A Federated Penetration Model Construction Method Based on Multi-Industry Network Range and Vulnerability Fusion

By constructing a federated penetration model system that integrates network test ranges and vulnerabilities across multiple industries, and utilizing federated learning technology to achieve collaborative training of multiple test range nodes, the system generates the optimal end-to-end penetration path. This solves the efficiency and accuracy problems of traditional penetration testing in complex network topology environments, and improves the level of automation and adaptability.

CN122137582APending Publication Date: 2026-06-02BEIJING INST OF COMP TECH & APPL

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
BEIJING INST OF COMP TECH & APPL
Filing Date
2026-01-30
Publication Date
2026-06-02

AI Technical Summary

Technical Problem

Traditional penetration testing methods are inefficient and have poor path accuracy in complex network topology environments. They cannot adapt to cross-industry data silos, have low automation levels, and cannot meet the needs of rapid attack and defense verification.

Method used

Design a federated penetration model system based on the fusion of multi-industry network ranges and vulnerabilities. The system includes a range node processing module, a federated learning coordination module, an attack chain generation engine module, a model evaluation and optimization module, and a task scheduling and control module. Through federated learning technology, it achieves privacy-preserving collaborative training of multiple range nodes and generates the optimal end-to-end penetration path.

Benefits of technology

Significantly improves the automation level and efficiency of penetration testing, generates highly accurate penetration paths, adapts to complex cross-industry network environments, and solves the efficiency and accuracy problems of traditional penetration testing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122137582A_ABST
    Figure CN122137582A_ABST
Patent Text Reader

Abstract

This invention relates to a method for constructing a federated penetration testing model based on the fusion of multi-industry network testbeds and vulnerabilities, belonging to the fields of network security testing and federated learning technology. This method utilizes federated learning technology to achieve privacy-preserving collaborative training of multiple testbed nodes, generating optimal end-to-end penetration paths. It effectively solves core problems of traditional penetration testing, such as low efficiency, poor accuracy of penetration paths, and cross-industry data silos, significantly improving the automation level and efficiency of penetration testing.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of network security testing and federated learning technology, specifically involving a method for constructing a federated penetration model based on the fusion of multi-industry network ranges and vulnerabilities. Background Technology

[0002] As network architecture continues to evolve towards distributed systems and secure zone partitioning, network topology complexity is increasing exponentially, and there are significant differences in network topology across industries. Traditional penetration testing methods are no longer adequate to meet the needs of dynamically changing and complex network environments.

[0003] Traditional penetration testing techniques face several prominent challenges in the application of network ranges. First, current penetration testing heavily relies on red team personnel manually planning attack paths and verifying vulnerability exploit chains step-by-step based on experience, resulting in low automation and failing to meet the practical needs of rapid attack and defense verification. Second, network range data across various industries contains a large amount of sensitive information that cannot be directly shared and used for model training. This leads to weak generalization ability of attack chain generation models trained in a single range, making them unable to adapt to the complex network topologies of cross-industry ranges. Furthermore, traditional penetration testing tools generate only single attack steps based on predefined vulnerability databases, lacking consideration for network topology correlations and failing to form a low-cost and complete optimal penetration chain. Summary of the Invention

[0004] (a) Technical problems to be solved The technical problem to be solved by this invention is: to meet the penetration testing needs of scenarios such as red team exercises, network attack and defense training and vulnerability verification in complex network topology environments, design a federated penetration model construction system and method based on the fusion of multi-industry network ranges and vulnerabilities, solve the core problems of low efficiency, poor accuracy of penetration paths and cross-industry data silos in traditional penetration testing, and improve the automation level and efficiency of penetration testing.

[0005] (II) Technical Solution To address the aforementioned technical issues, this invention provides a federated penetration model construction system based on the fusion of multi-industry network test ranges and vulnerabilities, including a test range node processing module, a federated learning coordination module, an attack chain generation engine module, a model evaluation and optimization module, and a task scheduling and control module. The target range node processing module is deployed in each network target range to perform local network target range asset data collection, vulnerability detection and local training of federated penetration model, provide raw parameter support for the federated penetration model, i.e. the global model, and perform attack chain testing tasks. The federated learning coordination module receives local model parameters from the target node processing modules in each network target range, aggregates them using a federated algorithm to generate a global model, and then distributes the global model to the target node processing modules in each network target range to achieve collaborative training across multiple network target ranges. Secondly, the global model is also distributed to the attack chain generation engine module to generate the optimal penetration chain. In addition, the global model is also distributed to the model evaluation and optimization module to optimize and adjust some parameters in the global model. The attack chain generation engine module is used to generate the optimal end-to-end penetration path based on the global model and real-time topology data, and output a complete penetration chain including the vulnerability exploitation order, tool selection, and operation steps; in addition, it sends the penetration chain to the target range node processing module where the topology data is located, and receives the execution results and operation log information from the target range node processing module. The model evaluation and optimization module is used to verify the effectiveness of the optimal penetration chain generated by the attack chain generation engine module, analyze the reasons for path failure, generate model optimization instructions, and continuously improve the accuracy of the federated global model and attack chain generation. The task scheduling and control module is used to uniformly schedule and control the entire penetration testing process, monitor the running status of other modules throughout the process, provide an interface for interaction with users, record task logs, and generate penetration testing reports.

[0006] (III) Beneficial Effects This invention provides a federated penetration testing model construction system and method based on the fusion of multi-industry network test ranges and vulnerabilities. The method uses federated learning technology to achieve privacy-preserving collaborative training of multiple test range nodes, generating end-to-end optimal penetration paths. It effectively solves the core problems of low efficiency, poor accuracy of penetration paths, and cross-industry data silos in traditional penetration testing, and significantly improves the automation level and efficiency of penetration testing. Attached Figure Description

[0007] Figure 1 A system architecture diagram provided for embodiments of the present invention; Figure 2 A flowchart illustrating the scheduling process for training tasks of the federated penetration model provided in this embodiment of the invention. Detailed Implementation

[0008] To make the objectives, contents, and advantages of the present invention clearer, the specific embodiments of the present invention will be described in further detail below with reference to the accompanying drawings and examples.

[0009] To meet the penetration testing needs of scenarios such as red team exercises, network attack and defense training, and vulnerability verification in complex network topology environments, this invention designs a federated penetration model construction system and method based on the fusion of multi-industry network ranges and vulnerabilities. This method uses federated learning technology to achieve privacy-preserving collaborative training of multiple range nodes, automatically generating end-to-end optimal penetration paths. It effectively solves core problems of traditional penetration testing, such as low efficiency, poor accuracy of penetration paths, and cross-industry data silos, significantly improving the automation level and efficiency of penetration testing.

[0010] To achieve the above objectives, this invention designs five core modules from five dimensions: data processing, model collaboration, path generation, iterative optimization, and system management. These modules are: a target range node processing module, a federated learning coordination module, an attack chain generation engine module, a model evaluation and optimization module, and a task scheduling and management module, forming a complete technical architecture covering the entire penetration testing process. The specific details are as follows: The target range node processing module is deployed in each network target range and is responsible for local network target range asset data collection, vulnerability detection, and local training of the federated penetration model. It provides raw parameter support for the federated penetration model (i.e., the global model) and performs attack chain testing. It mainly includes an asset collection unit, a vulnerability detection unit, a local model training unit, and a link testing unit. The global model can provide the optimal penetration chain (i.e., the optimal attack chain) from the starting node to the target node for any network target range's network topology.

[0011] The asset acquisition unit primarily employs two methods—active detection and passive monitoring—to collect network topology node data. This data includes information such as node IP, port, and application services, ultimately generating a structured topology node dataset. The basic data structure of each topology node is: {Range Number, Node Location, Inter-node Relationship, Node IP, Operating System Version, Node Type, [Port, Application Service Version, Communication Protocol, Network Bandwidth, Network Latency, Protection Rules]}. (1…n) A topology node refers to a node in the network topology corresponding to a network range, such as a host or a router.

[0012] The vulnerability detection unit constructs a "POC database matching-risk scoring" mechanism based on the topology node dataset. First, the vulnerability detection unit updates the vulnerability information in the POC database through online periodic acquisition or offline import, including CVEs, CNVDs, and industry-specific vulnerabilities specific to each network target location. Then, it filters potential vulnerabilities in the topology node dataset based on the "port-service version-vulnerability" mapping relationship. Finally, it uses the CVSS scoring standard to generate vulnerability attribute tags for the filtered potential vulnerabilities: <vulnerability, vulnerability type, exploitation difficulty (low / medium / high), impact scope (single node / regional / topology level), CVSS score (0-10 points)>.

[0013] The local model training unit uses a topology node dataset and vulnerability attribute labels as input to train a local attack chain model. The generation of local model parameters involves three steps: First, the input data is cleaned using methods such as deduplication, legitimization, normalization, and denoising. Second, an unstructured data structure based on a Transform neural network architecture is used to transform the unstructured data into feature vectors recognizable by the local model. Finally, after the feature vectors are passed to the local model, the local model parameters are dynamically optimized to effectively capture the correlation pattern of "topology link-vulnerability exploitation order." The weights of the local model parameters are continuously adjusted through a gradient descent mechanism to maximize the accuracy of correlation pattern recognition. The learned correlation patterns are then generated as local model parameters (excluding the original sensitive data from the target network range) for output.

[0014] The link testing unit receives the optimal penetration chain from the attack initiation node to the target node generated by the attack chain generation engine module, parses the penetration chain structure (basically defined as {vulnerability exploitation order, vulnerability information, selected tools, operation methods}), selects the appropriate tools based on the vulnerability information, and executes them according to the operation method sequence. After execution, it feeds back the actual penetration test results and operation logs from the local network range to the attack chain generation engine module.

[0015] The federated learning coordination module is primarily responsible for receiving local model parameters from the processing modules of each network target range node, aggregating them using a federated algorithm to generate a global model, and then distributing the global model to the local model training units of each network target range node processing module to achieve collaborative training across multiple network target ranges. Secondly, the global model is also distributed to the vulnerability priority ranking unit of the attack chain generation engine module to ensure the generation of the optimal penetration chain. Furthermore, the global model is distributed to the model optimization unit of the model evaluation and optimization module to optimize and adjust some parameters within the global model. It mainly includes a data security transmission unit, a parameter aggregation unit, a model distribution unit, and an optimization instruction receiving unit.

[0016] The data security transmission unit establishes a secure communication channel. Two-way authentication between the federated learning coordination module and other modules is achieved through PKI (Public Key Infrastructure). The federated learning coordination module issues exclusive certificates to the target node processing module, attack chain generation engine module, and model evaluation and optimization module; these certificates are carried during inter-module communication, and the transmitted data is signed and verified. Asymmetric encryption algorithms are used to encrypt the transmission of topology node datasets, vulnerability attribute tags, local model parameters, and global model parameters for each network target, ensuring data confidentiality. Data integrity is ensured by comparing the digest values ​​of the transmitted data. When transmission errors or data loss are detected, a retransmission mechanism is employed to ensure data validity.

[0017] The parameter aggregation unit uses FedAvg (Federated Average) to weight and aggregate the effective local model parameters submitted by the target node processing modules in each network target range. The weight calculation considers both the number of network target range nodes and the accuracy of the local model. By fusing model parameters from multiple network target ranges, overfitting caused by biases in the number of single nodes can be avoided. The formula for weighted aggregation of effective local model parameters, combining the two factors of "number of network target range nodes" and "accuracy of the local model," is as follows: ; ; in, Let be the number of nodes in the i-th network target range. Let α be the local model accuracy of the i-th network target range; α is the weighting coefficient of the proportion of the number of network target range nodes (reflecting the coverage of the network target range to different industry scenarios. More network target range nodes can cover richer network topology scenarios. Increasing the proportion can reduce model overfitting caused by a single industry scenario); β is the weighting coefficient of the proportion of the local model accuracy of the network target range (reflecting the accuracy of the training effect of a local model in a single network target range. Decreasing the proportion can reduce the dominance of the local model accuracy result of "small but precise" network target range (few network target range nodes but high local model accuracy) on the global model result). ; It is the weight of the node data volume in the i-th network target range. These are the local model accuracy weights for the i-th network target range. It is the total weight of the i-th network target range; These are the local model parameters of the i-th network target range. It refers to the global model parameters, which are the weighted aggregates of all local model parameters in the network test range according to the total weight. A test range node refers to a network test range representing an industry, such as a network test range for the transportation industry.

[0018] The model distribution unit employs an incremental update strategy to distribute the global model aggregated by the parameter aggregation unit. It only transmits parameters that differ from the previous global model to the local model training unit of the target range node processing module. Simultaneously, it synchronizes the global model to the vulnerability priority sorting unit of the attack chain generation engine module and the model optimization unit of the model evaluation and optimization module, ensuring that attack chain generation and target range penetration testing optimization are based on the latest model. The model distribution unit constructs a "model update status table" and a retransmission mechanism, recording the parameter reception status in real time for the local model training unit in each target range node processing module, the vulnerability priority sorting unit in the attack chain generation engine module, and the model optimization unit in the attack chain generation engine module, ensuring that all parameter data is received.

[0019] The optimization instruction receiving unit receives model optimization instructions generated by the model optimization unit in the model evaluation and optimization module in response to problems identified in the previous round of penetration training. It then updates and adjusts the differing parts of the global model parameters and calls the model distribution unit to distribute the model parameters to the local model training units in each target node processing module, the vulnerability priority ranking unit in the attack chain generation engine module, and the vulnerability priority ranking unit in the model evaluation and optimization module. By continuously integrating model optimization instructions from various network target ranges across multiple industries, the generalization capability of the global model parameters is gradually improved.

[0020] The attack chain generation engine module, based on a global model and real-time topology data, is primarily responsible for automatically generating the optimal end-to-end penetration path and outputting a complete penetration chain including the vulnerability exploitation order, tool selection, and operation steps. Furthermore, it sends the penetration chain to the target range node processing module where the topology data is located and receives the execution results and operation log information from the link testing unit in the target range node processing module. It mainly includes a topology parsing unit, a vulnerability priority ranking unit, and a path planning unit.

[0021] The topology parsing unit is responsible for converting the topology node dataset (generated by the asset acquisition unit of the target range node processing module) uploaded by the data security transmission unit in the federated learning coordination module into a structured directed graph. Vertices in the directed graph represent topology nodes, with attributes including node location, node IP, node type, and operating system version. Edges in the directed graph represent communication links between topology nodes, with attributes including port, application service version, communication protocol, and protection rules. Visualization tools are used to visualize the directed graph, providing an intuitive topology model for path planning.

[0022] The vulnerability priority ranking unit combines the global model (uploaded by the data security transmission unit of the federated learning coordination module) and vulnerability attribute tags (generated by the vulnerability detection unit of the target node processing module and uploaded by the data security transmission unit of the federated learning coordination module). It employs two scoring mechanisms: a base score and an adjustment score, to rank vulnerabilities by priority. The base score is based on the output of the global model obtained from multi-industry network target range learning and training, while the adjustment score is dynamically calculated based on the real-time network topology (e.g., if the vulnerable node is the only stepping stone to the target node, the score is increased; if the vulnerable node has deployed strong protection measures, the score is decreased). Finally, vulnerabilities are ranked from highest to lowest according to their total score to determine the priority attack target for each node.

[0023] The path planning unit calculates the vulnerability priority for each topology node based on the vulnerability priority ranking unit, and generates the optimal penetration chain from the attack initiation node to the target node based on the Deep Reinforcement Learning (DQN) algorithm. The DQN algorithm comprises two core components: a "cost function" and a "reward mechanism." The cost function includes three aspects: the number of attack steps (fewer steps mean lower cost), vulnerability exploitation difficulty (lower exploitation difficulty means lower cost), and protection tool cost (lower tool utilization means lower cost). Specific function values ​​are defined based on the difficulty of each aspect. The reward mechanism provides positive rewards based on the path progression effect (reward rules include: exploiting a high-priority vulnerability, moving closer to the target node by one level, avoiding invalid steps, etc.). Through N rounds of iterative training, the global model can output the optimal penetration chain.

[0024] The model evaluation and optimization module is primarily responsible for verifying the effectiveness of the optimal penetration chain generated by the path planning unit in the attack chain generation engine module, analyzing the reasons for path failures, generating model optimization instructions, and continuously improving the accuracy of the federated global model and attack chain generation. It mainly includes a penetration result verification unit, a model optimization unit, and an anomaly monitoring unit.

[0025] The penetration test result verification unit can generate a three-dimensional evaluation index by comparing the expected effect of the attack chain (the optimal penetration chain generated by the path planning unit in the attack chain generation engine module) with the actual penetration test results in the network range (the actual penetration test results processed by the link testing unit in the range node processing module corresponding to the optimal penetration chain). This index covers path success rate (number of successfully completed penetration steps / total number of penetration steps × 100%), vulnerability false positive rate (number of falsely identified exploitable vulnerabilities / total number of vulnerabilities used in the penetration test process × 100%), and step redundancy rate (number of redundant steps / total number of penetration steps × 100%). Based on the evaluation index, an evaluation report is generated to identify effective and invalid paths.

[0026] The model optimization unit receives the global model transmitted from the data security transmission unit in the federated learning coordination module; it locates problems through the evaluation report generated by the penetration result verification unit, and adjusts the weight coefficients of some features of the global model appropriately according to the cause of the problem. All the adjusted parameters are independently converted into model optimization instructions and sent to the optimization instruction receiving unit of the federated learning coordination module for the next round of global model training.

[0027] The anomaly monitoring unit is responsible for real-time identification of anomalies in the attack chain generation engine module's path planning unit during the optimal penetration chain generation process, such as loopback links, invalid penetration paths with unreachable nodes, and vulnerability exploitation deviations, to avoid resource consumption due to invalid computation. By monitoring the number of repetitions of each node during the penetration path detection process, if it exceeds 3 times, it is determined to be a loopback link, and the corresponding penetration task is immediately terminated and the loopback link sequence is recorded. The topology directed graph is traversed using a depth-first search (DFS) algorithm. If no valid path exists from the attack start node to the target node, the node is determined to be unreachable, and "target node unreachable" is immediately reported to the task management unit of the task scheduling and control module, automatically closing the task. The expected attack chain effect is compared with the actual penetration test results in the network range to calculate the path success rate. When the success rate is lower than the success rate deviation threshold or the actual test results completely deviate from the predicted results, "vulnerability exploitation deviation" is immediately reported to the task management unit of the task scheduling and control module, automatically closing the task. The administrator then analyzes the cause of failure, adjusts task parameters, and restarts the task.

[0028] The task scheduling and control module is responsible for the unified scheduling and control of the entire penetration testing process, providing an interface for user interaction, recording task logs, and generating penetration testing reports. It mainly includes a task control unit, a process scheduling unit, and a log management unit.

[0029] The task management unit allows users to manage test tasks through a visual interface, including functions such as task creation, pausing, and restarting. Penetration test tasks are created by setting information such as test objectives, network ranges participating in federated training, network topology ranges of each range, training time, number of training iterations, and evaluation metric weights. After data verification, the task is started for execution.

[0030] The process scheduling unit adopts an "event-driven" mechanism, triggering each module (target range node processing module, federated learning coordination module, attack chain generation engine module, and model evaluation and optimization module) in the order of "data acquisition -> federated training -> attack chain generation -> test execution -> model optimization," and monitoring the running status of each module throughout the process. Upon receiving the task start command from the task management unit, the process scheduling unit first triggers the target range node processing module to complete local network target range asset acquisition (asset acquisition unit), vulnerability attribute tag generation (vulnerability detection unit), and local model training generation (local model training unit). After the local models of each target range are generated, the data security transmission unit of the federated learning coordination module is triggered to receive the topology node datasets, vulnerability attribute tags, and local model parameters generated by each target range. After each target range node processing module completes data upload to the federated learning coordination module, the federated learning coordination module is triggered to complete parameter aggregation (parameter aggregation unit), model distribution (model distribution unit), and the transmission of each network target range topology node dataset and vulnerability attribute tags to the attack chain generation engine module (data security transmission unit). After model distribution and data transmission are completed, the attack chain generation engine module is triggered to complete network... The system performs network topology analysis (topology analysis unit), vulnerability priority ranking (vulnerability priority ranking unit), and generates the optimal penetration chain based on real-time topology data for each network range (path planning unit). This triggers the anomaly monitoring unit of the model evaluation and optimization module to monitor for anomalies in the attack chain generation engine module. The attack chain generation engine module then distributes the penetration chain to the corresponding network range for penetration testing and collects the test results (link testing unit of the range node processing module). After the penetration test is completed, the model evaluation and optimization module compares the expected effect of the attack chain with the actual test results of the network range and generates an evaluation report (penetration result verification unit). If optimization is required, the model optimization unit of the model evaluation and optimization module generates model optimization instructions based on the reported issues. The process scheduling unit obtains the optimization instructions and distributes them to the optimization instruction receiving module of the federated learning coordination module to start the next round of global model training.

[0031] The log management unit stores log data of various types, including data flow logs, model training logs, and penetration test logs. Logs can be retrieved based on keywords such as task identifier, time range, vulnerability type, and type of training network target. It can dynamically generate test reports (including network topology diagrams, penetration chain steps, evaluation indicators, optimization suggestions, etc.), making it convenient for users to trace and review data during penetration test training.

[0032] Furthermore, the federated penetration model architecture formed by the above five modules can be continuously optimized through two approaches. Firstly, by expanding the number of network test ranges from different industries participating in federated training, cross-industry penetration testing scenario characteristics are further aggregated. Secondly, by increasing the number of topology nodes in a single network test range, replacing different versions of security protection application software and different brands and models of firewalls, routers, and other physical devices within the same network test range, the richness of topology data, vulnerability coverage, correlation complexity, and adaptability to real-world environments in a single scenario are further improved. After multiple rounds of closed-loop training involving "local training -> parameter aggregation -> penetration testing -> model optimization iteration," a global model covering massive amounts of industry network test range penetration testing data can be obtained. This global model integrates a large number of topology features and vulnerability exploitation patterns from different industries, enhancing its adaptability to complex cross-industry network environments, the depth of its vulnerability correlation logic learning, and the accuracy of penetration path generation, exhibiting extremely strong generalization capabilities.

[0033] Furthermore, the final generated global model can be completely independent of the original training target range. When facing a brand new network target range, there is no need to go through the federated training process again. The global model can be directly input into the attack chain generation engine module, which can quickly provide an efficient and accurate end-to-end penetration chain for the new network target range, significantly shortening the penetration testing cycle in new scenarios.

[0034] See Figure 1This invention provides a technical architecture diagram of a federated penetration testing model. To simulate network testbeds across various industries, this invention leverages existing network testbed virtualization platforms, hardware and software infrastructure, and combines various industry network topologies to construct multi-location professional network testbeds with industry-specific and business characteristics. Further, testbed node processing modules are deployed in each industry network testbed to extract industry-specific feature coefficients through privacy-preserving training, resulting in local models exhibiting a correlation between "professional topology links and vulnerability exploitation order." Next, a federated learning coordination module combines the "number of network testbed nodes" and "local model accuracy" to merge the local models output from each industry network testbed into a global model covering numerous different industry topology features and vulnerability exploitation patterns. The attack chain generation engine module further utilizes a structured directed graph obtained through topology awareness and the global model trained through federated learning algorithms to obtain a complete and optimal penetration chain integrating "vulnerability exploitation order - vulnerability information - tool selection - operation method." By establishing a dynamic optimization closed-loop mechanism of "training-testing-feedback-optimization," the model evaluation and optimization module verifies the effectiveness of the model based on real-time penetration results and promptly optimizes and adjusts the weight coefficients of the federated model for path failures (such as loopback links, vulnerability exploitation deviations, and other anomalies), continuously improving the accuracy of penetration link generation and the generalization ability of the global model. The task scheduling and management module uniformly manages the entire process of penetration testing tasks, coordinating and scheduling the collaborative work of various modules. Figure 1 The functions and technical implementations of each unit contained in each module have been described in detail in the invention content and will not be repeated here.

[0035] To more clearly describe the role of each module in the federal penetration model generation system architecture, the model generation process, and the task scheduling and processing flow, combined with Figure 2 (Flowchart of training task scheduling for the federated penetration model) Describes the core process.

[0036] 1. Task creation and startup phase. Details (steps 1-1) are as follows: 1-1 The task scheduling and control module creates / adjusts multiple federated training penetration test tasks through a visual interface, and sends tasks and start instructions to each network range participating in the federated training (hereinafter referred to as "each network range").

[0037] 2. Data Acquisition and Local Training Phase. In this phase, each network testbed independently performs data acquisition and local training tasks. Specific details (steps 2-1 to 2-3) are as follows: 2-1. After receiving the task and start command, the target range node processing module calls the asset acquisition unit to collect asset data within the network topology range specified in the task and generate a topology node dataset. 2-2, Based on the topology node dataset, call the vulnerability detection unit to generate vulnerability attribute tags; 2-3. Based on the topology node dataset and vulnerability attribute labels, the local model training unit outputs local model parameters that have the correlation pattern of "professional topology link - vulnerability exploitation order".

[0038] 3. Federated Model Aggregation and Distribution Phase. Specific details (steps 3-1 to 3-3) are as follows: 3-1. Each network test range will securely send the topology node dataset, vulnerability attribute labels, and local model parameters generated by the test range node processing module to the federated learning coordination module through the data security transmission unit. 3-2 After all the data has been transmitted by the processing modules of each target range node, the parameter aggregation unit is called based on the local model parameters of each network target range to generate global model parameters covering a large number of different industry topology features and vulnerability exploitation rules. 3-3, The model distribution unit is invoked to distribute incremental model parameters to the target node processing modules of each network target range, and global model parameters are sent to the attack chain generation engine module and the model evaluation and optimization module simultaneously; the topology node dataset and vulnerability attribute tags of each network target range are sent to the attack chain generation engine module through the data security transmission unit.

[0039] 4. Attack Chain Generation and Testing Phase. In this phase, the attack chain generation module will perform attack chain generation and testing tasks in parallel for each network target range. Specific details (steps 4-1 to 4-6) are as follows: 4-1. Generate a structured directed graph by calling the topology parsing unit based on the topology node dataset; 4-2, Based on the vulnerability attribute tags and the global model, the vulnerability priority sorting unit is invoked to generate a priority sequence of attack targets for each node; 4-3. Based on the structured directed graph and the priority sequence of attack targets for each node, the path planning unit is invoked to generate the optimal penetration chain from the attack start node to the target node. 4-4 During the penetration chain generation process, the anomaly monitoring unit in the model evaluation and optimization module monitors anomalies such as loopback links and vulnerability exploitation deviations in real time, takes corresponding actions based on the actual situation, and generates a problem list. 4-4' The model evaluation and optimization module forwards the problem list generated in step 4-4 to the task scheduling and control module for the user to choose from; 4-5. After the optimal penetration chain is successfully generated, the attack chain generation engine module sends it to the link testing unit of the corresponding network range. The link testing unit executes the penetration test according to the steps of the optimal penetration chain and feeds back the execution results and running logs to the attack chain generation engine module. 4-6. Feed back the actual test results of each network range based on the optimal penetration chain to the model evaluation and optimization module.

[0040] 5. Model Iteration and Optimization Phase. In this phase, the model evaluation and optimization module will conduct parallel penetration test result verification tasks based on the measured results of each network target range. After completion, it will then generate unified model optimization instructions based on the problems encountered in each network target range. Specific details (steps 5-1 to 5-2) are as follows: 5-1 The penetration result verification unit generates three-dimensional evaluation indicators by comparing the expected effect of the attack chain with the actual penetration test results of each network target range, and outputs an evaluation report in combination with the problem analysis; The model optimization unit analyzes the problems based on the evaluation reports of each network target range, adjusts the weight coefficients of some features of the global model appropriately according to the causes of the problems, generates model optimization instructions and sends them to the federated learning coordination module for the next round of global model training.

[0041] 5-2, The penetration result verification unit sends the evaluation report to the task scheduling and control module, allowing users to fully understand the quality and problem list generated by the penetration chain.

[0042] In the above embodiments, a multi-location deployment approach was used to construct network testbeds for different industry sectors. This approach can directly use commercially available testbeds as the basis for this invention. However, multi-location deployment presents complex issues such as network interoperability and security. To reduce resource consumption and avoid the complexities of network interoperability between testbeds, scenario target data isolation technology can be used within the same network testbed to build targeted scenario targets for different industry sectors. The implementation principle of the federated penetration model technology architecture of this invention is also applicable in a single network testbed. It only requires integrating the testbed node processing module into the scenario targets of each industry sector, ensuring data security isolation between scenario targets, and interacting with the federated learning coordination module through an independent data security transmission channel.

[0043] The above description is only a preferred embodiment of the present invention. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the technical principles of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.

Claims

1. A federated penetration testing model construction system based on the fusion of multi-industry network test ranges and vulnerabilities, characterized in that, It includes a target range node processing module, a federated learning coordination module, an attack chain generation engine module, a model evaluation and optimization module, and a task scheduling and control module; The target range node processing module is deployed in each network target range to perform local network target range asset data collection, vulnerability detection and local training of federated penetration model, provide raw parameter support for the federated penetration model, i.e. the global model, and perform attack chain testing tasks. The federated learning coordination module receives local model parameters from the target node processing modules in each network target range, aggregates them using a federated algorithm to generate a global model, and then distributes the global model to the target node processing modules in each network target range to achieve collaborative training across multiple network target ranges. Secondly, the global model is also distributed to the attack chain generation engine module to generate the optimal penetration chain. In addition, the global model is also distributed to the model evaluation and optimization module to optimize and adjust some parameters in the global model. The attack chain generation engine module is used to generate the optimal end-to-end penetration path based on the global model and real-time topology data, and output a complete penetration chain including the vulnerability exploitation order, tool selection, and operation steps. In addition, the penetration chain is sent to the target node processing module where the topology data is located, and the execution results and operation log information of the target node processing module are received. The model evaluation and optimization module is used to verify the effectiveness of the optimal penetration chain generated by the attack chain generation engine module, analyze the reasons for path failure, generate model optimization instructions, and continuously improve the accuracy of the federated global model and attack chain generation. The task scheduling and control module is used to uniformly schedule and control the entire penetration testing process, monitor the running status of other modules throughout the process, provide an interface for interaction with users, record task logs, and generate penetration testing reports.

2. The system as described in claim 1, characterized in that, The target range node processing module includes an asset acquisition unit, a vulnerability detection unit, a local model training unit, and a link testing unit; The asset acquisition unit is used to collect network topology node data using both active detection and passive monitoring methods. It obtains information including node IP, port, and application service, ultimately generating a structured topology node dataset. The basic data structure of each topology node is: {Range ID, Node Location, Inter-node Relationship, Node IP, Operating System Version, Node Type, [Port, Application Service Version, Communication Protocol, Network Bandwidth, Network Latency, Protection Rules]} (1…n) }, where n is the number of topological nodes; The vulnerability detection unit is used to: first, update the vulnerability information of the POC library by acquiring it online at regular intervals or importing it offline; then, filter out potential vulnerabilities in the topology node dataset based on the POC library through the mapping relationship of "port-service version-vulnerability"; and finally, generate vulnerability attribute tags for the filtered potential vulnerabilities using the CVSS scoring standard. The local model training unit is used to train attack chains to generate local model parameters using topology node datasets and vulnerability attribute labels as input data. The local model parameter generation process includes three steps: First, the input data is cleaned; then, unstructured data is transformed into feature vectors recognizable by the local model using a Transform neural network architecture; finally, after the feature vectors are passed to the local model, the local model parameters are dynamically optimized to capture the correlation pattern of "topology link-vulnerability exploitation order". The weights of the local model parameters are continuously adjusted through a gradient descent mechanism, and the learned correlation pattern is generated as local model parameters for output. The link testing unit receives the optimal penetration chain from the attack start topology node to the target topology node generated by the attack chain generation engine module, parses the penetration chain structure, selects the appropriate tools according to the vulnerability information and executes them in the order of operation methods. After execution, it feeds back the actual penetration test results and operation log information of the local network range to the attack chain generation engine module.

3. The system as described in claim 2, characterized in that, The federated learning coordination module includes a data security transmission unit, a parameter aggregation unit, a model distribution unit, and an optimization instruction receiving unit; The data security transmission unit is used to build a secure communication channel and realize two-way identity authentication between the federated learning coordination module and other modules through PKI; it uses an asymmetric encryption algorithm to encrypt the transmission of topology node datasets, vulnerability attribute tags, local model parameters, and global model parameters of each network range; it ensures data integrity by comparing the digest values ​​of the transmitted data; and it uses a retransmission mechanism to ensure data validity when transmission errors or data loss are detected. The parameter aggregation unit is used to perform weighted aggregation of the effective local model parameters submitted by the target node processing modules in each network target range using the FedAvg algorithm. The weight calculation is achieved by combining two factors: "number of target range nodes" and "local model accuracy". The formula for weighted aggregation of effective local model parameters is as follows: ; ; in, Let be the number of nodes in the i-th target range. Let be the local model accuracy of the i-th network target range; α be the weighting coefficient of the proportion of the number of target range nodes; and β be the weighting coefficient of the proportion of the local model accuracy of the network target range. ; It is the weight of the data volume of the i-th target range node. These are the local model accuracy weights for the i-th network target range. It is the total weight of the i-th network target range; These are the local model parameters of the i-th network target range. These are the global model parameters obtained by weighting and aggregating all local model parameters of the network test range according to the total weight. The model distribution unit is used to distribute the global model aggregated by the parameter aggregation unit using an "incremental update" strategy. It only transmits the difference parameters between the global model and the previous round to the local model training unit of the target node processing module. At the same time, it synchronizes the global model to the vulnerability priority sorting unit of the attack chain generation engine module and the model optimization unit of the model evaluation and optimization module. The model distribution unit constructs a "model update status table" and a retransmission mechanism to record the parameter receiving status of the local model training unit in each target node processing module, the vulnerability priority sorting unit in the attack chain generation engine module, and the model optimization unit in the attack chain generation engine module in real time. The optimization instruction receiving unit is used to receive model optimization instructions generated by the model optimization unit in the model evaluation and optimization module in response to problems in the previous round of penetration training, update and adjust the differences in the global model parameters, and then call the model distribution unit to complete the distribution of model parameters to the local model training unit in each target node processing module, the vulnerability priority sorting unit in the attack chain generation engine module, and the vulnerability priority sorting unit in the model evaluation and optimization module.

4. The system as described in claim 3, characterized in that, The attack chain generation engine module includes a topology parsing unit, a vulnerability priority sorting unit, and a path planning unit. The topology parsing unit is used to convert the topology node dataset uploaded by the data security transmission unit in the federated learning coordination module into a structured directed graph. Vertices in the directed graph represent topology nodes, and vertex attributes include node location, node IP, node type, and operating system version. Edges in the directed graph represent communication links between topology nodes, and edge attributes include a set of port, application service version, communication protocol, and protection rule information. The directed graph is visualized through visualization tools to provide a topology model for path planning. The vulnerability priority ranking unit is used to combine the global model and vulnerability attribute tags, and uses two scoring mechanisms, base score and adjustment score, to rank the vulnerability priority. The base score of the vulnerability is based on the output of the global model obtained by learning and training in a multi-industry network target range, while the adjustment score is dynamically calculated and generated according to the real-time network topology environment. Finally, the vulnerabilities are ranked from high to low according to the total score to determine the priority attack target of each topology node. The path planning unit is used to calculate the vulnerability priority of each topology node based on the vulnerability priority ranking unit, and generate the optimal penetration chain from the attack starting topology node to the target topology node based on the deep reinforcement learning DQN algorithm; the function value of the cost function in the deep reinforcement learning DQN algorithm is determined according to the number of attack steps, vulnerability exploitation difficulty and protection tool cost; the reward mechanism in the deep reinforcement learning DQN algorithm provides positive rewards based on the path advancement effect.

5. The system as described in claim 4, characterized in that, The model evaluation and optimization module includes a penetration result verification unit, a model optimization unit, and an anomaly monitoring unit. The penetration result verification unit is used to compare the optimal penetration chain generated by the path planning unit in the attack chain generation engine module with the actual penetration test results of the local network target generated by the link testing unit in the target node processing module, and generate a three-dimensional evaluation index covering path success rate, vulnerability false positive rate, and step redundancy rate. Based on the evaluation index, an evaluation report is generated to identify effective and invalid paths. The model optimization unit is used to receive the global model transmitted from the data security transmission unit in the federated learning coordination module; locate the problem through the evaluation report generated by the penetration result verification unit; adjust the weight coefficients of some features of the global model in a targeted manner according to the cause of the problem; and send the adjusted weight coefficients as independent model optimization instructions to the optimization instruction receiving unit of the federated learning coordination module for the next round of global model training. The anomaly monitoring unit is used to identify loop links, invalid penetration paths with unreachable nodes, and vulnerability exploitation deviations in the optimal penetration chain generation process of the attack chain generation engine module's path planning unit in real time. By monitoring the number of repetitions of each node during the penetration path detection process, if it exceeds 3 times, it is determined to be a loop link, the corresponding penetration task is terminated, and the loop link sequence is recorded. The topology directed graph is traversed using a depth-first traversal algorithm. If there is no valid path from the attack start node to the target node, it is determined that the node is unreachable, and "target node unreachable" is fed back to the task management unit of the task scheduling and management module, and the task is closed. It is determined whether the success rate of the covered path is lower than the success rate deviation threshold. When the success rate of the covered path is lower than the success rate deviation threshold, "vulnerability exploitation deviation" is fed back to the task management unit of the task scheduling and management module, the task is closed, the task parameters are adjusted, and the task is restarted.

6. The system as described in claim 5, characterized in that, The task scheduling and control module includes a task control unit, a process scheduling unit, and a log management unit; The task management unit allows users to manage test tasks through a visual interface. By setting test objectives, network ranges to participate in federated training, network topology ranges of each range, training time, number of training iterations, and evaluation indicator weights, penetration test tasks can be created and the task execution process can be started after data verification. The process scheduling unit employs an "event-driven" mechanism, triggering four modules—the range node processing module, the federated learning coordination module, the attack chain generation engine module, and the model evaluation and optimization module—in the sequence of "data acquisition -> federated training -> attack chain generation -> test execution -> model optimization," and monitoring the operational status of all four modules throughout the process. Upon receiving the task start command from the task management unit, the process scheduling unit first triggers the range node processing module to complete local network range asset acquisition, vulnerability attribute tag generation, and local model training generation. After the local models for each range are generated, the data security transmission unit of the federated learning coordination module receives the topology node datasets, vulnerability attribute tags, and local model parameters generated by each range. After each range node processing module uploads data to the federated learning coordination module, the federated learning coordination module completes parameter aggregation, model distribution, and transmits the topology node datasets and vulnerability attribute tags for each network range to the attack chain generation engine module. After model distribution and data transmission are completed, the attack chain generation engine module completes network topology parsing, vulnerability priority ranking, and generates the optimal penetration chain for the real-time topology data of each network range. The anomaly monitoring unit of the model evaluation and optimization module then performs anomaly monitoring on the attack chain generation engine module. The attack chain generation engine module is triggered to send the penetration chain to the corresponding network target range to perform penetration testing and collect test results. After the penetration test is completed, the model evaluation and optimization module is triggered to compare the optimal penetration chain with the actual penetration test results of the local network target range and generate an evaluation report. If optimization is required, the model optimization unit of the model evaluation and optimization module generates a model optimization instruction based on the problem identified in the evaluation report. The process scheduling unit obtains the model optimization instruction and sends it to the optimization instruction receiving module of the federated learning coordination module to start the next round of global model training. The log management unit stores data such as data flow logs, model training logs, and penetration test logs. It can retrieve logs based on keywords such as task identifier, time range, vulnerability type, and type of network target range, and dynamically generate penetration test reports.

7. The system as described in claim 5, characterized in that, The success rate of the covered path = (number of successfully completed penetration steps / total number of penetration steps) × 100%.

8. The system as described in claim 5, characterized in that, The vulnerability false positive rate = (number of vulnerabilities falsely identified as exploitable / total number of vulnerabilities used in the penetration test) × 100%.

9. The system as described in claim 5, characterized in that, The redundancy rate of the steps is calculated as follows: (Number of redundant steps / Total number of penetration steps) × 100%.

10. A method for constructing a federated penetration model based on the system described in any one of claims 1 to 9, comprising the integration of multi-industry network test ranges and vulnerabilities, characterized in that... Includes the following steps: 1) Task creation and startup phase, details of which are as follows: The task scheduling and control module creates or adjusts multiple federated training penetration testing tasks through a visual interface, and sends tasks and start instructions to each network range participating in the federated training. 2) Data Acquisition and Local Training Phase: During this phase, each network test range independently performs data acquisition and local training tasks, as detailed below: 2-1 After receiving the task and start command, the target range node processing module calls the asset acquisition unit to collect asset data within the network topology range specified in the task and generate a topology node dataset. 2-2, Based on the topology node dataset, call the vulnerability detection unit to generate vulnerability attribute tags; 2-3, Based on the topology node dataset and vulnerability attribute labels, the local model training unit outputs local model parameters that have the correlation pattern of "professional topology link - vulnerability exploitation order"; 3) The aggregation and distribution phase of the federated model, the specific details of which are as follows: 3-1. Each network test range will securely send the topology node dataset, vulnerability attribute labels, and local model parameters generated by the test range node processing module to the federated learning coordination module through the data security transmission unit. 3-2 After all the data has been transmitted by the processing modules of each target range node, the parameter aggregation unit is called based on the local model parameters of each network target range to generate global model parameters covering a large number of different industry topology features and vulnerability exploitation rules. 3-3, The model distribution unit is invoked to distribute incremental model parameters to the target node processing modules of each network target range, and global model parameters are sent to the attack chain generation engine module and the model evaluation and optimization module simultaneously. The data security transmission unit sends the topology node datasets and vulnerability attribute tags of each network range to the attack chain generation engine module. 4) Attack Chain Generation and Testing Phase: In this phase, the attack chain generation module will conduct attack chain generation and testing tasks in parallel for each network target range. Specific details are as follows: 4-1. Generate a structured directed graph by calling the topology parsing unit based on the topology node dataset; 4-2, Based on the vulnerability attribute tags and the global model, the vulnerability priority sorting unit is invoked to generate a priority sequence of attack targets for each node; 4-3. Based on the structured directed graph and the priority sequence of attack targets for each node, the path planning unit is invoked to generate the optimal penetration chain from the attack start node to the target node. 4-4 During the penetration chain generation process, the anomaly monitoring unit in the model evaluation and optimization module monitors anomalies in real time, takes appropriate action based on the actual situation, and generates a problem list. 4-4' The model evaluation and optimization module forwards the problem list generated in step 4-4 to the task scheduling and control module for the user to select; 4-5. After the optimal penetration chain is successfully generated, the attack chain generation engine module sends it to the link testing unit of the corresponding network range; the link testing unit executes the penetration test according to the steps of the optimal penetration chain and feeds back the execution results and running logs to the attack chain generation engine module. 4-6. Feed back the actual test results of each network range based on the optimal penetration chain to the model evaluation and optimization module; 5) Model Iteration and Optimization Phase: In this phase, the model evaluation and optimization module will conduct penetration result verification tasks in parallel based on the measured results of each network target range. After completion, it will then generate unified model optimization instructions based on the problems encountered in each network target range. The specific content is as follows: 5-1. The penetration result verification unit generates three-dimensional evaluation indicators by comparing the expected effect of the attack chain with the actual penetration test results of each network target range, and outputs an evaluation report in combination with the problem analysis. The model optimization unit analyzes the problems based on the evaluation reports of each network target range, adjusts the weight coefficients of some features of the global model appropriately according to the causes of the problems, generates model optimization instructions and sends them to the federated learning coordination module for the next round of global model training. 5-2, The penetration result verification unit sends the evaluation report to the task scheduling and control module.