Digital twin data bidirectional synchronization security test and optimization method based on cloud test platform

By employing a cloud-based testing platform for the security testing and optimization of bidirectional synchronization of digital twin data, a twin database and an attack database were constructed. Network attack scenarios were simulated, and the digital twin model was optimized. This approach resolved security vulnerabilities in the digital twin data synchronization process and improved the system's security and reliability.

CN122027337APending Publication Date: 2026-05-12BEIJING OUTASITE TECHNOLOGY DEVELOPMENT CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
BEIJING OUTASITE TECHNOLOGY DEVELOPMENT CO LTD
Filing Date
2026-03-23
Publication Date
2026-05-12

AI Technical Summary

Technical Problem

Existing technologies have security vulnerabilities in the two-way synchronization of digital twin data, which can lead to the alteration of the physical entity's operating status and the leakage of sensitive data, or even cause malfunctions or loss of control. There is a lack of effective security testing and optimization methods.

Method used

A cloud-based testing platform-based bidirectional synchronous security testing method for digital twin data is adopted. By constructing a twin database and an attack database, network attack scenarios are simulated to predict the attack range and severity. Simulated annealing and genetic algorithms are used to optimize the digital twin model and generate protection strategies.

Benefits of technology

It improves the security and reliability of digital twin systems, enables accurate assessment and optimization of security risks, and builds an efficient security mechanism.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122027337A_ABST
    Figure CN122027337A_ABST
Patent Text Reader

Abstract

The invention discloses a digital twin data bidirectional synchronization security test and optimization method based on a cloud test platform, and relates to the technical field of security risk assessment. Comprising the following steps: acquiring a physical entity model and computing equipment information to generate a twin database, generating a digital twin topology model, and generating an attack database based on a preset automatic attack tool; simulating a network attack scene, and predicting an attack range and a hazard degree by using a digital twin topology model; the attack database attacks the physical entity model to obtain an actual attack range and a hazard degree, and compares the actual attack range and the hazard degree with prediction data to obtain an optimized digital twinborn model; and inputting an attack to be predicted into the optimized digital twin model to obtain a model deduction result, further judging a security attack risk, and generating and executing a targeted protection strategy according to the security attack risk. According to the invention, accurate assessment of the security risk of the digital twin system can be realized, and the security and reliability of the digital twin system are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of security risk assessment technology, and in particular to a method for security testing and optimization of bidirectional synchronization of digital twin data based on a cloud testing platform. Background Technology

[0002] In the wave of digital transformation, digital twin technology, as a key bridge connecting the physical world and the virtual digital world, has been widely applied in various fields such as intelligent manufacturing, smart cities, and cybersecurity. Digital twins, by constructing virtual models that are highly similar to physical entities, enable the monitoring, simulation, analysis, and optimization of the entire lifecycle of physical entities. Cloud testing platforms, with their powerful computing capabilities, elastic resource scalability, and distributed deployment characteristics, provide an ideal supporting environment for large-scale data processing, complex model computation, and security testing of digital twins.

[0003] Two-way synchronization of digital twin data is the core of achieving real-time interaction between physical entities and virtual models, and its security directly affects the stable operation and data security of the entire digital twin system. If a security vulnerability occurs during the two-way data synchronization process, it could lead to the alteration of the physical entity's operational status, the leakage of sensitive data, or even the malfunction or loss of control of the physical entity. Therefore, providing a security testing and optimization method for two-way synchronization of digital twin data based on a cloud testing platform to address the difficulties of existing technologies is a problem that urgently needs to be solved by those skilled in the art. Summary of the Invention

[0004] In view of this, the present invention provides a method for testing and optimizing the security of bidirectional synchronization of digital twin data based on a cloud testing platform, thereby enabling accurate assessment of the security risks of digital twin systems and improving the security and reliability of digital twin systems.

[0005] To achieve the above objectives, the present invention adopts the following technical solution: The security testing method for bidirectional synchronization of digital twin data based on a cloud testing platform includes the following steps: Obtain physical entity models and computing device information constructed by computing devices at different nodes, and preprocess the collected data to generate a twin database; A digital twin topology model is generated by modeling and mapping based on twin database data, and multiple attack methods are generated in batches based on preset automated attack tools to generate an attack database; By using an attack database to simulate network attack scenarios in a digital twin topology model, the corresponding changes in the digital twin topology model during the attack process are analyzed to predict the attack range and severity, and to obtain security test results.

[0006] Optionally, obtaining computing device information includes: obtaining the target network's basic configuration information and target network operating parameters corresponding to the computing device. The target network's basic configuration information includes the target network interface card (NIC), target network cable, target hub, and target switch. The target network operating parameters include the target IP address, target subnet mask, target default gateway, target DNS server, target network protocol, target network interface, and target subnet.

[0007] Optionally, generating a twin database includes: cleaning, normalizing, and performing correlation analysis on the collected raw data, extracting key features that can be used for modeling, obtaining processed data, and storing it in a structured twin database.

[0008] Optionally, generating a digital twin topology model includes: Based on the network configuration information, assess the network size of the target network and obtain the network size index. Based on the network size index, generate the modeling complexity and determine whether the modeling complexity is greater than the preset modeling complexity; If the modeling complexity is greater than the preset modeling complexity, obtain the dimensionality reduction instruction, reduce the dimensionality of the target network according to the dimensionality reduction instruction, and obtain the dimensionality-reduced network; Model and map the dimensionality-reduced network to generate a digital twin topology model.

[0009] Optionally, attacks on physical entity models include: Typical attack types are identified from the attack database, and attack characteristics, payload codes, and triggering conditions are extracted. Combined with the topology, node configuration, and data flow rules of the digital twin model, targeted attack scenarios are designed. Real-time tracking of attack commands to obtain the command transmission trajectory.

[0010] Optionally, the predicted attack range and severity can be generated by forming a mapping data set based on the triples of attack method, vulnerability cause, and vulnerability impact.

[0011] The method for optimizing the security of bidirectional synchronization of digital twin data based on a cloud testing platform, applied to any of the aforementioned methods for testing the security of bidirectional synchronization of digital twin data based on a cloud testing platform, includes the following steps: By attacking the physical entity model using the attack database, the actual attack range and degree of harm are obtained. The parameters of the digital twin topology model are then adjusted by comparing the data with the predicted data to obtain an optimized digital twin model. The attack to be predicted is input into the optimized digital twin model to obtain the model deduction results, thereby judging the security attack risk, and generating and executing targeted protection strategies based on the security attack risk.

[0012] Optionally, obtaining an optimized digital twin model includes: The actual attack range and severity are compared with the predicted data. If the attack exceeds the threshold, the simulated annealing algorithm is used to optimize all parameters of the physical entity model to obtain the first parameter. A genetic algorithm is used to optimize all parameters of the physical entity model to obtain the second parameter. Semantic standardization is performed on the first and second parameters corresponding to the physical entity model to obtain the standard data corresponding to the physical entity model. The standard data is weighted and accumulated to obtain optimized parameter data, and the digital twin model is optimized based on the optimized parameter data.

[0013] Optionally, assessing security attack risk includes: determining a risk value based on a pre-defined security risk assessment consensus, expressed as: , Where F is the simulated risk value, The weight values ​​for the simulation results of various attacks, Here, represents the risk value corresponding to the various attack simulation results, and n represents the total number of attack simulations.

[0014] As can be seen from the above technical solution, compared with the prior art, the present invention provides a method for security testing and optimization of bidirectional synchronization of digital twin data based on a cloud testing platform, which has the following beneficial effects: 1) This invention constructs a high-quality twin database and attack database, providing rich attack methods and feature information for simulating diverse attack scenarios, thereby improving the model construction efficiency and running performance; 2) This invention sets up a model optimization method that combines network attacks with virtual algorithms, effectively improving the simulation accuracy and prediction accuracy of the digital twin model, realizing accurate assessment of the security risks of the digital twin system, and providing a practical solution for the security guarantee of two-way synchronization of digital twin data. Attached Figure Description

[0015] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.

[0016] Figure 1 This is a flowchart of the security testing and optimization method for bidirectional synchronization of digital twin data based on a cloud testing platform disclosed in this invention. Detailed Implementation

[0017] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0018] Reference Figure 1 As shown, this invention discloses a method for testing the security of bidirectional synchronization of digital twin data based on a cloud testing platform, comprising the following steps: Obtain physical entity models and computing device information constructed by computing devices at different nodes, and preprocess the collected data to generate a twin database; A digital twin topology model is generated by modeling and mapping based on twin database data, and multiple attack methods are generated in batches based on preset automated attack tools to generate an attack database; By using an attack database to simulate network attack scenarios in a digital twin topology model, the corresponding changes in the digital twin topology model during the attack process are analyzed to predict the attack range and severity, and to obtain security test results.

[0019] Furthermore, obtaining computing device information includes: obtaining the target network's basic configuration information and target network operating parameters corresponding to the computing device. The target network's basic configuration information includes the target network interface card (NIC), target network cable, target hub, and target switch. The target NIC, as the interface connecting the computing device to the network, has parameters such as its model, bandwidth, and transmission protocol that directly affect the data transmission rate and stability. The target network cable's material, transmission distance, and shielding performance affect signal transmission quality. The target hub and switch are the core devices for network data forwarding; their port count, forwarding rate, and VLAN segmentation capabilities determine the network topology and data exchange efficiency. The target network operating parameters include the target IP address, target subnet mask, target default gateway, target DNS server, target network protocol, target network interface, and target subnet. The IP address is the unique identifier of a computing device within the network. The subnet mask is used to distinguish between network addresses and host addresses. The default gateway enables data communication between different subnets. The DNS server is responsible for converting domain names to IP addresses. These parameters collectively form the foundation of network communication. Target network protocols, such as TCP / IP, UDP, and HTTP, determine the rules and methods of data transmission. The target network interface is the channel through which computing devices interact with the network; its status and performance directly affect data transmission and reception. The division of the target subnet relates to network management efficiency and security isolation capabilities.

[0020] Furthermore, generating a twin database includes: cleaning, normalizing, and performing correlation analysis on the collected raw data, extracting key features that can be used for modeling, obtaining processed data, and storing it in a structured twin database.

[0021] Furthermore, generating a digital twin topology model includes: The network size is assessed based on the network configuration information to obtain the network size index. The calculation of the network size index takes into account multiple factors such as the number of nodes, device types, number of links, and bandwidth resources in the network. Based on the network size index, a modeling complexity is generated, and it is determined whether the modeling complexity is greater than the preset modeling complexity. The preset modeling complexity threshold can be set according to factors such as the computing power of the cloud testing platform, the modeling accuracy requirements, and the actual application scenario. If the modeling complexity is greater than the preset modeling complexity, obtain the dimensionality reduction instruction, perform dimensionality reduction on the target network according to the dimensionality reduction instruction, and obtain the dimensionality-reduced network. The dimensionality reduction methods include dimensionality reduction based on node aggregation, dimensionality reduction based on link simplification, and dimensionality reduction based on hierarchical modeling. Model and map the dimensionality-reduced network to generate a digital twin topology model.

[0022] Furthermore, the network size index is a weighted quantification result that comprehensively considers multiple key factors in the network, such as the number of nodes, device types, number of links, and bandwidth resources. Its expression is: S = ω1N + ω2T + ω3L + ω4B + ε Where N is the standardized value of the number of nodes, T is the standardized value of the complexity of the device type, L is the standardized value of the number of links, B is the comprehensive quantitative value of bandwidth resources, ε is the correction coefficient, and ω1, ω2, ω3 and ω4 are the corresponding weight coefficients, and satisfy ω1+ω2+ω3+ω4=1.

[0023] The weighting coefficients are determined based on the analytic hierarchy process (AHP) combined with the application scenario and security requirements of the target network.

[0024] Furthermore, modeling complexity is used to quantify the computing resources, time costs, and technical difficulties required to build a digital twin topology model. By establishing a mapping relationship, a fitting function between the network size index and modeling complexity is constructed. After generating the modeling complexity, it is compared with a preset modeling complexity threshold to determine whether the current modeling task is within the carrying capacity of the cloud testing platform.

[0025] The preset modeling complexity threshold is dynamically adjusted based on multiple factors, including the computing power of the cloud testing platform, modeling accuracy requirements, and actual application scenarios.

[0026] Specifically, the threshold for computing power of cloud testing platforms needs to be determined comprehensively by combining the platform's hardware resources such as the number of CPU cores, memory capacity, GPU computing power, and storage bandwidth, as well as software support capabilities such as virtualization technology and distributed computing architecture. The modeling accuracy requirements are determined based on the accuracy requirements of the digital twin topology model for different security application scenarios.

[0027] Furthermore, the core of the node aggregation-based dimensionality reduction method is to aggregate multiple nodes with similar functions, adjacent locations, or close relationships in the network into a single virtual node, thereby reducing the number of nodes and simplifying the network topology. Specifically, this involves determining node aggregation rules based on factors such as the functional attributes of the nodes, their network roles, and the frequency of data interaction, while ensuring that the aggregated virtual node retains the core characteristics of the original node cluster. Link simplification-based dimensionality reduction methods primarily target redundant, parallel, or low-priority links in the network, reducing the number of links and lowering link association complexity. Specifically, this involves performing corresponding operations on different links while ensuring the integrity and transmission characteristics of core service links. Redundant links refer to two or more links with identical connection nodes and interchangeable transmission functions; one core link is retained, and the remaining redundant links are deleted. Parallel links refer to links connecting the same pair of nodes but with different transmission media or bandwidths; these are integrated into a single virtual link by merging link bandwidths and simplifying transmission parameters. Low-priority links refer to links with minimal impact on core network data transmission and low bandwidth utilization; these are directly deleted or merged into adjacent links based on dimensionality reduction requirements. The dimensionality reduction method based on hierarchical modeling divides the target network into layers according to its hierarchical structure. Specifically, it selects key nodes and links in each layer to build a simplified model, retaining only the necessary connections between layers to achieve hierarchical simplification of the network topology. The layers can be simplified into a core layer, an aggregation layer, and an access layer. The core layer, as the core hub of the network, retains key equipment such as core routers and backbone switches, as well as core links. The aggregation layer aggregates some non-critical nodes, simplifying the number of nodes and link associations. The access layer is greatly simplified according to requirements, aggregating a large number of access terminals into virtual node clusters, retaining only the core connection links with the aggregation layer.

[0028] Furthermore, modeling mapping includes: feature extraction, digital modeling, and topological association construction; The element extraction stage requires comprehensive information collection from the physical entities in the dimensionality-reduced network, including node hardware parameters, software configurations, and security attributes; link transmission parameters and connection relationships; and interaction logic between devices. Collection methods include a combination of automated tool scanning, network configuration file parsing, and manual verification to ensure the completeness and accuracy of the element information. Digital modeling relies on professional digital twin modeling tools to transform extracted physical elements into digital models. Node devices are used to construct corresponding digital model instances, assigning them attribute parameters and identification information consistent with the physical devices, achieving a one-to-one mapping between physical and digital nodes. Links replicate the transmission characteristics and connection relationships of physical links through digital link models, establishing association channels between digital nodes. The network topology is constructed according to the actual layout of the reduced-dimensional network, creating a hierarchical and logically accurate digital topology diagram that intuitively presents the relationships between nodes and links. A time dimension attribute is added to the digital twin topology model, supporting dynamic updates and historical tracing of network status. Topology association construction simulates the operation mechanism and data interaction process of physical networks by establishing logical relationships between various elements within a digital twin topology model.

[0029] Furthermore, after the modeling and mapping are completed, the generated digital twin topology model undergoes accuracy verification and optimization. Accuracy verification involves comparing the physical characteristics and operational status of the digital model with those of the reduced-dimensional network. If deviations are found, the modeling parameters and mapping relationships need to be adjusted promptly to ensure the model's accuracy meets the requirements of security attack simulation. Optimization reduces redundant data in the model, improves its operational efficiency and response speed, and ensures smooth execution of subsequent large-scale attack simulations.

[0030] Furthermore, attacks on physical entity models include: Typical attack types are identified from the attack database, and attack characteristics, payload codes, and triggering conditions are extracted. Combined with the topology, node configuration, and data flow rules of the digital twin model, targeted attack scenarios are designed. Real-time tracking of attack commands to obtain the command transmission trajectory.

[0031] Specifically, when selecting automated attack tools, it is necessary to comprehensively consider the application scenario, security requirements, and attack types of the digital twin system. When generating attack methods in bulk, it is important to balance diversity and targeting, and to record the attack characteristics of each method in detail. Diversity needs to cover attacks at different levels, including network layer, application layer, data layer, and physical layer, including active and passive attacks, traditional and new attacks; in terms of targeting, it should combine the physical network characteristics corresponding to the digital twin system, and focus on generating attack methods that match the network vulnerability type, device type, and protocol type; attack feature information includes basic attack information, attack execution information, attack effect information, and vulnerability association information.

[0032] Furthermore, obtaining the instruction transmission trajectory also includes monitoring node response status, data flow anomalies, and the impact of model interactions. Specific indicators include: node response status includes: computing power utilization, memory utilization, port status, service start / stop, alarm triggering, and communication link connectivity. Data stream anomalies include: sudden changes in transmission rate, traces of data tampering, leakage paths, abnormal flow directions, encryption / decryption anomalies, and verification failure records; The impact of model interactions includes the effects of attacks on data interaction protocols, storage rules, and logical structures.

[0033] Furthermore, the attack scope and severity are predicted by forming a mapping data set based on the triples of attack method, vulnerability cause, and vulnerability impact. The mapping data set clarifies how the attack method exploits vulnerabilities with specific causes to produce corresponding vulnerability impacts, thereby determining the attack scope and severity.

[0034] Specifically, the attack method, as the core triggering element of the triple, refers to the specific means and implementation strategies adopted in the attack behavior, which directly determines the attack's propagation ability, penetration ability, and destructive ability. The cause of a vulnerability refers to the origin of a network vulnerability exploited by an attack method. It determines the vulnerability's exploitability, propagation path, and difficulty of patching, thereby affecting the spread of the attack and the escalation of its harm. Vulnerability impact refers to the specific harmful consequences that a vulnerability can cause to a network system after it is exploited, including its impact on devices, data, services, and network topology.

[0035] Furthermore, the construction of the mapping data set should follow the principles of data standardization, precise association, and comprehensive coverage to ensure the reliability and applicability of the mapping data set.

[0036] Specifically, the data standardization stage standardizes the descriptive information of each element in the triplet, adopts unified terminology, classification standards and quantitative indicators, and links with external authoritative databases to ensure the standardization and accuracy of element descriptions; In the precision mapping stage, through data analysis and manual verification, a precise mapping relationship between triple elements is established, invalid associations and erroneous mappings are eliminated, and a weighting mechanism for the mapping relationship is established, assigning different weights according to the credibility of the association. The comprehensive coverage phase ensures that the mapping data set can cover scenarios with different attack types, different vulnerability causes, and different impact levels. By continuously collecting new attack cases, vulnerability information, and attack simulation results, the scale of the mapping data set is constantly expanded, incorporating new attack methods, new vulnerability causes, and corresponding vulnerability impacts, ensuring the timeliness and comprehensiveness of the mapping data set.

[0037] Furthermore, the constructed mapping data set is used to predict the attack range and severity through various prediction models. Commonly used prediction models include rule-based reasoning models and machine learning models.

[0038] Rule-based reasoning prediction models extract association rules from mapping data sets to build a reasoning rule base for attack range and severity. When a new attack occurs, the corresponding triples in the rule base are matched to quickly predict the attack range and severity. Machine learning prediction models use the mapped data set as training samples to train the prediction model to learn the intrinsic relationship between triple elements and attack range and severity, thereby achieving accurate prediction. During the prediction process, the prediction results need to be dynamically corrected by combining the real-time status of the digital twin topology model, and a prediction result feedback mechanism needs to be established. By comparing the actual attack range and severity with the prediction results, the parameters of the mapped data set and the prediction model are continuously optimized to improve prediction accuracy.

[0039] The method for optimizing the security of bidirectional synchronization of digital twin data based on a cloud testing platform, applied to any of the aforementioned methods for testing the security of bidirectional synchronization of digital twin data based on a cloud testing platform, includes the following steps: By attacking the physical entity model using the attack database, the actual attack range and degree of harm are obtained. The parameters of the digital twin topology model are then adjusted by comparing the data with the predicted data to obtain an optimized digital twin model. The attack to be predicted is input into the optimized digital twin model to obtain the model deduction results, thereby judging the security attack risk, and generating and executing targeted protection strategies based on the security attack risk.

[0040] Furthermore, the optimized digital twin model includes: The actual attack range and severity are compared with the predicted data. If the attack exceeds the threshold, the simulated annealing algorithm is used to optimize all parameters of the physical entity model to obtain the first parameter. A genetic algorithm is used to optimize all parameters of the physical entity model to obtain the second parameter. Semantic standardization is performed on the first and second parameters corresponding to the physical entity model to obtain the standard data corresponding to the physical entity model. The standard data is weighted and accumulated to obtain optimized parameter data, and the digital twin model is optimized based on the optimized parameter data.

[0041] Specifically, the parameters of the digital twin model are used as optimization variables, and the deviation between the actual attack result and the prediction result is used as the objective function. By continuously adjusting the value of the parameters, the objective function value is minimized to obtain the first parameter. The parameters of the digital twin model are encoded as chromosomes. A certain number of chromosome populations are generated through initialization. Each chromosome in the population is evaluated according to the fitness function, and the chromosome with high fitness is selected as the parent. The crossover operation exchanges the genes of the parent chromosomes to generate new offspring chromosomes. Through multiple iterations, the optimal chromosome is gradually evolved, and the second parameter is obtained after decoding.

[0042] Furthermore, the first parameter is obtained through simulated annealing algorithm. The parameters of the digital twin model are used as optimization variables. The optimization variable node device parameters, link parameters, topology parameters, and attack response parameters are obtained. A multi-dimensional optimization variable space is constructed based on the optimization variables, and the value range of each variable is determined. The objective function is to minimize the deviation between the actual attack result and the predicted result, ensuring that the optimized parameters can make the model's prediction result highly consistent with the actual result. Specifically: Initialize parameters, setting the initial temperature, cooling coefficient, termination temperature, and number of iterations; A set of model parameters is randomly generated as an initial solution, and the corresponding objective function value is calculated. At the current temperature, the current solution is perturbed to generate computational parameters; Obtain the objective function value of the computational parameters and calculate the difference between it and the objective function of the initial solution. If the difference is less than 0, it indicates that the computational parameters are better, and the computational parameters are accepted as the current solution; otherwise, the Metropolis criterion is used to determine whether to accept the new solution and complete one iteration. Each iteration reduces the temperature based on the cooling coefficient, repeating the above perturbation, judgment, and acceptance process until the temperature drops to the termination temperature. The optimal solution obtained at this point is the first parameter.

[0043] Furthermore, semantic standardization of the first and second parameters includes: data format standardization, value range standardization, and semantic description standardization. Data format standardization requires unifying the formats of the first and second parameters; Standardizing the range of values ​​requires mapping the values ​​of different parameters to a unified standardized range. Methods include min-max standardization and z-score standardization. Semantic description standardization requires unifying the semantic representation of parameters, clarifying the definition, unit, and meaning of each parameter, and avoiding data misunderstanding due to semantic ambiguity.

[0044] Specifically, during the standardization process, the parameter data needs to be quality-checked, and outliers and missing values ​​need to be removed to ensure the integrity and accuracy of the standard data. Outliers can be detected using methods such as the 3σ criterion and box plots, and can be handled by replacing them with the mean, median, or deleting outliers. Missing values ​​are supplemented using interpolation methods or mean imputation methods. After processing, the standard data corresponding to the physical entity model can be obtained.

[0045] Furthermore, both the first and second parameters are vectors, with dimensions matching the total number of parameters in the digital twin model. Each element corresponds to a specific parameter in the model. The first parameter's value range needs to be determined based on the actual operating parameters of the physical entity and the requirements of digital twin modeling, and then normalized to the [0,1] interval. This is used to evaluate the rationality of the genetic algorithm's optimization results and to provide core data for subsequent weighted accumulation operations, thereby ensuring that the optimized parameters better reflect the real characteristics of the physical entity. Each vector element of the second parameter corresponds one-to-one with the first parameter. The final optimized parameters are obtained through weighted accumulation and fusion. The second parameter also supplements and verifies the first parameter. If the deviation between the corresponding elements is large, the accuracy and reliability of the final parameters can be ensured by adjusting the weight coefficients or iterating the optimization algorithm again, thus providing a reliable basis for updating the parameters of the digital twin model.

[0046] Furthermore, assessing security attack risks includes: determining a risk value based on a pre-defined security risk assessment consensus, expressed as: , Where F is the simulated risk value, The weight values ​​for the simulation results of various attacks, Let n be the total number of attack simulations, and let n be the risk value corresponding to the various attack simulation results. The simulation risk value F is calculated according to the above formula, and the simulation risk value is divided into different risk levels according to the pre-set security risk judgment consensus.

[0047] The above description of the disclosed embodiments enables those skilled in the art to make or use the invention. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the invention. Therefore, the invention is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A method for testing the security of bidirectional synchronization of digital twin data based on a cloud testing platform, characterized in that: Includes the following steps: Obtain physical entity models and computing device information constructed by computing devices at different nodes, and preprocess the collected data to generate a twin database; A digital twin topology model is generated by modeling and mapping based on twin database data, and multiple attack methods are generated in batches based on preset automated attack tools to generate an attack database; By using an attack database to simulate network attack scenarios in a digital twin topology model, the corresponding changes in the digital twin topology model during the attack process are analyzed to predict the attack range and severity, and to obtain security test results.

2. The digital twin data bidirectional synchronization security testing method based on a cloud testing platform according to claim 1, characterized in that, Obtaining computing device information includes: obtaining the target network's basic configuration information and target network operating parameters corresponding to the computing device. The target network's basic configuration information includes the target network interface card (NIC), target network cable, target hub, and target switch. The target network operating parameters include the target IP address, target subnet mask, target default gateway, target DNS server, target network protocol, target network interface, and target subnet.

3. The digital twin data bidirectional synchronization security testing method based on a cloud testing platform according to claim 1, characterized in that, Generating a twin database involves cleaning, normalizing, and performing correlation analysis on the collected raw data, extracting key features that can be used for modeling, obtaining the processed data, and storing it in a structured twin database.

4. The digital twin data bidirectional synchronization security testing method based on a cloud testing platform according to claim 2, characterized in that, The generation of digital twin topology models includes: Based on the network configuration information, assess the network size of the target network and obtain the network size index. Based on the network size index, generate the modeling complexity and determine whether the modeling complexity is greater than the preset modeling complexity; If the modeling complexity is greater than the preset modeling complexity, obtain the dimensionality reduction instruction, reduce the dimensionality of the target network according to the dimensionality reduction instruction, and obtain the dimensionality-reduced network; Model and map the dimensionality-reduced network to generate a digital twin topology model.

5. The digital twin data bidirectional synchronization security testing method based on a cloud testing platform according to claim 1, characterized in that, Attacks on physical entity models include: Typical attack types are identified from the attack database, and attack characteristics, payload codes, and triggering conditions are extracted. Combined with the topology, node configuration, and data flow rules of the digital twin model, targeted attack scenarios are designed. Real-time tracking of attack commands to obtain the command transmission trajectory.

6. The digital twin data bidirectional synchronization security testing method based on a cloud testing platform according to claim 5, characterized in that, The predicted attack range and severity are mapped into a data set based on a triplet of attack method, vulnerability cause, and vulnerability impact.

7. A method for optimizing the security of bidirectional synchronization of digital twin data based on a cloud testing platform, applied to the security testing method for bidirectional synchronization of digital twin data based on a cloud testing platform as described in any one of claims 1-6, characterized in that, Includes the following steps: By attacking the physical entity model using the attack database, the actual attack range and degree of harm are obtained. The parameters of the digital twin topology model are then adjusted by comparing the data with the predicted data to obtain an optimized digital twin model. The attack to be predicted is input into the optimized digital twin model to obtain the model deduction results, thereby judging the security attack risk, and generating and executing targeted protection strategies based on the security attack risk.

8. The method for optimizing the security of bidirectional synchronization of digital twin data based on a cloud testing platform according to claim 7, characterized in that, The optimized digital twin model includes: The actual attack range and severity are compared with the predicted data. If the attack exceeds the threshold, the simulated annealing algorithm is used to optimize all parameters of the physical entity model to obtain the first parameter. A genetic algorithm is used to optimize all parameters of the physical entity model to obtain the second parameter. Semantic standardization is performed on the first and second parameters corresponding to the physical entity model to obtain the standard data corresponding to the physical entity model. The standard data is weighted and accumulated to obtain optimized parameter data, and the digital twin model is optimized based on the optimized parameter data.

9. The method for optimizing the security of bidirectional synchronization of digital twin data based on a cloud testing platform according to claim 7, characterized in that, Assessing security attack risks includes: determining a risk value based on a pre-defined security risk assessment consensus, expressed as: , Where F is the simulated risk value, The weight values ​​for the simulation results of various attacks, Here, represents the risk value corresponding to the various attack simulation results, and n represents the total number of attack simulations.