WO2025246720A1 - 网络安全测试方法、电子设备、介质和计算机程序产品 - Google Patents
网络安全测试方法、电子设备、介质和计算机程序产品Info
- Publication number
- WO2025246720A1 WO2025246720A1 PCT/CN2025/089815 CN2025089815W WO2025246720A1 WO 2025246720 A1 WO2025246720 A1 WO 2025246720A1 CN 2025089815 W CN2025089815 W CN 2025089815W WO 2025246720 A1 WO2025246720 A1 WO 2025246720A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- target
- network
- controlled device
- simulation
- test scenario
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Pending
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/12—Detection or prevention of fraud
- H04W12/121—Wireless intrusion detection systems [WIDS]; Wireless intrusion prevention systems [WIPS]
- H04W12/122—Counter-measures against attacks; Protection against rogue devices
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/30—Security of mobile devices; Security of mobile applications
- H04W12/37—Managing security policies for mobile devices or for controlling mobile applications
Definitions
- This application relates to the field of network testing technology, and in particular to a network security testing method, electronic device, medium, and computer program product.
- Air interface attacks on wireless networks refer to attacks targeting the wireless transmission medium in wireless communication networks. This type of network attack utilizes the broadcast characteristics of wireless signals and potential security vulnerabilities.
- the air interface refers to the wireless transmission medium between mobile devices (such as mobile phones and Wi-Fi devices) and wireless access points (such as base stations and routers).
- DDoS Distributed Denial of Service
- This application provides a network security testing method, electronic device, medium, and computer program product.
- embodiments of this application provide a network security testing method, the method comprising: acquiring a test scenario simulation instruction, and determining a target simulated operation and a target controlled device according to the test scenario simulation instruction; executing the target simulated operation on a target network device through the target controlled device to build a network security test scenario; and performing security testing on a target network corresponding to the target network device based on the network security test scenario to obtain a security test report of the target network under the network security test scenario.
- embodiments of this application provide an electronic device, including: one or more processors; and a memory storing one or more programs thereon, wherein when the one or more programs are executed by the one or more processors, the one or more processors implement the network security testing method described in the first aspect above.
- embodiments of this application provide a computer-readable storage medium having a computer program stored thereon, wherein the program, when executed by a processor, implements the network security testing method described in the first aspect above.
- embodiments of this application provide a computer program product, including a computer program that, when executed by a processor, implements the network security testing method described in the first aspect above.
- Figure 1 is a flowchart illustrating a network security testing method provided in an embodiment of this application
- Figure 5 is another flowchart illustrating a network security testing method provided in an embodiment of this application.
- Figure 6 is another flowchart illustrating a network security testing method provided in an embodiment of this application.
- Figure 7 is another flowchart illustrating a network security testing method provided in an embodiment of this application.
- Figure 8 is another flowchart illustrating a network security testing method provided in an embodiment of this application.
- Figure 10A is another flowchart illustrating a network security testing method provided in an embodiment of this application.
- Figure 10E is a schematic diagram of an abnormal MAC PDU message provided in an embodiment of this application.
- Figure 11A is a schematic block diagram of a terminal provided in an embodiment of this application.
- FIG 11B is a schematic block diagram of a scheduling processing component provided in an embodiment of this application.
- Figure 12 is a schematic diagram of the device structure of the electronic device provided in the embodiment of this application.
- This application provides a network security testing method, electronic device, medium, and computer program product, which aims to perform target simulation operations on target network devices through a target controlled device, thereby building a network security testing scenario to simulate a network attack on the target network, and then test the target network to help improve the network security detection and defense capabilities of the target network devices.
- this application embodiment provides a network security testing method, which can be applied to a terminal.
- the network security testing method of this application embodiment may include, but is not limited to:
- Step S102 Perform target simulation operations on the target network device through the target controlled device to build a network security test scenario
- This application can build a network security test scenario by performing target simulation operations on the target network device through the target controlled device, thereby simulating the situation where the target network is subjected to network attacks, and then testing the target network to help improve the network security detection and network defense capabilities of the target network device.
- a test scenario simulation instruction is obtained, and the target simulation operation and target controlled device are determined according to the test scenario simulation instruction; wherein, the test scenario simulation instruction is used to instruct the simulated construction of a test scenario for the target network.
- the network security testing method of this application embodiment aims to simulate a network attack on the target network, and then test the target network. Therefore, the test scenario simulation instruction is used to instruct the simulated construction of a test scenario for the target network.
- the corresponding target simulation operation and target controlled device can be determined according to the scenario simulation instruction.
- obtaining the test scenario simulation instruction in step S101 may include, but is not limited to:
- Step S201 Display the configuration operation interface
- Step S202 In response to the input from the target object on the configuration operation interface, obtain the scene simulation configuration parameters
- Step S203 Based on the scenario simulation configuration parameters, generate test scenario simulation instructions for the target network.
- steps S201 to S203 can be used to first display a configuration operation interface, and then, in response to the input from the target object on the configuration operation interface, obtain scenario simulation configuration parameters. Based on the scenario simulation configuration parameters, a test scenario simulation command for the target network can be generated.
- the target object can refer to a user who initiates a security test scenario simulation for the target network.
- a user interface is the interface for communication and interaction between a person and a computer system. It includes the screen, pages, and controls and visual elements that the user can see and interact with the system.
- the configuration operation interface is a user interface used to receive input from the target object.
- the target object can be input in the configuration operation interface.
- the type of target simulation operation the target controlled device participating in the scenario simulation, the number of target controlled devices, and the time interval of the scenario simulation or other types of scenario simulation configuration parameters, test scenario simulation instructions for the target network are generated.
- scenario simulation configuration parameters can be obtained through a configuration interface, and then test scenario simulation instructions for the target network can be generated based on these parameters. This provides a convenient reference benchmark for building network security test scenarios, contributing to the efficient implementation of network security testing methods.
- the security test report of the target network in the network security test scenario after obtaining the security test report of the target network in the network security test scenario, it can also be displayed in the user interface for evaluation and analysis of the results of this security test scenario simulation.
- the step S101 of determining the target simulation operation and the target controlled device according to the test scenario simulation command may include, but is not limited to:
- Step S301 Based on the test scenario simulation instructions, determine the controlled device identification information and controlled device operation information that match the network security test scenario;
- Step S303 Based on the controlled device operation information, determine the target simulated operation performed by the target controlled device in the network security test scenario from the target network operation data.
- the test scenario simulation command is used to instruct the simulation setup of a test scenario for the target network.
- This can include information such as the type of target simulation operation, the target controlled devices participating in the scenario simulation, the number of target controlled devices, and the time interval for the scenario simulation.
- the controlled device identification information and controlled device operation information matching the network security test scenario can be determined.
- the controlled device identification information is a unique identifier for the target controlled device.
- the target controlled device pointed to by that identification information in the target network is used to participate in the simulation setup of the network security test scenario.
- the controlled device operation information is used to configure the target simulation operations that the target controlled device needs to perform. Therefore, based on the controlled device operation information, it can be determined that the target controlled device is the target simulation operation to be performed in the simulated network security test scenario.
- the target controlled device that needs to participate in the simulated network security test scenario can be clearly identified, as well as the target simulated operation that the target controlled device needs to perform, which helps to efficiently build the network security test scenario.
- the test scenario simulation instruction includes scenario simulation type information, device configuration parameters, and operation simulation frequency.
- Step S301 determines the controlled device identification information and controlled device operation information matching the network security test scenario based on the test scenario simulation instruction, which may include, but is not limited to:
- Step S401 Determine the simulation scenario mode corresponding to the test scenario simulation instruction based on the scenario simulation type information in the test scenario simulation instruction;
- Step S402 Based on the simulation scenario method and operation simulation frequency, obtain the controlled device identification information and controlled device operation information that match the device configuration parameters from the scenario database.
- the test scenario simulation instruction includes scenario simulation type information, device configuration parameters, and operation simulation frequency.
- the scenario simulation type information indicates the type of network security test scenario to be simulated; the device configuration parameters refer to the configuration parameters of the target controlled device; and the operation simulation frequency corresponds to the frequency at which the target controlled device performs the target simulated operation. The shorter the time interval between two target simulated operations, the higher the operation simulation frequency.
- the simulation scenario mode corresponding to the test scenario simulation instruction can be determined based on the scenario simulation type information in the test scenario simulation instruction, thereby determining the mode in which the target controlled device performs the target simulated operation.
- controlled device identification information and controlled device operation information matching the device configuration parameters are obtained from the scenario database.
- the controlled device identification information is used to clarify which target controlled devices need to perform the target simulated operation
- the controlled device operation information is used to clarify the operation that the target controlled device needs to perform and the corresponding operation frequency.
- the scenario database refers to a pre-set database used to store various device identification information and device operation information. Each type of network security test scenario stores corresponding device identification information and device operation information in the scenario database. Therefore, based on the simulation scenario method and operation simulation frequency, the controlled device identification information and controlled device operation information that match the device configuration parameters can be obtained from the scenario database.
- the controlled device identification information matching the device configuration parameters is obtained.
- the method by which the target controlled device performs the target simulation operation is determined, resulting in a simulation scenario mode.
- corresponding controlled device operation information is configured for the controlled device identification information.
- the test scenario simulation command can be explicitly transformed into a command to directly control the target controlled device, enabling the target controlled device to perform target simulation operations on the target network device, thereby building a network security test scenario to simulate a network attack on the target network.
- step S102 involves performing target simulation operations on a target network device using a target controlled device to establish a network security test scenario; wherein the target network device is used to maintain the operation of the target network.
- the target network is the network used as the test target, and the target network is maintained and operated by the target network device.
- the target network device as the operating and maintenance device of the target network, is responsible for the transmission and reception of wireless signals, resource management, mobility management, connection establishment and maintenance, data transmission, signal coverage, quality control, security control, billing and authentication, network operation support, emergency services, and network function integration in the target network, ensuring that users of the target network can obtain stable, secure, and efficient communication services.
- performing target simulation operations on the target network device using a target controlled device aims to interfere with the target network device's role in maintaining the target network, thereby establishing a network security test scenario to simulate a network attack on the target network.
- the target network device can be a base station responsible for providing wireless access, managing wireless resources, supporting mobility, and ensuring data transmission and communication quality.
- connection request overload can all be used to simulate denial-of-service (DoS) attacks against wireless communication networks. They exhaust network resources in different ways, causing legitimate users of the target network to be unable to obtain the services they need.
- DoS denial-of-service
- RRC connections are a critical component of the 3GPP standard used to manage communication between user equipment and the network, responsible for the transmission of signaling and control information. Attackers send a large number of RRC connection requests without completing the connection establishment process, causing the base station to continuously allocate resources for these incomplete connections, eventually exhausting the RRC connection resources and preventing legitimate users from establishing new RRC connections.
- Abnormal data packets are simulated messages. These involve sending malformed or anomalous data packets to the network. These packets may be of incorrect length, of unknown type, or contain illegal information. Base stations need to process these packets, but because they do not conform to protocol specifications, processing them consumes additional resources and may lead to errors or service interruptions. Attackers may exploit this to launch attacks, sending a large number of abnormal packets to overwhelm the base station's processing capacity and thus disrupt normal service.
- the network security testing method of this application embodiment can test the performance of the target network in the above three network security testing scenarios, thereby obtaining the corresponding security test report of the target network in the network security testing scenarios, so as to take corresponding security measures, such as enhancing network monitoring, implementing traffic filtering, and optimizing resource management, to defend against these network attacks and protect the stability and reliability of the target network.
- the target controlled device If the target controlled device needs to establish a connection with the target network, it will initiate a random access procedure by sending a preamble sequence to the target network device.
- the target network device After receiving the preamble sequence, if resources permit, the target network device will send a random access response to the target controlled device, which includes uplink and downlink resource allocation information.
- the target controlled device uses the resources allocated in the random access response to send a connection request message to the target network device to request the establishment of a connection;
- the target network device After the target network device processes the connection request, if it accepts the request, it will send a connection establishment message to the target controlled device, which includes the connection configuration information.
- the target network device initiates integrity protection and encryption mechanisms to ensure communication security
- the target network device sends an authentication request to the target controlled device, and the target controlled device replies with an authentication response.
- the core network then performs authentication.
- the core network is the central part of the target network, responsible for handling major network management and data transmission functions. As the brain of the target network, it connects the wireless access network to external networks, such as the Internet, other telecommunications networks, and the networks of various service providers.
- the target network device After successful authentication, the target network device sends an attach accept message to the core network, and the core network sends an attach complete message to the target controlled device.
- the target controlled device can begin to transmit data to the target network
- the target network device when it is determined that the target simulation operation corresponds to connection request overload, the target network device can be subjected to the target simulation operation in the following manner:
- Step S501 Modify the network connection memory variable of the target controlled device to set the connection acknowledgment message of the target controlled device to a rejected state;
- Step S502 Re-initiate a network connection request from the target controlled device to the target network device corresponding to the test scenario simulation command, and receive the connection establishment information from the target network device in response to the network connection request;
- Step S503 Based on the connection confirmation message and connection establishment information in the rejection state, control the target controlled device to refuse to reply with the connection establishment information, and return to execute to re-initiate a network connection request to the target network device corresponding to the test scenario simulation command through the target controlled device, thereby obtaining the network security test scenario.
- connection request overload is an attack method that overwhelms network or system resources by sending a large amount of traffic or requests to network devices.
- the purpose of this type of network attack is to render network services unavailable, as it exhausts bandwidth, processing power, or storage space.
- connection request overload may target base stations or the core network, achieved by sending a large number of meaningless signals or data packets.
- step S501 modifies the network connection memory variable of the target controlled device to set the connection acknowledgment message of the target controlled device to a rejected state. It should be noted that modifying the network connection memory variable of the target controlled device to set the connection acknowledgment message of the target controlled device to a rejected state means that after the target network device sends a random access response to the target controlled device, the target controlled device will not send an acknowledgment message to complete the normal connection establishment process.
- steps S502 to S504 involve re-initiating a network connection request from the target controlled device to the target network device corresponding to the test scenario simulation command, and receiving connection establishment information from the target network device in response to the network connection request. Based on the connection confirmation message and connection establishment information in the rejection state, the target controlled device is controlled to refuse to reply with connection establishment information, and the process returns to re-initiating a network connection request from the target controlled device to the target network device corresponding to the test scenario simulation command, thus obtaining the network security test scenario.
- the target controlled device initiating the network connection request has undergone modification of its network connection memory variables, it will be controlled to refuse to reply with connection establishment information based on the connection confirmation message and connection establishment information in the rejection state. Afterwards, the process returns to re-initiating a network connection request from the target controlled device to the target network device corresponding to the test scenario simulation command, thus obtaining the network security test scenario.
- connection confirmation message of the target controlled device is set to a rejected state
- the target network device after the target network device sends a random access response to the target controlled device, the target controlled device will not send an confirmation message to complete the normal connection establishment process.
- the target network device will then actively release the previously received network connection request after waiting for a period of time. Based on this, in embodiments of this application, after the target controlled device refuses to reply to the connection establishment information, it re-initiates a network connection request to the target network device. The target network device then needs to process the newly initiated network connection request while waiting to release the previous network connection request.
- embodiments of this application can construct a network security test scenario corresponding to connection request overload, so as to conduct security testing on the target network corresponding to the target network device and obtain a security test report of the target network under the network security test scenario.
- the target simulated operation corresponds to connection request overload. Only when the target controlled device meets a first preset condition can the target controlled device be controlled to stop initiating network connection requests to the target network device, thus terminating the setup of the network security test scenario.
- the first preset condition is used to define that the target controlled device has met the conditions for terminating the setup of the network security test scenario. For example, if the target controlled device receives a target simulated operation stop command and determines that the first preset condition is met, it can stop initiating network connection requests to the target network device, thus terminating the setup of the network security test scenario. It should be understood that there are various embodiments in which the target controlled device meets the first preset condition, and these are not limited to the examples described above.
- a network security test scenario can be built to simulate the target network encountering connection request overload under the condition that the target simulated operation corresponds to the connection request overload, thereby testing the target network and helping to improve the network security detection and network defense capabilities of the target network device.
- the target network device when it is determined that the target simulation operation corresponds to connection resource exhaustion, the target network device is subjected to the target simulation operation in the following manner:
- Step S601 Modify the authentication memory variable of the target controlled device to set the authentication confirmation message of the target controlled device to a rejected state
- Step S602 Re-initiate a network connection request from the target controlled device to the target network device corresponding to the test scenario simulation command, and receive connection establishment information from the target network device in response to the network connection request;
- Step S603 Generate connection confirmation information corresponding to the connection establishment information based on the connection establishment information, and send the connection confirmation information to the target network device;
- Step S604 Obtain the authentication request in response to the connection confirmation information of the target network device through the target controlled device; based on the authentication confirmation message in the rejection state, control the target controlled device to refuse to reply to the authentication request; return to execute the network connection request to the target network device to obtain the network security test scenario.
- connection resource exhaustion is a type of network attack that focuses on depleting the Radio Resource Control (RRC) connection resources in a wireless communication network.
- RRC connections are a critical component of the 3GPP standard used to manage communication between user equipment and the network, responsible for the transmission of signaling and control information. Attackers send a large number of RRC connection requests without completing the connection establishment process, causing the base station to continuously allocate resources for these incomplete connections, ultimately exhausting the RRC connection resources and preventing legitimate users from establishing new RRC connections.
- step S601 modifies the authentication memory variable of the target controlled device to set the authentication confirmation message of the target controlled device to a rejected state. It should be noted that modifying the authentication memory variable of the target controlled device to set the authentication confirmation message of the target controlled device to a rejected state means that after the target network device sends an authentication request to the target controlled device, the target controlled device will, based on the rejected authentication confirmation message, control the target controlled device to refuse to reply to the authentication request, thereby not sending an authentication response to the core network of the target network to complete authentication.
- steps S602 to S604 involve re-initiating a network connection request from the target controlled device to the target network device corresponding to the test scenario simulation command, receiving connection establishment information from the target network device in response to the network connection request, generating connection confirmation information corresponding to the connection establishment information based on the connection establishment information, and sending the connection confirmation information to the target network device. This means that a connection has been established between the target controlled device and the target network device.
- the target controlled device further obtains the authentication request from the target network device in response to the connection confirmation information, and, based on the authentication confirmation message in a rejected state, controls the target controlled device to refuse to reply to the authentication request, returning to initiating a network connection request to the target network device, thus obtaining the network security test scenario.
- the target controlled device initiating the network connection request has modified its authentication memory variables, after obtaining the authentication request, and after the target network device sends the authentication request to the target controlled device, the target controlled device will refuse to reply to the authentication request based on the authentication confirmation message in a rejected state. After that, it will return to execute and re-initiate a network connection request to the target network device corresponding to the test scenario simulation command through the target controlled device, thus obtaining the network security test scenario.
- the target network device because the authentication confirmation message of the target controlled device is set to a rejected state, after a connection is established between the target controlled device and the target network device, the target network device sends an authentication request to the target controlled device. However, the target controlled device, based on the rejected authentication confirmation message, refuses to reply to the authentication request and cannot complete the normal authentication process. After waiting for a period of time, the target network device will actively release the connection previously established with the network controlled device. Based on this, in the embodiments of this application, after the target controlled device refuses to reply to the authentication request, it re-initiates a network connection request to the target network device to establish a new connection.
- the target network device then needs to process the newly initiated network connection request while waiting to release the previous connection to establish a new connection. As a result, if the number of newly established connections exceeds the number of connections waiting to be released, the target network device will enter a state of connection resource exhaustion.
- the embodiments of this application can construct a network security test scenario corresponding to connection resource exhaustion, so as to conduct security testing on the target network corresponding to the target network device and obtain a security test report of the target network under the network security test scenario.
- the target simulated operation corresponds to the exhaustion of connection resources. Only when the target controlled device meets a second preset condition can the target controlled device be controlled to stop initiating network connection requests to the target network device, thus terminating the setup of the network security test scenario.
- the second preset condition is used to define whether the target controlled device has met the conditions for terminating the setup of the network security test scenario. For example, if the target controlled device receives a target simulated operation stop command and determines that the second preset condition is met, it can stop initiating network connection requests to the target network device, thus terminating the setup of the network security test scenario. It should be understood that there are various embodiments in which the target controlled device meets the second preset condition, and these are not limited to the examples described above.
- a network security test scenario can be built to simulate the situation where the target network encounters a situation where connection resources are exhausted, thereby testing the target network and helping to improve the network security detection and network defense capabilities of the target network devices.
- step S602 re-initiates a network connection request through the target controlled devices to the target network device corresponding to the test scenario simulation command, and receives connection establishment information from the target network device in response to the network connection request.
- This may include, but is not limited to:
- Step S701 For the first number of target controlled devices after modifying the authentication memory variables, determine the preamble sequence of each target controlled device in the request time slot, so that the preamble sequence corresponding to each target controlled device is different.
- each target controlled device initiates a network connection request to the target network device based on the corresponding preamble sequence.
- a request time slot refers to the time period during which a target controlled device initiates a network connection request.
- steps S701 to S702 require determining the preamble sequence for each of the first number of target controlled devices after modifying the authentication memory variables, ensuring that the preamble sequence for each target controlled device is unique. Furthermore, each target controlled device initiates a network connection request to the target network device based on its corresponding preamble sequence. This improves the success rate of concurrent random access attempts by multiple target controlled devices, preventing conflicts and resource contention caused by multiple target controlled devices using the same preamble sequence.
- step S701 for the first number of target controlled devices after modifying the authentication memory variable, determines the preamble sequence of each target controlled device in the requested time slot, which may include, but is not limited to:
- Step S801 Obtain a sequence index set including a second number of leader sequence indices; wherein, the leader sequence index is used to query candidate leader sequences;
- Step S802 Determine the device number corresponding to each target controlled device from the first number of target controlled devices
- Step S803 For each target controlled device, perform a modulo operation based on the device number and the second number to obtain the index number. Based on the index number, select the corresponding leader sequence index from the sequence index set, and configure the corresponding leader sequence for the target controlled device from the candidate leader sequences according to the leader sequence index.
- the preamble sequence index is used to determine the preamble sequence for each target controlled device in the request time slot, ensuring that the preamble sequence for each target controlled device is unique.
- Slot represents the slot number of the requested slot, and each Slot has a unique sequence number.
- Count[Slot] is used to record the number of UEs that send random access requests (Msg1) on a specific slot. This counter starts from 0 and counts independently for each slot to ensure that each device uses a different preamble sequence index under the same request slot.
- PreambleID represents the set of available leader sequence indices.
- the leader sequence index ranges from 0 to the total number of leader sequences, i.e., the second number.
- the embodiments of this application improve the success rate of contention-based access when multiple target controlled devices simultaneously initiate random access, and avoid multiple target controlled devices using the same preamble sequence, which could lead to conflicts and resource contention.
- the target simulation operation is performed on the target network device in the following manner:
- Step S901 Modify the channel memory variable of the target controlled device to set the channel transmission message of the target controlled device to an abnormal state
- Step S902 Re-establish connection between the target controlled device and the target network device corresponding to the test scenario simulation command; wherein, the data transmission between the target controlled device and the target network device is subject to the data transmission protocol.
- Step S903 Based on the channel transmission message in the abnormal state, generate simulated transmission data that does not conform to the data transmission protocol, and send the simulated transmission data to the target network device with which the connection has been established through the target controlled device, so that the target network device will identify the simulated transmission data as abnormal data and discard it, and return to execute the channel transmission message based on the abnormal state to generate simulated transmission data that does not conform to the data transmission protocol, thus obtaining the network security test scenario.
- abnormal data packet simulation involves sending malformed or anomalous data packets to the network. These anomalous data packets may be of incorrect length, of unknown type, or contain illegal information. Base stations need to process these packets, but because they do not conform to protocol specifications, processing consumes additional resources and may lead to errors or service interruptions. Attackers could exploit this to launch attacks, sending a large number of abnormal packets to overwhelm the base station's processing capacity, thereby affecting normal service.
- step S901 modifies the channel memory variable of the target controlled device to set the channel transmission message of the target controlled device to an abnormal state. It should be noted that modifying the channel memory variable of the target controlled device to set the channel transmission message of the target controlled device to a rejected state means that after the target controlled device establishes a connection with the target network device, the target controlled device will send simulated transmission data to the established target network device and send simulated transmission data to the target network device, thereby affecting the normal service of the target network.
- SRB1 Signaling Radio Bearer 1
- DATA packet Abnormal state
- the target network device will recognize the abnormal length of the SRB1 channel packets and discard them.
- steps S902 to S903 involve re-establishing a connection between the target controlled device and the target network device corresponding to the test scenario simulation command; wherein, data transmission between the target controlled device and the target network device is constrained by a data transmission protocol.
- simulated transmission data that does not conform to the data transmission protocol is generated based on the channel transmission message in the abnormal state.
- This simulated transmission data is then sent from the target controlled device to the established target network device, causing the target network device to identify the simulated transmission data as abnormal data and discard it.
- the target network device then returns to execute the channel transmission message based on the abnormal state to generate simulated transmission data that does not conform to the data transmission protocol, thus obtaining the network security test scenario.
- the target controlled device initiating the network connection request has modified its channel memory variables, after establishing a connection with the target network device, the target controlled device sends simulated transmission data to and from the target network device, causing the target network device to identify the simulated transmission data as abnormal and discard it. Subsequently, a new connection will be established between the target controlled device and the target network device corresponding to the test scenario simulation command, thus obtaining the network security test scenario.
- simulated transmission data that does not conform to the data transmission protocol can be generated based on the abnormal channel transmission messages after a connection is established between the target controlled device and the target network device. Furthermore, the target controlled device sends the simulated transmission data to the target network device with the established connection. It should be emphasized that data transmission between the target controlled device and the target network device is constrained by the data transmission protocol. Therefore, if the target network device receives simulated transmission data that does not conform to the data transmission protocol, it will identify it as abnormal data and discard it, failing to complete the normal data transmission process.
- the target controlled device repeatedly generates simulated transmission data that does not conform to the data transmission protocol based on the abnormal channel transmission messages and sends the simulated transmission data to the target network device with the established connection.
- the target network device receives simulated transmission data that does not conform to the data transmission protocol from the target controlled device for a long time, requiring frequent processing of the simulated transmission data as abnormal data, thus wasting a large amount of network resources in the target network device.
- the embodiments of this application can build a network security test scenario corresponding to the abnormal data simulation message, so as to conduct security tests on the target network device and the target network, and obtain a security test report of the target network under the network security test scenario.
- the target simulated operation corresponds to an abnormal data simulation message. Only when the target controlled device meets a third preset condition can the target controlled device be controlled to stop sending simulated transmission data to the target network device, thus terminating the setup of the network security test scenario.
- the third preset condition is used to define whether the target controlled device has met the conditions for terminating the setup of the network security test scenario. For example, if the target controlled device receives a target simulated operation stop command and determines that the third preset condition is met, it can stop sending simulated transmission data to the target network device, thus terminating the setup of the network security test scenario. It should be understood that there are various embodiments in which the target controlled device meets the third preset condition, and these are not limited to the examples described above.
- the simulated transmission data includes a message length identifier bit and a logical channel identifier bit.
- the generation of simulated transmission data that does not conform to the data transmission protocol in step S903 may include, but is not limited to:
- Step S1001 Determine the first constraint condition for the message length identifier bit and the second constraint condition for the logical channel identifier bit in the data transmission protocol;
- Step S1002 Generate simulated transmission data such that the simulated transmission data does not satisfy the first constraint condition in the message length identifier bit, or such that the simulated transmission data satisfies the second constraint condition in the logical channel identifier bit.
- a MAC PDU Medium Access Control Protocol Data Unit
- the simulated transmission data can be a MAC PDU message.
- the L bit (Length field) and LCID (Logical Channel ID) in the MAC PDU message are two key fields.
- the L bit can be a message length identifier for the simulated transmission data
- the LCID can be a logical channel identifier for the simulated transmission data.
- the data transmission protocol can be the transmission protocol followed when transmitting data using MAC PDU messages.
- the L bit is a field in the MAC PDU message used to indicate the length of the MAC PDU message.
- the value of the L bit represents the length of the payload (i.e., user data or control information) in the MAC PDU message, and the unit is usually bytes or bits, depending on the context.
- the maximum value of the L bit may be limited. For example, in LTE, the maximum value of the L bit is usually 65535, which means that the payload length of the MAC PDU message cannot exceed this value.
- LCID Logical Channel ID
- SRB1 Signaling Radio Bearer 1
- the reserved bits indicating the L-bit length refer to the reserved bits in the MAC PDU message used to indicate the length of the L-bit.
- the normal range for LCID is 0 to 32, which is the LCID value range specified by the 3GPP standard.
- MTU Maximum Transmission Unit
- the length of the L-bit should match the MTU size to ensure effective data transmission.
- the L bit of the MAC PDU message corresponds to the message length constraint in the data transmission protocol, and can be the first constraint.
- LCID is a field in a MAC PDU message used to identify logical channels.
- a physical channel can carry data from multiple logical channels.
- the LCID field distinguishes between different logical channels, ensuring data is correctly delivered to the target channel.
- Logical channels are divided into control channels (such as SRB1) and data channels (such as DRB).
- LCID helps differentiate between these different types of channels.
- LCID values typically range from 0 to 31, allowing for a maximum of 32 logical channels. Different LCID values correspond to different logical channels and different Quality of Service (QoS) requirements.
- QoS Quality of Service
- MAC PDU a typical MAC PDU message is shown.
- Reserved bits indicate the L-bit length; these bits are reserved to indicate the L-bit length, i.e., the effective payload length of the message.
- the Logical Channel ID identifies the logical channel to which the MAC PDU message belongs.
- the normal range for LCID is 0 to 32, which corresponds to the range of logical channel IDs defined in the 3GPP standard.
- MTU defines the maximum packet size that the network layer can process; common MTU values are 1400 or 1500 bytes.
- an abnormal MAC PDU message is shown.
- the reserved bit indicates the L-bit length, i.e., the effective payload length of the message. Since the LCID value ranges from 0 to 32 in the 3GPP standard, 50 is an abnormal value for the LCID. The target network device will recognize and discard such a message.
- An abnormal value for the L bit is set to 65535, which far exceeds the normal MTU size and is a non-compliant length value, causing the base station to discard the message.
- the LCID value of the MAC PDU message corresponds to the constraint of the number of logical channels in the data transmission protocol, and can be the second constraint.
- generating simulated transmission data such that the simulated transmission data exceeds 65535 in the L bit can determine that the simulated transmission data does not meet the first constraint condition in the message length identifier bit; or, generating simulated transmission data such that the simulated transmission data has a value of 50 in the LCID bit can determine that the simulated transmission data meets the second constraint condition in the logical channel identifier bit.
- sending simulated transmission data from the target controlled device to the target network device establishing the connection can be achieved by filling in an abnormal LCID in the MAC PDU packet. If the target controlled device fills in an abnormal LCID in the MAC PDU packet, the target network device will recognize the abnormal data packet and discard it.
- step S102 which involves performing target simulation operations on the target network device through the target controlled device to build a network security test scenario, may include, but is not limited to:
- the execution count is updated. This is to record and statistically analyze the execution count, facilitating the generation of a subsequent security test report.
- the network security test scenario simulates a network attack on the target network; therefore, the execution count simulates the number of times the target network is attacked. Based on the updated execution count, a network security test scenario is generated, designed to simulate a network security test scenario where the target network is subjected to multiple network attacks.
- a network security test scenario can be generated based on the updated number of executions, which may include, but is not limited to:
- a network security test scenario is generated.
- the intermediate simulation data refers to the number of times the target network is simulated to be attacked during the preset time interval. Based on the intermediate simulation data corresponding to each preset time interval, a network security test scenario is generated. The purpose is to statistically analyze the number of simulated network attacks on the target network at preset time intervals, and obtain the network security test scenario based on this.
- an AttckTimer can be set to start timing. Then, a network connection request is re-initiated through the target controlled device to the target network device corresponding to the test scenario simulation command, and connection establishment information in response to the network connection request is received from the target network device. Further, after obtaining the connection establishment information from the target network device, based on the rejected connection confirmation message and the connection establishment information, the target controlled device is controlled to refuse to reply with connection establishment information.
- the execution count of the target simulation operation is incremented by 1, and then execution returns to re-initiating a network connection request through the target controlled device to the target network device corresponding to the test scenario simulation command, thus obtaining the network security test scenario.
- the AttckTimer counts the accumulated execution count of the current target simulation operation every certain period of time, to facilitate the generation of a security test report in subsequent steps.
- an AttckTimer timer can be set to start timing. Then, the target controlled device with the modified authentication memory variable initiates a network connection request to the target network device corresponding to the test scenario simulation command at regular intervals; or, multiple target controlled devices with modified authentication memory variables sequentially initiate a network connection request to the target network device corresponding to the test scenario simulation command at predetermined time intervals. Further, after obtaining the authentication request sent by the target network device, based on the rejected authentication confirmation message, the target controlled device is controlled to refuse to reply to the authentication request.
- the execution count of the target simulation operation is incremented by 1, and then execution returns to re-initiate a network connection request to the target network device corresponding to the test scenario simulation command through the target controlled device, thus obtaining the network security test scenario.
- the AttckTimer timer counts the current accumulated execution count of the target simulation operation at regular intervals to facilitate the generation of a security test report in subsequent steps.
- step S103 involves performing security tests on the target network device and its corresponding target network based on a network security testing scenario, thereby obtaining a security test report for the target network under the network security testing scenario.
- security testing of the target network can only be conducted after the network security testing scenario has been established, thus obtaining a security test report for the target network under the network security testing scenario to test the target network's performance under network attack conditions.
- a network security testing scenario is established to simulate network attacks on the target network, thereby testing the target network and helping to improve the network security detection and defense capabilities of the target network device.
- the terminal used in the network security testing method of this application may include, but is not limited to, an operating interface, a scheduling processing component, a baseband processing component, and a mid-frequency radio frequency (RF) module.
- the scheduling processing component includes a simulated attack module and a scheduling processing module.
- the user interface plays a crucial role as the primary medium for interaction between the target object and the system.
- the target object can be configured in various ways through the user interface, including setting target simulation operations, specifying the number of controlled devices initiating the target simulation operations, and setting the time interval for these controlled devices to execute the target simulation operations.
- the user interface can also be used to display security test reports after the test is completed; these reports are essential for evaluating and analyzing the test results.
- the simulated attack module is responsible for receiving configuration parameters from the operation interface, setting different attack simulation strategies based on these parameters, generating corresponding instructions, and sending them to the scheduling and processing module to initiate the process of building a network security test scenario.
- the scheduling and processing module can schedule the baseband processing component according to the standard algorithm strategy of the communication protocol to complete the uplink and downlink data interaction.
- the main function of the scheduling and processing module is to receive simulated attack data from the simulated attack module, change the standard communication protocol process according to these instructions, and instruct the baseband processing component to control the target controlled device to perform the target simulated operation.
- the scheduling processing module can consist of several sub-modules, including UEM (Target Controlled Device Management), CPS (Signaling Control Platform), SPS (Service Scheduling Platform), and UPS (Service Data Platform).
- UEM Target Controlled Device Management
- CPS Signal Control Platform
- SPS Service Scheduling Platform
- UPS Service Data Platform
- the UEM sub-module can be used to control the access process of the target controlled device
- the CPS and SPS sub-modules can be used to simulate connection request overload and connection resource exhaustion
- the UPS sub-module can be used to simulate abnormal data packets by initiating SRB1 channel abnormal packet and malformed data packet attacks.
- the above modules and components work together to form a system that can simulate network security testing scenarios in network security testing methods.
- This system aims to improve the security protection capabilities of target networks and detect and defend against potential security threats by simulating network attacks on target networks.
- the gNodeB (the target network device in a 5G wireless network) will send an RRC Connection Establishment message to the device and start a waiting timer to wait for the device to reply with an RRC Connection Complete message. If the target controlled device does not reply before the timer expires, the target network device will release the device.
- the simulated attack module exploits this mechanism by configuring the target controlled device to not send the RRC Connection Complete message before the RRC Connection wait timer expires, but instead continuously and frequently initiate Random Access procedures, i.e., random access requests. This causes the gNodeB to frequently respond to these spurious access requests, thereby reducing the opportunities for access to other legitimate target controlled devices, ultimately creating a connection request overload.
- the Flooding Attack mode is set on the operation interface of the test terminal. Then, the number of target controlled devices initiating access requests is configured to be 1.
- the simulated attack module begins to execute the attack: it sends the configured number of target controlled devices and related context information to the device management platform module. It sends the Flooding Attack instruction to the signaling control platform module, which modifies the RRC Connection memory variable, sets the ACK packet to a rejection state, and starts a timer AttckTimer with a duration of 1 second.
- the signaling control platform module initiates the Attach process for the target controlled device. Once the RRC connection is established, the module determines whether the ACK packet is in a rejection state.
- the signaling control platform module automatically triggers, feeding back AttackNum to the simulated attack module, which then organizes and summarizes the results and stores them in a fixed directory on the test device. Finally, the user clicks the "Stop Attack Test” button on the test terminal's interface to end the attack and download the attack result report.
- This process can simulate a target network experiencing an overload of connection requests, thereby helping to detect and defend against such attacks.
- the process of establishing and releasing an RRC connection in a wireless communication protocol is utilized.
- a target controlled device successfully establishes an RRC connection, it replies to the gNodeB with an RRC Connection Complete message containing the IMSI (International Mobile Subscriber Identity).
- IMSI International Mobile Subscriber Identity
- the gNodeB sends the relevant information to the core network and requests authentication from the target controlled device.
- the core network then starts a timer T3560 (default value 5 seconds) to wait for the target controlled device to send an authentication response. If the target controlled device does not send an authentication response before the timer expires, the core network instructs the target network device to release the RRC connection.
- the simulated attack module instructs the target controlled device not to send an authentication response after receiving an authentication request, but instead to re-initiate the random access procedure. This results in frequent RRC connection establishment and release during the operation of timer T3560. If the number of newly established RRC connections exceeds the number of released connections, and multiple target controlled devices perform this operation for an extended period, eventually exhausting the RRC connection resources, thus simulating connection resource exhaustion.
- the Deplete RRC Res Attack mode is set on the operation interface, and the number of target controlled devices, IMSI, and the time interval for initiating Attach are configured.
- the simulated attack module After receiving the attack mode instruction, the simulated attack module begins executing the scenario simulation process. It first sends configuration information to the device management platform module, then sends an attack instruction to the signaling control platform module, modifies the authentication response to a denial state, and starts the timer AttckTimer.
- the signaling control platform module initiates the Attach process for the target controlled devices according to the configuration. When the target controlled device receives an authentication request, due to the denial state, it will not send an authentication response, but will instead increment the attack result count AttackNum and then re-initiate the Attach process.
- the signaling control platform module feeds back AttackNum to the simulated attack module, which then compiles and summarizes the results and stores them in a fixed directory on the test device. Finally, the user clicks the "Stop Attack Test” button on the operation interface to end the current attack and download the attack result report.
- This process can simulate a target network encountering connection resource exhaustion, helping to detect and improve the target network devices' defense capabilities against such attacks.
- the length of the L bit must be less than 65535, and the LCID (Logical Channel ID) bit must be between 0 and 32.
- the target controlled device intentionally sends MAC PDU messages with the LCID set to 1 and the L bit field abnormally filled, causing the target network device to recognize and discard the abnormal SRB1 (Signaling Radio Bearer 1) channel message length.
- the target controlled device fills the LCID in the MAC PDU message with an abnormal value, the target network device will also recognize and discard these abnormal data packets.
- the purpose of the attack is that if the target controlled device sends such abnormal data for an extended period of time, the target network device will have to respond to these abnormal messages frequently, thus failing to provide normal services to other users, resulting in a significant waste of network resources and achieving the goal of denial of service.
- the terminal device triggers the target controlled device to access the network normally and begins FTP file copying, transmitting uplink services according to the frame structure period scheduled by gNodeB.
- the target controlled device will send uplink SRB data in a specific uplink slot.
- the simulated attack module initiates the attack after receiving the SRB1 abnormal data attack mode instruction. It sends the SRB1 abnormal data attack instruction to the service data platform module. After receiving the instruction, the service data platform module modifies the SRB1 memory variable to an abnormal state and starts a timer AttckTimer for 1 second.
- the target controlled device packages the service data of the specific slot into SRB1 channel data and modifies the L bit in the MAC PDU data to the abnormal value 65535.
- the target network device will discard these abnormally long packets, and the data transmission frequency is approximately 1000ms divided by SlotU (the number of uplink slots).
- the simulated attack module initiates the attack again. It sends a malformed data packet attack command to the business data platform module, which modifies the DATA memory variable to an abnormal state and restarts the AttckTimer.
- the test device changes the business data of the uplink air interface slot to abnormal MAC packet data, fills in the LCID outside the protocol requirements, and maintains the same data transmission frequency as before.
- This process can simulate abnormal data packets encountered by the target network, helping to detect and improve the target network devices' defense capabilities against such attacks.
- This application also provides an electronic device, as shown in FIG12, the electronic device 1200 including:
- One or more processors 1210 are One or more processors 1210;
- the memory 1220 stores one or more programs that, when executed by one or more processors 1210, enable the one or more processors 1210 to implement a network security testing method.
- the memory 1220 can be used to store non-transitory software programs and non-transitory computer-executable programs. Furthermore, the memory 1220 may include high-speed random access memory, and may also include non-transitory memory, such as at least one disk storage device, flash memory device, or other non-transitory solid-state storage device.
- memory 1220 may include memory 1220 remotely located relative to processor 1210, and such remote memory 1220 may be connected to processor 1210 via a network.
- networks include, but are not limited to, the Internet, intranets, local area networks, mobile communication networks, and combinations thereof.
- the memory 1220 can be implemented as a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM).
- the memory 1220 can store the operating system and other application programs.
- the relevant program code is stored in the memory 1220 and is called and executed by the processor 1210.
- the processor 1210 can be implemented using a general-purpose CPU (Central Processing Unit), microprocessor, application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this application.
- a general-purpose CPU Central Processing Unit
- microprocessor microprocessor
- ASIC application-specific integrated circuit
- the electronic device further includes:
- Input/output interfaces are used to implement information input and output
- the communication interface is used to enable communication and interaction between this device and other devices. Communication can be achieved through wired means (such as USB, Ethernet cable, etc.) or wireless means (such as mobile network, WIFI, Bluetooth, etc.).
- wired means such as USB, Ethernet cable, etc.
- wireless means such as mobile network, WIFI, Bluetooth, etc.
- the bus transmits information between various components of the device (e.g., processor 1210, memory 1220, input/output interface, and communication interface);
- the processor 1210, memory 1220, input/output interface, and communication interface can communicate with each other within the device via a bus.
- An embodiment of this application also provides a computer-readable storage medium storing computer-executable instructions for executing a network security testing method.
- An embodiment of this application also provides a computer program product, which may include, but is not limited to, a computer program or computer instructions stored in a computer-readable storage medium.
- the processor of a computer device reads the computer program or computer instructions from the computer-readable storage medium and executes the computer program or computer instructions, causing the computer device to perform a method for implementing network security testing.
- the network security testing method provided in this application first obtains a test scenario simulation instruction, and determines the target simulated operation and the target controlled device based on the test scenario simulation instruction; then, it executes the target simulated operation on the target network device through the target controlled device to build a network security test scenario; further, it performs security testing on the target network device and the corresponding target network based on the network security test scenario to obtain a security test report of the target network under the network security test scenario.
- This application can build a network security test scenario by executing target simulated operations on the target network device through the target controlled device, thereby simulating the situation where the target network is subjected to network attacks, and then testing the target network to help improve the network security detection and network defense capabilities of the target network device.
- Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory.
- Volatile memory can include random access memory (RAM) or external cache memory.
- RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), dual data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), RAMbus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and RAMbus dynamic RAM (RDRAM), etc.
- SRAM static RAM
- DRAM dynamic RAM
- SDRAM synchronous DRAM
- DDRSDRAM dual data rate SDRAM
- ESDRAM enhanced SDRAM
- SLDRAM synchronous link DRAM
- RDRAM RAMbus direct RAM
- DRAM direct memory bus dynamic RAM
- RDRAM RAMbus dynamic RAM
- Computer storage media includes, but is not limited to, RAM, ROM, EEPROM, flash memory or other memory technologies, CD-ROM, digital versatile disc (DVD) or other optical disc storage, magnetic cartridges, magnetic tape, disk storage or other magnetic storage devices, or any other medium that can be used to store desired information and is accessible to a computer.
- communication media typically contain computer-readable instructions, data structures, program modules, or other data in modulated data signals such as carrier waves or other transmission mechanisms, and may include any information delivery medium.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
本申请涉及网络测试技术领域,尤其涉及一种网络安全测试方法、电子设备、介质和计算机程序产品。本申请实施例提供的网络安全测试方法,包括:需要获取测试场景模拟指令,并根据所述测试场景模拟指令确定目标模拟操作和目标受控设备(S101);通过所述目标受控设备对目标网络设备执行所述目标模拟操作,搭建网络安全测试场景(S102);基于所述网络安全测试场景对所述目标网络设备对应目标网络进行安全测试,得到所述目标网络在所述网络安全测试场景下的安全测试报告(S103)。
Description
相关申请的交叉引用
本申请基于申请号为202410695870.9、申请日为2024年05月30日的中国专利申请提出,并要求该中国专利申请的优先权,该中国专利申请的全部内容在此引入本申请作为参考。
本申请涉及网络测试技术领域,尤其涉及一种网络安全测试方法、电子设备、介质和计算机程序产品。
随着移动互联网的普及和物联网的发展,移动通信已经成为人们日常生活和工作中不可或缺的一部分,移动通信的安全问题也越来越引起人们的关注。无线网络的空口攻击指的是针对无线通信网络中无线传输媒介的攻击,这种类型的网络攻击利用无线信号的广播特性和可能存在的安全漏洞来实施。在无线网络中,空口(Air Interface)是指移动设备(如手机、Wi-Fi设备等)与无线接入点(如基站、路由器等)之间的无线传输媒介。分布式拒绝服务攻击(Distributed Denial of Service,DDoS)是空口攻击中的一种常见形式。
由于无线网路具有流量大和高度分散的特点,一些攻击者可以利用大量的移动设备和无线接入点进行攻击,这使得攻击更加难以检测和防御。因此,移动通信网络在投入运营前,需要测试其抵御分布式拒绝服务攻击的能力。然而,具体可以如何对无线网络受到的攻击进行有效模拟,以供移动通信网络进行测试,在业内仍然是亟待解决的一个难题。
本申请实施例提供了一种网络安全测试方法、电子设备、介质和计算机程序产品。
第一方面,本申请实施例提供了一种网络安全测试方法,所述方法包括:获取测试场景模拟指令,并根据所述测试场景模拟指令确定目标模拟操作和目标受控设备;通过所述目标受控设备对目标网络设备执行所述目标模拟操作,搭建网络安全测试场景;基于所述网络安全测试场景对所述目标网络设备对应目标网络进行安全测试,得到所述目标网络在所述网络安全测试场景下的安全测试报告。
第二方面,本申请实施例提供了一种电子设备,包括:一个或多个处理器;存储器,其上存储有一个或多个程序,当所述一个或多个程序被所述一个或多个处理器执行,使得所述一个或多个处理器实现如上第一方面所述的网络安全测试方法。
第三方面,本申请实施例提供了一种计算机可读存储介质,其上存储有计算机程序,所述程序被处理器执行时实现如上第一方面所述的网络安全测试方法。
第四方面,本申请实施例提供了一种计算机程序产品,包括计算机程序,所述计算机程序被处理器执行时实现如上第一方面所述的网络安全测试方法。
附图用来提供对本申请技术方案的进一步理解,并且构成说明书的一部分,与本申请的实施例一起用于解释本申请的技术方案,并不构成对本申请技术方案的限制。
图1是本申请实施例提供的一种网络安全测试方法的流程示意图;
图2是本申请实施例提供的一种网络安全测试方法的另一流程示意图;
图3是本申请实施例提供的一种网络安全测试方法的另一流程示意图;
图4是本申请实施例提供的一种网络安全测试方法的另一流程示意图;
图5是本申请实施例提供的一种网络安全测试方法的另一流程示意图;
图6是本申请实施例提供的一种网络安全测试方法的另一流程示意图;
图7是本申请实施例提供的一种网络安全测试方法的另一流程示意图;
图8是本申请实施例提供的一种网络安全测试方法的另一流程示意图;
图9是本申请实施例提供的一种网络安全测试方法的另一流程示意图;
图10A是本申请实施例提供的一种网络安全测试方法的另一流程示意图;
图10B为本申请实施例提供的正常SRB1信道MAC PDU报文的示意图;
图10C为本申请实施例提供的异常SRB1信道MAC PDU报文的示意图;
图10D为本申请实施例提供的正常的MAC PDU报文的示意图;
图10E为本申请实施例提供的异常的MAC PDU报文的示意图;
图11A是本申请实施例提供的一种终端的结构示意框图;
图11B是本申请实施例提供的一种调度处理组件的结构示意框图;
图12是本申请实施例提供的电子设备的设备结构示意图。
为了使本申请的目的、技术方案及优点更加清楚明白,以下结合附图及实施例,对本申请进行进一步详细说明。应当理解,此处所描述的实施例仅用以解释本申请,并不用于限定本申请。
应了解,在本申请实施例的描述中,如果有描述到“第一”、“第二”等只是用于区分技术特征为目的,而不能理解为指示或暗示相对重要性或者隐含指明所指示的技术特征的数量或者隐含指明所指示的技术特征的先后关系。“至少一个”是指一个或者多个,“多个”是指两个或两个以上。“和/或”,描述关联对象的关联关系,表示可以存在三种关系,例如,A和/或B,可以表示单独存在A、同时存在A和B、单独存在B的情况。其中A,B可以是单数或者复数。字符“/”一般表示前后关联对象是一种“或”的关系。“以下至少一项”及其类似表达,是指的这些项中的任意组,包括单项或复数项的任意组。例如,a、b和c中的至少一项可以表示:a,b,c,a和b,a和c,b和c,或者,a和b和c,其中a,b,c可以是单个,也可以是多个。
此外,下面所描述的本申请各个实施方式中所涉及到的技术特征只要彼此之间未构成冲突就可以相互组合。
为了方便理解本申请实施例的方案,以及下述各实施例的描述清楚简洁,首先给出相关技术的简要介绍:
随着移动互联网的普及和物联网的发展,移动通信已经成为人们日常生活和工作中不可或缺的一部分,移动通信的安全问题也越来越引起人们的关注。无线网络的空口攻击指的是针对无线通信网络中无线传输媒介的攻击,这种类型的网络攻击利用无线信号的广播特性和可能存在的安全漏洞来实施。在无线网络中,空口(Air Interface)是指移动设备(如手机、Wi-Fi设备等)与无线接入点(如基站、路由器等)之间的无线传输媒介。分布式拒绝服务攻击(Distributed Denial of Service,DDoS)是空口攻击中的一种常见形式。
由于无线网路具有流量大和高度分散的特点,一些攻击者可以利用大量的移动设备和无线接入点进行攻击,这使得攻击更加难以检测和防御。因此,移动通信网络在投入运营前,需要测试其抵御分布式拒绝服务攻击的能力。然而,可以如何对无线网络受到的攻击进行有效模拟,以供移动通信网络进行测试,在业内仍然是亟待解决的一个难题。
本申请实施例提供了一种网络安全测试方法、电子设备、介质和计算机程序产品,旨在通过目标受控设备对目标网络设备执行目标模拟操作,从而搭建网络安全测试场景,以模拟目标网络受到网络攻击的情况,进而对目标网络进行测试,帮助提升目标网络设备的网络安全检测和网络防御能力。
下面以附图为依据作出进一步说明。
参照图1,本申请实施例提供了一种网络安全测试方法,本申请实施例网络安全测试方法可以应用于一种终端。本申请实施例的网络安全测试方法可以包括,但不限于:
步骤S101,获取测试场景模拟指令,并根据测试场景模拟指令确定目标模拟操作和目标受控设备;
步骤S102,通过目标受控设备对目标网络设备执行目标模拟操作,搭建网络安全测试场景;
步骤S103,基于网络安全测试场景对目标网络设备对应目标网络进行安全测试,得到目标网络在网络安全测试场景下的安全测试报告。
经由本申请实施例步骤S101至步骤S103提供的网络安全测试方法,首先,获取测试场景模拟指令,并根据测试场景模拟指令确定目标模拟操作和目标受控设备;其中,测试场景模拟指令用于指示对目标网络进行测试场景的模拟搭建;接着,通过目标受控设备对目标网络设备执行目标模拟操作,搭建网络安全测试场景;其中,目标网络设备用于维系目标网络的运行;进一步,基于网络安全测试场景对目标网络设备对应目标网络进行安全测试,得到目标网络在网络安全测试场景下的安全测试报告。本申请能够通过目标受控设备对目标网络设备执行目标模拟操作,从而搭建网络安全测试场景,以模拟目标网络受到网络攻击的情况,进而对目标网络进行测试,帮助提升目标网络设备的网络安全检测和网络防御能力。
一些实施例的步骤S101,获取测试场景模拟指令,并根据测试场景模拟指令确定目标模拟操作和目标受控设备;其中,测试场景模拟指令用于指示对目标网络进行测试场景的模拟搭建。需要说明的是,本申请实施例的网络安全测试方法旨在模拟目标网络受到网络攻击的情况,进而对目标网络进行测试。因此,测试场景模拟指令用于指示对目标网络进行测试场景的模拟搭建。其中,根据场景模拟指令可以确定对应的目标模拟操作和目标受控设备。需要指出,目标模拟操作即为了模拟安全测试场景,需要对目标网络执行的操作;目标受控设备即为了模拟安全测试场景,执行目标模拟操作的受控设备,目标受控设备是用于模拟针对目标网络的异常连接设备。
可以理解的是,测试场景模拟指令的获取方式多种多样,例如可以通过键鼠、触摸屏等输入设备获取,又例如可以通过有线或者无线数据的传输而获取。
参照图2,根据本申请提供的一些实施例,步骤S101中获取测试场景模拟指令,可以包括,但不限于:
步骤S201,显示配置操作界面;
步骤S202,响应于目标对象在配置操作界面的输入,获取场景模拟配置参数;
步骤S203,基于场景模拟配置参数,生成针对目标网络的测试场景模拟指令。
本申请一些实施例中,可以通过步骤S201至步骤S203,先显示配置操作界面,再响应于目标对象在配置操作界面的输入,从而获取场景模拟配置参数,基于场景模拟配置参数,生成针对目标网络的测试场景模拟指令。需要说明的是,目标对象指的可以是针对目标网络发起安全测试场景模拟的用户。需要明确,用户界面(User Interface,UI)是人与计算机系统之间交流和交互的介面,它包括了用户能够看到的屏幕、页面以及与系统交互的控件和视觉元素。应理解,配置操作界面是一种用于接收目标对象输入的用户界面。
本申请一些实施例中,目标对象可以在配置操作界面进行输入,通过明确目标模拟操作的类型、参与场景模拟的目标受控设备、目标受控设备的数目以及场景模拟的时间间隔或者其他类型的场景模拟配置参数,生成针对目标网络的测试场景模拟指令。
经由步骤S201至步骤S203示出的实施例,可以通过配置操作界面来获取场景模拟配置参数,进而基于场景模拟配置参数,生成针对目标网络的测试场景模拟指令。如此一来,以一种便捷的方式,为网络安全测试场景的搭建提供参照基准,有助于网络安全测试方法的高效进行。
在其它一些实施例中,得到目标网络在网络安全测试场景下的安全测试报告之后,也可以显示在用户界面之中,用于评估分析本次对于安全测试场景模拟的结果。
参照图3,根据本申请提供的一些实施例,步骤S101中根据测试场景模拟指令确定目标模拟操作和目标受控设备,可以包括,但不限于:
步骤S301,根据测试场景模拟指令,确定与网络安全测试场景匹配的受控设备标识信息和受控设备操作信息;
步骤S302,根据受控设备标识信息从目标网络中,确定搭建网络安全测试场景的目标受控设备;
步骤S303,根据受控设备操作信息从目标网络的运行数据中,确定目标受控设备在网络安全测试场景中执行的目标模拟操作。
需要说明的是,测试场景模拟指令用于指示对目标网络进行测试场景的模拟搭建,其中可以包括目标模拟操作的类型、参与场景模拟的目标受控设备、目标受控设备的数目以及场景模拟的时间间隔等信息。根据测试场景模拟指令,可以从中确定出与网络安全测试场景匹配的受控设备标识信息和受控设备操作信息。受控设备标识信息是目标受控设备的唯一标识,在受控设备标识信息与网络安全测试场景相匹配的情况下,该受控设备标识信息在目标网络中所指向的目标受控设备,用于参与对网络安全测试场景的模拟搭建。受控设备操作信息用于对目标受控设备需要执行的目标模拟操作进行配置,因此根据受控设备操作信息,能够确定目标受控设备为模拟网络安全测试场景需要执行的目标模拟操作。
如此一来,经由步骤S301至步骤S303示出的步骤,能够确定出清楚地确定需要参与模拟网络安全测试场景的目标受控设备,以及目标受控设备需要执行的目标模拟操作,有助于高效进行网络安全测试场景的搭建。
参照图4,根据本申请提供的一些实施例,测试场景模拟指令包括场景模拟类型信息、设备配置参数和操作模拟频率,步骤S301根据测试场景模拟指令,确定与网络安全测试场景匹配的受控设备标识信息和受控设备操作信息,可以包括,但不限于:
步骤S401,基于测试场景模拟指令中的场景模拟类型信息确定出测试场景模拟指令对应的模拟场景方式;
步骤S402,根据模拟场景方式和操作模拟频率从场景数据库中,获取与设备配置参数匹配的受控设备标识信息以及受控设备操作信息。
需要说明的是,测试场景模拟指令包括场景模拟类型信息、设备配置参数和操作模拟频率。其中,场景模拟类型信息用于表明需要模拟的网络安全测试场景的类型;设备配置参数指的是目标受控设备的配置参数;操作模拟频率对应于目标受控设备执行目标模拟操作相应的操作频率,每两个目标模拟操作之间相隔的时间越短,则操作模拟频率越高。基于此,本申请实施例中可以基于测试场景模拟指令中的场景模拟类型信息确定出测试场景模拟指令对应的模拟场景方式,以确定目标受控设备执行目标模拟操作的方式,而后根据模拟场景方式和操作模拟频率从场景数据库中,获取与设备配置参数匹配的受控设备标识信息以及受控设备操作信息,受控设备标识信息用于明确需要哪些目标受控设备来执行目标模拟操作,,受控设备操作信息用于明确目标受控设备需要执行的操作与相应的操作频率。场景数据库指的是预先设置的、用于存储多种设备标识信息以及设备操作信息的数据库,其中,每一种网络安全测试场景的类型在场景数据库中都存储有对应的设备标识信息以及设备操作信。因此,根据模拟场景方式和操作模拟频率,即可从场景数据库中获取与设备配置参数匹配的受控设备标识信息以及受控设备操作信息。
经由步骤S401至步骤S402示出的实施例,依照测试场景模拟指令中的场景模拟类型信息、设备配置参数和操作模拟频率,获取匹配于设备配置参数的受控设备标识信息,确定目标受控设备执行目标模拟操作的方式,得到模拟场景方式,并且基于模拟场景方式和操作模拟频率,为受控设备标识信息配置对应的受控设备操作信息。如此一来,可以明确地将测试场景模拟指令,转变为直接控制目标受控设备的指令,以便于通过目标受控设备对目标网络设备执行目标模拟操作,从而搭建网络安全测试场景,以模拟目标网络受到网络攻击的情况。
一些实施例的步骤S102,通过目标受控设备对目标网络设备执行目标模拟操作,搭建网络安全测试场景;其中,目标网络设备用于维系目标网络的运行。需要说明的是,目标网络即作为测试目标的网络,目标网络由目标网络设备维系运行。在一些实施例中,目标网络设备作为目标网络的运行维系设备,负责目标网络中无线信号的传输与接收、资源管理、移动性管理、连接建立与维护、数据传输、信号覆盖、质量控制、安全控制、计费和身份验证、网络操作支持、紧急服务以及网络功能集成,保障目标网络的使用者能够获得稳定、安全、高效的通信服务。本申请实施例中,通过目标受控设备对目标网络设备执行目标模拟操作,旨在干扰目标网络设备对目标网络的维系作用,从而搭建网络安全测试场景,以模拟目标网络受到网络攻击的情况。应理解,目标网络设备可以是用于负责提供无线接入,管理无线资源,支持移动性,确保数据传输和通信质量的基站。
本申请提供的一些实施例中,网络安全测试场景的类型多种多样,可以包括但不限于连接请求过载、连接资源耗尽和异常数据模拟报文。需要说明的是,连接请求过载、连接资源耗尽和异常数据模拟报文,均可以用于模拟针对无线通信网络的拒绝服务(DoS)攻击手段,它们通过不同的方式耗尽网络资源,导致合法目标网络的用户无法获得需要的服务。
连接请求过载,也称作泛洪攻击场景(Flooding Attack)。连接请求过载是一种通过向网络设备发送大量流量或请求,以淹没网络或系统资源的攻击方式。这种类型的网络攻击的目的是使网络服务不可用,因为它会耗尽带宽、处理能力或存储空间。在无线网络中,连接请求过载可能针对基站或核心网络,通过发送大量无意义的信号或数据包来实现。
连接资源耗尽。这种类型的网络攻击专注于耗尽无线通信网络中的无线资源控制连接资源(RRC)。RRC连接是3GPP标准中用于管理用户设备和网络之间通信的关键组成部分,负责信令和控制信息的传输。攻击者通过发送大量的RRC连接请求,但不完成连接建立过程,导致基站持续为这些未完成的连接分配资源,最终耗尽RRC连接资源,使得合法用户无法建立新的RRC连接。
异常数据模拟报文。异常数据模拟报文涉及发送格式错误或异常的数据报文到网络。这些异常数据报文可能是长度错误、类型未知或包含非法信息的报文。基站需要处理这些报文,但由于它们不符合协议规范,处理过程中会消耗额外的资源,并且可能导致错误或服务中断。攻击者可能利用这一点来发起攻击,通过发送大量异常报文来消耗基站的处理能力,从而影响正常服务。
这三种网络攻击方式旨在通过不同的手段使网络资源过载,影响网络的正常运行。本申请实施例的网络安全测试方法,可以测试目标网络在以上三种网络安全测试场景的表现,从而得到目标网络在网络安全测试场景下对应的安全测试报告,以便于采取相应的安全措施,如增强网络监控、实施流量过滤、优化资源管理等,以防御这些网络攻击并保护目标网络的稳定性和可靠性。
相关技术中,如何对无线网络受到的攻击进行有效模拟,以供移动通信网络进行测试,仍然是一个难题。而本申请中,可以通过目标受控设备对目标网络设备执行目标模拟操作,搭建网络安全测试场景,以模拟目标网络受到网络攻击的情况,进而对目标网络进行测试,帮助提升目标网络设备的网络安全检测和网络防御能力。
本申请实施例中,为清楚说明本申请实施例对网络安全测试场景的搭建方式,以下示例性地提供一些无线通信网络的标准协议流程:
S1、如果目标受控设备需要与目标网络建立连接,它会启动随机接入过程,通过发送前导序列给目标网络设备;
S2、目标网络设备收到前导序列后,如果资源允许,将发送随机接入响应给目标受控设备,包含上下行资源分配信息;
S3、目标受控设备使用随机接入响应中分配的资源,发送连接请求消息给目标网络设备,请求建立连接;
S4、目标网络设备处理连接请求后,如果接受请求,将发送连接建立消息给目标受控设备,包含连接的配置信息;
S5、目标网络设备启动完整性保护和加密机制,确保通信的安全性;
S6、目标网络设备向目标受控设备发送鉴权请求,目标受控设备回复鉴权响应,核心网进行鉴权;其中,核心网(Core Network)是目标网络的中心部分,负责处理主要的网络管理和数据传输功能。它作为目标网络的大脑,连接着无线接入网和外部网络,如互联网、其他电信网络以及各种服务提供商的网络;
S7、鉴权成功后,目标网络设备向核心网发送附着接受消息,核心网向目标受控设备发送附着完成消息;
S8、目标受控设备与目标网络连接建立后,目标受控设备可以开始向目标网络进行数据传输;
在上述无线通信网络的标准协议流程整个过程中,目标受控设备和目标网络设备之间的通信遵循严格的时序和协议规范,确保连接的建立是安全和有效的。正常连接流程的目的是确保目标受控设备能够顺利接入网络,并开始通信。
参照图5,根据本申请提供的一些实施例,在确定出目标模拟操作对应于连接请求过载的情况下,可以对目标网络设备按照以下方式执行目标模拟操作:
步骤S501,修改目标受控设备的网络连接内存变量,以将目标受控设备的连接确认报文设置为拒绝状态;
步骤S502,重新通过目标受控设备向测试场景模拟指令对应的目标网络设备发起网络连接请求,并接收目标网络设备响应于网络连接请求的连接建立信息;
步骤S503,基于拒绝状态的连接确认报文和连接建立信息,控制目标受控设备拒绝回复连接建立信息,返回执行重新通过目标受控设备向测试场景模拟指令对应的目标网络设备发起网络连接请求,得到网络安全测试场景。
需要强调的是,连接请求过载是一种通过向网络设备发送大量流量或请求,以淹没网络或系统资源的攻击方式。这种类型的网络攻击的目的是使网络服务不可用,因为它会耗尽带宽、处理能力或存储空间。在无线网络中,连接请求过载可能针对基站或核心网,通过发送大量无意义的信号或数据包来实现。
一些实施例的步骤S501,修改目标受控设备的网络连接内存变量,以将目标受控设备的连接确认报文设置为拒绝状态。需要说明的是,修改目标受控设备的网络连接内存变量,以将目标受控设备的连接确认报文设置为拒绝状态,意味着在目标网络设备将发送随机接入响应给目标受控设备后,目标受控设备不会发送确认消息以完成正常的连接建立过程。
一些实施例中,修改目标受控设备的网络连接内存变量,以将目标受控设备的连接确认报文设置为拒绝状态,可以是将RRC Connection内存变量修改如下:“ACK报文=拒绝状态”。
一些实施例的步骤S502至步骤S504,重新通过目标受控设备向测试场景模拟指令对应的目标网络设备发起网络连接请求,并接收目标网络设备响应于网络连接请求的连接建立信息,基于拒绝状态的连接确认报文和连接建立信息,控制目标受控设备拒绝回复连接建立信息,返回执行重新通过目标受控设备向测试场景模拟指令对应的目标网络设备发起网络连接请求,得到网络安全测试场景。需要说明的是,由于发起网络连接请求的目标受控设备经过网络连接内存变量的修改,因此将会基于拒绝状态的连接确认报文和连接建立信息,控制目标受控设备拒绝回复连接建立信息。此后,将会返回执行重新通过目标受控设备向测试场景模拟指令对应的目标网络设备发起网络连接请求,得到网络安全测试场景。
本申请一些实施例中,由于目标受控设备的连接确认报文被设置为拒绝状态,因此在目标网络设备将发送随机接入响应给目标受控设备后,目标受控设备不会发送确认消息以完成正常的连接建立过程,目标网络设备在等待一段时间之后就会主动释放先前收到的网络连接请求。基于此,本申请实施例中目标受控设备在拒绝回复连接建立信息之后,目标受控设备重新向目标网络设备发起网络连接请求,则目标网络设备则需要在等待释放先前网络连接请求的同时,处理新发起的网络连接请求。如此一来,在新发起的网络连接请求多于等待释放的网络连接请求的情况下,目标网络设备将会进入连接请求过载的状态。本申请实施例基于这种实施方式,即可搭建出连接请求过载对应的网络安全测试场景,以便对目标网络设备对应目标网络进行安全测试,得到目标网络在网络安全测试场景下的安全测试报告。
本申请提供的一些实施例中,目标模拟操作对应于连接请求过载,在目标受控设备满足第一预设条件的情况下,方可控制目标受控设备停止向目标网络设备发起网络连接请求,如此便能终止网络安全测试场景的搭建。需要指出,第一预设条件用于界定目标受控设备达到了终止搭建网络安全测试场景的条件。举例而言,如若目标受控设备接收到目标模拟操作停止指令,确定第一预设条件满足,如此便能停止向目标网络设备发起网络连接请求,终止网络安全测试场景的搭建。应理解,目标受控设备满足第一预设条件的实施例多种多样,不限于上述举例。
通过步骤S501至步骤S504,可以在目标模拟操作对应于连接请求过载的情况下,对网络安全测试场景进行搭建,以模拟目标网络遇到连接请求过载的情况,进而对目标网络进行测试,帮助提升目标网络设备的网络安全检测和网络防御能力。
参照图6,根据本申请提供的一些实施例,在确定出目标模拟操作对应于连接资源耗尽的情况下,对目标网络设备按照以下方式执行目标模拟操作:
步骤S601,修改目标受控设备的鉴权内存变量,以将目标受控设备的鉴权确认报文设置为拒绝状态;
步骤S602,重新通过目标受控设备向测试场景模拟指令对应的目标网络设备发起网络连接请求,并接收目标网络设备响应于网络连接请求的连接建立信息;
步骤S603,基于连接建立信息生成与连接建立信息对应的连接确认信息,并向目标网络设备发送连接确认信息;
步骤S604,通过目标受控设备获取目标网络设备响应于连接确认信息的鉴权请求,基于拒绝状态的鉴权确认报文,控制目标受控设备拒绝回复鉴权请求,返回执行向目标网络设备发起网络连接请求,得到网络安全测试场景。
需要强调的是,连接资源耗尽,这种类型的网络攻击专注于耗尽无线通信网络中的无线资源控制连接资源(RRC)。RRC连接是3GPP标准中用于管理用户设备和网络之间通信的关键组成部分,负责信令和控制信息的传输。攻击者通过发送大量的RRC连接请求,但不完成连接建立过程,导致基站持续为这些未完成的连接分配资源,最终耗尽RRC连接资源,使得合法用户无法建立新的RRC连接。
一些实施例的步骤S601,修改目标受控设备的鉴权内存变量,以将目标受控设备的鉴权确认报文设置为拒绝状态。需要说明的是,修改目标受控设备的鉴权内存变量,以将目标受控设备的鉴权确认报文设置为拒绝状态,意味着在目标网络设备向目标受控设备发送鉴权请求之后,目标受控设备将会基于拒绝状态的鉴权确认报文,控制目标受控设备拒绝回复鉴权请求,从而不会发送鉴权响应至目标网络的核心网以完成鉴权。
一些实施例中,修改目标受控设备的鉴权内存变量,以将目标受控设备的鉴权确认报文设置为拒绝状态,可以是将Authentication内存变量修改如下:“ACK报文=拒绝状态”。
一些实施例的步骤S602至步骤S604,重新通过目标受控设备向测试场景模拟指令对应的目标网络设备发起网络连接请求,并接收目标网络设备响应于网络连接请求的连接建立信息,基于连接建立信息生成与连接建立信息对应的连接确认信息,并向目标网络设备发送连接确认信息。这意味着目标受控设备与目标网络设备之间已经建立连接。在此基础上,目标受控设备进一步通过目标受控设备获取目标网络设备响应于连接确认信息的鉴权请求,基于拒绝状态的鉴权确认报文,控制目标受控设备拒绝回复鉴权请求,返回执行向目标网络设备发起网络连接请求,得到网络安全测试场景。需要说明的是,由于发起网络连接请求的目标受控设备经过鉴权内存变量的修改,因此在获取鉴权请求之后,在目标网络设备向目标受控设备发送鉴权请求之后,目标受控设备将会基于拒绝状态的鉴权确认报文,拒绝回复鉴权请求。此后,将会返回执行重新通过目标受控设备向测试场景模拟指令对应的目标网络设备发起网络连接请求,得到网络安全测试场景。
本申请一些实施例中,由于目标受控设备的鉴权确认报文被设置为拒绝状态,因此在目标受控设备与目标网络设备之间建立连接之后,目标网络设备向目标受控设备发送鉴权请求,而目标受控设备则基于拒绝状态的鉴权确认报文,拒绝回复鉴权请求,无法完成正常的鉴权过程。目标网络设备在等待一段时间之后,就会主动释放先前与网络受控设备之间建立的连接。基于此,本申请实施例中目标受控设备在拒绝回复鉴权请求之后,目标受控设备重新向目标网络设备发起网络连接请求,以建立新的连接。则目标网络设备则需要在等待释放先前连接的同时,处理新发起的网络连接请求,已建立新的连接。如此一来,在新建立的连接数量多于等待释放的连接数量的情况下,目标网络设备将会进入连接资源耗尽的状态。本申请实施例基于这种实施方式,即可搭建出连接资源耗尽对应的网络安全测试场景,以便对目标网络设备对应目标网络进行安全测试,得到目标网络在网络安全测试场景下的安全测试报告。
本申请提供的一些实施例中,目标模拟操作对应于连接资源耗尽,在目标受控设备满足第二预设条件的情况下,方可控制目标受控设备停止向目标网络设备发起网络连接请求,如此便能终止网络安全测试场景的搭建。需要指出,第二预设条件用于界定目标受控设备达到了终止搭建网络安全测试场景的条件。举例而言,如若目标受控设备接收到目标模拟操作停止指令,确定第二预设条件满足,如此便能停止向目标网络设备发起网络连接请求,终止网络安全测试场景的搭建。应理解,目标受控设备满足第二预设条件的实施例多种多样,不限于上述举例。
通过步骤S601至步骤S604,可以在目标模拟操作对应于连接资源耗尽的情况下,对网络安全测试场景进行搭建,以模拟目标网络遇到连接资源耗尽的情况,进而对目标网络进行测试,帮助提升目标网络设备的网络安全检测和网络防御能力。
参照图7,根据本申请提供的一些实施例,存在第一数目个目标受控设备在同一请求时隙中发起网络连接请求,步骤S602重新通过目标受控设备向测试场景模拟指令对应的目标网络设备发起网络连接请求,并接收目标网络设备响应于网络连接请求的连接建立信息,可以包括,但不限于:
步骤S701,针对修改鉴权内存变量后的第一数目个目标受控设备,确定每一目标受控设备在请求时隙的前导序列,以使每一目标受控设备对应的前导序列均不相同;
步骤S702,每一目标受控设备基于对应的前导序列,向目标网络设备发起网络连接请求。
需要说明的是,本申请实施例中,由于第一数目个目标受控设备是在同一请求时隙发起网络连接请求,因此这些目标受控设备可能会出现冲突和资源争用的情况。应理解,请求时隙指的是目标受控设备发起网络连接请求的时间段。
基于此,步骤S701至步骤S702中需要针对修改鉴权内存变量后的第一数目个目标受控设备,确定每一目标受控设备在请求时隙的前导序列,以使每一目标受控设备对应的前导序列均不相同。进一步,每一目标受控设备基于对应的前导序列,向目标网络设备发起网络连接请求。如此一来,便可以提高多个目标受控设备同时发起随机接入时的竞争接入成功率,避免多个目标受控设备使用相同的前导序列,导致冲突和资源争用。
参照图8,根据本申请提供的一些实施例,步骤S701针对修改鉴权内存变量后的第一数目个目标受控设备,确定每一目标受控设备在请求时隙的前导序列,可以包括,但不限于:
步骤S801,获取包括第二数目个前导序列索引的序列索引集合;其中,前导序列索引用于查询候选的前导序列;
步骤S802,从第一数目个目标受控设备中,确定每一目标受控设备对应的设备编号;
步骤S803,针对每一目标受控设备,基于设备编号与第二数目进行模运算,得到索引序号,基于索引序号在序列索引集合选中相应的前导序列索引,并依据前导序列索引从候选的前导序列中,为目标受控设备配置对应的前导序列。
需要说明的是,针对修改鉴权内存变量后的第一数目个目标受控设备,通过前导序列索引来确定每一目标受控设备在请求时隙的前导序列,以使每一目标受控设备对应的前导序列均不相同。其中,对于同一请求时隙发起网络连接请求的第一数目个目标受控设备,计算每一目标受控设备唯一对应的前导序列索引PreambleIndex,可以表示为:
PreambleIndex=(Count[Slot]+1)mod PreambleID
PreambleIndex=(Count[Slot]+1)mod PreambleID
其中,Slot表示请求时隙的时隙编号,每个Slot有一个唯一的序号。
Count[Slot]用于记录在特定Slot上发送随机接入请求(Msg1)的UE数量,这个计数器从0开始,对于每个Slot独立计数,用于确保每个设备在同一请求时隙下使用不同的前导序列索引。
PreambleID表示可用的前导序列索引集合。前导序列索引的范围是从0开始,一直到前导序列的总数,也即第二数目。
通过前导序列索引来确定每一目标受控设备在请求时隙的前导序列,能够实现即使在高负载情况下,每个目标受控设备也能获得一个唯一的前导序列索引。基于此,本申请实施例提高了多个目标受控设备同时发起随机接入时的竞争接入成功率,避免多个目标受控设备使用相同的前导序列,导致冲突和资源争用。
参照图9,根据本申请提供的一些实施例,在确定出目标模拟操作对应于异常数据模拟报文的情况下,对目标网络设备按照以下方式执行目标模拟操作:
步骤S901,修改目标受控设备的信道内存变量,以将目标受控设备的信道传输报文设置为异常状态;
步骤S902,重新通过目标受控设备与测试场景模拟指令对应的目标网络设备建立连接;其中,目标受控设备与目标网络设备之间的数据传输,受数据传输协议的约束;
步骤S903,基于异常状态的信道传输报文,生成不符合数据传输协议的模拟传输数据,并通过目标受控设备向建立连接的目标网络设备发送模拟传输数据,以使目标网络设备将模拟传输数据识别为异常数据并丢弃,返回执行基于所述异常状态的所述信道传输报文,生成不符合所述数据传输协议的模拟传输数据,得到网络安全测试场景。
需要强调的是,异常数据模拟报文涉及发送格式错误或异常的数据报文到网络。这些异常数据报文可能是长度错误、类型未知或包含非法信息的报文。基站需要处理这些报文,但由于它们不符合协议规范,处理过程中会消耗额外的资源,并且可能导致错误或服务中断。攻击者可能利用这一点来发起攻击,通过发送大量异常报文来消耗基站的处理能力,从而影响正常服务。
一些实施例的步骤S901,修改目标受控设备的信道内存变量,以将目标受控设备的信道传输报文设置为异常状态。需要说明的是,修改目标受控设备的信道内存变量,以将目标受控设备的信道传输报文设置为拒绝状态,意味着在目标受控设备与目标网络设备建立连接之后,目标受控设备将会通过目标受控设备向建立连接的目标网络设备发送模拟传输数据,并向目标网络设备发送模拟传输数据,从而影响目标网络的正常服务。
一些实施例中,修改目标受控设备的信道内存变量,以将目标受控设备的信道传输报文设置为异常状态,可以是将SRB1内存变量修改如下:“DATA报文=Abnormal状态”。其中,SRB1(Signaling Radio Bearer1)是3GPP标准中定义的一种用于承载信令的无线承载。将SRB1内存变量修改如下:“DATA报文=Abnormal状态”的情况下,目标网络设备会识别到SRB1信道报文长度异常而丢弃。
一些实施例的步骤S902至步骤S903,重新通过目标受控设备与测试场景模拟指令对应的目标网络设备建立连接;其中,目标受控设备与目标网络设备之间的数据传输,受数据传输协议的约束。进一步,在目标受控设备与目标网络设备建立连接之后,基于异常状态的信道传输报文,生成不符合数据传输协议的模拟传输数据,并通过目标受控设备向建立连接的目标网络设备发送模拟传输数据,以使目标网络设备将模拟传输数据识别为异常数据并丢弃,返回执行基于所述异常状态的所述信道传输报文,生成不符合所述数据传输协议的模拟传输数据,得到网络安全测试场景。
需要说明的是,由于发起网络连接请求的目标受控设备经过信道内存变量的修改,因此在目标受控设备与目标网络设备建立连接之后,通过目标受控设备向建立连接的目标网络设备发送模拟传输数据,并向目标网络设备发送模拟传输数据,以使目标网络设备将模拟传输数据识别为异常数据并丢弃。此后,将会重新通过目标受控设备与测试场景模拟指令对应的目标网络设备建立连接,得到网络安全测试场景。
本申请一些实施例中,由于目标受控设备的信道传输报文被设置为异常状态,因此在目标受控设备与目标网络设备之间建立连接之后,基于异常状态的信道传输报文,可以生成不符合数据传输协议的模拟传输数据。进一步,通过目标受控设备向建立连接的目标网络设备发送模拟传输数据。需要强调,目标受控设备与目标网络设备之间的数据传输,受数据传输协议的约束。因此,目标网络设备收到不符合数据传输协议的模拟传输数据,则会将其识别为异常数据并丢弃,无法完成正常的数据传输过程。而后,目标受控设备反复地基于异常状态的信道传输报文,生成不符合数据传输协议的模拟传输数据,并通过目标受控设备向建立连接的目标网络设备发送模拟传输数据。目标网络设备长时间从目标受控设备接收到不符合数据传输协议的模拟传输数据,需要频繁将模拟传输数据视作异常数据进行处理,从而造成目标网络设备中大量网络资源的浪费。本申请实施例基于这种实施方式,即可搭建出异常数据模拟报文对应的网络安全测试场景,以便对目标网络设备对应目标网络进行安全测试,得到目标网络在网络安全测试场景下的安全测试报告。
本申请提供的一些实施例中,目标模拟操作对应于异常数据模拟报文,在目标受控设备满足第三预设条件的情况下,方可控制目标受控设备停止向目标网络设备发送模拟传输数据,如此便能终止网络安全测试场景的搭建。需要指出,第三预设条件用于界定目标受控设备达到了终止搭建网络安全测试场景的条件。举例而言,如若目标受控设备接收到目标模拟操作停止指令,确定第三预设条件满足,如此便能停止向目标网络设备发送模拟传输数据,终止网络安全测试场景的搭建。应理解,目标受控设备满足第三预设条件的实施例多种多样,不限于上述举例。
参照图10A,根据本申请提供的一些实施例,模拟传输数据包括报文长度标识位与逻辑信道标识位,步骤S903中生成不符合数据传输协议的模拟传输数据,可以包括,但不限于:
步骤S1001,确定数据传输协议中对报文长度标识位的第一约束条件、对逻辑信道标识位的第二约束条件;
步骤S1002,生成模拟传输数据,以使模拟传输数据在报文长度标识位不满足第一约束条件,或者,以使模拟传输数据在逻辑信道标识位满足第二约束条件。
需要说明的是,在无线通信网络中,MAC PDU(Medium Access Control Protocol Data Unit)是MAC层与物理层之间传输数据的单元。本申请实施例中,模拟传输数据可以是MAC PDU报文。需要指出,MAC PDU报文中的L位(Length field)和LCID(Logical Channel ID)是两个关键字段。其中,L位可以是模拟传输数据的报文长度标识位,LCID可以是模拟传输数据的逻辑信道标识位。数据传输协议可以是利用MAC PDU报文传输数据时所遵循的传输协议。
需要明确,L位是MAC PDU报文中的一个字段,用于指示MAC PDU报文的长度,L位的值表示MAC PDU报文中有效载荷(即用户数据或控制信息)的长度,单位通常是字节或比特,具体取决于上下文,在某些协议中,L位的最大值可能有限制,例如,在LTE中,L位的最大值通常为65535,这意味着MAC PDU报文的有效载荷长度不能超过这个值。
参照图10B,示出了正常SRB1信道MAC PDU报文。保留位指示L占长度,指的是MAC PDU报文中的某些位是保留的,用来指示L位(长度字段)所占的位数。逻辑信道ID(LCID)用来标识MAC PDU报文所属逻辑信道的字段。LCID的正常值是1,这对应于SRB1(信令无线承载1),用于承载控制信令。当LCID被设置为异常值时,目标网络设备会识别并丢弃这些异常数据报文。
参照图10C,示出了异常SRB1信道MAC PDU报文。保留位指示L占长度,指的是MAC PDU报文中保留位用于指示L位的长度。LCID的正常范围是0到32,这是3GPP标准规定的LCID取值范围。MTU(Maximum Transmission Unit)是网络层可以处理的最大数据单元大小。MAC PDU报文中,L位的长度应该与MTU大小相匹配,以确保数据的有效传输。
基于此,MAC PDU报文的L位在数据传输协议中对应于报文长度的约束条件,可以是第一约束条件。
需要明确,LCID是MAC PDU报文中用于标识逻辑信道的字段。在无线通信中,一个物理信道可以承载多个逻辑信道的数据。LCID字段用于区分不同的逻辑信道,确保数据能够正确地交付到目标信道。逻辑信道分为控制信道(如SRB1)和数据信道(如DRB)。LCID帮助区分这些不同类型的信道。LCID的取值范围通常在0到31之间,这允许最多32个逻辑信道。不同的LCID值对应不同的逻辑信道和不同的服务质量要求(QoS)。
参照图10D,示出了正常的MAC PDU报文。保留位指示L占长度,指MAC PDU报文中的某些位被保留用于指示L位的长度,即报文的有效载荷长度。逻辑信道ID(LCID)用于标识MAC PDU报文所属的逻辑信道。LCID的正常值范围是0到32,这与3GPP标准中定义的逻辑信道ID的范围相符。MTU定义了网络层可以处理的最大数据包大小,常见的MTU值如1400或1500字节。
参照图10E,示出了异常的MAC PDU报文。保留位指示L占长度,即报文的有效载荷长度。由于在3GPP标准中,LCID的取值范围是0到32,因此50是LCID的异常值,目标网络设备收到这样的报文会识别并丢弃。L位的异常值设置为65535,这远远超过了正常的MTU大小,是一个不合规范的长度值,会导致基站丢弃该报文。
基于此,MAC PDU报文的LCID值在数据传输协议中对应于逻辑信道数量的约束条件,可以是第二约束条件。
进一步,生成模拟传输数据,以使模拟传输数据在L位超过65535,可以确定模拟传输数据在报文长度标识位不满足第一约束条件;或者,生成模拟传输数据,以使模拟传输数据在LCID的值为50,可以确定模拟传输数据在逻辑信道标识位满足第二约束条件。
一些其他实施例中,通过目标受控设备向建立连接的目标网络设备发送模拟传输数据,可以是将MAC PDU报文中的LCID填写异常。在目标受控设备将MAC PDU报文中的LCID填写异常的情况下,目标网络设备会识别到异常数据报文而丢弃。
根据本申请提供的一些实施例,步骤S102通过目标受控设备对目标网络设备执行目标模拟操作,搭建网络安全测试场景,可以包括,但不限于:
在每一次目标模拟操作被执行之后,对目标模拟操作对应的执行次数进行更新;
基于更新后的执行次数,生成网络安全测试场景。
需要说明的是,在每一次目标模拟操作被执行之后,对目标模拟操作对应的执行次数进行更新,其目的在于记录目标模拟操作的执行次数,对目标模拟操作的执行次数进行统计,便于后续生成安全测试报告。需要指出,网络安全测试场景用于模拟目标网络受到网络攻击的情况,因此执行次数用于模拟目标网络受到网络攻击的次数。基于更新后的执行次数,生成网络安全测试场景,旨在模拟出目标网络受到多次网络攻击的网络安全测试场景。
根据本申请提供的一些实施例,基于更新后的执行次数,生成网络安全测试场景,可以包括,但不限于:
从执行目标模拟操作起,每经过一次预设时间间隔,对预设时间间隔期间更新的执行次数进行统计,得到中间模拟数据;
基于每一预设时间间隔相应的中间模拟数据,生成网络安全测试场景。
需要说明的是,由于执行次数用于模拟目标网络受到网络攻击的次数,因此中间模拟数据则指的是预设时间间隔期间模拟目标网络受到网络攻击的次数。基于每一预设时间间隔相应的中间模拟数据,生成网络安全测试场景,其目的在于,每隔一段预设时间间隔,对目标网络模拟受到的网络攻击次数进行统计,在此基础上得到网络安全测试场景。
本申请一些实施例中,在修改目标受控设备的网络连接内存变量,以将目标受控设备的连接确认报文设置为拒绝状态之后,可以设置一个AttckTimer定时器启动计时。而后重新通过目标受控设备向测试场景模拟指令对应的目标网络设备发起网络连接请求,并接收目标网络设备响应于网络连接请求的连接建立信息。进一步,在获取目标网络设备响应的连接建立信息之后,基于拒绝状态的连接确认报文和连接建立信息,控制目标受控设备拒绝回复连接建立信息,此时,目标模拟操作的执行次数累加1,再返回执行重新通过目标受控设备向测试场景模拟指令对应的目标网络设备发起网络连接请求,得到网络安全测试场景。其中,AttckTimer定时器每计时一段时间,就会将当前目标模拟操作累加的执行次数进行一次统计,以便于后续步骤生成安全测试报告。
本申请一些实施例中,在修改目标受控设备的鉴权内存变量,以将目标受控设备的鉴权确认报文设置为拒绝状态之后,可以设置一个AttckTimer定时器启动计时。而后通过修改鉴权内存变量后的目标受控设备,每间隔一段时间向测试场景模拟指令对应的目标网络设备发起一次网络连接请求;或者,通过修改鉴权内存变量后的多个目标受控设备,按照预定的时间间隔,依次向测试场景模拟指令对应的目标网络设备发起一次网络连接请求。进一步,在获取目标网络设备发送的鉴权请求之后,基于拒绝状态的鉴权确认报文,控制目标受控设备拒绝回复鉴权请求,此时,目标模拟操作的执行次数累加1,再返回执行重新通过目标受控设备向测试场景模拟指令对应的目标网络设备发起网络连接请求,得到网络安全测试场景。其中,AttckTimer定时器每计时一段时间,就会将当前目标模拟操作累加的执行次数进行一次统计,以便于后续步骤生成安全测试报告。
一些实施例的步骤S103,基于网络安全测试场景对目标网络设备对应目标网络进行安全测试,得到目标网络在网络安全测试场景下的安全测试报告。需要说明的是,在网络安全测试场景搭建完成之后,方可进一步对目标网络进行安全测试,从而得到目标网络在网络安全测试场景下的安全测试报告,以测试目标网络在受到网络攻击的情况时相对应的测试表现。通过目标受控设备对目标网络设备执行目标模拟操作,从而搭建网络安全测试场景,以模拟目标网络受到网络攻击的情况,进而对目标网络进行测试,能够帮助提升目标网络设备的网络安全检测和网络防御能力。
参照图11A,一些实施例中,本申请实施例网络安全测试方法应用的终端可以包括,但不限于操作界面、调度处理组件、基带处理组件以及中射频。其中,调度处理组件包括模拟攻击模块和调度处理模块。
操作界面作为目标对象与系统交互的主要媒介,起着至关重要的作用。目标对象可以通过操作界面进行多种配置,包括设定目标模拟操作、指定发起目标模拟操作的目标受控设备的数量,以及设定这些目标受控设备执行目标模拟操作的时间间隔。此外,操作界面还可以用于展示测试完成后的安全测试报告,这些报告对评估和分析测试结果至关重要。
模拟攻击模块负责接收来自操作界面的配置参数,并根据这些参数设定不同的攻击模拟策略,生成相应的指令,并发送给调度处理模块,以此启动搭建网络安全测试场景的流程。
调度处理模块的功能可以是按照通信协议的标准算法策略来调度基带处理组件,以完成数据的上下行交互。在本申请实施例中,调度处理模块的主要作用是接收模拟攻击模块的模拟攻击数据,根据这些指令改变标准的通信协议流程,并指示基带处理组件控制目标受控设备执行目标模拟操作。
参照图11B,调度处理模块可以由几个子模块组成,包括UEM(目标受控设备管理)、CPS(信令控制平台)、SPS(业务调度平台)和UPS(业务数据平台)。在一些实施例中,UEM子模块可以用于控制目标受控设备的接入过程;CPS和SPS子模块可以用于负责模拟连接请求过载和连接资源耗尽;UPS子模块则可以用于负责通过发起SRB1信道异常报文和畸形数据报文攻击来模拟异常数据模拟报文。
以上模块和组件协同工作,共同构成了一个能够在网络安全测试方法中模拟网络安全测试场景,旨在提高目标网络的安全性防护能力,通过模拟目标网络受到网络攻击的情况,来检测和防御潜在的安全威胁。
根据本申请提供的一些实施例,在正常通信中,gNodeB(5G无线网络目标网络设备)在成功接收到来自目标受控设备的RRC Connection Request消息后,会向该设备下发RRC Connection建立消息,并启动一个等待定时器以期待设备回复RRC Connection Complete消息。如果目标受控设备在定时器超时前没有回复,目标网络设备将释放该设备。
在Flooding Attack模式(对应于连接请求过载)中,模拟攻击模块利用这一机制,通过配置目标受控设备在RRC Connection等待定时器超时之前不发送RRC Connection Complete消息,而是持续高频率地发起Random Access过程,即随机接入请求。这样做会导致gNodeB频繁响应这些虚假的接入请求,从而减少对其他合法目标受控设备的接入机会,最终搭建出连接请求过载。
在一些实施例中,首先,在测试终端的操作界面上设置Flooding Attack模式。然后,配置发起接入请求的目标受控设备数目为1。模拟攻击模块在收到Flooding Attack模式指令后,开始执行攻击:给设备管理平台模块发送配置的目标受控设备数目和相关上下文信息。向信令控制平台模块发送Flooding Attack指令,该模块会修改RRC Connection内存变量,设置ACK报文为拒绝状态,并启动一个时长为1秒的定时器AttckTimer。信令控制平台模块启动目标受控设备发起Attach流程。一旦RRC连接建立,模块会判断ACK报文是否为拒绝状态,如果是,则进入异常报文流程,并将攻击结果次数AttackNum加1,然后重新发起Attach流程。当AttckTimer定时器超时后,信令控制平台模块自动触发,将AttackNum反馈给模拟攻击模块,后者将结果整理汇总,并存储到测试装置的固定目录下。最后,用户在测试终端的操作界面上点击停止攻击测试功能按钮,结束本轮攻击,并下载攻击结果报告。
通过这个过程,可以模拟目标网络遇到连接请求过载,从而帮助检测和防御此类攻击。
根据本申请提供的一些实施例,利用了无线通信协议中RRC连接建立和释放的过程。在正常情况下,当目标受控设备成功建立RRC连接后,它会向gNodeB回复一个包含IMSI(国际移动用户识别码)的RRC Connection Complete消息。gNodeB收到此消息后,将相关信息发送给核心网,并请求目标受控设备进行鉴权,核心网随即启动一个定时器T3560(默认值为5秒),等待目标受控设备发送鉴权响应。如果目标受控设备在定时器超时前未发送鉴权响应,核心网将指示目标网络设备释放RRC连接。
在Deplete RRC Res Attack模式(对应于连接资源耗尽)中,模拟攻击模块会指示目标受控设备在接收到鉴权请求后不发送鉴权响应,而是重新发起随机接入过程。这样,在定时器T3560运行期间,会频繁触发RRC连接的建立和释放。如果新建立的RRC连接数量超过释放的数量,并且多个目标受控设备长时间执行此操作,最终将耗尽RRC的连接资源,模拟出连接资源耗尽。
在一些实施例中,首先,在操作界面上设置Deplete RRC Res Attack模式,并配置目标受控设备的数量、IMSI和发起Attach的时间间隔。模拟攻击模块在收到攻击模式指令后,开始执行场景模拟流程。它首先向设备管理平台模块发送配置信息,然后向信令控制平台模块发送攻击指令,修改鉴权响应为拒绝状态,并启动定时器AttckTimer。信令控制平台模块根据配置启动目标受控设备发起Attach流程。当目标受控设备收到鉴权请求时,由于设置了拒绝状态,将不发送鉴权响应,而是增加攻击结果计数AttackNum,然后重新发起Attach流程。当定时器AttckTimer超时后,信令控制平台模块将AttackNum反馈给模拟攻击模块,后者将结果整理汇总,并存储到测试装置的固定目录下。最后,用户在操作界面上点击停止攻击测试功能按钮,结束本轮攻击,并下载攻击结果报告。
通过这一流程,可以模拟目标网络遇到连接资源耗尽,帮助检测和提升目标网络设备对此类攻击的防御能力。
根据本申请提供的一些实施例,基于无线通信协议中MAC PDU(Medium Access Control Protocol Data Unit)报文的规定,其中L位(长度字段)的长度必须小于65535,而LCID(Logical Channel ID)位必须在0到32之内。通过这种方式模拟异常数据模拟报文,目标受控设备会故意发送LCID填写为1且L位字段填写异常的MAC PDU报文,导致目标网络设备识别到SRB1(Signaling Radio Bearer 1)信道报文长度异常并将其丢弃。同样,如果目标受控设备将MAC PDU报文中的LCID填写为异常值,目标网络设备也会识别并丢弃这些异常数据报文。
攻击的目的在于,如果目标受控设备长时间发送这种异常数据,目标网络设备将不得不频繁响应这些异常报文,从而无法为其他用户提供正常服务,造成大量网络资源的浪费,实现拒绝服务的目的。
在一些实施例中,首先,终端装置触发目标受控设备正常接入网络,并开始进行FTP文件拷贝,按照gNodeB调度的帧结构周期进行上行业务传输。以TDD制式和2.5ms双周期帧结构为例,目标受控设备将在特定的上行Slot发送上行SRB数据。接下来,模拟攻击模块在收到SRB1异常数据攻击模式指令后,启动攻击。它向业务数据平台模块发送SRB1异常数据攻击指令,业务数据平台模块接收到指令后,将SRB1内存变量修改为异常状态,并启动定时器AttckTimer,持续时间为1秒。然后,目标受控设备将特定Slot的业务数据组包为SRB1信道数据,并修改MAC PDU数据中的L位为异常值65535。目标网络设备收到这些异常长度的报文后将予以丢弃,而数据发送频率大约为1000ms除以SlotU(上行Slot个数)。模拟攻击模块在收到畸形数据报文攻击模式指令后,再次启动攻击。它向业务数据平台模块发送畸形数据报文攻击指令,业务数据平台模块将DATA内存变量修改为异常状态,并再次启动定时器AttckTimer。在场景模拟过程中,测试装置将上行空口Slot的业务数据更改为异常MAC报文数据,LCID填充在协议要求之外,数据发送频率与之前相同。当需要结束攻击时,用户在测试终端的操作界面上点击停止攻击测试功能按钮。最后,用户可以下载攻击结果报告,该报告以Excel格式成功导出。
通过这一流程,可以模拟目标网络遇到异常数据模拟报文,帮助检测和提升目标网络设备对此类攻击的防御能力,帮助检测和提升目标网络设备对此类攻击的防御能力。
本申请实施例还提供了一种电子设备,如图12所示,该电子设备1200包括:
一个或多个处理器1210;
存储器1220,其上存储有一个或多个程序,当一个或多个程序被一个或多个处理器1210执行,使得一个或多个处理器1210实现网络安全测试方法。
存储器1220作为一种非暂态网络系统,可用于存储非暂态软件程序以及非暂态性计算机可执行程序。此外,存储器1220可以包括高速随机存取存储器,还可以包括非暂态存储器,例如至少一个磁盘存储器件、闪存器件、或其他非暂态固态存储器件。
在一些实施方式中,存储器1220可包括相对于处理器1210远程设置的存储器1220,这些远程存储器1220可以通过网络连接至该处理器1210。上述网络的实例包括但不限于互联网、企业内部网、局域网、移动通信网及其组合。
存储器1220,可以采用只读存储器(ReadOnlyMemory,ROM)、静态存储设备、动态存储设备或者随机存取存储器(RandomAccessMemory,RAM)等形式实现。存储器1220可以存储操作系统和其他应用程序,在通过软件或者固件来实现本说明书实施例所提供的技术方案时,相关的程序代码保存在存储器1220中,并由处理器1210来调用执行本申请实施例的方法。
处理器1210,可以采用通用的CPU(CentralProcessingUnit,中央处理器)、微处理器、应用专用集成电路(ApplicationSpecificIntegratedCircuit,ASIC)、或者一个或多个集成电路等方式实现,用于执行相关程序,以实现本申请实施例所提供的技术方案。
在一些实施例中,电子设备还包括:
输入/输出接口,用于实现信息输入及输出;
通信接口,用于实现本设备与其他设备的通信交互,可以通过有线方式(例如USB、网线等)实现通信,也可以通过无线方式(例如移动网络、WIFI、蓝牙等)实现通信;
总线,在设备的各个组件(例如处理器1210、存储器1220、输入/输出接口和通信接口)之间传输信息;
其中处理器1210、存储器1220、输入/输出接口和通信接口可以通过总线实现彼此之间在设备内部的通信连接。
本申请一实施例还提供了一种计算机可读存储介质,存储有计算机可执行指令,该计算机可执行指令用于执行实现网络安全测试方法。
本申请一实施例还提供了一种计算机程序产品,可以包括,但不限于计算机程序或计算机指令,该计算机程序或计算机指令存储在计算机可读存储介质中,计算机设备的处理器从计算机可读存储介质读取计算机程序或计算机指令,处理器执行计算机程序或计算机指令,使得计算机设备执行实现网络安全测试方法。
本申请实施例描述的系统架构以及应用场景是为了更加清楚的说明本申请实施例的技术方案,并不构成对于本申请实施例提供的技术方案的限定,本领域技术人员可知,随着系统架构的演变和新应用场景的出现,本申请实施例提供的技术方案对于类似的技术问题,同样适用。
本申请实施例提供的网络安全测试方法,首先,获取测试场景模拟指令,并根据所述测试场景模拟指令确定目标模拟操作和目标受控设备;接着,通过所述目标受控设备对目标网络设备执行所述目标模拟操作,搭建网络安全测试场景;进一步,基于所述网络安全测试场景对所述目标网络设备对应目标网络进行安全测试,得到所述目标网络在所述网络安全测试场景下的安全测试报告。本申请能够通过目标受控设备对目标网络设备执行目标模拟操作,从而搭建网络安全测试场景,以模拟目标网络受到网络攻击的情况,进而对目标网络进行测试,帮助提升目标网络设备的网络安全检测和网络防御能力。
本领域普通技术人员可以理解实现上述实施例方法中的全部或部分流程,是可以通过计算机程序来指令相关的硬件来完成,的计算机程序可存储于一非易失性计算机可读取存储介质中,该计算机程序在执行时,可包括如上述各方法的实施例的流程。其中,本申请所提供的各实施例中所使用的对存储器、存储、数据库或其它介质的任何引用,均可包括非易失性和/或易失性存储器。非易失性存储器可包括只读存储器(ROM)、可编程ROM(PROM)、电可编程ROM(EPROM)、电可擦除可编程ROM(EEPROM)或闪存。易失性存储器可包括随机存取存储器(RAM)或者外部高速缓冲存储器。作为说明而非局限,RAM以多种形式可得,诸如静态RAM(SRAM)、动态RAM(DRAM)、同步DRAM(SDRAM)、双数据率SDRAM(DDRSDRAM)、增强型SDRAM(ESDRAM)、同步链路(Synchlink)DRAM(SLDRAM)、存储器总线(Rambus)直接RAM(RDRAM)、直接存储器总线动态RAM(DRDRAM)、以及存储器总线动态RAM(RDRAM)等。
本领域普通技术人员可以理解,上文中所公开方法中的全部或某些步骤、系统可以被实施为软件、固件、硬件及其适当的组合。某些物理组件或所有物理组件可以被实施为由处理器,如中央处理器、数字信号处理器或微处理器执行的软件,或者被实施为硬件,或者被实施为集成电路,如专用集成电路。这样的软件可以分布在计算机可读介质上,计算机可读介质可以包括计算机存储介质(或非暂时性介质)和通信介质(或暂时性介质)。如本领域普通技术人员公知的,术语计算机存储介质包括在用于存储信息(诸如计算机可读指令、数据结构、程序模块或其他数据)的任何方法或技术中实施的易失性和非易失性、可移除和不可移除介质。计算机存储介质包括但不限于RAM、ROM、EEPROM、闪存或其他存储器技术、CD-ROM、数字多功能盘(DVD)或其他光盘存储、磁盒、磁带、磁盘存储或其他磁存储装置、或者可以用于存储期望的信息并且可以被计算机访问的任何其他的介质。此外,本领域普通技术人员公知的是,通信介质通常包含计算机可读指令、数据结构、程序模块或者诸如载波或其他传输机制之类的调制数据信号中的其他数据,并且可包括任何信息递送介质。
以上参照附图说明了本申请的一些实施例,并非因此局限本申请的权利范围。本领域技术人员不脱离本申请的范围和实质内所作的任何修改、等同替换和改进,均应在本申请的权利范围之内。
Claims (15)
- 一种网络安全测试方法,所述方法包括:获取测试场景模拟指令,并根据所述测试场景模拟指令确定目标模拟操作和目标受控设备;通过所述目标受控设备对目标网络设备执行所述目标模拟操作,搭建网络安全测试场景;基于所述网络安全测试场景对所述目标网络设备对应目标网络进行安全测试,得到所述目标网络在所述网络安全测试场景下的安全测试报告。
- 根据权利要求1所述的网络安全测试方法,其中,所述根据所述测试场景模拟指令确定目标模拟操作和目标受控设备,包括:根据所述测试场景模拟指令,确定与所述网络安全测试场景匹配的受控设备标识信息和受控设备操作信息,其中,所述测试场景模拟指令用于模拟在所述目标网络中搭建所述网络安全测试场景;根据所述受控设备标识信息从所述目标网络中,确定搭建所述网络安全测试场景的所述目标受控设备;根据所述受控设备操作信息从所述目标网络的运行数据中,确定所述目标受控设备在所述网络安全测试场景中执行的所述目标模拟操作。
- 根据权利要求2所述的网络安全测试方法,其中,所述测试场景模拟指令包括场景模拟类型信息、设备配置参数和操作模拟频率,所述根据所述测试场景模拟指令,确定与所述网络安全测试场景匹配的受控设备标识信息和受控设备操作信息,包括:基于所述测试场景模拟指令中的所述场景模拟类型信息确定出所述测试场景模拟指令对应的模拟场景方式;根据所述模拟场景方式和所述操作模拟频率从场景数据库中,获取与所述设备配置参数匹配的所述受控设备标识信息以及所述受控设备操作信息。
- 根据权利要求1所述的网络安全测试方法,其中,所述通过所述目标受控设备对目标网络设备执行所述目标模拟操作,搭建网络安全测试场景,包括:确定出所述目标模拟操作对应于连接请求过载:修改所述目标受控设备的网络连接内存变量,以将所述目标受控设备的连接确认报文设置为拒绝状态;重新通过所述目标受控设备向所述测试场景模拟指令对应的所述目标网络设备发起网络连接请求,并接收所述目标网络设备响应于所述网络连接请求的连接建立信息;基于所述拒绝状态的连接确认报文和所述连接建立信息,控制所述目标受控设备拒绝回复所述连接建立信息,返回执行重新通过所述目标受控设备向所述测试场景模拟指令对应的目标网络设备发起所述网络连接请求,以搭建得到所述网络安全测试场景。
- 根据权利要求1所述的网络安全测试方法,其中,所述通过所述目标受控设备对目标网络设备执行所述目标模拟操作,搭建网络安全测试场景,包括:确定出所述目标模拟操作对应于连接资源耗尽:修改所述目标受控设备的鉴权内存变量,以将所述目标受控设备的鉴权确认报文设置为所述拒绝状态;重新通过所述目标受控设备向所述测试场景模拟指令对应的所述目标网络设备发起网络连接请求,并接收所述目标网络设备响应于所述网络连接请求的连接建立信息;基于所述连接建立信息生成与所述连接建立信息对应的连接确认信息,并向所述目标网络设备发送所述连接确认信息;所述通过所述目标受控设备获取所述目标网络设备响应于所述连接确认信息的鉴权请求,基于所述拒绝状态的所述鉴权确认报文,控制所述目标受控设备拒绝回复所述鉴权请求,返回执行向所述目标网络设备发起所述网络连接请求,以搭建得到所述网络安全测试场景。
- 根据权利要求5所述的网络安全测试方法,其中,存在第一数目个所述目标受控设备在同一请求时隙中发起所述网络连接请求,所述重新通过所述目标受控设备向所述测试场景模拟指令对应的所述目标网络设备发起网络连接请求,包括:针对第一数目个所述目标受控设备,确定每一所述目标受控设备在所述请求时隙的前导序列,以使每一所述目标受控设备对应的所述前导序列均不相同;每一所述目标受控设备基于对应的所述前导序列,向所述目标网络设备发起所述网络连接请求。
- 根据权利要求6所述的网络安全测试方法,其中,所述针对第一数目个所述目标受控设备,确定每一所述目标受控设备在所述请求时隙的前导序列,包括:获取包括第二数目个前导序列索引的序列索引集合;其中,所述前导序列索引用于查询候选的所述前导序列;从第一数目个所述目标受控设备中,确定每一所述目标受控设备对应的设备编号;针对每一所述目标受控设备,基于所述设备编号与第二数目进行模运算,得到索引序号,基于所述索引序号在所述序列索引集合选中相应的所述前导序列索引,并依据所述前导序列索引从候选的所述前导序列中,为所述目标受控设备配置对应的所述前导序列。
- 根据权利要求1所述的网络安全测试方法,其中,所述通过所述目标受控设备对目标网络设备执行所述目标模拟操作,搭建网络安全测试场景,包括:确定出所述目标模拟操作对应于异常数据模拟报文:修改所述目标受控设备的信道内存变量,以将所述目标受控设备的信道传输报文设置为异常状态;重新通过所述目标受控设备与所述测试场景模拟指令对应的所述目标网络设备建立连接;其中,所述目标受控设备与所述目标网络设备之间的数据传输,受数据传输协议的约束;基于所述异常状态的所述信道传输报文,生成不符合所述数据传输协议的模拟传输数据,并通过所述目标受控设备向建立连接的所述目标网络设备发送所述模拟传输数据,以使所述目标网络设备将所述模拟传输数据识别为异常数据并丢弃,返回执行通过所述目标受控设备向建立连接的所述目标网络设备发送所述模拟传输数据,以搭建得到所述网络安全测试场景。
- 根据权利要求8所述的网络安全测试方法,其中,所述模拟传输数据包括报文长度标识位与逻辑信道标识位,所述生成不符合所述数据传输协议的模拟传输数据,包括:确定所述数据传输协议中对所述报文长度标识位的第一约束条件、对所述逻辑信道标识位的第二约束条件;生成所述模拟传输数据,以使所述模拟传输数据在报文长度标识位不满足所述第一约束条件,或者,以使所述模拟传输数据在所述逻辑信道标识位满足所述第二约束条件。
- 根据权利要求1所述的网络安全测试方法,其中,所述通过所述目标受控设备对目标网络设备执行所述目标模拟操作,搭建网络安全测试场景,包括:在每一次所述目标模拟操作被执行之后,对所述目标模拟操作对应的执行次数进行更新;基于更新后的所述执行次数,生成所述网络安全测试场景。
- 根据权利要求10所述的网络安全测试方法,其中,所述基于更新后的所述执行次数,生成所述网络安全测试场景,包括:从执行所述目标模拟操作起,每经过一次预设时间间隔,对所述预设时间间隔期间更新的所述执行次数进行统计,得到中间模拟数据;基于每一所述预设时间间隔相应的所述中间模拟数据,生成所述网络安全测试场景。
- 根据权利要求1所述的网络安全测试方法,其中,所述获取测试场景模拟指令,包括:显示配置操作界面;响应于目标对象在配置操作界面的输入,获取场景模拟配置参数;基于所述场景模拟配置参数,生成针对所述目标网络的所述测试场景模拟指令。
- 一种电子设备,包括:一个或多个处理器;存储器,其上存储有一个或多个计算机程序,当所述一个或多个计算机程序被所述一个或多个处理器执行,使得所述一个或多个处理器实现如权利要求1至12任一所述的网络安全测试方法。
- 一种计算机可读存储介质,其上存储有计算机程序,所述计算机程序被处理器执行时实现如权利要求1至12任一所述的网络安全测试方法。
- 一种计算机程序产品,包括计算机程序,所述计算机程序被处理器执行时实现如权利要求1至12任一所述的网络安全测试方法。
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN202410695870.9 | 2024-05-30 | ||
| CN202410695870.9A CN121056872A (zh) | 2024-05-30 | 2024-05-30 | 网络安全测试方法、电子设备、介质和计算机程序产品 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2025246720A1 true WO2025246720A1 (zh) | 2025-12-04 |
Family
ID=97808108
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2025/089815 Pending WO2025246720A1 (zh) | 2024-05-30 | 2025-04-18 | 网络安全测试方法、电子设备、介质和计算机程序产品 |
Country Status (2)
| Country | Link |
|---|---|
| CN (1) | CN121056872A (zh) |
| WO (1) | WO2025246720A1 (zh) |
Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN111245800A (zh) * | 2020-01-02 | 2020-06-05 | 北京航天测控技术有限公司 | 基于应用场景的工控网络的网络安全测试方法和装置 |
| US20220075708A1 (en) * | 2020-09-10 | 2022-03-10 | Doppelio Technologies Private Limited | Device virtualization and simulation of a system of things |
| CN115694970A (zh) * | 2022-10-28 | 2023-02-03 | 南方电网科学研究院有限责任公司 | 网络安全攻防演练系统、方法及可读存储介质 |
| CN116886584A (zh) * | 2023-08-02 | 2023-10-13 | 普联技术有限公司 | 网络测试方法、计算机设备、网络设备和可读存储介质 |
-
2024
- 2024-05-30 CN CN202410695870.9A patent/CN121056872A/zh active Pending
-
2025
- 2025-04-18 WO PCT/CN2025/089815 patent/WO2025246720A1/zh active Pending
Patent Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN111245800A (zh) * | 2020-01-02 | 2020-06-05 | 北京航天测控技术有限公司 | 基于应用场景的工控网络的网络安全测试方法和装置 |
| US20220075708A1 (en) * | 2020-09-10 | 2022-03-10 | Doppelio Technologies Private Limited | Device virtualization and simulation of a system of things |
| CN115694970A (zh) * | 2022-10-28 | 2023-02-03 | 南方电网科学研究院有限责任公司 | 网络安全攻防演练系统、方法及可读存储介质 |
| CN116886584A (zh) * | 2023-08-02 | 2023-10-13 | 普联技术有限公司 | 网络测试方法、计算机设备、网络设备和可读存储介质 |
Also Published As
| Publication number | Publication date |
|---|---|
| CN121056872A (zh) | 2025-12-02 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| CN110476474B (zh) | 用于执行随机接入过程的设备和方法 | |
| US8576780B2 (en) | Random access response processing | |
| KR100949972B1 (ko) | 단말의 임의접속 수행 기법 | |
| JP4677490B2 (ja) | 無線移動通信システムにおける無線接続情報送受信方法 | |
| KR101365757B1 (ko) | Rrc 접속 요청 메시지를 분리하여 전송하는 방법 | |
| CN102461306B (zh) | 便于中继节点通信的方法和装置 | |
| CN106550480B (zh) | 一种随机接入方法、装置及系统 | |
| JP7599549B2 (ja) | データ伝送タイプの設定方法と端末 | |
| US11297651B2 (en) | Multiple random access preamble transmission for a single random access procedure | |
| JP2010041729A (ja) | アップリンクグラントを処理する方法及び通信装置 | |
| CN113114650A (zh) | 网络攻击的解决方法、装置、设备及介质 | |
| WO2013166670A1 (zh) | 上行信道资源配置方法和设备 | |
| US20180160462A1 (en) | Data Radio Bearer Establishment Method and Apparatus | |
| Pratas et al. | Massive machine-type communication (mMTC) access with integrated authentication | |
| EP2596670B1 (en) | Apparatus and method for acquisition of a common enhanced dedicated channel resource | |
| WO2016186542A1 (en) | Methods for a random access procedure, and user terminal, network node, computer programs and computer program products | |
| WO2023133691A1 (zh) | Drx配置方法、装置、设备及介质 | |
| EP3364671B1 (en) | Method and device for data transmission | |
| CN103220718A (zh) | 上行数据传输方法及装置 | |
| KR101435688B1 (ko) | 이동통신시스템에서의 효과적으로 무선자원할당요청을 보내는 방법 | |
| CN114125914B (zh) | 无线通信方法和终端设备 | |
| CN115150878A (zh) | 随机接入信息上报方法和用户设备 | |
| KR102067865B1 (ko) | 이동통신시스템에서의 스케줄링 요청(Scheduling Request)을 효율적으로 전송하는 방법 | |
| KR101494907B1 (ko) | 기할당된 무선 자원을 이용한 효율적인 Buffer Status Report(BSR) 과정 수행 방법 | |
| WO2025246720A1 (zh) | 网络安全测试方法、电子设备、介质和计算机程序产品 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 25814441 Country of ref document: EP Kind code of ref document: A1 |