Network security test method, electronic device, medium, and computer program product

By performing simulated operations on target network devices, a network security testing scenario is built, which solves the problem that wireless networks are difficult to simulate distributed denial-of-service attacks, and improves network security detection and defense capabilities.

WO2025246720A1PCT designated stage Publication Date: 2025-12-04ZTE CORP
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/089815
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-05-30
Filing Date
2025-04-18
Publication Date
2025-12-04

AI Technical Summary

Technical Problem

Existing technologies are unable to effectively simulate distributed denial-of-service attacks on wireless networks, making it difficult to conduct effective security testing and defense before mobile communication networks are put into operation.

Method used

By performing target simulation operations on the target network device through the target controlled device, a network security test scenario is built to simulate network attack situations, including connection request overload, connection resource exhaustion, and abnormal data simulated packets, and a security test report is generated.

Benefits of technology

It enhances the network security detection and defense capabilities of target network devices, enabling the identification and response to distributed denial-of-service attacks, and improving network stability and reliability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025089815_04122025_PF_FP_ABST
    Figure CN2025089815_04122025_PF_FP_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of network tests, and particularly relates to a network security test method, an electronic device, a medium, and a computer program product. The network security test method provided in the embodiments of the present application comprises: acquiring a test scenario simulation instruction, and determining a target simulation operation and a target controlled device on the basis of the test scenario simulation instruction (S101); executing the target simulation operation on a target network device by means of the target controlled device, so as to construct a network security test scenario (S102); and on the basis of the network security test scenario, performing a security test on a target network corresponding to the target network device, so as to obtain a security test report of the target network in the network security test scenario (S103).
Need to check novelty before this filing date? Find Prior Art

Description

Network security testing method, electronic device, medium and computer program product

[0001] Cross-reference to Related Applications

[0002] This application is based on and claims priority to Chinese Patent Application No. 202410695870.9, filed on May 30, 2024, the entire contents of which are incorporated herein by reference. TECHNICAL FIELD

[0003] The present application relates to the technical field of network testing, and in particular to a network security testing method, an electronic device, a medium and a computer program product. BACKGROUND

[0004] With the popularity of mobile Internet and the development of Internet of Things, mobile communication has become an indispensable part of people's daily life and work, and the security problem of mobile communication has attracted more and more attention. Air interface attack of wireless network refers to an attack on the wireless transmission medium in wireless communication network. This type of network attack takes advantage of the broadcast nature of wireless signals and possible security vulnerabilities to implement. In a wireless network, the air interface refers to the wireless transmission medium between mobile devices (such as mobile phones, Wi-Fi devices, etc.) and wireless access points (such as base stations, routers, etc.). Distributed denial of service attack (DDoS) is a common form of air interface attack.

[0005] Due to the characteristics of large traffic and high dispersion of wireless network, some attackers can use a large number of mobile devices and wireless access points to attack, which makes the attack more difficult to detect and defend. Therefore, before the mobile communication network is put into operation, it needs to test its ability to resist distributed denial of service attack. However, how to effectively simulate the attack on the wireless network for the mobile communication network to test is still a difficult problem to be solved in the industry. SUMMARY

[0006] The embodiments of the present application provide a network security testing method, an electronic device, a medium and a computer program product.

[0007] In a first aspect, an embodiment of the present application provides a network security testing method, the method comprising: obtaining a test scene simulation instruction, and determining a target simulation operation and a target controlled device according to the test scene simulation instruction; performing the target simulation operation on a target network device through the target controlled device, and building a network security testing scene; performing a security test on a target network corresponding to the target network device based on the network security testing scene, and obtaining a security test report of the target network under the network security testing scene.

[0008] In a second aspect, an embodiment of the present application provides an electronic device, comprising: one or more processors; a memory having one or more programs stored thereon, when the one or more programs are executed by the one or more processors, the one or more processors implement the network security testing method according to the first aspect.

[0009] In a third aspect, an embodiment of the present application provides a computer readable storage medium having a computer program stored thereon, when the program is executed by a processor, the network security testing method according to the first aspect is implemented.

[0010] In a fourth aspect, an embodiment of the present application provides a computer program product comprising a computer program, when the computer program is executed by a processor, the network security testing method according to the first aspect is implemented. BRIEF DESCRIPTION OF DRAWINGS

[0011] The accompanying drawings are included to provide a further understanding of the technical scheme of the present application, and constitute a part of the specification, and are used together with the embodiments of the present application to explain the technical scheme of the present application, and do not constitute a limitation on the technical scheme of the present application.

[0012] FIG. 1 is a flow diagram of a network security testing method according to an embodiment of the present application;

[0013] FIG. 2 is another flow diagram of a network security testing method according to an embodiment of the present application;

[0014] FIG. 3 is another flow diagram of a network security testing method according to an embodiment of the present application;

[0015] FIG. 4 is another flow diagram of a network security testing method according to an embodiment of the present application;

[0016] FIG. 5 is another flow diagram of a network security testing method according to an embodiment of the present application;

[0017] FIG. 6 is another flow diagram of a network security testing method according to an embodiment of the present application;

[0018] FIG. 7 is another flow diagram of a network security testing method according to an embodiment of the present application;

[0019] FIG. 8 is another flow diagram of a network security testing method according to an embodiment of the present application;

[0020] FIG. 9 is another flow diagram of a network security testing method according to an embodiment of the present application;

[0021] FIG. 10A is another flow diagram of a network security testing method according to an embodiment of the present application;

[0022] FIG. 10B is a diagram of a normal SRB1 channel MAC PDU message according to an embodiment of the present application;

[0023] FIG. 10C is a diagram of an abnormal SRB1 channel MAC PDU message according to an embodiment of the present application;

[0024] FIG. 10D is a diagram of a normal MAC PDU message according to an embodiment of the present application;

[0025] FIG. 10E is a diagram of an abnormal MAC PDU message according to an embodiment of the present application;

[0026] FIG. 11A is a diagram of a structure of a terminal according to an embodiment of the present application;

[0027] FIG. 11B is a diagram of a structure of a scheduling processing component according to an embodiment of the present application;

[0028] FIG. 12 is a diagram of a structure of an electronic device according to an embodiment of the present application. DETAILED DESCRIPTION

[0029] In order to make the objects, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the embodiments described herein are only used to explain the present application and should not be used to limit the present application.

[0030] It should be understood that, in the description of the embodiments of the present application, if there is a description to "first", "second" and the like, it is only for the purpose of distinguishing technical features, and cannot be understood as indicating or implying relative importance or implicitly indicating the number of indicated technical features or the sequence of indicated technical features. "At least one" means one or more, and "multiple" means two or more. The "and / or" describes the association relationship of the associated objects, which means that there can be three kinds of relationships, for example, A and / or B can mean that A exists alone, A and B exist together, and B exists alone. Wherein A, B can be singular or plural. The character " / " generally represents that the front and rear associated objects are in an "or" relationship. "At least one of the following" and the like means any group of these items, including single item or any group of multiple items. For example, at least one of a, b and c can mean: a, b, c, a and b, a and c, b and c, or a and b and c, wherein a, b, c can be single or multiple.

[0031] In addition, the technical features involved in the various embodiments of the present application described below can be combined with each other as long as there is no conflict.

[0032] In order to facilitate the understanding of the scheme of the embodiments of the present application, and the description of the following embodiments is clear and concise, first give a brief introduction of related art:

[0033] With the popularity of mobile Internet and the development of Internet of Things, mobile communication has become an indispensable part of people's daily life and work, and the security problem of mobile communication has attracted more and more attention. The air interface attack of wireless network refers to the attack on the wireless transmission medium in the wireless communication network. This type of network attack uses the broadcast characteristics of wireless signals and possible security vulnerabilities to implement. In the wireless network, the air interface refers to the wireless transmission medium between the mobile device (such as mobile phone, Wi-Fi device, etc.) and the wireless access point (such as base station, router, etc.). Distributed denial of service attack (Distributed Denial of Service, DDoS) is a common form of air interface attack.

[0034] Due to the characteristics of large traffic and high dispersion of wireless network, some attackers can use a large number of mobile devices and wireless access points to attack, which makes the attack more difficult to detect and defend. Therefore, before the mobile communication network is put into operation, it needs to test its ability to resist distributed denial of service attack. However, how to effectively simulate the attack on the wireless network for the mobile communication network to test, is still a difficult problem to be solved in the industry.

[0035] The embodiment of the present application provides a network security testing method, an electronic device, a medium and a computer program product, which aims to perform target simulation operation on a target network device through a target controlled device, thereby building a network security testing scene, simulating the case that the target network is attacked by a network, and then testing the target network to help improve the network security detection and network defense capability of the target network device.

[0036] Further description is made below with reference to the accompanying drawings.

[0037] Referring to FIG. 1, the embodiment of the present application provides a network security testing method, and the network security testing method of the embodiment of the present application can be applied to a terminal. The network security testing method of the embodiment of the present application can include, but is not limited to:

[0038] In step S101, a test scene simulation instruction is acquired, and a target simulation operation and a target controlled device are determined according to the test scene simulation instruction;

[0039] In step S102, the target simulation operation is performed on the target network device through the target controlled device, and a network security testing scene is built.

[0040] In step S103, the target network corresponding to the target network device is tested based on the network security testing scene, and a security test report of the target network under the network security testing scene is obtained.

[0041] Via the network security testing method provided by the steps S101 to S103 of the embodiment of the present application, first, a test scene simulation instruction is acquired, and a target simulation operation and a target controlled device are determined according to the test scene simulation instruction; wherein the test scene simulation instruction is used to instruct the simulation building of the test scene of the target network; then, the target simulation operation is performed on the target network device through the target controlled device, and a network security testing scene is built; wherein the target network device is used to maintain the operation of the target network; further, the target network corresponding to the target network device is tested based on the network security testing scene, and a security test report of the target network under the network security testing scene is obtained. The present application can perform the target simulation operation on the target network device through the target controlled device, thereby building a network security testing scene, simulating the case that the target network is attacked by a network, and then testing the target network to help improve the network security detection and network defense capability of the target network device.

[0042] In step S101 of some embodiments, a test scenario simulation instruction is obtained, and the target simulation operation and target controlled device are determined according to the test scenario simulation instruction; wherein, the test scenario simulation instruction is used to instruct the simulated construction of a test scenario for the target network. It should be noted that the network security testing method of this application embodiment aims to simulate a network attack on the target network, and then test the target network. Therefore, the test scenario simulation instruction is used to instruct the simulated construction of a test scenario for the target network. The corresponding target simulation operation and target controlled device can be determined according to the scenario simulation instruction. It should be pointed out that the target simulation operation is the operation that needs to be performed on the target network in order to simulate a security test scenario; the target controlled device is the controlled device that performs the target simulation operation in order to simulate a security test scenario, and the target controlled device is a device used to simulate an abnormal connection to the target network.

[0043] It is understandable that there are many ways to obtain simulated commands in test scenarios. For example, they can be obtained through input devices such as keyboards, mice, and touch screens, or through wired or wireless data transmission.

[0044] Referring to Figure 2, according to some embodiments provided in this application, obtaining the test scenario simulation instruction in step S101 may include, but is not limited to:

[0045] Step S201: Display the configuration operation interface;

[0046] Step S202: In response to the input from the target object on the configuration operation interface, obtain the scene simulation configuration parameters;

[0047] Step S203: Based on the scenario simulation configuration parameters, generate test scenario simulation instructions for the target network.

[0048] In some embodiments of this application, steps S201 to S203 can be used to first display a configuration operation interface, and then, in response to the input from the target object on the configuration operation interface, obtain scenario simulation configuration parameters. Based on the scenario simulation configuration parameters, a test scenario simulation command for the target network can be generated. It should be noted that the target object can refer to a user who initiates a security test scenario simulation for the target network. It should be clarified that a user interface (UI) is the interface for communication and interaction between a person and a computer system; it includes the screen, pages, and controls and visual elements that the user can see and interact with the system. It should be understood that the configuration operation interface is a user interface used to receive input from the target object.

[0049] In some embodiments of this application, the target object can be input in the configuration operation interface. By specifying the type of target simulation operation, the target controlled device participating in the scenario simulation, the number of target controlled devices, and the time interval of the scenario simulation or other types of scenario simulation configuration parameters, test scenario simulation instructions for the target network are generated.

[0050] As illustrated in steps S201 to S203, scenario simulation configuration parameters can be obtained through a configuration interface, and then test scenario simulation instructions for the target network can be generated based on these parameters. This provides a convenient reference benchmark for building network security test scenarios, contributing to the efficient implementation of network security testing methods.

[0051] In some other embodiments, after obtaining the security test report of the target network in the network security test scenario, it can also be displayed in the user interface for evaluation and analysis of the results of this security test scenario simulation.

[0052] Referring to Figure 3, according to some embodiments provided in this application, the step S101 of determining the target simulation operation and the target controlled device based on the test scenario simulation command may include, but is not limited to:

[0053] Step S301: Based on the test scenario simulation instructions, determine the controlled device identification information and controlled device operation information that match the network security test scenario;

[0054] Step S302: Determine the target controlled device for building the network security test scenario from the target network based on the controlled device identification information;

[0055] Step S303: Based on the controlled device operation information, determine the target simulated operation performed by the target controlled device in the network security test scenario from the target network operation data.

[0056] It should be noted that the test scenario simulation command is used to instruct the simulation setup of a test scenario for the target network. This can include information such as the type of target simulation operation, the target controlled devices participating in the scenario simulation, the number of target controlled devices, and the time interval for the scenario simulation. Based on the test scenario simulation command, the controlled device identification information and controlled device operation information matching the network security test scenario can be determined. The controlled device identification information is a unique identifier for the target controlled device. When the controlled device identification information matches the network security test scenario, the target controlled device pointed to by that identification information in the target network is used to participate in the simulation setup of the network security test scenario. The controlled device operation information is used to configure the target simulation operations that the target controlled device needs to perform. Therefore, based on the controlled device operation information, it can be determined that the target controlled device is the target simulation operation to be performed in the simulated network security test scenario.

[0057] In this way, through the steps shown in steps S301 to S303, the target controlled device that needs to participate in the simulated network security test scenario can be clearly identified, as well as the target simulated operation that the target controlled device needs to perform, which helps to efficiently build the network security test scenario.

[0058] Referring to Figure 4, according to some embodiments provided in this application, the test scenario simulation instruction includes scenario simulation type information, device configuration parameters, and operation simulation frequency. Step S301 determines the controlled device identification information and controlled device operation information matching the network security test scenario based on the test scenario simulation instruction, which may include, but is not limited to:

[0059] Step S401: Determine the simulation scenario mode corresponding to the test scenario simulation instruction based on the scenario simulation type information in the test scenario simulation instruction;

[0060] Step S402: Based on the simulation scenario method and operation simulation frequency, obtain the controlled device identification information and controlled device operation information that match the device configuration parameters from the scenario database.

[0061] It should be noted that the test scenario simulation instruction includes scenario simulation type information, device configuration parameters, and operation simulation frequency. The scenario simulation type information indicates the type of network security test scenario to be simulated; the device configuration parameters refer to the configuration parameters of the target controlled device; and the operation simulation frequency corresponds to the frequency at which the target controlled device performs the target simulated operation. The shorter the time interval between two target simulated operations, the higher the operation simulation frequency. Based on this, in this embodiment, the simulation scenario mode corresponding to the test scenario simulation instruction can be determined based on the scenario simulation type information in the test scenario simulation instruction, thereby determining the mode in which the target controlled device performs the target simulated operation. Then, based on the simulation scenario mode and operation simulation frequency, controlled device identification information and controlled device operation information matching the device configuration parameters are obtained from the scenario database. The controlled device identification information is used to clarify which target controlled devices need to perform the target simulated operation, and the controlled device operation information is used to clarify the operation that the target controlled device needs to perform and the corresponding operation frequency. The scenario database refers to a pre-set database used to store various device identification information and device operation information. Each type of network security test scenario stores corresponding device identification information and device operation information in the scenario database. Therefore, based on the simulation scenario method and operation simulation frequency, the controlled device identification information and controlled device operation information that match the device configuration parameters can be obtained from the scenario database.

[0062] Through the embodiments shown in steps S401 to S402, based on the scenario simulation type information, device configuration parameters, and operation simulation frequency in the test scenario simulation command, the controlled device identification information matching the device configuration parameters is obtained. The method by which the target controlled device performs the target simulation operation is determined, resulting in a simulation scenario mode. Furthermore, based on the simulation scenario mode and operation simulation frequency, corresponding controlled device operation information is configured for the controlled device identification information. In this way, the test scenario simulation command can be explicitly transformed into a command to directly control the target controlled device, enabling the target controlled device to perform target simulation operations on the target network device, thereby building a network security test scenario to simulate a network attack on the target network.

[0063] In some embodiments, step S102 involves performing target simulation operations on a target network device using a target controlled device to establish a network security test scenario; wherein the target network device is used to maintain the operation of the target network. It should be noted that the target network is the network used as the test target, and the target network is maintained and operated by the target network device. In some embodiments, the target network device, as the operating and maintenance device of the target network, is responsible for the transmission and reception of wireless signals, resource management, mobility management, connection establishment and maintenance, data transmission, signal coverage, quality control, security control, billing and authentication, network operation support, emergency services, and network function integration in the target network, ensuring that users of the target network can obtain stable, secure, and efficient communication services. In this application embodiment, performing target simulation operations on the target network device using a target controlled device aims to interfere with the target network device's role in maintaining the target network, thereby establishing a network security test scenario to simulate a network attack on the target network. It should be understood that the target network device can be a base station responsible for providing wireless access, managing wireless resources, supporting mobility, and ensuring data transmission and communication quality.

[0064] In some embodiments provided in this application, the types of network security testing scenarios are diverse, including but not limited to connection request overload, connection resource exhaustion, and simulated abnormal data messages. It should be noted that connection request overload, connection resource exhaustion, and simulated abnormal data messages can all be used to simulate denial-of-service (DoS) attacks against wireless communication networks. They exhaust network resources in different ways, causing legitimate users of the target network to be unable to obtain the services they need.

[0065] Connection request overload, also known as a flooding attack, is an attack method that overwhelms network or system resources by sending a large amount of traffic or requests to network devices. The goal of this type of network attack is to render network services unavailable, as it exhausts bandwidth, processing power, or storage space. In wireless networks, connection request overload may target base stations or the core network by sending a large number of meaningless signals or data packets.

[0066] Connection resource exhaustion. This type of cyberattack focuses on depleting the Radio Resource Control (RRC) connection resources in a wireless communication network. RRC connections are a critical component of the 3GPP standard used to manage communication between user equipment and the network, responsible for the transmission of signaling and control information. Attackers send a large number of RRC connection requests without completing the connection establishment process, causing the base station to continuously allocate resources for these incomplete connections, eventually exhausting the RRC connection resources and preventing legitimate users from establishing new RRC connections.

[0067] Abnormal data packets are simulated messages. These involve sending malformed or anomalous data packets to the network. These packets may be of incorrect length, of unknown type, or contain illegal information. Base stations need to process these packets, but because they do not conform to protocol specifications, processing them consumes additional resources and may lead to errors or service interruptions. Attackers may exploit this to launch attacks, sending a large number of abnormal packets to overwhelm the base station's processing capacity and thus disrupt normal service.

[0068] These three network attack methods aim to overload network resources and affect the normal operation of the network through different means. The network security testing method of this application embodiment can test the performance of the target network in the above three network security testing scenarios, thereby obtaining the corresponding security test report of the target network in the network security testing scenarios, so as to take corresponding security measures, such as enhancing network monitoring, implementing traffic filtering, and optimizing resource management, to defend against these network attacks and protect the stability and reliability of the target network.

[0069] In related technologies, how to effectively simulate attacks on wireless networks for testing mobile communication networks remains a challenge. This application, however, utilizes a controlled target device to perform simulated operations on target network devices, creating a network security test scenario to simulate a network attack on the target network. This allows for testing of the target network and helps improve the network security detection and defense capabilities of the target network devices.

[0070] In this embodiment of the application, to clearly illustrate how the network security testing scenario is set up, the following provides some standard protocol flows of wireless communication networks:

[0071] S1. If the target controlled device needs to establish a connection with the target network, it will initiate a random access procedure by sending a preamble sequence to the target network device.

[0072] S2. After receiving the preamble sequence, if resources permit, the target network device will send a random access response to the target controlled device, which includes uplink and downlink resource allocation information.

[0073] S3. The target controlled device uses the resources allocated in the random access response to send a connection request message to the target network device to request the establishment of a connection;

[0074] S4. After the target network device processes the connection request, if it accepts the request, it will send a connection establishment message to the target controlled device, which includes the connection configuration information.

[0075] S5. The target network device initiates integrity protection and encryption mechanisms to ensure communication security;

[0076] S6. The target network device sends an authentication request to the target controlled device, and the target controlled device replies with an authentication response. The core network then performs authentication. The core network is the central part of the target network, responsible for handling major network management and data transmission functions. As the brain of the target network, it connects the wireless access network to external networks, such as the Internet, other telecommunications networks, and the networks of various service providers.

[0077] S7. After successful authentication, the target network device sends an attach accept message to the core network, and the core network sends an attach complete message to the target controlled device.

[0078] S8. After the connection between the target controlled device and the target network is established, the target controlled device can begin to transmit data to the target network;

[0079] Throughout the standard protocol process of the aforementioned wireless communication network, communication between the target controlled device and the target network device follows strict timing and protocol specifications to ensure that the connection establishment is secure and effective. The purpose of the normal connection process is to ensure that the target controlled device can successfully access the network and begin communication.

[0080] Referring to Figure 5, according to some embodiments provided in this application, when it is determined that the target simulation operation corresponds to connection request overload, the target network device can be subjected to the target simulation operation in the following manner:

[0081] Step S501: Modify the network connection memory variable of the target controlled device to set the connection acknowledgment message of the target controlled device to a rejected state;

[0082] Step S502: Re-initiate a network connection request from the target controlled device to the target network device corresponding to the test scenario simulation command, and receive the connection establishment information from the target network device in response to the network connection request;

[0083] Step S503: Based on the connection confirmation message and connection establishment information in the rejection state, control the target controlled device to refuse to reply to the connection establishment information, and return to execute to re-initiate a network connection request to the target network device corresponding to the test scenario simulation command through the target controlled device, thereby obtaining the network security test scenario.

[0084] It is important to emphasize that connection request overload is an attack method that overwhelms network or system resources by sending a large amount of traffic or requests to network devices. The purpose of this type of network attack is to render network services unavailable, as it exhausts bandwidth, processing power, or storage space. In wireless networks, connection request overload may target base stations or the core network, achieved by sending a large number of meaningless signals or data packets.

[0085] In some embodiments, step S501 modifies the network connection memory variable of the target controlled device to set the connection acknowledgment message of the target controlled device to a rejected state. It should be noted that modifying the network connection memory variable of the target controlled device to set the connection acknowledgment message of the target controlled device to a rejected state means that after the target network device sends a random access response to the target controlled device, the target controlled device will not send an acknowledgment message to complete the normal connection establishment process.

[0086] In some embodiments, the network connection memory variable of the target controlled device is modified to set the connection acknowledgment message of the target controlled device to a rejected state. This can be achieved by modifying the RRC Connection memory variable as follows: "ACK message = rejected state".

[0087] In some embodiments, steps S502 to S504 involve re-initiating a network connection request from the target controlled device to the target network device corresponding to the test scenario simulation command, and receiving connection establishment information from the target network device in response to the network connection request. Based on the connection confirmation message and connection establishment information in the rejection state, the target controlled device is controlled to refuse to reply with connection establishment information, and the process returns to re-initiating a network connection request from the target controlled device to the target network device corresponding to the test scenario simulation command, thus obtaining the network security test scenario. It should be noted that because the target controlled device initiating the network connection request has undergone modification of its network connection memory variables, it will be controlled to refuse to reply with connection establishment information based on the connection confirmation message and connection establishment information in the rejection state. Afterwards, the process returns to re-initiating a network connection request from the target controlled device to the target network device corresponding to the test scenario simulation command, thus obtaining the network security test scenario.

[0088] In some embodiments of this application, because the connection confirmation message of the target controlled device is set to a rejected state, after the target network device sends a random access response to the target controlled device, the target controlled device will not send an confirmation message to complete the normal connection establishment process. The target network device will then actively release the previously received network connection request after waiting for a period of time. Based on this, in embodiments of this application, after the target controlled device refuses to reply to the connection establishment information, it re-initiates a network connection request to the target network device. The target network device then needs to process the newly initiated network connection request while waiting to release the previous network connection request. As a result, if the number of newly initiated network connection requests exceeds the number of network connection requests waiting to be released, the target network device will enter a state of connection request overload. Based on this implementation method, embodiments of this application can construct a network security test scenario corresponding to connection request overload, so as to conduct security testing on the target network corresponding to the target network device and obtain a security test report of the target network under the network security test scenario.

[0089] In some embodiments provided in this application, the target simulated operation corresponds to connection request overload. Only when the target controlled device meets a first preset condition can the target controlled device be controlled to stop initiating network connection requests to the target network device, thus terminating the setup of the network security test scenario. It should be noted that the first preset condition is used to define that the target controlled device has met the conditions for terminating the setup of the network security test scenario. For example, if the target controlled device receives a target simulated operation stop command and determines that the first preset condition is met, it can stop initiating network connection requests to the target network device, thus terminating the setup of the network security test scenario. It should be understood that there are various embodiments in which the target controlled device meets the first preset condition, and these are not limited to the examples described above.

[0090] Through steps S501 to S504, a network security test scenario can be built to simulate the target network encountering connection request overload under the condition that the target simulated operation corresponds to connection request overload, thereby testing the target network and helping to improve the network security detection and network defense capabilities of the target network device.

[0091] Referring to Figure 6, according to some embodiments provided in this application, when it is determined that the target simulation operation corresponds to connection resource exhaustion, the target network device is subjected to the target simulation operation in the following manner:

[0092] Step S601: Modify the authentication memory variable of the target controlled device to set the authentication confirmation message of the target controlled device to a rejected state;

[0093] Step S602: Re-initiate a network connection request from the target controlled device to the target network device corresponding to the test scenario simulation command, and receive the connection establishment information from the target network device in response to the network connection request;

[0094] Step S603: Generate connection confirmation information corresponding to the connection establishment information based on the connection establishment information, and send the connection confirmation information to the target network device;

[0095] Step S604: Obtain the authentication request in response to the connection confirmation information of the target network device through the target controlled device; based on the authentication confirmation message in the rejection state, control the target controlled device to refuse to reply to the authentication request; return to execute the network connection request to the target network device to obtain the network security test scenario.

[0096] It is important to emphasize that connection resource exhaustion is a type of network attack that focuses on depleting the Radio Resource Control (RRC) connection resources in a wireless communication network. RRC connections are a critical component of the 3GPP standard used to manage communication between user equipment and the network, responsible for the transmission of signaling and control information. Attackers send a large number of RRC connection requests without completing the connection establishment process, causing the base station to continuously allocate resources for these incomplete connections, ultimately exhausting the RRC connection resources and preventing legitimate users from establishing new RRC connections.

[0097] In some embodiments, step S601 modifies the authentication memory variable of the target controlled device to set the authentication confirmation message of the target controlled device to a rejected state. It should be noted that modifying the authentication memory variable of the target controlled device to set the authentication confirmation message of the target controlled device to a rejected state means that after the target network device sends an authentication request to the target controlled device, the target controlled device will, based on the rejected authentication confirmation message, control the target controlled device to refuse to reply to the authentication request, thereby not sending an authentication response to the core network of the target network to complete authentication.

[0098] In some embodiments, the authentication memory variable of the target controlled device is modified to set the authentication acknowledgment message of the target controlled device to a rejected state. This can be achieved by modifying the Authentication memory variable as follows: "ACK message = rejected state".

[0099] In some embodiments, steps S602 to S604 involve re-initiating a network connection request from the target controlled device to the target network device corresponding to the test scenario simulation command, receiving connection establishment information from the target network device in response to the network connection request, generating connection confirmation information corresponding to the connection establishment information based on the connection establishment information, and sending the connection confirmation information to the target network device. This means that a connection has been established between the target controlled device and the target network device. Based on this, the target controlled device further obtains the authentication request from the target network device in response to the connection confirmation information, and, based on the authentication confirmation message in a rejected state, controls the target controlled device to refuse to reply to the authentication request, returning to initiating a network connection request to the target network device, thus obtaining the network security test scenario. It should be noted that, since the target controlled device initiating the network connection request has modified its authentication memory variables, after obtaining the authentication request, and after the target network device sends the authentication request to the target controlled device, the target controlled device will refuse to reply to the authentication request based on the authentication confirmation message in a rejected state. After that, it will return to execute and re-initiate a network connection request to the target network device corresponding to the test scenario simulation command through the target controlled device, thus obtaining the network security test scenario.

[0100] In some embodiments of this application, because the authentication confirmation message of the target controlled device is set to a rejected state, after a connection is established between the target controlled device and the target network device, the target network device sends an authentication request to the target controlled device. However, the target controlled device, based on the rejected authentication confirmation message, refuses to reply to the authentication request and cannot complete the normal authentication process. After waiting for a period of time, the target network device will actively release the connection previously established with the network controlled device. Based on this, in the embodiments of this application, after the target controlled device refuses to reply to the authentication request, it re-initiates a network connection request to the target network device to establish a new connection. The target network device then needs to process the newly initiated network connection request while waiting to release the previous connection to establish a new connection. As a result, if the number of newly established connections exceeds the number of connections waiting to be released, the target network device will enter a state of connection resource exhaustion. Based on this implementation method, the embodiments of this application can construct a network security test scenario corresponding to connection resource exhaustion, so as to conduct security testing on the target network corresponding to the target network device and obtain a security test report of the target network under the network security test scenario.

[0101] In some embodiments provided in this application, the target simulated operation corresponds to the exhaustion of connection resources. Only when the target controlled device meets a second preset condition can the target controlled device be controlled to stop initiating network connection requests to the target network device, thus terminating the setup of the network security test scenario. It should be noted that the second preset condition is used to define whether the target controlled device has met the conditions for terminating the setup of the network security test scenario. For example, if the target controlled device receives a target simulated operation stop command and determines that the second preset condition is met, it can stop initiating network connection requests to the target network device, thus terminating the setup of the network security test scenario. It should be understood that there are various embodiments in which the target controlled device meets the second preset condition, and these are not limited to the examples described above.

[0102] Through steps S601 to S604, a network security test scenario can be built to simulate the situation where the target network encounters a situation where connection resources are exhausted, thereby testing the target network and helping to improve the network security detection and network defense capabilities of the target network devices.

[0103] Referring to Figure 7, according to some embodiments provided in this application, if a first number of target controlled devices initiate network connection requests in the same request time slot, step S602 re-initiates a network connection request through the target controlled devices to the target network device corresponding to the test scenario simulation command, and receives connection establishment information from the target network device in response to the network connection request. This may include, but is not limited to:

[0104] Step S701: For the first number of target controlled devices after modifying the authentication memory variables, determine the preamble sequence of each target controlled device in the request time slot, so that the preamble sequence corresponding to each target controlled device is different.

[0105] In step S702, each target controlled device initiates a network connection request to the target network device based on the corresponding preamble sequence.

[0106] It should be noted that, in this embodiment, since the first number of target controlled devices initiate network connection requests within the same request time slot, conflicts and resource contention may occur among these target controlled devices. It should be understood that a request time slot refers to the time period during which a target controlled device initiates a network connection request.

[0107] Based on this, steps S701 to S702 require determining the preamble sequence for each of the first number of target controlled devices after modifying the authentication memory variables, ensuring that the preamble sequence for each target controlled device is unique. Furthermore, each target controlled device initiates a network connection request to the target network device based on its corresponding preamble sequence. This improves the success rate of concurrent random access attempts by multiple target controlled devices, preventing conflicts and resource contention caused by multiple target controlled devices using the same preamble sequence.

[0108] Referring to Figure 8, according to some embodiments provided in this application, step S701, for the first number of target controlled devices after modifying the authentication memory variable, determines the preamble sequence of each target controlled device in the requested time slot, which may include, but is not limited to:

[0109] Step S801: Obtain a sequence index set including a second number of leader sequence indices; wherein, the leader sequence index is used to query candidate leader sequences;

[0110] Step S802: Determine the device number corresponding to each target controlled device from the first number of target controlled devices;

[0111] Step S803: For each target controlled device, perform a modulo operation based on the device number and the second number to obtain the index number. Based on the index number, select the corresponding leader sequence index from the sequence index set, and configure the corresponding leader sequence for the target controlled device from the candidate leader sequences according to the leader sequence index.

[0112] It should be noted that, for the first number of target controlled devices after modifying the authentication memory variables, the preamble sequence index is used to determine the preamble sequence of each target controlled device in the request slot, ensuring that the preamble sequence corresponding to each target controlled device is unique. Specifically, for the first number of target controlled devices initiating network connection requests in the same request slot, the unique preamble sequence index PreambleIndex corresponding to each target controlled device is calculated, which can be expressed as: PreambleIndex = (Count[Slot] + 1) mod PreambleID

[0113] Here, Slot represents the slot number of the requested slot, and each Slot has a unique sequence number.

[0114] Count[Slot] is used to record the number of UEs that send random access requests (Msg1) on a specific slot. This counter starts from 0 and counts independently for each slot to ensure that each device uses a different preamble sequence index under the same request slot.

[0115] PreambleID represents the set of available leader sequence indices. The leader sequence index ranges from 0 to the total number of leader sequences, i.e., the second number.

[0116] By determining the preamble sequence index for each target controlled device in the requested time slot, it is possible to ensure that each target controlled device obtains a unique preamble sequence index even under high load conditions. Based on this, the embodiments of this application improve the success rate of contention-based access when multiple target controlled devices simultaneously initiate random access, and avoid multiple target controlled devices using the same preamble sequence, which could lead to conflicts and resource contention.

[0117] Referring to FIG9, according to some embodiments provided in this application, when it is determined that the target simulation operation corresponds to an abnormal data simulation packet, the target simulation operation is performed on the target network device in the following manner:

[0118] Step S901: Modify the channel memory variable of the target controlled device to set the channel transmission message of the target controlled device to an abnormal state;

[0119] Step S902: Re-establish connection between the target controlled device and the target network device corresponding to the test scenario simulation command; wherein, the data transmission between the target controlled device and the target network device is constrained by the data transmission protocol;

[0120] Step S903: Based on the channel transmission message in the abnormal state, generate simulated transmission data that does not conform to the data transmission protocol, and send the simulated transmission data to the target network device with which the connection has been established through the target controlled device, so that the target network device will identify the simulated transmission data as abnormal data and discard it, and return to execute the channel transmission message based on the abnormal state to generate simulated transmission data that does not conform to the data transmission protocol, thus obtaining the network security test scenario.

[0121] It is important to emphasize that abnormal data packet simulation involves sending malformed or anomalous data packets to the network. These anomalous data packets may be of incorrect length, of unknown type, or contain illegal information. Base stations need to process these packets, but because they do not conform to protocol specifications, processing consumes additional resources and may lead to errors or service interruptions. Attackers could exploit this to launch attacks, sending a large number of abnormal packets to overwhelm the base station's processing capacity, thereby affecting normal service.

[0122] In some embodiments, step S901 modifies the channel memory variable of the target controlled device to set the channel transmission message of the target controlled device to an abnormal state. It should be noted that modifying the channel memory variable of the target controlled device to set the channel transmission message of the target controlled device to a rejected state means that after the target controlled device establishes a connection with the target network device, the target controlled device will send simulated transmission data to the established target network device and send simulated transmission data to the target network device, thereby affecting the normal service of the target network.

[0123] In some embodiments, modifying the channel memory variable of the target controlled device to set the channel transmission packets of the target controlled device to an abnormal state can be achieved by modifying the SRB1 memory variable as follows: "DATA packet = Abnormal state". Here, SRB1 (Signaling Radio Bearer 1) is a radio bearer defined in the 3GPP standard for carrying signaling. When the SRB1 memory variable is modified to "DATA packet = Abnormal state", the target network device will recognize the abnormal length of the SRB1 channel packets and discard them.

[0124] In some embodiments, steps S902 to S903 involve re-establishing a connection between the target controlled device and the target network device corresponding to the test scenario simulation command; wherein, data transmission between the target controlled device and the target network device is constrained by a data transmission protocol. Further, after the connection is established between the target controlled device and the target network device, simulated transmission data that does not conform to the data transmission protocol is generated based on the channel transmission message in the abnormal state. This simulated transmission data is then sent from the target controlled device to the established target network device, causing the target network device to identify the simulated transmission data as abnormal data and discard it. The target network device then returns to execute the channel transmission message based on the abnormal state to generate simulated transmission data that does not conform to the data transmission protocol, thus obtaining the network security test scenario.

[0125] It should be noted that, because the target controlled device initiating the network connection request has modified its channel memory variables, after establishing a connection with the target network device, the target controlled device sends simulated transmission data to and from the target network device, causing the target network device to identify the simulated transmission data as abnormal and discard it. Subsequently, a new connection will be established between the target controlled device and the target network device corresponding to the test scenario simulation command, thus obtaining the network security test scenario.

[0126] In some embodiments of this application, since the channel transmission messages of the target controlled device are set to an abnormal state, simulated transmission data that does not conform to the data transmission protocol can be generated based on the abnormal channel transmission messages after a connection is established between the target controlled device and the target network device. Furthermore, the target controlled device sends the simulated transmission data to the target network device with the established connection. It should be emphasized that data transmission between the target controlled device and the target network device is constrained by the data transmission protocol. Therefore, if the target network device receives simulated transmission data that does not conform to the data transmission protocol, it will identify it as abnormal data and discard it, failing to complete the normal data transmission process. Subsequently, the target controlled device repeatedly generates simulated transmission data that does not conform to the data transmission protocol based on the abnormal channel transmission messages and sends the simulated transmission data to the target network device with the established connection. The target network device receives simulated transmission data that does not conform to the data transmission protocol from the target controlled device for a long time, requiring frequent processing of the simulated transmission data as abnormal data, thus wasting a large amount of network resources in the target network device. Based on this implementation method, the embodiments of this application can build a network security test scenario corresponding to the abnormal data simulation message, so as to conduct security tests on the target network device and the target network, and obtain a security test report of the target network under the network security test scenario.

[0127] In some embodiments provided in this application, the target simulated operation corresponds to an abnormal data simulation message. Only when the target controlled device meets a third preset condition can the target controlled device be controlled to stop sending simulated transmission data to the target network device, thus terminating the setup of the network security test scenario. It should be noted that the third preset condition is used to define whether the target controlled device has met the conditions for terminating the setup of the network security test scenario. For example, if the target controlled device receives a target simulated operation stop command and determines that the third preset condition is met, it can stop sending simulated transmission data to the target network device, thus terminating the setup of the network security test scenario. It should be understood that there are various embodiments in which the target controlled device meets the third preset condition, and these are not limited to the examples described above.

[0128] Referring to Figure 10A, according to some embodiments provided in this application, the simulated transmission data includes a message length identifier bit and a logical channel identifier bit. The generation of simulated transmission data that does not conform to the data transmission protocol in step S903 may include, but is not limited to:

[0129] Step S1001: Determine the first constraint condition for the message length identifier bit and the second constraint condition for the logical channel identifier bit in the data transmission protocol;

[0130] Step S1002: Generate simulated transmission data such that the simulated transmission data does not satisfy the first constraint condition in the message length identifier bit, or such that the simulated transmission data satisfies the second constraint condition in the logical channel identifier bit.

[0131] It should be noted that in wireless communication networks, a MAC PDU (Medium Access Control Protocol Data Unit) is a unit for transmitting data between the MAC layer and the physical layer. In this embodiment, the simulated transmission data can be a MAC PDU message. It should be pointed out that the L bit (Length field) and LCID (Logical Channel ID) in the MAC PDU message are two key fields. The L bit can be a message length identifier for the simulated transmission data, and the LCID can be a logical channel identifier for the simulated transmission data. The data transmission protocol can be the transmission protocol followed when transmitting data using MAC PDU messages.

[0132] It should be clarified that the L bit is a field in the MAC PDU message used to indicate the length of the MAC PDU message. The value of the L bit represents the length of the payload (i.e., user data or control information) in the MAC PDU message, and the unit is usually bytes or bits, depending on the context. In some protocols, the maximum value of the L bit may be limited. For example, in LTE, the maximum value of the L bit is usually 65535, which means that the payload length of the MAC PDU message cannot exceed this value.

[0133] Referring to Figure 10B, a normal SRB1 channel MAC PDU message is shown. The reserved bits indicate the length (L), meaning certain bits in the MAC PDU message are reserved to indicate the number of bits occupied by the L bits (length field). The Logical Channel ID (LCID) is used to identify the logical channel to which the MAC PDU message belongs. The normal value of LCID is 1, corresponding to SRB1 (Signaling Radio Bearer 1), used to carry control signaling. When LCID is set to an abnormal value, the target network device will identify and discard these abnormal data packets.

[0134] Referring to Figure 10C, an abnormal SRB1 channel MAC PDU message is shown. The reserved bits indicating L-bit length refer to the reserved bits in the MAC PDU message used to indicate the length of the L-bit. The normal range for LCID is 0 to 32, which is the LCID value range specified by the 3GPP standard. MTU (Maximum Transmission Unit) is the maximum data unit size that the network layer can process. In the MAC PDU message, the length of the L-bit should match the MTU size to ensure effective data transmission.

[0135] Based on this, the L bit of the MAC PDU message corresponds to the message length constraint in the data transmission protocol, and can be the first constraint.

[0136] It's important to clarify that LCID is a field in a MAC PDU message used to identify logical channels. In wireless communication, a physical channel can carry data from multiple logical channels. The LCID field distinguishes between different logical channels, ensuring data is correctly delivered to the target channel. Logical channels are divided into control channels (such as SRB1) and data channels (such as DRB). LCID helps differentiate between these different types of channels. LCID values ​​typically range from 0 to 31, allowing for a maximum of 32 logical channels. Different LCID values ​​correspond to different logical channels and different Quality of Service (QoS) requirements.

[0137] Referring to Figure 10D, a typical MAC PDU message is shown. Reserved bits indicate the L-bit length; these bits are reserved to indicate the L-bit length, i.e., the effective payload length of the message. The Logical Channel ID (LCID) identifies the logical channel to which the MAC PDU message belongs. The normal range for LCID is 0 to 32, which corresponds to the range of logical channel IDs defined in the 3GPP standard. MTU defines the maximum packet size that the network layer can process; common MTU values ​​are 1400 or 1500 bytes.

[0138] Referring to Figure 10E, an abnormal MAC PDU message is shown. The reserved bit indicates the L-bit length, i.e., the effective payload length of the message. Since the LCID value ranges from 0 to 32 in the 3GPP standard, 50 is an abnormal value for the LCID. The target network device will recognize and discard such a message. An abnormal value for the L bit is set to 65535, which far exceeds the normal MTU size and is a non-compliant length value, causing the base station to discard the message.

[0139] Based on this, the LCID value of the MAC PDU message corresponds to the constraint of the number of logical channels in the data transmission protocol, and can be the second constraint.

[0140] Furthermore, generating simulated transmission data such that the simulated transmission data exceeds 65535 in the L bit can determine that the simulated transmission data does not meet the first constraint condition in the message length identifier bit; or, generating simulated transmission data such that the simulated transmission data has a value of 50 in the LCID bit can determine that the simulated transmission data meets the second constraint condition in the logical channel identifier bit.

[0141] In some other embodiments, sending simulated transmission data from the target controlled device to the target network device establishing the connection can be achieved by filling the LCID in the MAC PDU packet with an error. If the target controlled device fills the LCID in the MAC PDU packet with an error, the target network device will recognize the abnormal data packet and discard it.

[0142] According to some embodiments provided in this application, step S102, which involves performing target simulation operations on the target network device through the target controlled device to build a network security test scenario, may include, but is not limited to:

[0143] After each target simulation operation is executed, the execution count corresponding to the target simulation operation is updated;

[0144] Based on the updated number of executions, generate a network security test scenario.

[0145] It should be noted that after each simulated target operation is executed, the execution count is updated. This is to record and statistically analyze the execution count, facilitating the generation of a subsequent security test report. It should be pointed out that the network security test scenario simulates a network attack on the target network; therefore, the execution count simulates the number of times the target network is attacked. Based on the updated execution count, a network security test scenario is generated, designed to simulate a network security test scenario where the target network is subjected to multiple network attacks.

[0146] According to some embodiments provided in this application, a network security test scenario can be generated based on the updated number of executions, which may include, but is not limited to:

[0147] Starting from the execution of the target simulation operation, after each preset time interval, the number of executions updated during the preset time interval is counted to obtain intermediate simulation data;

[0148] Based on the intermediate simulation data corresponding to each preset time interval, a network security test scenario is generated.

[0149] It should be noted that since the execution count is used to simulate the number of times the target network is attacked, the intermediate simulation data refers to the number of times the target network is simulated to be attacked during the preset time interval. Based on the intermediate simulation data corresponding to each preset time interval, a network security test scenario is generated. The purpose is to statistically analyze the number of simulated network attacks on the target network at preset time intervals, and obtain the network security test scenario based on this.

[0150] In some embodiments of this application, after modifying the network connection memory variable of the target controlled device to set the connection confirmation message of the target controlled device to a rejected state, an AttckTimer can be set to start timing. Then, a network connection request is re-initiated through the target controlled device to the target network device corresponding to the test scenario simulation command, and connection establishment information in response to the network connection request is received from the target network device. Further, after obtaining the connection establishment information from the target network device, based on the rejected connection confirmation message and the connection establishment information, the target controlled device is controlled to refuse to reply with connection establishment information. At this time, the execution count of the target simulation operation is incremented by 1, and then execution returns to re-initiating a network connection request through the target controlled device to the target network device corresponding to the test scenario simulation command, thus obtaining the network security test scenario. The AttckTimer counts the accumulated execution count of the current target simulation operation every certain period of time, to facilitate the generation of a security test report in subsequent steps.

[0151] In some embodiments of this application, after modifying the authentication memory variable of the target controlled device to set the authentication confirmation message of the target controlled device to a rejected state, an AttckTimer timer can be set to start timing. Then, the target controlled device with the modified authentication memory variable initiates a network connection request to the target network device corresponding to the test scenario simulation command at regular intervals; or, multiple target controlled devices with modified authentication memory variables sequentially initiate a network connection request to the target network device corresponding to the test scenario simulation command at predetermined time intervals. Further, after obtaining the authentication request sent by the target network device, based on the rejected authentication confirmation message, the target controlled device is controlled to refuse to reply to the authentication request. At this time, the execution count of the target simulation operation is incremented by 1, and then execution returns to re-initiate a network connection request to the target network device corresponding to the test scenario simulation command through the target controlled device, thus obtaining the network security test scenario. The AttckTimer timer counts the current accumulated execution count of the target simulation operation at regular intervals to facilitate the generation of a security test report in subsequent steps.

[0152] In some embodiments, step S103 involves performing security tests on the target network device and its corresponding target network based on a network security testing scenario, thereby obtaining a security test report for the target network under the network security testing scenario. It should be noted that security testing of the target network can only be conducted after the network security testing scenario has been established, thus obtaining a security test report for the target network under the network security testing scenario to test the target network's performance under network attack conditions. By performing target simulation operations on the target network device through a controlled target device, a network security testing scenario is established to simulate network attacks on the target network, thereby testing the target network and helping to improve the network security detection and defense capabilities of the target network device.

[0153] Referring to Figure 11A, in some embodiments, the terminal used in the network security testing method of this application may include, but is not limited to, an operating interface, a scheduling processing component, a baseband processing component, and a mid-frequency radio frequency (RF) unit. The scheduling processing component includes a simulated attack module and a scheduling processing module.

[0154] The user interface plays a crucial role as the primary medium for interaction between the target object and the system. The target object can be configured in various ways through the user interface, including setting target simulation operations, specifying the number of controlled devices initiating the target simulation operations, and setting the time interval for these controlled devices to execute the target simulation operations. Furthermore, the user interface can also be used to display security test reports after the test is completed; these reports are essential for evaluating and analyzing the test results.

[0155] The simulated attack module is responsible for receiving configuration parameters from the operation interface, setting different attack simulation strategies based on these parameters, generating corresponding instructions, and sending them to the scheduling and processing module to initiate the process of building a network security test scenario.

[0156] The scheduling and processing module can schedule the baseband processing component according to the standard algorithm strategy of the communication protocol to complete the uplink and downlink data interaction. In the embodiments of this application, the main function of the scheduling and processing module is to receive simulated attack data from the simulated attack module, change the standard communication protocol process according to these instructions, and instruct the baseband processing component to control the target controlled device to perform the target simulated operation.

[0157] Referring to Figure 11B, the scheduling processing module can consist of several sub-modules, including UEM (Target Controlled Device Management), CPS (Signaling Control Platform), SPS (Service Scheduling Platform), and UPS (Service Data Platform). In some embodiments, the UEM sub-module can be used to control the access process of the target controlled device; the CPS and SPS sub-modules can be used to simulate connection request overload and connection resource exhaustion; and the UPS sub-module can be used to simulate abnormal data packets by initiating SRB1 channel abnormal packet and malformed data packet attacks.

[0158] The above modules and components work together to form a system that can simulate network security testing scenarios in network security testing methods. This system aims to improve the security protection capabilities of target networks and detect and defend against potential security threats by simulating network attacks on target networks.

[0159] According to some embodiments provided in this application, during normal communication, after successfully receiving an RRC Connection Request message from the target controlled device, the gNodeB (the target network device in a 5G wireless network) will send an RRC Connection Establishment message to the device and start a waiting timer to wait for the device to reply with an RRC Connection Complete message. If the target controlled device does not reply before the timer expires, the target network device will release the device.

[0160] In Flooding Attack mode (corresponding to connection request overload), the simulated attack module exploits this mechanism by configuring the target controlled device to not send the RRC Connection Complete message before the RRC Connection wait timer expires, but instead continuously and frequently initiate Random Access procedures, i.e., random access requests. This causes the gNodeB to frequently respond to these fake access requests, thereby reducing the opportunities for access to other legitimate target controlled devices, ultimately creating a connection request overload.

[0161] In some embodiments, firstly, the Flooding Attack mode is set on the operation interface of the test terminal. Then, the number of target controlled devices initiating access requests is configured to be 1. After receiving the Flooding Attack mode instruction, the simulated attack module begins to execute the attack: it sends the configured number of target controlled devices and related context information to the device management platform module. It sends the Flooding Attack instruction to the signaling control platform module, which modifies the RRC Connection memory variable, sets the ACK packet to a rejection state, and starts a timer AttckTimer with a duration of 1 second. The signaling control platform module initiates the Attach procedure for the target controlled device. Once the RRC connection is established, the module determines whether the ACK packet is in a rejection state. If so, it enters the abnormal packet procedure, increments the attack result count AttackNum by 1, and then re-initiates the Attach procedure. When the AttckTimer expires, the signaling control platform module automatically triggers, feeding back AttackNum to the simulated attack module, which then organizes and summarizes the results and stores them in a fixed directory on the test device. Finally, the user clicks the "Stop Attack Test" button on the test terminal's interface to end the attack and download the attack result report.

[0162] This process can simulate a target network experiencing an overload of connection requests, thereby helping to detect and defend against such attacks.

[0163] According to some embodiments provided in this application, the process of establishing and releasing an RRC connection in a wireless communication protocol is utilized. Under normal circumstances, after a target controlled device successfully establishes an RRC connection, it replies to the gNodeB with an RRC Connection Complete message containing the IMSI (International Mobile Subscriber Identity). Upon receiving this message, the gNodeB sends the relevant information to the core network and requests authentication from the target controlled device. The core network then starts a timer T3560 (default value is 5 seconds) to wait for the target controlled device to send an authentication response. If the target controlled device does not send an authentication response before the timer expires, the core network will instruct the target network device to release the RRC connection.

[0164] In the Deplete RRC Res Attack mode (corresponding to connection resource exhaustion), the simulated attack module instructs the target controlled device not to send an authentication response after receiving an authentication request, but instead to re-initiate the random access procedure. This frequently triggers the establishment and release of RRC connections during the operation of timer T3560. If the number of newly established RRC connections exceeds the number of released connections, and multiple target controlled devices perform this operation for an extended period, eventually exhausting the RRC connection resources, thus simulating connection resource exhaustion.

[0165] In some embodiments, firstly, the Deplete RRC Res Attack mode is set on the operation interface, and the number of target controlled devices, IMSI, and the time interval for initiating Attach are configured. Upon receiving the attack mode instruction, the simulated attack module begins executing the scenario simulation process. It first sends configuration information to the device management platform module, then sends an attack instruction to the signaling control platform module, modifies the authentication response to a denial state, and starts the timer AttckTimer. The signaling control platform module initiates the Attach process for the target controlled devices according to the configuration. When the target controlled device receives an authentication request, due to the denial state, it will not send an authentication response, but will instead increment the attack result count AttackNum and then re-initiate the Attach process. When the timer AttckTimer expires, the signaling control platform module feeds back AttackNum to the simulated attack module, which then compiles and summarizes the results and stores them in a fixed directory on the test device. Finally, the user clicks the "Stop Attack Test" button on the operation interface to end the current attack and download the attack result report.

[0166] This process can simulate a target network encountering connection resource exhaustion, helping to detect and improve the target network devices' defense capabilities against such attacks.

[0167] According to some embodiments provided in this application, based on the specifications of MAC PDU (Medium Access Control Protocol Data Unit) messages in wireless communication protocols, the length of the L bit (length field) must be less than 65535, and the LCID (Logical Channel ID) bit must be between 0 and 32. By simulating abnormal data packets in this way, the target controlled device will intentionally send MAC PDU messages with the LCID set to 1 and the L bit field abnormally filled, causing the target network device to recognize and discard the abnormal SRB1 (Signaling Radio Bearer 1) channel message length. Similarly, if the target controlled device fills the LCID in the MAC PDU message with an abnormal value, the target network device will also recognize and discard these abnormal data packets.

[0168] The purpose of the attack is that if the target controlled device sends such abnormal data for an extended period of time, the target network device will have to respond to these abnormal messages frequently, thus failing to provide normal services to other users, resulting in a significant waste of network resources and achieving the goal of denial of service.

[0169] In some embodiments, firstly, the terminal device triggers the target controlled device to access the network normally and begins FTP file copying, transmitting uplink services according to the frame structure period scheduled by the gNodeB. Taking TDD standard and 2.5ms dual-period frame structure as an example, the target controlled device will send uplink SRB data in a specific uplink slot. Next, the simulated attack module initiates the attack after receiving the SRB1 abnormal data attack mode instruction. It sends the SRB1 abnormal data attack instruction to the service data platform module. After receiving the instruction, the service data platform module modifies the SRB1 memory variable to an abnormal state and starts a timer AttckTimer for 1 second. Then, the target controlled device packages the service data of the specific slot into SRB1 channel data and modifies the L bit in the MAC PDU data to the abnormal value 65535. The target network device will discard these abnormally long packets, and the data transmission frequency is approximately 1000ms divided by SlotU (the number of uplink slots). After receiving the malformed data packet attack mode instruction, the simulated attack module initiates the attack again. It sends a malformed data packet attack command to the business data platform module, which modifies the DATA memory variable to an abnormal state and restarts the AttckTimer. During the scenario simulation, the test device changes the business data of the uplink air interface slot to abnormal MAC packet data, fills in the LCID outside the protocol requirements, and maintains the same data transmission frequency as before. When it is necessary to end the attack, the user clicks the "Stop Attack Test" button on the test terminal's operation interface. Finally, the user can download the attack result report, which is successfully exported in Excel format.

[0170] This process can simulate abnormal data packets encountered by the target network, helping to detect and improve the target network devices' defense capabilities against such attacks.

[0171] This application also provides an electronic device, as shown in FIG12, the electronic device 1200 including:

[0172] One or more processors 1210;

[0173] The memory 1220 stores one or more programs that, when executed by one or more processors 1210, enable the one or more processors 1210 to implement a network security testing method.

[0174] The memory 1220, as a non-transitory network system, can be used to store non-transitory software programs and non-transitory computer-executable programs. Furthermore, the memory 1220 may include high-speed random access memory, and may also include non-transitory memory, such as at least one disk storage device, flash memory device, or other non-transitory solid-state storage device.

[0175] In some implementations, memory 1220 may include memory 1220 remotely located relative to processor 1210, and such remote memory 1220 may be connected to processor 1210 via a network. Examples of such networks include, but are not limited to, the Internet, intranets, local area networks, mobile communication networks, and combinations thereof.

[0176] The memory 1220 can be implemented as a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM). The memory 1220 can store the operating system and other application programs. When the technical solutions provided in the embodiments of this specification are implemented through software or firmware, the relevant program code is stored in the memory 1220 and is called and executed by the processor 1210.

[0177] The processor 1210 can be implemented using a general-purpose CPU (Central Processing Unit), microprocessor, application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this application.

[0178] In some embodiments, the electronic device further includes:

[0179] Input / output interfaces are used to implement information input and output;

[0180] The communication interface is used to enable communication and interaction between this device and other devices. Communication can be achieved through wired means (such as USB, Ethernet cable, etc.) or wireless means (such as mobile network, WIFI, Bluetooth, etc.).

[0181] The bus transmits information between various components of the device (e.g., processor 1210, memory 1220, input / output interface, and communication interface);

[0182] The processor 1210, memory 1220, input / output interface, and communication interface can communicate with each other within the device via a bus.

[0183] An embodiment of this application also provides a computer-readable storage medium storing computer-executable instructions for executing a network security testing method.

[0184] An embodiment of this application also provides a computer program product, which may include, but is not limited to, a computer program or computer instructions stored in a computer-readable storage medium. The processor of a computer device reads the computer program or computer instructions from the computer-readable storage medium and executes the computer program or computer instructions, causing the computer device to perform a method for implementing network security testing.

[0185] The system architecture and application scenarios described in this application are intended to more clearly illustrate the technical solutions of this application and do not constitute a limitation on the technical solutions provided in this application. Those skilled in the art will understand that as system architectures evolve and new application scenarios emerge, the technical solutions provided in this application are also applicable to similar technical problems.

[0186] The network security testing method provided in this application first obtains a test scenario simulation instruction, and determines the target simulated operation and the target controlled device based on the test scenario simulation instruction; then, it executes the target simulated operation on the target network device through the target controlled device to build a network security test scenario; further, it performs security testing on the target network device and the corresponding target network based on the network security test scenario to obtain a security test report of the target network under the network security test scenario. This application can build a network security test scenario by executing target simulated operations on the target network device through the target controlled device, thereby simulating the situation where the target network is subjected to network attacks, and then testing the target network to help improve the network security detection and network defense capabilities of the target network device.

[0187] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments of the above methods. Any references to memory, storage, databases, or other media used in the embodiments provided in this application can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), dual data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), RAMbus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and RAMbus dynamic RAM (RDRAM), etc.

[0188] It will be understood by those skilled in the art that all or some of the steps and systems in the methods disclosed above can be implemented as software, firmware, hardware, and suitable combinations thereof. Some or all of the physical components can be implemented as software executed by a processor, such as a central processing unit, digital signal processor, or microprocessor, or as hardware, or as an integrated circuit, such as an application-specific integrated circuit. Such software can be distributed on a computer-readable medium, which can include computer storage media (or non-transitory media) and communication media (or transient media). As is known to those skilled in the art, the term computer storage media includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information (such as computer-readable instructions, data structures, program modules, or other data). Computer storage media includes, but is not limited to, RAM, ROM, EEPROM, flash memory or other memory technologies, CD-ROM, digital versatile disc (DVD) or other optical disc storage, magnetic cartridges, magnetic tape, disk storage or other magnetic storage devices, or any other medium that can be used to store desired information and is accessible to a computer. Furthermore, as is known to those skilled in the art, communication media typically contain computer-readable instructions, data structures, program modules, or other data in modulated data signals such as carrier waves or other transmission mechanisms, and may include any information delivery medium.

[0189] The above description, with reference to the accompanying drawings, illustrates some embodiments of this application, but does not limit the scope of this application. Any modifications, equivalent substitutions, and improvements made by those skilled in the art without departing from the scope and spirit of this application shall be within the scope of this application.

Claims

1. A network security testing method, the method comprising: obtaining a test scene simulation instruction, and determining a target simulation operation and a target controlled device according to the test scene simulation instruction; performing the target simulation operation on a target network device through the target controlled device to build a network security testing scene; based on the network security testing scene, performing a security test on a target network corresponding to the target network device to obtain a security test report of the target network under the network security testing scene.

2. The network security testing method of claim 1, wherein, The determination of the target simulation operation and the target controlled device according to the test scene simulation instruction comprises: determining controlled device identification information and controlled device operation information matched with the network security testing scene according to the test scene simulation instruction, wherein the test scene simulation instruction is used to simulate the building of the network security testing scene in the target network; determining the target controlled device for building the network security testing scene from the target network according to the controlled device identification information; determining the target simulation operation performed by the target controlled device in the network security testing scene from the running data of the target network according to the controlled device operation information.

3. The network security testing method of claim 2, wherein, The test scene simulation instruction comprises scene simulation type information, device configuration parameters and operation simulation frequency, and the determination of the controlled device identification information and the controlled device operation information matched with the network security testing scene according to the test scene simulation instruction comprises: determining the simulation scene mode corresponding to the test scene simulation instruction based on the scene simulation type information in the test scene simulation instruction; obtaining the controlled device identification information and the controlled device operation information matched with the device configuration parameters from a scene database according to the simulation scene mode and the operation simulation frequency.

4. The network security testing method of claim 1, wherein, The building of the network security testing scene by performing the target simulation operation on the target network device through the target controlled device comprises: determining that the target simulation operation corresponds to a connection request overload: modifying a network connection memory variable of the target controlled device to set a connection confirmation packet of the target controlled device to a rejection state; reinitiating a network connection request to the target network device corresponding to the test scene simulation instruction through the target controlled device, and receiving connection establishment information of the target network device in response to the network connection request; based on the connection confirmation packet in the rejection state and the connection establishment information, controlling the target controlled device to reject the connection establishment information, and returning to reinitiate the network connection request to the target network device corresponding to the test scene simulation instruction through the target controlled device to build the network security testing scene.

5. The cyber security testing method of claim 1, wherein, The building of the network security testing scene by performing the target simulation operation on the target network device through the target controlled device comprises: determining that the target simulation operation corresponds to a connection resource exhaustion: modifying an authentication memory variable of the target controlled device to set an authentication confirmation packet of the target controlled device to the rejection state; reinitiating a network connection request to the target network device corresponding to the test scenario simulation instruction through the target controlled device, and receiving connection establishment information of the target network device in response to the network connection request; generating connection confirmation information corresponding to the connection establishment information based on the connection establishment information, and sending the connection confirmation information to the target network device; based on the authentication confirmation message of the rejection state, controlling the target controlled device to reject the authentication request, and returning to initiate the network connection request to the target network device to build the network security test scenario.

6. The network security testing method of claim 5, wherein, There are a first number of target controlled devices initiating the network connection request in the same request time slot, and the reinitiating a network connection request to the target network device corresponding to the test scenario simulation instruction through the target controlled device comprises: For a first number of target controlled devices, determining a preamble sequence of each target controlled device in the request time slot, so that the preamble sequence corresponding to each target controlled device is different; each target controlled device initiates the network connection request to the target network device based on the corresponding preamble sequence.

7. The cyber security testing method of claim 6, wherein, The determination of the preamble sequence of each target controlled device in the request time slot for a first number of target controlled devices comprises: obtaining a sequence index set including a second number of preamble sequence indexes; wherein the preamble sequence index is used to query the candidate preamble sequence; determining the device number corresponding to each target controlled device from the first number of target controlled devices; for each target controlled device, based on the device number and the second number, an index number is obtained by modulo operation, the index number is used to select the corresponding preamble sequence index in the sequence index set, and the corresponding preamble sequence of the target controlled device is configured from the candidate preamble sequence according to the preamble sequence index.

8. The cyber security testing method of claim 1, wherein, The target controlled device performs the target simulation operation on the target network device to build a network security test scenario, comprising: determining that the target simulation operation corresponds to an abnormal data simulation message: modify the channel memory variable of the target controlled device to set the channel transmission message of the target controlled device to an abnormal state; reinitiating a connection to the target network device corresponding to the test scenario simulation instruction through the target controlled device; wherein the data transmission between the target controlled device and the target network device is constrained by a data transmission protocol; generate analog transmission data that does not conform to the data transmission protocol based on the channel transmission packet of the abnormal state, and send the analog transmission data to the target network device connected through the target controlled device, so that the target network device identifies the analog transmission data as abnormal data and discards it, and returns to execute sending the analog transmission data to the target network device connected through the target controlled device to build the network security test scene.

9. The cyber security testing method of claim 8, wherein, The analog transmission data includes a packet length identification bit and a logical channel identification bit, and the generation of the analog transmission data that does not conform to the data transmission protocol includes: determining a first constraint condition on the packet length identification bit and a second constraint condition on the logical channel identification bit in the data transmission protocol; generate the analog transmission data so that the analog transmission data does not satisfy the first constraint condition in the packet length identification bit, or so that the analog transmission data satisfies the second constraint condition in the logical channel identification bit.

10. The cyber security testing method of claim 1, wherein, The target network device is executed through the target controlled device to build a network security test scene, including: updating the execution times corresponding to the target simulation operation after each execution of the target simulation operation; generate the network security test scene based on the updated execution times.

11. The cyber security testing method of claim 10, wherein, The network security test scene is generated based on the updated execution times, including: From the execution of the target simulation operation, every time a preset time interval passes, the execution times updated during the preset time interval are counted to obtain intermediate simulation data; generate the network security test scene based on the intermediate simulation data corresponding to each preset time interval.

12. The cyber security testing method of claim 1, wherein, The test scene simulation instruction includes: display a configuration operation interface; obtain scene simulation configuration parameters in response to input of a target object on the configuration operation interface; generate the test scene simulation instruction for the target network based on the scene simulation configuration parameters.

13. An electronic device, comprising: one or more processors; a memory having one or more computer programs stored thereon, when the one or more computer programs are executed by the one or more processors, the one or more processors implement the network security test method of any one of claims 1 to 12.

14. A computer readable storage medium having a computer program stored thereon, the computer program being executed by a processor to implement the network security test method of any one of claims 1 to 12.

15. A computer program product comprising a computer program, the computer program being executed by a processor to implement the network security test method of any one of claims 1 to 12.

Citation Information

Patent Citations

  • Network security test method and device for industrial control network based on application scenario

    CN111245800A

  • Network security attack and defense drilling system and method and readable storage medium

    CN115694970A

  • Network testing method, computer equipment, network equipment and readable storage medium

    CN116886584A

  • Device virtualization and simulation of a system of things

    US20220075708A1