Defense deployment method, system and device and network target range system

By acquiring predictive topology data and constructing defensive measures, the problem of insufficient response speed of the defense system in the network range was solved, realizing proactive prediction and dynamic defense, and improving the adaptability and practicality of the defense system.

CN121841685APending Publication Date: 2026-04-10CHINA STAR NETWORK SYST RES INST CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-12
Publication Date
2026-04-10

AI Technical Summary

Technical Problem

The response speed of existing network range defense systems cannot keep up with the second-level topology changes of low-Earth orbit satellite networks, leaving the defense systems in a passive state and unable to effectively deal with dynamic network attacks.

Method used

By acquiring predictive topology data, and based on the dynamic topology simulation engine module and the predictive adaptive defense building module, the system predicts the target network attacks that the attacking object will launch, and builds defense measures in the security node devices of the test range to achieve forward-looking defense deployment.

Benefits of technology

It realizes the transformation of the defense system from passive response to active prediction, and can proactively deploy defense measures before topology events occur, improving the depth and realism of defense verification and adapting to the training needs of highly dynamic network environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121841685A_ABST
    Figure CN121841685A_ABST
Patent Text Reader

Abstract

The invention discloses a defense deployment method, a defense deployment system, a defense deployment device and a network target range system, which are used for enabling a target range defense system to have a prospective defense deployment capability. The method comprises the steps that prediction topology data are acquired, and the prediction topology data are obtained through prediction based on network topology dynamic change within a preset duration after the current moment in a network environment provided by a target range infrastructure; determining a target network attack to be initiated by an attack object based on the predicted topological data; and constructing defense measures aiming at the target network attack in the security node equipment of the target range.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of cybersecurity technology, and in particular to a defense deployment method, system, device, and network range system. Background Technology

[0002] In existing cyber ranges, the mainstream technical solutions for constructing defender verification and training scenarios are based on the core idea of ​​"transplanting" security defense systems that have matured in traditional IT networks to the virtualized range environment. This approach aims to replicate a defense infrastructure within the range that is highly similar to the real world, but is essentially static.

[0003] Before the exercise began, all defense components and their initial security policies were instantiated and deployed in a one-time process based on a pre-defined static blueprint. This initial state, built by an automated process, constituted the defense baseline for the entire exercise. Once the exercise started, security personnel operated various pre-configured security devices within this baseline environment to monitor and respond to attackers' actions. When security personnel determined, based on real-time situation analysis, that adjustments to the existing defense strategy were necessary, they typically needed to log into specific virtualized security devices to manually update their rule bases, configuration items, or alerting logic.

[0004] This method of relying on manual, passive configuration and adjustment of strategies cannot keep up with the second-level topology changes of low-Earth orbit satellite networks, resulting in the defense system always being in a passive state of being "half a beat slower" during range exercises. Summary of the Invention

[0005] This application provides a defense deployment method, system, device, equipment, medium, program product, and network range system to enable the range defense system to have the capability of forward-looking defense deployment.

[0006] In a first aspect, an embodiment of this application provides a defense deployment method, the method comprising: Acquire predicted topology data, which is obtained based on the dynamic changes in network topology within a preset time period after the current moment in the network environment provided by the range infrastructure. Based on the predicted topology data, the target network attack to be launched by the attack target is determined. Defense measures against network attacks targeting the target are constructed in the security node devices of the test range.

[0007] As an optional implementation, determining the target network attack to be launched based on the predicted topology data includes: Obtain the security event data detected by the security node device; From the attack and defense exercise database, obtain at least one network attack data associated with the network topology event in the predicted topology data. The attack and defense exercise database is used to record the association between historical network topology events and network attack data. The network attack data includes network attack behavior and attack precursor behavior. By fusing and analyzing the network topology events in the predicted topology data, the security event data, and the at least one network attack data, the target network attack to be launched by the attack target can be determined.

[0008] As an optional implementation, the step of fusing and analyzing the network topology events in the predicted topology data, the security event data, and the at least one network attack data to determine the target network attack to be launched by the attack target includes: Based on the network topology events in the predicted topology data, the security event data, and the at least one network attack data, when the confidence level of any network attack meets a preset requirement, the network attack is identified as a target network attack.

[0009] As an optional implementation, the step of constructing defenses against the target network attack in the security node equipment of the test range includes: Determine a defense strategy against the target network attack, and build defense measures in the security node device based on the defense strategy.

[0010] As an optional implementation, determining a defense strategy against the target network attack and constructing defense measures in the security node device based on the defense strategy includes: Based on a pre-configured security policy database, a defense strategy for the target network attack is determined, wherein the security policy database is used to record the correspondence between network attacks and defense strategies; Based on the defense strategy, a defense command is generated and sent to the security node device.

[0011] As an optional implementation, the method further includes: Obtain real network attacks launched by the target, record the predicted topology data, the attack precursor behaviors, and the real network attacks, and generate training sample data; The attack and defense exercise database is iteratively learned using the training sample data.

[0012] As an optional implementation, obtaining the predicted topology data includes: In response to an object-triggered predictive defense mode, the predictive topology data is acquired, and defense deployment operations are performed.

[0013] Secondly, embodiments of this application provide a defense deployment system, the system comprising: a dynamic topology simulation engine module and a predictive adaptive defense construction module, wherein, The dynamic topology simulation engine module is used to determine the predicted topology data based on the dynamic changes in network topology within a preset time period after the current moment in the network environment provided by the test range infrastructure. The predictive adaptive defense construction module is used to acquire the predicted topology data, determine the target network attack to be launched by the attack target based on the predicted topology data, and build defense measures against the target network attack in the security node device of the test range.

[0014] As an optional implementation, the predictive adaptive defense building module includes: a knowledge base module, a predictive threat association engine module, and a security policy management module, wherein... The knowledge base module is used to store the attack and defense exercise database. The attack and defense exercise database is used to record the correlation between historical network topology events and network attack data. The network attack data includes network attack behaviors and attack precursor behaviors. The predictive threat association engine module is used to acquire security event data detected by the security node device, and to acquire at least one network attack data associated with the network topology event in the predicted topology data from the attack and defense exercise database. The module performs fusion analysis on the network topology event in the predicted topology data, the security event data, and the at least one network attack data to determine the target network attack to be launched by the attack target. The security policy management module is used to build defense measures against the target network attacks in the security node devices of the test range.

[0015] As an optional implementation, the predictive threat association engine module is specifically used for: Based on the network topology events in the predicted topology data, the security event data, and the at least one network attack data, when the confidence level of any network attack meets a preset requirement, the network attack is identified as a target network attack.

[0016] As an optional implementation, the security policy management module is specifically used for: Determine a defense strategy against the target network attack, and build defense measures in the security node device based on the defense strategy.

[0017] As an optional implementation, the security policy management module is specifically used for: Based on a pre-configured security policy database, a defense strategy for the target network attack is determined, wherein the security policy database is used to record the correspondence between network attacks and defense strategies; Based on the defense strategy, a defense command is generated and sent to the security node device.

[0018] As an optional implementation, the knowledge base module is further used for: Obtain real network attacks launched by the target, record the predicted topology data, the attack precursor behaviors, and the real network attacks, and generate training sample data; The attack and defense exercise database is iteratively learned using the training sample data.

[0019] As an optional implementation, the predictive adaptive defense building module is specifically used for: In response to an object-triggered predictive defense mode, the predictive topology data is acquired, and defense deployment operations are performed.

[0020] Thirdly, embodiments of this application provide a defense deployment device, the device comprising: The acquisition unit is used to acquire predicted topology data, which is obtained by predicting the dynamic changes in network topology within a preset time period after the current moment based on the network environment provided by the range infrastructure. The processing unit is used to determine the target network attack to be launched by the attack target based on the predicted topology data. The deployment unit is used to build defenses against network attacks against the target in the security node devices of the test range.

[0021] As an optional implementation, the processing unit is specifically used for: Obtain the security event data detected by the security node device; From the attack and defense exercise database, obtain at least one network attack data associated with the network topology event in the predicted topology data. The attack and defense exercise database is used to record the association between historical network topology events and network attack data. The network attack data includes network attack behavior and attack precursor behavior. By fusing and analyzing the network topology events in the predicted topology data, the security event data, and the at least one network attack data, the target network attack to be launched by the attack target can be determined.

[0022] As an optional implementation, the processing unit is specifically used for: Based on the network topology events in the predicted topology data, the security event data, and the at least one network attack data, when the confidence level of any network attack meets a preset requirement, the network attack is identified as a target network attack.

[0023] As an optional implementation, the deployment unit is specifically used for: Determine a defense strategy against the target network attack, and build defense measures in the security node device based on the defense strategy.

[0024] As an optional implementation, the deployment unit is specifically used for: Based on a pre-configured security policy database, a defense strategy for the target network attack is determined, wherein the security policy database is used to record the correspondence between network attacks and defense strategies; Based on the defense strategy, a defense command is generated and sent to the security node device.

[0025] As an optional implementation, the device further includes: The training unit is used to acquire real network attacks launched by the target, record the predicted topology data, the attack precursor behaviors, and the real network attacks, generate training sample data, and use the training sample data to iteratively learn the attack and defense exercise database.

[0026] As an optional implementation, the acquisition unit is specifically used for: In response to an object-triggered predictive defense mode, the predictive topology data is acquired, and defense deployment operations are performed.

[0027] Fourthly, this application provides a network range system, which includes: an infrastructure module, an attack and defense exercise scenario topology module, a defense deployment system provided in the second aspect of this application, an attack module, and a defense module. The attack and defense exercise scenario topology module is used to deploy the attack environment of the attack module and the defense environment of the defense module based on the supporting data provided by the dynamic topology simulation engine module.

[0028] Fifthly, embodiments of this application provide a defense deployment device, which includes a processor and a memory, the memory being used to store a program executable by the processor, and the processor being used to read the program in the memory and execute the method described in any one of the first aspects.

[0029] In a sixth aspect, embodiments of this application also provide a computer storage medium having a computer program stored thereon, which, when executed by a processor, is used to implement the steps of the method described in the first aspect above.

[0030] In a seventh aspect, embodiments of this application provide a computer program product comprising: computer program code, which, when executed on a computer, causes the computer to perform the method described in any one of the first aspects.

[0031] The beneficial effects of the embodiments of this application are as follows: This application provides a defense deployment method, system, device, equipment, medium, program product, and network range system. Based on the dynamic changes in network topology over a preset time period after the current moment, it determines predicted topology data, identifies the target network attack to be launched by the attack target based on the predicted topology data, and then deploys defense against the target network attack. This allows for proactive deployment of defense measures before the topology event corresponding to the predicted topology data actually occurs, changing the role of the defender in the range exercise from passive to active, and enabling the defense system to make forward-looking deployments using the predictability of network topology.

[0032] These or other aspects of the embodiments of this application will become more apparent in the following description of the embodiments. Attached Figure Description

[0033] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0034] Figure 1 A schematic diagram of the system architecture of a network range in the related technologies provided in the embodiments of this application; Figure 2 A schematic flowchart illustrating a defense deployment method provided in an embodiment of this application; Figure 3 A schematic flowchart illustrating the specific implementation process of a defense deployment method provided in this application embodiment; Figure 4 This is a schematic diagram of the structure of a defense deployment system provided in an embodiment of this application; Figure 5 A schematic diagram of the system architecture of a network range system provided in this application embodiment; Figure 6 A schematic diagram illustrating the interaction between various modules in a network range system provided in an embodiment of this application; Figure 7 This is a schematic diagram of the structure of a defense deployment device provided in an embodiment of this application; Figure 8This is a schematic diagram of a defense deployment device provided in an embodiment of this application. Detailed Implementation

[0035] To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0036] In the embodiments of this application, the term "and / or" describes the relationship between associated objects, indicating that three relationships can exist. For example, A and / or B can represent three cases: A alone, A and B simultaneously, and B alone. The character " / " generally indicates that the preceding and following associated objects have an "or" relationship.

[0037] The application scenarios described in this application are for the purpose of more clearly illustrating the technical solutions of this application, and do not constitute a limitation on the technical solutions provided in this application. Those skilled in the art will understand that with the emergence of new application scenarios, the technical solutions provided in this application are also applicable to similar technical problems. In the description of this application, unless otherwise stated, "multiple" means two or more.

[0038] Before introducing the defense deployment scheme provided in the embodiments of this application, for ease of understanding, the related technologies of the embodiments of this application will be described in detail below.

[0039] In existing cyber ranges, the mainstream technical solutions for constructing defender verification and training scenarios are based on the core idea of ​​"transplanting" security defense systems that have matured in traditional IT networks to the virtualized range environment. This approach aims to replicate a defense infrastructure within the range that is highly similar to the real world, but is essentially static.

[0040] The typical architecture of this technical solution is as follows: Figure 1 As shown, the entire test range environment is built from the bottom up. The underlying infrastructure provides physical and virtualized resources such as computing, storage, and networking for the upper layers, playing a "supporting" role. On this basis, the test range's scenario orchestration engine constructs a network attack and defense exercise scenario topology that includes all nodes, network devices, and link connections. This underlying scenario topology, through "instantiated hosting," forms logical environments (attack environment and defense environment) for the attacker and defender to operate respectively.

[0041] The attack environment mainly consists of attack virtual machines and attack tool libraries, providing attackers with an operational platform to launch network attacks. The defense environment mainly consists of business system nodes simulating real business systems and pre-installed security node devices (such as virtual firewalls, intrusion detection systems, etc.), providing protection personnel with an operational platform for monitoring and defense.

[0042] The deployment and operation of this technical solution follows a principle of "baseline deployment, manual adjustment as needed." Before the exercise begins, all defense components and their initial security policies are instantiated and deployed once, based on a pre-defined static blueprint. This initial state, built by an automated process, constitutes the defense baseline for the entire exercise. After the exercise begins, protection personnel operate various pre-installed security devices within this baseline environment to monitor and respond to attackers' behavior. When protection personnel determine, based on real-time situation analysis, that adjustments to the existing defense strategy are necessary, they typically need to log into specific virtualized security devices (such as virtual firewalls, Security Information and Event Management (SIEM) platforms, etc.) to manually update their rule bases, configuration items, or alarm logic.

[0043] This method of relying on manual, passive configuration and adjustment of strategies cannot keep up with the second-level topology changes of low-Earth orbit satellite networks, resulting in the defense system always being in a passive state of being "half a beat slower" during range exercises.

[0044] In view of this, embodiments of this application provide a defense deployment method, system, device, equipment, medium, program product, and network range system. Based on the dynamic changes in network topology over a preset time period after the current moment, predictive topology data is determined, and based on the predictive topology data, the target network attack to be launched by the attack target is determined. Then, defense deployment is carried out against the target network attack. This allows for proactive deployment of defense measures before the topology event corresponding to the predictive topology data actually occurs, changing the role of the defender in the range exercise from passive to active, and enabling the defense system to have the ability to make forward-looking deployments using the predictability of network topology.

[0045] After introducing the relevant technical background of the embodiments of this application, the overall concept of the defense deployment scheme provided by the embodiments of this application will be explained below.

[0046] Existing solutions completely ignore the fact that while satellite network topology evolution is high-speed, it is also highly predictable based on orbital mechanics. To address the fundamental contradiction between the static and passive nature of existing defense systems and the dynamic nature of highly maneuverable satellite networks, this application proposes a novel range architecture integrating predictive and adaptive defense capabilities. This architecture is pre-programmed to operate on a range with network topology dynamic simulation capabilities, capable of simulating and generating continuously evolving network environments. The specific simulation capabilities for network topology dynamics and the methods for simulating and generating continuously evolving network environments can adopt methods from existing technologies; this application does not limit these methods in its embodiments.

[0047] Based on this, the embodiments of this application determine the predicted topology data based on the dynamic changes in network topology over a preset period of time after the current moment, and determine the target network attack to be launched by the attack target based on the predicted topology data, and then deploy defense against the target network attack, thereby transforming the defender from a passive responder to an active planner, enabling the defense system to make forward deployments by utilizing the predictability of network topology.

[0048] After introducing the overall concept of the defense deployment scheme provided in the embodiments of this application, the implementation process of the defense deployment scheme provided in the embodiments of this application will be described in detail below with reference to specific embodiments.

[0049] like Figure 2 As shown in the embodiments of this application, the implementation process of the defense deployment method is as follows: Step 201: Obtain predicted topology data. The predicted topology data is obtained by predicting the dynamic changes in network topology within a preset time period after the current moment in the network environment provided by the test range infrastructure.

[0050] It should be noted that the predicted topology data is obtained by predicting the dynamic changes in network topology within a preset time period after the current moment in the network environment provided by the test range infrastructure. It includes at least one network topology event that will occur within the preset time period, such as link connectivity issues, latency changes, bandwidth fluctuations, etc., and includes both the network topology event and the time of its occurrence. Specifically, the predicted topology data obtained based on the dynamic changes in network topology can be obtained using methods found in related technologies, and this application does not limit this approach.

[0051] The preset duration can be pre-configured according to actual needs or selected by the object. This application embodiment does not limit this. For example, the preset duration can be 30 seconds, 60 seconds, 5 minutes, 10 minutes or even longer.

[0052] In practical applications, the operation of acquiring predictive topology data and deploying subsequent defense measures can be performed after the object triggers the start of predictive defense mode, or it can be performed spontaneously during attack and defense exercises in the network range.

[0053] Step 202: Based on the predicted topology data, determine the target network attack to be launched.

[0054] In some possible implementations, when determining the target network attack to be launched by the attack target based on the predicted topology data, the correspondence between network topology events and network attacks can be stored in advance, and then the target network attack corresponding to the network topology event in the predicted topology data can be determined directly based on the correspondence.

[0055] In one example, the pre-stored correspondence between network topology events and network attacks can define a network topology event such as "a satellite-to-ground link is about to be established" as highly correlated with attack techniques such as "man-in-the-middle attacks" and "session hijacking"; while a network topology event such as "a satellite is about to enter a communication dead zone" may be related to the final stage of attacks such as "data theft" and "command injection".

[0056] In another possible implementation, in order to improve the accuracy of the identified target network attack, this application embodiment can also obtain security event data detected by security node devices when determining the target network attack to be launched by the attack target based on the predicted topology data. Then, it can obtain at least one network attack data associated with the network topology event in the predicted topology data from the attack and defense exercise database, and perform fusion analysis on the network topology event, security event data and at least one network attack data in the predicted topology data to determine the target network attack to be launched by the attack target.

[0057] Among them, security event data is security monitoring data such as alarms and logs collected in real time from various security node devices (such as intrusion detection systems (IDS) and firewalls) and business system nodes in the network range's defense environment.

[0058] The attack and defense exercise database can be pre-recorded and stored, or it can be pre-obtained from third-party devices; this application embodiment does not limit this. This attack and defense exercise database is a structured database used to record the correlation between historical network topology events and network attack data. The network attack data includes network attack behaviors and pre-attack behaviors. This database can be generated and expanded based on the correlation analysis of real network attack events, pre-attack behaviors, and network topology events, and can continuously learn and iterate in subsequent attack and defense exercises to ensure the objectivity and effectiveness of its correlation rules.

[0059] In one example, the correlation between historical network topology events and network attack data recorded in the attack and defense exercise database is shown in Table 1. The network attack data in Table 1 includes not only historical network attacks and their precursory behaviors, but also the potential impact of each network attack. Of course, the partial correspondences listed in Table 1 are for illustrative purposes only; more correspondences can be included in practical applications.

[0060]

[0061] Table 1

[0062] Specifically, when analyzing network topology events, security events, and at least one network attack data from the predicted topology data to identify a target network attack, the attack can be identified as the target attack if the confidence level of any network attack meets a preset requirement. This preset requirement can be a confidence level greater than a preset threshold (set based on experience).

[0063] This application's embodiments perform correlation analysis on security event data and predicted topology data. Utilizing an attack and defense exercise database, it examines current real-time security events in the context of impending network topology events. For example, if it is predicted that "satellite-to-ground link AB" will be established in 60 seconds, and slight scanning or reconnaissance behavior targeting node A or B is detected in the current security event data, then based on the attack and defense exercise database, these two seemingly isolated events can be correlated, generating a high-confidence predictive threat announcement indicating that a session hijacking attack is highly likely to occur when link AB is established.

[0064] Step 203: Build defenses against target network attacks in the security node devices at the test range.

[0065] In practice, when building defense measures against target network attacks in the security node devices of the test range, the defense strategy against the target network attacks can be determined first, and then the defense measures can be built in the security node devices based on the defense strategy.

[0066] When determining a specific defense strategy against a target network attack and building defense measures in the security node device based on the defense strategy, the defense strategy against the target network attack can be determined according to a pre-configured security policy database. This security policy database is used to record the correspondence between network attacks and defense strategies. Then, defense instructions are generated according to the defense strategy and sent to the security node device.

[0067] It should be noted that the security policy database can be a policy library predefined by the protection personnel. It can match and activate the most appropriate defense policy for the target network attack. These defense policies transform the abstract network attack into a specific action plan. Finally, these plans are generated into a series of executable dynamic defense instructions and directly issued to the security node devices, so as to proactively and automatically complete the adjustment of defense deployment before the predicted target network attack occurs.

[0068] In practical applications, after sending the defense command to the security node device and instructing the security node device to deploy the defense, this embodiment of the application can also send a notification message to the object to notify the object of the deployed security defense measures.

[0069] This application's embodiments, through an intelligent defense process of perception and prediction -> correlation analysis -> automatic response, enable the defense system to truly possess a forward-looking adaptive defense capability that matches the dynamics of satellite networks.

[0070] In specific implementation, in order to expand the attack and defense exercise database, after a real network attack occurs, regardless of whether the real network attack is consistent with the predicted target network attack, this application embodiment obtains the real network attack launched by the attack target, records the predicted topology data, attack precursor behaviors, and the real network attack, generates training sample data, and then uses the training sample data (or when the training sample data reaches a certain amount) to iteratively learn the attack and defense exercise database.

[0071] The above, in conjunction with specific embodiments, provides a detailed description of the defense deployment scheme provided in this application. Overall, compared with traditional security defense systems in the prior art that are mainly geared towards static ground networks and adopt a passive response mode, as well as schemes that only provide basic, static defense capabilities within a test range, the defense deployment scheme provided in this application has the following characteristics: 1. The prediction mechanism in the defense deployment scheme provided in this application embodiment enables the defense to achieve a paradigm shift from passive response to active prediction, which greatly improves the depth of defense verification.

[0072] Specifically, traditional defense tools in cyber ranges can only alert and analyze attacks that have already occurred, which is a reactive approach. This application, however, can anticipate attacks, predicting their likelihood, timing, location, and method before they actually happen. This makes it possible to test and verify proactive and preemptive defense strategies in the range. For example, it can assess the actual effect of hardening nodes or deploying deceptive environments before satellite switching on attackers. This elevates the cyber range from a simple attack and defense exercise to a platform capable of conducting complex defense tactical simulations and verifications.

[0073] 2. The defense deployment scheme provided in this application embodiment records the correspondence between historical network topology events, historical attack precursor behaviors, and historical network attacks through an attack and defense exercise database. This achieves topology-aware context-based defense, deeply coupling general threat intelligence with specific, time-sensitive topology event backgrounds, greatly improving the realism of attack and defense exercises.

[0074] Specifically, traditional defense systems within firing ranges struggle to distinguish between truly high-threat attacks when faced with simulated attacks. This application enables simulated defense systems to understand the motives and timing of attacks. For example, it can clearly identify why a network device's scan is dangerous because it precisely targets a simulated ground station about to be switched over. This context-rich intelligent defense creates a more realistic and challenging adversary for attackers, allowing for more accurate testing of the effectiveness of attack tools and tactics.

[0075] 3. The defense deployment scheme provided in this application combines predictive analysis with defense strategy execution, so that the defense posture of the simulated network in the test range is no longer static and rigid, but a dynamic entity that can keep pace with the evolution of the simulated network, realizing the dynamic elasticity of the simulated defense system and providing a platform for the training of advanced offensive and defensive talents.

[0076] Specifically, the defense deployment scheme provided in this application provides a unique training platform for both attackers and defenders. Defenders can design, deploy, and verify their dynamic and adaptive defense strategies on this platform and observe their effectiveness against advanced attacks in real time. Correspondingly, attackers must also face a continuously evolving adversary for penetration, upgrading from traditionally exploiting fixed target range vulnerabilities to engaging in real confrontation with dynamic targets that can think and move. This solves the pain point that traditional target ranges can only practice static defenses, effectively cultivates advanced security attack and defense talents for future highly dynamic network environments, and creates a more reliable and resilient advanced network security experimental environment.

[0077] The following is combined Figure 3 Taking the manual triggering of predictive defense mode by an object as an example, the specific implementation process of the defense deployment method provided in this application embodiment will be described in general. Figure 3 As shown, the specific implementation process of the defense deployment method provided in this application embodiment includes: S301, Object triggers the start of predictive defense mode.

[0078] S302, Obtain predicted topology data. The predicted topology data is obtained based on the dynamic changes in network topology within a preset time period after the current time.

[0079] S303: Obtain security event data detected by the security node device.

[0080] S304. Obtain at least one network attack data item from the attack and defense exercise database that is associated with a network topology event in the predicted topology data.

[0081] This attack and defense exercise database is used to record the correlation between historical network topology events and network attack data. The network attack data includes network attack behaviors and attack precursor behaviors.

[0082] S305, perform fusion analysis on network topology events, security event data, and at least one network attack data in the predicted topology data to determine the target network attack to be launched by the attack target.

[0083] S306 determines defense strategies against target network attacks based on a pre-configured security policy database.

[0084] This security policy database is used to record the correspondence between network attacks and defense strategies.

[0085] S307 generates defense commands based on the defense strategy and sends the defense commands to the security node device.

[0086] Based on the same inventive concept, such as Figure 4 As shown in the illustration, this application also provides a defense deployment system, including: a dynamic topology simulation engine module 401 and a predictive adaptive defense construction module 402, wherein, The dynamic topology simulation engine module 401 is used to determine the predicted topology data based on the dynamic changes in network topology within a preset time period after the current moment in the network environment provided by the test range infrastructure. The predictive adaptive defense building module 402 is used to acquire predictive topology data, determine the target network attack to be launched by the attack target based on the predictive topology data, and build defense measures against the target network attack in the security node device of the test range.

[0087] As an optional implementation, the predictive adaptive defense building module 402 includes: a knowledge base module 4021, a predictive threat association engine module 4022, and a security policy management module 4023, wherein... The knowledge base module 4021 is used to store the attack and defense exercise database. The attack and defense exercise database is used to record the correlation between historical network topology events and network attack data. The network attack data includes network attack behavior and attack precursor behavior. The predictive threat association engine module 4022 is used to acquire security event data detected by security node devices, and to acquire at least one network attack data associated with network topology events in the predictive topology data from the attack and defense exercise database. It performs fusion analysis on network topology events, security event data and at least one network attack data in the predictive topology data to determine the target network attack to be launched by the attack target. The Security Policy Management Module 4023 is used to build defenses against target network attacks in the security node devices of the test range.

[0088] As an optional implementation, the predictive threat association engine module 4022 is specifically used for: Based on network topology events, security event data, and at least one network attack data in the predicted topology data, when the confidence level of any network attack meets the preset requirements, the network attack is identified as the target network attack.

[0089] As an optional implementation, the security policy management module 4023 is specifically used for: Determine defense strategies against target network attacks, and build defense measures in security node devices based on these strategies.

[0090] As an optional implementation, the security policy management module 4023 is specifically used for: Based on a pre-configured security policy database, defense strategies against target network attacks are determined. The security policy database is used to record the correspondence between network attacks and defense strategies. Based on the defense strategy, defense commands are generated and sent to the security node devices.

[0091] As an optional implementation, the knowledge base module 4021 is also used for: Acquire real network attacks launched by the target, record predicted topology data, attack precursor behaviors, and real network attacks, and generate training sample data; The attack and defense exercise database is iteratively learned using training sample data.

[0092] As an optional implementation, the predictive adaptive defense building block 402 is specifically used for: In response to an object triggering the predictive defense mode, acquire predictive topology data and perform defense deployment operations.

[0093] Based on the same concept, such as Figure 5As shown, in addition to providing a defense deployment system, this application embodiment also provides a network range system. The architecture of the network range system includes: an infrastructure module 501, an attack and defense exercise scenario topology module 502, a defense deployment system provided in this application embodiment (dynamic topology simulation engine module 401 and predictive adaptive defense construction module 402, wherein the predictive adaptive defense construction module 402 includes a knowledge base module 4021, a predictive threat association engine module 4022, and a security policy management module 4023), an attack module 503, and a defense module 504. The attack and defense exercise scenario topology module 502 is used to deploy the attack environment of the attack module 503 and the defense environment of the defense module 504 based on the support data provided by the dynamic topology simulation engine module 401.

[0094] In the network range system provided in this application embodiment, the infrastructure module 501 provides a basic network environment and provides supporting data for the dynamic topology simulation engine module 401. The predictive adaptive defense construction module 402, based on the predicted topology data provided by the dynamic topology simulation engine module 401, adopts the defense deployment scheme provided in this application embodiment and deploys defense measures in the security node device of the defense module 504. For specific implementation methods, please refer to the above embodiments, which will not be repeated here.

[0095] The following is combined Figure 6 Taking the manual triggering of predictive defense mode by an object as an example, this application illustrates the data interaction process between various modules in the network range system provided in its embodiments. Figure 6 As shown, the data interaction process between various modules in the network range system provided in this application embodiment can be divided into three stages, specifically: Phase 1: Initialization and detection of pre-attack warning signs.

[0096] 1. The defense personnel trigger the start of the predictive defense mode. This application's embodiments do not limit the method of triggering via virtual buttons or other means.

[0097] In practice, a virtual button can be set in the management interface of the security policy management module. Security personnel can use this virtual button to trigger the start of the predictive defense mode to activate advanced defense strategies, such as enabling the predictive defense mode for satellite-to-ground link switching events within the next 10 minutes.

[0098] 2. Attackers perform pre-attack activities. At this point, attackers begin to conduct some low-intensity pre-attack activities that are not easily judged as high-risk by traditional static rules, such as port scanning or information reconnaissance of a target virtual satellite node.

[0099] 3. Report security incident data. Security node devices detect pre-attack activities by attackers. Although these activities may not be sufficient to trigger a high-risk alert, they will still be reported as real-time security incidents to the predictive threat correlation engine module.

[0100] Phase Two: A closed loop of periodic forecasting, decision-making, and action; this phase can be a continuous cycle.

[0101] 4. Request topological events within a future time period of T (current time) + n (preset duration).

[0102] The predictive threat association engine module proactively sends requests to the dynamic topology simulation engine module to query known network topology events that will occur within a future time window (e.g., within T+n seconds).

[0103] 5. Return predicted topology data. The dynamic topology simulation engine module calculates and returns a structured data list based on its internal orbital dynamics model, containing the exact network topology events and their occurrence times. For example: {event: "link_establish", time: T+60s, node1: "SatA", node2: "GS-B"}.

[0104] 6. Query and predict network attacks related to network topology events in topology data.

[0105] After receiving the predicted topology data, the predictive threat association engine module uses the network topology events contained therein to query the attack and defense exercise database of the knowledge base module, requesting known attack tactics, techniques and processes related to such events.

[0106] 7. Return to the relevant attack mode.

[0107] The knowledge base module returns matching results, such as "satellite-to-ground link establishment events are usually associated with network attacks such as session hijacking and man-in-the-middle attacks".

[0108] 8. The predictive threat association engine module performs association analysis.

[0109] The predictive threat correlation engine module integrates and analyzes information from three aspects: security event data, predictive topology data, and relevant threat knowledge.

[0110] 9. Send predictive threat notifications.

[0111] If the predictive threat association engine module arrives at a high-confidence conclusion (e.g., the current scanning activity is likely preparing for a link establishment that will occur in 60 seconds to carry out session hijacking), it will generate a structured predictive threat announcement and send it to the security policy management module.

[0112] 10. Before time T+n, parse the announcement and generate adaptive defense actions, and issue dynamic defense commands.

[0113] The security policy management module receives and understands the notification. Based on its built-in security policy database, it automatically translates the abstract threat alert into one or more specific defensive actions. Before the actual occurrence of future network topology events, the security policy management module issues specific defensive instructions to the security node devices. For example, at T+59 seconds, it applies a stricter access control policy to port X of node GS-B.

[0114] 11. Security node devices apply new defense configurations.

[0115] Security node devices (such as virtual firewalls) receive and apply these defense instructions, dynamically and temporarily strengthening their own security status.

[0116] 12. The security node device reports to the protection personnel.

[0117] The system sends a notification to the protection personnel's console, informing them that a proactive defense action has been automatically executed, thus informing the protection personnel of the situation.

[0118] Phase Three: Attack and Mitigation.

[0119] 13. A broadcast network topology event actually occurs, and attackers launch a core attack associated with the topology event.

[0120] At time T+n, the dynamic topology simulation engine module simulates the previously predicted network topology changes in the test environment, such as the formal establishment of the link between SatA and GS-B. As planned, the attackers launch a session hijacking attack the instant the link is established.

[0121] 14. The attack was intercepted / mitigated by the pre-configured dynamic defense strategy.

[0122] Because the defense system had deployed targeted reinforcement strategies in advance, the attacker's behavior fell right into the preset defense system, and the attack was successfully intercepted, blocked, or diverted into the deception network, thus effectively protecting the target.

[0123] Based on the same inventive concept, such as Figure 7 As shown in the illustration, this application also provides a defense deployment device, comprising: The acquisition unit 701 is used to acquire predicted topology data, which is obtained by predicting the dynamic changes in network topology within a preset time period after the current moment based on the network environment provided by the range infrastructure. Processing unit 702 is used to determine the target network attack to be launched by the attack target based on the predicted topology data; Deployment unit 703 is used to build defenses against target network attacks in the security node devices of the test range.

[0124] As an optional implementation, the processing unit 702 is specifically used for: Acquire security event data detected by security node devices; From the attack and defense exercise database, obtain at least one network attack data associated with the network topology event in the predicted topology data. The attack and defense exercise database is used to record the correlation between historical network topology events and network attack data. The network attack data includes network attack behavior and attack precursor behavior. By fusing and analyzing network topology events, security events, and at least one network attack data from the predicted topology data, the target network attack to be launched by the attack target can be identified.

[0125] As an optional implementation, the processing unit 702 is specifically used for: Based on network topology events, security event data, and at least one network attack data in the predicted topology data, when the confidence level of any network attack meets the preset requirements, the network attack is identified as the target network attack.

[0126] As an optional implementation, deployment unit 703 is specifically used for: Determine defense strategies against target network attacks, and build defense measures in security node devices based on these strategies.

[0127] As an optional implementation, deployment unit 703 is specifically used for: Based on a pre-configured security policy database, defense strategies against target network attacks are determined. The security policy database is used to record the correspondence between network attacks and defense strategies. Based on the defense strategy, defense commands are generated and sent to the security node devices.

[0128] As an optional implementation, the apparatus further includes: Training unit 704 is used to acquire real network attacks launched by the target, record predicted topology data, attack precursor behaviors and real network attacks, generate training sample data, and use the training sample data to iteratively learn the attack and defense exercise database.

[0129] As an optional implementation, the acquisition unit 701 is specifically used for: In response to an object triggering the predictive defense mode, acquire predictive topology data and perform defense deployment operations.

[0130] Based on the same inventive concept, such as Figure 8 As shown in the illustration, this application also provides a defense deployment device, which includes a processor 800 and a memory 801. The memory 801 is used to store programs executable by the processor 800, and the processor 800 is used to read and execute the programs in the memory 801. The predicted topology data is obtained based on the network environment provided by the range infrastructure, which predicts the dynamic changes in the network topology within a preset time period after the current moment. Based on predicted topology data, the target network attack to be launched is determined. Build defenses against target network attacks in the security node devices at the test range.

[0131] As an optional implementation, the processor 800 is specifically configured to execute: Acquire security event data detected by security node devices; From the attack and defense exercise database, obtain at least one network attack data associated with the network topology event in the predicted topology data. The attack and defense exercise database is used to record the correlation between historical network topology events and network attack data. The network attack data includes network attack behavior and attack precursor behavior. By fusing and analyzing network topology events, security events, and at least one network attack data from the predicted topology data, the target network attack to be launched by the attack target can be identified.

[0132] As an optional implementation, the processor 800 is specifically configured to execute: Based on network topology events, security event data, and at least one network attack data in the predicted topology data, when the confidence level of any network attack meets the preset requirements, the network attack is identified as the target network attack.

[0133] As an optional implementation, the processor 800 is specifically configured to execute: Determine defense strategies against target network attacks, and build defense measures in security node devices based on these strategies.

[0134] As an optional implementation, the processor 800 is specifically configured to execute: Based on a pre-configured security policy database, defense strategies against target network attacks are determined. The security policy database is used to record the correspondence between network attacks and defense strategies. Based on the defense strategy, defense commands are generated and sent to the security node devices.

[0135] As an optional implementation, the processor 800 is also configured to execute: The system acquires real network attacks launched by the target, records predicted topology data, attack precursor behaviors, and real network attacks, generates training sample data, and uses the training sample data to iteratively learn the attack and defense exercise database.

[0136] As an optional implementation, the processor 800 is specifically configured to execute: In response to an object triggering the predictive defense mode, acquire predictive topology data and perform defense deployment operations.

[0137] Based on the same inventive concept, this disclosure provides a computer storage medium comprising: computer program code, which, when executed on a computer, causes the computer to perform any of the defense deployment methods discussed above. Since the principle by which the computer storage medium solves the problem is similar to that of the defense deployment method, the implementation of the computer storage medium can be referred to the implementation of the method, and repeated details will not be elaborated further.

[0138] In specific implementation, computer storage media can include: Universal Serial Bus Flash Drive (USB), portable hard drive, Read-Only Memory (ROM), Random Access Memory (RAM), magnetic disk or optical disk, and other storage media that can store program code.

[0139] Based on the same inventive concept, this disclosure also provides a computer program product, which includes computer program code that, when executed on a computer, causes the computer to perform any of the defense deployment methods discussed above. Since the principle by which the above-described computer program product solves the problem is similar to that of the defense deployment method, the implementation of the above-described computer program product can be referred to the implementation of the method, and repeated details will not be elaborated further.

[0140] Computer program products may employ any combination of one or more readable media. A readable medium may be a readable signal medium or a readable storage medium. A readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of readable storage media (a non-exhaustive list) include: electrical connections having one or more wires, portable disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0141] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage and optical storage) containing computer-usable program code.

[0142] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 Devices that specify the functions in one or more boxes.

[0143] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including an instruction device, which is implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0144] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0145] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.

Claims

1. A defensive deployment method, characterized in that, The method includes: Acquire predicted topology data, which is obtained based on the dynamic changes in network topology within a preset time period after the current moment in the network environment provided by the range infrastructure. Based on the predicted topology data, the target network attack to be launched by the attack target is determined. Defense measures against network attacks targeting the target are constructed in the security node devices of the test range.

2. The method according to claim 1, characterized in that, The process of determining the target network attack to be launched based on the predicted topology data includes: Obtain the security event data detected by the security node device; From the attack and defense exercise database, obtain at least one network attack data associated with the network topology event in the predicted topology data. The attack and defense exercise database is used to record the association between historical network topology events and network attack data. The network attack data includes network attack behavior and attack precursor behavior. By fusing and analyzing the network topology events in the predicted topology data, the security event data, and the at least one network attack data, the target network attack to be launched by the attack target can be determined.

3. The method according to claim 2, characterized in that, The step of fusing and analyzing network topology events in the predicted topology data, security event data, and at least one network attack data to determine the target network attack to be launched by the attack target includes: Based on the network topology events in the predicted topology data, the security event data, and the at least one network attack data, when the confidence level of any network attack meets a preset requirement, the network attack is identified as a target network attack.

4. The method according to claim 1, characterized in that, The construction of defense measures against the target network attack in the security node equipment of the test range includes: Determine a defense strategy against the target network attack, and build defense measures in the security node device based on the defense strategy.

5. The method according to claim 4, characterized in that, The process of determining a defense strategy against the target network attack and constructing defense measures in the security node device based on the defense strategy includes: Based on a pre-configured security policy database, a defense strategy for the target network attack is determined, wherein the security policy database is used to record the correspondence between network attacks and defense strategies; Based on the defense strategy, a defense command is generated and sent to the security node device.

6. The method according to any one of claims 2-5, characterized in that, The method further includes: Obtain real network attacks launched by the target, record the predicted topology data, the attack precursor behaviors, and the real network attacks, and generate training sample data; The attack and defense exercise database is iteratively learned using the training sample data.

7. The method according to any one of claims 1-5, characterized in that, The acquisition of predicted topology data includes: In response to an object-triggered predictive defense mode, the predictive topology data is acquired, and defense deployment operations are performed.

8. A defense deployment system, characterized in that, The system includes: a dynamic topology simulation engine module and a predictive adaptive defense construction module, wherein, The dynamic topology simulation engine module is used to determine the predicted topology data based on the dynamic changes in network topology within a preset time period after the current moment in the network environment provided by the test range infrastructure. The predictive adaptive defense construction module is used to acquire the predicted topology data, determine the target network attack to be launched by the attack target based on the predicted topology data, and build defense measures against the target network attack in the security node device of the test range.

9. The system according to claim 8, characterized in that, The predictive adaptive defense building module includes: a knowledge base module, a predictive threat association engine module, and a security policy management module, wherein... The knowledge base module is used to store the attack and defense exercise database. The attack and defense exercise database is used to record the correlation between historical network topology events and network attack data. The network attack data includes network attack behaviors and attack precursor behaviors. The predictive threat association engine module is used to acquire security event data detected by the security node device, and to acquire at least one network attack data associated with the network topology event in the predicted topology data from the attack and defense exercise database. The module performs fusion analysis on the network topology event in the predicted topology data, the security event data, and the at least one network attack data to determine the target network attack to be launched by the attack target. The security policy management module is used to build defense measures against the target network attacks in the security node devices of the test range.

10. The system according to claim 9, characterized in that, The predictive threat association engine module is specifically used for: Based on the network topology events in the predicted topology data, the security event data, and the at least one network attack data, when the confidence level of any network attack meets a preset requirement, the network attack is identified as a target network attack.

11. The system according to claim 9, characterized in that, The security policy management module is specifically used for: Determine a defense strategy against the target network attack, and build defense measures in the security node device based on the defense strategy.

12. The system according to claim 11, characterized in that, The security policy management module is specifically used for: Based on a pre-configured security policy database, a defense strategy for the target network attack is determined, wherein the security policy database is used to record the correspondence between network attacks and defense strategies; Based on the defense strategy, a defense command is generated and sent to the security node device.

13. The system according to any one of claims 9-12, characterized in that, The knowledge base module is also used for: Obtain real network attacks launched by the target, record the predicted topology data, the attack precursor behaviors, and the real network attacks, and generate training sample data; The attack and defense exercise database is iteratively learned using the training sample data.

14. The system according to any one of claims 8-12, characterized in that, The predictive adaptive defense construction module is specifically used for: In response to an object-triggered predictive defense mode, the predictive topology data is acquired, and defense deployment operations are performed.

15. A defensive deployment device, characterized in that, The device includes: The acquisition unit is used to acquire predicted topology data, which is obtained by predicting the dynamic changes in network topology within a preset time period after the current moment based on the network environment provided by the range infrastructure. The processing unit is used to determine the target network attack to be launched by the attack target based on the predicted topology data. The deployment unit is used to build defenses against network attacks against the target in the security node devices of the test range.

16. A network target range system, characterized in that, The network range system includes: an infrastructure module, an attack and defense exercise scenario topology module, a defense deployment system as described in any one of claims 8 to 14, an attack module, and a defense module, wherein the attack and defense exercise scenario topology module is used to deploy the attack environment of the attack module and the defense environment of the defense module based on the supporting data provided by the dynamic topology simulation engine module.

17. A defensive deployment device, characterized in that, The device includes a processor and a memory for storing a program executable by the processor, and the processor for reading the program in the memory and performing the steps of the method according to any one of claims 1 to 7.

18. A computer storage medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, it implements the steps of the method as described in any one of claims 1 to 7.

19. A computer program product, characterized in that, The computer program product includes: computer program code, which, when run on a computer, causes the computer to perform the steps of the method as described in any one of claims 1 to 7.