Method and system for establishing network attack and defense simulation model
By formally defining assets and behaviors and constructing a dynamic quantitative adjudication model, the problem of inconsistent definitions of assets and behaviors and subjective adjudication logic in network attack and defense simulation is solved, achieving highly consistent and accurate simulation results, and supporting flexible adaptation and rapid iteration of multiple network scenarios.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-10
- Publication Date
- 2026-03-13
AI Technical Summary
Existing network attack and defense simulation technologies lack unified standards for asset and behavior definitions, have subjective adjudication logic, and poor scenario adaptability, resulting in insufficient consistency and accuracy of simulation results, making it difficult to meet the needs of attack and defense performance evaluation in complex network environments.
It uses a pre-defined modeling language to formally define assets and behaviors, decompose them into atomic behavior units, and build a dynamic quantitative adjudication model. Combined with the comprehensive capability coefficients of both the attacker and defender, it realizes the quantitative deduction of behavior success rate and supports flexible adaptation to multiple network scenarios.
It achieves standardization of asset and behavior descriptions, improves the consistency and accuracy of simulation results, enhances the system's versatility and scalability, reduces the amount of configuration modifications required for scene switching, supports flexible adaptation to multiple network scenarios, and adapts to the rapid iteration of attack and defense technologies.
Smart Images

Figure CN121664521A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of network security simulation technology, specifically a method and system for establishing a network attack and defense simulation model. Background Technology
[0002] Network attack and defense simulation technology, as a core tool supporting network security decision-making, has its core value in identifying network vulnerabilities and verifying the effectiveness of protection strategies in advance by simulating real attack and defense scenarios. However, existing technical solutions still have significant limitations in practical applications:
[0003] On the one hand, there is a lack of unified standards for the definition of assets and behaviors. Different simulation tools have significantly different dimensions for describing network assets. For example, some tools only record hardware models and do not cover information such as software versions and security configurations. The logical characterization of attack and defense behaviors also mostly stays at the surface relationship between actions and results, failing to clarify the triggering conditions and specific execution logic. This makes it difficult to reuse simulation environments across tools, and the simulation results of the same scenario built by different users are often inconsistent.
[0004] On the other hand, the adjudication logic in attack and defense confrontations suffers from subjective flaws. Traditional models often employ fixed threshold judgments or experience-based weighted evaluation methods, failing to fully consider dynamic influencing factors such as the attacker's technical capabilities and the defender's equipment deployment level. This results in significant discrepancies between simulation results and real attack and defense scenarios, making it difficult to support accurate decision-making.
[0005] Furthermore, the adaptability to different scenarios is also significantly limited. Existing models are mostly designed for general information networks and lack specific support for special scenarios such as critical infrastructure networks and battlefield networks. When switching scenarios, most of the core logic often needs to be reconstructed, resulting in low adaptation efficiency. These problems collectively restrict the universality, accuracy, and practicality of existing simulation models, making it difficult to meet the needs of attack and defense performance evaluation in complex network environments. Summary of the Invention
[0006] The purpose of this invention is to provide a method and system for establishing a network attack and defense simulation model, so as to solve the problems of inconsistent definition of asset behavior, subjective adjudication logic, and poor scenario adaptability in the prior art mentioned in the background.
[0007] To solve the above-mentioned technical problems, the technical solution adopted by the present invention is as follows:
[0008] A method for establishing a network attack and defense simulation model includes the following steps:
[0009] Step S1, Asset and Behavior Standardization Definition Step: Using a preset modeling language, formally define the various assets involved in the simulation environment and the relationships between assets; at the same time, decompose the network attack and defense process into atomic behavior units, and formally define the triggering conditions and execution rules of each atomic behavior unit.
[0010] Step S2, Dynamic Quantification of Adjudication Step: Based on the formal assets and behaviors defined in Step S1, an adjudication model is constructed; the adjudication model extracts key factors affecting the outcome of the confrontation based on the correspondence between attack behaviors and defense behaviors, and combines the comprehensive capability coefficients of the attacking and defending parties to quantify and extrapolate the success rate of the execution of atomic behaviors.
[0011] Step S3, simulation deduction steps: After loading the configuration of a specific network scenario, the attack and defense behavior sequence is triggered according to the behavior rules defined in step S1, and the adjudication model constructed in step S2 is called to adjudicate the execution results of the behavior sequence one by one, and finally output the simulation deduction results.
[0012] According to the above technical solution, in step S1, the preset modeling language has a syntax structure that supports the definition of attributes for physical hardware assets, information software assets and security protection assets, and supports the description of the dependency or mapping relationship between assets through association relationships.
[0013] In step S1, the atomic behavior unit includes at least network reconnaissance behavior, network attack behavior that exploits vulnerabilities, and proactive network defense behavior against attacks; the triggering condition is used to describe the logical premise for the behavior to take effect, and the execution rule is used to determine whether the behavior is allowed to be executed.
[0014] According to the above technical solution, in step S2:
[0015] Key factors include attack factors that characterize the attacker's technological advantage and defense factors that characterize the defender's protective effectiveness.
[0016] The comprehensive capability coefficient includes the attacker's capability coefficient (δ) based on the attacker's technical reserves and target cognition calculations. a ), and the defense capability coefficient (δ) calculated based on the defense's equipment deployment and strategy level. d );
[0017] Quantitative deduction calculates the final success rate of atomic behaviors by combining the influence weights of key factors with the correction effect of comprehensive capability coefficients.
[0018] According to the above technical solution, the attack factors include at least: vulnerability exploitation potential, which is negatively correlated with the vulnerability's exposure time and exploitation difficulty; and attack tool maturity, which is positively correlated with the tool's development level and update frequency.
[0019] Defense factors include at least: the effectiveness of security devices, which is positively correlated with the rationality of device deployment and operational status; and the adaptability of defense strategies, which is positively correlated with the degree of matching between the strategy and the attack type.
[0020] According to the above technical solution, in step S3, the configuration of a specific network scenario is generated based on a preset scenario template; the scenario template predefines the typical asset topology, available atomic behavior library and simulation target settings under the scenario.
[0021] According to the above technical solution, the preset scene template library includes:
[0022] The core assets of the information network scenario template are concentrated in office terminals and enterprise servers, and the simulation targets focus on data security and access control.
[0023] The critical infrastructure network scenario template, whose core assets include industrial control equipment and monitoring systems, focuses on business continuity and equipment reliability in its simulation objectives.
[0024] Battlefield network scenario templates, whose core assets include military equipment and command systems, with simulation targets focusing on communication support and command integrity.
[0025] A network attack and defense simulation model establishment system includes:
[0026] The standardized definition module is used to provide a human-computer interface to receive user input and create and maintain a formalized asset library and atomic behavior rule library according to a preset modeling language.
[0027] The dynamic adjudication engine is used to load the output of the standardized definition module, build a built-in adjudication model, and respond to simulation requests by performing quantitative inference calculations based on key factors and comprehensive capability coefficients.
[0028] The simulation inference controller is used to load the network scene configuration, schedule the triggering of atomic behavior sequences, call the dynamic adjudication engine to adjudicate the execution result of each behavior, manage the entire simulation process, and generate output.
[0029] According to the above technical solution, the standardization definition module includes:
[0030] The asset modeling unit provides a graphical or scripted interface for defining asset attributes and relationships between assets;
[0031] The behavior editing unit provides a configuration interface for setting the triggering conditions and execution rules for each type of atomic behavior unit.
[0032] Based on the above technical solution, the dynamic adjudication engine includes:
[0033] The factor management unit is used to set and store the weight parameters of various attack and defense factors;
[0034] The capability assessment unit is used to calculate the attacker's capability coefficient (δ) based on the input basic data of both the attacker and defender. a ) and the defensive capability coefficient (δ) d );
[0035] The success rate calculation unit is used to execute a quantitative deduction algorithm based on the weight parameters of the factor management unit and the output coefficients of the capability assessment unit to calculate the final success rate of atomic behaviors.
[0036] According to the above technical solution, the simulation and deduction controller includes:
[0037] The scene loading unit is used to load or configure user-defined network scenes from the scene template library;
[0038] The process simulation unit is used to automatically or by script trigger attack and defense behaviors according to behavior rules during the simulation process, and submit the behaviors to be adjudicated to the dynamic adjudication engine.
[0039] The visualization and reporting unit is used to present the asset topology, attack and defense behavior links and status changes in real time, and generate a simulation report containing success rate statistics and risk analysis after the simulation ends.
[0040] Compared with the prior art, the present invention has the following beneficial effects:
[0041] This invention standardizes asset and behavior descriptions by employing a unified domain-specific modeling language, significantly improving the system's versatility and cross-tool reusability. This results in greater consistency of results and configuration efficiency within the same simulation scenario. By introducing a dynamic quantitative adjudication mechanism based on key influencing factors and comprehensive capability coefficients, it effectively reduces prediction errors in attack and defense behavior, achieving a significant improvement in accuracy compared to traditional experience-based judgment methods. Furthermore, by supporting flexible adaptation to various scenarios such as information networks, critical infrastructure networks, and battlefield networks, it greatly reduces the amount of configuration modifications required for scenario switching, significantly enhancing the application scope and deployment efficiency of the technology. In addition, through modular design and standardized interfaces, the system can flexibly expand factor types, scenario templates, and adjudication algorithms, adapting to the rapid iteration of attack and defense technologies without refactoring the core logic, demonstrating excellent scalability and evolution capabilities. Attached Figure Description
[0042] Figure 1 This is a flowchart of the method for establishing a network attack and defense simulation model according to the present invention;
[0043] Figure 2 A system block diagram is established for the network attack and defense simulation model of this invention. Detailed Implementation
[0044] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0045] Example 1
[0046] like Figure 1 As shown, this method achieves standardization, precision, and scenario-based approach to attack and defense simulation through a progressive process of standardized definition of assets and behaviors, construction of dynamic quantitative adjudication models, and multi-scenario simulation. The specific technical implementation process is as follows:
[0047] Step 1, Standardized Definition of Assets and Behaviors: This step focuses on reusability and parsability, and adopts an Extended Domain-Specific Language (DSL) as the unified modeling language. The syntax structure of this language is designed based on the characteristics of the network attack and defense domain, and includes three core syntax units: asset attribute description clauses, relationship definition clauses, and behavior logic characterization clauses. The asset attribute description clause supports full-dimensional formal definition of physical hardware assets (including 12 basic attributes such as device model, computing power, communication interface, deployment location, and operating system version), information software assets (including 8 key attributes such as software function modules, data storage path, permission level, and vulnerability history), and security protection assets (requiring explicit definition of 6 core attributes such as protection type, effectiveness threshold, response latency, and signature library version). The relationship definition clause accurately depicts the logical mapping between assets through predefined dependency, communication, and control relationship types. For example, the data dependency relationship between a database server and an application server requires annotation of data transmission protocol, encryption method, and transmission frequency. The behavioral logic description clause breaks down the network attack and defense process into indivisible atomic behavioral units, each of which must be defined through trigger condition expressions and execution rule scripts. The trigger condition expression must explicitly define the preconditions for the behavior's execution. For example, the trigger condition for port scanning is that the target IP is reachable and the network bandwidth is ≥1Mbps. The execution rule script must describe the specific logic for the behavior to take effect. For example, the execution rule for vulnerability exploitation must include a sequence of steps: matching the vulnerability CVE number, sending the attack payload, and obtaining target privileges, while defining the output parameters for each step. Through the above syntax design, the uniqueness, completeness, and resolvability of asset and behavior descriptions are ensured, laying the foundation for cross-scenario reuse.
[0048] Step 2, Dynamic Quantitative Adjudication Model Construction: Based on standardized asset and behavioral data, this step constructs a multi-factor weighted adjudication model. By quantifying the key influencing factors of both attacking and defending parties, it achieves accurate prediction of the success rate of atomic behavior execution. The model construction process requires the sequential completion of key factor definition, comprehensive capability coefficient calculation, and quantitative prediction algorithm design. At the key factor level, attack factors and defense factors need to be distinguished. Attack factors include vulnerability exploitation potential and attack tool maturity. Vulnerability exploitation potential is negatively correlated with vulnerability exposure time and exploitation difficulty, calculated using the following formula:
[0049] F vuln =1 / (α×T) expose +β×D exploit )
[0050] Where T expose D represents the number of days the vulnerability has been publicly disclosed. exploit To utilize the difficulty levels (1-10), α and β are weighting coefficients, with default values of 0.3 and 0.7 respectively.
[0051] The maturity of attack tools is positively correlated with the number of annual tool iterations and the success rate of vulnerability adaptation, calculated using the following formula:
[0052] F tool =γ×N update +δ×S adapt
[0053] Where N update S represents the number of times the tool is updated. adapt To accommodate the vulnerability ratio, γ and δ are weighting coefficients, with default values of 0.4 and 0.6, respectively.
[0054] Defense factors include the effectiveness of security devices and the adaptability of defense strategies. Specifically, the effectiveness of security devices is positively correlated with the device protection coverage and the rationality of deployment location, calculated using the following formula:
[0055] F device =ε×C coverage +ζ×R deploy
[0056] Where C coverage R represents the percentage of assets covered by equipment. deploy For deployment rationality scoring (levels 1-5), ε and ζ are weighting coefficients, with default values of 0.5 and 0.5 respectively; the adaptability of the defense strategy is positively correlated with the monthly update frequency of the strategy and the matching degree of the attack type, and is calculated by the following formula:
[0057] F policy =η×F update +θ×M attack
[0058] Where F update M represents the number of strategy updates. attack To match the proportion of attack types, η and θ are weighting coefficients, with default values of 0.3 and 0.7, respectively.
[0059] In terms of overall capability coefficients, the attacker's capability coefficient δ a Based on technological reserves and target cognitive computing, as shown in the following formula:
[0060] δ a =λ×C tech +μ×C cognition
[0061] Among them, C tech To allow attackers to determine the weighting factors of vulnerabilities and tools, C cognition The coefficient represents the level of understanding of the target network, λ and μ are weight coefficients with default values of 0.6 and 0.4, respectively, and the defender's capability coefficient is δ. d Based on device deployment and policy level calculations, as shown in the following formula:
[0062] δ d =ν×C deploy +ρ×C policy
[0063] Among them, C deploy For the security equipment deployment integrity factor, C policy ν and ρ are the strategy completeness coefficients, and their default values are 0.5 and 0.5, respectively. The quantitative inference algorithm calculates the final success rate P of atomic behaviors by weightedly fusing key factors and comprehensive capability coefficients, as shown in the following formula:
[0064] P=ω1×(F vuln ×F tool )×δ a -ω2×(F device ×F policy )×δ d
[0065] Wherein, ω1 and ω2 are the attack side and defense side weights, respectively, with default values of 0.45 and 0.55. The value of P is limited to 0-1, and the result is 0 when it is negative and 1 when it is greater than 1. All weight coefficients can be recalibrated based on user-defined test sets (sample size ≥ 50 groups) to ensure that they are adapted to the adjudication accuracy requirements of different scenarios.
[0066] Furthermore, to simulate the characteristics of experience accumulation and situational adaptation in real offensive and defensive scenarios, δ a δ d and the adaptability of defense strategies F policy Vulnerability Exploitation Potential F vulnDefined as a state variable, its state update is driven by the outcome (success / failure) of the behavior during the simulation process, and the specific rules are as follows:
[0067] Attacker's capability coefficient δ a The iterative rule cognitive gain rule: When the attacker performs network reconnaissance actions (such as port scanning and vulnerability detection) and the adjudication result is successful, its C tech Update according to the upper limit of the increment constraint, the formula is:
[0068]
[0069] Where Δ scout The cognitive gain step size (default 0.05, adjustable by users to 0.03-0.1 depending on the scenario, for example...) hour, If the reconnaissance operation fails, C tech Remain unchanged (due to lack of valid target information).
[0070] Experience accumulation rule: When an attacker executes exploit-type behaviors (such as SQL injection, buffer overflow) and the adjudication result is successful, their target cognitive coefficient K is... t Updated with diminishing marginal gain, target cognitive coefficient K t The attacker's target awareness coefficient C cognition The core sub-parameters are used to characterize the attacker's real-time cognitive depth of the target network's topology, asset attributes, and protection strategies. The formula is:
[0071]
[0072] Where Δ exploit This is the empirical gain coefficient (default 0.08), for example... hour, If the behavior fails, K t according to Small attenuation (Δ) fail =0.01), to avoid the excessive impact of a single failure on capabilities.
[0073] Iterative rule learning rules for defender parameters: When the defender performs proactive defense actions (such as firewall blocking, IDS alarm response) and the adjudication result is successful, its defense strategy adaptability F... policy The gain update is adapted to the scenario, and the formula is:
[0074]
[0075] in The policy learning rate (default 0.1, can be adjusted to 0.15 for industrial control and battlefield network scenarios), for example... hour, If the defensive action fails, F policy Remain unchanged (subsequent policy update behavior can trigger additional benefits).
[0076] Vulnerability Exposure Decay Rule: When an attacker executes an exploit-type action and the adjudication result is successful, the exploit potential F of the target asset is reduced. vuln Update based on threat confirmation decay, using the following formula:
[0077]
[0078] Where λ expose For example, the exposure attenuation factor (default 0.2). hour, If the behavior fails, F vuln Remains unchanged (due to the vulnerability not being actually verified). The scope of the iteration constraint: all parameter updates are only valid within the lifecycle of this simulation instance, serving as a short-term situational memory to influence subsequent atomic behaviors in the adjudication calculation; at the start of the simulation, parameters are loaded from the scenario template's base configuration (e.g., K). c The initial value is 0.5 by default, F. policy The initial value is 0.6 by default. After the simulation ends, the iteration state is automatically cleared to ensure that the initial conditions for the next simulation are pure and to avoid cross-scenario parameter interference.
[0079] Step 3, Multi-Scenario Simulation and Derivation: This step aims to achieve rapid configuration, dynamic scheduling, and accurate output, realizing the simulation and implementation of attack and defense scenarios. First, scenario configuration is loaded. Based on a pre-set scenario template library, a complete configuration for a specific network scenario is generated. The template library contains three core templates: the information network scenario template focuses on the asset topology of office terminals and enterprise servers, pre-defining 20 typical atomic behaviors such as phishing attacks and file theft, with simulation target parameters set to data leakage risk value and access control effectiveness; the critical infrastructure network scenario template uses industrial control equipment and monitoring systems as core assets, incorporating 15 exclusive atomic behaviors such as industrial control protocol attacks and equipment parameter tampering, with simulation target parameters set to service interruption duration and equipment failure recovery rate; the battlefield network scenario template builds a topology around military terminals and command systems, including 18 special atomic behaviors such as communication interference and command forgery, with simulation target parameters set to communication assurance integrity and command execution accuracy. All templates support user customization through topology drag-and-drop and parameter modification, and support importing external network topology diagrams (Visio, CAD format) to automatically generate basic configurations, reducing manual operations by more than 80%. Secondly, behavior sequence scheduling is performed, supporting two modes: automatic triggering and script triggering. The automatic triggering mode generates behavior sequences based on the mapping relationship between the conditions and behaviors preset in the scenario template (such as automatically triggering SQL injection behavior after a successful port scan), and supports setting the behavior execution interval (minimum interval 100ms). The script triggering mode allows users to write custom triggering logic through Python / Lua scripts, and supports calling asset status parameters (such as triggering DDoS defense behavior when the server CPU utilization exceeds 80%). Finally, the simulation controller performs successive adjudication and output of results. Following the sequence of actions, the controller calls the dynamic adjudication engine to calculate the success rate (response latency ≤100ms) for each triggered atomic action, and determines the action execution result (success / failure) based on the success rate. The execution result is fed back to the scenario state database in real time, affecting the triggering conditions of subsequent actions (e.g., switching to a buffer overflow attack after a failed SQL injection). After the simulation, a complete result containing visualization and quantitative data is output. The visualization results, based on WebGL technology, present an asset topology map (marking assets in normal / attacked / paralyzed states) and an attack / defense action link diagram (red marking attack paths, green marking defense paths). The quantitative data includes statistics on the success rate of each atomic action, the overall performance value of both attackers and defenders, and a list of high-risk assets. The analysis report generates protection strategy optimization suggestions based on the quantitative data (e.g., if the firewall's matching degree for SQL injection features is less than 60%, the feature library needs to be updated to version V2.3).
[0080] Furthermore, the simulation and inference controller dynamically evolves according to the sequence of behaviors through a two-way interactive process of request, decision, feedback, and update, specifically including the following steps:
[0081] Step 301, Status Submission: The controller reads the current state S from the scene state database. t (Including asset status, (Current values of each key factor), the atomic behavior A to be adjudicated. i With S t Submit them together to the dynamic adjudication engine;
[0082] Step 302, Decision Calculation: The engine first calculates A through the factor management unit and the capability assessment unit. i The basic success rate P, and the judgment of behavioral outcome R i (Success / Failure); then according to R i With A i The parameter change Δδ is calculated based on the type (reconnaissance / exploitation / defense) according to the iteration rule. a , Δδ d ΔF policy ΔF vuln ;
[0083] Step 303, Result Feedback: The engine will R i (Success / Failure) and Parameter Change (Δδ) a , Δδ d (etc.) are fed back to the controller;
[0084] Step 304, State Update: The controller first updates the state based on R. i Update the asset status (mark the asset as compromised if the attack is successful), and then update the status variables based on the parameter changes:
[0085]
[0086]
[0087] Updated status S t+1 Store in the scene state library;
[0088] Step 305, Execute in a loop: Schedule the next atomic action A i+1 At that time, the controller is based on the latest state S t+1 Initiate an adjudication request to achieve a closed-loop evolution of behavior, adjudication, and state updates, with the entire process response latency ≤100ms, ensuring the real-time performance of the simulation.
[0089] like Figure 2 As shown in the figure, this embodiment also provides a specific implementation of a network attack and defense simulation model establishment system. This system is designed to implement the above method and adopts a modular architecture. The modules work together through standardized interfaces. The core includes a standardized definition module, a dynamic adjudication engine, and a simulation inference controller.
[0090] Step 1, Standardization Definition Module: As the foundational data support module of the system, it provides a human-computer interaction interface for the formal definition and maintenance of assets and atomic behaviors. It includes an asset modeling unit and a behavior editing unit. The asset modeling unit provides a drag-and-drop graphical interface, supporting users to add, delete, and modify asset types and attributes. It supports batch import of asset data (CSV and Excel formats), has built-in asset attribute validation rules (such as IP address format validity and device model and operating system compatibility), and automatically prompts for abnormal configurations. The behavior editing unit provides a visual configuration interface, supporting the automatic loading of default trigger conditions and execution rule templates for selected atomic behavior types. Users can modify trigger conditions through the logic gate editor (AND / OR / NOT logic) and refine execution rules through the script editor (supporting Python syntax). It supports the import, export, and version management of behavior rules, ensuring the reusability of behavior definitions.
[0091] Step 2, Dynamic Adjudication Engine: As the core computing module of the system, it is responsible for loading the asset and behavior data output by the standardized definition module, and performing quantitative deduction of the success rate of attack and defense behaviors. It includes factor management unit, capability assessment unit and success rate calculation unit.
[0092] The factor management unit provides a factor configuration interface, displaying the calculation formulas and weight coefficients of default key factors. It supports users adding custom factors (such as the attacker's computing power coefficient), configuring the weight percentage of factors in the inference algorithm (0-20%), and setting factor priorities to ensure that new factors do not affect the original adjudication logic. The capability assessment unit supports importing basic data from both attackers and defenders (attacker's technical profile, defender's equipment list / strategy document), automatically extracting key parameters to calculate δ. a With δ d It supports manual adjustment of parameter values (adjustment range ±20%) and provides traceability logs for the coefficient calculation process. The success rate calculation unit has the aforementioned quantitative deduction algorithm built in, receives the weight parameters from the factor management unit and the coefficient values from the capability assessment unit, performs calculations in real time and outputs the success rate results, and supports breakpoint debugging of the calculation process, making it easy for users to verify the rationality of the algorithm.
[0093] Furthermore, the dynamic adjudication engine also includes a parameter iteration and evolution subunit, which is a submodule of the capability assessment unit; the parameter iteration and evolution subunit is used to receive the behavioral result R output by the success rate calculation unit. i Based on the behavior type, a predefined iterative rule is invoked to calculate the parameter change Δδ. a , Δδ d ΔF policy and ΔF vuln The change is compared with R iThe basic success rate is output to the simulation and deduction controller, and users can adjust the iteration step size through the configuration interface.
[0094] Step 3, Simulation and Inference Controller: As the system's process scheduling module, it is responsible for scene loading, behavior scheduling, and result presentation. It includes a scene loading unit, a process simulation unit, and a visualization and reporting unit. The scene loading unit provides a template selection interface and a custom configuration interface, supports saving, reusing, and version management of scene configurations, and supports the legality verification of scene configurations (such as whether there are isolated nodes in the asset topology and whether there are logical conflicts in the behavior rules). The process simulation unit receives scene configuration data, generates behavior sequences according to the trigger mode, calls the calculation interface of the dynamic adjudication engine in real time to obtain the success rate, updates the scene state library according to the results, supports pausing, continuing, and restarting the simulation process, and supports setting the simulation step size (minimum step size 1 second). The visualization and reporting unit presents the asset status and behavior chain in the simulation process in real time, supports the snapshot saving of scene status (automatically saved every 5 seconds), automatically generates an analysis report in Word / PDF format after the simulation ends, supports quantitative data export (CSV / Excel format), and supports custom configuration of report templates (such as adding a company logo and custom report chapters).
[0095] Example 2
[0096] This embodiment is a further refinement of Embodiment 1. In this embodiment, a medium-sized enterprise information network (including 100 office terminals, 5 enterprise servers, and 2 database servers) is used as the simulation object, and the goal is to assess the risk of data leakage after employees click on phishing emails.
[0097] First, standardization is defined: Import the existing network topology (Visio format) into the asset modeling unit. The system automatically identifies asset types and fills in default attributes. Users only need to modify IP addresses (office terminals 192.168.1.1-192.168.1.100, servers 192.168.2.1-192.168.2.5) and server operating system version (Windows Server 2019). Then, define three types of atomic behaviors through the behavior editing unit: phishing email clicks, malicious code execution, and database data theft. Specifically, the trigger condition for phishing email clicks is that the end user opens an email containing a malicious link, and the execution rule is to download malicious code to the terminal's C drive temp directory; the trigger condition for malicious code execution is that the terminal contains malicious code and antivirus software is not running, and the execution rule is to obtain terminal administrator privileges and establish a reverse connection; the trigger condition for database data theft is to obtain server privileges and open the database port, and the execution rule is to export core database table data to an external server.
[0098] Secondly, dynamic adjudication configuration is performed: the factor management unit uses default weight coefficients (α=0.3, β=0.7, γ=0.4, δ=0.6, ε=0.5, ζ=0.5, η=0.3, θ=0.7, ω1=0.45, ω2=0.55); the capability assessment unit imports attacker data (mastering 2 types of vulnerabilities, 3 attack tools, C) tech =0.8; Understand enterprise network topology, C cognition =0.7), δ is calculated. a =0.6×0.8+0.4×0.7=0.76; Import defender data (security devices cover 80% of assets, C) deploy =0.8; Strategy updated twice a month, C policy =0.7), δ is calculated. d =0.5×0.8+0.5×0.7=0.75.
[0099] Finally, a simulation was conducted: the scenario loading unit used an information network scenario template, setting the simulation target as the data leakage risk value; the process simulation unit adopted an automatic trigger mode to generate behavioral sequences of phishing email clicks, malicious code execution, and database data theft; the successive adjudication results showed that the phishing email click success rate was 85% (weak end-user security awareness), the malicious code execution success rate was 62% (30% of terminals did not have antivirus software enabled), and the database data theft success rate was 38% (firewall blocked some data transmission); in the simulation output results, the visualization interface marked 5 servers as high-risk assets, and the analysis report recommended increasing the terminal antivirus software enabling rate to 100% and adding characteristic detection rules for database data transmission to the firewall.
[0100] This invention standardizes asset and behavior descriptions by employing a unified domain-specific modeling language, significantly improving the system's versatility and cross-tool reusability. This greatly enhances the consistency of results and configuration efficiency within the same simulation scenario. By introducing a dynamic quantitative adjudication mechanism based on key influencing factors and comprehensive capability coefficients, it effectively reduces attack and defense behavior prediction errors, achieving a significant improvement in accuracy compared to traditional experience-based judgment methods. Furthermore, by supporting flexible adaptation to various scenarios such as information networks, critical infrastructure networks, and battlefield networks, it greatly reduces the amount of configuration modifications required for scenario switching, significantly enhancing the application scope and deployment efficiency of the technology. In addition, through modular design and standardized interfaces, the system can flexibly expand factor types, scenario templates, and adjudication algorithms, adapting to the rapid iteration of attack and defense technologies without refactoring the core logic, demonstrating excellent scalability and evolution capabilities. Practical verification shows that in complex simulation scenarios with large-scale assets, this invention exhibits excellent inference efficiency, providing efficient and accurate simulation support for network security protection decision-making and assessment.
[0101] Example 3
[0102] This embodiment is a further refinement of Embodiment 2. This embodiment uses a power grid industrial control system (containing 20 Siemens S7-1500 industrial control devices, 5 PLC controllers, and 3 monitoring servers) as the simulation object, and aims to verify the effectiveness of the protection strategy against PLC controller parameter tampering attacks.
[0103] During the standardization definition phase, the asset modeling unit focuses on configuring the communication protocol type (Modbus) and operating parameter range (voltage 0-380V, current 0-50A) of industrial control equipment. The behavior editing unit adds three exclusive atomic behaviors: industrial control protocol attack, PLC parameter tampering, and backup controller switching. The trigger condition for PLC parameter tampering is set to obtaining Modbus protocol access permission and the parameter modification request conforming to the format specification. The execution rule is set to modify the voltage parameter to 400V and trigger the equipment alarm.
[0104] During the dynamic adjudication configuration phase, the factor weighting coefficients are adjusted (the device deployment coefficient weight is increased to 0.6), and the attacker's δ a = 0.6 × 0.7 (Mastering one type of industrial control system vulnerability) + 0.4 × 0.6 (Understanding some industrial control system topologies) = 0.66, Defender δ d =0.6 × 0.8 (equipment redundancy deployment) + 0.4 × 0.7 (strategy adaptability) = 0.76; Add an industrial control equipment response latency factor, with a weighting of 10%, calculated using the following formula:
[0105] F delay =1 / (T) response / 100)
[0106] Among them, T response The device response time is in milliseconds (ms).
[0107] During the simulation phase, a critical infrastructure network scenario template was selected, with the behavior sequence set as industrial control protocol attack, PLC parameter tampering, and backup controller switching. The adjudication results showed that the success rate of PLC parameter tampering was 32% (some PLCs did not have parameter modification authentication enabled), and the success rate of backup controller switching was 85% (switching delay of 1.2s). The simulation results verified that the existing protection strategy can intercept 68% of parameter tampering attacks, but the switching delay needs to be optimized to within 500ms. The analysis report recommends adding a two-way authentication mechanism for parameter modification to the PLC controller and upgrading the backup controller switching logic to a pre-startup mode.
[0108] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus.
[0109] Finally, it should be noted that the above descriptions are merely preferred embodiments of the present invention and are not intended to limit the present invention. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing embodiments or make equivalent substitutions for some of the technical features. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
Claims
1. A method for establishing a network attack and defense simulation model, characterized in that: Includes the following steps: Step S1, Asset and Behavior Standardization Definition Step: Using a preset modeling language, formally define the various assets involved in the simulation environment and the relationships between assets; at the same time, decompose the network attack and defense process into atomic behavior units, and formally define the triggering conditions and execution rules of each atomic behavior unit. Step S2, Dynamic Quantification of Adjudication Step: Based on the formal assets and behaviors defined in Step S1, an adjudication model is constructed; the adjudication model extracts key factors affecting the outcome of the confrontation based on the correspondence between attack behaviors and defense behaviors, and combines the comprehensive capability coefficients of the attacking and defending parties to quantify and extrapolate the success rate of the execution of atomic behaviors. Step S3, simulation deduction steps: After loading the configuration of a specific network scenario, the attack and defense behavior sequence is triggered according to the behavior rules defined in step S1, and the adjudication model constructed in step S2 is called to adjudicate the execution results of the behavior sequence one by one, and finally output the simulation deduction results.
2. The method for establishing a network attack and defense simulation model according to claim 1, characterized in that: In step S1, the preset modeling language has a syntax structure that supports the definition of attributes for physical hardware assets, information software assets, and security protection assets, and supports the description of dependencies or mapping relationships between assets through association relationships. In step S1, the atomic behavior unit includes at least network reconnaissance behavior, network attack behavior that exploits vulnerabilities, and proactive network defense behavior against attacks. Triggering conditions describe the logical prerequisites for a behavior to take effect, while execution rules determine whether a behavior is allowed to be executed.
3. The method for establishing a network attack and defense simulation model according to claim 2, characterized in that: In step S2: Key factors include attack factors that characterize the attacker's technological advantage and defense factors that characterize the defender's protective effectiveness. The comprehensive capability coefficient includes the attacker's capability coefficient (δ) based on the attacker's technical reserves and target cognition calculations. a ), and the defense capability coefficient (δ) calculated based on the defense's equipment deployment and strategy level. d ); Quantitative deduction calculates the final success rate of atomic behaviors by combining the influence weights of key factors with the correction effect of comprehensive capability coefficients.
4. The method for establishing a network attack and defense simulation model according to claim 3, characterized in that: Attack factors include at least: vulnerability exploitation potential, which is negatively correlated with the vulnerability's exposure time and exploitation difficulty; and attack tool maturity, which is positively correlated with the tool's development level and update frequency. Defense factors include at least: the effectiveness of security devices, which is positively correlated with the rationality of device deployment and operational status; and the adaptability of defense strategies, which is positively correlated with the degree of matching between the strategy and the attack type.
5. The method for establishing a network attack and defense simulation model according to claim 1, characterized in that: In step S3, the configuration of a specific network scenario is generated based on a preset scenario template; the scenario template predefines the typical asset topology, available atomic behavior library, and simulation target settings for that scenario.
6. The method for establishing a network attack and defense simulation model according to claim 1, characterized in that: The preset scene template library includes: The core assets of the information network scenario template are concentrated in office terminals and enterprise servers, and the simulation targets focus on data security and access control. The critical infrastructure network scenario template, whose core assets include industrial control equipment and monitoring systems, focuses on business continuity and equipment reliability in its simulation objectives. Battlefield network scenario templates, whose core assets include military equipment and command systems, with simulation targets focusing on communication support and command integrity.
7. A network attack and defense simulation model establishment system, characterized in that: The method for implementing any one of claims 1 to 6 is characterized by comprising: The standardized definition module is used to provide a human-computer interface to receive user input and create and maintain a formalized asset library and atomic behavior rule library according to a preset modeling language. The dynamic adjudication engine is used to load the output of the standardized definition module, build a built-in adjudication model, and respond to simulation requests by performing quantitative inference calculations based on key factors and comprehensive capability coefficients. The simulation inference controller is used to load the network scene configuration, schedule the triggering of atomic behavior sequences, call the dynamic adjudication engine to adjudicate the execution result of each behavior, manage the entire simulation process, and generate output.
8. A network attack and defense simulation model establishment system according to claim 7, characterized in that: The standardized definition module includes: The asset modeling unit provides a graphical or scripted interface for defining asset attributes and relationships between assets; The behavior editing unit provides a configuration interface for setting the triggering conditions and execution rules for each type of atomic behavior unit.
9. A network attack and defense simulation model establishment system according to claim 8, characterized in that: The dynamic adjudication engine includes: The factor management unit is used to set and store the weight parameters of various attack and defense factors; The capability assessment unit is used to calculate the attacker's capability coefficient (δ) based on the input basic data of both the attacker and defender. a ) and the defensive capability coefficient (δ) d ); The success rate calculation unit is used to execute a quantitative deduction algorithm based on the weight parameters of the factor management unit and the output coefficients of the capability assessment unit to calculate the final success rate of atomic behaviors.
10. A network attack and defense simulation model establishment system according to claim 9, characterized in that: The simulation controller includes: The scene loading unit is used to load or configure user-defined network scenes from the scene template library; The process simulation unit is used to automatically or by script trigger attack and defense behaviors according to behavior rules during the simulation process, and submit the behaviors to be adjudicated to the dynamic adjudication engine. The visualization and reporting unit is used to present the asset topology, attack and defense behavior links and status changes in real time, and generate a simulation report containing success rate statistics and risk analysis after the simulation ends.