Safety attack and defense effectiveness full-automatic continuous verification system

By simulating attacks using generative AI and reinforcement learning algorithms, combined with real-time data processing and dynamic strategy adjustments, the problems of unknown threats and cross-domain defense assessment in existing technologies have been solved, enabling fully automated continuous verification of the hybrid architecture of smart energy enterprises.

CN121690659APending Publication Date: 2026-03-17CHINA UNICOM (JIANGXI) IND INTERNET CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-17
Publication Date
2026-03-17

AI Technical Summary

Technical Problem

Existing technologies cannot effectively simulate attacks from unknown threats and zero-day vulnerabilities, nor can they assess cross-domain defense synergy and resistance to quantum computing attacks, resulting in delayed verification conclusions and a lack of evaluation dimensions.

Method used

An attack simulation engine is used to generate highly realistic attack payloads using generative AI and reinforcement learning algorithms. A defense response monitor collects and processes defense system data in real time. An intelligent decision-making center integrates multi-dimensional indicators for evaluation. A dynamic strategy library adjusts strategies, and a threat modeling knowledge base generates new attack scenarios, achieving fully automated continuous verification.

Benefits of technology

It enables proactive detection and blocking of unknown threats, accurately quantifies and assesses cross-domain defense synergy and long-term risks of encryption systems, ensures that the verification system adapts to the network threat environment, and continuously optimizes defense strategies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121690659A_ABST
    Figure CN121690659A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of network security attack and defense verification, and provides a security attack and defense effectiveness full-automatic continuous verification system, which comprises an attack simulation engine, a defense response monitor, an intelligent decision center, a dynamic strategy library and a threat modeling knowledge base, and cooperatively forms an attack-defense-analysis-optimization closed-loop verification system. According to the system, open source intelligence and commercial intelligence are fused, and a multi-source heterogeneous intelligence aggregation center is constructed. Duplicate removal, normalization and dynamic verification are achieved through an intelligence cleaning engine, and real-time and multi-element threat genes are injected into the attack feature library; an attack simulation engine is in deep linkage with a threat modeling knowledge base and a dynamic strategy base, high-simulation attacks with variant attack loads and path optimization are generated based on cleaned intelligence, attack and defense verification is made to achieve active simulation of unknown threats, and the resistance of a defense system to novel and composite attacks is accurately checked.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of network security attack and defense verification, and particularly relates to a security attack and defense effectiveness full-automatic continuous verification system. BACKGROUND

[0002] Network security attack and defense effectiveness verification refers to evaluating the detection, response and blocking capabilities of a defense system by simulating real attack behaviors to ensure that it can effectively resist potential threats and protect the security of critical information assets.

[0003] The prior art mainly relies on periodic vulnerability scanning, manual penetration testing, and security log auditing and analysis. These methods are usually based on a known attack feature library or pre-set test cases and are executed in a controlled environment.

[0004] A smart energy enterprise builds a hybrid IT architecture of a public cloud data center + employee mobile terminal + factory IoT sensor, which needs to verify the defense capability of the architecture against attacks such as container escape of cloud servers, horizontal penetration to mobile terminals, and intrusion into IoT sensors to steal production data. In this scenario, the prior art has some technical defects: first, since attack simulation relies on fixed feature libraries and historical scenarios, it cannot dynamically generate test payloads for unknown threats such as zero-day exploits and APT variant attacks, resulting in detection blind spots for the defense system when facing new and disguised attacks, and the verification conclusion lags behind the actual threat evolution; second, traditional verification methods lack quantitative evaluation of cross-domain collaborative defense effectiveness and resistance to quantum computing attacks; in a hybrid cloud scenario, the attack path may cross multiple security domains, and the prior art is difficult to systematically evaluate the synergy and consistency of inter-domain defense strategies; at the same time, for classical encryption algorithms that have been deployed, it is impossible to simulate the cracking threat in a future quantum computing environment, resulting in the inability to pre-evaluate the long-term security risks of the encryption system. SUMMARY

[0005] The purpose of the embodiments of the present application is to propose a security attack and defense effectiveness full-automatic continuous verification system to solve the technical problems of verification conclusion lag and evaluation dimension missing in the background art.

[0006] To solve the above technical problems, the security attack and defense effectiveness full-automatic continuous verification system provided by the embodiments of the present application adopts the technical solutions as follows: The security attack and defense effectiveness full-automatic continuous verification system comprises: An attack simulation engine receives an attack scenario, strategy parameters, and global threat intelligence, analyzes intelligence to generate highly simulated attack payloads and variants using generative AI, optimizes attack paths through reinforcement learning algorithms, and outputs diversified attack vectors and the total number of attack paths after pre-attack in a digital twin environment, and outputs to an intelligent decision hub; A defense response monitor collects response data of the defense system in real time, standardizes the response data, calculates the defense response delay and the number of blocked attack paths, and outputs standardized data to provide a basis for effectiveness evaluation; An intelligent decision hub fuses defense response data, strategy library rules, and threat characteristics, calculates multi-dimensional indicators such as attack path blocking rate and vulnerability exploitation success rate, generates defense effectiveness evaluation results and optimization instructions in combination with cross-domain collaborative verification and quantum encryption confrontation, and drives closed-loop optimization; A dynamic strategy library stores evaluation strategies and optimization rules, dynamically adjusts strategy parameters according to the evaluation results of the intelligent decision hub, and provides real-time updated rule support for intelligent decision-making; A threat modeling knowledge base fuses historical attack and defense data and real-time threat intelligence, dynamically generates new attack scenarios through machine learning, constructs a defense knowledge graph, and provides scene basis for attack simulation.

[0007] Preferably, in the attack simulation engine, the generative AI includes a large language model and a generative adversarial network, which generates attack payloads and variants through adversarial training. Specifically, the generator creates the payload, and the discriminator verifies its similarity to the real attack. Iterative optimization generates variants that can bypass the feature detection of the defense system.

[0008] Preferably, in the attack simulation engine, the reinforcement learning algorithm optimizes the attack path based on the Q-value update formula, prioritizes high-value attack actions by evaluating the value of state-action pairs, eliminates low-value actions, and forms an optimal attack path.

[0009] Preferably, the data standardization processing of the defense response monitor includes: using a hash algorithm to identify and filter duplicate records, removing invalid data and format error data through a rule engine, and unifying log fields and formats of multiple source defense systems based on a pre-set heterogeneous field-standard field mapping table.

[0010] Preferably, in the defense response monitor, the calculation of the number of blocked attack paths is implemented through a finite state machine model, which divides the attack path state into not started, executing, successful, and blocked, counts the number of paths in the blocked state, and ensures accurate counting through a hash table to remove duplicates.

[0011] Preferably, the multi-dimensional evaluation algorithm of the intelligent decision hub adopts an analytic hierarchy process to assign weights to evaluation indexes, converts the indexes into standardized scores through linear normalization, and generates a comprehensive defense effectiveness score and grade through weighted summation.

[0012] Preferably, the cross-domain collaborative verification of the intelligent decision hub includes generating cross-domain attack scenarios covering cloud environments, mobile terminals and Internet of Things devices, collecting multi-domain defense data to calculate the domain internal blocking rate and inter-domain collaborative rate, generating a global defense heat map using a Kriging interpolation algorithm, and locating cross-domain defense blind areas.

[0013] Preferably, the quantum encryption confrontation evaluation of the intelligent decision hub includes simulating the threat of quantum attacks on existing encryption mechanisms, calculating the quantum cracking time and comparing it with the key update period, evaluating the vulnerability of the encryption defense, and proposing anti-quantum upgrade suggestions.

[0014] Preferably, the strategy adjustment of the dynamic strategy library is based on a preset update rule, and when the defense effectiveness does not meet the standard, the evaluation index threshold and the optimization rule trigger condition are adjusted.

[0015] Preferably, the new attack scenario generation of the threat modeling knowledge base is realized through a clustering algorithm, which groups the extracted attack features according to similarity, and expands the feature groups by combining real-time threat intelligence to generate scenarios simulating new attacks. The defense knowledge graph construction includes identifying entities from historical data and real-time intelligence, including attack types, defense measures and vulnerabilities, extracting entity relationships, and organizing them into a graph structure using a knowledge graph tool to support complex queries and reasoning of attack-defense-vulnerability relationships.

[0016] The beneficial effects of the present application are as follows: The present application provides a full-automatic continuous verification system for security attack and defense effectiveness, which cooperates in a closed loop through the attack simulation engine, the defense response monitor 200, the intelligent decision hub 300, the dynamic strategy library 400 and the threat modeling knowledge base 500, and can generate attack payloads and paths of zero-day vulnerabilities and APT variants dynamically based on global real-time threat intelligence using generative AI, in order to actively and realistically test the detection and blocking capabilities of the defense system against unknown threats. At the same time, the intelligent decision hub 300 accurately calculates indexes such as attack path blocking rate and inter-domain collaborative rate by fusing multi-domain defense response data, and realizes precise quantitative evaluation of cross-domain defense collaboration and long-term risks of encryption systems through quantum encryption confrontation simulation, solving the problems of lagging verification conclusions and missing evaluation dimensions.

[0017] The system has continuous optimization of the attack simulation through the deep integration of the generative adversarial network and the reinforcement learning algorithm. The iterative training of the generator and the discriminator can produce endless load variants, effectively bypassing the defense detection based on static features; and the reinforcement learning can autonomously optimize the most efficient attack path by evaluating the value of the attack action, which makes the security verification not only cover known threats, but also actively predict and test the combat capability of the defense system to respond to advanced and intelligent attacks.

[0018] The autonomous learning and evolution mechanism built into the system ensures the continuous leading of verification efficiency. The threat modeling knowledge base 500 generates new attack scenarios through dynamic clustering and generalization of real-time intelligence by machine learning; and the dynamic strategy library 400 automatically adjusts the evaluation threshold and optimization rules according to the evaluation results of the intelligent decision center 300. The closed loop of data-driven decision and feedback optimization enables the whole system to adapt to the evolving network threat environment, providing core support for building a forward-looking and flexible security defense system. BRIEF DESCRIPTION OF DRAWINGS

[0019] In order to more clearly illustrate the scheme in the present application, the drawings needed in the description of the embodiments of the present application will be briefly introduced. Obviously, the drawings in the following description are some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor on the basis of these drawings.

[0020] Figure 1 is a system architecture diagram of embodiment 1; Figure 2 is a verification flowchart of embodiment 1; Figure 3 is a method flowchart of embodiment 2. DETAILED DESCRIPTION

[0021] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs; the terms used herein in the specification and claims of the application and the above description of drawings are intended to cover not only the inclusive but also the exclusive. In addition, the singular forms "a", "an" and "the" are intended to include the plural forms, unless the context clearly indicates otherwise.

[0022] In this document, the term "embodiment" means that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of this application. The appearance of this phrase in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment mutually exclusive with other embodiments. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.

[0023] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings.

[0024] Example 1: like Figure 1 As shown, the fully automated continuous verification system for the effectiveness of security attack and defense includes an attack simulation engine 100, a defense response monitor 200, an intelligent decision center 300, a dynamic strategy library 400, and a threat modeling knowledge base 500, which work together to form a closed-loop verification system of attack-defense-analysis-optimization.

[0025] in: Attack Simulation Engine 100: The attack simulation engine 100 receives attack scenarios, strategy parameters, and global threat intelligence. It uses generative AI to analyze the intelligence and generate highly realistic attack payloads and variants. It optimizes the attack path through reinforcement learning algorithms. After rehearsing the attack in a digital twin environment, it outputs diverse attack vectors and the total number of attack paths, which are then output to the intelligent decision center 300 to achieve dynamic simulation of new attacks. Furthermore, in the attack simulation engine 100, the generative AI includes a large language model and a generative adversarial network (GAN), which generates attack payloads and variants through adversarial training. Specifically, the generator creates the payload, the discriminator verifies its similarity to real attacks, and iteratively optimizes the generation of variants that can bypass the feature detection of the defense system.

[0026] Furthermore, in the attack simulation engine 100, the reinforcement learning algorithm optimizes the attack path based on the Q-value update formula. By evaluating the value of the state-action pair (Q-value), it prioritizes high-value attack actions, such as effective vulnerability exploitation, and eliminates low-value actions, such as attacking a closed port, thus forming the optimal attack path.

[0027] Specifically, the attack simulation engine 100 receives attack scenarios provided by the threat modeling knowledge base 500, including historical attack scenarios and dynamically generated new attack scenarios, attack strategy parameters from the dynamic strategy library 400, such as attack intensity thresholds, and global threat intelligence, such as TTPs and zero-day vulnerability information from APT groups.

[0028] Historical attack scenarios refer to structured descriptions of past network attack events or attack patterns with clear characteristics and complete processes, including: Attack targets: objects under attack, such as enterprise core databases, user terminals and cloud servers, industry attributes such as finance, energy and healthcare, or system types such as Windows Server and Apache Tomcat; Attack means: technical methods used, such as SQL injection, ransomware encryption and supply chain hijacking, vulnerabilities such as CVE-2021-44228 and EternalBlue, and tools such as Metasploit and CobaltStrike; Attack path: complete steps from initial access to final target, such as phishing email implanting trojan → horizontal movement to internal network → obtaining administrator rights → stealing data; Attack features: unique identifiers such as malicious code hash value, C2 server IP, port and protocol characteristics of attack traffic; Defensive response: defensive system response measures at the time, such as firewall interception and IDS alarm, and effects such as successful blocking, partial interception and complete breakthrough.

[0029] Initial attack scenarios come from externally input historical attack cases such as public security incident reports, industry general attack scenarios such as OWASP Top10 attacks, and typical scenarios defined in compliance requirements.

[0030] Strategy parameters are preset by dynamic strategy library 400, such as attack strength and duration. Initial attack strategy parameters are preset based on industry security standards such as NIST security framework, enterprise internal defense strategy and historical verification experience, for example, initial attack strength and path selection priority.

[0031] Global threat intelligence sources include: from third-party threat intelligence platforms, international security organization reports such as MITRE ATT&CK, open source intelligence such as CVE vulnerability library, and public reports of APT organization activities. Global threat intelligence is automatically connected to the above intelligence sources by the system, and data is synchronized in real time or at regular intervals through API interface. Threat modeling knowledge base 500 receives and updates after integration.

[0032] The processing method of attack simulation engine 100 is as follows: Step 101: Use generative AI to analyze global threat intelligence, extract attack features and patterns, and generate highly simulated attack payloads and variants.

[0033] Generative AI refers to artificial intelligence models with the ability to generate new data, such as large language models and generative adversarial networks.

[0034] The steps for generative AI to generate attack payloads are as follows: Step 1011: Data preprocessing.

[0035] Collect global threat intelligence, such as the MITREATT&CK framework, CVE vulnerability database, APT group TTPs reports, and malware samples, and then clean and standardize them. For text-based intelligence, such as attack reports: remove redundant information, such as irrelevant descriptions; segment the data (using NLTK for English and Jieba for Chinese); standardize terminology, such as classifying phishing emails and spear-phishing attacks as social engineering initial access.

[0036] For code-based data, such as malicious scripts: decompile and deobfuscate them, and extract API call sequences and string features, such as C2 server domain names.

[0037] For log-type data, such as attack traffic logs: parse fields such as IP, port, and payload, and convert them into structured tables, such as source IP-target port-attack type.

[0038] Step 1012: Feature extraction and encoding.

[0039] Generative AI models, such as Transformer-based large language models and graph neural networks (GNNs), are used to extract multi-dimensional features: Behavioral characteristics: The sequence of attack steps, such as port scanning → vulnerability exploitation → lateral movement, is converted into a vector through sequence encoding algorithms, such as TokenEmbedding.

[0040] Technical characteristics: Exploitation methods, such as buffer overflows and SQL injection; tool characteristics, such as the use of the Metasploit module, extraction through keyword matching and entity recognition, such as the NER task using the BERT model.

[0041] Target characteristics: The type of system and service targeted by the attack, identified using text classification models such as TextCNN.

[0042] Step 1013: Pattern aggregation and generalization.

[0043] Clustering of extracted features, such as the K-means algorithm, can aggregate similar attack patterns, such as grouping attacks that exploit Log4j vulnerabilities into one category. Generative models such as GPT-4 can be used to generalize potential features, such as possible attack features of JNDI injection vulnerabilities similar to Log4j.

[0044] Step 1014: Attack payload and variant generation.

[0045] Step 10141: Initial attack payload generation.

[0046] Based on the extracted features, generative AI models, such as GAN and GPT-4Code, are used to generate initial payloads that match real attacks.

[0047] When using Generative Adversarial Networks (GANs), the generator G learns the syntax and structure of real payloads, such as the header format of HTTP requests and the encoding method of exploit payloads. The discriminator D judges the similarity between the generated payload and the real payload. Through adversarial training, the generator outputs highly realistic payloads, such as HTTP POST requests that conform to the exploit format.

[0048] Step 10142: Payload Variant Generation: Variants are generated through genetic algorithm mutation, such as encoding mutation, protocol substitution, and redundancy insertion. The mutation algorithm combines genetic algorithm with random mutation; samples from the initial payload that can successfully trigger the vulnerability are selected and retained, such as payloads that can be parsed by the target system; non-core segments of the two effective payloads are swapped through crossover; mutation includes encoding mutation, redundancy insertion, and protocol substitution. The core of mutation is to modify non-critical parts, such as encoding methods and redundant fields, while retaining the core logic of vulnerability exploitation.

[0049] Step 10143: Variant Screening: Through a digital twin environment simulation, test whether the variant can bypass the defense system and maintain the vulnerability exploitation capability. Retain valid variants, such as those whose coded mutated payload is neither intercepted by the WAF nor fails to successfully trigger the vulnerability.

[0050] The mutated payload has the same function as the initial payload, such as being able to execute commands by exploiting the target vulnerability, but the form is different, which can bypass defenses based on static features.

[0051] Step 102: Optimize the attack path using reinforcement learning algorithms to simulate the adversarial thinking of a real attacker.

[0052] To minimize disruption to the production environment, the system incorporates a digital twin environment integration, which simulates attack paths and real network topology and defense configurations in a virtual environment, ensuring the realism of the attack simulation while reducing verification risks.

[0053] The attack path is optimized using a reinforcement learning Q-value update formula. Q-value formula 1:

[0054] Where Q(s,a) represents the Q-value of performing action a in state s, used to evaluate the value of the state-action pair; state s is the current environmental state of the attack, including breached defense nodes, current network topology location, and exploitable vulnerability information; action a is the attack behavior that the attacker can perform in the current state; α is the learning rate, 0 < α ≤ 1, which determines the degree to which newly acquired information updates the original Q-value, dynamically adjusted by the system based on historical learning effects, with an initial value of 0.5, dynamically adjusted by the system based on historical learning effects; r is the immediate reward obtained after performing action a. When the attack path is closer to the target or successfully bypasses a defense node, r is a positive value, for example, r = +10, and vice versa, it is a negative value, for example, r = -5, its value is set according to the significance of the attack effect; γ is the discount factor, 0 ≤ γ ≤ 1, representing the importance of future rewards, set by the system based on the urgency of the attack scenario, generally with a value of 0.9; s' is the new state reached after performing action a; max a' Q(s',a') represents the maximum value of Q among all possible actions in the new state s'.

[0055] An attack path is a sequence of attack steps taken by an attacker from the attack origin to the target, such as scanning ports → exploiting vulnerabilities to infiltrate → lateral movement → acquiring data.

[0056] Q(s,a) is the value evaluation of performing action a in state s in reinforcement learning, used to measure the effectiveness of the action in advancing the attack path. The optimization of the attack path is achieved through Q-value updates: when an action, such as exploiting a vulnerability, brings the attack closer to the target, the reward r is positive and the Q-value increases, and the action is given priority; conversely, the Q-value decreases and the action is eliminated, ultimately forming the optimal attack path.

[0057] When Q(s,a)>10, it indicates a high-value action. This action, such as exploiting a vulnerability to infiltrate a database, can significantly advance the attack and bring the path closer to the target, such as a core server, and will be given priority.

[0058] When 0 < Q(s,a) ≤ 10, it indicates a medium-value action. The action has some effect, such as moving laterally to the middleware server, but its progress towards the target is limited. It should be selected according to the situation.

[0059] When Q(s,a)≤0, it indicates a low-value or negative-value action, which is invalid. Such actions include attacking a closed port or causing the attack to be exposed, such as triggering a firewall alarm, and will be eliminated.

[0060] Step 103: Digital twin environment rehearsal.

[0061] A digital twin environment simulates real network topology and defense configurations, rehearses attack paths, and reduces risks to the production environment. It simulates attack paths in a virtual environment and outputs diverse attack vectors and the total number of attack paths N. total .

[0062] Step 1031: An attack vector is a combination of attack payload, path, and triggering conditions, including penetration testing scripts, exploit programs, and malicious code injection instructions. The specific steps for generating attack vectors are as follows: Step 10311: Initial attack vector generation.

[0063] Input the attack scenarios from the threat modeling knowledge base 500 and the parameters from the dynamic policy library 400, and use generative AI to generate initial vectors, such as VBA macro code scripts.

[0064] Step 10312: Reinforcement learning optimizes attack vector parameters.

[0065] The vector parameters are adjusted based on the Q-learning algorithm to increase the probability of bypassing defenses: state s represents the characteristics of the current attack environment, and action a represents the adjustment of vector parameters. Q-value update: If the adjusted vector successfully bypasses macro security detection after testing in a digital twin environment, for example, with an immediate reward r=+8, it is updated according to the Q-value formula.

[0066] Step 10313: Diversified vector generation.

[0067] The optimized vectors are expanded in multiple dimensions, such as implementations in different programming languages ​​and different attack entry points, to generate diverse vector sets that cover more attack paths, i.e., attack vectors.

[0068] The final output attack vector is an execution carrier that is adapted to the target environment and can effectively bypass defenses.

[0069] Step 1032: Total number of attack paths N total This is the sum of all possible attack paths generated by Attack Simulation Engine 100, used to calculate the attack path blocking rate. Total number of attack paths N total The steps to derive this are as follows: Step 10321: Define the state and action space of the attack path.

[0070] State s: Key nodes in the attack process, such as external network → edge firewall → DMZ zone server → core database.

[0071] Action a: Transition behavior between states, such as bypassing firewalls, exploiting vulnerabilities to infiltrate servers, and lateral movement.

[0072] Step 10322: Use the Depth-First Search (DFS) algorithm to traverse the state space and generate all possible paths from the starting point to the target.

[0073] Step 10323: Deduplication and Filtering: Eliminate completely identical paths, such as those with the same step sequence and attack vector. Retain valid paths, i.e., paths that can theoretically reach the target, and eliminate invalid paths with contradictory attack steps, such as those that first infiltrate the core database and then breach the firewall.

[0074] Step 10324: Count the total number: Count the valid paths after deduplication and filtering, which is N. total N total The core of this approach is to fully cover all possible attack paths by traversing the state space, ensuring the accuracy of subsequent blocking rate calculations and providing a reliable denominator for defense effectiveness assessment.

[0075] Defense Response Monitor 200: The defense response monitor 200 collects response data from defense systems such as firewalls, IPS, and WAF in real time, standardizes the response data, filters redundancy and unifies the format, calculates the defense response delay and the number of blocked attack paths, and outputs standardized data to provide a basis for performance evaluation. Furthermore, the data standardization processing of the defense response monitor 200 includes: using a hash algorithm to identify and filter duplicate records, using a rule engine to remove invalid data and data with incorrect format, and unifying the log fields and formats of the multi-source defense system, such as timestamps, IP addresses, and interception results, based on a preset heterogeneous field-standard field mapping table.

[0076] Furthermore, in the defense response monitor 200, the calculation of the number of blocked attack paths is implemented through a finite state machine model, which divides the attack path status into not started, in progress, successful, and blocked, counts the number of blocked paths, and uses a hash table to remove duplicates to ensure accurate counting.

[0077] Response data includes: firewall interception records, IPS alarm information, and WAF processing time. Response data is collected in real-time from the logs of defense systems such as firewalls, IPS, and WAFs, through log interface interfaces or agent programs.

[0078] The processing method of the Defense Response Monitor 200 is as follows: Step 201: Data standardization involves cleaning and organizing the response data from multi-source defense systems such as firewalls, IPS, and WAFs to ensure uniform data format, absence of redundancy and errors, and to provide reliable input for the performance evaluation of the Intelligent Decision Center 300. The specific steps of data standardization are as follows: Step 2011: Raw Data Acquisition and Parsing: Raw response data from the defense system, such as firewall logs, IPS alarm logs, and WAF processing records, is collected in real time via Agent programs or API interfaces and parsed into processable structured data, such as JSON and CSV formats. A log parser based on regular expressions (Regex) is used, with parsing rules written for different log formats of the defense system.

[0079] Step 2012: Redundant data filtering.

[0080] Duplicate data detection: A hash algorithm, such as MD5, is used to generate a unique hash value for each record. Duplicate records are identified by comparing hash values. If the same attack is repeatedly alerted by multiple defense nodes, the earliest or most complete record is retained.

[0081] Invalid data removal: Filter data that is irrelevant to attack and defense verification based on business rules, and identify invalid data through keyword matching.

[0082] Low-value data filtering: Response data for attacks marked as invalid attacks for testing by the attack simulation engine 100, such as attack vectors known to be unsuccessful, are directly filtered out.

[0083] Step 2013: Error data identification and correction.

[0084] A rule engine, such as Drools, is used, with preset field format rules. Data that does not conform to the rules is marked as erroneous. For records with missing key fields, if they can be supplemented by associating with other fields, they are supplemented; otherwise, they are discarded.

[0085] Logical contradiction detection: Inconsistent data is identified through logical verification algorithms, marked as errors, and removed.

[0086] Step 2014: Standardize the format.

[0087] Logs are parsed using regular expressions and mapped to standard fields.

[0088] The standardized output data is in the form of a structured table or JSON array, which can be directly accessed by the Intelligent Decision Center 300.

[0089] Step 202: Calculate the indicators.

[0090] Step 2021: Calculate the defense response delay T delay , Formula 2:

[0091] Among them, T start The time when the defense system detected the attack vector is obtained from the defense system logs, T. endThe time taken for the defense system to complete processing of the attack vector, such as interception and alerting, is also obtained from the defense system logs and is measured in seconds.

[0092] Step 2022: Calculate the number N of blocked attack paths. blocked The path state is determined by a finite state machine (FSM): not started (S0), in progress (S1), successful (S2), blocked (S3). The number of paths in state S3 is counted and deduplicated using a hash table to ensure that the same path is counted only once.

[0093] The Defense Response Monitor 200 outputs standardized defense response data, including T delay Interception results and the number of blocked attack paths N blocked , to the intelligent decision-making center 300.

[0094] Intelligent Decision Center 300: The intelligent decision-making center 300 integrates defense response data, policy library rules, and threat characteristics to calculate multi-dimensional indicators such as attack path blocking rate and vulnerability exploitation success rate. Combined with cross-domain collaborative verification and quantum encryption countermeasures, it generates defense effectiveness evaluation results and optimization instructions to drive closed-loop optimization. Furthermore, the multi-dimensional evaluation algorithm of the intelligent decision-making center 300 adopts the analytic hierarchy process (AHP) to assign weights to indicators such as attack path blocking rate, defense response delay, and vulnerability exploitation success rate. The indicators are converted into standardized scores through linear normalization, and the weighted sum is used to generate a comprehensive defense effectiveness score and level, including excellent, good, medium, and poor.

[0095] Furthermore, the cross-domain collaborative verification of the intelligent decision-making center 300 includes: generating cross-domain attack scenarios covering cloud environment, mobile terminal, and IoT device; collecting multi-domain defense data to calculate intra-domain blocking rate and inter-domain collaboration rate; using the Kriging interpolation algorithm to generate a full-domain defense heat map; and locating cross-domain defense blind spots.

[0096] Furthermore, the quantum encryption countermeasure assessment of the intelligent decision-making center 300 includes: simulating the threat of quantum attacks such as Shor's algorithm and Grover's algorithm to existing encryption mechanisms, such as RSA and AES, calculating the quantum cracking time and comparing it with the key update cycle, assessing the vulnerability of encryption defenses and proposing suggestions for quantum-resistant upgrades.

[0097] The policy base rules refer to the criteria for evaluating defense effectiveness stored in the dynamic policy base 400, such as an attack path blocking rate of ≥90%, and rules that drive optimization, such as adjusting the firewall detection threshold if the response latency is >1 second. Threat signatures refer to the unique identifiers of attacks extracted from the threat modeling knowledge base 500, such as the C2 server IP of APT attacks and the exploit signature codes of zero-day vulnerabilities. The policy base's evaluation strategies are the rules for calculating indicators that quantify defense effectiveness, such as blocking rate = number of blocked paths / total number of paths; optimization rules are the adjustment logic when the defense is not up to standard, such as updating WAF rules if the vulnerability exploitation success rate is >5%.

[0098] The intelligent decision-making center 300 uses the following methods for analysis and evaluation: Step 301: Determine the evaluation indicator system, including the following evaluation indicators.

[0099] Attack path blocking rate R block , Formula 3:

[0100] R block This reflects the proportion of attack paths intercepted by the defense system. Among them, N... blocked N represents the number of blocked attack paths, calculated from interception records in the defense response data. total This represents the total number of attack paths, recorded and provided by the attack simulation engine 100.

[0101] Exploitation success rate R success , Formula 4:

[0102] R success This reflects the effectiveness of the defense system in intercepting vulnerability attacks. Among them, N success The number of attacks successfully exploiting the vulnerability was determined by combining defense response data and records from attack simulation engine 100. attempts The total number of attacks attempting to exploit the vulnerability was recorded by the attack simulation engine 100.

[0103] Average response delay T delay_avg , Formula 5:

[0104] T delay_avg This reflects the average time taken by the defense system from detecting an attack to completing the response. Among them, T... delay To defend against response delays, N total This represents the total number of attacks.

[0105] Cross-domain defense consistency C cross , Formula 6:

[0106] C cross This reflects the differences in defense capabilities across cross-domain scenarios such as cloud and endpoints; a lower value is better. Among them, R... block_domain R represents the attack path blocking rate for a specific domain. block_avg N represents the average attack path blocking rate across all domains. domain The number of domains.

[0107] Step 302: Multi-dimensional defense effectiveness assessment.

[0108] Based on the above indicators and information from the dynamic strategy library 400 and the threat modeling knowledge base 500, a multi-dimensional evaluation algorithm is used to quantitatively evaluate the defense and generate a defense effectiveness evaluation result. The specific steps are as follows: Step 3021: Indicator weight allocation: The Analytic Hierarchy Process (AHP) is used to determine R. block T delay_avg R success and C cross The weights are (w1, w2, ..., w4), and the sum of the weights is 1.

[0109] Step 3022: Standardization of indicators.

[0110] The original index values ​​are converted into standardized scores of 0 to 100 to eliminate the influence of dimensions, using a linear normalization algorithm: Positive indicators, the higher the value, the better, such as R. block , Formula 7:

[0111] Negative indicators, the smaller the value the better, such as T. delay_avg , Formula 8:

[0112] Where, x i x is the original value. max x min The threshold values ​​for metrics set for Dynamic Strategy Library 400, such as R block The maximum value is 100%, and the minimum value is 50%.

[0113] Step 3023: Calculate the total defense effectiveness score S using the weighted summation formula. total , Formula 9:

[0114] Step 3024: Performance level and weak link determination.

[0115] Level classification: Refer to the preset thresholds of the dynamic policy library 400, such as S.total ≥90 is excellent, 80-89 is good, 70-79 is average, and <70 is poor, thus determining the performance level.

[0116] Weakness identification: through indicator contribution analysis. i ×(100-S i Identify the lowest-scoring metrics, such as R. success With a score of 60, it made the highest contribution and identified weak points, such as insufficient defense against vulnerability attacks.

[0117] The defense effectiveness assessment result is a total score + grade + weak point. For example: the total defense effectiveness score is 73 points, the grade is medium, and the weak point is a low vulnerability exploitation interception rate of 60 points.

[0118] The preset thresholds for defense effectiveness are the standards set by the system to meet the defense effectiveness requirements, such as Rblock≥90%, Tdelay≤0.5 seconds, and comprehensive score≥85 points, which are set based on industry best practices, enterprise security needs, and historical verification data.

[0119] Step 303: Cross-domain collaborative verification extends attack simulation and defense assessment to multi-domain scenarios such as cloud environments, mobile terminals, and IoT devices. Through comprehensive data correlation analysis, a defense capability heatmap is generated to pinpoint cross-domain defense blind spots. The specific method is as follows: Step 3031: Generation of cross-domain attack scenarios.

[0120] Based on the cross-domain attack characteristics of the Threat Modeling Knowledge Base 500, such as cloud container escape → attacking IoT devices, attack scenarios covering multiple domains are generated to ensure that the attack path includes at least two different domains, such as external network → cloud server → terminal device.

[0121] We employ the minimum spanning tree algorithm from graph theory, using domains as nodes (such as cloud, terminal, and IoT) and attack path connectivity as edges to generate a minimum set of attack scenarios covering all domains, thus reducing redundant testing.

[0122] Step 3032: Multi-domain defense data collection and synchronization.

[0123] The system collects response data from various domain defense systems through distributed agents, such as cloud WAF logs, endpoint EDR alarms, and IoT firewall records. It employs timestamp alignment algorithms, such as NTP synchronization, to ensure the time consistency of cross-domain data. A unique ID is assigned to each cross-domain attack path, and the defense records of different domains are associated with this ID.

[0124] Step 3033: Calculate cross-domain defense indicators.

[0125] Using the MapReduce distributed framework, the intra-domain blocking rate R is calculated by grouping by domain.block_domain , Formula 10:

[0126] R block_domain This represents the attack path blocking rate within a single domain, such as independent domains like the cloud and endpoints. Where N... blocked_domain N represents the number of attack paths successfully blocked within this domain. total_domain This represents the total number of attack paths within the domain.

[0127] Calculate the inter-domain collaboration rate R using associated IDs. coop , Formula 11:

[0128] R coop Measure the ability of multiple domains, such as cloud + endpoint, to jointly intercept cross-domain attacks. Among them, N cross_block N represents the number of cross-domain attacks successfully intercepted by multi-domain collaboration. cross_attempts This represents the total number of cross-domain attack attempts.

[0129] Step 3034: Generate a heatmap for global defense.

[0130] Each domain is abstracted into spatial coordinates, such as cloud = (1,1) and terminal = (2,3). The Kriging interpolation algorithm is then used to interpolate R. block_domain Spatial interpolation is performed to generate a continuous heatmap of defense capabilities, which is then displayed using heatmap tools such as Matplotlib.

[0131] Step 304: Quantum encryption defense assessment simulates the threat posed by quantum computing to existing encryption defense systems, evaluates the resistance of encryption mechanisms such as AES to quantum attacks, identifies vulnerabilities, and proposes upgrade suggestions. The specific methods are as follows: Step 3041: Quantum attack scenario modeling: Based on a mathematical model of quantum computing, simulate typical quantum attacks against existing encryption algorithms, such as simulating Shor's algorithm to crack RSA and Grover's algorithm to accelerate AES brute-force cracking.

[0132] Step 3042: Extraction of encryption defense system parameters: Collect key parameters of the current encryption defense, including: encryption algorithm type, such as RSA-2048 and AES-256; key length, such as 2048 bits and 256 bits; key update cycle.

[0133] Step 3043: Simulation of quantum attack resistance: Calculate the cracking time using the Qiskit simulator and output the theoretical cracking time.

[0134] Step 3044: Vulnerability assessment.

[0135] Judgment rule: If the quantum cracking time is less than the key update cycle, the encryption defense has high vulnerability; otherwise, it has low vulnerability.

[0136] The Intelligent Decision Center 300 outputs defense effectiveness assessment results, a global defense heatmap, and a quantum encryption vulnerability report. The defense effectiveness assessment results include a comprehensive score, level, and weak points. Based on the assessment results, if the defense effectiveness does not reach a preset threshold, it generates instructions for optimizing the defense system configuration or instructions for adjusting the attack strategy from the Attack Simulation Engine 100.

[0137] Dynamic Policy Library 400: The dynamic strategy library 400 stores evaluation strategies and optimization rules, including industry compliance standards. It dynamically adjusts strategy parameters, such as interception thresholds, based on the evaluation results of the intelligent decision-making center 300, providing real-time updated rule support for intelligent decision-making. Furthermore, the dynamic strategy library 400 adjusts its strategies according to preset update rules. When the defense effectiveness does not meet the standard, such as when the attack path blocking rate is lower than the threshold, the evaluation index threshold is adjusted, such as temporarily lowering the blocking rate threshold, and the rule triggering conditions are optimized, such as shortening the response delay threshold to improve sensitivity.

[0138] The methods for adjusting and updating strategies are as follows: Adjustment basis: When the evaluation results of the Intelligent Decision Center 300 show that the defense effectiveness does not meet the standard, such as R block =85% < 90%, adjust according to preset update rules, such as reducing the blocking threshold by 10% for every 5% decrease in the blocking rate below the threshold.

[0139] Adjusting parameters: This includes setting thresholds for evaluation metrics, such as R... block The threshold has been temporarily lowered from 90% to 85% to adapt to the current defense capabilities; the triggering conditions of the rules have been optimized, such as adjusting the response latency > 1 second to response latency > 0.8 seconds to improve sensitivity.

[0140] Updated evaluation strategies and optimization rules: strategies more suited to the current network environment, such as those for cloud environments, R block The threshold has been adjusted to 80%, and a container vulnerability exploitation success rate assessment metric has been added.

[0141] The dynamic strategy library 400 outputs updated evaluation strategies and optimization rules to the intelligent decision-making center 300.

[0142] Threat Modeling Knowledge Base 500: The threat modeling knowledge base 500 integrates historical attack and defense data with real-time threat intelligence. Through machine learning, such as deep learning and clustering algorithms, it dynamically generates new attack scenarios, constructs a defense knowledge graph, and associates attack-defense-vulnerability relationships to provide scenario basis for attack simulation.

[0143] Furthermore, the generation of novel attack scenarios in the threat modeling knowledge base 500 is achieved through clustering algorithms. The extracted attack features are grouped according to similarity, and combined with real-time threat intelligence, such as zero-day vulnerability information, the feature groups are expanded to generate scenarios simulating novel attacks such as supply chain attacks and quantum attacks.

[0144] Furthermore, the construction of the defense knowledge graph of the threat modeling knowledge base 500 includes: identifying entities such as attack types, defense measures, and vulnerabilities from historical data and real-time intelligence; extracting entity relationships such as exploitation and defense; organizing them into a graph structure through knowledge graph tools; and supporting complex queries and reasoning of attack-defense-vulnerability relationships.

[0145] The Threat Modeling Knowledge Base 500 is a module that integrates historical attack and defense data with real-time threat intelligence, dynamically generating new attack scenarios through machine learning. Its data sources include historical attack cases, defense measure records, zero-day vulnerability information, and APT activity reports, which are then analyzed and processed using deep learning and clustering algorithms. Attack characteristics are the technical features of the attack, such as the use of a specific port 8080; defense standards are the baseline that the defense system should achieve, such as an interception delay of less than 0.5 seconds for known vulnerabilities.

[0146] Historical attack and defense data refers to records of past attack events, defensive measures, and their effectiveness, such as the firewall rules used at the time and whether they were successfully blocked, sourced from security log archives. Real-time threat intelligence refers to information on emerging threats that have recently occurred, sourced from real-time push notifications from threat intelligence platforms.

[0147] The processing method for Threat Modeling Knowledge Base 500 is as follows: Step 501: Utilize deep learning to analyze historical attack and defense data and real-time threat intelligence to extract attack characteristics, patterns, and trends; Deep learning is a machine learning technique based on neural networks, which has the ability to process complex data, such as unstructured logs and malicious code samples.

[0148] Analysis and Feature Extraction: Through deep learning models, such as CNN to identify malicious code features and LSTM to analyze the temporal features of attack paths, historical data and real-time intelligence are trained to automatically extract common features, patterns and trends of attacks. Common features include APT attacks often using phishing emails as the initial entry point, patterns include attack paths of phishing → Trojan implantation → lateral movement, and trends include a 30% year-on-year increase in the proportion of attacks targeting cloud-native technologies.

[0149] Step 502: Based on the analysis results, the clustering algorithm dynamically generates new attack scenarios, such as simulating zero-day vulnerability attacks or advanced tactics of APT groups.

[0150] Clustering algorithms are unsupervised learning algorithms that group similar data, such as K-means.

[0151] Generate new attack scenarios: The extracted attack features are grouped by similarity using clustering algorithms. For example, zero-day exploits and lateral movement are grouped into one category. Combined with real-time threat intelligence, such as new vulnerabilities, the features within the group are expanded to generate simulated scenarios, such as a scenario in which cloud servers are compromised through supply chain attacks using the CVE-2025-XXX zero-day vulnerability.

[0152] Step 503: Construct a defense knowledge graph: link attack methods, defense measures, and vulnerability information to improve the intelligence of decision-making.

[0153] A defense knowledge graph is a graph-based data structure used to represent the complex relationships between attacks, defenses, and vulnerabilities. Its construction process includes the following steps: Step 5031: Entity Identification: Identify entities from historical attack and defense data, threat intelligence, and defense systems, such as attack types, defense measures, and vulnerabilities.

[0154] Step 5032: Relationship Extraction: Determine the relationships between entities, such as exploitation, defense, and mitigation.

[0155] Step 5033: Graph Construction: Organize entities and relationships into a graph structure, where nodes represent entities and edges represent relationships.

[0156] Step 5034: Knowledge Reasoning: Use graph algorithms and machine learning methods to perform knowledge reasoning and discover new associations and patterns.

[0157] The advantage of defense knowledge graphs lies in their ability to intuitively display the knowledge structure in the security field, support complex queries and reasoning, and provide more comprehensive knowledge support for intelligent decision-making.

[0158] The Threat Modeling Knowledge Base 500 outputs new attack scenarios to the Attack Simulation Engine 100, providing a basis for generating attack vectors.

[0159] The system consists of: Attack component: Attack simulation engine 100, responsible for generating attack vectors and executing simulated attacks.

[0160] Defense component: Existing defense systems, such as firewalls, IPS, and WAF, are responsible for actual defense.

[0161] The verification component consists of a defense response monitor 200 that collects defense data, an intelligent decision-making center 300 that evaluates effectiveness, a dynamic policy library 400 that provides strategies, and a knowledge base 500 that provides threat modeling knowledge for attack scenarios. These components work together to complete the verification.

[0162] The entities and contents responsible for attack, defense, verification, and adjustment: Attack: Executed by Attack Simulation Engine 100, simulating various attack behaviors.

[0163] Defense: Performed by the defense system, it intercepts and alerts to attacks.

[0164] Verification: This is performed collaboratively by various modules of the system, with the monitor collecting data and the decision center evaluating its effectiveness.

[0165] Adjustments: Driven by the intelligent decision-making center 300, the adjustments include the defense system, optimizing configurations such as updating rules, and the attack simulation engine 100, adjusting strategies such as adding new types of attacks.

[0166] Validity, validation results, and ongoing validation: Effectiveness: refers to the defense system's ability to resist real attacks, such as whether it can intercept new APT attacks and zero-day exploits.

[0167] Verification results: refers to the defense effectiveness assessment report, including indicators such as blocking rate and latency, as well as weaknesses.

[0168] Continuous verification of implementation method: Through attack simulation → defense response → performance evaluation → strategy update → new round of attack simulation, a closed-loop mechanism of attack-defense-analysis-optimization is formed, which runs automatically 24 / 7 without manual intervention.

[0169] Verification termination time: There is no fixed termination time; the system runs continuously to dynamically adapt to constantly changing attack methods and defense requirements.

[0170] like Figure 2 As shown, the overall verification process of this fully automated continuous verification system for the effectiveness of security attacks and defenses is as follows: Step 1: Attack Simulation Phase: Objective: Generate highly realistic attack vectors, simulate attack behavior, and test the defense system's response capabilities.

[0171] The attack simulation engine 100 receives attack scenarios from the threat modeling knowledge base 500, policy parameters from the dynamic policy library 400, and global threat intelligence. It generates attack payloads through generative AI analysis of the intelligence, optimizes attack paths through reinforcement learning, and performs pre-simulation in a digital twin environment to ensure the realism of the attack simulation while reducing verification risks. It then outputs attack vectors to the defense system and records the total number of attack paths N. total .

[0172] Step 2: Defense Response Phase: Objective: To capture data on the defense system's response to attacks, providing raw data for evaluating defense effectiveness.

[0173] The Defense Response Monitor 200 collects real-time response data from firewalls, IPS, WAFs, and other defense systems in response to attack vectors, including interception records and processing times. After standardization, it calculates T. delay and N blocked The output is sent to the intelligent decision-making center 300.

[0174] Step 3: Analysis and Evaluation Phase: Objective: Quantitatively assess defense effectiveness and identify weaknesses.

[0175] The intelligent decision-making center 300 combines defense response data, dynamic policy library 400 rules, and threat characteristics to calculate R. block T delay_avg R success C cross The indicators generate a global heatmap through cross-domain collaborative verification, simulate quantum encryption attacks to assess vulnerabilities, and generate defense effectiveness assessment results.

[0176] Step 4: Optimization and Adjustment Phase: Objective: To form a closed loop and continuously optimize the defense system.

[0177] If the defense effectiveness fails to meet the standard, the intelligent decision center 300 generates optimization instructions: the defense system adjusts its configuration according to the instructions, the attack simulation engine 100 adjusts its strategy, the dynamic strategy library 400 updates its rules, the threat modeling knowledge base 500 generates new attack scenarios, and the next round of verification is initiated.

[0178] Example 2 Based on the same inventive concept as the fully automated continuous verification system for the effectiveness of security attack and defense provided in the embodiments of this application, the embodiments of this application also provide a fully automated continuous verification method for the effectiveness of security attack and defense. If there is anything unclear about the content in the system embodiments, please refer to the corresponding content in the method embodiments.

[0179] like Figure 3 As shown, the fully automated continuous verification method for the effectiveness of security attacks and defenses includes the following steps: Step S1: Multi-source threat intelligence processing and attack signature modeling.

[0180] Step S1.1: Intelligence Aggregation and Cleaning: Integrate open-source intelligence, commercial intelligence, and industry-specific intelligence, use the MD5 hash algorithm to remove duplicate intelligence entries, filter low-credibility information through a rule engine, such as rumors of zero-day vulnerabilities from unknown sources, and then form a standardized intelligence set through terminology normalization, such as classifying spear phishing attacks and phishing emails as social engineering initial access.

[0181] Open-source intelligence, such as the CVE vulnerability database and the MITREATT&CK framework; commercial intelligence, such as APT group attack tactic reports; and industry-specific intelligence, such as attack characteristics of IoT devices in the energy sector.

[0182] Step S1.2: Attack Feature Extraction and Scenario Generalization: Based on clustering algorithms such as K-means, attack features of the cleaned intelligence, such as vulnerability exploitation methods, attack path sequences, and payload encoding formats, are grouped by similarity. Combined with historical attack and defense data, such as past attack interception logs, cross-domain composite attack logic is generalized, such as cloud server container escape → mobile terminal lateral penetration → IoT sensor data theft. The attack targets and technical paths are clarified. Attack targets include core business systems and production data storage nodes, and technical paths include port scanning → vulnerability exploitation → privilege escalation → data theft.

[0183] Step S1.3: Verify parameter presets: Based on the characteristics of the target IT architecture, such as the number of public cloud nodes and the protocol type of IoT devices, preset attack strength thresholds, such as the number of simulated attack paths in a single round ≥ 50, and defense effectiveness evaluation benchmarks, such as an attack path blocking rate ≥ 90% to meet the standard, to provide a basis for subsequent verification.

[0184] Step S2: AI-driven high-fidelity attack generation and simulation.

[0185] Step S2.1: Generation of Unknown Threat Payloads: Generative Adversarial Networks (GANs) and large language models are used to collaboratively generate attack payloads. The GAN generator creates initial payloads based on the attack characteristics identified in Step S1, such as container escape scripts and IoT vulnerability exploits. The discriminator verifies the matching degree between the payload and real attacks using a cosine similarity algorithm, with a threshold of ≥90%. Iterative optimization generates variant payloads that can bypass static feature detection, such as zero-day vulnerability payloads that modify character encoding. Simultaneously, the large language model is used to parse attack technology documents, such as APT attack tool source code comments, to supplement the attack logic details of the payload, such as permission spoofing strategies during lateral movement.

[0186] Step S2.2: Intelligent Optimization of Attack Path: Based on reinforcement learning Q-value update formula 1, evaluate the value of attack action-environment state: prioritize high-value actions, such as exploiting unauthorized access vulnerabilities in cloud servers to breach boundaries, Q-value > 10, immediate reward r = +10, eliminate low-value actions, such as attacking closed test ports, Q-value ≤ 0, r = -5, forming an attack path that fits the thinking of real hackers, ensuring coverage of key cross-domain nodes, such as cloud → terminal → Internet of Things.

[0187] Step S2.3: Security rehearsal in digital twin environment: In a virtual environment that replicates the target IT architecture at a 1:1 scale, such as network topology, device configuration and defense strategy, execute the optimized attack path, record all possible attack vectors and the total number of attack paths. The attack vectors include web layer, network layer and terminal layer attack carriers. At the same time, avoid interfering with the production system, such as not triggering production control commands of IoT devices.

[0188] Step S3: Defense response data collection and standardization processing.

[0189] Step S3.1: Real-time Collection of Multi-Domain Response Data: Through distributed data collection nodes, synchronously acquire response data of each defense node in the target IT architecture to the attack vector, including attack interception records, alarm information, processing time, and defense action types, such as blocking, alarming, and allowing. Defense nodes include firewalls, web application firewalls, endpoint detection and response tools, and IoT security gateways.

[0190] Step S3.2: Data Cleaning and Format Unification: Use hash deduplication to remove duplicate alarm records of the same attack, filter by the rule engine, delete invalid data without attack identifiers or with abnormal timestamps, and then, based on the preset heterogeneous field-standard field mapping table, unify the interception results and blocking status into defense result fields, and convert unstructured logs of different defense nodes, such as firewall text logs and terminal JSON logs, into standardized structured data, such as CSV or JSON format.

[0191] Step S3.3: Preliminary calculation of key defense indicators: Based on the finite state machine model, the attack path state is divided into not started - in execution - successful - blocked, and the number of blocked attack paths is counted; the response delay of a single attack is calculated according to the defense response delay = the time when the defense node detects the attack - the time when the defense action is completed, forming basic data that can be directly used for evaluation.

[0192] Step S4: Quantitative evaluation of multi-dimensional defense effectiveness.

[0193] Step S4.1: Calculation of core defense metrics: Based on the total number of attack paths in Step S2 and the standardized data in Step S3, calculate key performance metrics: Attack path blocking rate = number of blocked attack paths / total number of attack paths, reflecting the overall defense and interception capability; Cross-domain defense coordination rate = number of cross-domain attack paths blocked by multi-domain coordination / total number of cross-domain attack paths, reflecting the effectiveness of inter-domain defense coordination; Average defense response latency = sum of response latencies for all attacks / total number of attacks, reflecting the timeliness of defense; Vulnerability exploitation success rate = number of attacks that successfully exploited the vulnerability / total number of attacks that attempted to exploit the vulnerability, reflecting the effectiveness of vulnerability protection.

[0194] Step S4.2: Cross-domain defense blind spot location: Map the attack path blocking rate of each security domain, such as cloud, terminal and IoT, to spatial heat value, and use the Kriging interpolation algorithm to generate a global defense heat map. Areas with heat value <60 are identified as cross-domain defense blind spots, such as the weak collaborative interception capability of cloud-IoT data transmission links.

[0195] Step S4.3: Quantum Attack Resistance Assessment: Simulate quantum computing attacks, such as Shor's algorithm breaking RSA encryption and Grover's algorithm accelerating AES brute-force attacks, calculate the theoretical quantum cracking time of core encryption mechanisms in the target IT architecture, such as production data transmission encryption and device authentication encryption, and compare it with the current key update cycle: if the cracking time is less than the update cycle, it is judged as high encryption vulnerability; otherwise, it is low vulnerability.

[0196] Step S4.4: Comprehensive Performance Level Determination: The Analytic Hierarchy Process (AHP) is used to assign weights to the above indicators, such as attack path blocking rate 0.4, cross-domain coordination rate 0.1, response latency 0.2, vulnerability exploitation success rate 0.2, and quantum vulnerability resistance 0.1. The indicator values ​​are converted into standardized scores of 0 to 100 through linear normalization. The weighted sum is used to generate a comprehensive performance score. The score is compared with the preset thresholds: ≥90 points is excellent, 80-89 points is good, 70-79 points is medium, and <70 points is poor, thus determining the defense performance level.

[0197] Step S5: Dynamic optimization and continuous iterative verification.

[0198] Step S5.1: Optimization Strategy Generation: If the overall performance score fails to meet the standard, such as <70 points, or if a single indicator is abnormal, such as cross-domain collaboration rate <80% and high encryption vulnerability, a targeted optimization strategy is generated based on the evaluation results: On the defense side: Adjust the configuration of defense nodes, such as updating Web Application Firewall rules, shortening the key update cycle, and establishing an inter-domain threat intelligence synchronization mechanism; Verification end: Optimize attack simulation parameters, such as adding unknown threat payload types and adjusting the priority of cross-domain attack paths.

[0199] Step S5.2: Verify the logic update: Adjust the attack feature model according to the optimization strategy, such as adding quantum attack adaptation scenarios and updating the performance evaluation threshold, such as temporarily adjusting the cross-domain collaboration rate target threshold to 75% to adapt to short-term optimization goals.

[0200] Step S5.3: Closed-loop iterative verification: The updated intelligence, attack characteristics, and evaluation thresholds are fed back to step S1, and the next round of intelligence processing-attack simulation-performance evaluation-optimization cycle is automatically started to achieve 24 / 7 fully automated continuous verification and ensure that the defense effectiveness always matches the trend of threat evolution.

[0201] Obviously, the embodiments described above are only some embodiments of this application, not all embodiments. The accompanying drawings show preferred embodiments of this application, but do not limit the patent scope of this application. This application can be implemented in many different forms; rather, the purpose of providing these embodiments is to provide a more thorough and comprehensive understanding of the disclosure of this application. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing specific embodiments, or make equivalent substitutions for some of the technical features. Any equivalent structures made using the content of this application's specification and drawings, directly or indirectly applied to other related technical fields, are similarly within the scope of patent protection of this application.

Claims

1. A fully automated continuous verification system for security attack-defense effectiveness, characterized in that, The system comprises: An attack simulation engine for receiving attack scenarios provided by a threat modeling knowledge base, policy parameters provided by a dynamic policy library, and global threat intelligence, using generative AI to analyze global threat intelligence to generate highly simulated network attack payloads and variants, optimizing attack paths through reinforcement learning algorithms, and after pre-attack in a digital twin environment, injecting generated diversified attack vectors into the defense system for security testing, and recording and outputting the total number of attack paths; A defense response monitor for real-time collection and standardized processing of defense system response data, calculating defense response delay and blocked attack path number, and outputting standardized data; An intelligent decision hub for fusing defense response data, policy rules from the dynamic policy library, and threat characteristics from the threat modeling knowledge base, calculating attack path blocking rate based on total attack path number and blocked attack path number, calculating exploit success rate and average response delay, and generating defense effectiveness evaluation results and optimization instructions based on cross-domain collaborative verification and quantum encryption confrontation; A dynamic policy library for storing evaluation policies and optimization rules, dynamically adjusting policy parameters based on evaluation results and optimization instructions, and using optimization instructions to drive the defense system for configuration updates and drive the attack simulation engine to adjust attack strategies; A threat modeling knowledge base for fusing historical attack and defense data and real-time threat intelligence, dynamically generating new attack scenarios through machine learning, and building a defense knowledge graph to provide scenario basis for the attack simulation engine.

2. The fully automated continuous verification system for the effectiveness of security attack and defense according to claim 1, characterized in that, In the attack simulation engine, the generative AI includes a large language model and a generative adversarial network, and the process of generating attack payloads and variants through adversarial training includes: creating an initial attack payload through a generator, verifying the similarity of the payload to real attacks through a discriminator, iteratively optimizing generator parameters, and if the similarity meets the preset standard, stopping iteration and generating a payload variant that can bypass the defense system's feature detection.

3. The system of claim 2, wherein the system is configured to automatically and continuously verify the security attack-defense effectiveness of the system by: In the attack simulation engine, the reinforcement learning algorithm optimizes the attack path based on the Q-value update formula, prioritizes high-value attack actions by evaluating the value of state-action pairs, eliminates low-value actions, and forms an optimal attack path; the high-value action is an action that can advance the attack path and obtain positive immediate rewards, including successfully exploiting vulnerabilities; the low-value action is an action that cannot advance the attack path or leads to attack exposure and negative immediate rewards, including closing ports. ​ 4. The fully automated continuous verification system for the effectiveness of security attack and defense according to claim 1, characterized in that, The data standardization processing of the defense response monitor includes: identifying and filtering duplicate records using a hash algorithm, removing invalid data and format error data through a rule engine, and unifying log fields and formats of multiple source defense systems based on a pre-set heterogeneous field-standard field mapping table.

5. The fully automated continuous verification system for the effectiveness of security attack and defense according to claim 4, characterized in that, In the defense response monitor, the calculation of the number of blocked attack paths is implemented through a finite state machine model, which divides the attack path state into not started, executing, successful, and blocked, counts the number of paths in the blocked state, and removes duplicates through a hash table.

6. The fully automated continuous verification system for the effectiveness of security attack and defense according to claim 1, characterized in that, In the intelligent decision hub, the exploit success rate is calculated based on the number of attack attempts and the number of successful attempts, and the average response delay is calculated based on the defense response delay. The analytic hierarchy process is used to assign weights to the attack path blocking rate, average response delay, vulnerability exploitation success rate and cross-domain defense consistency index, the index is converted into a standardized score through linear normalization, the standardized scores are weighted and summed to generate a comprehensive defense performance score and grade.

7. The fully automated continuous verification system for the effectiveness of security attack and defense according to claim 6, characterized in that, In the intelligent decision center, the cross-domain collaborative verification process includes: generating cross-domain attack scenarios covering cloud environments, mobile terminals and Internet of Things devices based on cross-domain attack features of the threat modeling knowledge base, collecting multi-domain defense data relying on diversified attack vectors output by the attack simulation engine, calculating the blocking rate in each domain and the inter-domain collaboration rate, the inter-domain collaboration rate is used to quantitatively evaluate the ability of different defense domains to collaboratively intercept cross-domain attack chains, the intra-domain blocking rate is mapped to a spatial heat value using the Kriging interpolation algorithm, the inter-domain collaboration rate is used to mark the location of the collaborative blind area, and a global defense heat map is output. The cross-domain defense consistency is obtained by calculating the average absolute value of the difference between the intra-domain blocking rate of each domain and the global average blocking rate.

8. The fully automated continuous verification system for the effectiveness of security attack and defense according to claim 7, characterized in that, In the intelligent decision center, the quantum encryption confrontation process includes: simulating quantum attacks on existing encryption mechanisms, calculating quantum cracking time and comparing it with the key update period to evaluate the vulnerability of encryption defense, if the quantum cracking time is less than the key update period, it is determined that the encryption defense has high vulnerability, otherwise it has low vulnerability; and proposing anti-quantum upgrade suggestions based on the vulnerability of the encryption defense.

9. The fully automated continuous verification system for the effectiveness of security attack and defense according to claim 1, characterized in that, The strategy adjustment of the dynamic strategy library is based on a preset update rule, when the defense performance is not up to standard, the evaluation index threshold and the optimization rule trigger condition are adjusted; the defense performance not up to standard is that the comprehensive defense performance score is lower than a preset threshold, or the attack path blocking rate is lower than a preset threshold, or the average response delay is higher than a preset threshold; the evaluation index threshold includes an attack path blocking rate threshold and an average response delay threshold; The optimization rule trigger condition is a rule trigger condition for driving the defense system to perform configuration optimization or adjusting the strategy of the attack simulation engine, including a response delay threshold and a vulnerability exploitation success rate threshold.

10. The system of claim 1, wherein the system is configured to automatically and continuously verify the effectiveness of the security measures by: The new attack scenario generation of the threat modeling knowledge base is realized by a clustering algorithm, the extracted attack features are grouped according to similarity, and the feature groups are expanded in combination with real-time threat intelligence to generate scenarios simulating new attacks; ​ The defense knowledge graph construction includes: identifying entities from historical data and real-time intelligence, the entities include attack types, defense measures and vulnerabilities, extracting entity relationships, organizing the relationships into a graph structure through a knowledge graph tool, and supporting complex queries and reasoning of attack-defense-vulnerability relationships.