Verification system and verification method for security protection application
By linking the network attack simulation engine and verification equipment, and utilizing behavior mapping, logic mapping, and zero-day effect surrogate modules, the problem of traditional technologies being unable to simulate complex multi-stage network attacks has been solved, achieving comprehensive defense verification of security protection applications and accurate simulation of unknown vulnerabilities.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-01-09
- Publication Date
- 2026-04-14
AI Technical Summary
Traditional technologies cannot effectively simulate complex, multi-stage cyberattacks, resulting in insufficient defense capabilities of cyberattack simulation platforms.
Employing a network attack simulation engine and verification equipment, and utilizing a behavior mapping module, a logic mapping module, a three-link linkage module, and a zero-day effect surrogate module, it accurately simulates network attack behaviors targeting known and unknown vulnerabilities and verifies the defense capabilities of security protection applications.
In the absence of real vulnerability code, it accurately simulates the impact of attacks on unknown vulnerabilities, improves the coverage and simulation capability of network attack simulation, ensures a comprehensive assessment of defense performance, and provides realistic and comprehensive attack simulation and defense verification.
Smart Images

Figure CN121864428A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of cybersecurity technology, and in particular to a verification system and verification method for security protection applications. Background Technology
[0002] With the advancement of digital transformation and the widespread adoption of technologies such as cloud computing, the Internet of Things, and artificial intelligence, the boundaries of cyberspace are becoming increasingly blurred. Cyberattack methods are becoming more intelligent and complex. To address unknown risks, enterprises and organizations have an increasingly urgent need for proactive defense capabilities, leading to the emergence of cyberattack simulation platforms. These platforms construct highly realistic cyber attack and defense environments, simulating real attack scenarios and tactics. This helps users test the effectiveness of their defense systems, discover potential vulnerabilities, and improve the emergency response capabilities of their security teams under secure and controllable conditions.
[0003] Traditional techniques typically simulate attacks using predefined attack scripts or vulnerability scanning tools. However, these methods can only simulate attacks on a single protocol or at a specific stage, failing to simulate complex, multi-stage network attacks. Therefore, establishing a network attack simulation platform capable of handling complex, multi-stage attacks has become a pressing issue. Summary of the Invention
[0004] Therefore, it is necessary to provide a verification system and verification method for security protection applications to address the aforementioned technical problems.
[0005] Firstly, this application provides a verification system for security protection applications, comprising:
[0006] A network attack simulation engine and a verification device are connected via a network. The network attack simulation engine includes: a behavior mapping module, a logic mapping module, a three-link linkage module, and a zero-day effect surrogate module. The behavior mapping module is connected to both the logic mapping module and the three-link linkage module. The logic mapping module is also connected to the three-link linkage module.
[0007] The network attack simulation engine is used to simulate first network attack behavior with known vulnerabilities and second network attack behavior with unknown vulnerabilities in a simulated real environment, and to launch the first network attack behavior and second network attack behavior to the verification device.
[0008] The verification device is used to launch the security protection application to defend against the first and second network attack behaviors, and to verify the protection performance of the security protection application based on the defense results.
[0009] The behavior mapping module is used to compile and generate multiple micro-instructions and replayable scripts based on custom network attack behaviors and existing network attack behaviors; the logic mapping module is used to generate attack strategies based on multiple micro-instructions and replayable scripts; the three-link linkage module is used to generate the first network attack behavior of known vulnerabilities based on the attack strategy; and the zero-day effect surrogate module is used to simulate the attack effects of unknown vulnerabilities and generate the corresponding second network attack behavior of unknown vulnerabilities based on the attack effects.
[0010] Secondly, this application also provides a verification method for security protection applications applied to a verification system for security protection applications, comprising:
[0011] Multiple micro-instructions and replayable scripts are compiled and generated based on custom network attack behaviors and existing network attack behaviors.
[0012] Attack strategies are generated based on multiple microinstructions and replayable scripts;
[0013] Initiate a first network attack and a second network attack against the verification device;
[0014] The attack strategy generates a first network attack behavior targeting known vulnerabilities; the zero-day effect surrogate module is used to obtain the attack effect simulating unknown vulnerabilities; and the attack effect is used to generate a second network attack behavior targeting the corresponding unknown vulnerabilities.
[0015] Thirdly, this application also provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to perform the following steps:
[0016] Multiple micro-instructions and replayable scripts are compiled and generated based on custom network attack behaviors and existing network attack behaviors.
[0017] Attack strategies are generated based on multiple microinstructions and replayable scripts;
[0018] Initiate a first network attack and a second network attack against the verification device.
[0019] The attack strategy generates a first network attack behavior based on known vulnerabilities; the zero-day effect surrogate module is used to simulate the attack effect of unknown vulnerabilities and generate a second network attack behavior based on the attack effect of the unknown vulnerabilities.
[0020] Fourthly, this application also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, performs the following steps:
[0021] Multiple micro-instructions and replayable scripts are compiled and generated based on custom network attack behaviors and existing network attack behaviors.
[0022] Attack strategies are generated based on multiple microinstructions and replayable scripts;
[0023] Initiate a first network attack and a second network attack against the verification device.
[0024] The attack strategy generates a first network attack behavior based on known vulnerabilities; the zero-day effect surrogate module is used to simulate the attack effect of unknown vulnerabilities and generate a second network attack behavior based on the attack effect of the unknown vulnerabilities.
[0025] Fifthly, this application also provides a computer program product, including a computer program that, when executed by a processor, performs the following steps:
[0026] Multiple micro-instructions and replayable scripts are compiled and generated based on custom network attack behaviors and existing network attack behaviors.
[0027] Attack strategies are generated based on multiple microinstructions and replayable scripts;
[0028] Initiate a first network attack and a second network attack against the verification device.
[0029] The attack strategy generates a first network attack behavior based on known vulnerabilities; the zero-day effect surrogate module is used to simulate the attack effect of unknown vulnerabilities and generate a second network attack behavior based on the attack effect of the unknown vulnerabilities.
[0030] The security protection application verification system and verification method of the above embodiments include a network attack simulation engine and a verification device; the network attack simulation engine and the verification device are connected via a network; the network attack simulation engine includes: a behavior mapping module, a logic mapping module, a three-link linkage module, and a zero-day effect surrogate module; the behavior mapping module is connected to the logic mapping module and the three-link linkage module respectively; the logic mapping module is connected to the three-link linkage module; the network attack simulation engine is used to simulate a first network attack behavior with known vulnerabilities and a second network attack behavior with unknown vulnerabilities in a simulated real environment, and to launch the first network attack behavior and the second network attack behavior to the verification device; wherein The behavior mapping module is used to compile and generate multiple micro-instructions and replayable scripts based on custom network attack behaviors and existing network attack behaviors; the logic mapping module is used to generate attack strategies based on multiple micro-instructions and replayable scripts; the three-link linkage module is used to generate the first network attack behavior for known vulnerabilities based on the attack strategy; the zero-day effect surrogate module is used to simulate the attack effect generated by unknown vulnerabilities and generate the corresponding second network attack behavior for unknown vulnerabilities based on the attack effect; the verification device is used to start the security protection application to defend against the first and second network attack behaviors, and verify the protection performance of the security protection application based on the defense results. The aforementioned verification system maps program-level vulnerability behavior to protocol effects through a zero-day effect surrogate module. This allows the verification system for security applications to accurately simulate and test the impact of attacks on unknown vulnerabilities without real vulnerability code, thus improving the coverage of network simulation attacks. Secondly, the system achieves dynamic control over different attack behaviors through behavior mapping and logic mapping modules, enabling flexible switching of attack strategies under different network topologies and permission environments, thereby enhancing the system's network simulation attack capabilities. Finally, the system's linkage between the network attack simulation engine and verification devices ensures a comprehensive evaluation of the security application's defense performance when dealing with network simulation attacks, providing more realistic and comprehensive attack simulation and defense verification. Attached Figure Description
[0031] To more clearly illustrate the technical solutions in the embodiments of this application or related technologies, the drawings used in the description of the embodiments of this application or related technologies will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.
[0032] Figure 1 This is an application environment diagram of the verification system for security protection applications in the embodiments of this application;
[0033] Figure 2 This is one of the structural block diagrams of the verification system for security protection applications in the embodiments of this application;
[0034] Figure 3 This is the second structural block diagram of the verification system for security protection applications in this application embodiment;
[0035] Figure 4 This is the third structural block diagram of the verification system for security protection applications in this application embodiment;
[0036] Figure 5 This is the fourth structural block diagram of the verification system for security protection applications in this application embodiment;
[0037] Figure 6 This is one of the flowcharts illustrating the verification method for security protection applications in the embodiments of this application;
[0038] Figure 7 This is the second flowchart illustrating the verification method for the security protection application in the embodiments of this application;
[0039] Figure 8 This is the third flowchart illustrating the verification method for the security protection application in the embodiments of this application;
[0040] Figure 9 This is the fourth flowchart illustrating the verification method for the security protection application in the embodiments of this application;
[0041] Figure 10 This is a diagram showing the internal structure of a computer device in an embodiment of this application. Detailed Implementation
[0042] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.
[0043] It should be noted that the terms "first," "second," etc., used in this application can be used to describe various elements, but these elements are not limited by these terms. These terms are only used to distinguish the first element from the second element. The terms "comprising" and "having," and any variations thereof, used in this application, are intended to cover non-exclusive inclusion. The term "multiple" used in this application refers to two or more. The term "and / or" used in this application refers to one of the embodiments, or any combination of multiple embodiments.
[0044] With the advancement of digital transformation and the widespread adoption of technologies such as cloud computing, the Internet of Things, and artificial intelligence, the boundaries of cyberspace are becoming increasingly blurred. Cyberattack methods are becoming more intelligent and complex. To address unknown risks, enterprises and organizations have an increasingly urgent need for proactive defense capabilities, leading to the emergence of cyberattack simulation platforms. These platforms construct highly realistic cyber attack and defense environments, simulating real attack scenarios and tactics. This helps users test the effectiveness of their defense systems, discover potential vulnerabilities, and improve the emergency response capabilities of their security teams under secure and controllable conditions.
[0045] Traditional techniques typically simulate attacks using predefined attack scripts or vulnerability scanning tools. However, these methods can only simulate attacks on a single protocol or at a specific stage, failing to simulate complex, multi-stage network attacks. Therefore, establishing a network attack simulation platform capable of handling complex, multi-stage attacks has become a pressing issue.
[0046] In view of the above-mentioned technical problems, this application provides a verification system and verification method for security protection applications. The following embodiments will specifically illustrate the verification system and verification method for security protection applications.
[0047] In one exemplary embodiment, such as Figure 1 As shown, a verification system for a security protection application is provided. This verification system includes a network attack simulation engine and a verification device. The network attack simulation engine and the verification device are connected via a network. The network attack simulation engine includes: a behavior mapping module, a logic mapping module, a three-link linkage module, and a zero-day effect surrogate module. The behavior mapping module is connected to both the logic mapping module and the three-link linkage module. The logic mapping module is connected to the three-link linkage module. The network attack simulation engine is used to simulate a first network attack behavior with known vulnerabilities and a second network attack behavior with unknown vulnerabilities in a simulated real environment, and to launch the first and second network attack behaviors at the verification device.
[0048] The system comprises the following modules: a behavior mapping module for compiling and generating multiple micro-instructions and replayable scripts based on custom network attack behaviors and existing network attack behaviors; a logic mapping module for generating attack strategies based on multiple micro-instructions and replayable scripts; a three-link linkage module for generating a first network attack behavior for known vulnerabilities based on the attack strategy; a zero-day effect surrogate module for simulating attack effects generated by unknown vulnerabilities and generating a second network attack behavior for corresponding unknown vulnerabilities based on the attack effects; and a verification device for launching a security protection application to defend against the first and second network attack behaviors and verifying the protection performance of the security protection application based on the defense results.
[0049] Customized network attack behavior refers to attack behavior tailored to specific targets and available resources, while existing network attack behavior refers to attack behavior extracted from real attack traffic.
[0050] The working principle of the security protection application verification system described in this application embodiment includes: the security protection application verification system mainly consists of a network attack simulation engine and verification equipment. The network attack simulation engine mainly comprises a behavior mapping module, a logic mapping module, a three-link linkage module, and a zero-day effect surrogate module. First, the network attack simulation engine, through the behavior mapping module, subdivides the steps and behaviors of custom network attacks and existing network attacks into multiple micro-instructions and replayable scripts. Second, the network attack simulation engine, through the logic mapping module, uses a computational model to orchestrate and set trigger conditions for different nodes using multiple micro-instructions and replayable scripts, and generates different attack strategies for different network topologies and permission environments.
[0051] Subsequently, the network attack simulation engine realizes the linkage behavior of the three links from traffic to attack behavior to system behavior through the three-link linkage module. It tightly couples the custom network attack behavior and the attack behavior of the existing network with the interaction between the network layer, control layer and physical layer, and generates network attack behavior with known vulnerabilities according to different attack strategies, namely the first network attack behavior.
[0052] Then, the network attack simulation engine maps program-level vulnerability behavior and protocol effects through the zero-day effect surrogate module, simulates the attack effects generated by unknown vulnerabilities, and uses the attack effects to generate corresponding network attack behaviors of unknown vulnerabilities, i.e., second network attack behaviors.
[0053] Finally, the network attack simulation engine launches a first network attack and a second network attack against the verification device. The verification device then activates a security protection application to defend against the first and second network attacks, and verifies the protection performance of the security protection application based on the defense results.
[0054] The security application verification system described in the above embodiments maps program-level vulnerability behavior to protocol effects through a zero-day effect surrogate module. This allows the verification system to accurately simulate and test the impact of unknown vulnerability attacks without real vulnerability code, thus improving the coverage of network simulation attacks. Secondly, the system achieves dynamic control over different attack behaviors through behavior mapping and logic mapping modules, enabling flexible switching of attack strategies under different network topologies and permission environments, thereby improving the system's network simulation attack capabilities. Finally, the system ensures a comprehensive evaluation of the security application's defense performance when dealing with network simulation attacks through the linkage between the network attack simulation engine and verification devices, providing more realistic and comprehensive attack simulation and defense verification.
[0055] In one exemplary embodiment, such as Figure 2 As shown, Figure 1 The behavior mapping module shown includes: a compilation unit, a message construction unit, a state maintenance unit, a timing control unit, and a conversion unit. The compilation unit acquires custom network attack behaviors and compiles them using an event domain-specific language, generating multiple micro-instructions containing execution timing. The message construction unit dynamically adapts to different protocols by calling a protocol template library and generates multiple attack messages based on the micro-instructions. The state maintenance unit records and displays the attack progress when the network attack simulation engine launches a network attack on the verification device; the attack progress includes session state, permission level, and device interaction data. The timing control unit simulates the real environment and determines the actual sending time of the attack messages. The conversion unit extracts attack logic from existing network attack behaviors and generates replayable scripts.
[0056] The working principle of the verification system for the security protection application described in this application embodiment includes: for the compilation unit, by accepting user-defined attack behaviors and their parameters, it compiles them into corresponding executable micro-instruction sequences using a Domain-Specific Language (DSL) for subsequent message construction and timing control. When the instructions are executed, the verification system calculates the execution timing of each instruction using relation (1) to ensure that the time sequence of the attack steps is consistent with the real scenario. Relation (1) is shown below:
[0057] (1);
[0058] in, Indicates the first The actual execution time of each microinstruction; Indicates the overall start time of the attack; Indicates the first Each microinstruction relative to The relative delay. By precisely controlling the timing of each instruction, the compilation unit can avoid the distortion of attack scenarios caused by disordered execution order.
[0059] For the message construction unit, the message construction unit can dynamically generate attack traffic data packets according to the specifications of the target protocol. The data packet content usually includes a message header, payload data, checksum field and protocol-specific fields. Taking the Modbus / TCP protocol commonly used in industrial control scenarios as an example, the construction formula of its attack message can be represented by relation (2), which is shown below:
[0060] (2);
[0061] in, This indicates the generated Modbus / TCP attack message; Indicates the message header; This indicates a function code (e.g., "0x06" indicates writing to a single register; in attack scenarios, this function code may be tampered with to inject malicious instructions). This indicates payload data (such as tampered register values or malicious control instructions). This indicates a checksum (such as CRC16, which ensures that the message format conforms to protocol requirements to bypass the basic checksum). Indicates the target device identifier (e.g., slave address); This represents the timestamp field.
[0062] Furthermore, the differences in message structure between different protocols are dynamically adapted through the "protocol template library". The constructor calls the corresponding template according to the protocol type specified by the DSL to ensure the correctness of the message format.
[0063] For the state preservation unit, it can record the interaction state between the network attack simulation engine and the verification device during the attack process (such as session connection state, device permission level, and tampered register values), avoiding replay failure due to state loss. Taking "permission state update" as an example, after a user obtains higher permissions through privilege escalation, the state preserver can update the permission state through relation (3), which is shown below:
[0064] (3);
[0065] in, Indicates the device's permission status after privilege escalation; Indicates the current privilege status before privilege escalation; Indicates the amount of privilege change (positive numbers indicate privilege escalation, negative numbers indicate privilege demotion, determined by the type of attack, such as "privilege escalation using buffer overflow") ).
[0066] In addition, the state maintainer also records TCP layer states such as session ID and window size to ensure the continuity of long-connection attacks.
[0067] For the timing control unit, due to the uncertainties such as delay, jitter, and packet loss in the real network environment, in order to simulate such scenarios, the verification system introduces a "jitter noise injection" mechanism on the basis of timing control. The final sending time of each attack packet is calculated through relation (4), which is shown below:
[0068] (4);
[0069] in, This indicates the actual time the message was sent; This represents the theoretical execution time of the instruction; This refers to fixed network latency (determined by the network topology of the target environment, such as the latency of cross-subnet attacks). ); This refers to random jitter noise (simulating network fluctuations, such as sudden delays or instantaneous packet loss).
[0070] For the conversion unit, to ensure the authenticity of the noise, Follows the condition that the mean is 0 and the standard deviation is 0. The normal distribution of " The jitter characteristics of the target network, such as industrial Ethernet, determine this. The relation (5) can be represented by the following:
[0071] (5);
[0072] when A negative value indicates that the message was sent ahead of schedule; a positive value indicates that the message was sent late; if ( () If the packet loss threshold is set, then "packet loss simulation" is triggered, and the packet is skipped (subsequent compensation is made through a retransmission mechanism, simulating the retransmission logic of the Transmission Control Protocol).
[0073] For the conversion unit, in order to support the extraction of attack logic from real attack traffic and the generation of replayable scripts, the verification system provides a packet capture file to script conversion tool. The conversion process is represented by relation (6), which is shown below:
[0074] (6);
[0075] in, This indicates the generated executable attack script; This refers to the input network packet capture file; Represents a set of transformation parameters, for example Indicates the protocol type, such as industrial communication protocol. This indicates the Internet protocol used by the verification device. This indicates the number of replays, etc., which can be configured by the user according to their testing needs. This indicates a conversion function (such as parsing the "0x06 function code message" from a network packet capture file, which can then be mapped to a "write register microinstruction").
[0076] Furthermore, the generated scripts support parameterized configuration and can be reused in different testing environments, reducing the development cost of customized attack scripts.
[0077] In summary, the behavior mapping module, through the process design of compilation unit, message construction unit, state preservation unit, timing control unit and conversion unit, realizes accurate replay and environmental simulation of attack behavior, providing high-fidelity attack scenario input for subsequent attack effect evaluation and defense strategy testing.
[0078] In one exemplary embodiment, such as Figure 3 As shown, Figure 1 The logical mapping module shown includes: a stage encapsulation unit, a constraint unit, a triggering unit, and an orchestration unit. The stage encapsulation unit determines the target attack behavior based on multiple attack packets and a replayable script, divides the target attack behavior into different stages according to its lifecycle, and encapsulates each stage into a corresponding stage node. Each node is associated with an attack behavior of a corresponding stage. The constraint unit provides constraints to evaluate whether a transition between two nodes is possible. The triggering unit provides triggering conditions to verify whether a successful transition between two nodes has occurred. The orchestration unit uses a finite state machine to orchestrate the attack behaviors associated with nodes in different stages based on the constraints and triggering conditions, generating an attack strategy.
[0079] The lifecycle can be divided into several stages, such as reconnaissance, initial access, dwell, lateral movement, and target achievement. Each stage is encapsulated as a node corresponding to the stage, such as a reconnaissance node for the reconnaissance stage, an initial access node for the initial access stage, a dwell node for the dwell stage, a lateral movement node for the lateral movement stage, and a target achievement node for the target achievement stage. Each node is associated with the attack behavior of the corresponding stage.
[0080] The working principle of the verification system for the security protection application described in this application embodiment includes: For the stage encapsulation unit, the target attack behavior is first determined based on multiple attack packets and replayable scripts, and the life cycle of the target attack behavior is divided into different stages. Each stage is encapsulated as a logical node, and the node contains three elements: input conditions, execution actions, and output status. To clarify the dependencies between nodes, a directed acyclic graph is used to organize the nodes, and the jump logic between nodes is defined by relation (7), which is shown below:
[0081] (7);
[0082] in, Indicates the next logical node to be executed; This indicates the logical node currently being executed; Indicates the triggering condition for the current node (such as successfully obtaining login credentials for the target device); This represents the node jump function (defined by the edge relationships of the directed acyclic graph, if...). If satisfied, then from point to Otherwise, a retry or branch switch will be triggered.
[0083] For example, when initially accessing the node The trigger condition is to obtain user permissions. When the condition is met, jump to the function. It will point to the horizontally moving node. ;like If the condition is not met, the branch will point to the privilege-elevating node.
[0084] For the constraint unit, since each stage of the attack needs to meet specific preconditions (such as permissions, device status) and resource constraints (such as available tools, network bandwidth), otherwise the stage cannot start, the verification system verifies whether the current environment meets the stage execution requirements and whether a jump can be made through the resource constraint function. The resource constraint function can be represented by relation (8), which is shown below:
[0085] (8);
[0086] in, This indicates the result of the resource constraint verification (a Boolean value, where True indicates that the condition is met, and False indicates that it is not met). This indicates the current asset's permission information (e.g., ordinary user permission is 1, administrator permission is 3, user permission is 5, and permission values are defined by the preset levels of the verification system). This indicates the current status information of the asset (such as device online status (1 / 0), list of open ports, and types of installed security software). The verification function is defined according to the stage requirements, such as the requirements of the lateral movement stage. And S contains port 445 open; if all conditions are met, then... ).
[0087] like The system will pause the attack path of the current attack strategy and trigger a precondition supplementation process until... Then restart the process; if the supplementary process fails, mark the path as infeasible and switch to the backup attack path.
[0088] For the triggering unit, in order to simulate the adaptive behavior of attackers in a dynamic environment, the verification system introduces a policy hook mechanism. The system evaluates the target state in real time through the rule engine, and triggers the path adjustment of the attack strategy when the preset conditions are met, that is, a successful jump between two nodes. Taking "insufficient permissions triggering privilege escalation" as an example, the formula for the condition triggering logic can be represented by relation (9), which is shown below:
[0089] (9);
[0090] in, Indicates the trigger result (1 indicates that the privilege escalation process is triggered, 0 indicates that it is not triggered); Indicates the actual permissions of the current target asset (synchronized in real time by the state maintainer); This indicates the administrator privilege threshold (pre-set by the authentication system, such as...). ).
[0091] Policy hooks support multiple conditions for triggering, such as simultaneously meeting insufficient permissions ( And there is a privilege escalation vulnerability. Privilege escalation is triggered only when ")", and relation (9) can be expanded into relation (10), as shown below:
[0092] (10);
[0093] Once triggered, the verification system will automatically call the "privilege escalation phase node" and pause the attack path of the original attack strategy until the privilege escalation is completed and execution resumes.
[0094] For the orchestration strategy, the overall progress of the attack strategy is globally controlled by a finite state machine. Each state of the finite state machine corresponds to a stage of the attack strategy. The finite state machine uses constraints and triggering conditions to orchestrate the attack behaviors associated with nodes in different stages, thereby generating the attack strategy. The state transitions between stages can be represented by relation (11), which is shown below:
[0095] (11);
[0096] in, This indicates the state of the finite state machine in the next stage; This represents the state of the finite state machine at the current stage; This represents the set of triggering conditions (including resource constraint results). Strategy hook trigger results (e.g., changes in environmental conditions) The state transition function represents the state transition function (based on the state table definition of the finite state machine, such as...). reconnaissance and =If the target's Internet Protocol is successfully obtained, then = Initial access.
[0097] Each state transition must be approved. Function validation conditions ensure the logical consistency of path orchestration; if a state transition fails (e.g., "Administrator (Admin) privileges not obtained after initial access"), a limited number of state transitions will automatically switch to a backup branch (e.g., ...). Initial access becomes Privilege escalation becomes Lateral movement enables the flexibility of multi-stage execution.
[0098] In summary, the logic mapping module, through its stage encapsulation unit, constraint unit, triggering unit, and orchestration unit, ensures that the attack strategy and attack path conform to the behavioral logic of a real attacker (such as reconnaissance before attack and privilege escalation when permissions are insufficient), while also being able to cope with environmental changes (such as changes in the target device status and adjustments to the protection strategy). This provides a "high-fidelity and adjustable" attack flow input for subsequent attack effect evaluation.
[0099] In one exemplary embodiment, such as Figure 4 As shown, Figure 1The three-link linkage module shown includes: a first coupling unit and a second coupling unit; the first coupling unit is a unit that couples the information domain and the control domain, and the second coupling unit is a unit that couples the control domain and the physical domain; the first coupling unit is used to generate a first network attack behavior with known vulnerabilities according to the attack strategy, and launch the first network attack behavior to the verification device; the second coupling unit is used to receive the physical parameter change information fed back by the verification device after being attacked by the first network attack behavior, and display the physical parameter change information.
[0100] The working principle of the verification system for the security protection application described in this application embodiment includes: a first coupling unit and a second coupling unit together form a closed-loop simulation system. Through the outputs of the behavior mapping module and the logic mapping module (the behavior mapping module provides traffic and attack behavior, and the logic mapping module provides attack strategies), the three-link linkage module outputs impact data in the information domain, control domain, and physical domain to facilitate subsequent defense assessment. The first coupling unit can generate a first network attack behavior based on the attack strategy, which exploits known vulnerabilities, and launch the first network attack behavior towards the verification device. The second coupling unit can receive and display the physical parameter change information fed back by the verification device after being attacked by the first network attack behavior. Since latency, packet loss, and jitter in the real network environment directly affect the reachability and effectiveness of the attack, such uncertainties need to be introduced into the three-link linkage to improve the simulation realism.
[0101] The total latency of attack traffic from the information domain to the control domain can be calculated using equation (12). Combining standard latency and random fluctuations, equation (12) is as follows:
[0102] (12);
[0103] in, Indicates the final delay; Indicates the delay factor (determined by network topology, such as transmission across subnets). Transmission within the same subnet ); Indicates standard delay; This represents random time delay noise (simulating network fluctuations, following a normal distribution). Industrial Ethernet typically takes ).
[0104] Regarding packet loss, a judgment can be made based on the packet loss threshold. ( This is the timeout threshold. For example... If the flag message is lost, the attack command cannot be delivered to the control domain.
[0105] To address data jitter, load skew can be simulated, which involves measuring the load data of the attack traffic. Adjusted to ( The jitter deviation follows a uniform distribution. ,like This is used to simulate distortion in data transmission.
[0106] These factors ultimately affect the effectiveness of the attack and can ensure that the simulation results are consistent with the uncertainties of the real network environment.
[0107] In one exemplary embodiment, Figure 4 The first coupling unit shown is specifically used to simulate a real abnormal network environment and to carry out a first network attack behavior under a real abnormal network environment.
[0108] The working principle of the verification system for the security protection application described in this application embodiment includes: the first coupling unit comprises an information domain and a control domain. The information domain is responsible for generating attack traffic, transmitting protocol instructions, and injecting noise; the control domain is responsible for parsing instructions, executing finite state machine state transitions, and triggering protection logic. The core of their coupling is that the attack traffic drives changes in the control logic, ensuring that network layer attacks can genuinely affect the execution behavior of the control system.
[0109] The analog control commands transmitted from the information domain to the control domain are calculated using relation (13) to realize the mapping between flow rate and control commands. Relation (13) is shown below:
[0110] (13);
[0111] in, This indicates the final control instruction passed to the control domain (such as tampering with the register value of the programmable logic controller or suspending the protection device). This represents the set of attack parameters (including attack type, such as industrial communication protocol function code tampering; target device identification code, such as PLC-101; attack strength, such as single injection / continuous injection). Indicates network traffic characteristics (including message protocol type, such as industrial communication protocol / transmission control protocol; payload data, such as the tampered register address 0x0001; timing information, such as message interval 100ms). This represents a traffic-command mapping function (which parses traffic characteristics according to protocol specifications, such as from...). Extract function code 0x06 and register value 0xFF, and combine them... The target PLC-101 in the middle generates Write 0xFF to register 0x0001 of PLC-101.
[0112] Control domain reception Afterwards, the state transition of the finite state machine will be triggered, and the protection logic will be executed synchronously, thereby realizing the complete link from network traffic to control instructions to state change, thus generating the first network attack behavior of the known vulnerability, and launching the first network attack behavior to the verification device.
[0113] In one exemplary embodiment, Figure 4 The second coupling unit shown is specifically used to generate status information based on changes in physical parameters and send the status information to the behavior mapping module. The behavior mapping module is also specifically used to generate alarm messages based on the status information and send the alarm messages to the verification device.
[0114] The working principle of the verification system for the security protection application described in this application embodiment includes: the second coupling unit includes a control domain and a physical domain. The state change of the control domain will directly affect the operating state of the physical domain; the physical domain will form a closed loop from control logic to physical state and then to feedback data by real-time simulation feedback of physical parameter changes. Taking the power system as an example, the deviation of key physical domain parameters caused by control domain commands is calculated by relation (14) to realize the quantitative mapping between control commands and physical effects. Relation (14) is as follows:
[0115] (14);
[0116] in, This represents the voltage deviation value of the physical domain device, indicating the actual impact of the attack on the physical device; Indicates characteristics of attack behavior; This indicates a control delay caused by the attack; This represents the control-physical mapping function (calculated based on a physical device model, for example, an attack causing "voltage regulation module output signal attenuation by 30%), combined with..." The results were obtained through a transformer voltage regulation model. ).
[0117] Feedback data from the physical domain (e.g.) The data will be synchronously transmitted back to the control domain to adjust subsequent control logic, thereby achieving linkage from control commands to physical deviations and then to feedback adjustment.
[0118] Furthermore, the real-time status of the physical domain devices is updated through relation (15), reflecting the cumulative impact of the attack across the three domains. Relation (15) is shown below:
[0119] (15);
[0120] in, Indicates the physical device at time The state (e.g., generator speed 1500 rpm, circuit breaker open / closed state). Indicates the physical device at time The historical state; Indicates time The state change caused by the attack (determined by both control domain commands and physical feedback, e.g., the attack causing the engine speed to drop from 1500 rpm to 1400 rpm) then... ).
[0121] The closed-loop process is as follows: the information domain generates attack traffic, which is then transmitted to the control domain and parsed. And triggers the state transition of the finite state machine; control domain instructions trigger the physical domain ,renew The physical domain will Feedback is sent to the control domain. If the status is abnormal, the control domain generates an emergency command. The control domain then sends the emergency command back to the information domain, which generates a corresponding alarm message (such as sending an SNMP alarm message to the verification system to complete the closed loop).
[0122] In one exemplary embodiment, such as Figure 5 As shown, Figure 1 The zero-day effect surrogate module shown includes: a surrogate unit, a mapping unit, an operation unit, and a scoring unit. The surrogate unit is used to extract common attack features of unknown vulnerability attacks in the existing network and generate a set of common attack features. The mapping unit is used to establish a mapping relationship between the program-level vulnerability behavior and the protocol-level attack behavior corresponding to the unknown vulnerability attack. The operation unit is used to generate standardized unknown vulnerability attack scenarios based on the mapping relationship and the set of common attack features, and generate a second network attack behavior for the unknown vulnerability based on the unknown vulnerability attack scenarios, and launch the second network attack behavior to the verification device. The scoring unit is used to score the attack effect of the second network attack behavior after it is completed and generate a scoring report.
[0123] The working principle of the verification system for the security protection application described in this application embodiment includes: for the substitute unit, it is mainly used to extract common attack features of unknown vulnerability attacks in the existing network and generate a set of common attack features, which can be represented by relation (16), as shown below:
[0124]
[0125] (16);
[0126] in, Represents a set of common attack characteristics; This indicates that the instruction execution delay / out-of-order is caused by simulating a 0-Day vulnerability, such as by injecting random latency ( This causes the control command to time out; This indicates the effect of simulating memory overflow or parameter tampering vulnerabilities, such as forcibly modifying the value of a protocol message field (such as the address of an industrial communication protocol register) to a value that is outside the legal range (such as changing 0x0001 to 0xFFFF). This indicates a simulation of an "unknown denial-of-service vulnerability," such as exhausting the target device's CPU / memory resources by repeatedly sending high-frequency requests. This indicates a vulnerability that simulates control logic hijacking, such as forcibly fixing the finite state machine of a device to a fault state, making it unable to respond to normal reset commands. For example, if an unknown vulnerability causes a programmable logic controller (PLC) to lock up, a network attack simulation engine does not need to obtain the exploit code; it can simply reproduce the uncontrollable device effect identical to the real vulnerability by forcibly modifying the PLC's state register value to 0xFF.
[0127] For the mapping unit, since the verification system of security protection application needs to improve the authenticity of the surrogate of unknown vulnerabilities, it is necessary to establish a mapping relationship between program layer vulnerability behavior and protocol layer attack performance. That is, to reverse the observable features in protocol interaction from the program abnormality caused by the vulnerability, so as to ensure that the surrogate effect is consistent with the protocol side performance of the real vulnerability.
[0128] The mapping process is achieved through relation (17), which transforms program semantic fragments into simulable protocol-side effects. Relation (17) is shown below:
[0129] (17);
[0130] in, This refers to the final attack effect at the protocol layer (i.e., the observable surrogate behavior, such as out-of-bounds data field errors in industrial communication protocols). The core semantic fragment representing a program-level vulnerability (i.e., the abnormal program behavior caused by the vulnerability, such as stack overflow leading to function parameter tampering, or null pointer reference leading to process suspension). Indicates the protocol characteristics used by the target system (such as the register address field range (0x0001-0xFFFF) of industrial communication protocols / transmission control protocols, and the control point field format of the DNP3 protocol). This represents a semantic-effect mapping function (deriving protocol-side behavior based on program exceptions, for example: if...) =Stack overflow caused register address parameters to be tampered with, and =The valid range of register addresses for industrial communication protocols is 0x0001-0xFFFF. Output =The message address field of the industrial communication protocol is changed to 0x10000 (out of bounds).
[0131] Through this mapping, the surrogate of the unknown vulnerability is no longer a random simulation of anomalies, but a targeted simulation based on the vulnerability semantics and protocol characteristics, ensuring that the attack effect is consistent with the protocol interaction logic of the real unknown vulnerability attack.
[0132] The execution unit mainly consists of an equipment library construction subunit and a multi-level parallel subunit. For the equipment library construction subunit, standardized unknown vulnerability attack scenarios can be generated based on the mapping relationship and the set of common attack features. The standardized weaponized equipment library, attack scenarios, scripts, constraints, and expected effects are packaged into "scenario units" and stored and delivered in a unified format. The standardized structure of each scenario unit can be represented by relation (18), which is shown below:
[0133]
[0134] (18);
[0135] in, Indicate the attack type and specify the category to which the attack belongs (e.g., unknown vulnerability surrogate attack (state deadlock type), Distributed Denial-of-Service Attack (DDoS) attack (unrestricted or throttled resource allocation), Industrial Control Protocol attack (tampering with industrial communication protocol function codes)). Adopt the Common Vulnerabilities and Exposures (CVE) / Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK) classification standard. It displays target information, describing the technical parameters of the target (such as device type: programmable logic controller (e.g., Schneider M340), protocol: industrial communication protocol / transmission control protocol (port 502), target Internet protocol: 192.168.1.10), and supports automatic matching of target devices in the simulation environment; This refers to an attack script, which is an executable automated script containing surrogate triggering logic, traffic generation code, and timing control functions. It supports parameterized configuration (such as modifying the attack frequency and surrogate type). These constraints represent the preconditions and limitations for simulation execution (such as the target device needing to be in operation, network latency needing to be controlled within 50-200ms, and direct write operations to physical devices being prohibited) to prevent simulation from damaging the real system. The expected effect is defined by the observable results after a successful attack (such as the programmable logic controller being locked and unable to respond to normal control commands, or the central processing unit utilization of the target device reaching more than 95%), which serve as the benchmark for evaluating the subsequent attack effect.
[0136] For multi-level parallel sub-units, to improve simulation efficiency (especially for large-scale scenario verification), the equipment library integrates a one-click orchestration process and a multi-machine parallel mechanism, allowing users to configure simulation tasks through a visual interface and automatically complete script loading, node scheduling, and result aggregation. The one-click orchestration process mainly consists of: First, scenario selection: Users select target scenarios from the equipment library (such as surrogate attacks for unknown vulnerabilities (resource exhaustion type) or industrial communication protocol tampering attacks); then, parameter configuration: The network attack simulation engine automatically loads the default parameters of the scenario (such as attack frequency and target Internet protocol), which users can modify as needed (e.g., adjusting the attack frequency from 100 times / second to 500 times / second); then, execution plan generation: The verification system generates a timing execution plan based on scenario dependencies (e.g., executing a resource exhaustion attack first, followed by a state lockout attack); finally, automatic deployment: The verification system distributes the attack script to the specified simulation node (local or remote node) via Secure Shell (SSH) / Application Programming Interface (API) and starts execution.
[0137] The verification system primarily employs a master-slave architecture to achieve multi-machine parallelism. The master node is mainly responsible for task scheduling (e.g., assigning 10 surrogate scenarios with unknown vulnerabilities to 5 slave nodes, with each slave node executing 2 scenarios), status monitoring (receiving real-time execution progress from slave nodes), and result aggregation (collecting attack logs and effect data from all nodes). Slave nodes can independently execute their assigned attack scenarios without manual intervention. If an anomaly is encountered during execution (e.g., target device offline), an alarm is automatically reported to the master node and a retry is initiated. Multi-machine parallelism significantly reduces the simulation time for large-scale scenarios (e.g., reducing the simulation time for 100 scenarios from 2 hours on a single machine to 24 minutes on 5 machines), supporting comprehensive attack verification of complex systems (e.g., multi-subnet industrial control networks).
[0138] For the scoring unit, after the simulation, the verification system automatically generates an attack mechanism explanation and quantitative scoring report, which not only presents whether the attack was successful, but also explains how the attack took effect and how the defense system performed, providing a basis for decision-making for defense optimization. The attack mechanism explanation includes three parts: surrogate mapping logic, attack propagation path, and system failure cause. For example, the surrogate attack of this unknown vulnerability is based on the stack overflow in the program semantic segment causing the status register to be tampered with, which can be mapped to the message status field in the industrial communication protocol in the protocol side effect being written to 0xFF; the attack injects abnormal messages through the 502 port of the programmable logic controller, causing the finite state machine of the programmable logic controller to lock from the running state to the fault state, and cannot respond to the reset command of the scheduling master station. Finally, the quantitative scoring report is output, and the comprehensive score is calculated using a weighted formula to quantify the attack effect and the defense system performance. The weighted formula can be expressed by the relation (19), which is shown below:
[0139] (19);
[0140] in, The score represents the overall rating (0-100 points, where a higher score indicates a greater threat to the verification system or a worse performance of the security application). Indicates the attack success rate (0-100%, such as 8 out of 10 attacks succeeding, resulting in a state lock-in, the success rate is 80%). This indicates the response time of the defense system (unit: seconds; for example, if an Intrusion Detection System (IDS) triggers an alarm 3 seconds after an attack is launched, the response time is 3 seconds. The shorter the response time, the lower the score, which can be converted to 0-100 points). This indicates the resource consumption caused by the attack (0-100%, such as when the CPU utilization increases from 30% to 90%, the resource consumption is 60%). This represents the weighting coefficient (configured according to business priority; for example, in industrial control systems, resource consumption has a higher weighting). ).
[0141] The report also includes attack sequence diagrams, defense alarm logs, and parameter sensitivity analysis (such as the success rate increasing from 80% to 95% when the attack frequency increases to 500 times / second), providing data support for defense strategy optimization (such as adjusting IDS alarm thresholds and increasing resource monitoring of programmable logic controllers).
[0142] In one exemplary embodiment, the verification system for the security protection application based on any of the foregoing embodiments also provides a verification method for the security protection application, such as... Figure 6 As shown, it includes:
[0143] S101 compiles and generates multiple micro-instructions and replayable scripts based on custom network attack behaviors and existing network attack behaviors.
[0144] In this application embodiment, the specific method for compiling and generating multiple microinstructions and replayable scripts based on custom network attack behaviors and existing network attack behaviors is similar to the aforementioned Figures 1-5 The methods described in any implementation are basically the same, and for details, please refer to the foregoing explanation, which will not be repeated here.
[0145] S102 generates attack strategies based on multiple microinstructions and replayable scripts.
[0146] In this application embodiment, the specific method for generating an attack strategy based on multiple microinstructions and a replayable script is described above. Figures 1-5 The methods described in any implementation are basically the same, and for details, please refer to the foregoing explanation, which will not be repeated here.
[0147] S103, initiate the first network attack and the second network attack against the verification device.
[0148] In this application embodiment, the specific method for launching a first network attack and a second network attack against a verification device is described above. Figures 1-5 The methods described in any implementation are basically the same, and for details, please refer to the foregoing explanation, which will not be repeated here.
[0149] S104: Generate a first network attack behavior for a known vulnerability based on the attack strategy, obtain the attack effect of a simulated unknown vulnerability based on the zero-day effect surrogate module, and generate a second network attack behavior for the corresponding unknown vulnerability based on the attack effect.
[0150] In this embodiment of the application, the method involves generating a first network attack behavior based on an attack strategy that exploits a known vulnerability, obtaining an attack effect simulating an unknown vulnerability using a zero-day effect surrogate module, and then generating a second network attack behavior corresponding to the unknown vulnerability based on the attack effect. This method is similar to the aforementioned... Figures 1-5 The methods described in any implementation are basically the same, and for details, please refer to the foregoing explanation, which will not be repeated here.
[0151] The security application verification method described in the above embodiments maps program-level vulnerability behavior to protocol effects through a zero-day effect surrogate module. This allows the security application verification system to accurately simulate and test the impact of unknown vulnerability attacks without real vulnerability code, thus improving the coverage of network simulation attacks. Secondly, the security application verification system achieves dynamic control over different attack behaviors through behavior mapping and logic mapping modules, enabling attack strategies to be flexibly switched under different network topologies and permission environments, thereby improving the network simulation attack simulation capability of the security application verification system. Finally, the security application verification system, through the linkage between the network attack simulation engine and the verification device, ensures that the defense performance of the security application can be comprehensively evaluated when dealing with network simulation attacks, thus providing more realistic and comprehensive attack simulation and defense verification.
[0152] In an exemplary embodiment, the "compiling and generating multiple micro-instructions and replayable scripts based on custom network attack behaviors and existing network attack behaviors" in S101 above, such as... Figure 7 As shown, it includes:
[0153] S201: Obtain custom network attack behavior and compile the custom network attack behavior using an event domain-specific language to generate multiple micro-instructions containing the execution sequence.
[0154] In this embodiment of the application, the method involves acquiring custom network attack behaviors and compiling these custom network attack behaviors using an event domain-specific language to generate multiple microinstructions containing execution timing sequences. This method is similar to the aforementioned... Figures 1-5 The methods described in any implementation are basically the same, and for details, please refer to the foregoing explanation, which will not be repeated here.
[0155] S202 calls the protocol template library to dynamically adapt to different protocols and generates multiple attack packets based on multiple micro-instructions.
[0156] In this embodiment of the application, the method for dynamically adapting different protocols by calling a protocol template library and generating multiple attack packets based on multiple microinstructions is described above. Figures 1-5 The methods described in any implementation are basically the same, and for details, please refer to the foregoing explanation, which will not be repeated here.
[0157] S203 extracts attack logic from existing network attack behavior and generates replayable scripts.
[0158] In this application embodiment, the specific method for extracting attack logic from existing network attack behavior and generating replayable scripts is described above. Figures 1-5 The methods described in any implementation are basically the same, and for details, please refer to the foregoing explanation, which will not be repeated here.
[0159] In an exemplary embodiment, the above-mentioned S104 "generates a first network attack behavior for a known vulnerability according to the attack strategy, obtains the attack effect of simulating an unknown vulnerability according to the zero-day effect surrogate module, and generates a second network attack behavior for a corresponding unknown vulnerability based on the attack effect" is as follows: Figure 8 As shown, it includes:
[0160] S301: Extract common attack features of unknown vulnerability attacks in existing networks and generate a set of common attack features.
[0161] In this embodiment of the application, the method for extracting common attack features of unknown vulnerability attacks in existing networks and generating a set of common attack features is described above. Figures 1-5 The methods described in any implementation are basically the same, and for details, please refer to the foregoing explanation, which will not be repeated here.
[0162] S302, Establish a mapping relationship between the program-level vulnerability behavior and the protocol-level attack behavior corresponding to the attack on the unknown vulnerability.
[0163] In this application embodiment, the specific method for establishing a mapping relationship between the program-level vulnerability behavior corresponding to an unknown vulnerability attack and the protocol-level attack behavior is described above. Figures 1-5 The methods described in any implementation are basically the same, and for details, please refer to the foregoing explanation, which will not be repeated here.
[0164] S303 generates a standardized unknown vulnerability attack scenario based on the mapping relationship and common attack feature set, generates a second network attack behavior for unknown vulnerabilities based on the unknown vulnerability attack scenario, and launches the second network attack behavior to the verification device.
[0165] In this embodiment of the application, a method is described that generates a standardized unknown vulnerability attack scenario based on a mapping relationship and a set of common attack features, generates a second network attack behavior for an unknown vulnerability based on the unknown vulnerability attack scenario, and launches the second network attack behavior to a verification device. This method is similar to the aforementioned... Figures 1-5 The methods described in any implementation are basically the same, and for details, please refer to the foregoing explanation, which will not be repeated here.
[0166] S304. After the second network attack is completed, the attack effect of the second network attack is scored and a score report is generated.
[0167] In this embodiment of the application, a specific method is provided for scoring the effectiveness of a second network attack and generating a scoring report after the second network attack has been completed. This method is similar to the aforementioned... Figures 1-5 The methods described in any implementation are basically the same, and for details, please refer to the foregoing explanation, which will not be repeated here.
[0168] In summary, based on all the above embodiments, a verification method for security protection applications is also provided, such as... Figure 9 As shown, the method includes:
[0169] S401: Obtain custom network attack behavior and compile the custom network attack behavior using an event domain-specific language to generate multiple micro-instructions containing the execution sequence.
[0170] S402 calls the protocol template library to dynamically adapt to different protocols and generates multiple attack packets based on multiple micro-instructions;
[0171] S403 extracts attack logic from existing network attack behavior and generates replayable scripts;
[0172] S404 generates attack strategies based on multiple microinstructions and replayable scripts;
[0173] S405, Initiate a first network attack and a second network attack against the verification device;
[0174] S406: Extract common attack features of unknown vulnerability attacks in existing networks and generate a set of common attack features;
[0175] S407, Establish a mapping relationship between the program-level vulnerability behavior and the protocol-level attack behavior corresponding to unknown vulnerability attacks;
[0176] S408 generates a standardized unknown vulnerability attack scenario based on the mapping relationship and common attack feature set, generates a second network attack behavior for unknown vulnerabilities based on the unknown vulnerability attack scenario, and launches the second network attack behavior to the verification device.
[0177] S409: After the second network attack is completed, the attack effect of the second network attack is scored and a score report is generated.
[0178] The methods described in each of the above steps have been described in the foregoing embodiments. For details, please refer to the foregoing descriptions. They will not be repeated here.
[0179] It should be understood that although the steps in the flowcharts of the embodiments described above are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the embodiments described above may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages in other steps. It is understood that the steps in different embodiments can be freely combined as needed, and all non-contradictory solutions formed by such combinations are within the scope of protection of this application.
[0180] In one exemplary embodiment, a computer device is provided, which may be a terminal, and its internal structure diagram may be as follows: Figure 10 As shown, the computer device includes a processor, memory, input / output interfaces, a communication interface, a display unit, and an input device. The processor, memory, and input / output interfaces are connected via a system bus, and the communication interface, display unit, and input device are also connected to the system bus via the input / output interfaces. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The input / output interfaces are used for exchanging information between the processor and external devices. The communication interface is used for wired or wireless communication with external terminals; wireless communication can be achieved through Wi-Fi, mobile cellular networks, Near Field Communication (NFC), or other technologies. When the computer program is executed by the processor, it implements a verification method for a security application.
[0181] Those skilled in the art will understand that Figure 10 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.
[0182] In one exemplary embodiment, a computer device is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to perform the following steps:
[0183] Multiple micro-instructions and replayable scripts are compiled and generated based on custom network attack behaviors and existing network attack behaviors.
[0184] Attack strategies are generated based on multiple microinstructions and replayable scripts;
[0185] Initiate a first network attack and a second network attack against the verification device;
[0186] The attack strategy generates a first network attack behavior targeting known vulnerabilities; the zero-day effect surrogate module is used to obtain the attack effect simulating unknown vulnerabilities; and the attack effect is used to generate a second network attack behavior targeting the corresponding unknown vulnerabilities.
[0187] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon, the computer program performing the following steps when executed by a processor:
[0188] Multiple micro-instructions and replayable scripts are compiled and generated based on custom network attack behaviors and existing network attack behaviors.
[0189] Attack strategies are generated based on multiple microinstructions and replayable scripts;
[0190] Initiate a first network attack and a second network attack against the verification device;
[0191] The attack strategy generates a first network attack behavior targeting known vulnerabilities; the zero-day effect surrogate module is used to obtain the attack effect simulating unknown vulnerabilities; and the attack effect is used to generate a second network attack behavior targeting the corresponding unknown vulnerabilities.
[0192] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, performs the following steps:
[0193] Multiple micro-instructions and replayable scripts are compiled and generated based on custom network attack behaviors and existing network attack behaviors.
[0194] Attack strategies are generated based on multiple microinstructions and replayable scripts;
[0195] Initiate a first network attack and a second network attack against the verification device;
[0196] The attack strategy generates a first network attack behavior targeting known vulnerabilities; the zero-day effect surrogate module is used to obtain the attack effect simulating unknown vulnerabilities; and the attack effect is used to generate a second network attack behavior targeting the corresponding unknown vulnerabilities.
[0197] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, artificial intelligence (AI) processors, etc., and are not limited to these.
[0198] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this application.
[0199] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.
Claims
1. A verification system for a security protection application, characterized in that, The verification system includes: a network attack simulation engine and a verification device; the network attack simulation engine and the verification device are connected via a network; the network attack simulation engine includes: a behavior mapping module, a logic mapping module, a three-link linkage module, and a zero-day effect surrogate module; the behavior mapping module is connected to the logic mapping module and the three-link linkage module respectively; the logic mapping module is connected to the three-link linkage module. The network attack simulation engine is used to simulate a first network attack behavior with known vulnerabilities and a second network attack behavior with unknown vulnerabilities in a simulated real environment, and to launch the first network attack behavior and the second network attack behavior to the verification device. The verification device is used to activate the security protection application to defend against the first network attack and the second network attack, and to verify the protection performance of the security protection application based on the defense results. The behavior mapping module is used to compile and generate multiple micro-instructions and replayable scripts based on custom network attack behaviors and existing network attack behaviors; the logic mapping module is used to generate attack strategies based on the multiple micro-instructions and the replayable scripts; the three-link linkage module is used to generate a first network attack behavior for the known vulnerability based on the attack strategy; and the zero-day effect surrogate module is used to simulate the attack effect of an unknown vulnerability and generate a second network attack behavior for the corresponding unknown vulnerability based on the attack effect.
2. The verification system according to claim 1, characterized in that, The behavior mapping module includes: a compilation unit, a message construction unit, a state preservation unit, a timing control unit, and a conversion unit; The compilation unit is used to acquire custom network attack behaviors and compile the custom network attack behaviors using an event domain-specific language to generate multiple micro-instructions containing execution timing sequences. The message construction unit is used to call the protocol template library to dynamically adapt to different protocols and generate multiple attack messages according to the multiple micro-instructions. The state-keeping unit is used to record and display the attack progress when the network attack simulation engine launches a network attack against the verification device; the attack progress includes session state, permission level, and device interaction data. The timing control unit is used to simulate the real environment and determine the actual sending time of the attack message; The conversion unit is used to extract attack logic from the attack behavior of existing networks and generate replayable scripts.
3. The verification system according to claim 2, characterized in that, The logic mapping module includes: a stage encapsulation unit, a constraint unit, a triggering unit, and an orchestration unit; The stage encapsulation unit is used to determine the target attack behavior based on the multiple attack packets and the replayable script, divide the target attack behavior into different stages according to the life cycle of the target attack behavior, and encapsulate the different stages into nodes corresponding to the corresponding stages; each node is associated with the attack behavior of the corresponding stage. The constraint unit is used to provide constraint conditions; the constraint conditions are used to evaluate whether a jump can be made between two nodes. The triggering unit is used to provide triggering conditions; the triggering conditions are used to verify whether the jump between the two nodes is successful. The orchestration unit is used to orchestrate the attack behaviors associated with nodes at different stages according to the constraints and triggering conditions using a finite state machine, and generate an attack strategy.
4. The verification system according to claim 3, characterized in that, The three-link linkage module includes: a first coupling unit and a second coupling unit; the first coupling unit is a unit that couples the information domain and the control domain, and the second coupling unit is a unit that couples the control domain and the physical domain; The first coupling unit is used to generate a first network attack behavior that exploits a known vulnerability according to the attack strategy, and to launch the first network attack behavior to the verification device. The second coupling unit is used to receive physical parameter change information fed back by the verification device after being attacked by the first network attack behavior, and to display the physical parameter change information.
5. The verification system according to claim 4, characterized in that, The first coupling unit is also used to simulate a real abnormal network environment and to launch an attack on the first network under the real abnormal network environment.
6. The verification system according to claim 4, characterized in that, The second coupling unit is further configured to generate state information based on physical parameter change information and send the state information to the behavior mapping module; Correspondingly, the behavior mapping module is also used to generate an alarm message based on the status information and send the alarm message to the verification device.
7. The verification system according to claim 1, characterized in that, The zero-day effect surrogate module includes: a surrogate unit, a mapping unit, an operation unit, and a scoring unit; The substitute unit is used to extract common attack features of unknown vulnerability attacks in existing networks and generate a set of common attack features. The mapping unit is used to establish a mapping relationship between the program-layer vulnerability behavior and the protocol-layer attack behavior corresponding to the unknown vulnerability attack. The operating unit is configured to generate a standardized unknown vulnerability attack scenario based on the mapping relationship and the common attack feature set, generate a second network attack behavior for the unknown vulnerability based on the unknown vulnerability attack scenario, and launch the second network attack behavior to the verification device. The scoring unit is used to score the attack effect of the second network attack after the second network attack is completed, and to generate a scoring report.
8. A verification method for a security protection application, characterized in that, A network attack simulation engine applied in a verification system for a security protection application as described in any one of claims 1-7, the method comprising: Multiple micro-instructions and replayable scripts are compiled and generated based on custom network attack behaviors and existing network attack behaviors. An attack strategy is generated based on the multiple microinstructions and the replayable script; Initiate the first network attack and the second network attack against the verification device; The attack strategy generates a first network attack behavior for the known vulnerability; the zero-day effect surrogate module obtains the attack effect of simulating the unknown vulnerability; and the attack effect is used to generate a second network attack behavior for the corresponding unknown vulnerability.
9. The method according to claim 8, characterized in that, The process of compiling and generating multiple micro-instructions and replayable scripts based on custom network attack behaviors and existing network attack behaviors includes: A custom network attack behavior is obtained, and the custom network attack behavior is compiled using an event domain-specific language to generate multiple micro-instructions containing the execution sequence. The protocol template library is invoked to dynamically adapt to different protocols, and multiple attack packets are generated based on the multiple micro-instructions; The attack logic is extracted from the attack behavior of existing networks to generate replayable scripts.
10. The method according to claim 8, characterized in that, The first network attack behavior based on the attack strategy is generated to exploit the known vulnerability; and the attack effect simulating the unknown vulnerability is obtained based on the zero-day effect surrogate module, and the second network attack behavior corresponding to the unknown vulnerability is generated based on the attack effect. Extract common attack features from unknown vulnerability attacks in existing networks and generate a set of common attack features; Establish a mapping relationship between the program-level vulnerability behavior and the protocol-level attack behavior corresponding to the aforementioned unknown vulnerability attack; Based on the mapping relationship and the set of common attack features, a standardized unknown vulnerability attack scenario is generated, and a second network attack behavior for the unknown vulnerability is generated based on the unknown vulnerability attack scenario, and the second network attack behavior is launched to the verification device. After the second network attack is completed, the attack effect of the second network attack is scored and a score report is generated.