Network attack and defense exercise system

By combining online team networks, VPN exit routers, and team exit routers, the lack of flexibility in existing network topology construction methods is solved, enabling flexible access for online and offline participants and expanding the application scenarios of network attack and defense exercises.

WO2026065593A1PCT designated stage Publication Date: 2026-04-02XIAN THERMAL POWER RES INST CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-10-15
Publication Date
2026-04-02

AI Technical Summary

Technical Problem

The existing network topology construction method cannot meet the needs of scenarios where some participants are engaged in attack and defense exercises offline and others are engaged in them online, and lacks flexibility.

Method used

By combining the online team network, VPN egress router, local team network, and team egress router, interconnection between online team terminals and local team terminals is achieved. The VPN egress router and team egress router provide access paths for the Internet side and the local side, respectively, and security control is achieved by configuring WAN and LAN interfaces and firewall rules.

Benefits of technology

It expands the application scenarios of network attack and defense exercises, enables flexible access for online and offline participants, and increases the flexibility of network attack and defense exercises.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024124924_02042026_PF_FP_ABST
    Figure CN2024124924_02042026_PF_FP_ABST
Patent Text Reader

Abstract

Provided in the embodiments of the present application is a network attack and defense exercise system, comprising an online team network, a VPN egress router, a local team network and a team egress router which are connected in sequence, wherein the online team network is used for providing access for online team terminals, and the local team network is used for providing access for local team terminals; the VPN egress router is used for enabling the online team terminals to access the local team network; and the team egress router is used for enabling the online team terminals and the local team terminals to access a network attack and defense exercise target. In the embodiments of the present application, Internet-side exercise participants are enabled to access a team subnetwork by means of a VPN, and local exercise participants are enabled to directly access the team subnetwork, such that all the participants can simultaneously access an exercise target by means of a team egress router, thereby meeting the requirements of exercise participants for simultaneous offline access by means of the Intranet and online access by means of the Internet, expanding application scenarios of network attack and defense exercises, and increasing the flexibility of the network attack and defense exercises.
Need to check novelty before this filing date? Find Prior Art

Description

A network attack and defense exercise system

[0001] Cross-reference to related applications

[0002] The present application claims priority to the Chinese patent application No. 202411332057.1, filed on September 24, 2024, and entitled "A network attack and defense exercise system", the entire content of which is incorporated herein by reference. TECHNICAL FIELD

[0003] Embodiments of the present application belong to the technical field of network security, and specifically relate to a network attack and defense exercise system. BACKGROUND

[0004] With the continuous iteration and upgrading of information technology, information warfare confrontation is intensifying worldwide, and the importance of network security is increasingly highlighted. The essence of network security lies in confrontation, which is essentially a competition between attack vectors and defense mechanisms. In order to enhance the comprehensive competitiveness of network defense, the construction of network security ranges is an effective means. These range platforms are committed to carrying out network security red team and blue team attack and defense exercises to promote the research and development of information security technology, conduct penetration testing of network security products, and provide professional skill training for network security personnel.

[0005] The existing exercise network topology construction method generally divides offline participation in the exercise and online participation in the exercise into two templates, i.e., a set of network topology construction templates is used when organizing personnel to participate in the exercise offline, and another set of network topology construction templates is used when organizing personnel to participate in the exercise online. There is no any association between the network topologies constructed by the two sets of templates.

[0006] Therefore, the existing exercise network topology cannot meet the scene of offline participation in the attack and defense exercise by some participants and online participation in the attack and defense exercise by some participants, and the use scene is relatively single and lacks flexibility.

[0007] SUMMARY

[0008] Embodiments of the present application aim to at least solve one of the technical problems existing in the prior art, and provide a network attack and defense exercise system, which comprises an online team network, a VPN export router, a local team network and a team export router connected in sequence.

[0009] The online team network is configured to access online team terminals, and the local team network is configured to access local team terminals.

[0010] The VPN export router is configured to access the online team terminals to the local team network.

[0011] The team exit router is configured to enable the online team terminal and the local team terminal to access the cyber attack and defense exercise target.

[0012] Optionally, the VPN exit router is provided with a first WAN interface and / or a first LAN interface.

[0013] Optionally, the first WAN interface and / or the first LAN interface adopts a static IP address.

[0014] Optionally, the first WAN interface is provided with a first wide area network firewall, and the first LAN interface is provided with a first local area network firewall.

[0015] The first wide area network firewall and the first local area network firewall both discard all traffic not explicitly allowed.

[0016] Optionally, the first local area network firewall allows traffic from a specific IP address.

[0017] Optionally, the team exit router is provided with a second WAN interface and / or a second LAN interface.

[0018] Optionally, the second WAN interface and / or the second LAN interface adopts a static IP address.

[0019] Optionally, the second WAN interface is provided with a second wide area network firewall, and the second LAN interface is provided with a second local area network firewall.

[0020] The second wide area network firewall and the second local area network firewall both discard all traffic not explicitly allowed.

[0021] Optionally, the second local area network firewall allows traffic from a specific IP address.

[0022] Optionally, the system further comprises an exercise competition router.

[0023] The exercise competition router is connected with the local team network, and is configured to enable the online team terminal and the local team terminal to access a competition answering platform.

[0024] The network attack and defense exercise system according to the embodiments of the present application enables personnel participating in the exercise on the Internet to access the team subnet through VPN and access the exercise target through the team exit router; and enables personnel participating in the exercise locally to directly access the team subnet and access the exercise target through the team exit router. Thus, the online and offline use of the Internet access and the internal network access of the exercise personnel are simultaneously satisfied, the use scenario of the network attack and defense exercise is expanded, and the flexibility of the network attack and defense exercise is increased. BRIEF DESCRIPTION OF DRAWINGS

[0025] Fig. 1 is a structural schematic diagram of a network attack and defense exercise system according to an embodiment of the present application. DETAILED DESCRIPTION

[0026] The technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative work are within the scope of protection of the present application.

[0027] In addition, the described features, structures, or characteristics can be combined in any suitable manner in one or more embodiments. In the following description, numerous specific details are provided to give a thorough understanding of embodiments of the present application. One skilled in the relevant art will recognize, however, that the technology can be practiced without one or more of the specific details, or with other methods, components, devices, steps, etc. In other instances, well-known methods, devices, implementations, or operations are not shown or described in detail to avoid obscuring aspects of the present application.

[0028] The flowcharts shown in the drawings are only exemplary illustrations, and do not necessarily include all contents and operations / steps, nor are they necessarily executed in the described order. For example, some operations / steps can be further divided, and some operations / steps can be combined or partially combined, so the actual execution order can be changed according to actual conditions.

[0029] It should be understood that although the terms first, second, third, etc. can be used in this application to describe various components, these components should not be limited by these terms. These terms are used to distinguish one component from another component. Therefore, the first component discussed below can be called the second component without departing from the teachings of the present application. As used in this application, the term "and / or" includes all combinations of any one and one or more of the associated listed items.

[0030] Those skilled in the art can understand that the modules or flows in the drawings are not necessarily required to implement the present application, and therefore cannot be used to limit the scope of protection of the present application.

[0031] As shown in FIG. 1, the embodiment of the present application provides a network attack and defense exercise system, which comprises an online team network 110, a VPN exit router 120, a local team network 130 and a team exit router 140 connected in sequence. The online team network 110 is configured to access online team terminals 111, and the local team network 130 is configured to access local team terminals 131. The VPN exit router 120 is configured to connect the online team terminals 111 to the local team network 130. The team exit router 140 is configured to enable the online team terminals 111 and the local team terminals 131 to access a network attack and defense exercise target.

[0032] Specifically, the network attack and defense exercise system of the present application connects the online team network 110 and the local team network 130 through the VPN exit router 120, so that the online team terminals 111 and the local team terminals 131 can both access the network attack and defense exercise target through the team exit router 140, and the online team and the local team can participate in the network attack and defense exercise at the same time. Obviously, the online team terminals 111 and the local team terminals 131 can both include multiple devices such as PCs and mobile phones used by the participants.

[0033] The VPN exit router 120 is a virtual machine that bears the function of VPN exit routing, which is referred to as a first virtual machine in the embodiment. The first virtual machine is bound with a public network IP, and the function of VPN exit routing is realized by modifying the firewall strategy of the first virtual machine, configuring WAN and LAN interfaces for the first virtual machine, configuring NAT rules and port forwarding rules, etc. The participants on the Internet, i.e. the online team terminals 111, can access the team subnet, i.e. the local team network 130, through VPN, and access the exercise target through the team exit router; the local participants, i.e. the local team terminals 131, can access the team subnet, i.e. the local team network 130, through hub access, and access the exercise target through the team exit router.

[0034] Exemplarily, the following script can be issued to the first virtual machine to modify the above-mentioned related configurations of the first virtual machine:

[0035] #! / bin / vbash

[0036] source / opt / vyatta / etc / functions / script-template

[0037] configure

[0038] #wancidr for variable, actual configured public ip

[0039] wancidr=172.17.0.12

[0040] waneth=`ip a|grep $wancidr|awk '{print $7}'`

[0041] wanip=`ip a|grep $wancidr|awk '{print $2}'`

[0042] lancidr=10.101.0.253

[0043] laneth=`ip a|grep $lancidr|awk '{print $7}'`

[0044] lanip=`ip a|grep $lancidr|awk '{print $2}'`

[0045] del interface ethernet $waneth address dhcp

[0046] set interface ethernet $waneth address $wanip

[0047] del interface ethernet $laneth address dhcp

[0048] set interface ethernet $laneth address $lanip

[0049] #gateway for variable, actual configured public gateway

[0050] set system gateway-address 172.17.0.1

[0051] set nat source rule 100 outbound-interface $waneth

[0052] set nat source rule 100 source address 0.0.0.0 / 0

[0053] set nat source rule 100 translation address masquerade

[0054] firename = wan

[0055] set firewall name $firename default-action 'drop'

[0056] set interfaces ethernet $waneth firewall local name $firename

[0057] firename = local

[0058] set firewall name $firename default-action 'drop'

[0059] set firewall name $firename rule 100 action 'accept'

[0060] set firewall name $firename rule 100 destination port 22

[0061] set firewall name $firename rule 100 source address 10.101.0.254

[0062] set firewall name $firename rule 100 protocol tcp

[0063] set interfaces ethernet $laneth firewall local name $firename

[0064] wan_ip = `echo $wanip | awk -F / '{print $1}'`

[0065] # targetxx_ip, targetxx_port, targetxxwan_port, rule are incremented according to actual situation

[0066] # values of targetxx_ip, targetxxwan_port, rule are gradually incremented by 1 according to the increment situation

[0067] # the value of targetxx_port is unchanged

[0068] target1_ip = 10.101.0.1

[0069] target1_port = 1194

[0070] target1wan_port = 11941

[0071] set nat destination rule 91 inbound-interface $waneth

[0072] set nat destination rule 91 destination address $wan_ip

[0073] set nat destination rule 91 destination port $target1wan_port

[0074] set nat destination rule 91 source address 0.0.0.0 / 0

[0075] set nat destination rule 91 protocol tcp

[0076] set nat destination rule 91 translation address $target1_ip

[0077] set nat destination rule 91 translation port $target1_port

[0078] target2_ip = 10.101.0.2

[0079] target2_port = 1194

[0080] target2wan_port = 11942

[0081] set nat destination rule 92 inbound-interface $waneth

[0082] set nat destination rule 92 destination address $wan_ip

[0083] set nat destination rule 92 destination port $target2wan_port

[0084] set nat destination rule 92 source address 0.0.0.0 / 0

[0085] set nat destination rule 92 protocol tcp

[0086] set nat destination rule 92 translation address $target2_ip

[0087] set nat destination rule 92 translation port $target2_port

[0088] target3_ip = 10.101.0.3

[0089] target3_port = 1194

[0090] target3wan_port = 11943

[0091] set nat destination rule 93 inbound-interface $waneth

[0092] set nat destination rule 93 destination address $wan_ip

[0093] set nat destination rule 93 destination port $target3wan_port

[0094] set nat destination rule 93 source address 0.0.0.0 / 0

[0095] set nat destination rule 93 protocol tcp

[0096] set nat destination rule 93 translation address $target3_ip

[0097] set nat destination rule 93 translation port $target3_port

[0098] target4_ip = 10.101.0.4

[0099] target4_port = 1194

[0100] target4wan_port = 11944

[0101] set nat destination rule 94 inbound-interface $waneth

[0102] set nat destination rule 94 destination address $wan_ip

[0103] set nat destination rule 94 destination port $target4wan_port

[0104] set nat destination rule 94 source address 0.0.0.0 / 0

[0105] set nat destination rule 94 protocol tcp

[0106] set nat destination rule 94 translation address $target4_ip

[0107] set nat destination rule 94 translation port $target4_port

[0108] target5_ip = 10.101.0.5

[0109] target5_port = 1194

[0110] target5wan_port = 11945

[0111] set nat destination rule 95 inbound-interface $waneth

[0112] set nat destination rule 95 destination address $wan_ip

[0113] set nat destination rule 95 destination port $target5wan_port

[0114] set nat destination rule 95 source address 0.0.0.0 / 0

[0115] set nat destination rule 95 protocol tcp

[0116] set nat destination rule 95 translation address $target5_ip

[0117] set nat destination rule 95 translation port $target5_port

[0118] target6_ip = 10.101.0.6

[0119] target6_port = 1194

[0120] target6wan_port = 11946

[0121] set nat destination rule 96 inbound-interface $waneth

[0122] set nat destination rule 96 destination address $wan_ip

[0123] set nat destination rule 96 destination port $target6wan_port

[0124] set nat destination rule 96 source address 0.0.0.0 / 0

[0125] set nat destination rule 96 protocol tcp

[0126] set nat destination rule 96 translation address $target6_ip

[0127] set nat destination rule 96 translation port $target6_port

[0128] target7_ip = 10.101.0.7

[0129] target7_port = 1194

[0130] target7wan_port = 11947

[0131] set nat destination rule 97 inbound-interface $waneth

[0132] set nat destination rule 97 destination address $wan_ip

[0133] set nat destination rule 97 destination port $target7wan_port

[0134] set nat destination rule 97 source address 0.0.0.0 / 0

[0135] set nat destination rule 97 protocol tcp

[0136] set nat destination rule 97 translation address $target7_ip

[0137] set nat destination rule 97 translation port $target7_port

[0138] target8_ip = 10.101.0.8

[0139] target8_port = 1194

[0140] target8wan_port = 11948

[0141] set nat destination rule 98 inbound-interface $waneth

[0142] set nat destination rule 98 destination address $wan_ip

[0143] set nat destination rule 98 destination port $target8wan_port

[0144] set nat destination rule 98 source address 0.0.0.0 / 0

[0145] set nat destination rule 98 protocol tcp

[0146] set nat destination rule 98 translation address $target8_ip

[0147] set nat destination rule 98 translation port $target8_port

[0148] target9_ip = 10.101.0.9

[0149] target9_port = 1194

[0150] target9wan_port = 11949

[0151] set nat destination rule 99 inbound-interface $waneth

[0152] set nat destination rule 99 destination address $wan_ip

[0153] set nat destination rule 99 destination port $target9wan_port

[0154] set nat destination rule 99 source address 0.0.0.0 / 0

[0155] set nat destination rule 99 protocol tcp

[0156] set nat destination rule 99 translation address $target9_ip

[0157] set nat destination rule 99 translation port $target9_port

[0158] target10_ip = 10.101.0.10

[0159] target10_port = 1194

[0160] target10wan_port = 11950

[0161] set nat destination rule 910 inbound-interface $waneth

[0162] set nat destination rule 910 destination address $wan_ip

[0163] set nat destination rule 910 destination port $target10wan_port

[0164] set nat destination rule 910 source address 0.0.0.0 / 0

[0165] set nat destination rule 910 protocol tcp

[0166] set nat destination rule 910 translation address $target10_ip

[0167] set nat destination rule 910 translation port $target10_port commit

[0168] save

[0169] sudo reboot

[0170] The above script sets two variables, wancidr and lancidr, representing the IP addresses of the WAN and LAN interfaces, respectively, when configuring the WAN and LAN interfaces. It then uses the ip command and grep to determine the names (waneth and laneth) and IP addresses (wanip and lanip) of these interfaces and removes the DHCP configuration for the WAN and LAN interfaces, setting static IP addresses. When configuring NAT rules, it configures source NAT for the WAN interface, allowing all traffic from the internal network to masquerade to access the internet. When configuring the firewall, it defines two firewall names, wan and local, sets the default action to drop (discard) for all traffic not explicitly allowed, and configures firewall rules for each interface, including the local firewall. The script adds a rule to allow SSH connections (port 22) from a specific IP address (10.101.0.254). It configures a series of port forwarding rules, each forwarding traffic from a specific port on the WAN interface to a different server and port in the internal network. With the above configuration, the first virtual machine VPN exit router function is achieved, allowing personnel on the internet side to participate in the exercise to access the team subnet through the VPN.

[0171] Exemplarily, the embodiment also configures the second virtual machine as a team exit router 140. The configuration script for the second virtual machine to implement the team exit routing function is as follows:

[0172] #! / bin / vbash

[0173] source / opt / vyatta / etc / functions / script-template

[0174] configure

[0175] wancidr=172.30

[0176] waneth=`ip a|grep $wancidr|awk '{print $7}'`

[0177] wanip=`ip a|grep $wancidr|awk '{print $2}'`

[0178] lancidr=192.168.0

[0179] laneth=`ip a | grep $lancidr | awk '{print $7}'`

[0180] lanip=`ip a | grep $lancidr | awk '{print $2}'`

[0181] lancidr2=`echo $lanip | awk -F\.' '{print $1"."$2"."$3}'`

[0182] # Configure port ip

[0183] del interface ethernet $waneth address dhcp

[0184] set interface ethernet $waneth address $wanip

[0185] del interface ethernet $laneth address dhcp

[0186] set interface ethernet $laneth address $lanip

[0187] # Set external network gateway

[0188] set system gateway-address 172.30.0.1

[0189] # Set nat forwarding

[0190] set nat source rule 100 outbound-interface $waneth

[0191] set nat source rule 100 source address 0.0.0.0 / 0

[0192] set nat source rule 100 translation address masquerade

[0193] # Configure local rules, prohibit all ports

[0194] firename=local

[0195] set firewall name $firename default-action 'drop'

[0196] set interfaces ethernet $waneth firewall local name $firename firename = local2

[0197] set firewall name $firename default-action 'drop'

[0198] set firewall name $firename rule 100 action 'accept'

[0199] set firewall name $firename rule 100 destination port 22

[0200] set firewall name $firename rule 100 source address $lancidr2.254

[0201] set firewall name $firename rule 100 protocol tcp

[0202] set interfaces ethernet $laneth firewall local name $firename

[0203] commit

[0204] save

[0205] sudo reboot

[0206] The above script configures the WAN and LAN interfaces for the second virtual machine, removes the DHCP configuration for the WAN and LAN interfaces, and sets static IP addresses for them; sets the gateway for the second virtual machine to access the external network through the team subnet, i.e., the local team network 130; configures NAT rules to masquerade all traffic from the internal network (source address 0.0.0.0 / 0, i.e., all addresses) so that they can access the Internet through the WAN interface; and configures local firewall rules for the WAN firewall and the LAN firewall, with a default action of 'drop' (i.e., discard all traffic that is not explicitly allowed), and adds a rule to allow traffic from a specific IP address.

[0207] Exemplarily, in some embodiments, a third virtual machine implementing the routing function of the drill competition system can also be configured as a drill competition router 150, which is connected with the team subnet, i.e., the local team network 130, so that each online team terminal 111 and the local team terminal 131 can access the competition answering platform of the drill competition system through the drill competition router 150.

[0208] The network attack and defense drill system of the embodiments of the present application enables the personnel participating in the drill on the Internet side to access the team subnet through VPN, access the answering platform through the drill competition system routing, and access the drill target through the team export routing; and enables the personnel participating in the drill on the local side to access the team subnet through hub access and the like, access the answering platform through the drill competition system routing, and access the drill target through the team export routing. Thus, the online use of the Internet access and the offline use of the intranet access of the drill personnel are simultaneously satisfied, the use scenario of the network attack and defense drill is expanded, and the flexibility of the network attack and defense drill is increased.

[0209] It can be understood that the above embodiments are only exemplary embodiments for illustrating the principles of the present application, and the present application is not limited thereto. Various modifications and improvements can be made by those of ordinary skill in the art without departing from the spirit and essence of the present application, and these modifications and improvements are also considered to be within the protection scope of the present application.

Claims

1. A cyber red teaming system, comprising: The system comprises an online team network, a VPN exit router, a local team network and a team exit router connected in sequence; The online team network is configured to access online team terminals, and the local team network is configured to access local team terminals; The VPN exit router is configured to access the online team terminals to the local team network; The team exit router is configured to enable the online team terminals and the local team terminals to access the cyber attack and defense exercise target.

2. The system of claim 1, wherein, The VPN exit router is provided with a first WAN interface and / or a first LAN interface.

3. The system of claim 2, wherein, The first WAN interface and / or the first LAN interface adopts a static IP address.

4. The system of claim 2, wherein, The first WAN interface is provided with a first wide area network firewall, and the first LAN interface is provided with a first local area network firewall; Both the first wide area network firewall and the first local area network firewall discard all traffic that is not explicitly allowed.

5. The system of claim 4, wherein, The first local area network firewall allows traffic from a specific IP address.

6. The system of claim 1, wherein, The team exit router is provided with a second WAN interface and / or a second LAN interface.

7. The system of claim 6, wherein, The second WAN interface and / or the second LAN interface adopts a static IP address.

8. The system of claim 6, wherein, The second WAN interface is provided with a second wide area network firewall, and the second LAN interface is provided with a second local area network firewall; Both the second wide area network firewall and the second local area network firewall discard all traffic that is not explicitly allowed.

9. The system of claim 8, wherein, The second local area network firewall allows traffic from a specific IP address.

10. The system of any one of claims 1 to 9, wherein, The system further comprises an exercise competition router; The exercise competition router is connected with the local team network, and is configured to enable the online team terminals and the local team terminals to access a competition answering platform.

Citation Information

Patent Citations

  • An industrial control network attack and defense experiment platform and a semi-physical simulation method

    CN109831443A

  • Attack and defense drill method and device, electronic equipment and computer storage medium

    CN115580452A

  • Cloud sharing industrial control network security target range system

    CN116319341A