Wireless interconnection security simulation method, system and device based on pseudo terminal and storage medium

By constructing a pseudo-terminal simulated attack chain, the security of wireless IoT devices is assessed, which solves the shortcomings of existing technologies in the security assessment of wireless IoT devices and realizes a comprehensive, real-world security assessment and quantitative risk analysis.

CN122054150APending Publication Date: 2026-05-15GUANGDONG ANJUBAO DIGITAL TECHNOLOGY CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
GUANGDONG ANJUBAO DIGITAL TECHNOLOGY CO LTD
Filing Date
2026-02-09
Publication Date
2026-05-15

AI Technical Summary

Technical Problem

Existing technologies lack a systematic and in-depth simulation of real attack chains, and an effective method for integrated security penetration and quantitative assessment of wireless IoT devices and their networks, making it difficult to fully understand and effectively manage their potential risks.

Method used

Construct fake terminals to capture communication data of the target test network, crack access authentication credentials, execute simulated attacks such as data replay and distributed denial-of-service attacks, assess the security of the target test network, and generate a security assessment report.

Benefits of technology

It comprehensively covers cryptographic security, transmission security, access control, and anti-attack capabilities, reveals systemic vulnerabilities in the co-design of devices and networks, and provides objective and quantitative security assessment data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122054150A_ABST
    Figure CN122054150A_ABST
Patent Text Reader

Abstract

The invention provides a pseudo-terminal-based wireless interconnection security simulation method, system and device and a storage medium, and the method comprises the steps: constructing a pseudo terminal and establishing a target test network, the target test network comprising a gateway and a tested Internet of Things device which is wirelessly accessed to the gateway; accessing the pseudo terminal to the target test network, capturing first communication data of the target test network through the pseudo terminal, and cracking an access authentication credential of the target test network based on the first communication data; executing at least one preset simulation actual combat attack on the target test network through the pseudo terminal by using the access authentication evidence, evaluating the security of the target test network under the corresponding attack vector, and finally outputting a security evaluation report; wherein the simulated actual combat attack comprises a data replay attack and a distributed denial of service attack. According to the method, systematic vulnerabilities existing in the collaborative design of the equipment and the network are revealed through various simulation actual combat attacks, so that the measurement of the safety level and the judgment of the risk level are more objective and accurate.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of public safety technology, and in particular to a wireless interconnection security simulation method, system, device and storage medium based on pseudo-terminals. Background Technology

[0002] The widespread application of wireless IoT devices has brought severe security challenges. Due to the openness of the electromagnetic spectrum, wireless communication signals are easily detected and intercepted. Attackers can easily obtain communication content and terminal identity information, and launch air-to-ground attacks such as signal interference and data tampering, directly leading to communication interruptions or network paralysis. More significantly, many low-power wireless interconnection devices on the market (such as smart home components) simplify or omit necessary security mechanisms in their design to pursue low cost and low power consumption, such as strong encryption, two-way authentication, and anti-replay protection. Current technology lacks an effective method to systematically and deeply simulate real attack chains and conduct integrated security penetration and quantitative assessment of such devices and the networks they constitute, making it difficult to fully understand and effectively manage their potential risks. Therefore, there is an urgent need to propose a simulation testing scheme that closely resembles real-world scenarios to scientifically assess their security baseline and reveal systemic vulnerabilities. Summary of the Invention

[0003] This invention provides a wireless interconnection security simulation method, system, device, and storage medium based on pseudo-terminals to solve the problems existing in related technologies. The technical solution is as follows: In a first aspect, embodiments of the present invention provide a wireless interconnection security simulation method based on a pseudo-terminal, comprising: Construct a pseudo-terminal and establish a target test network, which includes a gateway and IoT devices under test that access the gateway wirelessly; The fake terminal is connected to the target test network, and the first communication data of the target test network is captured through the fake terminal. Based on the first communication data, the access authentication credentials of the target test network are cracked. Using access authentication credentials, at least one preset simulated attack is executed on the target test network through a fake terminal to evaluate the security of the target test network under the corresponding attack vector, and finally output a security assessment report; among them, the simulated attacks include data replay attacks and distributed denial-of-service attacks.

[0004] In one implementation, it further includes: By using a pseudo-terminal to monitor and capture data on the target test network, second communication data is obtained. The second communication data is then parsed to determine whether the tested IoT device is transmitting sensitive information in plaintext. The results of the protocol parsing are then incorporated into the evaluation report.

[0005] In one implementation, capturing first communication data of the target test network via a fake terminal, and then cracking the access authentication credentials of the target test network based on the first communication data, includes: The test device sends authentication frames to the target test network through a pseudo-terminal to trigger the IoT device under test to re-authenticate with the gateway, captures data packets from multiple handshake processes, and obtains the first communication data. The first communication data was cracked offline using a password dictionary to obtain the access password of the target test network; The MAC address of the fake terminal is modified to the MAC address of the IoT device under test, and the access password is used to allow the fake terminal to pass authentication and join the target test network, thereby gaining access to the internal network.

[0006] In one implementation, a data replay attack includes: After the pseudo-terminal is authenticated and joins the target test network, it listens for and captures the control command data packets transmitted between the tested IoT device and the gateway. Control command packets are repeatedly sent to the target test network via a pseudo-terminal, and the state changes of the tested IoT device, the response of the target test network, and the attack success rate are recorded to evaluate its defense capability against replay attacks.

[0007] In one implementation, a distributed denial-of-service attack includes: By using fake terminals and network attack tools, a large number of concurrent connections or data streams are simulated to continuously send attack traffic to the target test network. During the attack, key performance indicators of the target test network are monitored and recorded in real time. Key performance indicators include, but are not limited to, network bandwidth utilization, response latency of gateways or IoT devices under test, and frequency and duration of service interruptions. Based on changes in key performance indicators, assess the service resilience and stability of the target test network under stress.

[0008] In one implementation, the method for generating a security assessment report includes: Obtain simulation test results data from multiple security dimensions obtained from executing each simulated real-world attack; The simulation test results are quantitatively compared with the corresponding preset safety benchmarks. Based on the results of the quantitative comparison, a comprehensive security assessment report containing specific quantitative conclusions is generated; Among these, multiple security dimensions include at least password security, transmission security, access security, and anti-attack capabilities.

[0009] In one implementation, the IoT device under test is a smart home device, including at least one of a smart camera, a smart lock, and a smart switch.

[0010] Secondly, embodiments of the present invention provide a wireless interconnection security simulation system based on a pseudo-terminal, which executes the wireless interconnection security simulation method based on a pseudo-terminal as described above; the system includes: The building module is used to build pseudo-terminals and establish a target test network, which includes a gateway and IoT devices under test that access the gateway wirelessly. The data capture module is used to connect the pseudo terminal to the target test network, capture the first communication data of the target test network through the pseudo terminal, and crack the access authentication credentials of the target test network based on the first communication data. The simulation attack module is used to perform at least one preset simulated attack on the target test network through a fake terminal using access authentication credentials, evaluate the security of the target test network under the corresponding attack vector, and finally output a security assessment report.

[0011] Thirdly, embodiments of the present invention provide an electronic device comprising a memory and a processor. The memory and the processor communicate with each other via an internal connection path. The memory stores instructions, and the processor executes the instructions stored in the memory. When the processor executes the instructions stored in the memory, it causes the processor to perform the method described in any of the above embodiments.

[0012] Fourthly, embodiments of the present invention provide a computer-readable storage medium that stores a computer program, wherein when the computer program is run on a computer, the methods in any of the embodiments described above are executed.

[0013] The advantages or beneficial effects of the above technical solutions include at least the following: This invention constructs a pseudo-terminal that captures wireless communication data from a target test network to crack its access authentication credentials. Using these credentials, the pseudo-terminal gains the same internal network identity and permissions as a real device, allowing it to impersonate and access the target test network to execute at least one pre-set simulated attack. This allows the security of the target test network to be evaluated under corresponding attack vectors. This method proactively simulates real threats from external reconnaissance to internal penetration, comprehensively covering multiple key security dimensions such as cryptographic security, transmission security, access control, and anti-attack capabilities, overcoming the limitations of traditional single-point testing. Through various simulated attacks, it reveals systemic vulnerabilities in the co-design of devices and networks, making the measurement of security levels and the determination of risk levels more objective and accurate.

[0014] The above overview is for illustrative purposes only and is not intended to be limiting in any way. In addition to the illustrative aspects, embodiments, and features described above, further aspects, embodiments, and features of the invention will become readily apparent from the accompanying drawings and the following detailed description. Attached Figure Description

[0015] In the accompanying drawings, unless otherwise specified, the same reference numerals throughout the various drawings denote the same or similar parts or elements. These drawings are not necessarily drawn to scale. It should be understood that these drawings depict only some embodiments disclosed in the invention and should not be construed as limiting the scope of the invention.

[0016] Figure 1 This is a flowchart illustrating the wireless interconnection security simulation method based on pseudo-terminals of the present invention. Figure 2 This is a schematic diagram of the pseudo-terminal structure of the present invention; Figure 3 This is a schematic diagram showing the connection between the pseudo-terminal of the present invention and the target test network; Figure 4 This is a structural block diagram of an electronic device according to an embodiment of the present invention. Detailed Implementation

[0017] In the following description, only certain exemplary embodiments are briefly described. As those skilled in the art will recognize, the described embodiments can be modified in various ways without departing from the spirit or scope of the invention. Therefore, the drawings and description are considered to be exemplary in nature and not restrictive.

[0018] Example 1 This embodiment provides a wireless interconnection security simulation method based on pseudo-terminals, applied to 2.4G (Wi-Fi) wireless communication technology in the field of public security technology prevention. By analyzing the root causes of security risks such as eavesdropping, decryption, replay, deception, hijacking, and even intrusion and control during Wi-Fi wireless interconnection data interaction, it studies the authentication of terminal node access application, encrypted transmission and key security of access sessions, and encryption of data transmission and storage. It adopts key technologies such as automated simulation testing based on pseudo-terminals to search for known and unknown vulnerabilities in relevant wireless protocols, providing a testing technique for the security of 2.4G (Wi-Fi) interconnection networks in the field of public security technology prevention.

[0019] like Figure 1 As shown, the wireless interconnection security simulation method based on pseudo-terminals specifically includes: Step S1: Construct a pseudo-terminal and establish a target test network, which includes a gateway and IoT devices under test accessing the gateway wirelessly.

[0020] The pseudo-terminal is the core device of the testing system, designed to integrate a dedicated testing device with capabilities for wireless eavesdropping, protocol analysis, password cracking, and attack simulation.

[0021] In this embodiment, as Figure 2 As shown, a development board or custom hardware based on the RK3578 chip can be selected as the core hardware platform for the pseudo terminal. This chip integrates an eight-core processor, which can efficiently handle parallel data capture, real-time encryption and decryption operations, and multi-task attack script execution, meeting the computing performance requirements of the testing process.

[0022] The pseudo-terminal is equipped with at least 8GB of RAM and 64GB of embedded storage (eMMC or SSD). The large memory ensures smooth operation when multiple tools are running concurrently; the large storage space is used to save the captured large data packet files, password dictionaries and test logs.

[0023] Meanwhile, the wireless network interface of the pseudo terminal uses a dual-band wireless network card that supports monitor mode and packet injection, such as the RTL8822CE. This network card needs to support the 2.4GHz band and ensure that its driver can fully enable the above-mentioned key functions under the selected operating system.

[0024] Build a pseudo-terminal and configure its testing environment. Install a Debian 10 or later version of Linux operating system on the hardware platform, install a Python 3.8 or later programming language runtime environment in the operating system, and configure relevant development libraries (such as scapy, socket, etc.) to support the writing and running of subsequent automated test scripts.

[0025] Install a complete suite of wireless network penetration testing and network attack tools within a pseudo-terminal using the operating system's package manager (such as apt) or by compiling from source. Core tools include: Aircrack-ng Suite: Includes airodump-ng (for wireless network scanning and packet capture), aireplay-ng (for generating interactive traffic such as deauthentication attacks), and aircrack-ng (for offline cracking of WPA / WPA2 handshake packets).

[0026] Network tools include hping3 (for custom packet generation and DoS stress testing), tcpdump (for advanced network traffic capture and filtering), and tcpreplay (for precise packet replay).

[0027] Perform basic functional verification on the installed tools to ensure that the wireless network card can be correctly switched to listening mode and that all tools can access hardware resources normally.

[0028] At the same time, establish and configure the target test network. For example... Figure 3 As shown, the target test network mainly consists of a gateway and at least one IoT device under test. The IoT devices under test are smart home devices, including one or more combinations of smart cameras, smart locks, and smart switches. The devices are interconnected via 2.4G Wi-Fi. Before testing, network configuration is performed, setting the gateway as an access point (AP) to allow the IoT devices under test, such as smart cameras, smart locks, and smart switches, to connect to this AP. Corresponding passwords are set to ensure the IoT devices under test can function normally after connecting to the target test network. Table 1 shows the specific configuration of the target test network.

[0029] Table 1 Target Test Network Configuration equipment IP password Encryption / Protocol Description Gateway (AP) 192.168.31.1 123456 WPA2-PSK Smart door lock 192.168.31.219 123456 AES-ECB Smart camera 192.168.31.118 camera123 UDP / 5000 smart switch 192.168.31.140 admin TCP / 8080 Step S2: Connect the fake terminal to the target test network, capture the first communication data of the target test network through the fake terminal, and crack the access authentication credentials of the target test network based on the first communication data.

[0030] Switch the wireless network card of the pseudo terminal to 2.4G listening mode, and use the Airodump-ng tool to listen to the target test network and capture the data packets in the network.

[0031] It should be noted that this operation enables the pseudo-terminal's wireless network card to receive all radio frequency signals passing through the channel (including data packets from the target network), but the network card itself does not associate or authenticate with the target AP, does not obtain an IP address, and is not a member of the network.

[0032] During the monitoring process, precise monitoring can be achieved through parameter configuration. The configuration command is as follows: airodump-ng -c 3 --bssid EC:41:18:E3:A1:66 -w capture wlan0mon; The configuration command uses the -c parameter to specify the wireless channel (e.g., channel 3) for the target test network. This operation locks the network card to that channel, greatly improving listening efficiency and reducing interference from irrelevant data. Using the --bssid parameter to specify the unique MAC address of the target access point (AP) (e.g., EC:41:18:E3:A1:66), this operation performs two-layer filtering to ensure that the captured data streams all originate from or are sent to the target network, which greatly improves the signal-to-noise ratio of the data and the efficiency of subsequent analysis. By using the -w parameter to specify the output file prefix (e.g., capture), the tool will continuously save the captured raw wireless packets as a series of files (e.g., capture-01.cap, capture-01.csv).

[0033] After executing the above command, the pseudo-terminal begins to continuously listen to and record all communication data related to the specified BSSID within the target channel. The pseudo-terminal can stop listening when it detects communication packets between the terminal device and the AP.

[0034] While keeping the monitoring process running, open a new, independent control terminal or process. In this new terminal or process, invoke the Aireplay-ng tool and execute the following commands to launch a deauthentication attack: Aireplay-ng -0 0 -a EC:41:18:E3:A1:66 wlan0mon; The -0 parameter is used to start the deauthentication attack mode, and the subsequent attack count parameter is set to 0 to indicate continuous sending; the -a parameter is used to specify the BSSID of the target AP.

[0035] This command continuously sends forged authentication frames to all clients associated with the target AP, or broadcasts them to all devices. In this embodiment, all IoT devices under test that receive the authentication frames are forcibly disconnected from the gateway and then automatically attempt to reconnect. This process proactively creates an opportunity for the IoT devices under test and the gateway to perform a complete WPA / WPA2 four-way handshake authentication.

[0036] The data packets of each handshake process are captured, and the captured handshake data is collectively referred to as the first communication data. Based on the first communication data, a weak password detection process is executed, that is, after capturing the first communication data, a password cracking tool is automatically invoked, a preset or custom password dictionary is loaded to attempt to crack the password, and the cracking process and results are recorded.

[0037] The password dictionary systematically covers common weak password patterns, typically including but not limited to: Pure numeric sequences: such as "123456", "000000", birthdays, phone numbers, etc.; Simple letter combinations: such as "password", "admin", "qwerty", etc.; Common mixed patterns: such as simple combinations of numbers and letters ("abc123"), combinations of adjacent keys on the keyboard, etc. Social engineering related terms: such as device brand, common names, default passwords, etc.

[0038] In this embodiment, the password cracking tool, such as Aircrack-ng, loads a prepared dictionary file and launches an offline cracking attack on the first communication data. The specific command is as follows: aircrack-ng -w password.diccapture.cap.

[0039] The password cracking process automatically extracts the necessary interactive information for the four-way handshake process from the first communication data, including the MAC addresses of the AP and the client, the nonce, and the handshake message integrity check code (MIC). Based on the WPA / WPA2 key derivation function (PBKDF2), each candidate password in the password dictionary is used in turn, combined with the parameters extracted from the handshake packet, to calculate and generate the corresponding pair master key (PMK) and message integrity check code (MIC). The calculated MIC is compared with the real MIC captured in the handshake packet. When the two are completely consistent, the current candidate password is determined to be the correct network access password, the cracking is successful, and the process terminates immediately.

[0040] Record the final result of the cracking attempt; if successful, record the obtained plaintext access password (e.g., "123456"). Regardless of success or failure, record key process data including total time, number of attempts, and the category of the successfully cracked password. Total time refers to the total time spent from initiating the cracking attempt to obtaining a result (success or dictionary failure); the number of attempts is the total number of candidate passwords tried before obtaining the result; the password category can be a pure number combination, a simple letter combination, a mixed combination, etc. Table 2 shows the statistics of weak password cracking efficiency.

[0041] Table 2 Comparison of brute-force cracking efficiency for different password complexities Cracking phase Time consumption Number of password attempts Success rate Pure number combination 3 minutes 20 seconds 100,000 100% Simple letter combinations - - miss Mixed cryptography - - miss Based on recorded data of the cracking process, the password strength is quantitatively assessed. This quantitative assessment includes cracking time analysis and password pattern vulnerability analysis. Among them, cracking time analysis compares the actual cracking time with industry-recognized security benchmarks (e.g., the recommended password cracking time should be greater than 72 hours). If the cracking time is too short (e.g., only 3 minutes and 20 seconds), it directly proves that the password strength is seriously insufficient.

[0042] Cryptographic pattern vulnerability analysis, by analyzing the dictionary category to which a successful password belongs, can clearly point out deficiencies in the password strategy, such as the failure to enforce the use of letters, special characters, or minimum length.

[0043] Finally, based on the above analysis, a clear quantitative security conclusion is drawn, such as: "The target network password is the common weak password '123456', which can be cracked within 3 minutes and 20 seconds, far below the security time threshold, indicating a serious flaw in the password strategy."

[0044] The core technological value of the aforementioned weak password detection process lies in utilizing the characteristics of the WPA / WPA2-PSK authentication mechanism for offline password verification. Since the information exchanged during the four-way handshake includes a MIC (Match Detection Token) used to verify the password, and the generation of the MIC depends on the password itself, attackers do not need to perform interactive guessing while online. This allows for unlimited and high-speed password attempts. Through systematic dictionary attacks and meticulous process data statistics, this method transforms the subjective concept of password security into objective, measurable, and comparable quantitative indicators, providing a direct and reliable basis for network security risk assessment and hardening.

[0045] This embodiment, while maintaining continuous network monitoring and data capture, executes a series of pre-set, time-sequential interactive operations on the IoT devices under test in the target test network. For example, using a mobile application or web client connected to the same network, it performs actions such as "accessing the real-time video stream of a smart camera," "remotely controlling the on / off state of a smart switch," and "sending a command to unlock a smart door lock." Each operation is executed at a pre-set interval (e.g., every 10 to 20 seconds) to ensure that network traffic can be clearly distinguished and captured. The entire interactive operation phase lasts for a set time period (e.g., a total of 1 minute). This controlled rhythm aims to simulate real-world usage scenarios while ensuring that the generated data packets are clearly distributed over time, facilitating subsequent correlation analysis.

[0046] At the end of the network monitoring, all communication data packets related to each tested IoT device are filtered out based on its IP address, MAC address, or known service port number. This is called the second communication data. The second communication data contains all communication data transmitted between each tested IoT device (such as a smart camera, door lock, or switch) and the access point (AP) in the target test network during the monitoring period.

[0047] The plaintext transmission analysis process is performed based on the second communication data. In this embodiment, a professional network protocol analysis tool (such as Wireshark) is used to open the second communication data and perform protocol parsing to determine whether the tested IoT device is transmitting sensitive information in plaintext. The protocol parsing results are then incorporated into the evaluation report. Specifically, the tool's display filter function is used to sequentially filter out application layer traffic using known plaintext or weak encryption protocols. For the filtered application layer traffic, the analysis tool's "Tracking Stream" function (such as "Follow TCP Stream" or "Follow UDP Stream") is further used to reassemble the scattered data packets into complete, readable session content or application layer data payload.

[0048] Manual or rule-based analysis is performed on the reconstructed session content or data packet payload to identify sensitive information transmitted in plaintext, such as device identity and metadata leakage detection, device status and control command leakage detection, and sensitive field statistics.

[0049] To clarify, device identity and metadata leakage detection involves searching for and recording metadata transmitted in plaintext, such as unique device identifiers (e.g., device ID, serial number), timestamps, geolocation information, and firmware version, within HTTP protocol streams or specific device data streams. Device status and control command leakage detection, on the other hand, analyzes specific data values ​​in the payload, including identifying plaintext encodings representing device status. For example, in the payload of a smart switch, consecutive ASCII codes 0x30 (character '0') represent "off," and 0x31 (character '1') represent "on." It also involves identifying critical control commands, such as directly searching for and extracting the user unlocking password field transmitted in plaintext in the communication data of a smart lock. Sensitive field statistics, however, involves statistically analyzing the specific field types that pose a risk of plaintext transmission and their frequency of occurrence.

[0050] The identified risks are quantified. For example, the proportion of smart lock unlocking commands containing plaintext passwords is statistically analyzed (e.g., 76%). Furthermore, the transmission security risks are assessed by considering factors such as the type of sensitive information (metadata, status information, or direct control password), the proportion and frequency of leakage (the high percentage of plaintext transmission and the frequency of data transmission), and the prevalence of the protocol (whether it's a problem with a single device or multiple devices using insecure protocols). This leads to a clear assessment conclusion, such as: "Smart camera metadata, smart switch status, and smart lock passwords all exhibit a high proportion of plaintext transmission, indicating a serious lack of communication encryption mechanisms and a high risk of sensitive information leakage and command tampering."

[0051] The core of this plaintext transmission analysis process lies in using network protocol analysis tools to deeply analyze application layer communication content. Its technical principle is based on the decapsulation and analysis of the TCP / IP protocol stack, stripping away the header information of underlying frames, packets, and segments to reach the application layer payload. By systematically filtering unencrypted protocols (such as HTTP) and analyzing traffic on specific ports, this method can effectively expose design flaws in equipment manufacturers' pursuit of simplicity at the expense of security when implementing communication functions. It transforms the concept of "insecure transmission" into concrete, verifiable plaintext data instances and quantifiable risk indicators, providing direct and urgent evidence for strengthening communication security (such as mandating the use of TLS / SSL encryption).

[0052] Step S3: Using access authentication credentials, execute at least one preset simulated attack on the target test network through a fake terminal, evaluate the security of the target test network under the corresponding attack vector, and finally output a security assessment report; wherein, the simulated attack includes data replay attack and distributed denial-of-service attack.

[0053] It should be noted that the access authentication credentials are the access passwords that have been cracked through the aforementioned weak password detection process.

[0054] This embodiment performs a pseudo-terminal access authentication process based on the access password. Specifically, it selects a target IoT device (such as a smart lock or smart camera) to be impersonated from the target test network and records its unique MAC address (e.g., 64:90:C1:90:C4:14). On the pseudo-terminal's operating system, the MAC address of its wireless network card is temporarily modified to match the MAC address of the target IoT device. This operation can be performed before initiating a connection using command-line tools (such as `ip link set` or `macchanger`).

[0055] By using the cracked access password, a fake terminal can be authenticated and join the target network under a fake or legitimate identity, thereby gaining access to the internal network for proactive communication. If the fake terminal successfully obtains an IP address and establishes a data link with the access point (AP), it is considered a "successful spoofing access," and key indicators such as whether the access was successful, the total access time (e.g., 10 seconds), and the number of attempts (e.g., first successful or third successful) are recorded.

[0056] Based on the access authentication process results, an in-depth analysis of the target network's security mechanisms is conducted, including static credential vulnerability verification and dynamic key and device fingerprint missing verification. Static credential vulnerability verification directly proves successful access; however, the target test network relies solely on the "static password + static MAC address" pair—factors easily obtained or forged by attackers—for authentication, indicating a fundamental flaw in the authentication mechanism. Dynamic key and device fingerprint missing verification compares the time taken for spoofed access with the historical access time of legitimate devices (e.g., 1.2 seconds vs. 1.1 seconds). If there is no significant difference, it strongly suggests that the AP is not enabled or the device does not support dynamically negotiating a unique key for each connection, nor does it verify secondary factors such as device hardware / software fingerprints, making it unable to identify physical device replacements.

[0057] Based on the combined results of multiple spoofing tests on different devices (e.g., 100% success rate), a quantitative assessment conclusion is generated, such as: "The target network access control is completely ineffective. Attackers can use password cracking and MAC address forgery to achieve 100% successful unauthorized access with efficiency approaching that of legitimate devices (time difference <0.1 seconds). The network boundary has been lost."

[0058] This pseudo-terminal access authentication process transforms the theoretical risk of "MAC address spoofing" into an observable and measurable security event by actively implementing identity impersonation; it provides an objective quantitative assessment basis for the "access control" dimension of network security through indicators such as access time and success rate.

[0059] After the pseudo-terminal authenticates and joins the target test network using the access password, it executes a data replay attack process, which involves listening to and capturing control command data packets transmitted between the tested IoT device and the gateway, repeatedly sending the control command data packets to the target test network through the pseudo-terminal, and recording the state changes of the tested IoT device, the response of the target test network, and the attack success rate to evaluate its defense capabilities against replay attacks.

[0060] The methods for listening to and capturing control command data packets include: On the pseudo-terminal, use a network sniffing tool (such as tcpdump) and configure filtering rules to capture only control command traffic related to the IoT device under test. For example, execute the command: tcpdump -i wlan0 -w switch.pcap 'tcp port 8080 and host192.168.31.140'; This command will capture all TCP packets sent to or from the target IP address 192.168.31.140 and the target port 8080 on the network interface wlan0, and save them to the file switch.pcap.

[0061] During the capture process, the IoT device under test is triggered to perform a specific control action (e.g., turn off a smart switch) to ensure that at least one complete control command data packet is captured; and after the capture stops, it is verified whether the captured file contains a valid control command data packet.

[0062] Use a packet replay tool (such as tcpreplay) to load the captured packet file (switch.pcap). Set key attack parameters, including the number of replays and the attack interval. Initiate a replay attack based on these parameters and execute the replay command, for example: tcpreplay -i wlan0 -tK --loop=50 switch.pcap; The replay command will continuously and rapidly retransmit the captured "close instruction" data packet 50 times over the network.

[0063] During the execution of the data replay attack process, the actual status changes of the tested IoT device are monitored synchronously, or the effectiveness of the attack is determined by listening to its response messages. The total number of replays, the number of successful triggers, the number of failures and their reasons (such as network transmission timeout, device protocol verification failure, device being in a non-responsive state, etc.), and the device response delay time are recorded. As shown in Table 3, Table 3 is a statistical table of the data replay attack effect.

[0064] Table 3. Statistics on the Effects of Data Replay Attacks Number of replays Number of successes Reasons for failure Response latency (ms) 1-10 10 none 780-850 11-30 19 2 timeouts 800-830 31-50 18 3 verification failures Average 820 Key security indicators are calculated based on the recorded information. These key security indicators include: Replay attack success rate: (Number of successful triggers / Total number of replays) * 100%; Average response latency: Calculates the average latency of all successful responses; Security vulnerability assessment: Security assessment is conducted based on quantitative results. For example, a high success rate (e.g., 94%) indicates that the tested IoT device or its communication protocol lacks an effective anti-replay mechanism, such as failure to verify instruction sequence numbers, timestamps, or the use of one-time tokens; a stable low-latency response indicates that replay attacks can be handled normally by the device, indistinguishable from legitimate instructions; failure cause analysis: if "verification failure" occurs, it indicates that the protocol may have unstable simple verification, but it is insufficient to constitute an effective defense; if "timeout" occurs, it may reflect network or device performance issues, rather than security mechanisms.

[0065] Furthermore, after the fake terminal successfully authenticates using the access password and joins the target test network, it also executes a distributed denial-of-service (DDoS) attack. The DDoS attack process specifically includes: The target entity for the attack is pre-selected from the IoT devices under test. Key attack parameters, such as attack type, concurrency scale, and duration, are preset according to the test target. Using a pseudo-terminal, a network attack tool (such as hping3) is used to write and execute an attack script according to the key parameters to simulate a large number of concurrent connections or data streams, continuously injecting high-intensity malicious UDP traffic into the target test network and continuously sending attack traffic to the target test network for the entire attack cycle (e.g., 30 minutes).

[0066] Throughout the attack execution process, multi-dimensional performance monitoring and recording of key performance indicators (KPIs) are performed simultaneously on the target test network and target entities. These KPIs include, but are not limited to, network bandwidth utilization, response latency of gateways or tested IoT devices, and the frequency and duration of service outages. Based on changes in these KPIs, the service resilience and stability of the target test network under stress are assessed. For example: Compare bandwidth utilization before and after the attack (e.g., from 15% to 92%) to determine if it exceeds the device's nominal carrying capacity (e.g., 80Mbps).

[0067] Compare the baseline value of critical business latency with the peak value of the attack (e.g., the smart lock authentication latency increases from 0.3ms to 4.2ms), calculate the degradation factor, and compare it with the industry acceptable threshold (e.g., 1ms).

[0068] Statistics include the total number of service interruptions, total duration, and average recovery time (e.g., if the video stream is interrupted 5 times, the average recovery time is 2 minutes).

[0069] Based on the above quantitative data, the DDoS resistance capability of the target test network is evaluated. If the attack causes rapid bandwidth saturation, a surge in critical service latency far exceeding the threshold, and multiple service interruptions, it is determined that the network and equipment have insufficient resource redundancy, lack resilience design, and have weak stress resistance. Based on changes in indicators, the main bottlenecks can be located (such as the CPU processing power of the AP, uplink bandwidth, and the number of service threads of the device itself). A clear evaluation report is ultimately generated, for example: "Under a simulated 10,000 concurrent UDP Flood attack, the target network's bandwidth utilization reached 92%, exceeding its maximum carrying capacity; core equipment service latency increased by more than 14 times, and video service was interrupted 5 times, indicating that it does not have the ability to withstand a medium-scale DDoS attack and requires capacity expansion and the deployment of anti-DDoS strategies."

[0070] Based on the above simulated attack scenarios, this embodiment summarizes the vulnerabilities in the simulation test results data across multiple security dimensions and generates a security assessment report. Table 4 shows the vulnerability summary table.

[0071] Table 4 Vulnerability Summary Vulnerability type Affecting equipment Risk level Verification scheme Weak password design Gateway / Door Lock critical Dictionary / mask brute force Plaintext transmission Camera High risk MITM data tampering MAC spoofing All equipment High risk MAC Cloning Access No replay protection smart switch High risk TCP session replay Key management defects gateway Medium risk KRACK attack test The specific methods for security assessment reports include: Acquire simulation test results data for multiple security dimensions obtained from executing each simulated real-world attack; among these, multiple security dimensions include at least password security, transmission security, access security, and anti-attack capability; The simulation test results are quantitatively compared with the corresponding preset safety benchmarks. Based on the results of the quantitative comparison, a comprehensive security assessment report containing specific quantitative conclusions is generated.

[0072] Specifically, in terms of password security, the quantitative comparison includes: The actual time required to crack the network access password; The actual cracking time is compared with the preset minimum suggested cracking time threshold; If the actual cracking time is lower than the minimum recommended cracking time threshold, a quantitative conclusion of insufficient cryptographic strategy strength will be generated in the security assessment report.

[0073] In terms of transmission security, the quantitative comparison includes: The proportion of data transmitted in plaintext or weak encryption in statistical control instructions or sensitive data; Compare the data ratio with a preset threshold for acceptable plaintext transmission ratio; If the data proportion exceeds the threshold, a quantitative conclusion will be generated in the evaluation report indicating that the transmission encryption is missing or insufficient.

[0074] In terms of access security, the quantitative comparison includes: Obtain the success rate of fake terminals attempting to access the network while masquerading as legitimate devices; The success rate is compared with a preset access authentication failure rate security threshold. If the success rate is higher than the access authentication failure rate security threshold, a quantitative conclusion that the access control mechanism has failed will be generated in the evaluation report.

[0075] In terms of attack resistance, the quantitative comparison includes: Obtain the command execution success rate under a data replay attack, and the service interruption frequency and recovery time under a denial-of-service attack; The command execution success rate is compared with the preset replay attack defense success rate threshold, and the service interruption frequency is compared with the preset maximum tolerable interruption number threshold. If the command execution success rate is higher than the defense success rate threshold, and / or the service interruption frequency exceeds the maximum tolerable interruption threshold, a quantitative conclusion of weak anti-attack capability will be generated in the assessment report.

[0076] A comprehensive security assessment report can be presented in a structured format, clearly listing the test data for each security dimension, the security benchmarks compared, and the final quantitative risk level.

[0077] The wireless interconnection security simulation test method based on pseudo-terminals proposed in this embodiment, through the systematic integration of multiple technical features, produces the following significant beneficial effects: 1. Achieved a comprehensive and realistic security assessment of wireless IoT systems: By designing a complete attack chain of "eavesdropping-cracking-spoofing access-internal attack", this method can actively simulate real threats from external reconnaissance to internal penetration, comprehensively covering multiple key security dimensions such as password security, transmission security, access control and anti-attack capabilities, and overcoming the limitations of traditional single-point testing.

[0078] 2. Deeply reveal systemic security risks and design flaws: The method can not only discover surface vulnerabilities such as weak passwords and plaintext transmission, but also verify the lack of device authentication mechanisms through successful spoofing access, and expose protocol or logic layer defects through high-success-rate replay attacks, thereby revealing systemic vulnerabilities in the collaborative design of devices and networks.

[0079] 3. Provide objective and quantitative security assessment basis: By comparing test results such as cracking time, plaintext transmission ratio, spoofing access success rate, replay attack success rate and service interruption indicators with preset security benchmarks, a security assessment report with clear data support can be generated, making the measurement of security level and the determination of risk level more objective and accurate.

[0080] Example 2 This embodiment provides a wireless interconnection security simulation system based on a pseudo-terminal, which executes the wireless interconnection security simulation method based on a pseudo-terminal as described in Embodiment 1. The system in this embodiment includes: The building module is used to build pseudo-terminals and establish a target test network, which includes a gateway and IoT devices under test that access the gateway wirelessly. The data capture module is used to connect the pseudo terminal to the target test network, capture the first communication data of the target test network through the pseudo terminal, and crack the access authentication credentials of the target test network based on the first communication data. The simulation attack module is used to perform at least one preset simulated attack on the target test network through a fake terminal using access authentication credentials, evaluate the security of the target test network under the corresponding attack vector, and finally output a security assessment report.

[0081] It should be noted that the functions of each module in the system of this embodiment can be found in the corresponding descriptions in the above methods, and will not be repeated here.

[0082] Example 3 This embodiment provides an electronic device. Figure 4 A structural block diagram of an electronic device according to an embodiment of the present invention is shown. Figure 4 As shown, the electronic device includes a memory 100 and a processor 200. The memory 100 stores a computer program that can run on the processor 200. When the processor 200 executes the computer program, it implements the wireless interconnection security simulation method based on a pseudo-terminal as described in the above embodiments. The number of memories 100 and processors 200 can be one or more.

[0083] The electronic device also includes: The communication interface 300 is used to communicate with external devices and perform data exchange and transmission.

[0084] If the memory 100, processor 200, and communication interface 300 are implemented independently, they can be interconnected via a bus to communicate with each other. This bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. This bus can be divided into address bus, data bus, control bus, etc.

[0085] Optionally, in a specific implementation, if the memory 100, processor 200, and communication interface 300 are integrated on a single chip, then the memory 100, processor 200, and communication interface 300 can communicate with each other through an internal interface.

[0086] This invention provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the method provided in this invention.

[0087] This invention also provides a chip, which includes a processor for calling and executing instructions stored in a memory, causing a communication device on which the chip is installed to perform the method provided in this invention.

[0088] This invention also provides a chip, including: an input interface, an output interface, a processor, and a memory. The input interface, output interface, processor, and memory are connected through an internal connection path. The processor is used to execute code in the memory. When the code is executed, the processor is used to execute the method provided in this invention.

[0089] It should be understood that the aforementioned processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. General-purpose processors can be microprocessors or any conventional processor. It is worth noting that the processor can be a processor supporting the Advanced Reduced Instruction Set Computing (RISC) machine (ARM) architecture.

[0090] Further, optionally, the aforementioned memory may include read-only memory and random access memory, and may also include non-volatile random access memory. The memory may be volatile or non-volatile, or may include both. Non-volatile memory may include read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. Volatile memory may include random access memory (RAM), which serves as an external cache. Many forms of RAM are available by way of example, but not limitation. Examples include static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous linked dynamic random access memory (SLDRAM), and direct rambus RAM (DR RAM).

[0091] In the above embodiments, implementation can be achieved, in whole or in part, by software, hardware, firmware, or any combination thereof. When implemented in software, it can be implemented, in whole or in part, as a computer program product. A computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the flow or function according to the present invention is generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another.

[0092] In the description of this specification, references to terms such as "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of the invention. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples. Moreover, without contradiction, those skilled in the art can combine and integrate the different embodiments or examples described in this specification, as well as the features of those different embodiments or examples.

[0093] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include at least one of that feature. In the description of this invention, "a plurality of" means two or more, unless otherwise explicitly specified.

[0094] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any person skilled in the art can easily conceive of various variations or substitutions within the technical scope disclosed in the present invention, and these should all be included within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.

Claims

1. A wireless interconnection security simulation method based on pseudo-terminals, characterized in that, include: A pseudo-terminal is constructed and a target test network is established, the target test network including a gateway and IoT devices under test that wirelessly access the gateway; The pseudo-terminal is connected to the target test network, and the first communication data of the target test network is captured through the pseudo-terminal. Based on the first communication data, the access authentication credentials of the target test network are cracked. Using the access authentication credentials, at least one preset simulated attack is executed on the target test network through the pseudo terminal to evaluate the security of the target test network under the corresponding attack vector, and finally output a security assessment report; wherein, the simulated attack includes data replay attack and distributed denial-of-service attack.

2. The wireless interconnection security simulation method based on pseudo-terminals according to claim 1, characterized in that, Also includes: The pseudo-terminal performs wireless network monitoring and data capture on the target test network to obtain second communication data. The second communication data is then parsed to determine whether the tested IoT device is transmitting sensitive information in plaintext. The parsing results are then incorporated into the evaluation report.

3. The wireless interconnection security simulation method based on pseudo-terminals according to claim 1, characterized in that, The step of capturing the first communication data of the target test network through the pseudo-terminal and cracking the access authentication credentials of the target test network based on the first communication data includes: The pseudo-terminal sends an authentication frame to the target test network to trigger the tested IoT device to re-associate with the gateway, captures data packets from multiple handshake processes, and obtains the first communication data. The first communication data is cracked offline using a password dictionary to obtain the access password of the target test network; The MAC address of the fake terminal is modified to the MAC address of the IoT device under test, and the access password is used to allow the fake terminal to pass authentication and join the target test network to obtain internal network access permissions.

4. The wireless interconnection security simulation method based on pseudo-terminals according to claim 1, characterized in that, The data replay attack includes: After the pseudo-terminal is authenticated and joins the target test network, it listens for and captures the control command data packets transmitted between the IoT device under test and the gateway. The control command data packets are repeatedly sent to the target test network through the pseudo terminal, and the status changes of the tested IoT device, the response of the target test network, and the attack success rate are recorded to evaluate its defense capability against replay attacks.

5. The wireless interconnection security simulation method based on pseudo-terminals according to claim 1, characterized in that, The distributed denial-of-service attack includes: Using the pseudo-terminal, network attack tools are used to simulate a large number of concurrent connections or data streams, and attack traffic is continuously sent to the target test network. During the attack, key performance indicators of the target test network are monitored and recorded in real time. These key performance indicators include, but are not limited to, network bandwidth utilization, response latency of the gateway or the IoT device under test, and frequency and duration of service interruptions. Based on the changes in the key performance indicators, assess the service resilience and stability of the target test network under stress.

6. The wireless interconnection security simulation method based on pseudo-terminals according to claim 1, characterized in that, The method for generating the security assessment report includes: Obtain simulation test results data from multiple security dimensions obtained from executing each simulated real-world attack; The simulation test results data are quantitatively compared with the corresponding preset safety benchmarks. Based on the results of the quantitative comparison, a comprehensive security assessment report containing specific quantitative conclusions is generated; Among them, the multiple security dimensions include at least password security, transmission security, access security, and anti-attack capabilities.

7. The wireless interconnection security simulation method based on pseudo-terminals according to claim 1, characterized in that, The IoT device under test is a smart home device, including at least one of a smart camera, a smart door lock, and a smart switch.

8. A wireless interconnection security simulation system based on pseudo-terminals, characterized in that, The system implements the wireless interconnection security simulation method based on pseudo-terminals as described in any one of claims 1 to 7; the system includes: A construction module is used to build a pseudo-terminal and establish a target test network, the target test network including a gateway and IoT devices under test that wirelessly access the gateway; The data capture module is used to connect the pseudo terminal to the target test network, capture the first communication data of the target test network through the pseudo terminal, and crack the access authentication credentials of the target test network based on the first communication data. The simulation attack module is used to use the access authentication credentials to perform at least one preset simulated combat attack on the target test network through the pseudo terminal, evaluate the security of the target test network under the corresponding attack vector, and finally output a security assessment report.

9. An electronic device, characterized in that, include: A processor and a memory, wherein the memory stores instructions that are loaded and executed by the processor to implement the wireless interconnection security simulation method based on a pseudo-terminal as described in any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, which, when executed by a processor, implements the wireless interconnection security simulation method based on any one of claims 1 to 7.