Network security equipment vulnerability scanning method and device and electronic equipment
Through multi-dimensional data collection and comprehensive judgment, the problem of incomplete and inaccurate vulnerability scanning of network security equipment in existing technologies has been solved, more accurate detection target positioning and intelligent vulnerability scanning have been achieved, and the accuracy of network security management has been improved.
Patent Information
- Application Number
- CN202510931531.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-07
- Publication Date
- 2025-09-19
- Estimated Expiration
- 2045-07-07
AI Technical Summary
Existing technologies lack comprehensive consideration of the device environment and dynamic status when scanning network security device vulnerabilities, resulting in incomplete detection, inaccurate results, and weak targeting, making it difficult to effectively respond to complex network security threats.
Through multi-dimensional data collection and integration, a structured data set is formed. Differentiated signal strength thresholds are set based on the device's mobility status, the signal strength value is corrected, the device connection frequency and data interaction volume are obtained, and the importance of the network topology location is judged to generate a key information set for vulnerability detection.
It achieves more accurate detection target positioning, improves the accuracy of port anomaly judgment and adaptability to dynamic network environments, enhances the comprehensiveness and intelligence of vulnerability scanning, and provides accurate guidance for network security management.
Smart Images

Figure CN120675783A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of Internet of Things security technology, and in particular to a network security device vulnerability scanning method, device and electronic equipment. Background Art
[0002] The field of IoT security encompasses device security, network security, data security, authentication, and access control. Its core focus is protecting IoT devices, networks, and data from unauthorized access, malicious attacks, and data leaks. Device security ensures the hardware and software security of IoT devices, including device authentication and firmware updates. Network security protects communication networks, including network isolation and firewalls. Data security safeguards the generation, transmission, and storage of data, including encryption and backup. Authentication and access control ensure that only authorized users or devices can access the system, including user and device authentication and access control policies. The network security device vulnerability scanning method is based on a vulnerability database and involves scanning and detecting security vulnerabilities in designated remote or local computer systems, identifying exploitable vulnerabilities. This method targets network devices such as website systems, databases, ports, and application software. Specifically, it uses host scanning to determine whether the target network host is online; port scanning to identify open ports and services on the remote host; OS identification technology to determine the operating system; and vulnerability detection data collection technology to scan the network system database. Vulnerability scanning is accomplished through intelligent port identification, multi-service detection, and other methods, combined with automated database inspection and case discovery technology.
[0003] Existing technologies use vulnerability databases as the basis for single-dimensional detection in network security device vulnerability scanning, such as determining device status through host and port scanning, lacking comprehensive consideration of the device environment and dynamic status. For example, device screening does not take into account mobility status and environmental interference, which can easily lead to inaccurate signal strength judgments and misscreening of devices; key devices are determined based solely on data indicators such as connection frequency, without considering the importance of network topology location, making it difficult to accurately locate key devices; port detection uses a fixed threshold to determine response delay, which cannot adapt to dynamic network changes and is prone to missing or misjudging abnormal ports; device system type identification mainly relies on configuration parameter comparison, without combining log time series analysis, resulting in insufficient accuracy; vulnerability intelligence processing lacks multi-source intelligence weight adjustment and weighted aggregation, making it difficult to generate targeted detection information. These deficiencies lead to problems such as incomplete detection, inaccurate results, and weak targeting, making it difficult to effectively respond to complex network security threats. Potential vulnerabilities may not be discovered and handled in a timely manner, increasing security risks. Summary of the Invention
[0004] The main purpose of the present invention is to provide a network security device vulnerability scanning method, device and electronic device, which can effectively solve the problems involved in the above background technology.
[0005] To achieve the above object, the technical solution adopted by the present invention is: A method for scanning network security device vulnerabilities, comprising the following steps: S1. Data collection: collects device movement status, signal strength, and environmental interference data to form a basic device data set; S2. Device screening: Set a signal strength threshold based on the mobile status data in the device basic data set, compare the signal strength data with the threshold, call the environmental interference data for correction, and compare again. Obtain a preliminary screening list of target devices through the threshold comparison method; S3. Device confirmation: For the initial screening list of target devices, the connection frequency and data interaction volume are obtained, compared with the baseline values, and combined with the importance of the network topology location to obtain the final list of target devices; S4. Port status detection: Send a port detection request to the target device in the final list, record the response delay and calculate the delay gradient, use the adaptive algorithm to calculate the adaptive threshold, compare the response delay with the new threshold, and obtain the basic port status data; S5. Port status determination: Based on the basic port status data, the port traffic data is collected and segmented, the maximum value and the number of changes are counted, and the standard value is set and compared. The port abnormality is determined in combination with the response delay to obtain the port abnormality determination result; S6. Generate detection results, collect device configuration parameters, calculate correlation and match templates, analyze the operation log time series to obtain the device system type determination result, collect vulnerability intelligence data, set adjustment weights and perform weighted aggregation, combine device connection relationships and business importance, and generate a key information set for vulnerability detection.
[0006] Preferably, the data collection in S1 specifically includes: S1.1. Collect device movement status data, signal strength data, and environmental interference data from environmental monitoring nodes to obtain basic device data collection values; S1.2. Integrate the collected device movement status data, signal strength data, and environmental interference data to establish a basic device data set.
[0007] Preferably, the device screening in S2 specifically includes: S2.1. Set a signal strength threshold based on the mobile status data in the device basic data set, compare the signal strength data with the set threshold, and obtain an initial comparison signal strength value; S2.2. Call the environmental interference data in the device basic data set to correct the initial comparison signal strength value, compare the corrected signal strength value with the signal strength threshold again, and obtain the initial screening list of target devices through the threshold comparison method.
[0008] Preferably, the device confirmation in S3 specifically includes: S3.1. For devices in the initial screening list of target devices, obtain the connection frequency data between them and the core network devices, and obtain the device connection frequency data value; S3.2. Count the data interaction volume of the devices in the initial screening list of target devices per unit time to obtain the device data interaction volume value; S3.3. Compare the device connection frequency data value with the set connection frequency benchmark value, compare the device data interaction value with the set data interaction benchmark value, and combine the network topology location importance judgment to obtain the final list of target devices.
[0009] Preferably, the port status monitoring in S4 specifically includes: S4.1. Send a port probe request to the target device in the final list, record the port response delay, and obtain the port response delay record value; S4.2. Calculate the difference between adjacent response delays based on the recorded port response delay values to obtain a delay gradient calculation value; S4.3. Calculate an adaptive threshold value based on the delay gradient calculation value using an adaptive algorithm, compare the port response delay record value with the new threshold value, and obtain port basic status data.
[0010] Preferably, the port status determination in S5 specifically includes: S5.1. Based on the basic port status data, collect the traffic data of each port of the target device and divide it into time segments to obtain segmented port traffic data; S5.2. Count the maximum and minimum flow rates, and the number of changes in each time period of the segmented port flow data to obtain the maximum and minimum flow rate statistics; S5.3. Set the normal range standard values for the flow rate change rate and the number of changes, calculate the flow rate change rate and compare it with the standard value, count the number of changes and compare it with the standard value, and determine whether the port is abnormal in combination with the port response delay record value to obtain the port abnormality determination result.
[0011] Preferably, the generation of the detection result in S6 specifically includes: S6.1. Collect device configuration parameters from the final list of target devices, count parameter combinations of a large number of devices of known system types, calculate the correlation between the parameters, and obtain a calculated value of the device parameter correlation; S6.2. Match the calculated device parameter correlation value with a parameter correlation template of a known system type, obtain the target device operation log, extract key event information to construct a time series sequence, and obtain the device log time series sequence value; S6.3. Analyze the frequency and characteristics of events in the device log time series values and compare them with typical log time series patterns of known system types to determine the device system type. S6.4. Collect vulnerability intelligence from multiple sources, obtain data on intelligence release time, the credibility of the issuing organization, and the number of intelligence verifications, set time weights, credibility weights, and verification weights, calculate the initial weights for each intelligence source, and obtain the calculated initial weight values for the intelligence sources; S6.5. Adjust the initial weight calculation values of intelligence sources based on the device system type determination results and port anomaly determination results. Aggregate intelligence from different sources according to the adjusted weights to obtain vulnerability intelligence assessment data. S6.6. Analyze the scope of system functions and the amount of data involved in each vulnerability in the vulnerability intelligence assessment data, and generate a key information set for vulnerability detection based on the device's connection relationship in the IoT network and the importance of the services it carries.
[0012] A network security device vulnerability scanning device, the device is used to perform the network security device vulnerability scanning method described above, and the device includes the following modules: A data acquisition module, used to execute step S1; Equipment initial screening module, used to perform S2 step; The device confirmation module is used to execute step S3; A port detection module is used to execute step S4; A port determination module is used to execute step S5; Type analysis and intelligence processing module, used to execute step S6.
[0013] An electronic device includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the program, the processor executes the operation steps corresponding to each module in the network security device vulnerability scanning device.
[0014] Compared with the prior art, the present invention has the following beneficial effects: 1. This invention integrates device mobility status, signal strength, and environmental interference data into a structured data set through multi-dimensional data collection and integration, providing a standardized data basis for subsequent analysis. This solves the problem of single data collection in existing technologies and lays a comprehensive data support for vulnerability scanning.
[0015] 2. The present invention sets differentiated signal strength thresholds based on the mobility status of the device, corrects the signal strength value in combination with environmental interference data, obtains the device connection frequency and data interaction volume and compares them with the benchmark value, and then combines the importance judgment of the network topology location. This not only improves the accuracy of the initial screening of target devices, but also can accurately locate key detection devices, changing the limitations of existing equipment screening and key determination, and achieving more accurate detection target positioning.
[0016] 3. The present invention sends a port detection request to record the response delay, calculates the delay gradient and uses an adaptive algorithm to calculate the threshold to dynamically judge the basic status of the port. At the same time, it collects the port traffic data segmented statistics of the maximum value and the number of changes, and combines the response delay to comprehensively judge the port abnormality. It breaks through the disadvantages of the fixed threshold in the existing port detection technology, improves the accuracy of port abnormality judgment and adaptability to the dynamic network environment.
[0017] 4. The present invention collects device configuration parameters to calculate correlation matching templates, analyzes log time series to determine system types, collects multi-source vulnerability intelligence and adjusts weighted aggregation according to system types and port abnormality results, and generates key vulnerability detection information based on device connection relationships and business importance. It realizes the intelligence and pertinence from device system type identification to vulnerability intelligence processing, enhances the comprehensiveness and intelligence level of vulnerability scanning, and provides precise guidance for network security management. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] Figure 1 It is the overall workflow diagram of the present invention; Figure 2 It is a data collection flow chart of the present invention; Figure 3 A flow chart for screening the equipment of the present invention; Figure 4 Validation flow chart for the device of the present invention; Figure 5 This is a flow chart of port status detection of the present invention; Figure 6 It is a flow chart of port status determination of the present invention; Figure 7 A flow chart is generated for the detection results of the present invention. DETAILED DESCRIPTION
[0019] In order to make the technical means, creative features, objectives and effects achieved by the present invention easier to understand, the present invention is further described below in conjunction with specific implementation methods.
[0020] The present invention mainly relates to a network security device vulnerability scanning method, referring to Figure 1 , this method specifically comprises the following steps: S1. Collect device movement status, signal strength, and environmental interference data to form a basic device data set; S2. Set a signal strength threshold based on the mobile status data of the device basic data set, compare the signal strength data with the threshold, call the environmental interference data for correction and compare again, and obtain a preliminary screening list of target devices through the threshold comparison method; S3. For the initial screening list of target devices, obtain the connection frequency and data interaction volume, compare them with the benchmark values, and combine them with the importance judgment of the network topology location to obtain the final list of target devices; S4. Send a port detection request to the target device in the final list, record the response delay and calculate the delay gradient, use the adaptive algorithm to calculate the adaptive threshold, compare the response delay with the new threshold, and obtain the basic port status data; S5. Based on the basic status data of the port, collect and segment the port traffic data, count the maximum value and the number of changes, set a standard value and compare it, and determine the port abnormality in combination with the response delay to obtain the port abnormality determination result; S6. Collect device configuration parameters, calculate correlation and match templates, analyze the operation log time series to obtain the device system type determination result, collect vulnerability intelligence data, set adjustment weights and perform weighted aggregation, combine device connection relationships and business importance, and generate a key information set for vulnerability detection.
[0021] Specifically, the present invention also relates to a network security device vulnerability scanning device, which includes the following modules: A data acquisition module, used to execute step S1; Equipment initial screening module, used to perform S2 step; The device confirmation module is used to execute step S3; A port detection module is used to execute step S4; A port determination module is used to execute step S5; Type analysis and intelligence processing module, used to execute step S6.
[0022] Based on the above-mentioned network security device vulnerability scanning device and scanning method, they are further disclosed below in conjunction with specific implementation methods.
[0023] Example 1, as Figure 2 As shown, this embodiment realizes the collection of device-related data based on IoT sensors, signal receiving modules and environmental monitoring nodes; In the technical framework of this solution, data collection is the basis for all subsequent processing; Specifically, during the data collection process, the IoT sensors are used to collect real-time data on the movement status of the device, the signal receiving module is used to obtain the signal strength data of the device, and the environmental interference data is collected through the environmental monitoring node; The collected data are aligned by timestamp and stored as a structured dataset.
[0024] In an industrial park application scenario, at 10:00:00 on May 22, 2025, the system starts the data collection process. The GPS sensor and accelerometer deployed on the mobile inspection robot collect the robot's coordinates (120.12, 30.15) in real time, with a moving speed of 0.5 m / s, completing the acquisition of the device's mobile status data. At the same time, the signal receiving module collected the signal strength of a network security device in the park. Over the next 10 minutes, it recorded signal strength values such as -65dBm, -70dBm, and -68dBm. The environmental monitoring node (radio monitoring equipment) simultaneously detected that the interference intensity in the 2.4 GHz frequency band in the area was 80 μV / m.
[0025] After data collection is completed, the system aligns the data based on the timestamps generated, integrating the three types of data: device movement status, signal strength, and environmental interference into a structured data set; Construct a table containing the fields of "time-movement coordinates-signal strength-interference strength", such as generating the data record: 2025-05-22 10:00:00, (120.12, 30.15), -68dBm, 75μV / m, and store it in the system database to lay a standardized data foundation for subsequent device screening and analysis.
[0026] Example 2, as Figure 3 As shown, this embodiment performs a preliminary screening of network security devices based on the data collected in the first embodiment; Specifically, a signal strength threshold is set according to the mobile state of the device, and the collected signal strength data is compared with the threshold; Then, the environmental interference data is called to correct the signal strength value, and the corrected signal strength value is compared with the threshold again, and the devices that meet the conditions are included in the initial screening list.
[0027] Based on the data collected in Example 1, the system sets differentiated signal strength thresholds according to the device's mobility status: When the device is in a stationary state, the threshold is set to -80dBm; When the device is moving, the threshold is set to -90dBm considering that the signal fluctuation is greater.
[0028] For example, a network security device in a static state may detect a signal strength of -75dBm. This is compared to the static state threshold of -80dBm. Since -75dBm > -80dBm, the device is initially judged to be normal. For a device in a mobile state, the collected signal strength is -95dBm. Compared with the mobile state threshold of -90dBm, -95dBm is less than -90dBm, and the signal is initially judged to be abnormal.
[0029] For mobile devices initially identified as having abnormal signals, the system uses environmental interference data to make corrections. When the environmental interference intensity is greater than 70μV / m, the system uses the formula "corrected signal strength = collected value + environmental interference compensation coefficient" (compensation coefficient is +5dBm) for calculation. For example, if the interference intensity of the mobile device mentioned above is 80μV / m, the corrected signal strength is -95dBm+5dBm=-90dBm. The corrected value is equal to the mobile state threshold. Ultimately, the device signal is determined to be normal and is included in the preliminary screening list, thereby preliminarily defining the target device range for subsequent processing.
[0030] Example 3, as Figure 4 As shown, this embodiment further determines the target devices for key inspection based on the initial screening results of the second embodiment; Specifically, we first count the connection frequency between the device and the core switch, calculate the data interaction volume of the device per unit time, compare the connection frequency and data interaction volume with the benchmark value, and judge the importance of the device based on the network topology location. The devices that meet the importance criteria will be included in the final list.
[0031] Based on the initial screening in Example 2, a network security device was monitored through the network management system. Within 1 hour, the device was connected to the core switch 15 times. At the same time, the data interaction volume within 5 minutes was calculated to be 80MB. After conversion, the interaction volume per unit time reached 960MB / h.
[0032] The system sets the connection frequency benchmark value to 10 times / h and the data exchange volume benchmark value to 500MB / h. Comparing the monitoring data with the benchmark values, the device's connection frequency of 15 times / h is greater than 10 times / h, and the data exchange volume of 960MB / h is greater than 500MB / h. Based on the data indicators, the device is preliminarily determined to be a critical device. Further combined with the network topology location, if the device is located at the aggregation layer and its importance level is rated as "high", it will be directly included in the final target device list; if the device is located at the access layer and its importance level is "medium", it is necessary to further verify it in combination with other factors to decide whether to include it, so as to accurately locate the key devices for subsequent vulnerability scans.
[0033] Example 4, as Figure 5 As shown, this embodiment obtains basic port status information based on determining the target device in embodiment three; Specifically, a request is sent to the target device port and the response delay is recorded. The difference between adjacent response delays is calculated to obtain the delay gradient. An adaptive algorithm is used to calculate the threshold, and the response delay is compared with the threshold to mark abnormal delays.
[0034] Taking port 80 of the target device determined in Example 3 as an example, the system sends a TCPSYN request to it and records the response delay of each request in turn. The delays obtained from five consecutive detections are 20ms, 22ms, 18ms, 25ms, and 21ms respectively.
[0035] By calculating the difference between adjacent response delays, the delay gradient is obtained, such as 22-20=2ms, 18-22=-4ms, 25-18=7ms, 21-25=-4ms, thus forming a gradient sequence [2, -4, 7, -4].
[0036] The threshold is calculated using the moving average method. For the first three delays of 20 ms, 22 ms, and 18 ms, the average value is (20 + 22 + 18) ÷ 3 = 20 ms. The standard deviation is calculated using the standard deviation formula to obtain a standard deviation of 1.63 ms. The threshold is then calculated as 20 + 2 × 1.63 = 23.26 ms.
[0037] Each response delay is compared with the threshold. If the fourth delay is 25ms and greater than 23.26ms, it is marked as "abnormal delay." If the fifth delay is 21ms and less than 23.26ms, it is marked as "normal." This completes the preliminary detection of the basic status of the port.
[0038] Example 5, as Figure 6 As shown, this embodiment comprehensively determines the port status based on the basic port status obtained in the fourth embodiment; Specifically, the port traffic is segmented by time; the maximum, minimum and change times of each segment traffic are counted; the traffic characteristic value is compared with the standard value, and combined with the response delay abnormality record, it is determined whether the port is abnormal.
[0039] Based on the basic port status obtained in Example 4, the port traffic is segmented into time periods of 5 minutes; For example, a port has traffic data of 10MB, 15MB, 8MB, 20MB, and 12MB. Analyzing this traffic data reveals that the maximum value is 20MB, the minimum value is 8MB, and the number of traffic changes is 4 (adjacent value changes are counted). The system sets a standard value for traffic change rate of ≤30% and a standard value for change frequency of ≤3 times / 5 minutes. The calculated maximum change rate for this traffic segment is (20-8) ÷ 8 = 150%, which is much greater than 30%. Furthermore, the number of changes is greater than 3 times (4). Combined with the abnormal response delay recorded in Example 4, this port is considered "abnormal," providing a reliable basis for subsequent vulnerability analysis.
[0040] Example 6: Figure 7 As shown, this embodiment generates key vulnerability detection information based on the port determination in the fifth embodiment; Specifically, it collects device configuration parameters; analyzes log time series; identifies device system types based on configuration parameter correlation and log matching; collects multi-source vulnerability intelligence; adjusts the weight of each source intelligence based on the device system type; weights and aggregates vulnerability intelligence, and generates key vulnerability detection information based on the importance of the device business.
[0041] Based on Example 5, the configuration parameters of a device are collected, and "Intel i5-1135G7 / 8GB / Windows 10 IoT" is obtained. This is compared with the known system template, and the correlation with the Windows system template is calculated to be 92%; At the same time, we analyzed the device log information and extracted the time series of key events, such as "system startup-service loading-data synchronization". We found that the frequency of their occurrence matched the typical Windows pattern at 85%. We comprehensively determined that the device was running the Windows IoT system.
[0042] Multi-source vulnerability intelligence collected: Intelligence A: released on May 20, 2025 (time weight 0.3), the issuing agency's credibility is 90 (credibility weight 0.5), the number of verifications is 50 (verification weight 0.2), and the initial weight is 0.3×(3 / 3)+0.5×(90 / 100)+0.2×(50 / 100)=0.3+0.45+0.1=0.85; Intelligence B: released on May 15, 2025 (time weight 0.2), credibility is 80 (0.4), verification times are 30 (0.06), initial weight is 0.2 + 0.4 + 0.06 = 0.66; Intelligence C: Release time 2025-05-22 (time weight 0.1), credibility 70 (0.3), verification times 20 (0.04), initial weight = 0.1 + 0.3 + 0.04 = 0.44; Since the device system type is Windows, the weight of intelligence A for Windows vulnerabilities is increased to 0.9, the weight of intelligence B remains at 0.66, and the weight of intelligence C for common vulnerabilities remains at 0.44.
[0043] The final vulnerability risk value is calculated using a weighted aggregation method. The final risk value = 0.9×8.0 (A) + 0.66×6.0 (B) + 0.44×5.0 (C) = 7.2 + 3.96 + 2.2 = 13.36.
[0044] Combined with the fact that the device is connected to the core switch and has high business importance, key information of "high-priority vulnerability detection tasks" is ultimately generated, providing network security managers with accurate vulnerability handling guidance.
[0045] The present invention also discloses an electronic device, comprising a memory and a processor, wherein the memory stores a computer program that can be run on the processor, and when the processor runs the program, the processor executes the operation steps corresponding to each module in the above-mentioned network security device vulnerability scanning device; Specifically, the processor first calls the data acquisition module to obtain real-time data from IoT sensors, signal receiving modules, and environmental monitoring nodes, and stores this data in the memory; The device initial screening module and the device confirmation module are triggered in sequence to screen the data in the memory, determine the final target device list, and store the list back to the memory; Then, the port detection module and the port determination module detect and determine the status of the target device, generate port status data, and update it to the memory again; Finally, the type analysis module and intelligence assessment module perform device system type identification and vulnerability intelligence aggregation analysis based on the data stored in the memory, generate key vulnerability detection information, and output it to the management interface for security managers to view and process.
[0046] The basic principles, main features, and advantages of the present invention are shown and described above. Those skilled in the art should understand that the present invention is not limited to the above embodiments. The above embodiments and descriptions are merely illustrative of the principles of the present invention. Various changes and modifications may be made to the present invention without departing from the spirit and scope of the present invention. Such changes and modifications are intended to fall within the scope of the present invention. The scope of protection claimed in the present invention is defined by the appended claims and their equivalents.
Claims
1. A method for scanning network security device vulnerabilities, characterized in that: The following steps are involved: S1. Data collection: collects device movement status, signal strength, and environmental interference data to form a basic device data set; S2. Device screening: Set a signal strength threshold based on the mobile status data in the device basic data set, compare the signal strength data with the threshold, call the environmental interference data for correction, and compare again. Obtain a preliminary screening list of target devices through the threshold comparison method; S3. Device confirmation: For the initial screening list of target devices, the connection frequency and data interaction volume are obtained, compared with the baseline values, and combined with the importance of the network topology location to obtain the final list of target devices; S4. Port status detection: Send a port detection request to the target device in the final list, record the response delay and calculate the delay gradient, use the adaptive algorithm to calculate the adaptive threshold, compare the response delay with the new threshold, and obtain the basic port status data; S5. Port status determination: Based on the basic port status data, the port traffic data is collected and segmented, the maximum value and the number of changes are counted, and the standard value is set and compared. The port abnormality is determined in combination with the response delay to obtain the port abnormality determination result; S6. Generate detection results, collect device configuration parameters, calculate correlation and match templates, analyze the operation log time series to obtain the device system type determination result, collect vulnerability intelligence data, set adjustment weights and perform weighted aggregation, combine device connection relationships and business importance, and generate a key information set for vulnerability detection.
2. A network security device vulnerability scanning method according to claim 1, characterized in that: The data collection described in S1 specifically includes: S1.
1. Collect device movement status data, signal strength data, and environmental interference data from environmental monitoring nodes to obtain basic device data collection values; S1.
2. Integrate the collected device movement status data, signal strength data, and environmental interference data to establish a basic device data set.
3. The method for scanning network security device vulnerabilities according to claim 1, wherein: The device screening described in S2 specifically includes: S2.
1. Set a signal strength threshold based on the mobile status data in the device basic data set, compare the signal strength data with the set threshold, and obtain an initial comparison signal strength value; S2.
2. Call the environmental interference data in the device basic data set to correct the initial comparison signal strength value, compare the corrected signal strength value with the signal strength threshold again, and obtain the initial screening list of target devices through the threshold comparison method.
4. The method for scanning network security device vulnerabilities according to claim 1, wherein: The device confirmation in S3 specifically includes: S3.
1. For devices in the initial screening list of target devices, obtain the connection frequency data between them and the core network devices, and obtain the device connection frequency data value; S3.
2. Count the data interaction volume of the devices in the initial screening list of target devices per unit time to obtain the device data interaction volume value; S3.
3. Compare the device connection frequency data value with the set connection frequency benchmark value, compare the device data interaction value with the set data interaction benchmark value, and combine the network topology location importance judgment to obtain the final list of target devices.
5. The method for scanning network security device vulnerabilities according to claim 1, wherein: The port status monitoring in S4 specifically includes: S4.
1. Send a port probe request to the target device in the final list, record the port response delay, and obtain the port response delay record value; S4.
2. Calculate the difference between adjacent response delays based on the recorded port response delay values to obtain a delay gradient calculation value; S4.
3. Calculate an adaptive threshold value based on the delay gradient calculation value using an adaptive algorithm, compare the port response delay record value with the new threshold value, and obtain port basic status data.
6. A network security device vulnerability scanning method according to claim 1, characterized in that: The port status determination in S5 specifically includes: S5.
1. Based on the basic port status data, collect the traffic data of each port of the target device and divide it into time segments to obtain segmented port traffic data; S5.
2. Count the maximum and minimum flow rates, and the number of changes in each time period of the segmented port flow data to obtain the maximum and minimum flow rate statistics; S5.
3. Set the normal range standard values for the flow rate change rate and the number of changes, calculate the flow rate change rate and compare it with the standard value, count the number of changes and compare it with the standard value, and determine whether the port is abnormal in combination with the port response delay record value to obtain the port abnormality determination result.
7. The method for scanning network security device vulnerabilities according to claim 1, wherein: The generation of the detection result in S6 specifically includes: S6.
1. Collect device configuration parameters from the final list of target devices, count parameter combinations of a large number of devices of known system types, calculate the correlation between the parameters, and obtain a calculated value of the device parameter correlation; S6.
2. Match the calculated device parameter correlation value with a parameter correlation template of a known system type, obtain the target device operation log, extract key event information to construct a time series sequence, and obtain the device log time series sequence value; S6.
3. Analyze the frequency and characteristics of events in the device log time series values and compare them with typical log time series patterns of known system types to determine the device system type. S6.
4. Collect vulnerability intelligence from multiple sources, obtain data on intelligence release time, the credibility of the issuing organization, and the number of intelligence verifications, set time weights, credibility weights, and verification weights, calculate the initial weights for each intelligence source, and obtain the calculated initial weight values for the intelligence sources; S6.
5. Adjust the initial weight calculation values of intelligence sources based on the device system type determination results and port anomaly determination results. Aggregate intelligence from different sources according to the adjusted weights to obtain vulnerability intelligence assessment data. S6.
6. Analyze the scope of system functions and the amount of data involved in each vulnerability in the vulnerability intelligence assessment data, and generate a key information set for vulnerability detection based on the device's connection relationship in the IoT network and the importance of the services it carries.
8. A network security device vulnerability scanning device, the device being used to execute the network security device vulnerability scanning method according to claim 1, characterized in that: The device includes: a data acquisition module for executing step S1; an equipment initial screening module for executing step S2; an equipment confirmation module for executing step S3; a port detection module for executing step S4; a port determination module for executing step S5; and a type analysis and intelligence processing module for executing step S6.
9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor runs the program, the processor executes the operation steps corresponding to each module in the network security device vulnerability scanning device as claimed in claim 8.
Citation Information
Patent Citations
Network system vulnerability scanning method
CN116668079A
Network security vulnerability position detection method and system
CN117614741A
Network security detection method and system
CN118101250A
Computer network security data transmission method and device
CN119922011A
System and method for network vulnerability detection and reporting
US20030217039A1