Method for dynamic allocation of targets in network security range
By introducing virtual firewall technology into the cybersecurity range and dynamically adjusting target allocation, the problems of fixed target allocation and resource waste were solved, enabling teams to flexibly switch targets and improving exercise efficiency and automation.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-10-23
- Publication Date
- 2026-04-02
AI Technical Summary
Existing cybersecurity range technologies lack flexibility during exercises, resulting in fixed target allocations that cannot be frequently adjusted, leading to significant resource waste and an inability to support complex multi-team, multi-target scenarios.
Using virtual firewall technology, the target allocation is dynamically adjusted through the range control terminal. After a team completes the penetration, it automatically applies for a new target. After the referee approves the application, the firewall rules are modified to switch targets. This supports multiple teams to flexibly switch targets.
It improves the flexibility and resource utilization of exercises, reduces manual intervention and management costs, enhances the level of system automation and operational efficiency, and supports exercise needs in complex scenarios.
Smart Images

Figure CN2024126690_02042026_PF_FP_ABST
Abstract
Description
Methods for dynamically allocating targets in cybersecurity test ranges
[0001] Cross-reference to related applications
[0002] This application claims priority to Chinese Patent Application No. 202411331159.1, filed on September 24, 2024, entitled “Method for Dynamically Allocating Targets in a Cybersecurity Range”, the entire contents of which are incorporated herein by reference. Technical Field
[0003] This application relates to the fields of automation and control, and in particular to a method, electronic device and storage medium for dynamically allocating targets in a cybersecurity test range. Background Technology
[0004] With the rapid development of information technology, information competition between nations is intensifying, and cybersecurity issues are becoming increasingly serious. The essence of cybersecurity lies in confrontation, and the essence of confrontation is a contest of capabilities between the attackers and defenders. To enhance cybersecurity competitiveness, countries around the world have successively built cybersecurity test ranges for conducting red team / blue team exercises, cybersecurity technology research and development, product security testing, and cybersecurity skills training.
[0005] Existing cybersecurity range technologies typically assign targets to different teams at the start of an exercise and maintain this fixed allocation throughout the exercise. This fixed target allocation method lacks flexibility, leading to the following problems in practical operation:
[0006] Inability to flexibly switch targets: In existing technologies, once a target is assigned to a team, the connection between that target and the team is fixed, and it is impossible to flexibly switch targets throughout the exercise. This is particularly inconvenient in scenarios that require frequent adjustments to strategies or involve multiple teams.
[0007] Resource waste: When a team completes the infiltration or operation of a target, if there is no mechanism to reassign that target to another team, the target will remain idle, resulting in resource waste. Furthermore, because the allocation cannot be dynamically adjusted, the mismatch between the number of targets and the number of teams cannot be resolved in certain situations.
[0008] Lack of support for complex scenarios: In some complex cybersecurity exercise scenarios, multiple teams need to simultaneously infiltrate multiple targets and flexibly adjust target allocation at different times. These complex exercise requirements cannot be met by existing technologies and are usually only compensated for by manually adjusting network connections offline, which is inefficient.
[0009] In order to overcome these defects, there is an urgent need for a more flexible and intelligent network security range technology that can dynamically adjust the allocation of targets during the exercise, improve the realism and effectiveness of the exercise, and meet the needs of various complex scenarios. This is also the technical problem to be solved by the present application.
[0010] SUMMARY
[0011] The embodiments of the present application aim to at least solve one of the technical problems existing in the prior art, and provide a method for dynamically allocating targets in a network security range, comprising:
[0012] randomly allocating a target to each team and starting the exercise;
[0013] detecting whether the possession time of each team to the allocated target ends;
[0014] in the case of ending, disconnecting the access of the ended team to the allocated target, and in the case of not ending, judging whether the penetration of the not ended team to the allocated target is completed;
[0015] in the case of the not ended team completing the penetration to the allocated target, applying for a new target for it, and in the case of the not ended team not completing the penetration to the allocated target, maintaining the access of the not ended team to the allocated target until the possession time ends and disconnects the access of the not ended team to the allocated target;
[0016] applying for a new target for the team whose access to the allocated target is disconnected;
[0017] the referee audits the new target applied for by each team;
[0018] in the case of passing the audit, the range control end gives the access permission of the new target applied for by the team that passes the audit, and in the case of not passing the audit, after waiting for a preset time, reapplying for a new target for the team that does not pass the audit.
[0019] In combination with the first aspect, the number of targets is greater than or equal to the number of teams.
[0020] In combination with the first aspect, the target can be occupied by only one team in a single possession time.
[0021] In combination with the first aspect, the target becomes an empty target after the occupation by the team ends, and is reallocated as a new target when the team applies.
[0022] In combination with the first aspect, the access of the team to the historical occupied target is disconnected at the same time when the referee passes the new target application of the team.
[0023] With reference to the first aspect, in the case that the audit is passed, the target range control terminal gives the access right of the new target to the passed audit team, which includes giving the access right of the new target to the passed audit team by modifying the control program of the virtual firewall rule.
[0024] With reference to the first aspect, one end of the virtual firewall interaction port is connected to the network of the team, and the other end is connected to the network of the target range.
[0025] With reference to the first aspect, in the case that the audit is not passed, after waiting for a preset time, the team that fails the audit re-applies for a new target, which includes:
[0026] In the case that the audit is not passed, after waiting for a preset time, the team that fails the audit, the team whose time is up, and the team that completes the penetration of the target together apply for a new target.
[0027] The second aspect of the present application provides an electronic device, which includes:
[0028] one or more processors;
[0029] a storage unit configured to store one or more programs, which, when executed by the one or more processors, cause the one or more processors to implement the method for dynamically allocating targets in the network security target range.
[0030] The third aspect of the present application provides a computer readable storage medium, which stores a computer program, and the computer program, when executed by a processor, can implement the method for dynamically allocating targets in the network security target range.
[0031] The method for dynamically allocating targets in the network security target range, the electronic device, and the storage medium provided by the present application can increase a virtual firewall in an existing target range network, so that a team participating in the exercise can apply for a new target after completing the penetration task of a certain target. The function of flexibly switching targets for different exercise teams in the network security exercise process is realized. The flexibility of the exercise is improved, the team can switch targets at any time during the exercise, and resource waste is avoided; the utilization rate of target resources is optimized, complex exercise scenarios are supported, manual intervention and management costs are significantly reduced, and the automation level and operation efficiency of the system are improved. BRIEF DESCRIPTION OF DRAWINGS
[0032] FIG. 1 is a flowchart of the method for dynamically allocating targets in the network security target range according to an embodiment of the present application;
[0033] FIG. 2 is a schematic diagram of the network topology of the network security target range according to an embodiment of the present application;
[0034] FIG. 3 is a structural schematic diagram of an electronic device according to an embodiment of the present application. DETAILED DESCRIPTION
[0035] The exemplary embodiments will be described in detail herein below with reference to the accompanying drawings. In the following description, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments are not representative of all embodiments consistent with the present application.
[0036] The terminology used herein in the present application is merely for the purpose of describing particular embodiments and is not intended to limit the present application. The singular forms "a", "an" and "the" used in the present application and the appended claims are intended to include both singular and plural forms, unless the context clearly indicates otherwise. It should also be understood that the term "and / or" used herein is intended to mean any or all possible combinations of one or more associated listed items.
[0037] It should be understood that although the terms first, second, third, etc. can be employed in this application to describe various information, such information should not be limited to these terms. These terms are only used to distinguish one piece of information from another. For example, a first information can also be termed a second information, and similarly, a second information can also be termed a first information without departing from the scope of the present application. Depending on the context, the word "if' as used herein can be interpreted to mean "when" or "in response to determining".
[0038] As shown in FIG. 1, a flowchart of a method for dynamically allocating targets in a network security range according to an embodiment of the present application is shown. The method comprises the following steps:
[0039] Randomly allocate a target to each team and start the drill;
[0040] Detect whether the possession time of each team to the allocated target ends;
[0041] In the case of ending, disconnect the access of the ended team to the allocated target, and in the case of not ending, determine whether the not-ended team completes penetration to the allocated target;
[0042] In the case that the not-ended team completes penetration to the allocated target, apply for a new target for the not-ended team, and in the case that the not-ended team does not complete penetration to the allocated target, maintain the access of the not-ended team to the allocated target until the possession time ends and disconnect the access of the not-ended team to the allocated target;
[0043] Apply for a new target for the team whose access to the allocated target is disconnected;
[0044] The judge reviews the new targets applied by each team;
[0045] If the review is passed, the target range control terminal gives the team that passed the review access to the new target it applied for. If the review is not passed, the team that did not pass the review is given a new target after a preset time.
[0046] The control method is described below with reference to FIGS. 2-3.
[0047] As shown in FIG. 2, the network security range in the embodiment of the application has a network topology.
[0048] There are n teams and m targets in the exercise team, m is greater than or equal to n, each target is electrically connected to the range network, each team is electrically connected to the virtual firewall through a switch, and the range network is electrically connected to the virtual firewall.
[0049] The range network is also electrically connected to the range control terminal, the range control terminal issues a program to modify the virtual firewall policy through the range network, cuts off the access of any exercise team to the existing target, and allocates a new target to the exercise team.
[0050] Before the exercise starts, each team is allocated a target.
[0051] Specifically, n targets are randomly selected from m targets, and the n targets are randomly allocated to the n teams one by one, and each team has and only corresponds to one target.
[0052] After the targets are allocated, the exercise starts, and each team starts to attack the allocated target. The accessible time of each team to the allocated target is limited, and this time is called possession time.
[0053] Optionally, the possession time is fixed, and some teams have already captured the target before the possession time ends. In this case, it is called that the penetration of the allocated target is completed.
[0054] If the penetration of the allocated target is completed before the possession time ends, the team is given a new target.
[0055] If the penetration of the allocated target is not completed before the possession time ends, the team continues to attack, maintains the access of the team to the target, and applies for a new target for the team until the possession time ends.
[0056] If some teams have not captured the allocated target, i.e., the penetration of the allocated target is not completed, the access of the team to the target is cut off after the possession time ends, and a new target is applied for the team.
[0057] The judge reviews the new target applied by each team, which can be manually reviewed by the judge or automatically reviewed according to the pre-set review rules.
[0058] The review content includes but is not limited to determining whether the new target applied by the application team is in an empty state, whether the application team is allowed to continue to apply, and prioritizing the application of the application team according to the historical exercise results of each application team.
[0059] After the judge reviews the new target applied by each team and passes, the target control terminal modifies the control program of the virtual firewall rule to give the team that passes the review access permission to the new target.
[0060] Specifically, the target control terminal controls the modification of the control program of the virtual firewall rule to cut off the network access permission of the team to the previously occupied target, modifies the firewall rule of the virtual firewall, stops the communication between the team and the old target, and ensures that the data flow cannot pass through the connection. The purpose of this step is to avoid the team still being able to access the old target after occupying the new target, to ensure the fairness of the competition and the standardization of the exercise.
[0061] At the same time as disconnecting the old target connection, the rule of the virtual firewall will be updated to allow the team that passes the review to access the new target allocated to it. The control program will dynamically generate a new firewall rule to specify the communication path between the IP address or network area of the team and the network area of the new target, thereby ensuring that the team can successfully establish a network connection with the new target and continue the penetration test or other exercise tasks.
[0062] This process does not require human intervention and relies entirely on the automated program interaction of the target control terminal and the virtual firewall, greatly improving the efficiency and smoothness of the exercise. Through this method of dynamically modifying the firewall rule, flexible attack and defense exercises can be carried out by multiple teams in the target range at different time periods for different targets, improving the flexibility and intelligence level of the network target range.
[0063] In the case where the judge reviews the new target applied by each team and fails, the team that fails the review waits for a preset time, which is not limited to a fixed time. Optionally, the preset time is the time when the next round of team exercise ends and applies for a new target, which includes teams that complete penetration in advance and teams that occupy time.
[0064] The method for dynamically allocating targets in a network security range, the electronic device and the storage medium provided by the embodiments of the present application can increase a virtual firewall in an existing target range network, so that a team participating in the exercise can apply for a new target after completing a penetration task on a certain target. The function of flexibly switching targets for different exercise teams during a network security exercise is realized. The flexibility of the exercise is improved, the team can switch targets at any time during the exercise, resource waste is avoided, the utilization rate of target resources is optimized, complex exercise scenarios are supported, manual intervention and management costs are significantly reduced, and the automation level and operation efficiency of the system are improved.
[0065] The electronic device 300 can be a desktop computer, a notebook computer, a palm computer, a cloud server and the like. The electronic device 300 can include but is not limited to a processor 301 and a memory 302. Those skilled in the art can understand that FIG. 3 is only an example of the electronic device 300 and does not constitute a limitation on the electronic device 300, and can include more or fewer components than the diagram, or combine certain components, or different components, for example, the electronic device can also include an input / output device, a network access device, a bus and the like.
[0066] The processor 301 can be a central processing unit (CPU), and can also be other general-purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), field programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor.
[0067] The memory 302 can be an internal storage unit of the electronic device 300, for example, a hard disk or a memory of the electronic device 300. The memory 302 can also be an external storage device of the electronic device 300, for example, a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card and the like equipped on the electronic device 300. Alternatively, the memory 302 can include both the internal storage unit and the external storage device of the electronic device 300. The memory 302 is used to store the computer program 303 and other programs and data required by the electronic device. The memory 302 can also be used to temporarily store data that has been output or will be output.
[0068] Those skilled in the art can clearly understand that, for the convenience and brevity of description, only the division of the above functional units and modules is taken as an example, and in actual application, the above functions can be completed by different functional units and modules according to needs, that is, the internal structure of the device is divided into different functional units or modules to complete all or part of the functions described above. Each functional unit and module in the embodiment can be integrated in one processing unit, or each unit can be physically present separately, or two or more units can be integrated in one unit. The above integrated unit can be realized in the form of hardware or software functional unit. In addition, the specific name of each functional unit and module is only for easy distinction, and does not limit the protection scope of the application. The specific working process of the units and modules in the above system can refer to the corresponding process in the foregoing method embodiments, which will not be repeated here.
[0069] In the above embodiments, the description of each embodiment has its own emphasis, and the parts not described or recorded in detail in a certain embodiment can be referred to the related description of other embodiments.
[0070] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be realized in electronic hardware or a combination of computer software and electronic hardware. Whether the functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the application.
[0071] In the embodiments provided in the present application, it should be understood that the disclosed devices / equipment and methods can be implemented in other ways. For example, the device / equipment embodiments described above are only schematic, for example, the division of modules or units is only a logical function division, and actual implementation can have another division manner, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the shown or discussed mutual units can be indirect coupling or communication connection through some interface, device or unit, which can be electrical, mechanical or other forms.
[0072] The units described as separate components can or can not be physically separated, and the components shown as units can or can not be physical units, that is, they can be located in one place, or can be distributed on multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the embodiment.
[0073] In addition, each of the function units in each of the embodiments of the present application can be integrated in one processing unit, or each unit can be physically present separately, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of a software function unit.
[0074] If the integrated module / unit is realized in the form of a software function unit and sold or used as an independent product, it can be stored in a computer readable storage medium. Based on such understanding, all or part of the processes in the above-mentioned embodiment methods can also be implemented by a computer program instructing related hardware to complete, and the computer program can be stored in a computer readable storage medium. The computer program can be executed by a processor to implement the steps of each method embodiment. The computer program can include computer program code, which can be in the form of source code, object code, executable file, or some intermediate form. The computer readable medium can include any entity or device capable of carrying the computer program code, recording medium, U disk, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signal, telecommunication signal, and software distribution medium, etc. Optionally, the readable storage medium is a non-transitory readable storage medium. It should be noted that the content contained in the computer readable medium can be appropriately increased or decreased according to the requirements of legislation and patent practice in the jurisdiction, for example, in some jurisdictions, according to legislation and patent practice, the computer readable medium does not include electrical carrier signals and telecommunication signals.
[0075] The above embodiments are only used to illustrate the technical solutions of the present application, but not to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that they can modify the technical solutions recorded in the foregoing embodiments, or make equivalent replacements for some technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application, and should be included in the protection scope of the present application.
Claims
1. A method of dynamically allocating targets in a cyber range, the method comprising: The method comprises: randomly assigning a target to each team and starting the drill; detecting whether the possession time of each team on the assigned target ends; in the case of ending, disconnecting the access of the ended team to the assigned target, and in the case of not ending, judging whether the penetration of the not ended team on the assigned target is completed; in the case that the penetration of the not ended team on the assigned target is completed, applying a new target to the not ended team, and in the case that the penetration of the not ended team on the assigned target is not completed, maintaining the access of the not ended team to the assigned target until the possession time ends and disconnects the access of the not ended team to the assigned target; applying a new target to the team whose access to the assigned target is disconnected; the judge audits the new target applied by each team; in the case of passing the audit, the range control end gives the access permission of the new target applied by the passed team to the range control end, and in the case of failing the audit, after waiting for a preset time, the failed team applies a new target.
2. The method of claim 1, wherein, The number of the targets is greater than or equal to the number of the teams.
3. The method of claim 1, wherein, The target can be possessed by only one team in a single possession time.
4. The method of claim 1, wherein, The target becomes an empty target after being possessed by the team, and is re-assigned as a new target when the team applies.
5. The method of claim 1, wherein, The judge audits the new target applied by each team.
6. The method of claim 1, wherein, The range control end gives the access permission of the new target applied by the passed team to the range control end.
7. The method of claim 6, wherein, The virtual firewall interactive port is connected to the network of the team at one end and to the network of the range at the other end.
8. The method of claim 1, wherein, In the case of failing the audit, after waiting for a preset time, the failed team, the team whose possession time ends and the team whose penetration of the target is completed apply a new target together. It comprises:
9. An electronic device, comprising: one or more processors; a storage unit for storing one or more programs, which can make the one or more processors implement the method for dynamically assigning targets in the network security range according to any one of claims 1 to 8 when the one or more programs are executed by the one or more processors. The computer program can implement the method for dynamically assigning targets in the network security range according to any one of claims 1 to 8 when executed by the processor.
10. A computer-readable storage medium having stored thereon a computer program, characterized in that,
Citation Information
Patent Citations
Attack and defense evaluation method and device
CN109685347A
Independent dynamic network security target range system, equipment and application method thereof
CN115225410A
Automatic vulnerability repair control method and system based on network attack and defense drill
CN116506220A
Practical operation result verification method and system for network security target range
CN118296593A
Cyber attack practice system, practice environment providing method, and, practice environment providing program
JP2015231138A