Security deduction method and apparatus, and network device and readable storage medium
By using digital twin networks (DTN) for attack event overlay analysis and dynamic protection configuration, the problem of inaccurate simulation in existing security simulation methods is solved, and high-precision security drills for business systems are realized in a real network environment.
Patent Information
- Application Number
- PCT/CN2025/102606
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-06-21
- Filing Date
- 2025-06-20
- Publication Date
- 2025-12-26
AI Technical Summary
Existing security simulation methods are inaccurate in simulating real network environments, failing to achieve the desired effect of security drills for business systems. Furthermore, they lack accurate consideration of intrusion time and success rate, resulting in a lack of dynamic mitigation measures in attack analysis.
By employing a digital twin network (DTN) for high-precision simulation capabilities and network management, and through the overlay analysis of attack events, the attacked entities and network states are dynamically adjusted to perform security protection configurations, thereby forming a high-precision dynamic security simulation.
It enables high-precision security drills for business systems in a real-world network environment, accurately simulating attack processes and responses, dynamically adjusting protective measures, and improving the accuracy and practicality of the simulation process.
Smart Images

Figure CN2025102606_26122025_PF_FP_ABST
Abstract
Description
Security deduction method and device, network equipment and readable storage medium
[0001] Cross-reference of related disclosures
[0002] The present disclosure is based on and claims priority from Chinese Patent Application No. 202410808617.X filed on June 21, 2024, the entire contents of which are incorporated herein by reference. TECHNICAL FIELD
[0003] The present disclosure relates to the technical field of security, in particular to a security deduction method and device, network equipment and readable storage medium. BACKGROUND
[0004] Security deduction for mobile communication networks is of great significance for grasping the current network security situation, deploying security protection measures in advance, and avoiding or mitigating attacks. Currently, the implementation of security deduction includes two key parts: the construction of a security attack and defense simulation environment and the construction of a security deduction method. For the construction of a security attack and defense simulation environment, a network target range is generally constructed. Current network target ranges are mostly constructed based on network security simulation and virtualization technology. The simulated business systems have problems such as data real-time flow lag, basic network environment limitations, single solidification of built-in attack paths and vulnerability utilization, and cannot achieve the business system defense effect similar to or equivalent to the real network environment. On the other hand, in terms of security deduction, attack prediction focuses on attack target analysis and path and probability analysis, lacking consideration of intrusion time and success rate, resulting in inaccurate deduction / simulation, lack of dynamic consideration of mitigation measures in attack analysis, and mismatch with actual scenarios such as response and regular investigation. SUMMARY
[0005] The technical solution of the present disclosure aims to provide a security deduction method, device, network equipment and readable storage medium, to solve the problem of inaccurate deduction / simulation and inability to achieve business system security simulation effect in real network environment using existing security deduction methods.
[0006] One embodiment of the present disclosure provides a security deduction method, comprising:
[0007] obtaining attack times of attack events that are successfully executed in the twin network before a first time according to network state information of the twin network and a plurality of attack events preset in advance;
[0008] determining each attacked entity corresponding to a successful attack before the first time according to the network state information and the attack times;
[0009] superimposing analysis of attack effects generated by the successful attacks on each of the attacked entities, to obtain attack evaluation information;
[0010] According to the attack evaluation information, the network state information of the twin network and / or the attack event are adjusted, and the twin network is configured for security protection.
[0011] Optionally, the security deduction method, wherein the method further comprises:
[0012] According to the twin network after the security protection configuration, and the twin network and / or the attack event after the adjustment, a security deduction process before a second time is performed until the security deduction reaches a target length of time and / or the network state information reaches a target state; wherein the second time is after the first time.
[0013] Optionally, the security deduction method, wherein according to the network state information of the twin network and the pre-set multiple attack events, the attack time of the attack event successfully attacking the twin network before the first time is obtained, including one or more of the following:
[0014] According to the network state information of the twin network and the pre-set multiple attack events, the attack time of the attack event successfully attacking the twin network before the first time is obtained by setting method;
[0015] According to the network state information of the twin network and the pre-set multiple attack events, the probability of the attack event successfully attacking the twin network before the first time is calculated, and the attack time of the attack event successfully attacking is calculated according to the probability and using a random model;
[0016] According to the network state information of the twin network and the pre-set multiple attack events, the start time of the attack event successfully attacking the twin network before the first time is obtained by setting method;
[0017] According to the network state information of the twin network and the pre-set multiple attack events, the start time of the attack event attacking the twin network before the first time is determined by using a random model;
[0018] According to the network state information of the twin network and the pre-set multiple attack events, according to the start time of the attack event attacking the twin network before the first time, the attack time of the attack event successfully attacking the twin network is determined by the running logic of the simulation attack performed by the twin network.
[0019] Optionally, the security deduction method, wherein the network state information comprises one or more of the following:
[0020] entity information;
[0021] routing information among multiple entities;
[0022] connection state information;
[0023] entity state information.
[0024] Optionally, the security deduction method, wherein the attack assessment information comprises one or more of the following:
[0025] the attack on the attacked entity comprises a data confidentiality attack;
[0026] a degree of harm of the data confidentiality attack;
[0027] the attack on the attacked entity comprises an availability attack;
[0028] a degree of harm of the availability attack;
[0029] the attack on the attacked entity comprises an enforcement control;
[0030] a control type of the enforcement control;
[0031] a degree of harm of the control type of the enforcement control.
[0032] Optionally, the security deduction method, wherein the method further comprises:
[0033] reporting the attack assessment information to a security analysis center.
[0034] Optionally, the security deduction method, wherein the adjusting of the network state information of the twin network and / or the attack event comprises one or more of the following:
[0035] in a case where the attack on the attacked entity comprises an availability attack, performing state modification on the attacked entity;
[0036] in a case where the attack on the attacked entity comprises an availability attack, determining connection state information and / or entity state information after the state modification on the attacked entity;
[0037] in a case where the attack on the attacked entity comprises an enforcement control, determining a to-be-joined attack event initiated by the attacked entity according to the control type and the degree of harm of the enforcement control, and adding the to-be-joined attack event into the multiple attack events.
[0038] Optionally, the security deduction method, wherein the security protection configuration of the twin network comprises one or more of the following:
[0039] configuring a security protection policy of the twin network;
[0040] configuring or deploying a security capability of the twin network;
[0041] updating network state information of the twin network;
[0042] updating attack parameters of the attack event.
[0043] An embodiment of the present disclosure further provides a security deduction device, comprising:
[0044] a first processing module configured to obtain attack time of successful attack of each attack event on the twin network before a first time according to network state information of the twin network and a plurality of attack events preset in advance;
[0045] a second processing module configured to determine each attacked entity corresponding to the successful attack before the first time according to the network state information and the attack time;
[0046] a third processing module configured to perform superposition analysis on attack effect of the successful attack on each of the attacked entities to obtain attack evaluation information;
[0047] a fourth processing module configured to adjust the network state information of the twin network and / or the attack event according to the attack evaluation information, and configure security protection of the twin network.
[0048] An embodiment of the present disclosure further provides a network device, comprising a processor, a memory, and a program stored in the memory and executable on the processor, wherein the program is executed by the processor to implement the security deduction method according to any one of the above.
[0049] An embodiment of the present disclosure further provides a readable storage medium, wherein the readable storage medium stores a program, and the program is executed by a processor to implement the steps of the security deduction method according to any one of the above.
[0050] An embodiment of the present disclosure further provides a computer program product, comprising computer instructions, and the computer instructions are executed by a processor to implement the steps of the security deduction method according to any one of the above.
[0051] At least one of the above technical solutions of the present disclosure has the following beneficial effects:
[0052] The security deduction method provided in the embodiments of the present disclosure utilizes the high-precision simulation capability, network management, and configuration capability of a digital twin network (DTN) for network and services to perform time sequence-based attack event superposition analysis, and dynamically adjusts the security protection configuration of the attacked entity, attack event, and network basic model on the basis of the superposition analysis, so that the deduction / simulation process is more accurate, and the effect of service system security rehearsal in a real network environment is achieved. BRIEF DESCRIPTION OF DRAWINGS
[0053] Fig. 1 is a schematic diagram of one of the DTN system architectures to which the method provided in the embodiments of the present disclosure is applied;
[0054] Fig. 2 is a flowchart of the security deduction method provided in the embodiments of the present disclosure;
[0055] Fig. 3 is a flowchart of a specific implementation of the method provided in the embodiments of the present disclosure;
[0056] Fig. 4 is a structural diagram of the security deduction apparatus provided in the embodiments of the present disclosure. DETAILED DESCRIPTION
[0057] To make the technical problems, technical solutions, and advantages to be solved by the present disclosure clearer, the following will be described in detail with reference to the accompanying drawings and specific embodiments.
[0058] To solve the problem that the security deduction method provided in the prior art is inaccurate in deduction / simulation and cannot achieve the effect of service system rehearsal in a real network environment, the present disclosure provides a security deduction method that utilizes the high-precision simulation capability, network management, and configuration capability of a digital twin network (DTN) for network and services to perform time sequence-based attack event superposition analysis, and dynamically adjusts the security protection configuration of the attacked entity, attack event, and network basic model on the basis of the superposition analysis, so that the deduction / simulation process is more accurate, and the effect of service system security rehearsal in a real network environment is achieved.
[0059] Digital twin is a real-time mirror image of a physical entity in the digital world. A DTN is a network system that has a physical network entity and a virtual twin, and the two can interact and map in real time. In this system, various network management and applications can use digital twin technology to build network twins, and based on data and models, efficiently analyze, diagnose, simulate, and control the physical network. Network twins can help physical networks achieve low-cost trial and error, intelligent decision-making, high-efficiency innovation, and predictive maintenance. At the same time, DTN can help users clearly perceive network status, efficiently mine valuable network information, and explore network innovation applications with a more friendly immersive interface through capability exposure and twin copying.
[0060] The advantages of the DTN include: the twin network element and the network can be synchronized with the live network in near real time, and the coherent relationship between the network and the service can be completely modeled; the network management capability based on the DTN can directly configure the network element state and the protection measures, has the capability of simulating the attack and defense quickly, accurately and dynamically, and has the complete live network interaction simulation capability, and based on the DTN, a plurality of network (including service and management) replicas can be formed to meet the requirement of continuous attempts of attack evaluation and deduction. Therefore, the method based on the DTN can better solve the problems in the attack simulation or attack and defense deduction, and the state can be evolved based on the transition of the attack process and the implementation of the mitigation measures, and a highly simulated deduction is formed.
[0061] As shown in FIG. 1, the DTN system architecture applied to the method of the embodiment of the present disclosure includes a physical network layer, a twin network layer and a network application layer. Optionally, the twin network layer includes a twin network and a function model, and further includes a data sharing warehouse and a network twin management model connected with the twin network and the function model respectively. Optionally, the twin network can also be referred to as a network base model or a network twin, that is, a virtual network body generated according to the physical network to be deduced.
[0062] By using the secure deduction method of the embodiment of the present disclosure, it is assumed that the DTN has been constructed, including the twin network of the physical network to be deduced, and having network management capability. Specifically, the method includes: 1) the DTN can real-time twin the network state of the network; 2) the function / whole network of the twin network is regarded as a black box, and for a determined attack input on the twin network, the DTN can give an accurate state feedback; 3) the DTN can dynamically configure the state and function of the entity, and simulate the attack and defense confrontation; 4) the DTN can deploy new protection measures, such as adding a firewall and a signaling gateway, which can not only resist attacks, but also simulate the impact on the network; and 5) the DTN can record the state of the twin network and replay it.
[0063] By using the secure deduction method of the embodiment of the present disclosure, the DTN system architecture used can further include the following models, as shown in FIG. 1.
[0064] A security attack model: the security attack model is a simulation implementation of a security attack (such as simulating a distributed denial of service attack (DDoS) attack by manufacturing a large number of service requests) and a security risk (such as deploying a module with a vulnerability and not patching or upgrading), which can simulate the attack based on a dedicated security device, a simulation instrument, traffic injection, configuration operation, etc.
[0065] The twin network can simulate the physical network to be deduced based on a virtual network element, a logical code, an intelligent model, and actual network traffic, so as to construct a network base model.
[0066] The security capability resource pool can provide security capability for the DTN.
[0067] The security brain can analyze the security attack result, the network state change reported by the DTN, and the like, derive a security risk, and recommend a security protection measure.
[0068] Optionally, the above model can be a logical entity or a functional model integrated in other network elements. For example, the security attack model, the twin network, and the security capability resource pool can be one of the models of the twin network layer, or can be logical entities capable of interacting with the twin network layer. The security brain can be one of the models of the network application layer or one of the models of the twin network layer. It should be noted that the DTN system architecture shown in FIG. 1 is only one implementation, and the specific implementation is not limited thereto.
[0069] The security deduction method described in the embodiments of the present disclosure adopts the DTN system of the above implementation architecture, uses the high-precision simulation capability of the DTN for the network and the service, obtains the attack result based on the network base model (twin network), that is, obtains the attack time of the successful attack of the attack event and the attacked entity corresponding to the successful attack; then, based on the network management and configuration capability of the DTN, the state of the entity in the DTN is set, and on this basis, a dynamic protection technology is further superimposed for intervention, forming a high-precision dynamic security deduction based on the DTN, so that the deduction / simulation process is more accurate, and the effect of the security drill of the service system in the real network environment is achieved.
[0070] As shown in FIG. 2, the security deduction method described in one of the embodiments of the present disclosure includes:
[0071] S201, obtaining the attack time of the successful attack of each attack event in the twin network before a first time according to the network state information of the twin network and a plurality of attack events preset in advance;
[0072] S202, determining each attacked entity corresponding to the successful attack before the first time according to the network state information and the attack time;
[0073] S203, superimposing and analyzing the attack effect of the successful attack on each attacked entity to obtain attack evaluation information;
[0074] S204, adjusting the network state information of the twin network and / or the attack event according to the attack evaluation information, and performing security protection configuration on the twin network.
[0075] Optionally, the network base model can also be referred to as a twin network, which is a virtual network of a physical network that needs to be subjected to security deduction.
[0076] By using the method described in the embodiment, the environment and attack parameters of the network that needs to be subjected to security deduction are defined in advance, and the network state information and the plurality of attack parameters of the twin network can be determined according to the pre-defined environment and attack parameters.
[0077] Optionally, the network state information includes one or more of the following:
[0078] entity information;
[0079] routing information among the plurality of entities;
[0080] connection state information;
[0081] entity state information.
[0082] Optionally, the entity information is information of an entity that can be attacked in the network base model; the entity mentioned in the embodiment of the disclosure includes one or more of a network entity, a network element, an application, a service, a database, and a log, and each entity in combination can form an entity set E.
[0083] The routing information is used to represent a connection relationship formed by the plurality of entities in the network base model, and optionally, the routing information among the plurality of entities can form a routing set, which is represented as R; the routing information R in the routing set eiej represents that there is a directed connection relationship from the entity ei to the entity ej.
[0084] Optionally, the connection state information and the entity state information in the network state information can be combined to form a state set STATUS; and optionally, the plurality of attack events can form an attack event set ATT_EVE, and each attack event can be represented as att_eve1, att_eve2, ¨¨, att_eve n .
[0085] By using the security deduction method described in the embodiment of the disclosure, before the method is implemented, DTN initialization is performed to obtain the above-mentioned entity set E, routing set R, state set STATUS, and attack event set ATT_EVE. Optionally, when the DTN is initialized, the total time length T of the attack performed when the security deduction is performed and the time period INTERVAL are also set; the time period INTERVAL is the minimum time unit for monitoring the state conversion.
[0086] After the DTN initialization, step S201 can be performed to perform security deduction of the network base model.
[0087] In the embodiments of the present disclosure, optionally, in step S201, within the total duration T of performing the attack during the security deduction, the time nodes T1 during the security deduction are sequentially accumulated based on the time period INTERVAL, the attack time of successfully performing the attack between the time nodes T1 is determined, and each attacked entity corresponding to the successful attack before the time nodes T1 is determined. In this way, by superimposing and analyzing the attack effects generated by each attacked entity, a superimposition technical analysis result of the attack event based on the time sequence is obtained. Then, the attack set and the network state can be updated according to the attack state and the security measures determined based on the superimposition analysis result, and the DTN network element, the network service and the like are configured and set according to the state, and the deduction is entered again until a specified time or a specified network state, to form a high-precision dynamic security deduction based on the DTN, so that the deduction / simulation process is more accurate.
[0088] In the embodiments of the present disclosure, optionally, the first time is one of the times within the total duration T of performing the attack during the security deduction.
[0089] In the embodiments of the present disclosure, in step S201, according to the network state information of the twin network and the plurality of attack events preset in advance, the attack time of successfully performing the attack on the attack events before the first time in the twin network is obtained, including one or more of the following:
[0090] According to the network state information of the twin network and the plurality of attack events preset in advance, the attack time of successfully performing the attack on the attack events before the first time in the twin network is obtained by setting;
[0091] According to the network state information of the twin network and the plurality of attack events preset in advance, the probability of successfully performing the attack on the attack events before the first time in the twin network is calculated, and the attack time of successfully performing the attack on the attack events is calculated by using a random model according to the probability;
[0092] According to the network state information of the twin network and the plurality of attack events preset in advance, the start time of performing the attack on the attack events before the first time in the twin network is obtained by setting;
[0093] According to the network state information of the twin network and the plurality of attack events preset in advance, the start time of performing the attack on the attack events before the first time in the twin network is determined by using a random model;
[0094] According to the network state information of the twin network and the plurality of attack events preset in advance, according to the start time of the attack events to perform successful attacks on the twin network before the first time, the running logic of the simulation attack performed on the twin network is determined.
[0095] In the embodiments of the present disclosure, the attack time can include the attack start time and / or the attack success time.
[0096] In one of the embodiments of the present disclosure, the attack time of the attack events to perform successful attacks on the twin network before the first time can be obtained by direct setting.
[0097] In one of the embodiments, the attack time of the attack events to perform successful attacks on the twin network before the first time can be determined by initiating a model attack on the twin network through a security attack model, and making the twin network run according to the set logic. The logic running can be implemented by a virtualized network element of the twin network, or by a trimmed logic code or an intelligent model based on data. Specifically, according to the network state information of the twin network and the elements or parameters of the plurality of attack events preset in advance, the running logic of the simulation attack performed on the twin network is used to obtain the attack time of the attack events to perform successful attacks on the twin network before the first time.
[0098] In one of the embodiments, the attack time of the attack events to perform successful attacks on the twin network can be determined by theoretically analyzing the attack events that do not actually occur on the twin network. The theoretically analyzing can include: according to the network state information of the twin network and the elements or parameters of the plurality of attack events preset in advance, calculating the probability of the attack events to perform successful attacks on the twin network before the first time, and according to the probability, using a random model to calculate the attack time of the attack events to perform successful attacks; or according to the network state information of the twin network and the elements or parameters of the plurality of attack events preset in advance, using a random model to determine the start time of the attack events to perform attacks on the twin network before the first time, and according to the start time, determining the attack time of the attack events to perform successful attacks.
[0099] In an embodiment, optionally, according to the network state information of the twin network and a plurality of attack events preset, the start time of the attack event in the twin network performing a successful attack before the first time is obtained by setting; or the start time of the attack event in the twin network performing an attack before the first time is determined by using a random model; after the start time of the twin network performing a successful attack is determined, the attack time of the attack event in the twin network performing a successful attack is determined by using the running logic of the simulation attack of the twin network.
[0100] Optionally, for a time period INTERVAL in the total duration T of performing an attack during security deduction, according to each attack event in the attack event set ATT_EVE, the probability of each attack event performing a successful attack in the time period is calculated, and the probability of each attack event performing a successful attack before each time node T1 is determined by accumulating each time period.
[0101] Optionally, each attack event includes one or more of the event description information att_msg, the attack strength tensity and the attack duration duration, the attack model mode (including a simulation attack mode and / or a hypothetical attack mode), the attack condition, the attack start time, the attack success time, and the like.
[0102] For the simulation attack mode, optionally, the attack start time and / or the attack success time are determined according to the attack condition, the attack start time, the attack success time, and the like in the attack event.
[0103] For the hypothetical attack mode, optionally, the probability of the attack event performing a successful attack is determined according to the attack strength tensity and the attack duration duration, and the like, wherein, without other interference factors, the probability of a single attack event performing a successful attack can be calculated according to the parameters in the attack event.
[0104] For example, taking the system password cracking attack as an example, it is known that in a certain test environment, 0.00172 probability of completing the guessing can be achieved by an average of 100,000 times of guessing, and the success rate of the guessing is linearly related to the number of times of guessing. In this attack event, the attack strength tensity = 100 times / sec, and the attack duration duration = 60 minutes, and the probability of the attack event att_eve performing a successful attack is:
[0105] Optionally, in the case of setting a protection measure d1 e D, d1 is the password error limit, the protection measure is enabled, and the password error attempt frequency is reduced to 1 time per second, and the probability of successful attack of the attack event att_eve is reduced to 0.00006192 within 60 minutes.
[0106] On the basis of determining the probability of successful attack of the attack event in the twin network by using the above-mentioned manner, the attack time of the attack event performing successful attack can be predicted by using a random model, and the first time of successful attack of a single attack event is obtained.
[0107] Optionally, the attack time of the attack event performing successful attack can form a time set, which is used to determine each attacked entity corresponding to the successful attack before the first time.
[0108] In the embodiment of the present disclosure, by performing theoretical analysis, the attack time of the attack event performing successful attack in each time period is determined, in addition to the above-mentioned manner of first determining the probability of successful attack of the attack event in the twin network, and then determining the attack time of performing successful attack, the attack time of the attack event performing successful attack in the twin network can be determined by using a random model in the first time period.
[0109] In the embodiment of the present disclosure, after determining the attack time of the attack event performing successful attack in the twin network before the first time, each attacked entity Ej corresponding to the successful attack before the first time is further determined according to the network state information and the attack time.
[0110] Specifically, in step S202, the corresponding attacked entity Ej can be determined by analyzing the entity of each successful attack, and the attacked entity set is obtained. Then, in step S203, the attack effect of the successful attack on each attacked entity is superimposed and analyzed, and the attack evaluation information corresponding to each attacked entity is obtained.
[0111] Optionally, the attack evaluation information includes one or more of the following:
[0112] The attack on the attacked entity includes a data confidentiality attack;
[0113] The damage degree of the data confidentiality attack;
[0114] The attack on the attacked entity includes an availability attack;
[0115] The damage degree of the availability attack;
[0116] The attack on the attacked entity includes implementing control;
[0117] A control type of the implemented control;
[0118] A degree of harm of the control type of the implemented control.
[0119] For example, it is assumed that one attack event successfully attacks the entity e2 at a certain time, the attack has an impact on the data confidentiality of the user, and the degree of harm of the data confidentiality attack is con_degree=60. Alternatively, the attack event also controls the entity e2, the control type is ctrl_type=host, that is, the host is controlled, and the degree of harm of the control type of the implemented control is ctrl_degree=80.
[0120] Based on this, the attack effect of the successful attack on the entity e2 is superimposed and analyzed, and the attack evaluation information obtained can be represented as:
[0121] Specifically, the attack effect is further analyzed. The attacker of the attack event steals the data of e2, forming a security risk, and forms the permission control of the host, so that the host has a certain probability of being converted into an attacker, for example, a new attack event can be formed. In an ideal state, any type of attack can be launched, but since the host can not be connected to the outside or does not support data uploading services and operations after being controlled, the attack that can be performed can be set according to a certain probability, that is, by adjusting the state of the attacked entity and / or the attack event, and performing security protection configuration on the twin network, the security deduction can be intervened, and then the security deduction process of the next time period is continued, to form a high-precision dynamic security deduction based on the DTN.
[0122] In the embodiments of the present disclosure, the method further includes:
[0123] Reporting the attack evaluation information to a security analysis center.
[0124] In one implementation, the attack evaluation information is reported to the security analysis center in a case where it is determined according to the attack evaluation information that the successful attack on the attacked entity does not affect the confidentiality and integrity of the state of the network element or the entity.
[0125] In one implementation, the adjustment of the network state information of the twin network and / or the attack event in step S204 includes one or more of the following:
[0126] In a case where the attack on the attacked entity includes an availability attack, the state of the attacked entity is modified.
[0127] In a case where the attack on the attacked entity includes an availability attack, connection state information and / or entity state information after the state modification of the attacked entity is determined;
[0128] In a case where the attack on the attacked entity includes an implemented control, a to-be-added attack event initiated by the attacked entity is determined according to a control type and a harm degree of the implemented control, and the to-be-added attack event is added to the plurality of attack events.
[0129] In an embodiment, in a case where the attack effect on the attacked entity Ej is determined to include an impact on availability according to the attack evaluation information, the state of the attacked entity Ej is modified based on the twin network; optionally, the new network state information STATUSNEW of the attacked entity Ej after the state modification is formed based on the twin network, such as obtaining the connection state information and / or the entity state information after the state modification;
[0130] In an embodiment, in a case where the attack on the attacked entity Ej includes an implemented control, a to-be-added attack event initiated by the attacked entity is determined according to a control type and a harm degree of the implemented control, and the to-be-added attack event is added to the plurality of attack events, that is, a new attack event sent by the attacked entity Ej as an attack source is set according to a certain probability, and the new attack event is added to the attack event set ATT_EVE to form a new attack event set ATT_EVEnew.
[0131] In an embodiment of the present disclosure, the security protection configuration of the network base model includes one or more of the following:
[0132] The security protection strategy of the twin network is configured;
[0133] The security capability of the twin network is configured or deployed;
[0134] The network state information of the twin network is updated;
[0135] The attack parameter of the attack event is updated.
[0136] In an embodiment, the security protection configuration of the twin network can be performed by the security brain, such as configuring the security protection strategy, configuring the security capability, updating the network state information of the twin network, and updating the attack parameter or factor of the attack event.
[0137] Optionally, the attack parameter includes one or more of an attack probability, a power attack strength, and an attack duration.
[0138] Optionally, an instance of a network function (Network Function, NF) e n The attack event of the e
[0139] Device security shell protocol (Secure Shell, SSH) remote connection password cracking attack;
[0140] Distributed denial of service (Distributed Denial of Service, DDoS) attack against 80 port;
[0141] Web service common vulnerability disclosure (Common Vulnerabilities&Exposures, CVE) vulnerability attack;
[0142] NF signaling attack.
[0143] Due to the introduction of the security protection configuration, multiple attack events can form mutual influence, thereby affecting the attack probability of one attack. By using the method described in the embodiment, the security protection configuration is performed in the twin network, such as configuring a security protection strategy, configuring or deploying a security capability, updating network state information of the twin network, and updating attack parameters of the attack event, so as to adjust the attack success probability of the attack event, to meet the requirement of continuous attempt of attack evaluation deduction, and to form highly simulated deduction.
[0144] For example, for the attack event of the e n The attack event of the e e1en , DDoS attack att_eve e2en ; assuming that when the traffic reaches a certain threshold, the protection measure black hole routing is started, and 90% of the overall traffic is lost, the DDoS attack att_eve e2en may cause the efficiency of the password cracking attack att_eve e1en to decrease by 90%, and if the detection and cleaning of the DDoS are subsequently started, the attack efficiency of e1 may recover to normal.
[0145] In the embodiments of the present disclosure, optionally, in each time period, a security deduction process is performed; in the security deduction process, before a first time corresponding to the time period, an attack time at which an attack event successfully attacks the network base model, according to network state information and the attack time, each attacked entity corresponding to a successful attack before the first time is determined, an attack effect generated by the successful attack on each attacked entity is superimposed and analyzed to obtain attack evaluation information, and according to the attack evaluation information, a state of the attacked entity and / or the attack event is adjusted based on a twin network, and the twin network is configured for security protection, and then the method further comprises:
[0146] According to the twin network configured for security protection, and the attacked entity and / or the attack event adjusted, a security deduction process before a second time is performed until the security deduction reaches a target time length and / or the network state information reaches a target state; wherein the second time is after the first time; optionally, a time interval between the second time and the first time is a time period.
[0147] Specifically, the security deduction reaching the target time length and / or the network state information reaching the target state are termination conditions of the security deduction, when the termination conditions are not met, in each time period, an attack effect generated by the successful attack on each attacked entity is superimposed and analyzed to obtain attack evaluation information, according to the attack evaluation information, a state of the attacked entity and / or the attack event is adjusted based on a twin network, and the twin network is configured for security protection, and then the next cycle of the security deduction process is continued.
[0148] For example, in the case that the instance (attacked entity) en of the NF includes the above four types of attack events, at t2, the SSH password cracking attack is successful, the DDoS attack forms part of the influence of 60%, the vulnerability attack and the signaling attack do not work, and the superposition forms an attack influence set impact en . According to the case of the embodiment, the attack effect is set, and the network state information STATUS of en at t2 is updated, and the DTN performs complete simulation changes based on the changes of the network element state. Further, if it is assumed that att_eve e1en After the attack is successful, the host Host is closed. Then, the state of the network element en can be changed by configuration, and the state and damage of the network operation and service operation after the state change can be observed through the network management platform, the service management platform, and the like.
[0149] Meanwhile, if the availability of the en entity is attacked, the control authority is obtained, and the state is changed, the implementation of the attack is also affected. Therefore, after the state of the network element is changed, the attack being implemented needs to be reset. According to the analysis of each element in the set of all attacks ATT_EVE, the attack containing the en entity in the route information of the element is found, and the attack success probability is adjusted again.
[0150] By using the security deduction method according to the embodiments of the present disclosure, according to each element in ATT_EVE, on the one hand, the attack parameters of the attack event can be used to initiate a simulated attack on the network base model (twin network) through the security attack model, and the network elements on the twin network run according to the set logic; on the other hand, theoretical analysis can be performed, and attacks that do not actually occur on the twin network are assumed. Within the range of T, the probability that each attack can form in this attack is calculated according to the attack parameters of the attack event, whether it occurs in this attack simulation is determined according to the random model, and the time point of the success of a single attack is predicted; if there is a successful attack before a certain time, the effects of all attacks on the entity in the attack set are analyzed. According to the state after the attack and the security measures, the attack set and the network state are updated, and the DTN network element, network service, etc. are configured and set according to the state. The deduction is entered again until the specified time or the specified network state.
[0151] By using the implementation process, the state influence on the network entity is included in the attack effect from the perspective of attack success expectation, and then the migration of the entity state is determined according to the state influence. In addition, based on the migration of the network state of the entity, the high-precision simulation of the network and service of the DTN is fully utilized to quickly form the attack result based on the twin network, which is equivalent to taking a "snapshot" of an attack. Then, based on the network management and configuration capability of the DTN, the state of the entity in the DTN is set, and on this basis, the dynamic protection technology is further intervened to form a high-precision dynamic security deduction based on the DTN.
[0152] As shown in FIG. 3, a flowchart of one embodiment of the security deduction method according to the embodiments of the present disclosure is shown, which includes the following steps:
[0153] S301, start;
[0154] S302, performing DTN initialization, obtaining entity set E, routing set R, state set STATUS and attack event set ATT_EVE, and setting total time length T of performing attack when performing security deduction, and time period INTERVAL; optionally, the attack event set contains attack events, and the attack events include one or more of event description information att_msg, attack intensity tensity and attack duration duration, attack model mode (including simulation attack mode and / or assumption attack mode), attack condition, attack start time, attack success time and other parameters or elements;
[0155] S303, based on time T1 (first time), starting security deduction;
[0156] S304, initiating simulation attack on the twin network through the security attack model; or, determining the start time of initiating simulation attack on the twin network by the security attack model before T1 through a random model;
[0157] S305, according to theoretical analysis, setting or analyzing the attack time of the attack event performing successful attack on the twin network before T1 through a random model;
[0158] Optionally, step S304 and step S305 are steps that can be executed alternatively, and one of step S304 and step S305 can be selected to be executed;
[0159] S306, according to the execution result of step S304 or step S305, judging whether there is an attack event performing successful attack before T1; in the case of yes, performing step S307; in the case of no, performing step S311;
[0160] S307, according to the network state information of the twin network and a plurality of attack events, determining each attacked entity corresponding to successful attack before T1, and performing superposition analysis on the attack effect of successful attack on the attacked entity;
[0161] S308, updating the network state information of the twin network; optionally, the state information includes connection state information and / or entity state information;
[0162] S309, analyzing a new attack event (to-be-added attack event) initiated by the attacked entity, and updating the attack event set according to the new attack event;
[0163] S310, the security brain performs security protection configuration on the twin network, and updates the attack event parameters and the state information of the twin network; optionally, the state information includes connection state information and / or entity state information;
[0164] S311, increase the time length TI of the current security deduction by a time period; that is, TI = TI + INTERVAL;
[0165] S312, determine whether TI is greater than a target time length T, or determine whether the network state information of the twin network reaches a target state; in the case of a positive determination, execute step S313, and in the case of a negative determination, return to execute S303 to perform a security deduction process of the next time period;
[0166] S313, output the final impact information of the security deduction;
[0167] S314, end.
[0168] It should be noted that the above implementation process is only one implementation process of the security deduction method described in the embodiments of the present disclosure, and is not limited thereto.
[0169] One embodiment of the present disclosure also provides a security deduction device, as shown in FIG. 4, which comprises:
[0170] A first processing module 410 is configured to obtain attack times of successful attacks of a plurality of attack events on a twin network before a first time according to network state information of the twin network and the plurality of attack events;
[0171] A second processing module 420 is configured to determine each attacked entity corresponding to the successful attacks before the first time according to the network state information and the attack times;
[0172] A third processing module 430 is configured to perform superposition analysis on attack effects of the successful attacks on each of the attacked entities to obtain attack evaluation information;
[0173] A fourth processing module 440 is configured to adjust the network state information of the twin network and / or the attack events according to the attack evaluation information, and perform security protection configuration on the twin network.
[0174] The security deduction device described in the embodiments of the present disclosure utilizes the high-precision simulation capability, network management, and configuration capability of the digital twin network (DTN) for network and business, performs time sequence-based attack event superposition analysis, and performs dynamic adjustment of security protection configuration of the attacked entity, the attack event, and the twin network on the basis of the superposition analysis, so as to make the deduction / simulation process more accurate and achieve the effect of business system security drill in a real network environment.
[0175] Optionally, the security deduction device, wherein the device further comprises:
[0176] The fifth processing module 450 is configured to perform a security deduction process before the second time according to the twin network after the security protection configuration, and the adjusted attacked entity and / or the attack event, until the security deduction reaches a target time length and / or the network state information reaches a target state.
[0177] Optionally, the security deduction device, wherein the first processing module 410 obtains the attack time of the attack event in the twin network performing a successful attack before the first time according to the network state information of the twin network and the plurality of attack events preset in advance, including one or more of the following:
[0178] According to the network state information of the twin network and the plurality of attack events preset in advance, the attack time of the attack event in the twin network performing a successful attack before the first time is obtained by setting.
[0179] According to the network state information of the twin network and the plurality of attack events preset in advance, the probability of the attack event in the twin network performing a successful attack before the first time is calculated, and the attack time of the attack event performing a successful attack is calculated according to the probability and by using a random model.
[0180] According to the network state information of the twin network and the plurality of attack events preset in advance, the start time of the attack event in the twin network performing a successful attack before the first time is obtained by setting.
[0181] According to the network state information of the twin network and the plurality of attack events preset in advance, the start time of the attack event in the twin network performing an attack before the first time is determined by using a random model.
[0182] According to the network state information of the twin network and the plurality of attack events preset in advance, according to the start time of the attack event in the twin network performing an attack before the first time, the attack time of the attack event in the twin network performing a successful attack is determined by using the running logic of the simulation attack of the twin network.
[0183] Optionally, the security deduction device, wherein the network state information includes one or more of the following:
[0184] Entity information;
[0185] Routing information between a plurality of entities;
[0186] Connection state information;
[0187] Entity state information.
[0188] Optionally, the security deduction apparatus, wherein the attack assessment information comprises one or more of:
[0189] the attack on the attacked entity comprises a data confidentiality attack;
[0190] a degree of harm of the data confidentiality attack;
[0191] the attack on the attacked entity comprises an availability attack;
[0192] a degree of harm of the availability attack;
[0193] the attack on the attacked entity comprises an enforcement control;
[0194] a control type of the enforcement control;
[0195] a degree of harm of the control type of the enforcement control.
[0196] Optionally, the security deduction apparatus, wherein the apparatus further comprises:
[0197] a reporting module 460, configured to report the attack assessment information to a security analysis center.
[0198] Optionally, the security deduction apparatus, wherein the fourth processing module 440 adjusts the network state information of the digital twin network and / or the attack events, comprising one or more of:
[0199] in a case where the attack on the attacked entity comprises an availability attack, performing state modification on the attacked entity;
[0200] in a case where the attack on the attacked entity comprises an availability attack, determining connection state information and / or entity state information after the state modification on the attacked entity;
[0201] in a case where the attack on the attacked entity comprises an enforcement control, determining a to-be-joined attack event initiated by the attacked entity according to the control type and the degree of harm of the enforcement control, and adding the to-be-joined attack event into the plurality of attack events.
[0202] Optionally, the security deduction apparatus, wherein the fourth processing module 440 performs security protection configuration on the twin network, comprising one or more of:
[0203] configuring a security protection policy of the twin network;
[0204] configuring or deploying a security capability of the twin network;
[0205] updating network state information of the twin network;
[0206] updating attack parameters of the attack event.
[0207] In the embodiments of the present disclosure, the method and the device are based on the same application concept. Since the principles of the method and the device for solving problems are similar, the implementation of the device and the method can be referred to each other, and the repeated parts will not be described herein.
[0208] In one embodiment of the present disclosure, a network device is also provided, which comprises a processor, a memory, and a program stored in the memory and executable on the processor. The program is executed by the processor to implement the security derivation method according to any one of the above.
[0209] The program executed on the processor of the network device to implement the specific implementation of the security derivation method can refer to the detailed description of the security derivation method applied to the network device, which will not be described herein.
[0210] In addition, a readable storage medium is also provided in the embodiments of the present disclosure, which stores a computer program. The program is executed by the processor to implement the steps of the security derivation method according to any one of the above.
[0211] Specifically, the readable storage medium is applied to the network device described above. When applied to the network device, the detailed description of the execution steps of the corresponding security derivation method is as above, which will not be described herein.
[0212] Another embodiment of the present disclosure also provides a computer program product, which comprises computer instructions. The computer instructions are executed by the processor to implement the steps of the security derivation method according to any one of the above.
[0213] Optionally, the embodiments of the present disclosure can adopt the form of a computer program product implemented on one or more computer usable storage media (including but not limited to disk memory, CD-ROM, optical memory, etc.) containing computer usable program codes.
[0214] The computer program product of the embodiments of the present disclosure comprises computer instructions which are executed by the processor to implement various processes of the security derivation method embodiments shown above, and can achieve the same technical effects. To avoid repetition, they will not be described herein.
[0215] In several embodiments provided by the present disclosure, it should be understood that the disclosed methods and devices can be implemented in other manners. For example, the embodiments of the device described above are merely schematic. For example, the division of the units is only a logical function division. There can be another division manner for the actual implementation. For example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed mutual couplings or direct couplings or communication connections can be indirect couplings or communication connections through some interfaces, devices or units, and can be in electrical, mechanical or other forms.
[0216] In addition, each function unit in the various embodiments of the present disclosure can be integrated into a processing unit, or each unit can be physically separated, or two or more units can be integrated into one unit. The above-mentioned integrated unit can be implemented in the form of hardware, or in the form of hardware plus software function units.
[0217] The integrated unit implemented in the form of software function units can be stored in a computer readable storage medium. The software function unit stored in the storage medium includes a plurality of instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute part of the steps of the transceiving method described in the various embodiments of the present disclosure. The aforementioned storage medium includes a variety of media that can store program codes, such as a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, etc.
[0218] The above describes the preferred embodiments of the present disclosure. It should be pointed out that for those skilled in the art, without departing from the principles of the present disclosure, a number of improvements and refinements can be made, and these improvements and refinements should be considered as the protection scope of the present disclosure.
Claims
1. A security simulation method, characterized in that, include: Based on the network status information of the twin network and multiple pre-set attack events, obtain the attack time when the attack event was successfully executed on the twin network before the first time. Based on the network status information and the attack time, determine each attacked entity corresponding to the successful attack before the first time. The attack effects of the successful attacks on each of the attacked entities are analyzed in an aggregated manner to obtain attack evaluation information. Based on the attack assessment information, the network status information of the twin network and / or the attack events are adjusted, and security protection configurations are performed on the twin network.
2. The security simulation method according to claim 1, characterized in that, The method further includes: Based on the twin network after the security protection configuration, the adjusted twin network, and / or the attack event, a security simulation process prior to the second time is executed until the security simulation reaches the target duration and / or the network status information reaches the target state; wherein, the second time is after the first time.
3. The security simulation method according to claim 1 or 2, characterized in that, Based on the network status information of the twin network and multiple pre-set attack events, obtain the attack time when the attack event successfully executed on the twin network before the first time, including one or more of the following: Based on the network status information of the twin network and multiple pre-set attack events, the attack time when the attack event successfully executed an attack on the twin network before the first time is obtained through a setting method. Based on the network state information of the twin network and multiple pre-set attack events, calculate the probability that the attack event will successfully execute an attack on the twin network before the first time, and calculate the attack time when the attack event will successfully execute an attack based on the probability and using a stochastic model. Based on the network status information of the twin network and multiple pre-set attack events, the start time of the successful attack executed by the attack event on the twin network before the first time is obtained by setting a method. Based on the network state information of the twin network and multiple pre-set attack events, a random model is used to determine the start time of the attack events executing attacks on the twin network before the first time. Based on the network status information of the twin network and multiple pre-set attack events, and according to the start time of the attack event executing the attack on the twin network before the first time, the attack time when the attack event successfully executes the attack on the twin network is determined by the running logic of the twin network executing the simulated attack.
4. The security simulation method according to any one of claims 1-3, characterized in that, The network status information includes one or more of the following: Entity information; Routing information between multiple entities; Connection status information; Entity status information.
5. The security simulation method according to any one of claims 1-4, characterized in that, The attack assessment information includes one or more of the following: Attacks against the attacked entity include attacks on data confidentiality; The severity of the data confidentiality attack; Attacks on the attacked entity include usability attacks; The severity of the availability attack; Attacks on the attacked entity include the exercise of control; The type of control implemented; The degree of harm caused by the type of control implemented.
6. The security simulation method according to any one of claims 1-5, characterized in that, The method further includes: The attack assessment information will be reported to the security analysis center.
7. The security simulation method according to any one of claims 1-6, characterized in that, Adjustments are made to the network state information of the twin network and / or the attack events, including one or more of the following: In the event that the attack on the attacked entity includes an availability attack, the state of the attacked entity is modified. In the case where the attack on the attacked entity includes an availability attack, determine the connection state information and / or entity state information of the attacked entity after the state modification is performed. In the case where the attack on the attacked entity includes the implementation of control, the attack event to be added is determined based on the control type and degree of harm of the implemented control, and the attack event to be added is added to the plurality of attack events.
8. The security simulation method according to any one of claims 1-6, characterized in that, The twin network is configured with security protection measures, including one or more of the following: Configure the security protection strategy for the twin network; Configure or deploy the security capabilities of the twin network; Update the network state information of the twin network; Update the attack parameters for the attack event.
9. A safety simulation device, characterized in that, include: The first processing module is used to obtain the attack time when the attack event successfully executed the attack on the twin network before the first time, based on the network status information of the twin network and multiple pre-set attack events; The second processing module is used to determine each attacked entity corresponding to the successful attack before the first time based on the network status information and the attack time. The third processing module is used to perform superimposed analysis on the attack effects of the successful attack on each of the attacked entities to obtain attack evaluation information. The fourth processing module is used to adjust the network status information of the twin network and / or the attack event based on the attack assessment information, and to configure security protection for the twin network.
10. A network device, characterized in that, It includes a processor, a memory, and a program stored in the memory and executable on the processor, wherein the program, when executed by the processor, implements the security deduction method as described in any one of claims 1 to 8.
11. A readable storage medium, characterized in that, The readable storage medium stores a program that, when executed by a processor, implements the steps of the security deduction method as described in any one of claims 1 to 8.
12. A computer program product, characterized in that, It includes computer instructions that, when executed by a processor, implement the steps in the security deduction method as described in any one of claims 1 to 8.
Citation Information
Patent Citations
Network security deduction method, device and equipment and storage medium
CN112073411A
Network attack and defense deduction method and device, computing equipment and storage medium
CN114095262A
Method for evaluating survivability of deliberate attack based on network digital twin
CN115189910A
Network security analysis method and system based on digital twinning
CN117478394A
Network security attack and defense drill method, system and device and communication equipment
CN117675236A