comprises a virtual-real fusion target range environment construction module, which combines a virtualization device and a real physical device to simulate network attack and defense scenes, wherein the virtualization device is used to quickly construct large-scale and diversified network nodes, and the real physical device is used to simulate key real environment components, and the two work together to improve the reality of the scenes.

[0056] As shown in Figure 4 , the design process comprises:

[0057] S41, task description management stage: after the user enters the corresponding interface of the system, the user first configures basic information of the scheme, such as inputting a test scheme name, a scheme number, uploading a scheme thumbnail, selecting a test script bound to the scheme, setting a recommended completion time length, and setting an on-off state of group communication, etc. If there is an existing similar scheme template, the user can select to import or copy the scheme template to quickly generate a scheme framework and reduce repetitive work. After the template is imported or copied, the user can adjust and improve the scheme information according to actual test requirements.

[0058] S42, enter the scene arrangement management link: the user can construct a topology scene according to network devices, external networks, terminal devices, security devices, etc. The user can either select a suitable scene from the system preset scene template for quick construction, or customize a scene. After the topology scene construction is completed, the user sets a collection strategy for the scene, determines parameters such as a data type to be collected and a collection frequency, etc. Then, the user configures a traffic simulation strategy according to test requirements, supports a rule-based traffic generation mode, such as setting a traffic size, a protocol type, etc. in a specific time period, and also supports a machine learning-based traffic simulation, which uses an algorithm to learn a real network traffic mode to simulate more complex and real normal business traffic and attack traffic. In summary, the scheme conceiving subsystem supports rule-based traffic generation and machine learning-based traffic simulation when configuring the traffic simulation strategy, and can simulate more real and complex network traffic, including normal business traffic and attack traffic.

[0059] S43, in the seat management part, the user first performs test seat adding, editing and deleting operations to determine the number of seats participating in the test and the responsibilities. The user allocates corresponding test dimensions to each test seat to ensure that each dimension has a corresponding test personnel responsible. At the same time, in the associated topology scene, the user marks test tools to corresponding nodes to clearly indicate the use positions of the test tools in the scene, which facilitates the test personnel to quickly call in the test process.

[0060] S44, test task management: the user binds the test script to the current scenario. The system pre-generates test cases according to the bound script, and if the pre-generated cases cannot meet all requirements, the user can also manually add test cases. Then, the system automatically generates an evaluation model according to the association relationship among the script, test standards, test dimensions and test cases, determines evaluation rules and index weights, and the like, and prepares for subsequent test result evaluation. In the scenario execution management stage, the system comprehensively checks the data of task description, topology scene, seat and test task, and ensures that the data is complete and compliant. If the check passes, the test task is generated in the task steering subsystem with the scenario as a template; if the check fails, the system prompts the user with specific error information, and the user returns to the corresponding module for modification.

[0061] Figure 5 A task steering subsystem design flowchart is provided for the embodiments of the present application. As shown in the design process includes: Figure 5

[0062] S51, task initialization stage, the task steering subsystem receives scenario information from the scenario assumption subsystem, and generates main task and subtask architecture according to the scenario template. The system allocates a unique identifier for each task, records the basic attributes of the task, such as task name, belonging scenario, estimated execution time, and the like, and initializes the execution state of the task as "not started", and prepares for subsequent task execution.

[0063] S52, main task control link, the steering officer performs opening, pausing, continuing, backing up, restoring and the like on the main task through the system operation interface. When the task is opened, the system checks whether the task precondition is met, such as whether the related resources are ready, whether the dependent environment is built, and the like; when the task is paused, the system records the current task execution progress and state information, and ensures that the task can continue to be normally executed when the task is resumed later; the task data is backed up to prevent data loss, and facilitate backtracking and analysis when problems occur.

[0064] S53, subtask management aspect, the steering officer can dynamically issue subtasks to the testers according to the test requirements. In the task execution process, if it is found that the test content needs to be supplemented, the subtask can also be added; for the issued subtask that is unreasonable, the editing or deleting operation can be performed. When the subtask is issued, the system pushes the task details to the corresponding tester, and updates the task state.

[0065] ​S54 Real-time Monitoring of Host Resource Utilization: The system continuously collects host resource utilization data, including CPU, memory, and hard disk utilization. The collection frequency can be configured according to actual needs. The collected data is displayed in real-time on a line graph on the monitoring interface, allowing the administrator to intuitively view resource usage trends. If abnormal fluctuations in resource utilization occur, such as a sudden spike in CPU utilization exceeding a preset threshold, the system immediately triggers an emergency response mechanism. In other words, during real-time monitoring, the task scheduling subsystem can detect anomalies in the collected host information. When abnormal fluctuations in host resource utilization or a security event are detected, the emergency response mechanism is automatically triggered, suspending relevant tasks and notifying the administrator. During task execution, the task scheduling subsystem dynamically adds subtasks based on real-time monitored host resource utilization, task priority, and other factors. It compares the planned and actual task progress using a Gantt chart. When the actual progress lags behind, it automatically issues a warning and prompts adjustments to resource allocation or task order.

[0066] S55, Task Execution and Evaluation Phase: After receiving the task, the tester performs the testing operations according to the task requirements. Upon completion, the tester submits the test results, including test conclusions, test scores, and related reports. The system collects all test results, combines them with the evaluation model to comprehensively evaluate the results, and generates a detailed evaluation report. The report covers task completion status, network security effectiveness analysis, identified problems, and improvement suggestions. After the task is completed, the system archives and stores the task-related data for subsequent retrieval and auditing.

[0067] This invention also provides a network security testing and evaluation method, based on the system described above. The method includes the following steps:

[0068] Construct a test standard tree, define multi-dimensional test metrics, and add corresponding test dimensions and test types at different levels of the test standard tree according to different test objectives and scenarios;

[0069] Based on artificial intelligence, an evaluation model is generated by associating test cases and rules in the test script and using machine learning algorithms to learn from historical test data and relevant security knowledge to generate a targeted evaluation model.

[0070] Dynamically orchestrate virtual and physical test range scenarios, configure traffic simulation strategies, select appropriate virtualization devices and real physical devices to combine according to test requirements, and set corresponding traffic simulation parameters;

[0071] Issue main tasks and sub-tasks, monitor resource utilization in real time and adjust task priorities. During task execution, automatically increase or decrease the priority of certain tasks based on the real-time monitoring of resource utilization.

[0072] According to the evaluation model, a test report is automatically generated, the network security performance is analyzed, the test results are comprehensively evaluated, and a detailed test report is generated to provide a basis for network security improvement.

[0073] The following refers to Figure 6 A design flowchart of virtual-real combination in test identification of embodiments of the present application is described.

[0074] S61, the core purpose of this test identification is determined, for example, whether it is to detect the defense capability of network security equipment in a specific complex network environment or to evaluate the stability of a new network architecture when facing various attacks. According to the target, the specific test scene is determined, including network size, application type, potential attack means, etc., which provides direction for subsequent selection of appropriate equipment and environment building.

[0075] S62, analyze the scene requirements to determine the device type. Analyze the determined test scene requirements to determine which virtualized devices and real physical devices are needed. For virtualized devices, consider their performance, scalability, and other factors to select virtualization technologies such as virtual machines, containers, etc. that can meet the needs of simulating large-scale network nodes or specific network functions. For real physical devices, according to the requirements of key network components in the scene, determine the types of devices such as hardware firewalls, real servers, etc. to ensure that the selected devices can accurately simulate the key links in the real network environment.

[0076] S63, build and connect virtual-real devices. First, build a virtual network environment, create multiple virtual network nodes, and assign each node a specific network role such as client, server, etc. according to the test scene. Configure virtual network parameters, including IP address, subnet mask, routing rules, etc. to make the virtual network have complete network communication capabilities. After selecting the real physical devices, determine their access points in the virtual network and connect the real physical devices to the virtual network through network interfaces. After connection, perform connectivity testing to check if the virtual-real devices can communicate normally. If there are connection problems, troubleshoot and solve them to ensure stable connection of virtual-real devices.

[0077] S64, test execution and result output. After ensuring that the virtual-real devices are connected normally, configure network traffic according to the test plan to simulate normal business traffic and various attack traffic to comprehensively detect the performance and security of the network under different conditions. Start the test and monitor network data in real time, including network traffic, device status, security events, etc. During the test, continuously determine whether the test is complete. If not, continue monitoring. After the test is completed, collect and analyze test data to evaluate the performance of the network in a virtual-real combined environment and finally output the test identification results to provide a reliable basis for network security decision-making.

[0078] The following refers to Figure 7A design flowchart of the artificial intelligence generated evaluation model is described. As shown in Figure 7 The process includes:

[0079] S71, collect historical test data. Data is widely collected from past network security tests, covering different test scenarios, execution results of various test cases, relevant information of target systems, and corresponding security event records, etc. Data sources include but are not limited to previous test evaluation projects, logs of network security monitoring systems, etc. For example, data generated during network security tests on different military equipment, industrial control systems and enterprise networks is collected to ensure the diversity and comprehensiveness of the data, providing rich materials for subsequent model training.

[0080] S72, data cleaning and preprocessing. The collected historical test data is cleaned to remove duplicate, erroneous or incomplete data records to ensure data quality. Then preprocessing operations are performed, including data standardization to unify different magnitudes of data to the same scale for model learning; data encoding to convert non-numeric data into numeric data, such as converting descriptive information of test results into digital codes; and filling missing values by using mean, median or other statistical methods to supplement the missing parts of the data, making the data complete and usable, laying a good foundation for model training.

[0081] S73, associate test scripts and rules. The cleaned and preprocessed data is associated with test scripts and rules. The evaluation indicators and rules corresponding to each test case are determined, such as vulnerability scanning cases, and the evaluation criteria are determined according to the number of discovered vulnerabilities, severity, etc. These rules are integrated into the data so that the model can learn the relationship between test cases and evaluation results, providing a basis for generating a reasonable evaluation model.

[0082] S74, model training, verification and optimization. Select a machine learning algorithm such as decision tree or neural network based on data characteristics and test requirements. Use the preprocessed data to train the selected algorithm, and continuously adjust the algorithm parameters to let the model learn the patterns and rules in the data to generate an initial evaluation model. Then the model is verified by testing a part of the data that did not participate in the training to evaluate the accuracy, recall rate and other indicators of the model. If the model does not meet the evaluation requirements, analyze the reasons, adjust the algorithm or parameters, and retrain and verify until the model reaches the expected evaluation effect. Finally, the optimized model is applied to actual network security test evaluation.

[0083] The application also provides a computer readable storage medium storing computer instructions for causing a processor to execute the above network security test evaluation method.

[0084] It should be noted that the above content is only the preferred embodiments of the present application, and the technical principles used are described. Those skilled in the art should understand that the present application is not limited to the specific embodiments listed here. In actual application scenarios, those skilled in the art can make various obvious changes, re-adjustments and alternative operations based on the technical solutions of the present application, and these operations will not deviate from the protection scope of the present application. Therefore, although the foregoing has described the present application in more detail through a plurality of embodiments, the scope of the present application is not limited to these shown embodiments. There are more equivalent embodiments without deviating from the core idea of the present application. The actual protection scope of the present application is ultimately determined by the scope of the appended claims.

Claims

1. A multi-dimensional network security test and evaluation system based on virtual-real fusion and dynamic guidance, characterized in that, Comprise: A test standard subsystem for creating and managing test standards based on a tree structure, supporting the import, export and state management of standards; A test script subsystem for arranging test cases and evaluation models, supporting dynamic copying, importing and exporting of scripts, and AI-driven model optimization; A scenario subsystem that generates network target scenarios through virtual-real integration technology, configures traffic simulation strategies and test seats, and realizes dynamic arrangement of scenario topology; A task scheduling subsystem that supports dynamic scheduling, suspension, resumption and real-time monitoring of main tasks and subtasks, and displays CPU, memory and hard disk utilization changes of hosts through line charts. 2.The multi-dimensional network security test and evaluation system based on virtual-real fusion and dynamic guidance according to claim 1, wherein, The test standard subsystem uses a tree structure to display the hierarchical relationship of standards, dimensions and types, supports state switching between draft, available and used states, and changes from draft state to available state when the standard meets the preset integrity and accuracy requirements. Used standards enter the used state, and used standards cannot be deleted or modified at will. 3.The multi-dimension network security test and evaluation system based on virtual-real fusion and dynamic guidance according to claim 1, wherein, During task execution, the task scheduling subsystem dynamically adds subtasks based on real-time monitored host resource utilization and task priority factors, and compares planned and actual task progress based on Gantt charts. When the actual progress lags behind, it automatically issues a warning and prompts to adjust resource allocation or task order.

4. The multi-dimensional network security test and evaluation system based on virtual-real fusion and dynamic guidance according to claim 1, characterized in that, The scenario subsystem includes a virtual-real integrated target environment construction module that simulates network attack and defense scenarios using virtualization devices and real physical devices. Virtualization devices are used to quickly build large-scale and diverse network nodes, while real physical devices are used to simulate key real environment components. Both work together to improve the realism of the scenario.

5. The multi-dimensional network security test and evaluation system based on virtual-real fusion and dynamic guidance according to claim 1, characterized in that, The evaluation model optimization process in the test script subsystem is based on deep learning algorithms, which automatically adjust the weights and parameters of the evaluation model to adapt to different test scenarios and target systems by learning from a large amount of historical test data.

6. The multi-dimensional network security test and evaluation system based on virtual-real fusion and dynamic guidance according to claim 1, characterized in that, During real-time monitoring, the task scheduling subsystem can detect abnormalities in collected host information. When it detects abnormal fluctuations in host resource utilization or security incidents, it automatically triggers an emergency response mechanism, suspends related tasks and notifies administrators.

7. The multi-dimensional network security test and evaluation system based on virtual-real fusion and dynamic guidance according to claim 1, characterized in that, When configuring traffic simulation strategies, the scenario subsystem supports rule-based traffic generation and machine learning-based traffic simulation, enabling the simulation of more realistic and complex network traffic, including normal business traffic and attack traffic. 8.The multi-dimensional network security test and evaluation system based on virtual-real fusion and dynamic guidance according to claim 1, wherein, When creating test standards, the test standard subsystem supports association and mapping with internationally and domestically recognized network security standards, ensuring the universality and compliance of test standards.

9. A multi-dimensional network security test and evaluation method based on virtual-real fusion and dynamic guidance, executed based on the multi-dimensional network security test and evaluation system based on virtual-real fusion and dynamic guidance according to any one of claims 1-8, characterized in that, The following steps are included: Build a test standard tree, define multi-dimensional test indicators, and add corresponding test dimensions and test types at different levels of the test standard tree according to different test targets and scenarios; Generate evaluation models based on artificial intelligence, associate use cases and rules in test scripts, and use machine learning algorithms to learn from historical test data and related security knowledge to generate targeted evaluation models; Dynamic arrangement of virtual-real fusion target range scene, configuration of traffic simulation strategy, selection of appropriate virtualization equipment and real physical equipment for combination according to test requirements, and setting of corresponding traffic simulation parameters; Distribute main tasks and subtasks, monitor resource utilization rate in real time and adjust task priority, and during task execution, automatically improve or reduce the priority of certain tasks according to the real-time monitored resource utilization rate; According to the evaluation model, a test report is automatically generated, the network security performance is analyzed, the test results are comprehensively evaluated, and a detailed test report is generated to provide a basis for network security improvement.

10. A computer readable storage medium characterized by The computer readable storage medium stores computer instructions for causing the processor to implement the multi-dimensional network security test identification method based on virtual-real fusion and dynamic guidance adjustment of claim 9 when executed.

Citation Information

Patent Citations

  • Target range construction method, apparatus and device, and storage medium

    CN112448857A

  • Use method of combat knowledge system and combat decision auxiliary method

    CN113255916A

  • Defense level measurement method and system for automatic arrangement of information security attack task, and storage medium

    CN116318840A

  • Virtual-real integrated management and control system and method based on Agent technology

    CN116431707A

  • Model training method, evaluation method, device, equipment and medium

    CN117312861A

Cited By

  • Mobile communication wireless network coverage real-time dynamic evaluation method and system

    CN122340516A