Network security test method, electronic device, medium and computer program product
Patent Information
- Application Number
- CN202410695870.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-05-30
- Publication Date
- 2025-12-02
Smart Images

Figure CN121056872A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network testing technology, and in particular to a network security testing method, electronic device, medium, and computer program product. Background Technology
[0002] With the popularization of mobile internet and the development of the Internet of Things (IoT), mobile communication has become an indispensable part of people's daily lives and work, and the security issues of mobile communication are increasingly attracting attention. Air interface attacks on wireless networks refer to attacks targeting the wireless transmission medium in wireless communication networks. This type of network attack utilizes the broadcast characteristics of wireless signals and potential security vulnerabilities to carry out its purpose. In wireless networks, the air interface refers to the wireless transmission medium between mobile devices (such as mobile phones, Wi-Fi devices, etc.) and wireless access points (such as base stations, routers, etc.). Distributed Denial-of-Service (DDoS) attacks are a common form of air interface attacks.
[0003] Due to the high traffic volume and highly distributed nature of wireless networks, attackers can utilize numerous mobile devices and wireless access points to launch attacks, making these attacks more difficult to detect and defend against. Therefore, mobile communication networks need to be tested for their ability to withstand distributed denial-of-service (DDoS) attacks before being put into operation. However, how to effectively simulate attacks on wireless networks for testing purposes remains a pressing problem in the industry. Summary of the Invention
[0004] This application provides a network security testing method, electronic device, medium, and computer program product, which aims to perform target simulation operations on target network devices through a target controlled device, thereby building a network security testing scenario to simulate a network attack on the target network, and then test the target network to help improve the network security detection and defense capabilities of the target network devices.
[0005] In a first aspect, embodiments of this application provide a network security testing method, the method comprising:
[0006] Obtain test scenario simulation instructions, and determine the target simulated operation and target controlled device based on the test scenario simulation instructions;
[0007] By performing the target simulation operation on the target network device through the target controlled device, a network security test scenario is established;
[0008] Based on the network security test scenario, a security test is conducted on the target network corresponding to the target network device, and a security test report of the target network under the network security test scenario is obtained.
[0009] Secondly, embodiments of this application provide an electronic device, including:
[0010] One or more processors;
[0011] A memory having stored one or more programs that, when executed by one or more processors, cause the one or more processors to implement the network security testing method described in the first aspect above.
[0012] Thirdly, embodiments of this application provide a computer-readable storage medium having a computer program stored thereon, wherein the program, when executed by a processor, implements the network security testing method described in the first aspect above.
[0013] Fourthly, embodiments of this application provide a computer program product, including a computer program that, when executed by a processor, implements the network security testing method described in the first aspect above.
[0014] The network security testing method provided in this application first obtains a test scenario simulation instruction, and determines the target simulated operation and the target controlled device based on the test scenario simulation instruction; then, it executes the target simulated operation on the target network device through the target controlled device to build a network security test scenario; further, it performs security testing on the target network device and the corresponding target network based on the network security test scenario to obtain a security test report of the target network under the network security test scenario. This application can build a network security test scenario by executing target simulated operations on the target network device through the target controlled device, thereby simulating the situation where the target network is subjected to network attacks, and then testing the target network to help improve the network security detection and network defense capabilities of the target network device. Attached Figure Description
[0015] The accompanying drawings are used to provide a further understanding of the technical solutions of this application and constitute a part of the specification. They are used together with the embodiments of this application to explain the technical solutions of this application and do not constitute a limitation on the technical solutions of this application.
[0016] Figure 1 This is a flowchart illustrating a network security testing method provided in an embodiment of this application;
[0017] Figure 2 This is another flowchart illustrating a network security testing method provided in an embodiment of this application;
[0018] Figure 3 This is another flowchart illustrating a network security testing method provided in an embodiment of this application;
[0019] Figure 4 This is another flowchart illustrating a network security testing method provided in an embodiment of this application;
[0020] Figure 5 This is another flowchart illustrating a network security testing method provided in an embodiment of this application;
[0021] Figure 6 This is another flowchart illustrating a network security testing method provided in an embodiment of this application;
[0022] Figure 7 This is another flowchart illustrating a network security testing method provided in an embodiment of this application;
[0023] Figure 8 This is another flowchart illustrating a network security testing method provided in an embodiment of this application;
[0024] Figure 9 This is another flowchart illustrating a network security testing method provided in an embodiment of this application;
[0025] Figure 10A This is another flowchart illustrating a network security testing method provided in an embodiment of this application;
[0026] Figure 10B A schematic diagram of a normal SRB1 channel MAC PDU message provided in an embodiment of this application;
[0027] Figure 10C A schematic diagram of an abnormal SRB1 channel MAC PDU message provided in an embodiment of this application;
[0028] Figure 10D A schematic diagram of a normal MAC PDU message provided in an embodiment of this application;
[0029] Figure 10E A schematic diagram of an abnormal MAC PDU message provided in an embodiment of this application;
[0030] Figure 11A This is a schematic block diagram of the structure of a terminal provided in an embodiment of this application;
[0031] Figure 11B This is a schematic block diagram of a scheduling processing component provided in an embodiment of this application;
[0032] Figure 12 This is a schematic diagram of the device structure of the electronic device provided in the embodiments of this application. Detailed Implementation
[0033] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.
[0034] It should be understood that in the description of the embodiments of this application, the use of terms such as "first" and "second" is only for the purpose of distinguishing technical features and should not be construed as indicating or implying relative importance, or implicitly indicating the number of technical features indicated, or implicitly indicating the order of the technical features indicated. "At least one" refers to one or more, and "more" refers to two or more. "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent the existence of A alone, the simultaneous existence of A and B, or the existence of B alone. A and B can be singular or plural. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship. "At least one of the following" and similar expressions refer to any group of these items, including any group of singular or plural items. For example, at least one of a, b, and c can represent: a, b, c, a and b, a and c, b and c, or a and b and c, where a, b, and c can be single or multiple.
[0035] Furthermore, the technical features involved in the various embodiments of this application described below can be combined with each other as long as they do not conflict with each other.
[0036] To facilitate understanding of the solutions in the embodiments of this application, and to ensure that the descriptions of the following embodiments are clear and concise, a brief introduction to the relevant technologies is given first:
[0037] With the popularization of mobile internet and the development of the Internet of Things (IoT), mobile communication has become an indispensable part of people's daily lives and work, and the security issues of mobile communication are increasingly attracting attention. Air interface attacks on wireless networks refer to attacks targeting the wireless transmission medium in wireless communication networks. This type of network attack utilizes the broadcast characteristics of wireless signals and potential security vulnerabilities to carry out its purpose. In wireless networks, the air interface refers to the wireless transmission medium between mobile devices (such as mobile phones, Wi-Fi devices, etc.) and wireless access points (such as base stations, routers, etc.). Distributed Denial-of-Service (DDoS) attacks are a common form of air interface attacks.
[0038] Due to the high traffic volume and highly distributed nature of wireless networks, attackers can utilize numerous mobile devices and wireless access points to launch attacks, making these attacks more difficult to detect and defend against. Therefore, mobile communication networks need to be tested for their ability to withstand distributed denial-of-service (DDoS) attacks before being put into operation. However, how to effectively simulate attacks on wireless networks for testing purposes remains a pressing problem in the industry.
[0039] This application provides a network security testing method, electronic device, medium, and computer program product, which aims to perform target simulation operations on target network devices through a target controlled device, thereby building a network security testing scenario to simulate a network attack on the target network, and then test the target network to help improve the network security detection and defense capabilities of the target network devices.
[0040] The following explanation is based on the accompanying drawings.
[0041] Reference Figure 1 This application provides a network security testing method, which can be applied to a terminal. The network security testing method of this application may include, but is not limited to:
[0042] Step S101: Obtain the test scenario simulation command, and determine the target simulation operation and the target controlled device according to the test scenario simulation command;
[0043] Step S102: Perform target simulation operations on the target network device through the target controlled device to build a network security test scenario;
[0044] Step S103: Based on the network security test scenario, perform security tests on the target network device and the corresponding target network to obtain a security test report of the target network under the network security test scenario.
[0045] The network security testing method provided by steps S101 to S103 of this application embodiment first obtains a test scenario simulation instruction, and determines the target simulation operation and the target controlled device based on the test scenario simulation instruction; wherein, the test scenario simulation instruction is used to instruct the simulation construction of a test scenario for the target network; then, the target controlled device performs target simulation operations on the target network device to build a network security test scenario; wherein, the target network device is used to maintain the operation of the target network; further, based on the network security test scenario, a security test is performed on the target network corresponding to the target network device to obtain a security test report of the target network under the network security test scenario. This application can build a network security test scenario by performing target simulation operations on the target network device through the target controlled device, thereby simulating the situation where the target network is subjected to network attacks, and then testing the target network to help improve the network security detection and network defense capabilities of the target network device.
[0046] In step S101 of some embodiments, a test scenario simulation instruction is obtained, and the target simulation operation and target controlled device are determined according to the test scenario simulation instruction; wherein, the test scenario simulation instruction is used to instruct the simulated construction of a test scenario for the target network. It should be noted that the network security testing method of this application embodiment aims to simulate a network attack on the target network, and then test the target network. Therefore, the test scenario simulation instruction is used to instruct the simulated construction of a test scenario for the target network. The corresponding target simulation operation and target controlled device can be determined according to the scenario simulation instruction. It should be pointed out that the target simulation operation is the operation that needs to be performed on the target network in order to simulate a security test scenario; the target controlled device is the controlled device that performs the target simulation operation in order to simulate a security test scenario, and the target controlled device is a device used to simulate an abnormal connection to the target network.
[0047] It is understandable that there are many ways to obtain simulated commands in test scenarios. For example, they can be obtained through input devices such as keyboards, mice, and touch screens, or through wired or wireless data transmission.
[0048] Reference Figure 2 According to some embodiments provided in this application, obtaining the test scenario simulation instruction in step S101 may include, but is not limited to:
[0049] Step S201: Display the configuration operation interface;
[0050] Step S202: In response to the input from the target object on the configuration operation interface, obtain the scene simulation configuration parameters;
[0051] Step S203: Based on the scenario simulation configuration parameters, generate test scenario simulation instructions for the target network.
[0052] In some embodiments of this application, steps S201 to S203 can be used to first display a configuration operation interface, and then, in response to the input from the target object on the configuration operation interface, obtain scenario simulation configuration parameters. Based on the scenario simulation configuration parameters, a test scenario simulation command for the target network can be generated. It should be noted that the target object can refer to a user who initiates a security test scenario simulation for the target network. It should be clarified that a user interface (UI) is the interface for communication and interaction between a person and a computer system. It includes the screen, pages, and controls and visual elements that the user can see and interact with the system. It should be understood that the configuration operation interface is a user interface used to receive input from the target object.
[0053] In some embodiments of this application, the target object can be input in the configuration operation interface. By specifying the type of target simulation operation, the target controlled device participating in the scenario simulation, the number of target controlled devices, and the time interval of the scenario simulation or other types of scenario simulation configuration parameters, test scenario simulation instructions for the target network are generated.
[0054] As illustrated in steps S201 to S203, scenario simulation configuration parameters can be obtained through a configuration interface, and then test scenario simulation instructions for the target network can be generated based on these parameters. This provides a convenient reference benchmark for building network security test scenarios, contributing to the efficient implementation of network security testing methods.
[0055] In some other embodiments, after obtaining the security test report of the target network in the network security test scenario, it can also be displayed in the user interface for evaluation and analysis of the results of this security test scenario simulation.
[0056] Reference Figure 3 According to some embodiments provided in this application, the step S101 of determining the target simulation operation and the target controlled device based on the test scenario simulation command may include, but is not limited to:
[0057] Step S301: Based on the test scenario simulation instructions, determine the controlled device identification information and controlled device operation information that match the network security test scenario;
[0058] Step S302: Determine the target controlled device for building the network security test scenario from the target network based on the controlled device identification information;
[0059] Step S303: Based on the controlled device operation information, determine the target simulated operation performed by the target controlled device in the network security test scenario from the target network operation data.
[0060] It should be noted that the test scenario simulation command is used to instruct the simulation setup of a test scenario for the target network. This can specifically include information such as the type of target simulation operation, the target controlled devices participating in the scenario simulation, the number of target controlled devices, and the time interval for the scenario simulation. Based on the test scenario simulation command, the controlled device identification information and controlled device operation information matching the network security test scenario can be determined. The controlled device identification information is a unique identifier for the target controlled device. When the controlled device identification information matches the network security test scenario, the target controlled device pointed to by that identification information in the target network is used to participate in the simulation setup of the network security test scenario. The controlled device operation information is used to configure the target simulation operations that the target controlled device needs to perform. Therefore, based on the controlled device operation information, it can be determined that the target controlled device is the target simulation operation to be performed in the simulated network security test scenario.
[0061] In this way, through the steps shown in steps S301 to S303, the target controlled device that needs to participate in the simulated network security test scenario can be clearly identified, as well as the target simulated operation that the target controlled device needs to perform, which helps to efficiently build the network security test scenario.
[0062] Reference Figure 4 According to some embodiments provided in this application, the test scenario simulation instruction includes scenario simulation type information, device configuration parameters, and operation simulation frequency. Step S301 determines the controlled device identification information and controlled device operation information matching the network security test scenario based on the test scenario simulation instruction, which may include, but is not limited to:
[0063] Step S401: Determine the simulation scenario mode corresponding to the test scenario simulation instruction based on the scenario simulation type information in the test scenario simulation instruction;
[0064] Step S402: Based on the simulation scenario method and operation simulation frequency, obtain the controlled device identification information and controlled device operation information that match the device configuration parameters from the scenario database.
[0065] It should be noted that the test scenario simulation instruction includes scenario simulation type information, device configuration parameters, and operation simulation frequency. The scenario simulation type information indicates the type of network security test scenario to be simulated; the device configuration parameters refer to the configuration parameters of the target controlled device; and the operation simulation frequency corresponds to the frequency at which the target controlled device performs the target simulated operation. The shorter the time interval between two target simulated operations, the higher the operation simulation frequency. Based on this, in this embodiment, the simulation scenario method corresponding to the test scenario simulation instruction can be determined based on the scenario simulation type information in the test scenario simulation instruction, thereby determining the specific method by which the target controlled device performs the target simulated operation. Then, based on the simulation scenario method and operation simulation frequency, controlled device identification information and controlled device operation information matching the device configuration parameters are obtained from the scenario database. The controlled device identification information is used to clarify which target controlled devices need to perform the target simulated operation, and the controlled device operation information is used to clarify the specific operation that the target controlled device needs to perform and the corresponding operation frequency. The scenario database refers to a pre-set database used to store various device identification information and device operation information. Each type of network security test scenario stores corresponding device identification information and device operation information in the scenario database. Therefore, based on the simulation scenario method and operation simulation frequency, the controlled device identification information and controlled device operation information that match the device configuration parameters can be obtained from the scenario database.
[0066] Through the embodiments shown in steps S401 to S402, based on the scenario simulation type information, device configuration parameters, and operation simulation frequency in the test scenario simulation command, the controlled device identification information matching the device configuration parameters is obtained. The specific method by which the target controlled device performs the target simulation operation is determined, resulting in a simulation scenario method. Furthermore, based on the simulation scenario method and operation simulation frequency, corresponding controlled device operation information is configured for the controlled device identification information. In this way, the test scenario simulation command can be explicitly transformed into a command to directly control the target controlled device, enabling the target controlled device to perform target simulation operations on the target network device, thereby building a network security test scenario to simulate a network attack on the target network.
[0067] In some embodiments, step S102 involves performing target simulation operations on a target network device using a target controlled device to establish a network security test scenario; wherein the target network device is used to maintain the operation of the target network. It should be noted that the target network is the network used as the test target, and the target network is maintained and operated by the target network device. Specifically, the target network device, as the operating and maintenance device of the target network, is responsible for the transmission and reception of wireless signals, resource management, mobility management, connection establishment and maintenance, data transmission, signal coverage, quality control, security control, billing and authentication, network operation support, emergency services, and network function integration within the target network, ensuring that users of the target network can obtain stable, secure, and efficient communication services. In this embodiment, performing target simulation operations on the target network device using a target controlled device aims to interfere with the target network device's role in maintaining the target network, thereby establishing a network security test scenario to simulate a network attack on the target network. It should be understood that the target network device can be a base station responsible for providing wireless access, managing wireless resources, supporting mobility, and ensuring data transmission and communication quality.
[0068] In some embodiments provided in this application, the types of network security testing scenarios are diverse, including but not limited to connection request overload, connection resource exhaustion, and simulated abnormal data messages. It should be noted that connection request overload, connection resource exhaustion, and simulated abnormal data messages can all be used to simulate denial-of-service (DoS) attacks against wireless communication networks. They exhaust network resources in different ways, causing legitimate users of the target network to be unable to obtain the services they need.
[0069] Connection request overload, also known as a flooding attack, is an attack method that overwhelms network or system resources by sending a large amount of traffic or requests to network devices. The goal of this type of network attack is to render network services unavailable, as it exhausts bandwidth, processing power, or storage space. In wireless networks, connection request overload may target base stations or the core network by sending a large number of meaningless signals or data packets.
[0070] Connection resource exhaustion. This type of cyberattack focuses on depleting the Radio Resource Control (RRC) connection resources in a wireless communication network. RRC connections are a critical component of the 3GPP standard used to manage communication between user equipment and the network, responsible for the transmission of signaling and control information. Attackers send a large number of RRC connection requests without completing the connection establishment process, causing the base station to continuously allocate resources for these incomplete connections, eventually exhausting the RRC connection resources and preventing legitimate users from establishing new RRC connections.
[0071] Abnormal data packets are simulated messages. These involve sending malformed or anomalous data packets to the network. These packets may be of incorrect length, of unknown type, or contain illegal information. Base stations need to process these packets, but because they do not conform to protocol specifications, processing them consumes additional resources and may lead to errors or service interruptions. Attackers may exploit this to launch attacks, sending a large number of abnormal packets to overwhelm the base station's processing capacity and thus disrupt normal service.
[0072] These three network attack methods aim to overload network resources and affect the normal operation of the network through different means. The network security testing method of this application embodiment can test the performance of the target network in the above three network security testing scenarios, thereby obtaining the corresponding security test report of the target network in the network security testing scenarios, so as to take corresponding security measures, such as enhancing network monitoring, implementing traffic filtering, and optimizing resource management, to defend against these network attacks and protect the stability and reliability of the target network.
[0073] In related technologies, how to effectively simulate attacks on wireless networks for testing mobile communication networks remains a challenge. This application, however, utilizes a controlled target device to perform simulated operations on target network devices, creating a network security test scenario to simulate a network attack on the target network. This allows for testing of the target network and helps improve the network security detection and defense capabilities of the target network devices.
[0074] In this embodiment of the application, to clearly illustrate how the network security testing scenario is set up, the following provides some standard protocol flows of wireless communication networks:
[0075] S1. If the target controlled device needs to establish a connection with the target network, it will initiate a random access procedure by sending a preamble sequence to the target network device.
[0076] S2. After receiving the preamble sequence, if resources permit, the target network device will send a random access response to the target controlled device, which includes uplink and downlink resource allocation information.
[0077] S3. The target controlled device uses the resources allocated in the random access response to send a connection request message to the target network device to request the establishment of a connection;
[0078] S4. After the target network device processes the connection request, if it accepts the request, it will send a connection establishment message to the target controlled device, which includes the connection configuration information.
[0079] S5. The target network device initiates integrity protection and encryption mechanisms to ensure communication security;
[0080] S6. The target network device sends an authentication request to the target controlled device, and the target controlled device replies with an authentication response. The core network then performs authentication. The core network is the central part of the target network, responsible for handling major network management and data transmission functions. As the brain of the target network, it connects the wireless access network to external networks, such as the Internet, other telecommunications networks, and the networks of various service providers.
[0081] S7. After successful authentication, the target network device sends an attach accept message to the core network, and the core network sends an attach complete message to the target controlled device.
[0082] S8. After the connection between the target controlled device and the target network is established, the target controlled device can begin to transmit data to the target network;
[0083] Throughout the standard protocol process of the aforementioned wireless communication network, communication between the target controlled device and the target network device follows strict timing and protocol specifications to ensure that the connection establishment is secure and effective. The purpose of the normal connection process is to ensure that the target controlled device can successfully access the network and begin communication.
[0084] Reference Figure 5 According to some embodiments provided in this application, when it is determined that the target simulation operation corresponds to connection request overload, the target network device can be subjected to the target simulation operation in the following manner:
[0085] Step S501: Modify the network connection memory variable of the target controlled device to set the connection acknowledgment message of the target controlled device to a rejected state;
[0086] Step S502: Re-initiate a network connection request from the target controlled device to the target network device corresponding to the test scenario simulation command, and receive the connection establishment information from the target network device in response to the network connection request;
[0087] Step S503: Based on the connection confirmation message and connection establishment information in the rejection state, control the target controlled device to refuse to reply to the connection establishment information, and return to execute to re-initiate a network connection request to the target network device corresponding to the test scenario simulation command through the target controlled device, thereby obtaining the network security test scenario.
[0088] It is important to emphasize that connection request overload is an attack method that overwhelms network or system resources by sending a large amount of traffic or requests to network devices. The purpose of this type of network attack is to render network services unavailable, as it exhausts bandwidth, processing power, or storage space. In wireless networks, connection request overload may target base stations or the core network, achieved by sending a large number of meaningless signals or data packets.
[0089] In some embodiments, step S501 modifies the network connection memory variable of the target controlled device to set the connection acknowledgment message of the target controlled device to a rejected state. It should be noted that modifying the network connection memory variable of the target controlled device to set the connection acknowledgment message of the target controlled device to a rejected state means that after the target network device sends a random access response to the target controlled device, the target controlled device will not send an acknowledgment message to complete the normal connection establishment process.
[0090] In some more specific embodiments, the network connection memory variable of the target controlled device is modified to set the connection acknowledgment message of the target controlled device to a rejected state. This can be achieved by modifying the RRC Connection memory variable as follows: "ACK message = rejected state".
[0091] In some embodiments, steps S502 to S504 involve re-initiating a network connection request from the target controlled device to the target network device corresponding to the test scenario simulation command, and receiving connection establishment information from the target network device in response to the network connection request. Based on the connection confirmation message and connection establishment information in the rejection state, the target controlled device is controlled to refuse to reply with connection establishment information, and the process returns to re-initiating a network connection request from the target controlled device to the target network device corresponding to the test scenario simulation command, thus obtaining the network security test scenario. It should be noted that because the target controlled device initiating the network connection request has undergone modification of its network connection memory variables, it will be controlled to refuse to reply with connection establishment information based on the connection confirmation message and connection establishment information in the rejection state. Afterwards, the process returns to re-initiating a network connection request from the target controlled device to the target network device corresponding to the test scenario simulation command, thus obtaining the network security test scenario.
[0092] In some embodiments of this application, because the connection confirmation message of the target controlled device is set to a rejected state, after the target network device sends a random access response to the target controlled device, the target controlled device will not send an confirmation message to complete the normal connection establishment process. The target network device will then actively release the previously received network connection request after waiting for a period of time. Based on this, in embodiments of this application, after the target controlled device refuses to reply to the connection establishment information, it re-initiates a network connection request to the target network device. The target network device then needs to process the newly initiated network connection request while waiting to release the previous network connection request. As a result, if the number of newly initiated network connection requests exceeds the number of network connection requests waiting to be released, the target network device will enter a state of connection request overload. Based on this implementation method, embodiments of this application can construct a network security test scenario corresponding to connection request overload, so as to conduct security testing on the target network corresponding to the target network device and obtain a security test report of the target network under the network security test scenario.
[0093] In some specific embodiments provided in this application, the target simulated operation corresponds to connection request overload. Only when the target controlled device meets a first preset condition can the target controlled device be controlled to stop initiating network connection requests to the target network device, thus terminating the setup of the network security test scenario. It should be noted that the first preset condition is used to define that the target controlled device has met the conditions for terminating the setup of the network security test scenario. For example, if the target controlled device receives a target simulated operation stop command and determines that the first preset condition is met, it can stop initiating network connection requests to the target network device, thus terminating the setup of the network security test scenario. It should be understood that there are various optional embodiments in which the target controlled device meets the first preset condition, and these are not limited to the examples described above.
[0094] Through steps S501 to S504, a network security test scenario can be built to simulate the target network encountering connection request overload under the condition that the target simulated operation corresponds to connection request overload, thereby testing the target network and helping to improve the network security detection and network defense capabilities of the target network device.
[0095] Reference Figure 6 According to some embodiments provided in this application, when it is determined that the target simulation operation corresponds to the exhaustion of connection resources, the target simulation operation is performed on the target network device in the following manner:
[0096] Step S601: Modify the authentication memory variable of the target controlled device to set the authentication confirmation message of the target controlled device to a rejected state;
[0097] Step S602: Re-initiate a network connection request from the target controlled device to the target network device corresponding to the test scenario simulation command, and receive the connection establishment information from the target network device in response to the network connection request;
[0098] Step S603: Generate connection confirmation information corresponding to the connection establishment information based on the connection establishment information, and send the connection confirmation information to the target network device;
[0099] Step S604: Obtain the authentication request in response to the connection confirmation information of the target network device through the target controlled device; based on the authentication confirmation message in the rejection state, control the target controlled device to refuse to reply to the authentication request; return to execute the network connection request to the target network device to obtain the network security test scenario.
[0100] It is important to emphasize that connection resource exhaustion is a type of network attack that focuses on depleting the Radio Resource Control (RRC) connection resources in a wireless communication network. RRC connections are a critical component of the 3GPP standard used to manage communication between user equipment and the network, responsible for the transmission of signaling and control information. Attackers send a large number of RRC connection requests without completing the connection establishment process, causing the base station to continuously allocate resources for these incomplete connections, ultimately exhausting the RRC connection resources and preventing legitimate users from establishing new RRC connections.
[0101] In some embodiments, step S601 modifies the authentication memory variable of the target controlled device to set the authentication confirmation message of the target controlled device to a rejected state. It should be noted that modifying the authentication memory variable of the target controlled device to set the authentication confirmation message of the target controlled device to a rejected state means that after the target network device sends an authentication request to the target controlled device, the target controlled device will, based on the rejected authentication confirmation message, control the target controlled device to refuse to reply to the authentication request, thereby not sending an authentication response to the core network of the target network to complete authentication.
[0102] In some more specific embodiments, the authentication memory variable of the target controlled device is modified to set the authentication acknowledgment message of the target controlled device to a rejected state. This can be achieved by modifying the Authentication memory variable as follows: "ACK message = rejected state".
[0103] In some embodiments, steps S602 to S604 involve re-initiating a network connection request from the target controlled device to the target network device corresponding to the test scenario simulation command, receiving connection establishment information from the target network device in response to the network connection request, generating connection confirmation information corresponding to the connection establishment information based on the connection establishment information, and sending the connection confirmation information to the target network device. This means that a connection has been established between the target controlled device and the target network device. Based on this, the target controlled device further obtains the authentication request from the target network device in response to the connection confirmation information, and, based on the authentication confirmation message in a rejected state, controls the target controlled device to refuse to reply to the authentication request, returning to initiating a network connection request to the target network device, thus obtaining the network security test scenario. It should be noted that, since the target controlled device initiating the network connection request has modified its authentication memory variables, after obtaining the authentication request, and after the target network device sends the authentication request to the target controlled device, the target controlled device will refuse to reply to the authentication request based on the authentication confirmation message in a rejected state. After that, it will return to execute and re-initiate a network connection request to the target network device corresponding to the test scenario simulation command through the target controlled device, thus obtaining the network security test scenario.
[0104] In some embodiments of this application, because the authentication confirmation message of the target controlled device is set to a rejected state, after a connection is established between the target controlled device and the target network device, the target network device sends an authentication request to the target controlled device. However, the target controlled device, based on the rejected authentication confirmation message, refuses to reply to the authentication request and cannot complete the normal authentication process. After waiting for a period of time, the target network device will actively release the connection previously established with the network controlled device. Based on this, in the embodiments of this application, after the target controlled device refuses to reply to the authentication request, it re-initiates a network connection request to the target network device to establish a new connection. The target network device then needs to process the newly initiated network connection request while waiting to release the previous connection to establish a new connection. As a result, if the number of newly established connections exceeds the number of connections waiting to be released, the target network device will enter a state of connection resource exhaustion. Based on this implementation method, the embodiments of this application can construct a network security test scenario corresponding to connection resource exhaustion, so as to conduct security testing on the target network corresponding to the target network device and obtain a security test report of the target network under the network security test scenario.
[0105] In some specific embodiments provided in this application, the target simulated operation corresponds to the exhaustion of connection resources. Only when the target controlled device meets a second preset condition can the target controlled device be controlled to stop initiating network connection requests to the target network device, thus terminating the setup of the network security test scenario. It should be noted that the second preset condition is used to define whether the target controlled device has met the conditions for terminating the setup of the network security test scenario. For example, if the target controlled device receives a target simulated operation stop command and determines that the second preset condition is met, it can stop initiating network connection requests to the target network device, thus terminating the setup of the network security test scenario. It should be understood that there are various optional embodiments in which the target controlled device meets the second preset condition, and these are not limited to the examples described above.
[0106] Through steps S601 to S604, a network security test scenario can be built to simulate the situation where the target network encounters a situation where connection resources are exhausted, thereby testing the target network and helping to improve the network security detection and network defense capabilities of the target network devices.
[0107] Reference Figure 7 According to some embodiments provided in this application, if a first number of target controlled devices initiate network connection requests in the same request time slot, step S602 re-initiates a network connection request through the target controlled device to the target network device corresponding to the test scenario simulation command, and receives connection establishment information from the target network device in response to the network connection request. This may include, but is not limited to:
[0108] Step S701: For the first number of target controlled devices after modifying the authentication memory variables, determine the preamble sequence of each target controlled device in the request time slot, so that the preamble sequence corresponding to each target controlled device is different.
[0109] In step S702, each target controlled device initiates a network connection request to the target network device based on the corresponding preamble sequence.
[0110] It should be noted that, in this embodiment, since the first number of target controlled devices initiate network connection requests within the same request time slot, conflicts and resource contention may occur among these target controlled devices. It should be understood that a request time slot refers to the time period during which a target controlled device initiates a network connection request.
[0111] Based on this, steps S701 to S702 require determining the preamble sequence for each of the first number of target controlled devices after modifying the authentication memory variables, ensuring that the preamble sequence for each target controlled device is unique. Furthermore, each target controlled device initiates a network connection request to the target network device based on its corresponding preamble sequence. This improves the success rate of concurrent random access attempts by multiple target controlled devices, preventing conflicts and resource contention caused by multiple target controlled devices using the same preamble sequence.
[0112] Reference Figure 8 According to some embodiments provided in this application, step S701, for the first number of target controlled devices after modifying the authentication memory variable, determines the preamble sequence of each target controlled device in the requested time slot, which may include, but is not limited to:
[0113] Step S801: Obtain a sequence index set including a second number of leader sequence indices; wherein, the leader sequence index is used to query candidate leader sequences;
[0114] Step S802: Determine the device number corresponding to each target controlled device from the first number of target controlled devices;
[0115] Step S803: For each target controlled device, perform a modulo operation based on the device number and the second number to obtain the index number. Based on the index number, select the corresponding leader sequence index from the sequence index set, and configure the corresponding leader sequence for the target controlled device from the candidate leader sequences according to the leader sequence index.
[0116] It should be noted that, for the first number of target controlled devices after modifying the authentication memory variables, the preamble sequence index is used to determine the preamble sequence for each target controlled device in the request time slot, ensuring that the preamble sequence for each target controlled device is unique. Specifically, for the first number of target controlled devices initiating network connection requests in the same request time slot, the unique preamble sequence index PreambleIndex for each target controlled device is calculated, which can be expressed as:
[0117] PreambleIndex=(Count[Slot]+1)mod PreambleID
[0118] Here, S lot represents the slot number of the requested slot, and each S lot has a unique sequence number.
[0119] Count[S lot] is used to record the number of UEs that send random access requests (Msg1) on a specific S lot. This counter starts from 0 and counts independently for each S lot to ensure that each device uses a different preamble sequence index under the same request slot.
[0120] Preamb leID represents the set of available leader sequence indices. The leader sequence index ranges from 0 to the total number of leader sequences, i.e., the second number.
[0121] By determining the preamble sequence index for each target controlled device in the requested time slot, it is possible to ensure that each target controlled device obtains a unique preamble sequence index even under high load conditions. Based on this, the embodiments of this application improve the success rate of contention-based access when multiple target controlled devices simultaneously initiate random access, and avoid multiple target controlled devices using the same preamble sequence, which could lead to conflicts and resource contention.
[0122] Reference Figure 9 According to some embodiments provided in this application, when it is determined that the target simulation operation corresponds to an abnormal data simulation packet, the target network device is subjected to the target simulation operation in the following manner:
[0123] Step S901: Modify the channel memory variable of the target controlled device to set the channel transmission message of the target controlled device to an abnormal state;
[0124] Step S902: Re-establish connection between the target controlled device and the target network device corresponding to the test scenario simulation command; wherein, the data transmission between the target controlled device and the target network device is constrained by the data transmission protocol;
[0125] Step S903: Based on the channel transmission message in the abnormal state, generate simulated transmission data that does not conform to the data transmission protocol, and send the simulated transmission data to the target network device with which the connection has been established through the target controlled device, so that the target network device will identify the simulated transmission data as abnormal data and discard it, and return to execute the channel transmission message based on the abnormal state to generate simulated transmission data that does not conform to the data transmission protocol, thus obtaining the network security test scenario.
[0126] It is important to emphasize that abnormal data packet simulation involves sending malformed or anomalous data packets to the network. These anomalous data packets may be of incorrect length, of unknown type, or contain illegal information. Base stations need to process these packets, but because they do not conform to protocol specifications, processing consumes additional resources and may lead to errors or service interruptions. Attackers could exploit this to launch attacks, sending a large number of abnormal packets to overwhelm the base station's processing capacity, thereby affecting normal service.
[0127] In some embodiments, step S901 modifies the channel memory variable of the target controlled device to set the channel transmission message of the target controlled device to an abnormal state. It should be noted that modifying the channel memory variable of the target controlled device to set the channel transmission message of the target controlled device to a rejected state means that after the target controlled device establishes a connection with the target network device, the target controlled device will send simulated transmission data to the established target network device and send simulated transmission data to the target network device, thereby affecting the normal service of the target network.
[0128] In some specific embodiments, the channel memory variable of the target controlled device is modified to set the channel transmission message of the target controlled device to an abnormal state. This can be achieved by modifying the SRB1 memory variable as follows: "DATA message = Abnormal state". Here, SRB1 (Signaling Radio Bearer 1) is a radio bearer defined in the 3GPP standard for carrying signaling. When the SRB1 memory variable is modified to "DATA message = Abnormal state", the target network device will recognize the abnormal SRB1 channel message length and discard it.
[0129] In some embodiments, steps S902 to S903 involve re-establishing a connection between the target controlled device and the target network device corresponding to the test scenario simulation command; wherein, data transmission between the target controlled device and the target network device is constrained by a data transmission protocol. Further, after the connection is established between the target controlled device and the target network device, simulated transmission data that does not conform to the data transmission protocol is generated based on the channel transmission message in the abnormal state. This simulated transmission data is then sent from the target controlled device to the established target network device, causing the target network device to identify the simulated transmission data as abnormal data and discard it. The target network device then returns to execute the channel transmission message based on the abnormal state to generate simulated transmission data that does not conform to the data transmission protocol, thus obtaining the network security test scenario.
[0130] It should be noted that, because the target controlled device initiating the network connection request has modified its channel memory variables, after establishing a connection with the target network device, the target controlled device sends simulated transmission data to and from the target network device, causing the target network device to identify the simulated transmission data as abnormal and discard it. Subsequently, a new connection will be established between the target controlled device and the target network device corresponding to the test scenario simulation command, thus obtaining the network security test scenario.
[0131] In some embodiments of this application, since the channel transmission messages of the target controlled device are set to an abnormal state, simulated transmission data that does not conform to the data transmission protocol can be generated based on the abnormal channel transmission messages after a connection is established between the target controlled device and the target network device. Furthermore, the target controlled device sends the simulated transmission data to the target network device with the established connection. It should be emphasized that data transmission between the target controlled device and the target network device is constrained by the data transmission protocol. Therefore, if the target network device receives simulated transmission data that does not conform to the data transmission protocol, it will identify it as abnormal data and discard it, failing to complete the normal data transmission process. Subsequently, the target controlled device repeatedly generates simulated transmission data that does not conform to the data transmission protocol based on the abnormal channel transmission messages and sends the simulated transmission data to the target network device with the established connection. The target network device receives simulated transmission data that does not conform to the data transmission protocol from the target controlled device for a long time, requiring frequent processing of the simulated transmission data as abnormal data, thus wasting a large amount of network resources in the target network device. Based on this implementation method, the embodiments of this application can build a network security test scenario corresponding to the abnormal data simulation message, so as to conduct security tests on the target network device and the target network, and obtain a security test report of the target network under the network security test scenario.
[0132] In some specific embodiments provided in this application, the target simulated operation corresponds to an abnormal data simulation message. Only when the target controlled device meets a third preset condition can the target controlled device be controlled to stop sending simulated transmission data to the target network device, thus terminating the setup of the network security test scenario. It should be noted that the third preset condition is used to define whether the target controlled device has met the conditions for terminating the setup of the network security test scenario. For example, if the target controlled device receives a target simulated operation stop command and determines that the third preset condition is met, it can stop sending simulated transmission data to the target network device, thus terminating the setup of the network security test scenario. It should be understood that there are various optional embodiments in which the target controlled device meets the third preset condition, and these are not limited to the examples above.
[0133] Reference Figure 10A According to some embodiments provided in this application, the simulated transmission data includes a message length identifier bit and a logical channel identifier bit. The generation of simulated transmission data that does not conform to the data transmission protocol in step S903 may include, but is not limited to:
[0134] Step S1001: Determine the first constraint condition for the message length identifier bit and the second constraint condition for the logical channel identifier bit in the data transmission protocol;
[0135] Step S1002: Generate simulated transmission data such that the simulated transmission data does not satisfy the first constraint condition in the message length identifier bit, or such that the simulated transmission data satisfies the second constraint condition in the logical channel identifier bit.
[0136] It should be noted that in wireless communication networks, a MAC PDU (Medium Access Control Protocol Data Unit) is a unit for transmitting data between the MAC layer and the physical layer. In this embodiment, the simulated transmission data can be a MAC PDU message. It should be pointed out that the L bit (Length field) and LCID (Logical Channel ID) in the MAC PDU message are two key fields. The L bit can be the message length identifier bit for the simulated transmission data, and the LCID can be the logical channel identifier bit for the simulated transmission data. The data transmission protocol can be the transmission protocol followed when transmitting data using MAC PDU messages.
[0137] It should be clarified that the L bit is a field in the MAC PDU message used to indicate the length of the MAC PDU message. The value of the L bit represents the length of the payload (i.e., user data or control information) in the MAC PDU message, and the unit is usually bytes or bits, depending on the context. In some protocols, the maximum value of the L bit may be limited. For example, in LTE, the maximum value of the L bit is usually 65535, which means that the payload length of the MAC PDU message cannot exceed this value.
[0138] Reference Figure 10B This shows a normal SRB1 channel MAC PDU message. The reserved bits indicate the length (L), meaning certain bits in the MAC PDU message are reserved to indicate the number of bits occupied by the L bits (length field). The Logical Channel ID (LCID) is used to identify the logical channel to which the MAC PDU message belongs. The normal value of LCID is 1, corresponding to SRB1 (Signaling Radio Bearer 1), used to carry control signaling. When LCID is set to an abnormal value, the target network device will identify and discard these abnormal data packets.
[0139] Reference Figure 10C This shows an abnormal SRB1 channel MAC PDU message. The reserved bits indicating L-bit length refer to the reserved bits in the MAC PDU message used to indicate the length of the L-bit. The normal range for LCID is 0 to 32, which is the range of LCID values specified by the 3GPP standard. MTU (Maximum Transmission Unit) is the maximum data unit size that the network layer can process. In the MAC PDU message, the length of the L-bit should match the MTU size to ensure effective data transmission.
[0140] Based on this, the L bit of the MAC PDU message corresponds to the message length constraint in the data transmission protocol, and can be the first constraint.
[0141] It's important to clarify that LCID is a field in a MAC PDU message used to identify logical channels. In wireless communication, a physical channel can carry data from multiple logical channels. The LCID field distinguishes between different logical channels, ensuring data is correctly delivered to the target channel. Logical channels are divided into control channels (such as SRB1) and data channels (such as DRB). LCID helps differentiate between these different types of channels. LCID values typically range from 0 to 31, allowing for a maximum of 32 logical channels. Different LCID values correspond to different logical channels and different Quality of Service (QoS) requirements.
[0142] Reference Figure 10DThis shows a normal MAC PDU message. Reserved bits indicate the L-bit length; these bits are reserved to indicate the length of the L-bit payload. The Logical Channel ID (LCID) identifies the logical channel to which the MAC PDU message belongs. The normal range for LCID is 0 to 32, which corresponds to the range of logical channel IDs defined in the 3GPP standard. MTU defines the maximum packet size that the network layer can handle; common MTU values are 1400 or 1500 bytes.
[0143] Reference Figure 10E This indicates an abnormal MAC PDU message. The reserved bit indicates the L-bit length, i.e., the effective payload length of the message. Since the LCID value ranges from 0 to 32 in the 3GPP standard, 50 is an abnormal value for the LCID. The target network device will recognize and discard such a message. The abnormal value of the L bit is set to 65535, which far exceeds the normal MTU size and is a non-compliant length value, causing the base station to discard the message.
[0144] Based on this, the LCID value of the MAC PDU message corresponds to the constraint of the number of logical channels in the data transmission protocol, and can be the second constraint.
[0145] Furthermore, generating simulated transmission data such that the simulated transmission data exceeds 65535 in the L bit can determine that the simulated transmission data does not meet the first constraint condition in the message length identifier bit; or, generating simulated transmission data such that the simulated transmission data has a value of 50 in the LCID bit can determine that the simulated transmission data meets the second constraint condition in the logical channel identifier bit.
[0146] In some other more specific embodiments, sending simulated transmission data from the target controlled device to the target network device establishing the connection can be achieved by filling the LCID in the MAC PDU packet with an error. When the target controlled device fills the LCID in the MAC PDU packet with an error, the target network device will recognize the abnormal data packet and discard it.
[0147] According to some embodiments provided in this application, step S102, which involves performing target simulation operations on the target network device through the target controlled device to build a network security test scenario, may include, but is not limited to:
[0148] After each target simulation operation is executed, the execution count corresponding to the target simulation operation is updated;
[0149] Based on the updated number of executions, generate a network security test scenario.
[0150] It should be noted that after each simulated target operation is executed, the execution count is updated. This is to record and statistically analyze the execution count, facilitating the generation of a subsequent security test report. It should be pointed out that the network security test scenario simulates a network attack on the target network; therefore, the execution count simulates the number of times the target network is attacked. Based on the updated execution count, a network security test scenario is generated, designed to simulate a network security test scenario where the target network is subjected to multiple network attacks.
[0151] According to some embodiments provided in this application, a network security test scenario can be generated based on the updated number of executions, which may include, but is not limited to:
[0152] Starting from the execution of the target simulation operation, after each preset time interval, the number of executions updated during the preset time interval is counted to obtain intermediate simulation data;
[0153] Based on the intermediate simulation data corresponding to each preset time interval, a network security test scenario is generated.
[0154] It should be noted that since the execution count is used to simulate the number of times the target network is attacked, the intermediate simulation data refers to the number of times the target network is simulated to be attacked during the preset time interval. Based on the intermediate simulation data corresponding to each preset time interval, a network security test scenario is generated. The purpose is to statistically analyze the number of simulated network attacks on the target network at preset time intervals, and obtain the network security test scenario based on this.
[0155] In some embodiments of this application, after modifying the network connection memory variable of the target controlled device to set the connection confirmation message of the target controlled device to a rejected state, an AttckTimer can be set to start timing. Then, a network connection request is re-initiated through the target controlled device to the target network device corresponding to the test scenario simulation command, and connection establishment information in response to the network connection request is received from the target network device. Further, after obtaining the connection establishment information from the target network device, based on the rejected connection confirmation message and the connection establishment information, the target controlled device is controlled to refuse to reply with connection establishment information. At this time, the execution count of the target simulation operation is incremented by 1, and then execution returns to re-initiating a network connection request through the target controlled device to the target network device corresponding to the test scenario simulation command, thus obtaining the network security test scenario. The AttckTimer counts the accumulated execution count of the current target simulation operation every certain period of time, to facilitate the generation of a security test report in subsequent steps.
[0156] In some embodiments of this application, after modifying the authentication memory variable of the target controlled device to set the authentication confirmation message of the target controlled device to a rejected state, an AttckTimer timer can be set to start timing. Then, the target controlled device with the modified authentication memory variable initiates a network connection request to the target network device corresponding to the test scenario simulation command at regular intervals; or, multiple target controlled devices with modified authentication memory variables sequentially initiate a network connection request to the target network device corresponding to the test scenario simulation command at predetermined time intervals. Further, after obtaining the authentication request sent by the target network device, based on the rejected authentication confirmation message, the target controlled device is controlled to refuse to reply to the authentication request. At this time, the execution count of the target simulation operation is incremented by 1, and then execution returns to re-initiate a network connection request to the target network device corresponding to the test scenario simulation command through the target controlled device, thus obtaining the network security test scenario. The AttckTimer timer counts the current accumulated execution count of the target simulation operation at regular intervals to facilitate the generation of a security test report in subsequent steps.
[0157] In some embodiments, step S103 involves performing security tests on the target network device and its corresponding target network based on a network security testing scenario, thereby obtaining a security test report for the target network under the network security testing scenario. It should be noted that security testing of the target network can only be conducted after the network security testing scenario has been established, thus obtaining a security test report for the target network under the network security testing scenario to test the target network's performance under network attack conditions. By performing target simulation operations on the target network device through a controlled target device, a network security testing scenario is established to simulate network attacks on the target network, thereby testing the target network and helping to improve the network security detection and defense capabilities of the target network device.
[0158] Reference Figure 11A In some embodiments, the terminal used in the network security testing method of this application may include, but is not limited to, an operating interface, a scheduling and processing component, a baseband processing component, and a mid-frequency radio frequency (RF) unit. The scheduling and processing component includes a simulated attack module and a scheduling and processing module.
[0159] The user interface plays a crucial role as the primary medium for interaction between the target object and the system. The target object can be configured in various ways through the user interface, including setting target simulation operations, specifying the number of controlled devices initiating the target simulation operations, and setting the time interval for these controlled devices to execute the target simulation operations. Furthermore, the user interface can also be used to display security test reports after the test is completed; these reports are essential for evaluating and analyzing the test results.
[0160] The simulated attack module is responsible for receiving configuration parameters from the operation interface, setting different attack simulation strategies based on these parameters, generating corresponding instructions, and sending them to the scheduling and processing module to initiate the process of building a network security test scenario.
[0161] The scheduling and processing module can schedule the baseband processing component according to the standard algorithm strategy of the communication protocol to complete the uplink and downlink data interaction. In the embodiments of this application, the main function of the scheduling and processing module is to receive simulated attack data from the simulated attack module, change the standard communication protocol process according to these instructions, and instruct the baseband processing component to control the target controlled device to perform the target simulated operation.
[0162] Reference Figure 11B The scheduling and processing module can be composed of several sub-modules, including UEM (Target Controlled Device Management), CPS (Signaling Control Platform), SPS (Service Scheduling Platform), and UPS (Service Data Platform). Specifically, the UEM sub-module can be used to control the access process of the target controlled device; the CPS and SPS sub-modules can be used to simulate connection request overload and connection resource exhaustion; and the UPS sub-module can be used to simulate abnormal data packets by launching SRB1 channel abnormal packets and malformed data packets attacks.
[0163] The above modules and components work together to form a system that can simulate network security testing scenarios in network security testing methods. This system aims to improve the security protection capabilities of target networks and detect and defend against potential security threats by simulating network attacks on target networks.
[0164] According to some specific embodiments provided in this application, during normal communication, after successfully receiving an RRC Connection Request message from the target controlled device, the gNodeB (the target network device in the 5G wireless network) will send an RRC Connection Establishment message to the device and start a waiting timer to wait for the device to reply with an RRC Connection Complete message. If the target controlled device does not reply before the timer expires, the target network device will release the device.
[0165] In Flowing Attack mode (corresponding to connection request overload), the simulated attack module exploits this mechanism by configuring the target controlled device to not send RRC Connection Complete messages before the RRC Connection wait timer expires, but instead continuously and frequently initiate Random Access procedures, i.e., random access requests. This causes the gNodeB to frequently respond to these fake access requests, thereby reducing opportunities for access to other legitimate target controlled devices, ultimately creating a connection request overload.
[0166] Specifically, first, the "Following Attack" mode is set on the test terminal's interface. Then, the number of target controlled devices initiating access requests is configured to be 1. Upon receiving the "Following Attack" mode command, the simulated attack module begins executing the attack: it sends the configured number of target controlled devices and related context information to the device management platform module. It then sends the "Following Attack" command to the signaling control platform module, which modifies the RRC Connection memory variable, sets the ACK packet to a rejected state, and starts a 1-second timer, "AttckTimer." The signaling control platform module initiates the Attach process on the target controlled device. Once the RRC connection is established, the module checks if the ACK packet is in a rejected state. If so, it enters the abnormal message process, increments the attack result count (AttackNum) by 1, and then re-initiates the Attach process. When the AttckTimer expires, the signaling control platform module automatically triggers, feeding back AttackNum to the simulated attack module, which then compiles and stores the results in a fixed directory on the test device. Finally, the user clicks the "Stop Attack Test" button on the test terminal's interface to end the attack and download the attack result report.
[0167] This process can simulate a target network experiencing an overload of connection requests, thereby helping to detect and defend against such attacks.
[0168] According to some specific embodiments provided in this application, the process of establishing and releasing an RRC connection in a wireless communication protocol is utilized. Under normal circumstances, after the target controlled device successfully establishes an RRC connection, it replies to the gNodeB with an RRC Connection Complete message containing the IMSI (International Mobile Subscriber Identity). Upon receiving this message, the gNodeB sends the relevant information to the core network and requests authentication from the target controlled device. The core network then starts a timer T3560 (default value is 5 seconds) to wait for the target controlled device to send an authentication response. If the target controlled device does not send an authentication response before the timer expires, the core network will instruct the target network device to release the RRC connection.
[0169] In the Depende RRC Res Attack mode (corresponding to connection resource exhaustion), the simulated attack module instructs the target controlled device not to send an authentication response after receiving an authentication request, but instead to re-initiate the random access procedure. This frequently triggers the establishment and release of RRC connections during the operation of timer T3560. If the number of newly established RRC connections exceeds the number of released connections, and multiple target controlled devices perform this operation for an extended period, eventually exhausting the RRC connection resources, thus simulating connection resource exhaustion.
[0170] Specifically, first, the Deplete RRC Res Attack mode is set on the operation interface, and the number of target controlled devices, IMSI, and the time interval for initiating Attach are configured. Upon receiving the attack mode instruction, the simulated attack module begins executing the scenario simulation process. It first sends configuration information to the device management platform module, then sends an attack instruction to the signaling control platform module, modifying the authentication response to a denial state and starting the AttckTimer. The signaling control platform module initiates the Attach process for the target controlled device according to the configuration. When the target controlled device receives the authentication request, due to the denial state setting, it will not send an authentication response, but will instead increment the attack result count AttackNum and then re-initiate the Attach process. When the AttckTimer expires, the signaling control platform module feeds back AttackNum to the simulated attack module, which then compiles and stores the results in a fixed directory on the test device. Finally, the user clicks the "Stop Attack Test" button on the operation interface to end the current attack and download the attack result report.
[0171] This process can simulate a target network encountering connection resource exhaustion, helping to detect and improve the target network devices' defense capabilities against such attacks.
[0172] According to some specific embodiments provided in this application, based on the specifications of MAC PDU (Medium Access Control Protocol Data Unit) messages in wireless communication protocols, the length of the L bit (length field) must be less than 65535, and the LCID (Logical Channel ID) bit must be between 0 and 32. By simulating abnormal data packets in this way, the target controlled device will intentionally send MAC PDU messages with the LCID set to 1 and the L bit field abnormally filled, causing the target network device to identify and discard the abnormal SRB1 (Signaling Radio Bearer 1) channel message length. Similarly, if the target controlled device fills the LCID in the MAC PDU message with an abnormal value, the target network device will also identify and discard these abnormal data packets.
[0173] The purpose of the attack is that if the target controlled device sends such abnormal data for an extended period of time, the target network device will have to respond to these abnormal messages frequently, thus failing to provide normal services to other users, resulting in a significant waste of network resources and achieving the goal of denial of service.
[0174] Specifically, first, the terminal device triggers the target controlled device to access the network normally and begins copying FTP files, transmitting uplink services according to the frame structure period scheduled by the gNodeB. Taking TDD standard and 2.5ms dual-cycle frame structure as an example, the target controlled device will send uplink SRB data in a specific uplink S lot. Next, the simulated attack module starts the attack after receiving the SRB1 abnormal data attack mode instruction. It sends the SRB1 abnormal data attack instruction to the service data platform module. After receiving the instruction, the service data platform module modifies the SRB1 memory variable to an abnormal state and starts the AttckTimer for 1 second. Then, the target controlled device assembles the service data of the specific S lot into SRB1 channel data and modifies the L bit in the MAC PDU data to the abnormal value 65535. The target network device will discard these abnormally long packets, and the data transmission frequency is approximately 1000ms divided by S lotU (the number of uplink S lots). After receiving the malformed data packet attack mode instruction, the simulated attack module starts the attack again. It sends a malformed data packet attack command to the business data platform module, which modifies the DATA memory variable to an abnormal state and restarts the AttckTimer. During the scenario simulation, the test device changes the uplink air interface S lot of business data to abnormal MAC packet data, fills the LCID outside the protocol requirements, and maintains the same data transmission frequency as before. When it is necessary to end the attack, the user clicks the "Stop Attack Test" button on the test terminal's operation interface. Finally, the user can download the attack result report, which is successfully exported in Excel format.
[0175] This process can simulate abnormal data packets encountered by the target network, helping to detect and improve the target network devices' defense capabilities against such attacks.
[0176] This application also provides an electronic device, such as... Figure 12 As shown, the electronic device 1200 includes:
[0177] One or more processors 1210;
[0178] The memory 1220 stores one or more programs that, when executed by one or more processors 1210, enable the one or more processors 1210 to implement a network security testing method.
[0179] The memory 1220, as a non-transitory network system, can be used to store non-transitory software programs and non-transitory computer-executable programs. Furthermore, the memory 1220 may include high-speed random access memory, and may also include non-transitory memory, such as at least one disk storage device, flash memory device, or other non-transitory solid-state storage device.
[0180] In some embodiments, memory 1220 may optionally include memory 1220 remotely located relative to processor 1210, and this remote memory 1220 may be connected to processor 1210 via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.
[0181] The memory 1220 can be implemented as a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM). The memory 1220 can store the operating system and other application programs. When the technical solutions provided in the embodiments of this specification are implemented through software or firmware, the relevant program code is stored in the memory 1220 and is called and executed by the processor 1210 to execute the methods of the embodiments of this application.
[0182] The processor 1210 can be implemented using a general-purpose CPU (Central Processing Unit), microprocessor, application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this application.
[0183] In some embodiments, the electronic device further includes:
[0184] Input / output interfaces are used to implement information input and output;
[0185] The communication interface is used to enable communication and interaction between this device and other devices. Communication can be achieved through wired means (such as USB, Ethernet cable, etc.) or wireless means (such as mobile network, WIFI, Bluetooth, etc.).
[0186] The bus transmits information between various components of the device (e.g., processor 1210, memory 1220, input / output interface, and communication interface);
[0187] The processor 1210, memory 1220, input / output interface, and communication interface can communicate with each other within the device via a bus.
[0188] An embodiment of this application also provides a computer-readable storage medium storing computer-executable instructions for executing a network security testing method.
[0189] An embodiment of this application also provides a computer program product, which may include, but is not limited to, a computer program or computer instructions stored in a computer-readable storage medium. The processor of a computer device reads the computer program or computer instructions from the computer-readable storage medium and executes the computer program or computer instructions, causing the computer device to perform a method for implementing network security testing.
[0190] The system architecture and application scenarios described in this application are intended to more clearly illustrate the technical solutions of this application and do not constitute a limitation on the technical solutions provided in this application. Those skilled in the art will understand that as system architectures evolve and new application scenarios emerge, the technical solutions provided in this application are also applicable to similar technical problems.
[0191] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments of the above methods. Any references to memory, storage, databases, or other media used in the embodiments provided in this application can include non-volatile and / or volatile memory. Non-volatile memory may include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory may include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in a variety of forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), dual data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), RAMbus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM).
[0192] It will be understood by those skilled in the art that all or some of the steps and systems in the methods disclosed above can be implemented as software, firmware, hardware, and suitable combinations thereof. Some or all of the physical components can be implemented as software executed by a processor, such as a central processing unit, digital signal processor, or microprocessor, or as hardware, or as an integrated circuit, such as an application-specific integrated circuit. Such software can be distributed on a computer-readable medium, which can include computer storage media (or non-transitory media) and communication media (or transient media). As is known to those skilled in the art, the term computer storage media includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information (such as computer-readable instructions, data structures, program modules, or other data). Computer storage media includes, but is not limited to, RAM, ROM, EEPROM, flash memory or other memory technologies, CD-ROM, digital versatile disc (DVD) or other optical disc storage, magnetic cartridges, magnetic tape, disk storage or other magnetic storage devices, or any other medium that can be used to store desired information and is accessible to a computer. Furthermore, as is known to those skilled in the art, communication media typically contain computer-readable instructions, data structures, program modules, or other data in modulated data signals such as carrier waves or other transmission mechanisms, and may include any information delivery medium.
[0193] The above description, with reference to the accompanying drawings, illustrates some embodiments of this application, but does not limit the scope of this application. Any modifications, equivalent substitutions, and improvements made by those skilled in the art without departing from the scope and spirit of this application shall be within the scope of this application.
Claims
1. A network security testing method, the method comprising: Obtain test scenario simulation instructions, and determine the target simulated operation and target controlled device based on the test scenario simulation instructions; By performing the target simulation operation on the target network device through the target controlled device, a network security test scenario is established; Based on the network security test scenario, a security test is conducted on the target network corresponding to the target network device, and a security test report of the target network under the network security test scenario is obtained.
2. The network security testing method according to claim 1, characterized in that, The step of determining the target simulated operation and the target controlled device according to the test scenario simulation instructions includes: According to the test scenario simulation instructions, the controlled device identification information and controlled device operation information that match the network security test scenario are determined, wherein the test scenario simulation instructions are used to simulate the construction of the network security test scenario in the target network; Based on the controlled device identification information, the target controlled device for building the network security test scenario is determined from the target network; Based on the controlled device operation information, the target simulated operation performed by the target controlled device in the network security test scenario is determined from the target network operation data.
3. The network security testing method according to claim 2, characterized in that, The test scenario simulation command includes scenario simulation type information, device configuration parameters, and operation simulation frequency. The step of determining the controlled device identification information and controlled device operation information matching the network security test scenario based on the test scenario simulation command includes: The simulation scenario mode corresponding to the test scenario simulation instruction is determined based on the scenario simulation type information in the test scenario simulation instruction. Based on the simulation scenario method and the operation simulation frequency, obtain the controlled device identification information and the controlled device operation information that match the device configuration parameters from the scenario database.
4. The network security testing method according to claim 1, characterized in that, The step of performing the target simulation operation on the target network device through the target controlled device to build a network security test scenario includes: It was determined that the target simulated operation corresponds to a connection request overload: Modify the network connection memory variable of the target controlled device to set the connection confirmation message of the target controlled device to a rejected state; Re-initiate a network connection request from the target controlled device to the target network device corresponding to the test scenario simulation command, and receive connection establishment information from the target network device in response to the network connection request; Based on the connection confirmation message in the rejected state and the connection establishment information, the target controlled device is controlled to refuse to reply to the connection establishment information, and the process returns to re-initiating the network connection request through the target controlled device to the target network device corresponding to the test scenario simulation command, so as to build the network security test scenario.
5. The network security testing method according to claim 1, characterized in that, The step of performing the target simulation operation on the target network device through the target controlled device to build a network security test scenario includes: It was determined that the target simulation operation corresponds to connection resource exhaustion: Modify the authentication memory variable of the target controlled device to set the authentication confirmation message of the target controlled device to the rejected state; Re-initiate a network connection request from the target controlled device to the target network device corresponding to the test scenario simulation command, and receive connection establishment information from the target network device in response to the network connection request; Based on the connection establishment information, a connection confirmation information corresponding to the connection establishment information is generated, and the connection confirmation information is sent to the target network device; The system obtains the authentication request from the target network device in response to the connection confirmation information through the target controlled device, and controls the target controlled device to refuse to reply to the authentication request based on the authentication confirmation message in the rejection state, and returns to execute the network connection request to the target network device to build the network security test scenario.
6. The network security testing method according to claim 5, characterized in that, If a first number of the target controlled devices initiate the network connection request in the same request time slot, the step of re-initiating the network connection request through the target controlled device to the target network device corresponding to the test scenario simulation command includes: For a first number of target controlled devices, a preamble sequence for each target controlled device in the requested time slot is determined, such that the preamble sequence corresponding to each target controlled device is different; Each of the target controlled devices initiates the network connection request to the target network device based on the corresponding preamble sequence.
7. The network security testing method according to claim 6, characterized in that, Determining the preamble sequence of each of the first number of target controlled devices in the requested time slot includes: Obtain a sequence index set including a second number of leader sequence indices; wherein the leader sequence indexes are used to query the candidate leader sequence; From the first number of target controlled devices, determine the device number corresponding to each target controlled device; For each target controlled device, a modulo operation is performed based on the device number and the second number to obtain an index number. Based on the index number, the corresponding leader sequence index is selected from the sequence index set, and a corresponding leader sequence is configured for the target controlled device from the candidate leader sequences according to the leader sequence index.
8. The network security testing method according to claim 1, characterized in that, The step of performing the target simulation operation on the target network device through the target controlled device to build a network security test scenario includes: It was determined that the target simulation operation corresponded to an abnormal data simulation message: Modify the channel memory variable of the target controlled device to set the channel transmission message of the target controlled device to an abnormal state; A new connection is established between the target controlled device and the target network device corresponding to the test scenario simulation command; wherein, the data transmission between the target controlled device and the target network device is subject to the data transmission protocol. Based on the channel transmission message in the abnormal state, simulated transmission data that does not conform to the data transmission protocol is generated, and the simulated transmission data is sent to the target network device with the established connection through the target controlled device, so that the target network device identifies the simulated transmission data as abnormal data and discards it, and returns to the execution of sending the simulated transmission data to the target network device with the established connection through the target controlled device, so as to build the network security test scenario.
9. The network security testing method according to claim 8, characterized in that, The simulated transmission data includes a message length identifier and a logical channel identifier. Generating simulated transmission data that does not conform to the data transmission protocol includes: Determine the first constraint condition for the message length identifier bit and the second constraint condition for the logical channel identifier bit in the data transmission protocol; The simulated transmission data is generated such that the simulated transmission data does not satisfy the first constraint condition in the message length identifier bit, or such simulated transmission data satisfies the second constraint condition in the logical channel identifier bit.
10. The network security testing method according to claim 1, characterized in that, The step of performing the target simulation operation on the target network device through the target controlled device to build a network security test scenario includes: After each of the target simulation operations is executed, the execution count corresponding to the target simulation operation is updated; The network security test scenario is generated based on the updated number of executions.
11. The network security testing method according to claim 10, characterized in that, The process of generating the network security test scenario based on the updated number of executions includes: Starting from the execution of the target simulation operation, after each preset time interval, the number of executions updated during the preset time interval is statistically analyzed to obtain intermediate simulation data; The network security test scenario is generated based on the intermediate simulation data corresponding to each preset time interval.
12. The network security testing method according to claim 1, characterized in that, The command to obtain the test scenario simulation includes: Display the configuration interface; In response to the input from the target object in the configuration operation interface, obtain the scene simulation configuration parameters; Based on the scenario simulation configuration parameters, the test scenario simulation instructions for the target network are generated.
13. An electronic device, comprising: One or more processors; A memory having stored one or more computer programs thereon, which, when executed by the one or more processors, cause the one or more processors to implement the network security testing method as described in any one of claims 1 to 12.
14. A computer-readable storage medium having a computer program stored thereon, the computer program, when executed by a processor, implementing the network security testing method as described in any one of claims 1 to 12.
15. A computer program product comprising a computer program that, when executed by a processor, implements the network security testing method as described in any one of claims 1 to 12.