Botnet attack simulation-oriented knowledge enhanced large model time series data generation method

By combining knowledge graphs with normalized time series generation methods, the problems of scene representation and data adaptation in botnet simulation data generation were solved, achieving the generation of highly realistic simulation data and improving the authenticity and applicability of botnet simulation data.

CN121887490APending Publication Date: 2026-04-17GUANGZHOU UNIVERSITY +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
GUANGZHOU UNIVERSITY
Filing Date
2026-01-11
Publication Date
2026-04-17

AI Technical Summary

Technical Problem

Existing methods for generating botnet simulation data lack the ability to characterize the temporal structure of attack behavior, making it difficult to cover different botnet families and different topological structures. Furthermore, large models suffer from high feature dimensionality, large scale differences, and difficulty in uniformly representing scenarios during training. There is a lack of technical solutions that combine knowledge graphs with time-series data generated by large models.

Method used

By combining knowledge graph and normalized time series generation methods, semantic parsing and parameter completion are performed through a semantic enhancement module. Normalized trend curves are generated using Transformer, and scaling factors are calculated through an environment-aware adaptation module. Closed-loop optimization is then performed in conjunction with network environment constraints to generate highly realistic simulation data.

Benefits of technology

It achieves the generation of highly realistic simulation data adapted to different botnet families and asset environments within a unified normalized time-series space, improving the scene expression ability and the realism and generalization ability of simulation data, and avoiding numerical instability issues.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure FT_1
    Figure FT_1
  • Figure FT_2
    Figure FT_2
  • Figure FT_3
    Figure FT_3
Patent Text Reader

Abstract

The invention provides a Botnet attack simulation-oriented knowledge enhanced large model time series data generation method. A simulation instruction is received through an interaction interface, a semantic enhancement module is communicated with a knowledge graph and threat intelligence to complete intention recognition, graph reasoning, template matching and consistency verification, and structured scene features with confidence are output; the environment perception adaptation module calculates a scale scaling factor in combination with asset surveying and mapping, vulnerability risks and a historical utilization success rate; the generation engine generates an exponential growth-cosine platform-exponential decay parameter template by using Transform in a unified normalized time sequence space, renders a curve, and introduces OU noise synthesis flow and an active host time sequence; the self-adaptive optimization module verifies the peak value, the accumulated value and the increment under the asset / IP / port / bandwidth boundary and updates the template or the low-rank adaptation layer in a closed loop mode, high simulation of form-scale decoupling is achieved, and simulation data can be restrained.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the fields of network traffic simulation and network security technology, and in particular to a method for generating time-series data for knowledge-enhanced large-scale models for botnet attack simulation. Background Technology

[0002] In training network security attack and defense and detection models, a large amount of representative network simulation data is needed, especially in complex scenarios such as botnet attacks, where simulation data that realistically reproduces botnet behavior is particularly important. Existing botnet simulation data mostly relies on manually written scripts or is generated using simple statistical models. Parameters such as ports, protocols, and speeds are typically set based on experience, lacking a characterization of the temporal structure of attack behavior and failing to cover different botnet families and botnet scenarios with different topologies.

[0003] With the development of large-scale modeling technology, large language models have strong capabilities in sequence modeling and condition generation. However, training large models directly on raw traffic data presents challenges such as high feature dimensionality, large scale differences, and difficulty in uniformly representing scenarios, making it difficult to transfer the models to new scenarios. Meanwhile, the cybersecurity field has accumulated a wealth of domain knowledge regarding attack types, node roles, protocol characteristics, and traffic patterns, often organized in the form of knowledge graphs. However, current technologies primarily use knowledge graphs for detection and alert analysis, lacking technical solutions that combine knowledge graphs with time-series data generated by large models for simulation data construction.

[0004] Therefore, how to use knowledge graphs to enhance the characterization of botnet scenarios, guide large models to generate data in a unified normalized time-series space, and restore them to simulation data that meets the needs of the scenario through inverse normalization is a technical problem that urgently needs to be solved in this field. Summary of the Invention

[0005] The purpose of this invention is to propose a method and system for constructing botnet simulation data that combines knowledge graph enhancement and normalized time series generation. This method generates trend patterns of botnet behavior within a unified normalized time series space, restores the scale by combining scaling factors based on asset exposure surface, historical utilization success rate, and regional adjustment coefficient, and performs closed-loop optimization under network environment constraints. This automatically constructs highly realistic simulation data that adapts to different botnet families and asset environments.

[0006] To achieve the above objectives, the present invention proposes the following technical solution: a knowledge-enhanced large model time-series data generation method for botnet attack simulation, the method comprising an interactive interface layer, a semantic enhancement module, an environment-aware adaptation module, a simulation data generation engine, an adaptive optimization module, a data support layer, and a data storage and display module.

[0007] The interaction interface layer is used to receive botnet simulation instructions from users or simulation platforms and convert the simulation instructions into inputs that the system can process.

[0008] The semantic enhancement module is connected to the cybersecurity knowledge graph and threat intelligence database. It performs semantic parsing, graph inference, parameter completion, and consistency verification on the input provided by the interaction interface layer, and finally outputs structured scene features with confidence labels. Preferably, the semantic enhancement module includes, in sequence: an intent recognition unit, a graph inference unit, a scene template matching unit, a semantic consistency verification unit, and a confidence evaluation and labeling unit. The intent recognition unit identifies semantic elements such as botnet families, target asset types, attack stages, and time windows through word segmentation, part-of-speech tagging, and dependency analysis. The graph reasoning unit performs path matching and parameter derivation according to a preset relational path rule base (such as "botnet family-vulnerability-protocol", "stage-feature-duration", "botnet family-typical scale", etc.) to generate a parameter candidate set. The scenario template matching unit performs similarity matching between the parameter candidate set and the botnet scenario template base (weak password outbreak, high-speed IoT propagation, etc.) and outputs the parameters after template correction. The semantic consistency verification unit verifies the asset type, protocol and port openness, and stage and time window compatibility and corrects conflicting parameters. The confidence assessment and labeling unit calculates the confidence score for each parameter, labels the parameters with confidence, and forms a structured scenario feature with confidence.

[0009] The environmental perception and adaptation module is connected to the asset mapping database and is used to determine the exposure surface baseline of the target asset. Historical utilization success rate and regional adjustment coefficient Calculate scaling factor Specifically, the asset mapping interface retrieves the baseline of asset exposure surfaces that match the scene characteristics from the asset mapping database. The scaling factor calculation unit calculates based on CVSS and historical utilization success rate. Calculated based on regional online rate, reachability, and blocking intensity. , and according to Obtain the scaling factor.

[0010] The simulation data generation engine is used to generate botnet simulation data in a normalized time-series space. It includes a parameter template generation unit and a morphological rendering unit. The parameter template generation unit uses a Transformer-based sequence-to-sequence generative language model. It takes the structured scene features as input and outputs a parameter template conforming to a predefined JSON Schema. This parameter template references three combinations from a fixed function template library and provides a set of parameters. The morphological rendering unit generates a normalized trend curve based on the parameter template. Apply scale-aware modulator to For input pairs Monotonic modulation is performed to obtain , and according to Synthesized simulation data, applying C¹ continuity constraints to inter-segment connections, the... This is an OU noise process.

[0011] The adaptive optimization module includes a boundary verification unit and a feedback unit. The boundary verification unit constructs a boundary set E based on network environment constraints, which includes at least the maximum number of assets. Maximum number of IP addresses Maximum number of ports With bandwidth limit The peak value, cumulative value, and single-step increment of Y(t) are checked for out-of-bounds errors, and the peak value is maintained within the peak maintenance window. Internal peak micro-seismic control is implemented when Reaching the fast response threshold When this occurs, fast response control is activated, and the decay rate is updated to [value]. ,continued Each sampling step. When the evaluation result does not meet the preset threshold, the feedback unit forms a comprehensive evaluation signal R based on shape similarity, boundary compliance, and stability scores, and iteratively updates the parameter template and low-rank adaptation layer parameters. The low-rank adaptation layer is only inserted into the Q / K / V projection matrix of the generated model, and the weights of the main model remain frozen, thus achieving closed-loop optimization of the generation process.

[0012] The data support layer includes a threat intelligence database, a cybersecurity knowledge graph database, and an asset mapping database, which provide threat intelligence data, knowledge graph data, and asset exposure surface data for the semantic enhancement module and the environment awareness adaptation module; the data storage and display module is used to persistently store the verified simulation data and provide interfaces to external simulation platforms or detection models.

[0013] This invention also provides a method for constructing botnet simulation data based on knowledge graph enhancement and normalized time series generation, applied to the aforementioned system, the method comprising:

[0014] S1: Semantic parsing and knowledge enhancement: Initial semantic slots are obtained from simulation instructions, graph reasoning and parameter completion are performed according to the relational path rule base, and structured scene features are obtained through template matching, semantic consistency verification and confidence labeling.

[0015] S2: Normalized parameter generation, which takes structured scene features as input from a Transformer-based sequence-to-sequence model and outputs parameter templates. This is used to construct a normalized trend curve. ;

[0016] S3: Scaling factor calculation, which calculates the scaling factor based on asset mapping data, CVSS, and historical success rate. ;

[0017] S4: Shape rendering and scale-aware modulation, using S as input. Monotonic modulation is performed to obtain , and according to Synthetic simulation data, among which For OU noise process;

[0018] S5: Network environment constraints and closed-loop optimization, constructing the boundary set E. The peak value, cumulative value and single-step increment are checked for out-of-bounds; when the evaluation result does not meet the threshold, a feedback signal is generated to update the parameter template and only update the low-rank adaptation layer parameters.

[0019] Compared with the prior art, the present invention has the following beneficial effects:

[0020] 1. By adopting the form-scale decoupling design of "normalized time series + environment scaling", the large model learns and generates trend patterns only within a unified normalized space, and then restores the scale by a calculable scaling factor S. This avoids the numerical instability caused by directly manipulating absolute values ​​and ensures that the generated results meet the network environment constraints such as the number of assets and bandwidth.

[0021] 2. By using intent recognition, graph reasoning, template matching, semantic consistency verification, and confidence labeling in the semantic enhancement module, botnet families, attack stages, vulnerability information, and asset environment are modeled in a unified manner, realizing automatic mapping from natural language scene description to structured scene features, thereby improving scene expressiveness and interpretability.

[0022] 3. By using a fixed function template library and scale-aware modulation, a monotonically coupled relationship is established between the three-segment function combination and the scale S. OU noise, peak micro-vibration, and fast response control are introduced to make the generated simulation curves more closely resemble the behavior of real botnets in terms of shape and local fluctuations at each stage of burst, plateau, and decay.

[0023] 4. By constructing a closed loop from generation, boundary verification, quality evaluation to parameter template and low-rank adaptation layer updates through the adaptive optimization module, the system can continuously absorb new threat intelligence and asset mapping data during long-term operation, thereby improving the realism and generalization ability of simulation data in different botnet families and different regional scenarios. Attached Figure Description

[0024] Figure 1This is a schematic diagram of the overall architecture of a knowledge-enhanced large model time-series data generation method for botnet attack simulation provided in an embodiment of the present invention.

[0025] Figure 2 This is a schematic diagram of the internal processing flow of the semantic enhancement module provided in an embodiment of the present invention.

[0026] Figure 3 This is a schematic flowchart of a knowledge-enhanced large model time-series data generation method for botnet attack simulation provided by an embodiment of the present invention. Detailed Implementation

[0027] The technical solution of the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the following embodiments are only for illustrating the present invention and are not intended to limit the present invention.

[0028] Example 1: System Architecture

[0029] See Figure 1 This embodiment provides a method for generating time-series data for knowledge-enhanced large-scale models for botnet attack simulation. The system can be deployed on a single server, in a cluster environment, or on a cloud platform. It includes an interactive interface layer, a semantic enhancement module, an environment-aware adaptation module, a simulation data generation engine, an adaptive optimization module, a data support layer, and a data storage and display module. The modules can communicate with each other through an internal bus or network interface.

[0030] (1) Interaction Interface Layer

[0031] The interaction interface layer is used to interact with users or the simulation platform, receiving simulation instructions in natural language or structured configuration files. Users can input descriptions such as "simulating the infection curve of a Mirai botnet spreading with weak passwords in a certain province" or "simulating HTTP flood attack traffic targeting a cloud server." The interaction interface layer validates the input, converts it into an internally standardized text or JSON structure, and appends metadata such as request identifiers and timestamps before forwarding it to the semantic enhancement module.

[0032] (2) Semantic enhancement module

[0033] See Figure 2 The semantic enhancement module is connected to the cybersecurity knowledge graph and threat intelligence database, and includes, in sequence, an intent recognition unit, a graph reasoning unit, a scene template matching unit, a semantic consistency verification unit, and a confidence assessment and annotation unit.

[0034] The intent recognition unit performs word segmentation, part-of-speech tagging, and dependency analysis on the simulated commands to identify key components such as "botnet family name," "target asset type," "attack phase description," and "time window." For example, for the command "simulating the infection curve of a Mirai botnet spreading weak passwords within a certain province," initial semantic slots such as family=Mirai, asset=home router / camera, scenario=weak password spread, region=a certain province, and duration=48h can be extracted.

[0035] The graph reasoning unit performs graph retrieval and parameter derivation on the aforementioned slots according to a preset relational path rule base. The relational paths include at least "botnet family - vulnerability - protocol," "stage - characteristic - duration," and "botnet family - typical size," etc. The graph reasoning unit first searches for associated vulnerability entities in the knowledge graph based on the "family" entity, then obtains the protocol type and port range based on the relationship between the vulnerability and the protocol / port; next, it searches for typical characteristics and duration intervals based on the stage entity; finally, it queries the typical size distribution of the botnet family, using the typical size intervals corresponding to different quantiles as candidate parameters. Combining this with statistical information from the threat intelligence database regarding the historical success rate and geographical distribution of attacks on this botnet family, the candidate parameters are corrected and weighted to form a parameter candidate set.

[0036] The scenario template matching unit maintains a botnet scenario template library. Each template corresponds to a common scenario, such as weak password outbreaks, high-speed IoT propagation, and slow cloud server penetration. Each template includes a set of keywords, typical parameter configurations, and curve shape labels. The scenario template matching unit vectorizes the parameter candidate set and template parameters, selects one or more templates with the highest similarity using cosine similarity, and corrects or completes parameters such as scanning cycle, lifecycle stage division, and typical size range using the default values ​​provided by the template.

[0037] The semantic consistency verification unit performs consistency checks on the user-input semantics, graph inference results, and template inference parameters. Specific checks include: whether the asset type matches the vulnerability platform; whether the protocol type matches the target port; whether the phase division can be completed within a given time window; and whether the parameter values ​​violate the upper and lower limits recorded in the knowledge graph. For inconsistent parameters, the semantic consistency verification unit adjusts them according to a preset priority strategy or marks them as parameters requiring deweighting.

[0038] The confidence assessment and annotation unit integrates semantic recognition confidence, graph inference credibility, template matching similarity, and consistency verification pass rate to calculate a confidence score for each scene parameter, classifying the parameters into high, medium, and low confidence categories. High-confidence parameters are directly used as conditions for subsequent generation; medium-confidence parameters are allowed to have slight perturbations introduced during generation; and low-confidence parameters can be replaced by default safe values. The final output structured scene features include parameter values ​​and corresponding confidence labels, providing interpretable scene input for subsequent modules.

[0039] (3) Environmental perception and adaptation module

[0040] The environmental perception and adaptation module is connected to the asset mapping database and includes an asset mapping interface and a scaling factor calculation unit.

[0041] The asset mapping interface uses fields such as region and asset type in the structured scene features to query the asset mapping database for the number of assets that meet the criteria within a given area. For example, it can count the number of home routers and cameras with open Telnet / 23 ports within a province and sum the results to obtain the asset exposure surface base. .

[0042] Scaling factor calculation unit according to Historical utilization success rate and regional adjustment coefficient Calculate the scaling factor S. Success rates can be based on CVSS and historical utilization. Calculation, for example Regional adjustment coefficient The following is obtained by mapping regional online rate, reachability, and blocking intensity: All are limited to , and according to Calculate. The final scaling factor is calculated according to... This provides a basis for controlling the scale of subsequent simulation data.

[0043] (4) Simulation data generation engine

[0044] The simulation data generation engine includes a parameter template generation unit and a morphology rendering unit.

[0045] The parameter template generation unit employs a Transformer-based sequence-to-sequence generative language model. After encoding the structured scene features, it outputs parameter templates conforming to a predefined JSON Schema. These parameter templates contain... Four parameters. The function template library is fixed at three combinations: exponential growth segment. Cosine perturbation platform segment Exponential decay phase The parameter template generation unit, during the training phase, uses (scene features, target normalized curve) as samples and employs a combination of shape loss based on Dynamic Time Warping (DTW) and statistical feature loss for optimization, resulting in a more efficient and effective template generation system. It closely resembles the curves of a real botnet in terms of shape and statistical properties.

[0046] The morphological rendering unit first constructs a piecewise combination function based on the parameter template to generate a normalized trend curve. Its numerical range is strictly limited to This only indicates a relative change in activity. Subsequently, the morphology rendering unit invokes the scale-aware modulator to... For input, Monotonic modulation is performed to obtain To achieve scale The impact on growth rate, plateau duration, and decay rate. To ensure curve smoothness, the morphology rendering unit applies a C¹ continuity constraint at the junctions of each segment. Finally, the morphology rendering unit... Synthetic simulation data, among which The OU noise process is used to simulate network jitter and measurement errors, resulting in botnet simulation data with actual units.

[0047] (5) Adaptive optimization module

[0048] The adaptive optimization module includes a boundary check unit and a feedback unit.

[0049] Boundary verification units construct boundary sets based on network environment constraints. At least the maximum number of assets Maximum number of IP addresses Maximum number of ports With bandwidth limit Boundary check unit The peak value, cumulative value, and single-step increment are checked for out-of-bounds errors. When the peak value exceeds the limit, the check is performed. When the cumulative value exceeds the reasonable upper limit or the single-step increment is abnormal, it is marked as out of bounds. For values ​​within the peak maintenance window... Within the specified time period, the boundary verification unit also follows... Introduce small-amplitude micro-vibrations; when Reaching the fast response threshold At that time, it enters the rapid response phase and updates the decay rate to... ,continued The sampling steps were designed to simulate the rapid decline in infection levels after an emergency response.

[0050] The feedback unit iteratively updates the parameter template and low-rank adaptation layer based on the boundary verification results and the comprehensive evaluation signal R. The comprehensive evaluation signal R is composed of shape similarity (measured by 1 / DTW), boundary compliance, and stability score (e.g., whether the platform oscillation amplitude is within a certain range). Weighted calculation. The feedback unit uses R as the optimization objective and adjusts the output distribution of the parameter template generation unit by updating only the parameters of the low-rank adaptation layer. Simultaneously, it can modify the parameters in the parameter template. Make minor adjustments to achieve closed-loop optimization of the simulation data generation process.

[0051] (6) Data support layer

[0052] The data support layer includes a threat intelligence database, a cybersecurity knowledge graph database, and an asset mapping database. The threat intelligence database stores vulnerability information, attack activity records, and exploit tool characteristics, providing... It provides a foundation for estimation and scenario template construction; the network security knowledge graph database stores botnet family entities, attack stage entities, vulnerability entities, protocol entities, and parameter entities, and establishes an association structure through relationships such as "exploitation," "infection," "communication," and "configuration parameters"; the asset mapping database records the asset exposure status of different regions, ports, and protocols, providing a basis for... The calculation of parameters provides support.

[0053] (7) Data storage and display module

[0054] The data storage and display module is used to persistently store the verified botnet simulation data and provide query, download and interface call services in the form of graphs, event sequences or data files, which can be directly used by external simulation platforms or intrusion detection models.

[0055] Example 2: Method Flow

[0056] See Figure 3 This embodiment presents a method for constructing botnet simulation data based on knowledge graph enhancement and normalized time-series generation, applied to the system described in Embodiment 1. The method includes the following steps:

[0057] S1: Semantic parsing and knowledge enhancement. After receiving simulation commands, the interaction interface layer passes them to the semantic enhancement module. The semantic enhancement module obtains initial semantic slots through the intent recognition unit, and the graph reasoning unit performs graph reasoning and parameter completion based on the relational path rule base. After scene template matching, semantic consistency verification, and confidence labeling, structured scene features with confidence labels are obtained.

[0058] S2: Normalized parameter generation. The parameter template generation unit in the simulation data generation engine takes structured scene features as input to the Transformer-based sequence-to-sequence model and outputs parameter templates. The morphological rendering unit calls a fixed function template library to map the above parameters into a combination of exponential growth segments, cosine perturbation plateau segments, and exponential decay segments, constructing a normalized trend curve in the numerical domain. This curve only represents the relative change in activity.

[0059] S3: Scaling factor calculation; the environment-aware adaptation module obtains the asset exposure surface base from the asset mapping database. And calculate based on CVSS and historical utilization success rate. Based on regional online rate, reachability and blocking intensity, the following was obtained: ,according to Get the scaling factor .

[0060] S4: Morphology Rendering and Scale-Aware Modulation, the morphology rendering unit in the simulation data generation engine... For input pairs Monotonic modulation is performed to obtain And while maintaining the continuity of C¹ between segments, a normalized trend curve is generated based on the adjusted parameters. Then press Synthetic simulation data, This is the OU noise process, used to simulate network jitter and measurement errors.

[0061] S5: Network environment constraints and closed-loop optimization, adaptive optimization module constructs boundary set ,right The peak value, cumulative value, and single-step increment are checked for out-of-bounds errors, and micro-seismic and rapid response control is implemented during the peak maintenance phase. When the evaluation result does not meet the preset threshold, the feedback unit forms a comprehensive evaluation signal R based on shape similarity, boundary compliance, and stability score. The generation strategy of the simulation data generation engine is adjusted by updating the parameter template and updating only the parameters of the low-rank adaptation layer, so that the subsequently generated simulation data is more in line with the network environment and historical statistical patterns in terms of shape and scale.

[0062] As can be seen from the above embodiments, the present invention uses a large model to generate trend patterns in a unified normalized time-series space, and then combines knowledge graphs and asset mapping data to calculate scaling factors and perform network environment constraint verification. At the same time, it introduces peak micro-seismic and fast response mechanisms, so that the generated zombie network simulation data can closely resemble the real scene in terms of macro trends, local fluctuations and scale. This overcomes the shortcomings of existing methods such as uncontrollable numerical values, lack of environmental semantics and high script maintenance costs.

Claims

1. A knowledge-enhanced large model time series data generation method for botnet attack simulation, characterized in that, The system includes: The interaction interface layer is used to receive simulation commands and convert them into inputs that the system can process. The semantic enhancement module is connected to the network security knowledge graph library and threat intelligence library. It is used to parse the input, perform graph reasoning, parameter completion and consistency verification, and finally output structured scene features with confidence labels. The environmental perception and adaptation module is connected to the asset mapping database and is used to determine the exposure surface baseline of the target asset. Historical utilization success rate and regional adjustment coefficient The scaling factor is calculated. ; The simulation data generation engine includes a parameter template generation unit and a shape rendering unit: The parameter template generation unit employs a Transformer-based sequence-to-sequence generative language model. It takes the structured scene features as input and outputs a parameter template conforming to a predefined JSON Schema. This parameter template references three combinations from a fixed function template library and provides a set of parameters. ; The morphological rendering unit generates a normalized trend curve according to the parameter template. Apply scale-aware modulator to For input pairs Monotonic modulation is performed to obtain , and according to Synthesized simulation data, applying C¹ continuity constraints to inter-segment connections, the... For the Ornstein–Uhlenbeck (OU) noise process; The adaptive optimization module includes a boundary check unit and a feedback unit: Boundary verification unit, constructing boundary sets based on network environment constraints ,right The peak value, cumulative value, and single-step increment are checked for out-of-bounds errors. The feedback unit outputs a feedback signal to update the parameter template or only update the parameters of the low-rank adaptation layer when the evaluation result does not meet the preset threshold. The low-rank adaptation layer is only inserted into the generative model. The projection matrix and the main model weights are kept frozen to achieve closed-loop optimization. The data support layer includes a threat intelligence database, a cybersecurity knowledge graph database, and an asset mapping database; The data storage and display module persistently stores the verified simulation data and provides an interface to the outside world.

2. The system according to claim 1, characterized in that, The semantic enhancement module includes, in sequence: The intent recognition unit is used to perform word segmentation, part-of-speech tagging and dependency analysis on the simulation instructions, and outputs initial semantic slots containing botnet family, target asset type, attack stage and time window. The graph reasoning unit is used to perform path matching and parameter derivation according to a preset relational path rule base. The relational path includes at least "botnet family-vulnerability-protocol", "stage-feature-duration" and "botnet family-typical size". The scenario template matching unit is used to perform similarity matching between the derived candidate parameters and the botnet scenario template library (weak password outbreak, high-speed IoT propagation, etc.), and output the parameters after template correction. The semantic consistency verification unit is used to verify asset type, protocol and port open status, phase-time window compatibility and correct conflict parameters; The confidence assessment and labeling unit is used to calculate the confidence score for each parameter and output structured scene features with confidence labels.

3. The system according to claim 1, characterized in that, The scaling factor Calculated using the following deterministic function: Among them, the success rate of historical utilization The calculation formula is Regional adjustment coefficient The calculation formula is: in The values ​​are obtained by mapping online rate, reachability, and blocking strength, respectively, and the range of values ​​is limited to [missing information]. ,function Indicates when Time to take ,when Time to take .

4. The system according to claim 1, characterized in that, The three-segment combination in the fixed function template library is as follows: Exponential growth phase: ; Cosine perturbation plateau segment: ; Exponential decay phase: ; The parameters The range of values ​​for are respectively limited to: .

5. The system according to claim 1, characterized in that: The scale-aware modulator As input, a monotonically increasing function is used to... Modulation is performed, and the specific modulation formula is as follows: in Let be the scale normalization constant. Let be the modulation coefficient, satisfying .

6. The system according to claim 1, characterized in that, The boundary set constructed by the boundary verification unit At least including: Maximum number of assets The calculation formula is as follows: Maximum number of IPs Maximum number of ports With bandwidth limit ; And the boundary verification unit is in the peak maintenance window Internal peak microseismic control; when Reaching the fast response threshold When entering fast response control, where: The decay rate is updated during fast response control to: and maintain Each sampling step.

7. The system according to claim 1, characterized in that, The feedback unit uses a comprehensive evaluation signal based on shape similarity, boundary compliance, and stability scores. The parameter template and low-rank adaptation layer are iteratively updated, where shape similarity is measured by 1 / DTW (Dynamic Time Warping), and stability score is determined by whether the platform oscillation amplitude falls within... Evaluate.

8. A method for constructing botnet simulation data based on knowledge graph enhancement and normalized time series generation, applied to the system described in claim 1, characterized in that, Includes the following steps: S1: Semantic parsing and knowledge enhancement: Initial semantic slots are obtained from simulation instructions, graph reasoning and parameter completion are performed according to the relational path rule base, and structured scene features are obtained through template matching, semantic consistency verification and confidence labeling. S2: Normalized parameter generation, which takes structured scene features as input from a Transformer-based sequence-to-sequence model and outputs parameter templates. And based on this, a normalized trend curve is constructed. ; S3: Scaling factor calculation, which calculates the scaling factor based on asset mapping data, CVSS, and historical success rate. ; S4: Shape rendering and scale-aware modulation, with For input pairs Monotonic modulation is performed to obtain , and according to Synthetic simulation data, among which For OU noise process; S5: Network Environment Constraints and Closed-Loop Optimization, Constructing Boundary Sets right The peak value, cumulative value and single-step increment are checked for out-of-bounds; when the evaluation result does not meet the threshold, a feedback signal is generated to update the parameter template and only update the low-rank adaptation layer parameters.

9. The method according to claim 8, characterized in that, The parameter template of S2 is constructed by using a combination of three fixed template segments: an exponential growth segment, a cosine perturbation plateau segment, and an exponential decay segment, and C¹ continuity constraints are applied between the segments.

10. The method according to claim 8, characterized in that, In step S3: , in The range of values ​​is limited to . .

11. The method according to claim 8, characterized in that: S4's scale-aware modulation uses a monotonically increasing function to... Modulation is performed to ensure the flow rate. When it is larger, the growth rate Larger, platform duration The longer, the lower the attenuation rate The larger.

12. The method according to claim 8, characterized in that: S5 network environment constraints include the maximum number of assets. Maximum number of IPs Maximum number of ports With bandwidth limit ,in: And set a fast response threshold: , when Attenuation rate Updated to: , And continue Each sampling step.