构建可复现的网络安全实验平台,支持多协议环境下的攻击模拟与数据生成。
NetSecBed: A Container-Native Testbed for Reproducible Cybersecurity Experimentation
- 用容器化架构集成60种攻击场景和9个服务,实现即插即用
- 自动化执行、抓包、日志收集与数据集整合,提升实验可重复性
- 适合物联网与工业互联网安全研究者,支持持续数据生成
网络安全研究越来越依赖可复现的证据,如流量记录、日志和标注数据集,但大多数公开数据集仍为静态,缺乏对受控重演和可追溯性的支持,尤其在异构多协议环境中。本文提出NetSecBed,一个容器原生、场景导向的测试平台,可在受控条件下生成网络流量证据与执行产物,特别适用于物联网(IoT)、工业物联网(IIoT)及普遍存在的多协议环境。该框架集成60种攻击场景、9个目标服务及良性流量生成器,均以单用途容器形式部署,通过声明式规范实现即插即用扩展与可追溯性。其流水线自动完成参数化执行、报文捕获、日志收集、服务探测、特征提取与数据集合并。主要贡献在于提供可重复、可审计、可扩展的网络安全实验框架,减少操作偏差并支持持续数据生成。
原文摘要 · Abstract (English)
Cybersecurity research increasingly depends on reproducible evidence, such as traffic traces, logs, and labeled datasets, yet most public datasets remain static and offer limited support for controlled re-execution and traceability, especially in heterogeneous multi-protocol environments. This paper presents NetSecBed, a container-native, scenario-oriented testbed for reproducible generation of network traffic evidence and execution artifacts under controlled conditions, particularly suitable for IoT, IIoT, and pervasive multi-protocol environments. The framework integrates 60 attack scenarios, 9 target services, and benign traffic generators as single-purpose containers, enabling plug-and-play extensibility and traceability through declarative specifications. Its pipeline automates parametrized execution, packet capture, log collection, service probing, feature extraction, and dataset consolidation. The main contribution is a repeatable, auditable, and extensible framework for cybersecurity experimentation that reduces operational bias and supports continuous dataset generation.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。