A multi-domain fusion network target modeling method and system

By employing a multi-domain fusion network target modeling method, physical, information, social, and vulnerability domain models are constructed. Combined with causal inference algorithms, this achieves realistic simulation of complex network topologies and dynamic attack behaviors, accurately models personnel capabilities, and improves the computational and deductive efficiency of network attack and defense tactics and strategies.

CN121486209BActive Publication Date: 2026-03-27BEIJING ZHANGBA NETWORK SECURITY TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2026-01-08
Publication Date
2026-03-27

AI Technical Summary

Technical Problem

Existing network target modeling systems cannot meet the computational and deductive needs of network attack and defense tactics and strategies. They lack comprehensive support for complex network topologies and dynamic attack behaviors, and also lack the ability to model and analyze the specific capabilities of attackers and defenders.

Method used

A multi-domain fusion network target modeling approach is adopted, which includes constructing physical domain, information domain, social domain and vulnerability domain models. Through role and permission matrix and organizational structure simulation, combined with the CWE standard system to classify vulnerability types, a multi-dimensional knowledge graph is generated to achieve semantic-level inter-domain fusion, and causal inference algorithm is used for attack path analysis.

Benefits of technology

It achieves realistic simulation of complex network topology and dynamic attack behavior, accurately models the capabilities of attackers and defenders, improves the scientific nature and efficiency of the simulation system, supports rapid simulation of large-scale networks at the Internet level, and solves the problems of high resource consumption and slow simulation speed.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121486209B_ABST
    Figure CN121486209B_ABST
Patent Text Reader

Abstract

The application belongs to the technical field of network security simulation, and discloses a network target modeling method of multi-domain fusion, which comprises the following steps: S1, constructing a physical domain model based on collected device parameters and a communication link model; S2, constructing an information domain model based on an operating system model, and establishing an association with the physical domain model to simulate each key aspect of an information system in a network; S3, constructing a social domain model through a role permission matrix and an organizational structure simulation; S4, constructing a vulnerability domain model according to a CWE standard systematized classification of vulnerability types, and outputting a multi-dimensional associated knowledge graph to reveal a vulnerability evolution path; and S5, automatically checking the dependency relationship and compatibility between models based on predefined metadata. The application efficiently meets the calculation deduction requirements of network attack and defense tactics and strategies, solves the problems of large resource consumption and slow deduction speed of traditional simulation technology, and meanwhile, the introduction of the social domain model and the vulnerability domain model improves the overall fidelity.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application belongs to the technical field of network security simulation, and particularly relates to a multi-domain fusion network target modeling method and system. BACKGROUND

[0002] In the process of continuous iteration and update of information technology, network attack and defense technology presents an accelerating evolution trend. Attackers rely on advanced algorithms, automated tools and new types of vulnerability exploitation methods to continuously break through the boundaries of traditional security protection. At the same time, the defense system also needs to be upgraded to cope with the increasingly complex threat landscape. Under this background, the network war game system as a professional technology platform has significantly improved its practical value. The platform builds a controllable and repeatable network environment, provides a systematic training path for network security decision makers and commanders, and enables them to carry out deduction under the condition similar to actual combat, thereby effectively improving the technical literacy and emergency response capability of individuals and teams.

[0003] The network war game system can simulate diversified network architecture, business logic and data flow, and provide a realistic environment modeling and simulation condition for organizations. On this basis, decision makers can objectively evaluate the implementation effect of existing security strategies based on quantitative analysis indicators, and identify potential configuration defects or strategy blind spots. Therefore, a network target modeling method and system are needed.

[0004] However, most of the current network target modeling systems focus on the technical level, but the current network attack is not limited to the technical level, but also includes social engineering attacks such as phishing emails and identity impersonation. Furthermore, it cannot meet the calculation deduction needs of network attack and defense tactics and strategies, lacks comprehensive support for complex network topology and dynamic attack behavior, and lacks modeling and analysis capabilities of specific capabilities of the attacking and defending parties. SUMMARY

[0005] The application provides a multi-domain fusion network target modeling method and system, which aims to solve the problem that the prior art cannot meet the calculation deduction needs of network attack and defense tactics and strategies, lacks comprehensive support for complex network topology and dynamic attack behavior, and lacks modeling and analysis capabilities of specific capabilities of the attacking and defending parties.

[0006] In a first aspect, a multi-domain fusion network target modeling method is provided, which comprises:

[0007] S1: constructing a physical domain model based on collected device parameters and a communication link model;

[0008] S2: constructing an information domain model based on an operating system model, establishing an association with the physical domain model, and simulating each key aspect of the information system in the network;

[0009] S3: Construct a social domain model through role permission matrix and organizational structure simulation;

[0010] S4: Construct a vulnerability domain model according to the CWE standard systematized classification of vulnerability types, and output a multi-dimensional associated knowledge graph to reveal the vulnerability evolution path;

[0011] S5: Based on the pre-defined metadata, automatically check the dependency relationship and compatibility between models, and realize semantic-level inter-domain fusion through the model interface engine, automatically establish cross-domain interaction link, and obtain a composite model;

[0012] S6: Use the assembled composite model to perform network environment simulation running, and drive the pre-configured attack and defense behavior data sequence;

[0013] S7: Use the causal inference algorithm to construct an attack path graph, and analyze and evaluate the network environment simulation results.

[0014] Further, the communication link model is used to access various types of device wired and wireless communication methods, and to distinguish wired transmission media.

[0015] Further, the specific content of S3 is as follows:

[0016] S3.1: Adopt a role-based access control model, predefine a permission template, divide the role permissions into three permission granularities, assign the minimum necessary operation set to each role, and construct a role permission matrix;

[0017] S3.2: Construct an organizational topology graph, simulate the internal trust relationship and security boundary, and abstract the network into a directed graph through the role-based access control model, with nodes being roles and edges representing trust relationships and data flow directions.

[0018] Further, the specific content of S5 is as follows:

[0019] S5.1: Store the physical domain model, information domain model, social domain model and vulnerability domain model into a unified registry, and each module is attached with metadata tags;

[0020] S5.2: Automatic checking based on the dependency relationship and compatibility of pre-defined metadata;

[0021] S5.3: Based on the pre-defined semantic mapping rule library, automatic binding and code generation are performed, and semantic-level inter-domain fusion is realized through the model interface engine.

[0022] The first aspect is a multi-domain fusion network target modeling system, which includes a multi-domain model generation module, a cross-domain combination module, a simulation running module and an analysis and evaluation module;

[0023] The multi-domain model generation module can generate physical domain models, information domain models, social domain models and vulnerability domain models, and attach standardized metadata tags to each model when stored; the multi-domain model generation module includes a physical domain model generation subunit, an information domain model generation subunit, a social domain model generation subunit and a vulnerability domain model generation subunit;

[0024] The cross-domain combination module can combine the multiple models output by the multi-domain model generation module into a composite model based on a two-level verification mechanism and an automatic generation mechanism;

[0025] The simulation running module is constructed based on a lightweight running environment isolated at the kernel level of the operating system, and can create an isolated running environment for each target data sequence to simulate the running state of a single network node;

[0026] The analysis and evaluation module uses a causal inference algorithm to construct an attack path map, and restores the real attack chain and key breakthrough point of the attacker.

[0027] Further, the physical domain model generation subunit can digitally model hardware devices and communication infrastructure in the network to obtain a physical domain model;

[0028] The information domain model generation subunit is used to construct models of multiple operating systems;

[0029] The social domain model generation subunit constructs a social domain model containing a security boundary through a role permission matrix and an organization topology graph;

[0030] The vulnerability domain model generation subunit classifies and models vulnerabilities according to the CWE standard to obtain a vulnerability domain model.

[0031] Further, the multi-domain model generation module further includes a multi-source data acquisition subunit, which can automatically perform targeted crawling and passive reception from multiple types of data sources through a pre-set standardized data interface.

[0032] Further, the organization topology graph is based on real-world organizational structure data, abstracts organization members as nodes, and marks logical boundaries as simulation network regions.

[0033] Further, the simulation running module is constructed based on a discrete event driven mechanism, and its architecture is composed of a core simulation kernel and modular network components, which can meet the needs of different simulation scenarios.

[0034] Further, the analysis and evaluation module further includes an AI assisted decision making subunit, which integrates AI large model technology to quickly generate targeted action suggestions and action templates.

[0035] Compared with the prior art, this application has at least the following beneficial effects:

[0036] Based on further analysis and research of existing technical problems, this application supports large-scale network simulation at the Internet level through a simulation operation module. This enables the system to perform both macro-level practical simulations and micro-level tactical calculations, thereby efficiently meeting the computational simulation needs of network attack and defense tactics and strategies. It also solves the problems of high resource consumption and slow simulation speed of traditional simulation technologies.

[0037] Meanwhile, by constructing an organizational topology diagram and simulating inherent trust relationships and security boundaries, the Role-Based Access Control (RBAC) model can abstract the network into a directed graph, where nodes represent roles and edges represent trust relationships and data flow. This allows for the simulation of real-world packet flow, attack paths, network link failures, and the discovery of new vulnerabilities, thus achieving a comprehensive and realistic simulation of complex network topologies and dynamic attack behaviors.

[0038] This invention also introduces a "social domain model" to accurately model the specific capabilities of attackers and defenders. This model is parametrically designed according to three dimensions: attack, defense, and security awareness, and includes skills such as vulnerability discovery, tactical decision-making, and incident response. This allows the simulation system to quantify and simulate the behavior and decision-making effects of attackers and defenders at different capability levels, overcoming the shortcomings of traditional tools that oversimplify or completely ignore the "human" factor, making the simulation results more closely resemble real-world scenarios.

[0039] At the same time, it integrates AI large model technology to realize intelligent assisted decision-making and automated inference functions. Through AI technology, it simulates complex network attack and defense scenarios, generates realistic attack behaviors and defense strategies, and improves the efficiency and scientific nature of inference. Attached Figure Description

[0040] Figure 1 A flowchart illustrating a multi-domain fusion network target modeling method provided in one embodiment of this application;

[0041] Figure 2 This is a block diagram of a multi-domain fusion network target modeling system provided in one embodiment of this application. Detailed Implementation

[0042] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments.

[0043] like Figure 1 As shown, this application provides a multi-domain fusion network target modeling method, which includes the following steps:

[0044] S1: Construct a physical domain model based on collected device parameters and communication link models, providing materials for subsequent composite target construction.

[0045] Device parameters include various devices connected to the network, their hardware specification parameters, and aging levels (such as disk I / O speed reduction rate, CPU processing efficiency reduction rate). Hardware specification parameters include CPU model / core number, memory capacity, storage medium type and capacity, and interface standards.

[0046] Communication link models are used to access various wired and wireless communication methods of devices, distinguish between wired (Ethernet, optical fiber) and wireless (Wi-Fi 6 / 7, 5G / 6G cellular network) transmission media, and configure basic bandwidth upper limit values and physical layer loss coefficients.

[0047] Communication link models can simulate the transmission process of data packets on physical media. It receives data packets from device models and processes them according to its built-in queue management algorithms (such as FIFO, WFQ) and channel characteristic parameters (such as bandwidth, propagation delay, packet loss rate).

[0048] The information domain model simulates various key aspects of information systems in the network, including operating systems, software, service protocols, and data resources. The operating system model simulates various mainstream operating systems such as Windows, Linux, and establishes an association with the physical domain by configuring compatible hardware parameters.

[0049] Software model: provides users with a rich software library model, covering application software, office software, attack and defense tools, and other fields.

[0050] Service and protocol model: simulates various common application layer network services and protocol implementations (such as HTTP, FTP, SMTP, RDP, etc.).

[0051] Attack and defense tool model: simulates the main functions and use effects of various attack or defense tools in network security.

[0052] S2: Construct an information domain model based on the operating system model and establish an association with the physical domain model, enabling it to simulate various key aspects of information systems in the network, focusing on business processes and state changes.

[0053] The operating system model can simulate Windows, Linux, macOS, and Unix operating systems. When simulating operating system core elements, it adds simulation of system update mechanisms, including automatic and manual updates.

[0054] S3: Build a social domain model through role permission matrix and organizational structure simulation, and design parameters according to the core capabilities of attack, defense and security awareness. It can clearly define the principle of least privilege to prevent unauthorized operations, while replicating the security boundaries of real organizational structures to evaluate the protection effectiveness of the horizontal movement attack surface.

[0055] The specific content of S3 is as follows:

[0056] S3.1: Adopt the Role-Based Access Control (RBAC) model, predefine permission templates, divide the role permissions into three levels of granularity, assign the minimum necessary operation set to each role, and construct a role permission matrix.

[0057] S3.2: Build an organizational topology map to simulate the internal trust relationship and security boundary. The Role-Based Access Control (RBAC) model abstracts the network as a directed graph, with nodes representing roles and edges representing trust relationships and data flow.

[0058] For example, in attack and defense simulation, when the attacker model compromises an initial node, the simulation engine will automatically analyze the potential paths of horizontal movement based on this topology map. Attackers can use the simulated trust relationships in the model to try to break through security boundaries, while defenders can clearly observe the attack path to accurately evaluate the protection effectiveness of existing network segmentation strategies and access control lists against horizontal movement.

[0059] Attacker and defender personnel model: In the simulation system, the attacker and defender personnel are simulated entities (virtual troops) commanded by the participants, who can receive and execute various action instructions, simulate the behavior patterns and action processes of the attacker and defender personnel in the real network security environment.

[0060] Neutral personnel model: Simulate ordinary people in reality. These roles do not have professional attack and defense capabilities, but have access to specific systems or hosts in their daily operations, and can be assigned social security awareness vulnerabilities.

[0061] S4: Build a vulnerability domain model based on the CWE (Common Weakness Enumeration) standard system, which can output a multi-dimensional associated knowledge graph to reveal the evolution path of vulnerabilities. Each vulnerability model is a structured data object, containing "unique identifier", "domain type" (physical / information / social), "existence condition", "trigger condition", "exploitation complexity", "impact consequences" and other attributes.

[0062] The knowledge graph is used to reveal the evolution path of vulnerabilities and attack chain association, where nodes are vulnerabilities, affected hardware and software models, related attack techniques (such as the ATT&CK framework) and remediation measures (patches). The edges represent the relationship between them.

[0063] For example, "Vulnerability A exists on software B", "Exploit A can achieve attack technique C", "Patch D can fix vulnerability A". The vulnerability domain model can predict the next possible attack based on the graph of associated vulnerabilities, and vice versa, when a certain patch is applied, the vulnerability domain model can automatically infer which attack paths are blocked.

[0064] The vulnerability domain model is divided into physical domain vulnerabilities, information domain vulnerabilities, and social domain vulnerabilities. For vulnerabilities in different domains, it can simulate the weak points of device protection in the physical environment, attackable points in the information system, and human behavior weaknesses and trust abuse in social engineering attacks.

[0065] S5: Based on the pre-defined metadata, the dependency relationship and compatibility between the models are automatically checked, and the semantic-level inter-domain fusion is realized through the model interface engine, automatically establishing cross-domain interaction links, realizing multi-domain fusion, and obtaining a composite model.

[0066] The specific content of S5 is as follows:

[0067] S5.1: Store the physical domain model, information domain model, social domain model, and vulnerability domain model in the unified registry, and each module is attached with metadata tags (such as interface protocol, dependency list, and compatible version range).

[0068] For example, a device model of a certain router will be marked with its supported maximum bandwidth and compatible network protocol stack version.

[0069] S5.2: Based on the pre-defined metadata dependency relationship and compatibility automatic check, when the user selects the required composite model through the graphical interface or script, the logical compatibility is automatically checked, fundamentally avoiding invalid combinations.

[0070] For example: To build a web server target, select "physical server model", "Linux OS model", "Apache service model", and "CVE-2023-12345 vulnerability model", the system will parse the metadata of each model (such as version, dependency), and automatically check the logical compatibility (such as whether the Apache version is compatible with the selected Linux distribution).

[0071] S5.3: Based on the pre-defined semantic mapping rule library for automatic binding and code generation, and through the model interface engine to realize semantic-level inter-domain fusion, the rule library contains the logical rules for interaction between different domain models.

[0072] For example, when the "social domain personnel model" is bound to the "information domain operating system model", the engine automatically triggers the "create user account" rule, calls the user management interface provided by the operating system model, generates the corresponding script code to create the account and set the permissions; when the "vulnerability domain model" is associated with the "information domain service model", the correctness of the interface call is ensured by parsing the metadata tags of each domain model, and finally a target data sequence encapsulating all the interaction logic is generated, thereby realizing semantic-level deep fusion of cross-domain models.

[0073] S6: Use the assembled composite model to run the network environment simulation, drive the pre-configured attack and defense behavior data sequence, and promote the simulation process. At the same time, simulate the dynamic interaction of network attack and defense, and support real-time control and intervention of the simulation process to reproduce complex attack and defense scenarios.

[0074] Among them, the simulation running module is constructed based on the discrete event driving mechanism, and various events in the simulation process are managed through an efficient event scheduler. Its architecture is composed of a core simulation kernel and modular network components, supports multiple scheduling strategies, and can flexibly cope with the needs of different simulation scenarios. The simulation engine can start more than 100,000 network nodes in seconds on a single server, supporting large-scale network simulation at the Internet level, significantly reducing resource consumption, while improving the flexibility and scalability of the deduction.

[0075] A lightweight running environment (such as LXC / Docker) with operating system kernel-level isolation is used to allocate independent network stacks and resource quotas for each target. The runtime monitoring agent continuously collects performance indicators (CPU utilization, memory occupancy, network throughput) of each layer, simulates the concurrent load characteristics of the real world through a discrete event scheduling algorithm. The dynamic fault injection module triggers abnormal conditions (such as link interruption, electromagnetic interference simulation) according to the preset strategy, and verifies the effectiveness of the fault tolerance and self-healing mechanism of the system. All interaction behaviors are recorded as time sequence logs, including original packet payload, process call stack tracking information and state transition trajectory, providing complete audit traceability for subsequent analysis.

[0076] S7: Use causal inference algorithms to construct attack path maps to analyze and evaluate the results of network environment simulation.

[0077] First, use causal inference algorithms to construct attack path maps, correlate multi-source heterogeneous data (traffic metadata, system logs, vulnerability exploitation records), identify key turning points and high-risk operation sequences. Then use Bayesian network modeling methods to quantify risk propagation probabilities and evaluate the reduction effect of different protection strategies on attack surfaces.

[0078] The evaluation system includes three dimensions: technical effectiveness (exploit success rate), management compliance (policy implementation), and operational reliability (service availability), and automatically generates a difference analysis report to compare the deviation of the baseline configuration and the actual operation data, and locates the potential optimization space. All evaluation results can be exported as a structured report (JSON-LD format) to support import into a SIEM system for deep drilling analysis. Thus, the effectiveness of the network protection system and the realism of the composite model are provided with quantitative and qualitative basis.

[0079] As shown in Figure 2 The multi-domain fusion network target modeling system provided by the application comprises a multi-domain model generation module, a cross-domain combination module, a simulation running module and an analysis and evaluation module.

[0080] The multi-domain model generation module can generate physical domain models, information domain models, social domain models and vulnerability domain models, and attach standardized metadata tags to each model when warehousing, describing the interface protocol and compatible version range of each model.

[0081] The multi-domain model generation module can also provide registration, retrieval, verification and update interfaces for each model. When a user or other module needs to call a model, it can be efficiently retrieved and version matched based on the metadata through the query interface. The module automatically checks the integrity and standardization of the metadata description when the model is warehoused or updated, ensuring that the model meets the system integration standards and provides high-quality, reusable model materials for subsequent target combination.

[0082] The multi-domain model generation module comprises a physical domain model generation subunit, an information domain model generation subunit, a social domain model generation subunit and a vulnerability domain model generation subunit.

[0083] The physical domain model generation subunit can digitally model hardware devices and communication infrastructure in the network. At the same time, according to the physical characteristics (such as bandwidth, loss coefficient) of wired and wireless transmission media and queue management algorithms, a communication link model that can simulate the data packet transmission process is constructed, providing accurate hardware behavior basis and real network transmission environment for network simulation, and ensuring that the underlying physical conditions of the simulation are highly realistic.

[0084] The information domain model generation subunit is used to construct models that can simulate multiple operating systems such as Windows and Linux, and integrate automatic and manual system update mechanisms for simulation. It realizes dynamic behavior simulation of key aspects of information systems, and produces dynamic linkage with other domains (such as vulnerability domain) through the update mechanism, reproducing the real life cycle of software systems.

[0085] The social domain model generation subunit constructs a social domain model containing security boundaries through a role-based access control (RBAC) matrix and an organizational topology graph. The RBAC matrix is a three-level permission granularity that implements the principle of least privilege. Then, the organizational structure is abstracted as a directed graph to simulate the trust relationships and data flow between departments and personnel. This provides a structural basis for evaluating lateral movement attack surfaces by clarifying access control and preventing unauthorized operations.

[0086] The organizational topology graph is based on real-world organizational structure data such as department division, reporting relationships, and project team lists. It abstracts organizational members (users or roles) as nodes and marks logical boundaries such as departments and project groups as simulated network regions. Then, according to actual business transactions and data access strategies, directed edges representing trust relationships and authorized data flow are established between nodes and regions.

[0087] The vulnerability domain model generation subunit classifies and models vulnerabilities based on the CWE standard. Each vulnerability is defined as a structured object containing unique identifiers, existence conditions, trigger conditions, and other attributes. Its core function is to build and maintain a multi-dimensional associated vulnerability knowledge graph that links vulnerabilities, affected assets, attack techniques, and remediation measures. Systematically manage vulnerability knowledge and intelligently reveal the evolution paths and attack chain associations between vulnerabilities through the knowledge graph to support attack prediction and defense effectiveness reasoning.

[0088] The multi-domain model generation module also includes a multi-source data acquisition subunit that can automatically collect raw data such as hardware performance parameters of physical devices, operating system behavior logs, network traffic data, social engineering event records, and vulnerability disclosure information from various data sources such as real network devices, software systems, security audit logs, and public vulnerability databases (such as CVE and NVD) through pre-set standardized data interfaces.

[0089] Meanwhile, the multi-source data acquisition subunit has a built-in data cleaning and format conversion engine that converts the acquired multi-source heterogeneous data into a standardized format recognizable by the system and stores it in a unified data warehouse. This provides accurate and real-time data input for each domain model generation subunit, which is used for model parameter calibration, behavior rule verification, and knowledge graph construction and updating.

[0090] The cross-domain combination module can combine multiple models output by the multi-domain model generation module into a composite model based on a two-level verification mechanism and an automatic generation mechanism.

[0091] The first level of the two-level verification mechanism refers to the compatibility checker automatically parsing the dependency and conflict relationships in the metadata of the multi-domain model set selected by the user, constructing a dependency graph and performing static verification to ensure the logical feasibility of the model combination, such as verifying the compatibility of web server software and operating system versions.

[0092] The second level refers to a cross-domain combination module semantic mapping rule library that predefines rules for cross-domain model interaction. The cross-domain combination module can match the corresponding rules according to the current model combination and automatically generate adaptation code or configuration scripts that execute these semantic logic, ultimately encapsulating all models and their interaction logic into an independently deployable target data sequence.

[0093] The simulation running module is built based on the lightweight running environment of the operating system kernel-level isolation, and can create an isolated running environment for each target data sequence. Each running environment is allocated independent network namespace, CPU and memory resource quota, so as to accurately simulate the running state of a single network node.

[0094] During simulation running, the discrete event-driven engine within the simulation running module is responsible for scheduling the entire simulation process. Events such as "packet sending", "timer timeout" are handled, thus advancing the simulation time. At the same time, the runtime monitoring agent continuously collects performance indicators (CPU, memory, network traffic) of each running environment, while the dynamic fault injection module simulates network interruption, hardware failure and other abnormal conditions according to the preset strategy, in order to test the behavior and fault tolerance of the target in complex dynamic environment.

[0095] The analysis and evaluation module uses causal inference algorithms (such as PC algorithm or causal forest) to construct attack path maps. This algorithm analyzes the massive time series logs provided by the multi-source data acquisition subunit to identify the causal relationship between events, rather than simply the sequence, thus accurately restoring the attacker's real attack chain and key breakthrough points.

[0096] The analysis and evaluation module is tightly integrated with the data collection, evaluation model management and situation display functions of the system. Through the built-in tracking system and traffic monitoring module, it can comprehensively and accurately collect key data during simulation, including network performance indicators, model running state, simulation network traffic, intelligence analysis results and user operation logs. The evaluation model supports multiple pre-set models (such as ATT&CK, D3FEND, CIAN asset exchange model) and custom models, can perform multi-dimensional quantitative analysis on the deduction process, and generate detailed evaluation reports. In addition, the system supports multiple evaluation presentation forms (tables, charts, 3D situation display), helping users intuitively understand complex data relationships and network structures.

[0097] The analysis evaluation module also includes an AI-assisted decision-making subunit that integrates AI large model technology to provide intelligent action recommendations and decision support. Through AI technology combined with scenario deduction, action recommendations and action templates are quickly generated according to current task lists, camp topology, intelligence data, available virtual troop lists, and built-in instructions. AI-driven agents can replace human beings to make some decisions, improving the efficiency of deduction.

[0098] Furthermore, the analysis evaluation module uses a Bayesian network to quantitatively evaluate security risks. Network nodes represent system states or attack steps, and edges represent transition probabilities. By inputting different defense strategies (such as closing a certain port or installing a certain patch), the model can dynamically calculate the probability of an attack path being blocked, thereby quantitatively evaluating the effectiveness of different protection measures. Finally, the analysis evaluation module can also generate structured evaluation reports (such as JSON-LD format) to provide direct and quantitative decision support for optimizing network protection systems.

[0099] In the above-mentioned multi-domain fusion network target modeling method and system, the simulation running module can start more than 100,000 network nodes on a single server within seconds, supporting large-scale Internet-level network simulation, so that the system can not only perform macro practice deduction, but also execute micro tactical calculation, thereby efficiently meeting the needs of network attack and defense tactics and strategy calculation deduction, and solving the problems of large resource consumption and slow deduction speed of traditional simulation technology.

[0100] At the same time, by constructing an organizational topology graph, simulating the internal trust relationship and security boundary, and using a role-based access control (RBAC) model, the network can be abstracted as a directed graph, with nodes being roles and edges representing trust relationships and data flow directions. Furthermore, real data packet flow, attack paths, network link failures, and new vulnerabilities discovered can be simulated, thereby achieving comprehensive and realistic simulation of complex network topology and dynamic attack behavior.

[0101] The present application also introduces a "social domain model" to accurately model the specific abilities of attack and defense personnel. This model parameterizes the skills of personnel (such as vulnerability mining, tactical decision-making, and emergency response) according to the three dimensions of attack, defense, and security awareness. This enables the deduction system to quantitatively simulate the behavior and decision-making of attack and defense personnel with different ability levels, solving the problem of simplification or complete neglect of the "human" factor in traditional tools, and making the deduction results more realistic.

[0102] At the same time, AI large model technology is integrated to realize intelligent auxiliary decision-making and automatic deduction functions. Through AI technology, complex network attack and defense scenarios are simulated to generate realistic attack behaviors and defense strategies, improving the efficiency and scientificity of deduction.

[0103] A specific embodiment is also given below:

[0104] Network router target modeling:

[0105] Take building a router composite model as an example: physical domain model: select router device model, configure hardware parameters (CPU, memory), communication link (bandwidth 100Mbps, delay 5ms). Information domain model: select routing protocol model (such as OSPF), operating system model (such as Linux kernel). Social domain model: select attacker and defender model, give attack ability parameters (such as vulnerability exploitation skill). Vulnerability domain model: select information domain vulnerability model (such as CVE-2021-1234 routing protocol vulnerability).

[0106] Assemble and combine: through the multi-domain model generation module, bind the above multi-domain models. For example, deploy the routing protocol model on the router device, and associate the vulnerability model and the attacker and defender model.

[0107] Simulation running: in the simulation engine, the attacker and defender model attempts to exploit the vulnerability to launch an attack, the router model responds according to the configuration, and the simulation engine records the attack path and effect. According to the attack result, automatically adjust the firewall rules or vulnerability state of the router, simulate the real defense process.

[0108] The technical features of the above embodiments can be combined in any way. In order to make the description simple, not all possible combinations of the technical features in the above embodiments are described, however, as long as the combination of the technical features does not exist contradictory, it should be considered as the scope of the present disclosure.

Claims

1. A multi-domain fusion network target modeling method, characterized in that, The method includes: S1: Construct a physical domain model based on the collected device parameters and communication link model; S2: Construct an information domain model based on the operating system model and establish its association with the physical domain model to simulate the various key layers of the information system in the network; S3: Construct a social domain model through role-permission matrix and organizational structure simulation; S4: Based on the CWE standard system, classify vulnerability types, construct a vulnerability domain model, and output a multi-dimensional knowledge graph to reveal the vulnerability evolution path; S5: Automatically validates dependencies and compatibility between models based on predefined metadata, and implements semantic-level inter-domain fusion in the model interface engine to automatically establish cross-domain interaction links and obtain composite models; S6: Use the assembled composite model to simulate the network environment and drive the pre-configured attack and defense behavior data sequence; S7: Use causal inference algorithms to construct attack path graphs and analyze and evaluate network environment simulation results.

2. The multi-domain fusion network target modeling method according to claim 1, characterized in that, The communication link model is used to access various devices via wired and wireless communication methods, and to distinguish between wired transmission media.

3. The multi-domain fusion network target modeling method according to claim 1, characterized in that, The specific content of S3 is as follows: S3.1: Adopting a role-based access control model, predefined permission templates divide role permissions into three levels of permission granularity, assigning a minimum necessary set of operations to each role, and forming a role permission matrix; S3.2: Construct an organizational topology graph, simulate the inherent trust relationships and security boundaries, and abstract the network into a directed graph through a role-based access control model, where nodes are roles and edges represent trust relationships and data flow.

4. The multi-domain fusion network target modeling method according to claim 1, characterized in that, The specific content of S5 is as follows: S5.1: Store the physical domain model, information domain model, social domain model, and vulnerability domain model in a unified registry, with each module accompanied by metadata tags; S5.2: Automatic verification of dependencies and compatibility based on predefined metadata; S5.3: Automated binding and code generation are performed based on a predefined semantic mapping rule base, and semantic-level inter-domain fusion is achieved through a model interface engine.

5. A multi-domain fusion network target modeling system, characterized in that, It includes a multi-domain model generation module, a cross-domain combination module, a simulation execution module, and an analysis and evaluation module; The multi-domain model generation module can generate physical domain models, information domain models, social domain models, and vulnerability domain models, and attach standardized metadata tags to each model when it is added to the database. The multi-domain model generation module includes a physical domain model generation subunit, an information domain model generation subunit, a social domain model generation subunit, and a vulnerability domain model generation subunit. The cross-domain combination module can combine multiple models output by the multi-domain model generation module into a composite model based on a two-level verification mechanism and an automatic generation mechanism. The simulation operation module is built on a lightweight operating environment isolated at the operating system kernel level, which can create an isolated operating environment for each target data sequence and simulate the operating state of a single network node. The analysis and evaluation module uses a causal inference algorithm to construct an attack path graph, reconstructing the attacker's true attack chain and key breakthrough points.

6. The multi-domain fusion network target modeling system according to claim 5, characterized in that, The physical domain model generation subunit can digitally model the hardware devices and communication infrastructure in the network to obtain a physical domain model; The information domain model generation subunit is used to construct models for various operating systems; The social domain model generation subunit constructs a social domain model containing security boundaries using a role and permission matrix and an organizational topology graph. The vulnerability domain model generation subunit systematically classifies and models vulnerabilities according to the CWE standard to obtain the vulnerability domain model.

7. The multi-domain fusion network target modeling system according to claim 5, characterized in that, The multi-domain model generation module also includes a multi-source data acquisition subunit, which can automatically crawl and passively receive data from multiple data sources through a preset standardized data interface.

8. The multi-domain fusion network target modeling system according to claim 6, characterized in that, The organizational topology diagram is based on real-world organizational structure data, abstracting organizational members as nodes and marking logical boundaries as simulated network regions.

9. The multi-domain fusion network target modeling system according to claim 5, characterized in that, The simulation operation module is built on a discrete event-driven mechanism. Its architecture consists of a core simulation kernel and modular network components, which can meet the needs of different simulation scenarios.

10. A multi-domain fusion network target modeling system according to claim 5, characterized in that, The analysis and evaluation module also includes an AI-assisted decision-making subunit, which integrates AI large-scale model technology to quickly generate targeted action suggestions and action templates.

Citation Information

Patent Citations

  • Network system security vulnerability relevance modeling and analysis method

    CN113259334A

  • Large-scale network node scene construction method and system based on network target range

    CN119996079A