A self-calibration system for dynamic scenarios in a target range based on multi-agent collaboration
By using a multi-agent collaborative system to identify asset status and simulate attack processes in real time, the problem of high manual costs in creating test range scenarios has been solved. This enables efficient dynamic calibration and personalized scenario customization, improving test range operation efficiency and training effectiveness.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- BEIJING CHANGYANG TECH CO LTD
- Filing Date
- 2026-01-23
- Publication Date
- 2026-06-02
AI Technical Summary
The creation of existing target range scenarios relies on high manual costs, depends on preset rules and static matching logic, and lacks a dynamic closed-loop optimization mechanism, resulting in low scenario accuracy and an inability to adapt to the personalized needs of users with different skill levels.
A multi-agent collaborative system is adopted, including a scenario configuration module, an asset identification agent, a penetration agent, and a dynamic calibration module. It identifies asset status in real time through port scanning, service detection, and fingerprint matching algorithms, simulates attack processes to verify vulnerability exploitability, and achieves dynamic calibration and automated optimization.
Significantly reduces manual verification costs, improves the fit between scenarios and real attack and defense environments, shortens customization time, reduces maintenance costs, enhances training effectiveness, and adapts to the personalized needs of users with different skill levels.
Smart Images

Figure CN122137578A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network range technology, and in particular to a range dynamic scene self-calibration system based on multi-agent collaboration. Background Technology
[0002] As a core platform for attack and defense drills and skills training, the realism and accuracy of cybersecurity test ranges directly determine the effectiveness of drills and the quality of instruction. Currently, most test range scenarios are created using preset templates or manual configuration, providing users with a fixed training environment by pre-defining static parameters such as vulnerability types, asset topology, and attack paths.
[0003] Some advanced solutions introduce single-function AI agents to assist in scenario construction. For example, an asset identification agent can be used to scan and label target machine assets, or a penetration agent can be used to simulate attack behavior to verify scenario usability. Chinese patent "CN202311445349.1 A virtual-real hybrid networking device and its networking method based on port mapping" discloses a virtual-real hybrid target range networking technology based on port mapping. Its core is to achieve interconnection between virtual assets and real devices through port mapping, to build virtual-real hybrid target range scenarios in batches, and then manually verify the network connectivity and vulnerability exploitability of the scenarios.
[0004] While such solutions reduce the manual cost of scene creation to some extent, they still rely on preset rules and static matching logic, and do not form a dynamic closed-loop optimization mechanism.
[0005] Therefore, there is an urgent need to provide a target range dynamic scene self-calibration system based on multi-agent collaboration. Summary of the Invention
[0006] To address the issue that existing target range scene creation still requires manual labor, relies on preset rules and static matching logic, and lacks a dynamic closed-loop optimization mechanism, this invention provides a target range dynamic scene self-calibration system based on multi-agent collaboration.
[0007] On the one hand, a target range dynamic scene self-calibration system based on multi-agent collaboration is provided. The system includes: a scene configuration module, a multi-agent collaboration module, and a dynamic calibration module; the multi-agent collaboration module includes at least an asset identification agent and a penetration agent. The scenario configuration module is used to receive the training objectives, skill levels and scenario parameters input by the user, and generate an initial scenario configuration; the initial scenario configuration includes the asset types of virtual machines in the test range, the vulnerability candidate set of each virtual machine, the network topology and the test range security knowledge graph; The asset identification agent is used to identify the actual asset status of each virtual machine in the target range in real time based on the initial scenario configuration, using port scanning, service detection, and fingerprint matching algorithms, generating an asset topology map and a real asset list, and synchronizing them to the penetration agent and the dynamic calibration module. The penetration agent is used to load an attack script library that matches the vulnerability candidate set, and based on the real asset list provided by the asset identification agent, simulate a real attack process to exploit the vulnerability, record the verification results containing vulnerability exploitability, attack success rate and triggering conditions, and feed them back to the dynamic calibration module. The dynamic calibration module is used to compare and analyze the asset matching degree based on the initial scenario configuration and the real asset list, so as to automatically adjust the asset configuration and the vulnerability candidate set; and based on the verification results of the penetration agent for each virtual machine vulnerability and the skill level input by the user, dynamically adjust the vulnerability candidate set and the triggering conditions of each vulnerability, and synchronize the calibrated scenario configuration to the scenario configuration module.
[0008] On the other hand, a target range dynamic scene self-calibration method based on multi-agent collaboration, according to any system embodiment of the specification, is provided, including: The scenario configuration module generates an initial scenario configuration based on the user-input training objectives, skill levels, and scenario parameters. The initial scenario configuration includes the asset types of virtual machines in the test range, the vulnerability candidate set of each virtual machine, the network topology, and the test range security knowledge graph. Based on the initial scenario configuration, the asset identification agent uses port scanning, service detection, and fingerprint matching algorithms to identify the actual asset status of each virtual machine in the test range in real time, generate an asset topology map and a real asset list, and synchronize them to the penetration agent and dynamic calibration module. The penetration agent loads an attack script library that matches the vulnerability candidate set. Based on the real asset list provided by the asset identification agent, the agent simulates a real attack process to exploit the vulnerability. The agent records the verification results, which include vulnerability exploitability, attack success rate, and triggering conditions, and feeds them back to the dynamic calibration module. The dynamic calibration module uses the initial scenario configuration and the real asset list to compare and analyze the asset matching degree, so as to automatically adjust the asset configuration and the vulnerability candidate set; and based on the verification results of the penetration agent for each virtual machine vulnerability and the skill level input by the user, it dynamically adjusts the vulnerability candidate set and the triggering conditions of each vulnerability, and synchronizes the calibrated scenario configuration to the scenario configuration module.
[0009] The technical solution provided by this invention can bring at least the following beneficial effects: By using the asset identification agent to scan real assets and the penetration agent to verify vulnerabilities, the matching rate of scenario assets and the exploitability of vulnerabilities are both improved to over 90%, significantly reducing the cost of manual verification. The fit between the scenario and the real attack and defense environment is significantly improved, which can improve the accuracy and authenticity of the scenario. The entire process of scenario "creation-verification-calibration-update" is automated and dynamically optimized in a closed loop. The time for scenario customization is shortened from 24 hours in the traditional manual configuration to within 1 hour, the maintenance cost is reduced by more than 60%, and the operational efficiency of the test range is significantly improved. Attached Figure Description
[0010] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0011] Figure 1 This is a schematic diagram of a target range dynamic scene self-calibration system based on multi-agent collaboration provided in an embodiment of the present invention; Figure 2 This is a flowchart of a target range dynamic scene self-calibration method based on multi-agent collaboration provided by an embodiment of the present invention. Detailed Implementation
[0012] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are some embodiments of the present invention, but not all embodiments. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative effort are within the scope of protection of the present invention.
[0013] The following describes the specific implementation of the above concept.
[0014] Please refer to Figure 1 This invention provides a target range dynamic scene self-calibration system based on multi-agent collaboration. The system includes: a scene configuration module, a multi-agent collaboration module, and a dynamic calibration module; the multi-agent collaboration module includes at least an asset identification agent and a penetration agent. The scenario configuration module is used to receive the training objectives, skill levels and scenario parameters input by the user, and generate the initial scenario configuration. The initial scenario configuration includes the asset types of virtual machines in the test range, the vulnerability candidate set of each virtual machine, the network topology and the test range security knowledge graph. The asset identification agent is used to identify the actual asset status of each virtual machine in the test range in real time based on the initial scenario configuration, using port scanning, service detection, and fingerprint matching algorithms. It generates an asset topology map and a real asset list, which are then synchronized to the penetration agent and dynamic calibration module. The penetration agent is used to load an attack script library that matches the vulnerability candidate set. Based on the real asset list provided by the asset identification agent, it simulates the real attack process to exploit vulnerabilities and records the verification results containing vulnerability exploitability, attack success rate and triggering conditions, and feeds them back to the dynamic calibration module. The dynamic calibration module is used to compare and analyze the asset matching degree based on the initial scenario configuration and the real asset list, so as to automatically adjust the asset configuration and vulnerability candidate set; and based on the verification results of the penetration agent for each virtual machine vulnerability and the skill level input by the user, it dynamically adjusts the vulnerability candidate set and the triggering conditions of each vulnerability, and synchronizes the calibrated scenario configuration to the scenario configuration module.
[0015] By using the asset identification agent to scan real assets and the penetration agent to verify vulnerabilities, the matching rate of scenario assets and the exploitability of vulnerabilities are both improved to over 90%, significantly reducing the cost of manual verification. The fit between the scenario and the real attack and defense environment is significantly improved, which can improve the accuracy and authenticity of the scenario. The entire process of scenario "creation-verification-calibration-update" is automated and dynamically optimized in a closed loop. The time for scenario customization is shortened from 24 hours in the traditional manual configuration to within 1 hour, the maintenance cost is reduced by more than 60%, and the operational efficiency of the test range is significantly improved.
[0016] In this embodiment, the scenario configuration module is used to receive the training objectives input by the user, such as web penetration testing and vulnerability incident response, skill levels including beginner, intermediate and advanced, and scenario scale parameters, and generate an initial scenario configuration. The initial scenario configuration includes asset types, such as servers, terminals and network devices, and vulnerability candidate sets such as associated MITRE ATT&CK TTPs, network topology, target range security knowledge graph and other basic information.
[0017] The asset identification agent is used to identify the actual status of assets in the target virtual machine cluster (such as operating system version, running services, and open ports) in real time based on the initial scenario configuration, using port scanning, service detection, and fingerprint matching algorithms. It generates an asset topology map and a real asset list, which are then synchronized to the penetration agent and dynamic calibration module.
[0018] In some implementations, the multi-agent collaboration module further includes: an intelligent question-answering agent; The intelligent question-answering agent is used to generate teaching prompts that are appropriate for the user's skill level based on scenario configuration, the verification results of the penetration agent and the target range security knowledge graph; it also receives questions from users during the exercise process, generates answers based on graph retrieval and semantic analysis, and synchronizes high-frequency user questions and operation feedback to the dynamic calibration module.
[0019] In this embodiment, the intelligent question-answering agent dynamically generates personalized teaching prompts based on the scenario, increasing the user's success rate in practice by 40%, and achieving a satisfaction rate of over 85% for users of different skill levels, effectively balancing the practice and teaching functions of the shooting range.
[0020] In this embodiment, the teaching prompts adapted to the user's skill level are set as follows: beginner users are provided with explanations of vulnerability principles, while advanced users are provided with guidance on attack strategies.
[0021] In some implementations, the dynamic calibration module is also used to: receive frequently asked questions and operational feedback from the intelligent question-and-answer agent; if the frequency of user questions about a certain type of vulnerability exceeds a threshold, the intelligent question-and-answer agent is triggered to update the teaching prompts to increase the explanation of the vulnerability's principles and operational guidance; if the user fails to perform the attack steps multiple times, the scenario parameters are adjusted to reduce the difficulty of operation.
[0022] In some implementations, the dynamic calibration module calculates the scene parameter adjustment coefficients in the following manner: In the formula, Adjust the coefficients for scene parameters. For vulnerability exploitability, To increase the success rate of the attack, For the frequency of user inquiries, , and These are the weighting coefficients.
[0023] In this embodiment, α∈[0,1], the larger α is, the greater the range of scene difficulty adjustment. When the novice user α Difficulty was reduced at version 0.6, for advanced users (α). Increase the difficulty at 0.4.
[0024] In some implementations, the dynamic calibration module is also used for: Based on the initial scenario configuration and the real asset list, the asset matching degree is compared and analyzed. When the difference rate between the initial configuration and the real assets exceeds the preset threshold, the asset configuration and the vulnerability candidate set are automatically adjusted to ensure that the vulnerability and asset type are compatible. If the exploitability of a vulnerability is lower than a preset threshold in the verification results of the penetration agent for each virtual machine vulnerability, then a vulnerability with the same attack path and difficulty level is selected from the vulnerability database and replaced in the vulnerability candidate set; if the vulnerability attack success rate exceeds the threshold corresponding to the user's skill level, then the vulnerability triggering conditions are dynamically adjusted. If a user fails to complete the attack steps multiple times, the scene parameters are adjusted based on the user's skill level and the scene parameter adjustment coefficient to reduce the difficulty of operation. When the user's skill level is advanced, it is determined whether the scene parameter adjustment coefficient is less than a set threshold. If so, the scene parameters are adjusted based on the scene parameter adjustment coefficient to increase the difficulty of operation.
[0025] In this embodiment, if the attack success rate is higher than 80% (for novice users), the vulnerability triggering conditions are dynamically adjusted, such as by adding defense strategies and modifying vulnerability configuration parameters, to increase the difficulty of operation; if the attack success rate is lower than 30% (for advanced users), the vulnerability triggering conditions are dynamically adjusted, such as by reducing defense strategies and modifying vulnerability configuration parameters, to reduce the difficulty of operation.
[0026] If a user fails to complete a certain attack step multiple times, adjust the scenario parameters to reduce the difficulty of operation, such as simplifying environment configuration and providing key clues.
[0027] The calibrated scene parameters are synchronized to the scene configuration module to update the actual configuration of the test range virtual machine cluster, completing a closed-loop calibration. The calibration cycle can be set to real-time calibration (triggered instantly based on Agent feedback) or timed calibration (such as global calibration once per hour).
[0028] In some implementations, fingerprint matching algorithms combine rule-based fingerprint database matching with machine learning classification models to analyze detected service ports, protocol features, and response messages to identify asset types and system versions.
[0029] In existing technologies, the matching of asset topology and vulnerabilities, as well as the feasibility of attack paths, all require manual verification. This is not only inefficient but also prone to human error, leading to a disconnect between the scenario and real-world attack and defense scenarios, thus affecting the authenticity of the exercise. Moreover, relying solely on asset identification or a single penetration agent cannot achieve full coverage of the "scenario creation - validity verification - teaching adaptation" process. This results in scenarios that are either lacking in operability or unsuitable for users' skill levels, thus diminishing their educational value. Once a scenario is created, it remains fixed and cannot be adjusted in real time based on user feedback and vulnerability exploitation, making it difficult to adapt to the personalized needs of users with different skill levels and limiting the effectiveness of the exercise.
[0030] This embodiment can overcome the shortcomings of existing target range scenario creation, such as low accuracy, high labor costs, and incomplete functional coverage. Through multi-agent cross-role collaboration and dynamic closed-loop calibration, it can automate the entire process of scenario "creation-verification-adaptation-update", improve the realism, operability and teaching adaptability of the scenario, and reduce the customization and maintenance costs of target range scenarios.
[0031] In addition, define the data interaction format and collaborative communication rules between agents, including asset data format (asset ID-type-status-fingerprint information), vulnerability verification result format (vulnerability ID-exploitability-attack success rate-triggering conditions), and teaching prompt generation rules (skill level-vulnerability type-prompt content), to ensure the consistency and efficiency of data interaction. Define a unified data interaction format and communication rules between agents to ensure efficient linkage among multiple agents, reduce system integration and maintenance costs, and facilitate the subsequent expansion to add new agent types (such as defense agents and audit agents).
[0032] In some implementations, a federated learning update module is also included.
[0033] The federated learning update module uses a federated averaging algorithm, with each virtual machine acting as a local training endpoint to train a local decision model based on anonymized collaborative data. The federated global center aggregates the local decision model parameters corresponding to each virtual machine, generates a global model, and then distributes the parameters of the global model to each virtual machine to update the local decision model, so that the original sensitive data is not leaked during the model iteration process.
[0034] The target range scenario contains a large amount of sensitive vulnerability configurations and attack and defense data. If a centralized model training and update collaboration strategy is adopted, it is easy to cause data leakage risks. If the model is not updated, the collaboration logic cannot adapt to new vulnerabilities and attack methods, resulting in poor scenario timeliness.
[0035] The decision-making logic is built based on MITRE ATT&CK TTPs, which clarifies the task triggering conditions and data flow paths of each agent: "Asset identification agent completes asset scanning → triggers penetration agent to start vulnerability verification → penetration agent verification fails → triggers dynamic calibration module to adjust vulnerability configuration → asset identification and penetration verification restart after adjustment".
[0036] Therefore, by adopting federated learning to update the collaborative model, only model parameters are uploaded instead of raw sensitive data, resolving the conflict between target range data security and model timeliness, and adapting to target range privacy protection requirements. The federated learning mechanism ensures that there is no risk of leakage of sensitive data in the target range, shortens the model update cycle to once every 7 days, and can quickly adapt to new vulnerabilities and attack methods, improving scenario timeliness by 50%.
[0037] In some implementations, it also includes: a data storage module; The data storage module uses encrypted storage to store asset topology maps, vulnerability verification results, agent collaboration logs, user feedback data, and federated learning model parameters, in order to support data traceability and log auditing.
[0038] In some implementations, it also includes: a user interaction module; The user interaction module provides users with interfaces for scene configuration input, exercise progress viewing, question submission, and skill level adjustment, while simultaneously displaying the teaching prompts and responses from the intelligent question-and-answer agent.
[0039] Please refer to Figure 2 This invention provides a method for self-calibration of a target range dynamic scene based on multi-agent collaboration, according to any system embodiment of the specification. The method includes: 200. The scenario configuration module generates an initial scenario configuration based on the user-input training objectives, skill levels, and scenario parameters. The initial scenario configuration includes the asset types of virtual machines in the test range, the vulnerability candidate set of each virtual machine, the network topology, and the test range security knowledge graph. 202. Based on the initial scenario configuration, the asset identification agent uses port scanning, service detection, and fingerprint matching algorithms to identify the actual asset status of each virtual machine in the test range in real time, generate an asset topology map and a real asset list, and synchronize them to the penetration agent and dynamic calibration module. 204. The penetration agent loads an attack script library that matches the vulnerability candidate set. Based on the real asset list provided by the asset identification agent, the agent simulates the real attack process to exploit the vulnerability. The agent records the verification results containing vulnerability exploitability, attack success rate and triggering conditions, and feeds them back to the dynamic calibration module. 206. The dynamic calibration module compares and analyzes the asset matching degree based on the initial scenario configuration and the real asset list to automatically adjust the asset configuration and vulnerability candidate set. Based on the verification results of the penetration agent for each virtual machine vulnerability and the skill level input by the user, the vulnerability candidate set and the triggering conditions of each vulnerability are dynamically adjusted, and the calibrated scenario configuration is synchronized to the scenario configuration module.
[0040] Since the above method is based on the same concept as the system embodiment of the present invention, the specific details can be found in the description of the system embodiment of the present invention, and will not be repeated here.
[0041] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus.
[0042] Those skilled in the art will understand that all or part of the steps of the above method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When the program is executed, it performs the steps of the above method embodiments. The aforementioned storage medium includes various media that can store program code, such as ROM, RAM, magnetic disk, or optical disk.
[0043] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A target range dynamic scene self-calibration system based on multi-agent collaboration, characterized in that, include: The module includes a scene configuration module, a multi-agent collaboration module, and a dynamic calibration module. The multi-agent collaboration module includes at least an asset identification agent and a penetration agent; The scenario configuration module is used to receive the training objectives, skill levels and scenario parameters input by the user, and generate an initial scenario configuration; the initial scenario configuration includes the asset types of virtual machines in the test range, the vulnerability candidate set of each virtual machine, the network topology and the test range security knowledge graph; The asset identification agent is used to identify the actual asset status of each virtual machine in the target range in real time based on the initial scenario configuration, using port scanning, service detection, and fingerprint matching algorithms, generating an asset topology map and a real asset list, and synchronizing them to the penetration agent and the dynamic calibration module. The penetration agent is used to load an attack script library that matches the vulnerability candidate set, and based on the real asset list provided by the asset identification agent, simulate a real attack process to exploit the vulnerability, record the verification results containing vulnerability exploitability, attack success rate and triggering conditions, and feed them back to the dynamic calibration module. The dynamic calibration module is used to compare and analyze the asset matching degree based on the initial scenario configuration and the real asset list, so as to automatically adjust the asset configuration and the vulnerability candidate set. Based on the verification results of the penetration agent for each virtual machine vulnerability and the skill level input by the user, the vulnerability candidate set and the triggering conditions of each vulnerability are dynamically adjusted, and the calibrated scenario configuration is synchronized to the scenario configuration module.
2. The system as described in claim 1, characterized in that, The multi-Agent collaboration module also includes: an intelligent question-answering agent; The intelligent question-answering agent is used to generate teaching prompts adapted to the user's skill level based on the scenario configuration, the verification results of the penetration agent, and the target range security knowledge graph; and to receive questions from the user during the exercise process, generate answers based on graph retrieval and semantic analysis, and synchronize the user's high-frequency questions and operation feedback to the dynamic calibration module.
3. The system as described in claim 2, characterized in that, The dynamic calibration module is also used to: receive the user's frequently asked questions and the operation feedback from the intelligent question-and-answer agent; if the frequency of a user's questions about a certain type of vulnerability exceeds a threshold, the intelligent question-and-answer agent is triggered to update the teaching prompts to increase the explanation of the vulnerability's principle and operation guidance; if the user fails to perform the attack steps multiple times, the scenario parameters are adjusted to reduce the difficulty of operation.
4. The system as described in claim 3, characterized in that, The dynamic calibration module calculates the scene parameter adjustment coefficients in the following manner: In the formula, Adjust the coefficients for scene parameters. For vulnerability exploitability, To increase the success rate of the attack, For the frequency of user inquiries, , and These are the weighting coefficients.
5. The system as described in claim 4, characterized in that, The dynamic calibration module is also used for: Based on the initial scenario configuration and the real asset list, the asset matching degree is compared and analyzed. When the difference rate between the initial configuration and the real assets exceeds a preset threshold, the asset configuration is automatically adjusted to match the vulnerability candidate set to ensure that the vulnerability and asset type are compatible. If the exploitability of a vulnerability is lower than a preset threshold in the verification results of the penetration agent for each virtual machine vulnerability, then a vulnerability with the same attack path and difficulty level is selected from the vulnerability database and replaced in the vulnerability candidate set; if the vulnerability attack success rate exceeds the threshold corresponding to the user's skill level, then the triggering conditions of the vulnerability are dynamically adjusted. If the user fails to complete the attack steps multiple times, the scene parameters are adjusted based on the user's skill level and the scene parameter adjustment coefficient to reduce the difficulty of operation. When the user's skill level is advanced, it is determined whether the scene parameter adjustment coefficient is less than a set threshold. If so, the scene parameters are adjusted based on the scene parameter adjustment coefficient to increase the difficulty of operation.
6. The system as described in claim 1, characterized in that, The fingerprint matching algorithm integrates rule-based fingerprint database matching with machine learning classification models to analyze the detected service ports, protocol features, and response messages to identify asset types and system versions.
7. The system as described in claim 1, characterized in that, Also includes: Federated learning update module; The federated learning update module is used to train a local decision model based on the desensitized collaborative data by employing a federated averaging algorithm, with each virtual machine serving as a local training end. The Federation Global Center aggregates the local decision model parameters corresponding to each virtual machine, generates a global model, and then distributes the parameters of the global model to each virtual machine to update the local decision model, so as to prevent the leakage of original sensitive data during the model iteration process.
8. The system as described in claim 1, characterized in that, Also includes: Data storage module; The data storage module uses encrypted storage to store asset topology maps, vulnerability verification results, agent collaboration logs, user feedback data, and federated learning model parameters, respectively, to support data traceability and log auditing.
9. The system as described in claim 1, characterized in that, Also includes: User interaction module; The user interaction module provides users with interfaces for scene configuration input, exercise progress viewing, question submission, and skill level adjustment, while simultaneously displaying the teaching prompts and responses from the intelligent question-and-answer agent.
10. A method for self-calibration of a target range dynamic scene based on multi-agent collaboration, using the system described in any one of claims 1-9, characterized in that, include: The scenario configuration module generates an initial scenario configuration based on the user's input of training objectives, skill level, and scenario parameters. The initial scenario configuration includes the asset types of virtual machines in the test range, the vulnerability candidate set of each virtual machine, the network topology, and the test range security knowledge graph. Based on the initial scenario configuration, the asset identification agent uses port scanning, service detection, and fingerprint matching algorithms to identify the actual asset status of each virtual machine in the test range in real time, generate an asset topology map and a real asset list, and synchronize them to the penetration agent and dynamic calibration module. The penetration agent loads an attack script library that matches the vulnerability candidate set. Based on the real asset list provided by the asset identification agent, the agent simulates a real attack process to exploit the vulnerability. The agent records the verification results, which include vulnerability exploitability, attack success rate, and triggering conditions, and feeds them back to the dynamic calibration module. The dynamic calibration module uses the initial scenario configuration and the real asset list to compare and analyze the asset matching degree, so as to automatically adjust the asset configuration and the vulnerability candidate set. Based on the verification results of the penetration agent for each virtual machine vulnerability and the skill level input by the user, the vulnerability candidate set and the triggering conditions of each vulnerability are dynamically adjusted, and the calibrated scenario configuration is synchronized to the scenario configuration module.