Formal language-based security operation element characterization method and system and medium
Through the term language-based security operation element characterization method, the characterization of the secure operation environment is generated and verified, and the problem of difficulty in verifying and timely repairing network security protection in the prior art is solved, achieving more efficient security analysis and protection effects.
Patent Information
- Application Number
- CN202510079963.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-18
- Publication Date
- 2025-05-06
AI Technical Summary
It is difficult for existing network security protection technologies to effectively verify the effectiveness of protective measures, and promptly discover and repair network security problems, resulting in unclear effects of conventional protection, lagging response, and difficult to detect key protection points.
Using a formal language-based security operation element representation method, the host of the target environment is used to detect and scan or enter configuration files, and configuration information of network entities and security operation entities are obtained, and configuration information of network entities and security operation entities are abstracted and generated based on formal language-based security operation entity representations, attribute representations and contact representations are conducted to ensure accuracy and availability.
It provides a unified description and specification of the safe operation environment, realizes the reliability and completeness verification of the safe operation environment, provides a foundation for strengthening safety protection measures, and improves the analysis efficiency and protection effect of the safe operation environment.
Smart Images

Figure CN119945769A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network security, and more specifically, to a security operation element characterization method, system and medium based on formal language. Background Art
[0002] Cyber attacks have a serious impact on people's lives. Attackers use vulnerability exploitation and social engineering to attack user networks or nodes to achieve malicious purposes such as network control or information acquisition. In order to timely detect and intercept cyber attacks and reduce the impact of cyber attacks, it is very important to study network security protection technologies against cyber attacks.
[0003] After statistics on the causes of network attacks, it was found that 97% of network attacks occurred in companies that have deployed network security systems, 99% of network attacks were caused by vulnerabilities that have existed for many years or by known attack methods, and 95% of network attacks were caused by incorrect configuration of security equipment. It can be seen that although users have deployed network security measures in their own networks, if the protection strategy is not correctly configured or continuously upgraded, the security protection measures will not be able to play their due role and effectively prevent network penetration attacks. Conventional network security protection measures have problems such as unclear network protection effects, delayed passive defense response, and difficulty in finding key protection points. How to verify the effectiveness of protection measures and promptly discover network security issues for repair and improvement has become an urgent problem to be solved in network security protection.
[0004] The reason why network security is difficult to verify is that it is difficult to uniformly describe and model the network security operation environment. The complex and ever-changing security operation environment has led to different analysis principles and methods for various scenarios in the industry, which has greatly increased the difficulty of verifying the effectiveness of security operation means. Therefore, by standardizing the description of the security operation environment, it can effectively assist the automatic calculation of the reliability and completeness of the security operation environment, and provide more intelligent and powerful security protection. Summary of the invention
[0005] The purpose of the embodiments of the present application is to provide a security operation element characterization method, system and medium based on formal language.
[0006] To achieve the above objectives, this application provides the following technical solutions:
[0007] In a first aspect, an embodiment of the present application provides a security operation element characterization method based on a formal language, comprising the following specific steps:
[0008] Step S1: acquiring partial network entity configuration information of the target environment by performing a detection scan on the host of the target environment or inputting a configuration file;
[0009] Step S2: Obtaining security operation entity configuration information in the target environment by inputting a configuration file of the security system in the target environment;
[0010] Step S3: abstract the configurations obtained in S1 and S2, and generate a formal language-based representation of security operation entities according to the specification definition library;
[0011] Step S4: for each entity representation generated in S3, based on the configuration information, generate a security operation entity attribute representation based on a formal language corresponding to the entity;
[0012] Step S5: Generate a security operation entity connection representation based on a formal language according to the network topology information of the target environment;
[0013] Step S6: Perform further specification checks on the representations generated by S3, S4, and S5 to ensure accuracy and usability.
[0014] The specific method of obtaining the configuration information of the security operation entity in the target environment by inputting the configuration file of the security system in the target environment is as follows:
[0015] The real-time distribution results of hosts, ports and services in the obtained network environment are parsed to generate a data structure for storing relevant entity configuration information. The data structure for storing entity configuration information includes: entity type, surviving host IP, operating system type, open ports, service name, service version, and contained vulnerabilities.
[0016] The specific method of obtaining the configuration information of the security operation entity in the target environment by inputting the configuration file of the security system in the target environment is:
[0017] By parsing network configuration information in various formats, additional static network entity information is obtained to improve the accuracy and completeness of the information; a data structure is generated to store relevant entity configuration information, and the data structure that stores relevant security operation entity configuration information includes: security operation entity type, deployment location, and scope data.
[0018] The specific implementation method of generating a formal language-based representation of security operation entities according to the specification definition library is as follows:
[0019] According to the data structure that stores the relevant entity configuration information, the entity name and entity type are extracted and the corresponding entity representation is generated based on the specification definition.
[0020] The specific implementation method of generating a formal language-based security operation entity attribute representation based on entity configuration information is as follows:
[0021] By determining the type of entity, the entity's inherent attribute representation can be obtained through knowledge base matching; by parsing the data structure that stores the entity configuration information, the entity's occasional attribute values can be extracted for representation; finally, by retrieving the connections and attributes between entities, the entity's transfer attributes can be obtained.
[0022] The specific implementation method of generating security operation entity connection representation based on the target environment network topology is:
[0023] Extract the relationship between hosts, ports and services in the network topology, and generate security operation entity relationship representations according to the specification definition.
[0024] In a second aspect, an embodiment of the present application provides a security operation element characterization system based on a formal language, the system comprising: a memory and a processor, the memory comprising a program of a security operation element characterization method based on a formal language, and the program of the security operation element characterization method based on a formal language, when executed by the processor, implements the following steps: obtaining partial network entity configuration information of the target environment by performing a detection scan on the host of the target environment or inputting a configuration file; obtaining security operation entity configuration information in the target environment by inputting a configuration file of a security system in the target environment; abstracting the obtained configuration, and generating a security operation entity representation based on a formal language according to a specification definition library; for each generated entity representation, generating a security operation entity attribute representation based on a formal language corresponding to the entity based on the configuration information; generating a security operation entity connection representation based on a formal language according to the network topology information of the target environment; and performing further specification checks on the generated representation to ensure accuracy and availability.
[0025] In a third aspect, an embodiment of the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores program code, and when the program code is executed by a processor, the steps of the security operation element characterization method based on formal language as described above are implemented.
[0026] Compared with the prior art, the beneficial effects of the present invention are: the present invention provides a unified description specification for the secure operating environment, based on which the reliability and completeness of the secure operating environment can be verified, providing a basis for further strengthening security protection measures.
[0027] Furthermore, the security operation element representation provided by the present invention is implemented based on a formal language, which can be processed and analyzed by a computer program, thereby realizing the computability of the security operation environment and effectively improving the efficiency of the analysis of the security operation environment.
[0028] Furthermore, the security operation element representation provided by the present invention has strong scalability and can describe a complex and changeable security operation environment by characterizing entities, connections and entity attributes.
[0029] Furthermore, the security operation element characterization method provided by the present invention has strong portability and can uniformly and normatively describe the network security operation environment in different network topologies and even different business systems. BRIEF DESCRIPTION OF THE DRAWINGS
[0030] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for use in the embodiments of the present application will be briefly introduced below. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying creative work.
[0031] Figure 1 A flow chart of a security operation element characterization method based on a formal language provided in an embodiment of the present invention;
[0032] Figure 2 A formal grammar structure diagram for representing security operation elements based on a formal language provided in an embodiment of the present invention;
[0033] Figure 3 An example diagram of a formal language for representing security operation entities and security operation entity relationships provided in an embodiment of the present invention. DETAILED DESCRIPTION
[0034] The technical solutions in the embodiments of the present application will be described below in conjunction with the drawings in the embodiments of the present application. It should be noted that similar reference numerals and letters represent similar items in the following drawings, so once an item is defined in one drawing, it does not need to be further defined and explained in the subsequent drawings.
[0035] The terms "comprises," "comprising," or any other variation thereof are intended to encompass non-exclusive inclusion, such that a process, method, article, or apparatus that includes a list of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of additional identical elements in the process, method, article, or apparatus that includes the element.
[0036] The terms "first", "second", etc. are only used to distinguish one entity or operation from another entity or operation, and should not be understood as indicating or implying relative importance, nor should they be understood as requiring or implying any such actual relationship or order between these entities or operations.
[0037] like Figure 1As shown, an embodiment of the present invention provides a security operation entity characterization method based on formal language, including:
[0038] Step S1: Obtain some network entity configuration information of the target environment by performing a detection scan on the host of the target environment or inputting a configuration file.
[0039] More specifically, the real-time distribution results of hosts, ports and services in the network environment obtained by scanning tools such as Nmap and Masscan are parsed to generate a data structure that stores relevant entity configuration information.
[0040] More specifically, additional static network entity information is obtained by parsing network configuration information in various formats to improve the accuracy and completeness of the information; and a data structure for storing related entity configuration information is also generated.
[0041] More specifically, the data structure storing the entity configuration information includes: entity type, surviving host IP, operating system type, open ports, service name, service version, included vulnerabilities and other data.
[0042] Step S2: Obtain the security operation entity configuration information in the target environment by inputting the configuration file of the security system in the target environment.
[0043] More specifically, by parsing security system configuration files in various formats, security system and policy information in the network environment is extracted, and a data structure that stores configuration information of related security operation entities is generated.
[0044] Step S3: Abstract the configurations obtained in S1 and S2, and generate a formal language-based representation of security operation entities according to the specification definition library.
[0045] More specifically, according to the data structure storing the relevant entity configuration information, the entity name and entity type are extracted and the corresponding entity representation is generated based on the specification definition.
[0046] Step S4: For each entity representation generated in S3, based on the configuration information, generate a security operation entity attribute representation based on a formal language corresponding to the entity.
[0047] More specifically, by determining the type of entity, the entity's inherent attribute representation can be obtained through knowledge base matching; by parsing the configuration file, the entity's occasional attribute values can be extracted for representation; finally, by retrieving the connections between entities and the knowledge base, the entity's transfer attributes can be obtained.
[0048] Step S5: Generate a security operation entity connection representation based on a formal language according to the network topology information of the target environment.
[0049] More specifically, the connection relationships among hosts, ports, and services in the network topology are extracted, and security operation entity connection representations are generated according to specification definitions.
[0050] Step S6: Perform further specification checks on the representations generated by S3, S4, and S5 to ensure accuracy and usability.
[0051] More specifically, by constructing a syntax analyzer corresponding to the security operation entity representation specification, the formal language representation generated in the above steps can be syntax checked to determine whether its syntax structure conforms to the specification definition.
[0052] An embodiment of the present application provides a security operation element characterization system based on a formal language, the system comprising: a memory and a processor, the memory comprising a program of a security operation element characterization method based on a formal language, and the program of the security operation element characterization method based on a formal language, when executed by the processor, implements the following steps: obtaining partial network entity configuration information of the target environment by performing a detection scan on the host of the target environment or inputting a configuration file; obtaining security operation entity configuration information in the target environment by inputting a configuration file of a security system in the target environment; abstracting the obtained configuration, and generating a security operation entity characterization based on a formal language according to a specification definition library; for each generated entity characterization, generating a security operation entity attribute characterization based on a formal language corresponding to the entity based on the configuration information; generating a security operation entity connection characterization based on a formal language according to the network topology information of the target environment; and performing further specification checks on the generated characterization to ensure accuracy and availability.
[0053] A security operation environment representation specification based on a formal language is used to uniformly describe the security operation environment including network hosts, topology, and security system configuration.
[0054] A formal language-based security operation entity representation specification used to uniformly describe network entities such as network host ports, services, and security system components.
[0055] A formal language-based representation specification for security operation entity relationships, used to uniformly describe the relationships and dependencies between network entities.
[0056] A security operation entity attribute representation specification based on a formal language is used to uniformly describe the various attributes of network entities.
[0057] Specifically, Figure 2 As shown, the formal language-based security operation element representation specification includes:
[0058] A security operation entity representation grammar 100 based on a formal language includes a grammatical variable set 200, a terminal symbol set 300, a grammatical rule set 400 and a start symbol of the grammar; the grammar is a generation rule of a security operation element representation specification language, which describes how to use characters in the terminal symbol set 300 to generate a valid string that conforms to the specification.
[0059] The grammar variable set 200 is used to describe the variables used in the grammar rule set 400 .
[0060] The ultimate symbol set 300 is used to describe all characters used in the formal language-based security operation entity representation specification.
[0061] A grammar rule set 400, used to describe the generation rules of valid character strings in the specification, including productions 401, 402, 403, 404, 405, 406, 407;
[0062] Specifically, production 401 indicates that this language only accepts two types of sentence instances. One is the entity sentence represented by the security operation entity (hereinafter referred to as entity), which also contains grammatical variables A and B to describe the entity name and entity attributes respectively; the other sentence is the connection sentence represented by the security operation entity connection (hereinafter referred to as connection), which contains a grammatical variable C for specifically describing the connection between entities.
[0063] Specifically, production 402 describes the generation rule of the entity name in production 401. To simplify the expression, production 402 only describes the derivation of the variable name with the terminal symbol a. In fact, it can be any element in the terminal symbol set 300.
[0064] Specifically, production 403 describes the generation specification of security operation entity attributes (hereinafter referred to as attributes) possessed by the entity, and the attributes include inherent attributes, occasional attributes and transfer attributes, which correspond to the first three parts separated by the symbol | in 403 respectively.
[0065] More specifically, the inherent attributes of an entity refer to the fixed attributes that all objects of the same type of entity have. Therefore, in the entity graph description language, only one variable name is needed to distinguish different inherent attributes, and the inherent attribute name can be directly derived by using the variable name generation rules.
[0066] More specifically, the occasional attributes of an entity refer to the attributes that may be different even for entities of the same type due to different specific objects. Therefore, the key-value pair format is used to describe this characteristic of value differences. The generation specification of the occasional attributes of an entity is described by production formula 404.
[0067] More specifically, the entity's transfer attribute describes the association between different entity attributes in the security operation environment, and is also the inherent logic of security attack and defense, including transfer conditions, transfer starting points, and transfer endpoints. Production 405 describes the generation specification of the transfer attribute, where the grammatical variable A represents the starting point attribute of the transfer attribute, which is an attribute of the entity to which the transfer attribute belongs, and the end point attribute of the transfer process can be transferred from one entity to another, so it is described in the form of AA. The grammatical variable F describes the transfer condition. As described in production 406, the transfer condition has three conditions: and, or, and not. Specifically, when F=or, it means that as long as one transfer step reaches the starting point of the transfer attribute, the transfer can be executed; when F=and, the transfer attribute can only be further transferred when all the previous transfers at the starting point are completed; when F=#, it means that the end point of the transfer attribute is unreachable.
[0068] More specifically, the category described by the grammatical variable C is the connection between entities. Production 407 describes the representation specification of the connection. The A at both ends of the production represents the entity, and the grammatical variable A in the middle represents the connection name.
[0069] Further, Figure 3 The example of a formal language for representing port entities and entity relationships in a certain security operation scenario is described. The entity inherent attributes describe the attributes of the port entity that are accessible, scannable, and firewall-configurable. The entity occasional attributes describe the port number of the port entity. The entity transfer attributes describe the accessible attributes of the port entity that can be transferred to the scannable attributes of the port entity, and the scannable attributes of the port entity can be transferred to the identification attributes of the service entity. In addition, the scannable attributes of the port entity can be prevented from being accessed by configuring the firewall of the port entity. The entity relationships include the relationships between attackers, network environments, ports, and service entities in the security operation environment.
[0070] An embodiment of the present application provides a computer-readable storage medium, which stores program code. When the program code is executed by a processor, the steps of the security operation element characterization method based on formal language are implemented as described above.
[0071] An embodiment of the present application provides a computer-readable storage medium storing program codes. When the program codes are executed by a processor, the steps of the method for determining the movement form of riverbed silt deposits in a mountain river as described above are implemented.
[0072] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application may adopt the form of a computer program product implemented in one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that include computer-usable program code.
[0073] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0074] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0075] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0076] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.
[0077] The memory may include non-permanent memory in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. The memory is an example of a computer-readable medium.
[0078] Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.
[0079] The above description is only an embodiment of the present application and is not intended to limit the protection scope of the present application. For those skilled in the art, the present application may have various modifications and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.
Claims
1. A security operation element representation method based on formal language, characterized in that: The specific steps include: Step S1: acquiring partial network entity configuration information of the target environment by performing a detection scan on the host of the target environment or inputting a configuration file; Step S2: Obtaining security operation entity configuration information in the target environment by inputting a configuration file of the security system in the target environment; Step S3: abstract the configurations obtained in S1 and S2, and generate a formal language-based representation of security operation entities according to the specification definition library; Step S4: for each entity representation generated in S3, based on the configuration information, generate a security operation entity attribute representation based on a formal language corresponding to the entity; Step S5: Generate a security operation entity connection representation based on a formal language according to the network topology information of the target environment; Step S6: Perform further specification checks on the representations generated by S3, S4, and S5 to ensure accuracy and usability.
2. According to the formal language-based security operation element characterization method of claim 1, it is characterized in that: The specific method of obtaining the configuration information of the security operation entity in the target environment by inputting the configuration file of the security system in the target environment is as follows: The real-time distribution results of hosts, ports and services in the obtained network environment are parsed to generate a data structure for storing relevant entity configuration information. The data structure for storing entity configuration information includes: entity type, surviving host IP, operating system type, open ports, service name, service version, and contained vulnerabilities.
3. According to the formal language-based security operation element characterization method of claim 1, it is characterized in that: The specific method of obtaining the configuration information of the security operation entity in the target environment by inputting the configuration file of the security system in the target environment is: Obtain additional static network entity information by parsing network configuration information in various formats to improve the accuracy and completeness of the information; A data structure for storing relevant entity configuration information is generated, wherein the data structure for storing relevant security operation entity configuration information includes: security operation entity type, deployment location, and scope data.
4. According to a formal language-based security operation element characterization method according to claim 1, it is characterized in that: The specific implementation method of generating a formal language-based representation of security operation entities according to the specification definition library is as follows: According to the data structure that stores the relevant entity configuration information, the entity name and entity type are extracted and the corresponding entity representation is generated based on the specification definition.
5. The security operation element characterization method based on formal language according to claim 1 is characterized in that: The specific implementation method of generating a formal language-based security operation entity attribute representation based on entity configuration information is as follows: By determining the type of entity, the entity's inherent attribute representation can be obtained through knowledge base matching; by parsing the data structure that stores the entity configuration information, the entity's occasional attribute values can be extracted for representation; finally, by retrieving the connections and attributes between entities, the entity's transfer attributes can be obtained.
6. The security operation element characterization method based on formal language according to claim 1 is characterized in that: The specific implementation method of generating security operation entity connection representation based on the target environment network topology is: Extract the relationship between hosts, ports and services in the network topology, and generate security operation entity relationship representations according to the specification definition.
7. A security operation element representation system based on formal language, characterized in that: The system includes: a memory and a processor, wherein the memory includes a program of a security operation element characterization method based on a formal language, and when the program of the security operation element characterization method based on a formal language is executed by the processor, the following steps are implemented: obtaining partial network entity configuration information of the target environment by performing a detection scan on the host of the target environment or inputting a configuration file; obtaining security operation entity configuration information in the target environment by inputting a configuration file of a security system in the target environment; abstracting the obtained configuration, and generating a security operation entity representation based on a formal language according to a specification definition library; for each generated entity representation, generating a security operation entity attribute representation based on a formal language corresponding to the entity based on the configuration information; generating a security operation entity connection representation based on a formal language according to the network topology information of the target environment; and performing further specification checks on the generated representation to ensure accuracy and availability.
8. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores program code, and when the program code is executed by a processor, the steps of the formal language-based security operation element characterization method according to any one of claims 1 to 6 are implemented.