A virtual-real combined network target range system and an internet of things security evaluation method

By deploying attack tools on real IoT devices to capture and combine them with deep learning to generate synthetic traffic, a virtual-real network range system is constructed. This solves the problems of difficult data acquisition and unstable simulation in IoT security assessment, and achieves efficient and repeatable security assessment and policy generation.

CN122457313APending Publication Date: 2026-07-24SHANGHAI JIAOTONG UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
SHANGHAI JIAOTONG UNIV
Filing Date
2026-04-27
Publication Date
2026-07-24

AI Technical Summary

Technical Problem

Existing IoT security assessment methods suffer from difficulties in acquiring assessment data, poor scalability of attack traffic, and unstable attack simulations, making it difficult to accurately reflect the device's response to complex and diverse attacks.

Method used

A virtual-real network range system is constructed, which captures attack traffic by deploying attack tools on real IoT devices and generates synthetic traffic by combining deep learning, thus building a multi-dimensional traffic database that supports traffic replay and security assessment.

Benefits of technology

It enables efficient, repeatable, and multi-dimensional security assessments of IoT devices, generates accurate security policies, reduces testing costs, and improves the authenticity and repeatability of assessments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122457313A_ABST
    Figure CN122457313A_ABST
Patent Text Reader

Abstract

A kind of virtual-real combined network target range system, the system includes: setting up real Internet of Things scene test platform, carrying out different network attacks and carrying out flow capture, on the basis of this part of self-attack data and open source flow data, flow synthesis is carried out, node is set on real Internet of Things equipment, constructs network target range system, aims at realizing the security evaluation of real Internet of Things equipment, and gives further security strategy.The present application is based on the replay processing of network flow data, faces the security evaluation of equipment under Internet of Things scene, realizes the security evaluation of Internet of Things node, simultaneously proposes a kind of flow synthesis mode based on counter information, improves the scalability of original data, realizes stable and reliable attack simulation.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the fields of network security technology, IoT security assessment technology, and network range construction technology, specifically a virtual-real integrated network range system and an IoT security assessment method. This system addresses the security assessment needs of real IoT devices by constructing a controllable testing platform. Combining real and synthetic attack traffic, and based on replay processing of network traffic data, it assesses the security performance of IoT nodes under various attack scenarios and further generates security policies. Background Technology

[0002] With the large-scale deployment and widespread application of Internet of Things (IoT) devices, the security threats they face are becoming increasingly prominent, making it one of the core challenges in cyberspace security governance. Statistics show that as of 2019, the number of internet connections for IoT devices worldwide exceeded the number of connections for non-IoT devices for the first time, with the total number of IoT devices exceeding 16 billion, and this number is expected to double by 2030. The application scenarios of IoT have expanded from early consumer-grade smart home devices to critical information infrastructure fields such as healthcare, industrial automation, smart cities, transportation, energy management, and agricultural monitoring. However, the rapid proliferation of IoT devices contrasts sharply with the lagging security protection capabilities, making IoT systems a prime target for cyberattacks.

[0003] Currently, cyberattacks against IoT systems exhibit significant characteristics of multi-layered, large-scale, and continuously evolving nature. Since the emergence of IoT botnets, exemplified by Mirai in 2016, its source code has been publicly released, spawning dozens of variants including Satori, Mukashi, Moobot, and Sonic. These variants collectively target more than 15 known vulnerabilities in IoT devices discovered between 2014 and 2021. Attack vectors include, but are not limited to, typical weaknesses such as improper input validation, command injection, insufficient credential protection, out-of-bounds writes, and hard-coded passwords. Mirai and its variants have successfully controlled millions of IoT terminals, including cameras, routers, and network storage devices, by brute-forcing weak passwords in protocols such as Telnet and SSH, and by exploiting vulnerabilities such as CVE-2014-8361, CVE-2017-17215, and CVE-2020-11899. They have launched large-scale distributed denial-of-service (DDoS) attacks, causing major security incidents such as widespread internet outages on the US East Coast and the downing of 900,000 routers at Deutsche Telekom.

[0004] Besides DDoS attacks, IoT devices are also being used by attackers as springboards to infiltrate critical infrastructure networks. Furthermore, new threats are emerging, such as ransomware attacks targeting medical IoT devices and remote control attacks targeting connected vehicles. These attacks demonstrate that the security vulnerabilities of IoT devices have become a significant source of risk for cyberspace security, with harm not only limited to the devices themselves but also potentially impacting personal safety, public safety, and even national security.

[0005] To address these threats, academia and industry have conducted extensive research on IoT security assessments, proposing a series of assessment frameworks and tools, such as IoTBench and Firmadyne, to support the security assessment of IoT devices. For example, IoTBench is a benchmark suite for IoT devices that evaluates metrics such as encryption performance and network protocol stack security through standardized test cases. Firmadyne, on the other hand, is a simulation-based firmware analysis platform that enables dynamic analysis and vulnerability discovery of embedded device firmware without real hardware. In addition, there are fuzzing-based IoT protocol security assessment tools, such as dedicated fuzzers for protocols like MQTT and CoAP.

[0006] Considering the heterogeneity of IoT systems, existing research has proposed a layered evaluation methodology covering the network, software, and hardware layers. At the network layer, the evaluation focuses on the security of communication protocols, access control strength, and DDoS protection capabilities. At the software layer, the evaluation focuses on vulnerabilities in the operating system, applications, and web interfaces. At the hardware layer, the evaluation addresses physical security issues such as exposed debug interfaces and sensitivity to side-channel attacks. By collecting evaluation metrics layer by layer and employing a weighted scoring system, researchers can generate quantitative security evaluation results, providing a reference for device selection and hardening in different scenarios.

[0007] However, existing IoT security assessments still have the following key issues: First, obtaining assessment data is difficult. Most existing assessment methods rely on known vulnerability databases or simulation environments, which are insufficient to accurately reflect the actual response of devices under complex and diverse attack traffic. Obtaining real attack traffic is limited by legal, ethical, and technical hurdles, and publicly available datasets often cover a limited range of attack types and lack timeliness.

[0008] Second, attack traffic suffers from poor scalability. Existing attack traffic datasets are limited in size, making it difficult to support large-scale, repeatable testing needs. While synthetic traffic methods have been proposed, existing methods still fall short in maintaining semantic consistency of attack behavior and traffic diversity.

[0009] Third, the stability and realism of attack simulations are insufficient. Existing network ranges often lack accurate reproduction of the behavior of real devices in IoT scenarios, leading to discrepancies between the evaluation results and the real environment.

[0010] Therefore, there is an urgent need for a network range system that can combine real attack traffic with synthetic traffic and possesses good scalability, for efficient, secure, and repeatable security assessments of real IoT devices. This invention addresses this need by proposing a network range system based on self-collected and synthetic attack traffic. Through traffic replay and intelligent synthesis technologies, it achieves systematic security assessments of IoT nodes. Summary of the Invention

[0011] This invention provides a virtual-real network range system that addresses the security assessment needs of real IoT devices. It aims to solve the problems of limited traffic data and unstable attack simulation in existing IoT security assessments by constructing a controllable testing environment that combines real and synthetic traffic. This provides IoT systems with comprehensive, efficient, and repeatable security performance assessments and generates corresponding security hardening strategies.

[0012] The core structure of the system of this invention includes: (a) Traffic Data Module: Step 1: Setting up the physical environment.

[0013] Build a real-world IoT scenario testing platform to simulate the actual operating environment. By deploying real IoT devices, it supports the execution of various network attacks and traffic capture.

[0014] The system first constructs a test platform to simulate a real-world operating environment. Unlike traditional purely virtualized environments, this platform realistically deploys the IoT devices to be evaluated. It supports the execution of various network attacks and traffic capture, serving as a bridge between the physical world and digital evaluation. The platform's design takes into account the diversity of devices and the complexity of network topologies, providing a high-fidelity foundation for subsequent traffic capture and evaluation.

[0015] Step 2: Collect attack traffic.

[0016] (2-1) Deploy attack tools. Install a Kali virtual machine on the attacking machine and deploy real attack tools (such as Hping3, Hydra, etc.) to execute different types of network attacks (including but not limited to DDoS, port scanning, brute-force attacks, spoofing attacks, etc.). For example, for flood attacks, use the Hping3 tool on the Kali virtual machine to execute this type of attack.

[0017] (2-2) Capturing network traffic. The attack is executed using the deployed attack tools. During the attack, the system uses a traffic capture tool (such as Wireshark) to capture the traffic under a specific network card in order to accurately capture the corresponding original attack traffic and record the captured traffic packets.

[0018] (2-3) Result verification. An Intrusion Detection System (NIDS) was deployed on the network monitoring equipment. The captured attack traffic was input for anomaly detection. It was verified that the captured traffic was indeed abnormal traffic.

[0019] Step 3: Synthesize network traffic.

[0020] Based on the attack data and open-source traffic data obtained in step 2, a traffic synthesis method based on counter information is used to generate scalable synthetic attack traffic. This method uses deep learning to train a neural network Transformer model by statistically analyzing the statistical characteristics of real traffic (such as packet size distribution, packet timestamp distribution, packet number distribution, etc.), thereby generating synthetic abnormal traffic that is similar to the original traffic in statistical characteristics and can closely simulate real network behavior, effectively solving the problem of data scarcity.

[0021] (3-1) Raw Traffic Processing. The raw Pcap traffic packets are preprocessed by traversing all packets within each time window to generate data in counter format. Each time window contains three characteristics: time window length, total number of packets within the window, and total number of bytes in the packets within the window.

[0022] (3-2) Model Training. Input the counter information processed in the previous step into the model for training. The core architecture of the model is as follows: Figure 3 As shown, a Transformer model is used to capture the temporal information within the sequence, and a BiLSTM model is used to remove the influence of extreme values. A progressive approximation of data packets is achieved: for example, for a 1-second time window, Model 1 (1 second to 100 milliseconds) is used to predict the 100-millisecond window, Model 2 (100 milliseconds to 10 milliseconds) is used to predict the 10-millisecond window, and Model 3 (10 milliseconds to 1 millisecond) is used to predict the 1-millisecond window. As the time window shrinks, the original counter data is amplified to more closely approximate the actual time interval of the traffic.

[0023] (3-3) Model Inference. Input the predicted data into the trained model to obtain the inference results. The output format is a CSV file, with each line containing information about a data packet, including 7 features: source IP address, destination IP address, source port, destination port, protocol, packet length, and packet timestamp.

[0024] (3-4) Post-processing. The output of step 3 is processed to generate the original traffic data packet format. That is, the information of each line of the input file is parsed line by line, the field types are converted, the Ethernet layer, network layer, transport layer and payload are constructed according to the data packet header information, the packet timestamp is set and then assembled to generate a complete data packet.

[0025] Step 4: Build the dataset.

[0026] The attack traffic obtained in step 2 and the synthetic network traffic obtained in step 3 were used together as the experimental dataset, which included both attack traffic captured in real scenarios and synthetic traffic generated based on real traffic, thus constructing a multi-dimensional traffic database.

[0027] (ii) Traffic replay module: Step 1: Input attack requirements.

[0028] Users can input their requirements in two ways. The first is by inputting text, which is then parsed by a large model to extract key information and construct attack parameters. The second method allows users to directly select the attack type and parameters from a dropdown menu. Both methods ultimately return an attack parameter pair, containing the attack type and attack parameters.

[0029] Step 2: Modify the data packet parameters.

[0030] Using the attack parameter pairs obtained in the previous step as a baseline, the attack type information is extracted, and traffic corresponding to the attack parameters is selected from the database. Then, based on the attack parameter information, such as destination IP and destination port, the original traffic data packets are modified to obtain new data packets that meet the user's requirements. Figure 4 For example, for the SYN flood attack type in DoS flooding, it supports modifying four features: destination IP address, source port, packet interval, and packet payload length.

[0031] Step 3: Set the time information.

[0032] By combining the requirements for packet intervals in the attack parameters, the timestamps of the original packets are modified to obtain traffic data that better reflects the requirements of real-world scenarios.

[0033] Step 4: Replay the traffic.

[0034] In step 3, the data packet, which has been completely modified according to the user's requirements, is obtained. At the physical link layer, the data packet is replayed by specifying the corresponding network card, thus executing a network attack.

[0035] (III) Safety Assessment Module: Step 1: Target machine response.

[0036] After the attacking machine completes a traffic replay process, the target machine uses Tcpdump to capture attack packets based on the attack information, and uses the intrusion detection system deployed on the target machine to detect the attack packets, calculate the anomaly detection rate of this attack (number of abnormal packets / total number of packets sent by the attacking machine), and return it to the attacking machine.

[0037] Step 2: Decision-making by the attacking machine.

[0038] The target machine returns the attack detection rate to the attacking machine. The attacking machine pre-sets corresponding thresholds for different attack types and determines whether to continue the attack by comparing the anomaly detection rate with the threshold. If the anomaly detection rate is lower than the set threshold, the attack is considered to have failed to achieve the desired effect. By calling a large model, based on information such as the network attack type and feedback results, the large model provides suggestions for modifying packet parameters, and the attack is relaunched until the new attack's anomaly detection rate is higher than the threshold, at which point the attack is considered successful.

[0039] Step 3: Log the information.

[0040] If the anomaly detection rate is greater than the set threshold, the attack is considered successful, and the information of this test (including attack start time, network attack type, success or failure, anomaly detection rate, etc.) is recorded in the database, ending the attack. Front-end query operations are supported.

[0041] Step 4: Generate strategy.

[0042] After completing the entire process described above, the system enters the final evaluation and decision-making phase. This module invokes a large model, leveraging its internal knowledge base on network attacks and security protection, and combining this knowledge with test information (such as attack types and results). The large model then provides assessments of the device's resilience to attacks and the impact on its performance, while also outputting security policy recommendations for specific devices. These recommendations can include specific firewall rules, access control list (ACL) optimizations, firmware upgrade suggestions, or network isolation solutions, thus forming a closed loop from "testing" to "hardening."

[0043] This invention constructs a complete "virtual-real hybrid" network test range environment by setting up nodes on real IoT devices and combining virtualization technology, which is used to conduct security assessments of devices in IoT scenarios.

[0044] This test environment integrates real IoT devices to be evaluated with virtualized network nodes (such as virtual routers, virtual attack machines, and virtual servers). It allows users to modify and replay specified types of attacks based on pre-prepared attack traffic data, observing the target machine's defense capabilities against such attacks. Through large-scale anomaly attack testing based on traffic replay, the security defense capabilities of the corresponding IoT devices are obtained, achieving end-to-end security assessment.

[0045] Compared with the prior art, the technical effects of the present invention are as follows: 1) Traditional IoT security assessments often rely solely on self-collected traffic from real-world environments. Limited by testing cycles, device types, and attack tool libraries, they struggle to cover novel or low-frequency attack patterns. Conversely, relying solely on open-source data suffers from incompatibility with specific device environments and poor timeliness. This invention, however, combines self-collected attack traffic (ensuring high fidelity and environment specificity) with synthetic network traffic (incorporating open-source and extended data) to construct a multi-dimensional attack traffic library, enabling multi-faceted evaluation of IoT devices' attack resistance capabilities.

[0046] 2) When performing network attacks (such as DDoS, brute-force attacks, and vulnerability exploits) on real IoT devices, the attacks can easily lead to device crashes, network paralysis, or irreversible state changes, making it impossible to standardize and repeat the tests. This invention introduces synthetic attack traffic and supports user-defined attack parameters, enabling large-scale, high-frequency simulation testing without repeatedly subjecting real devices to destructive attacks. This avoids the problems of repeated attacks potentially damaging devices, and the inability to standardize and repeat the tests that arise in traditional testing, significantly improving the efficiency and repeatability of security assessments and reducing testing costs.

[0047] 3) Simulated network testbeds (networks formed using software tools, without the need for physical network devices) offer high security but cannot realistically reflect the physical reactions of the underlying hardware when attacked (e.g., response latency, abnormal power consumption). This invention constructs a hybrid virtual-real network testbed by setting up nodes on real IoT devices and combining this with self-collected high-fidelity attack traffic. Compared to purely simulated network testbeds, this invention's solution can accurately capture the physical state changes of real devices when attacked (e.g., response latency, abnormal power consumption), making the evaluation results more realistic. This overcomes the deficiency of simulation environments in reflecting the underlying hardware attack response and accurately captures the state changes of real devices when attacked. Attached Figure Description

[0048] Figure 1 This is a schematic diagram of the physical network topology constructed in an embodiment of the present invention.

[0049] Figure 2This is the core framework diagram of the network target range system of this invention.

[0050] Figure 3 This is a schematic diagram of the core module processing for amplifying the time window based on counter information in an embodiment of the present invention.

[0051] Figure 4 This is a diagram showing the effect of attack parameter settings on the front-end interactive interface of the traffic replay module in this embodiment of the invention.

[0052] Figure 5 This is a screenshot showing the attack log query effect displayed on the front end of the security assessment module in this embodiment of the invention. Detailed Implementation

[0053] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be described in further detail below with reference to the accompanying drawings and specific embodiments. However, it should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of protection of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without inventive effort are within the scope of protection of this invention.

[0054] See Figure 2 This invention provides a virtual-physical integrated network range system, consisting of three core modules: a traffic data module 100, a traffic replay module 200, and a security assessment module 300. These three modules are organically connected to signal control lines via data interfaces and work collaboratively with the underlying physical testing platform to form a closed-loop technical solution encompassing traffic preparation, attack simulation, and assessment and hardening.

[0055] Specifically, the physical testing platform deploys real IoT target devices and network interconnection devices, providing a high-fidelity underlying operating environment for the system. The traffic data module 100 communicates with the attacking machine in the physical testing platform, responsible for collecting real attack traffic and generating synthetic traffic to construct a multi-dimensional traffic database. The input terminals of the traffic replay module 200 are connected to the database interface and user interaction interface of the traffic data module 100, respectively, and its output terminal is connected to the network interface card of the physical testing platform, used to retrieve, modify, and replay attack traffic from the database according to user-customized requirements. The first input terminal of the security assessment module 300 communicates with the real IoT target device to receive response feedback data, the second input terminal is connected to the control output terminal of the traffic replay module 200 to obtain current attack parameters, its first output terminal is connected to the parameter adjustment input terminal of the traffic replay module 200 to form a closed-loop iterative attack mechanism, and its second output terminal is used to output the final security hardening strategy.

[0056] The specific implementation methods of these three modules will be explained in detail below: (a) Traffic data module 100, used to construct a multi-dimensional traffic database containing real attack traffic and synthetic attack traffic; specifically including: The physical environment setup unit 101 is used to build a real IoT scenario test platform to simulate the actual operating environment. By deploying real IoT devices, it supports the execution of various network attacks and traffic capture.

[0057] First, a test platform was built to simulate a real-world operating environment. Unlike traditional purely virtualized environments, this platform realistically deployed the IoT devices to be evaluated, including two routers, three standalone hosts, and five Raspberry Pis. The specific physical topology is as follows: Figure 1 As shown. This platform includes both wireless and wired connection methods, and also supports cross-subnet attack paths, such as attacking target machines in the 192.168.0.0 / 24 network segment from the 192.168.1.0 / 24 network segment.

[0058] This platform supports the execution of various network attacks and traffic capture, serving as a bridge between the physical world and digital assessment. Its design takes into account the diversity of devices and the complexity of network topologies, providing a high-fidelity foundation for subsequent traffic capture and assessment.

[0059] The attack traffic acquisition unit 102 is connected to the attack machine in the physical test platform and is used to execute various network attacks and capture the corresponding raw attack traffic.

[0060] (2-1) Deploy attack tools. Install a Kali virtual machine on the attacking machine and deploy real attack tools (such as Hping3, Hydra, etc.) to execute different types of network attacks (including but not limited to DDoS, port scanning, brute-force attacks, spoofing attacks, etc.). For example, for flooding attacks, use the Hping3 tool on the Kali virtual machine to execute this type of attack; for scanning attacks, use the Nmap tool on the Kali virtual machine to execute the attack; for brute-force attacks, use the Hydra tool to execute the attack; for spoofing attacks, use the Ettercap tool to execute the attack; and for penetration attacks, use the BurpSuite tool to execute the attack.

[0061] (2-2) Capturing network traffic. The attack is executed using the deployed attack tools. During the attack, the system uses a traffic capture tool (such as Wireshark) to capture the traffic under a specific network card in order to accurately capture the corresponding original attack traffic and record the captured traffic packets.

[0062] (2-3) Result Verification. An Intrusion Detection System (NIDS) was deployed on the network monitoring equipment, and the captured attack traffic was input for anomaly detection. This detection system uses flow-level characteristics and a deep detection model of network traffic. Verification showed that the captured traffic was indeed abnormal traffic.

[0063] The traffic synthesis unit 103, based on the obtained attack data and open-source traffic data, uses a traffic synthesis method based on counter information to generate scalable synthetic attack traffic. This method uses deep learning to train a neural network Transformer model by statistically analyzing the statistical characteristics of real traffic (such as packet size distribution, packet timestamp distribution, packet quantity distribution, etc.), thereby generating synthetic abnormal traffic that is similar to the original traffic in statistical characteristics and can closely simulate real network behavior, effectively solving the problem of data scarcity.

[0064] (3-1) Raw Traffic Processing. The raw Pcap traffic packets are preprocessed by traversing all packets within each time window to generate data in counter format. Each time window contains three characteristics: time window length, total number of packets within the window, and total number of bytes in the packets within the window.

[0065] (3-2) Model Training. Input the counter information processed in the previous step into the model for training. The core architecture of the model is as follows: Figure 3 As shown, a Transformer model is used to capture the temporal information within the sequence, and a BiLSTM model is used to remove the influence of extreme values. A progressive approximation of data packets is achieved: for example, for a 1-second time window, Model 1 first predicts a window of 100 milliseconds, Model 2 predicts a window of 10 milliseconds, and Model 3 predicts a window of milliseconds. As the time window shrinks, the original counter data is amplified to more closely approximate the actual time interval of the traffic. The training data for Models 1, 2, and 3 all come from the processed results of the same traffic file, with different file divisions obtained according to different time windows, and the three models are trained according to the window size.

[0066] (3-3) Model Inference. Input the predicted data into the trained model to obtain the inference results. The output format is a CSV file, with each line containing information about a data packet, including 7 features: source IP address, destination IP address, source port, destination port, protocol, packet length, and packet timestamp.

[0067] After the amplification model training is completed, the timestamp distribution of the corresponding traffic type is obtained. Using a pre-trained header constraint generation model, data packets containing fields such as IP address information are inferred. The IP address distribution of the synthetic traffic is correlated with that of the original traffic because the training data for the header constraint generation model also comes from the original traffic. Constraints are applied to the header generation of the generated traffic based on the characteristics of the original traffic to ensure it conforms to the required traffic type.

[0068] (3-4) Post-processing. The output of step 3 is processed to generate the original traffic data packet format. That is, the information of each line of the input file is parsed line by line, the field types are converted, the Ethernet layer, network layer, transport layer and payload are constructed according to the data packet header information, the packet timestamp is set and then assembled to generate a complete data packet.

[0069] The dataset construction unit 104 has its input terminals connected to the output terminals of the attack traffic acquisition unit 102 and the traffic synthesis unit 103, respectively. It uses the acquired attack traffic and synthetic network traffic together as the experimental dataset, aggregating, classifying, indexing, and storing them to ultimately form a multi-dimensional traffic database covering various attack types and possessing both environment specificity and scalability. This database includes both attack traffic captured in real-world scenarios and synthetic traffic generated based on real traffic.

[0070] (ii) The traffic replay module 200 is used to retrieve, customize, and replay attack traffic from the database constructed by the traffic data module 100 based on the attack requirements input by the user. Specifically, it includes: The requirement parsing unit 201 provides two user interaction interfaces to receive attack requirements.

[0071] The first method involves inputting text, which is then parsed by a large model to extract key information and construct attack parameters. The second method allows users to directly select the attack type and parameters via a dropdown menu. Both methods ultimately return an attack parameter pair, containing the attack type and attack parameters.

[0072] The data packet modification unit 202 has its control terminal connected to the output terminal of the demand parsing unit 201 and is used to receive the attack command; its data terminal is connected to the database interface of the traffic data module 100.

[0073] The workflow of this unit is as follows: Using the attack parameter pairs obtained in the previous step as a baseline, the attack type information is extracted, and traffic corresponding to the attack parameters is selected from the database. Then, based on the attack parameter information, such as destination IP and destination port, the original traffic data packets are modified to obtain new data packets that meet the user's requirements. Figure 4For example, in the SYN flood attack type of DoS flooding, it supports modifying four characteristics: destination IP address, source port, packet interval, and packet payload length. Among them, the destination IP address determines the direction to which the packet is sent, while the source port, packet interval, and packet payload all affect the effectiveness of the flooding attack.

[0074] The timestamp setting unit 203 is connected to the output of the data packet modification unit 202. After the data packet has undergone header and payload modification, its original timestamp information is no longer applicable. The timestamp setting unit 203 recalculates the timestamp of the entire data packet sequence according to the data packet interval requirements in the attack command (e.g., user-specified packet per second (PPS) or directly specified packet interval time). Combining the packet interval requirements in the attack parameter information, the timestamp of the original data packet is modified to obtain traffic data that better reflects the requirements of the real scenario.

[0075] The input of the network interface card (NIC) replay unit 204 is connected to the output of the timestamp setting unit 203, and its output is physically connected to the designated network interface card (NIC) of the physical test platform. This unit operates at the physical link layer (Layer 2), sending the fully modified and timestamped data packet sequence to the physical network packet by packet through the designated NIC. Each complete sequence transmission process corresponds to a network attack simulation that meets the user's customized requirements.

[0076] (III) Security Assessment Module 300, used to assess the security performance of real IoT target devices subjected to attacks, optimize attack strategies through a closed-loop feedback mechanism, and ultimately generate security hardening strategies. Specifically, it includes: The input terminal of the indicator receiving unit 301 is communicatively connected to the real IoT target device in the physical test platform.

[0077] After the attacking machine completes a traffic replay process through the traffic replay module 200, it uses Tcpdump to capture attack packets based on the attack information, and uses the intrusion detection system deployed on the target machine to detect the attack packets, calculate the anomaly detection rate of this attack (number of abnormal packets / total number of packets sent by the attacking machine), and return it to the attacking machine.

[0078] The first input terminal of the attack decision unit 302 is connected to the output terminal of the indicator receiving unit 301, and the second input terminal is connected to the output terminal of the demand parsing unit 201 in the traffic replay module 200 (to obtain the current attack type and parameters).

[0079] The target machine returns the attack detection rate to the attacking machine. The attacking machine pre-sets corresponding thresholds for different attack types and determines whether to continue the attack by comparing the anomaly detection rate with the threshold. If the anomaly detection rate is lower than the set threshold, the attack is considered to have failed to achieve the desired effect. By calling a large model, based on information such as the network attack type and feedback results, the large model provides suggestions for modifying packet parameters, and the attack is relaunched until the new attack's anomaly detection rate is higher than the threshold, at which point the attack is considered successful.

[0080] If the anomaly detection rate is greater than the set threshold, the attack is considered successful, and the information of this test (including attack start time, network attack type, success or failure, anomaly detection rate, etc.) is recorded in the database, ending the attack. Front-end query operations are supported.

[0081] After completing the entire process described above, the system enters the final evaluation and decision-making phase. This module invokes a large model, leveraging its internal knowledge base on network attacks and security protection, and combining this knowledge with test information (such as attack types and results). The large model then provides assessments of the device's resilience to attacks and the impact on its performance, while also outputting security policy recommendations for specific devices. These recommendations can include specific firewall rules, access control list (ACL) optimizations, firmware upgrade suggestions, or network isolation solutions, thus forming a closed loop from "testing" to "hardening."

[0082] Any modifications, equivalent substitutions, or improvements made within the spirit and principles of this invention shall be included within the scope of protection of this invention.

Claims

1. A virtual-real integrated network range system, characterized in that, include: The system comprises a physical testing platform, a traffic data module, a traffic replay module, and a security assessment module; among which, The physical testing platform is equipped with at least one real IoT target device and provides underlying network connectivity for the network test range system. The traffic data module is communicatively connected to the attack machine in the physical test platform. It is used to collect the real attack traffic generated when performing network attacks on the physical test platform and to construct a traffic database together with the internally generated synthetic attack traffic. The traffic replay module has its input end connected to the database interface and user interaction interface of the traffic data module, respectively, and is used to retrieve and modify the target traffic data from the traffic database according to the received attack requirements. Its output end is connected to the network interface of the physical test platform to replay the modified traffic to the real IoT target device. The security assessment module has a first input terminal that is communicatively connected to the real IoT target device to receive response feedback data from the target device in response to replayed traffic; a second input terminal that is connected to the control output terminal of the traffic replay module to obtain the current attack parameters; a first output terminal that is connected to the parameter adjustment input terminal of the traffic replay module to provide parameter optimization suggestions to the traffic replay module when the attack does not achieve the expected results, so as to form a closed-loop iterative attack; and a second output terminal that is used to output a security hardening strategy for the target device.

2. The virtual-real integrated network range system according to claim 1, characterized in that, The traffic data module includes: The attack traffic acquisition unit is used to execute various network attacks on the physical test platform using deployed attack tools, and to call traffic capture tools to capture the real attack traffic; The result verification unit is connected to the attack traffic acquisition unit and is used to call the intrusion detection system to perform anomaly verification on the captured real attack traffic. A traffic synthesis unit, whose input is connected to the attack traffic acquisition unit and / or an open-source database, is used to receive raw traffic data packets and generate synthetic attack traffic that is statistically similar to the raw traffic data packets using a deep learning model based on counter information. The dataset construction unit is connected to the output ends of the attack traffic acquisition unit and the traffic synthesis unit, respectively, and is used to aggregate and store the real attack traffic and the synthesized attack traffic to form the traffic database.

3. The virtual-real integrated network range system according to claim 2, characterized in that, The flow synthesis unit specifically performs the following operations: The input raw traffic data packets (Pcap format) are traversed according to a preset hierarchical time window, and the total number of data packets and total number of bytes in each time window are extracted to generate time-series data in counter format. The time-series data in the counter format is input into a neural network model containing Transformer and BiLSTM architectures. Through a multi-level time window progressive prediction method, the coarse-grained counter information is gradually refined into millisecond-level packet-level multi-dimensional feature information. The multi-dimensional feature information includes source IP address, destination IP address, source port, destination port, protocol, packet length, and timestamp. Post-processing is performed based on the multi-dimensional feature information to reversely reconstruct the Ethernet layer, network layer, transport layer, and payload of the data packet, generating the complete synthetic attack traffic data packet.

4. The virtual-real integrated network range system according to claim 1, characterized in that, The traffic replay module includes: The requirement parsing unit has an interface for receiving natural language text or graphical selection instructions from users, and extracting structured information by calling a large language model to generate attack instructions containing attack type and attack parameters. The data packet modification unit has its control end connected to the demand parsing unit to receive the attack instruction, and its data end connected to the database interface of the traffic data module. It is used to select target traffic data according to the attack type in the attack instruction, and modify the destination IP address, source port, payload length and data packet interval fields in the data packet according to the attack parameters. The timestamp setting unit, connected to the data packet modification unit, is used to recalculate and set the timestamp of each data packet according to the modified data packet interval field. The network card replay unit has its input end connected to the timestamp setting unit and its output end connected to the designated network interface card of the physical test platform. It is used to send the modified data packet sequence packet by packet at the physical link layer.

5. The virtual-real integrated network range system according to claim 1, characterized in that, The security assessment module includes: The indicator receiving unit, whose input end is connected to the real IoT target device, is used to receive the anomaly detection rate calculated by the target device using the intrusion detection system deployed locally; wherein, the anomaly detection rate is the ratio of the number of detected abnormal packets to the total number of packets sent by the traffic replay module; An attack decision unit, whose input terminals are connected to the attack parameter output terminals of the indicator receiving unit and the traffic replay module respectively, is used to compare the anomaly detection rate with a preset threshold: If the anomaly detection rate is greater than or equal to the preset threshold, the attack is deemed valid, and log information is generated to record the attack start time, attack type, and anomaly detection rate. If the anomaly detection rate is less than the preset threshold, the attack is determined to have failed to meet expectations. The large language model is then triggered to generate parameter optimization suggestions based on the current attack type, attack parameters, and the anomaly detection rate. These suggestions are then sent to the parameter modification unit of the traffic replay module through its output to drive the next round of iterative attacks.

6. The virtual-real integrated network range system according to claim 5, characterized in that, The security assessment module also includes: The strategy generation unit, whose input is connected to the log output of the attack decision unit, is used to call the large language model to integrate the test logs and target machine response data of the entire process after the attack process is completed, and generate a security assessment report and specific security hardening strategies for the target machine device.

7. An Internet of Things (IoT) security assessment method based on the system described in any one of claims 1 to 6, characterized in that, Includes the following steps: On a physical test platform with real IoT target devices deployed, real attack traffic is collected through a traffic data module, and synthetic attack traffic is generated using a deep learning model based on counter information to build a multi-dimensional traffic database. The system receives attack requests through a traffic replay module, extracts target traffic from the traffic database, and modifies data packet parameters and timestamps according to the attack requests. The traffic replay module replays the modified data packet sequence to the real IoT target device through the network interface of the physical test platform; The security assessment module receives the anomaly detection rate reported by the real IoT target device and compares it with a preset threshold. When the anomaly detection rate is lower than the preset threshold, the security assessment module generates parameter optimization suggestions and feeds them back to the traffic replay module, controlling the traffic replay module to perform iterative replay based on the optimized parameters until the preset threshold is reached. After the attack test is completed, the security assessment module generates a security hardening strategy for the real IoT target device based on the test data.

8. The IoT security assessment method according to claim 7, characterized in that, The steps of generating synthetic attack traffic using a deep learning model based on counter information specifically include: The original traffic data packets are traversed according to a preset time window to generate counter format data containing window duration, number of packets and total number of bytes; The counter format data is input into a neural network model based on Transformer and BiLSTM architecture for training. Through multi-level time window progressive prediction, the coarse-grained time window data is gradually refined into millisecond-level data packet feature files containing source / destination IP, source / destination port, protocol, packet length and timestamp. The data packet feature file is parsed, and the Ethernet layer, network layer, transport layer, and load information of the data packet are reconstructed in reverse to generate a complete synthetic attack traffic data packet.

9. The IoT security assessment method according to claim 7, characterized in that, The step of generating parameter optimization suggestions through the security assessment module includes: When it is determined that the attack did not achieve the expected results, the current attack type, attack parameters, and anomaly detection rate reported by the target machine are used as contextual prompts and input into the large language model. Obtain the data packet parameter modification suggestions from the large language model, based on the output of the internal security knowledge base, which are aimed at circumventing the existing defense mechanisms of the target machine.

10. The IoT security assessment method according to claim 7, characterized in that, The security hardening strategy includes: For the real IoT target device, one or more combinations of firewall filtering rules, access control list (ACL) configuration schemes, firmware version upgrade instructions, or network topology isolation suggestions.