The invention discloses an automated
network attack characteristic generation method, comprising the following steps: 1) a virtual
operating system is installed in a virtual host, an operation environment coincident with the real application of a brittle program is configured, and a taint data operation rule is configured; 2) the brittle program is started, all network input thereof is marked as the taint data to be monitored, the state of the taint data is recorded, and relative operation command of the taint data is recorded to form a taint transmission flow graph; 3) when the abnormal operation of the taint data is detected, a command sequence operated and handled by the brittle the taint data starting from the input
data pack is obtained from the taint transmission flow graph; 4) the command sequence is processed to be a compiling performing command, and a judging output
sentence is added to generate Turing-type
attack characteristics. The method of the invention is favourable for finding unknown bug
attack behaviour and extracting the
attack flow and has no need of obtaining brittle program
source code, the generated attack characteristics are more accurate, and the attack characteristic
generation process is automatic and quick.