作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2021, Vol. 47 ›› Issue (10): 103-110. doi: 10.19678/j.issn.1000-3428.0059355

• 网络空间安全 • 上一篇    下一篇

基于交互式流量回放的用户行为仿真技术

黄宁, 刘渊, 王晓锋   

  1. 江南大学 人工智能与计算机学院, 江苏 无锡 214122
  • 收稿日期:2020-08-25 修回日期:2020-09-27 发布日期:2020-10-09
  • 作者简介:黄宁(1994-),男,硕士研究生,主研方向为网络安全、流量仿真;刘渊,教授、博士生导师;王晓锋,副教授、博士。
  • 基金资助:
    国家重点研发计划(2016YFB0800305);国家自然科学基金(61672264,61972182)。

User Behavior Emulation Technology Based on Interactive Traffic Replay

HUANG Ning, LIU Yuan, WANG Xiaofeng   

  1. School of Artificial Intelligence and Computer Science, Jiangnan University, Wuxi, Jiangsu 214122, China
  • Received:2020-08-25 Revised:2020-09-27 Published:2020-10-09

摘要: 流量回放可为网络靶场提供逼真的流量数据并支持网络新技术验证与安全评测。面向复杂虚拟网络的交互式用户行为仿真需求,设计一种交互式流量链路的用户行为仿真架构。采用基于云平台的分布式流量仿真策略,以实现面向复杂虚拟网络用户的行为仿真多样化和可扩展加载。对交互式流量回放过程中延时修复与补偿策略进行研究,提升交互式用户行为仿真的时序逼真性。仿真实验结果表明,该仿真架构能够在保证流量时序准确性的前提下,实现交互式的大规模用户行为仿真,与传统的ITRM、Tcpreplay等方法相比,在仿真行为的多样性、规模性、逼真性上具有一定优势,可为安全评测提供有效支撑。

关键词: 网络靶场, 交互式流量回放, 流量仿真, 虚拟目标网络, 大规模用户行为仿真

Abstract: Traffic replay can provide realistic traffic data for the cyber range, and support new technology verification and network security evaluation.To meet the needs of interactive user behavior simulation for complex virtual networks, an architecture for user behavior emulation is designed based on interactive traffic links.The architecture adopts a distributed traffic emulation strategy based on cloud platform to achieve diversified and scalable loading of user behavior emulation for complex target networks.The delay repair and compensation strategy in the process of traffic replay is further studied to improve the timing fidelity of interactive user behavior emulation.Results of emulation experiments show that this method can realize interactive large-scale user behavior emulation with the accuracy of traffic timing ensured.It has certain advantages in the diversity, scale and fidelity of behavior emulation over traditional methods such as ITRM and Tcpreplay, providing effective support for security evaluation.

Key words: cyber range, interactive traffic replay, traffic emulation, virtual target network, large-scale user behavior emulation

中图分类号: