Network equipment vulnerability assessment method

By performing cross-point statistics and risk assessment on network paths within network devices and establishing a vulnerability association risk prediction model, we can solve the problems of high cost and low efficiency in traditional network device vulnerability assessment and achieve more rigorous and efficient vulnerability detection.

CN120768705AActive Publication Date: 2025-10-10GRANPECT
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202511295132.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-11
Publication Date
2025-10-10
Estimated Expiration
2045-09-11

AI Technical Summary

Technical Problem

Traditional network equipment vulnerability assessment methods do not conduct prior vulnerability risk assessment, resulting in high vulnerability investigation costs, waste of resources, and inaccurate detection, which reduces the rigor and efficiency of the assessment work.

Method used

By counting the intersection points of network paths within network devices, evaluating the number of intersection points, logical distance and risk density, establishing a vulnerability association risk prediction model, and performing vulnerability simulation attack scans to detect vulnerability risks.

Benefits of technology

It enhances the rigor and organization of network equipment vulnerability assessment, refines the risk assessment level, avoids resource waste and inefficiency, and provides targeted response measures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120768705A_ABST
    Figure CN120768705A_ABST
Patent Text Reader

Abstract

The invention discloses a network equipment vulnerability assessment method, and relates to the technical field of network equipment vulnerability assessment, and the method comprises the steps: selecting a target cross path, an auxiliary measurement path I and an auxiliary measurement path II from network paths with cross points, and if the target cross path and the auxiliary measurement path I and the auxiliary measurement path II have partial cross point coincidence, determining that the target cross path and the auxiliary measurement path I and the auxiliary measurement path II are overlapped; if the target cross path and the auxiliary measurement path II have partial cross sink coincidence, and the auxiliary measurement path I and the auxiliary measurement path II have partial cross sink coincidence, performing statistics on second to-be-measured risk feature data to which the cross sink belongs under the condition; and if the target cross path and the auxiliary measurement path I or the auxiliary measurement path II have cross point coincidence and the target cross path, the auxiliary measurement path I and the auxiliary measurement path II are in a complete non-coincidence relation, performing statistics on third to-be-measured risk feature data, and performing comprehensive vulnerability estimation value evaluation on the to-be-measured network path according to the three to-be-measured risk feature data. According to the invention, the vulnerability mining accuracy can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of network device vulnerability assessment, and in particular to a network device vulnerability assessment method. Background Art

[0002] With the widespread adoption of technologies like cloud computing, the Internet of Things (IoT), and 5G, businesses and individuals are relying on network services at an exponential rate. The integration of massive numbers of devices creates a vast, heterogeneous network environment (e.g., routers, switches, firewalls, etc.), dramatically expanding the attack surface. For example, supply chain attacks can penetrate edge devices and laterally migrate to core systems, causing a chain reaction.

[0003] In traditional technologies, the assessment of network device vulnerabilities often directly adopts attack simulation processing steps to detect vulnerabilities without conducting prior vulnerability risk assessment. This can easily increase the cost of vulnerability detection and waste resources. It also fails to accurately and effectively detect actual risk points, reducing the rigor and efficiency of the entire network device vulnerability assessment work. Summary of the Invention

[0004] In order to overcome the above-mentioned deficiencies of the prior art, the present application provides a network device vulnerability assessment method.

[0005] This application provides a network device vulnerability assessment method, the method comprising: Step S1: Select a target cross-path, auxiliary test path 1, and auxiliary test path 2 from network paths with cross-junctions within the network device. If the target cross-path has some overlap with auxiliary test path 1 and auxiliary test path 2, output preprocessing condition 1. Based on preprocessing condition 1, evaluate the correlation impact value between the number of cross-junctions on the target cross-path and the vulnerability risk, and output vulnerability risk estimation value 1. Step S2: Calculate the logical distance between two adjacent intersections in pre-processing case 1 to obtain a logical distance of intersection risk, and calculate the ratio between the number of paths distributed and the area of ​​each intersection in pre-processing case 1 to obtain a concentration of intersection risk. If the auxiliary test path 1 still contains non-overlapping intersections excluding the conditions of pre-processing case 1, output pre-processing case 2. Calculate the first risk feature data to be tested based on pre-processing case 2, vulnerability risk estimation 1, logical distance of intersection risk, and concentration of intersection risk. Step S3: If there is some overlap between the target cross-path and the auxiliary test path 2, and there is some overlap between the auxiliary test path 1 and the auxiliary test path 2, then the second risk feature data to be tested belonging to the intersection convergence is counted; if there is some overlap between the target cross-path and the auxiliary test path 1 or the auxiliary test path 2, and the target cross-path, the auxiliary test path 1, and the auxiliary test path 2 are completely non-overlapping, then the third risk feature data to be tested is counted; based on the three risk feature data to be tested, the comprehensive vulnerability estimate value of the network path to be tested is evaluated, and the vulnerability simulation attack scan of the corresponding position is performed to output the vulnerability exploitation detection result.

[0006] Preferably, the network paths in the network device are detected and the network paths to be tested are output. If there are cross junctions in the network paths to be tested, the network path with the largest number of cross junctions is selected from the network paths to be tested and the target cross junction is output. Auxiliary test path 1 and auxiliary test path 2 that have an intersection relationship with the target cross path are extracted from the network path to be tested, the auxiliary test path 1 is a network path that has an intersection point with the target cross path, and the auxiliary test path 2 is a network path excluding the auxiliary test path 1 and has an intersection point with the target cross path.

[0007] Preferably, if the target cross path partially overlaps with the auxiliary test path 1 and the auxiliary test path 2 at intersection points, a preprocessing condition 1 is output, in which the target cross path partially overlaps with the auxiliary test path, and the target cross path does not overlap with the auxiliary test path 2 at all; According to the first preprocessing condition, the number of intersection points on the target intersection path is counted to obtain the number of target intersection points; Obtain historical vulnerability detection data indicating that encryption configurations of network devices have been weakened and degraded over historical periods, extract the number of historical path intersection points and historical vulnerability risk values ​​from the historical vulnerability detection data, perform statistical analysis on risk correlation coefficients between the number of historical path intersection points and the historical vulnerability risk values, and output a risk correlation factor; Multiply the target number of sinks by the risk correlation factor to obtain an estimated vulnerability risk value of a configuration being weakened and degraded, and output a vulnerability risk estimate of one.

[0008] Preferably, the logical distances between two adjacent intersection nodes in the preprocessing case 1 are counted to output the intersection node distribution logical distance, and all logical distance values ​​in the intersection node distribution logical distance are averaged to output the intersection node risk logical distance; The path distribution area of ​​each intersection in the preprocessing case 1 is counted to obtain the path coverage area, and the number of path releases within the path coverage area is counted to obtain the number of path releases. The ratio of the path distribution number and the path coverage area is calculated to obtain the intersection risk density.

[0009] Preferably, if the auxiliary measurement path 1 still has non-coincident intersection points excluding the preprocessing condition 1, the preprocessing condition 2 is output, the path length of the intersection points in the preprocessing condition 2 to the starting data output terminal is counted, and the distance value to be measured 1 is output; The path lengths from the intersection point on the target intersection path to the starting data output terminal are counted, and the shortest path length is extracted. The second distance value to be measured is output, and the ratio of the second distance value to be measured and the first distance value to be measured is calculated to obtain the intersection point risk association distance ratio 1; The sink point risk logic distance, sink point risk density and sink point risk association distance ratio are combined into a group of first risk feature data to be measured.

[0010] Preferably, if the target cross-path and the auxiliary test path 2 partially overlap at their intersection points, the auxiliary test path 1 and the auxiliary test path 2 partially overlap at their intersection points, and the target cross-path, the auxiliary test path 1, and the auxiliary test path 2 are completely non-overlapping, then the path lengths from the overlapping intersection points of the auxiliary test path 1 and the auxiliary test path 2 to the starting data output terminal are counted respectively, and the third distance value to be measured is output; Calculate the ratio of the third distance value to be measured to the first distance value to be measured to obtain a second sink point risk association distance ratio, and combine the sink point risk logical distance and the second sink point risk association distance ratio to form the second risk feature data to be measured; If the target cross-path coincides with the auxiliary test path 1 or auxiliary test path 2 at a cross-point, and the target cross-path, auxiliary test path 1, and auxiliary test path 2 do not overlap with each other, the cross-point risk logic distance is used as the third risk feature data to be measured; The first risk feature data to be measured, the second risk feature data to be measured and the third risk feature data to be measured are combined into pre-processed comprehensive risk feature data.

[0011] Preferably, based on the risk characteristic data to be tested, historical risk characteristic data and corresponding historical comprehensive associated risk values ​​are extracted from historical vulnerability detection data, and a vulnerability associated risk prediction model is established based on the historical risk characteristic data and the corresponding historical comprehensive associated risk values; Input the pre-processed comprehensive risk feature data into the vulnerability association risk prediction model for testing to obtain vulnerability risk estimation 2; Summing the vulnerability risk estimation value 1 and the vulnerability risk estimation value 2 to obtain a vulnerability estimation value of the target cross-path, and obtaining a comprehensive vulnerability estimation value of the network path with the cross-junction in the network path to be tested based on the vulnerability estimation value; Based on the comprehensive vulnerability estimation value, a vulnerability simulation attack scan is performed on the corresponding location, and a vulnerability exploitation detection result is output.

[0012] Compared with the prior art, the present invention has the following characteristics and beneficial effects: By counting whether there are cross-convergence points in the network paths within the network device, it is found that the existence of cross-convergence points between network paths will cause conflicts between encryption configurations, which will in turn weaken and degrade the encryption configuration, making it easier for external attackers to crack encrypted information. Different statistics and analysis are performed on the characteristic data of the diversity of influencing factors that induce vulnerability risk values ​​in different situations of cross-convergence points between network paths. The first situation is that the target cross-path has some overlap with the auxiliary test path one and auxiliary test path two at some cross-convergence points, where the target cross-path has some overlap with the auxiliary test path, and the target cross-path has no overlap with the auxiliary test path two. In this case, the degree of induction of vulnerability risk value is the greatest (that is, the relevant influencing factors are the greatest). The second situation is that the target cross-path has some overlap with the auxiliary test path two at some cross-convergence points. There is some overlap in the intersection points between auxiliary test path one and auxiliary test path two, and the target intersection path, auxiliary test path one and auxiliary test path two are completely non-overlapping. In this case, the degree of induction of vulnerability risk value is second. The third case is that there is overlap in the intersection points between the target cross path and auxiliary test path one and auxiliary test path two, and the target cross path, auxiliary test path one and auxiliary test path two are completely non-overlapping. In this case, the degree of induction of vulnerability risk value is the smallest. By conducting a step-by-step analysis of differentiated situations, the rigor and orderliness of the vulnerability assessment processing of network equipment vulnerabilities are enhanced, and the severity level of the vulnerability risk assessment value is further refined to facilitate subsequent targeted differentiated response measures, avoiding the waste of resources and inefficiency caused by direct vulnerability simulation attack scanning without prior vulnerability assessment prediction in traditional technologies. BRIEF DESCRIPTION OF THE DRAWINGS

[0013] Figure 1 This is a flowchart of a method for assessing network device vulnerabilities, as mainly embodied in this embodiment. DETAILED DESCRIPTION

[0014] The present invention is further described in detail below with reference to the following examples.

[0015] Reference Figure 1 , a network device vulnerability assessment method, the method comprising the following steps: Step S1: Select the target cross-path, auxiliary test path 1, and auxiliary test path 2 from the network paths with cross-junctions within the network device. If the target cross-path has some overlapping cross-junctions with auxiliary test path 1 and auxiliary test path 2, output preprocessing situation 1. Based on preprocessing situation 1, evaluate the correlation impact value between the number of cross-junctions on the target cross-path and the vulnerability risk, and output vulnerability risk valuation 1.

[0016] Step S2, the logical distance between the two adjacent intersections in the pre-processing case one is counted to obtain the intersection risk logical distance, and the ratio between the path distribution number and the area of each intersection in the pre-processing case one is counted to obtain the intersection risk density, if the auxiliary measurement path one still exists the non-coincidence intersection under the condition of pre-processing case one, output the pre-processing case two, according to the pre-processing case two, the vulnerability risk evaluation one, the intersection risk logical distance, the intersection risk density, the first to be measured risk characteristic data is counted.

[0017] Step S3, if the target intersection path and the auxiliary measurement path two exist part of the intersection intersection, and the auxiliary measurement path one and the auxiliary measurement path two exist part of the intersection intersection, the second to be measured risk characteristic data of the intersection intersection is counted, if the target intersection path and the auxiliary measurement path one or the auxiliary measurement path two exist intersection intersection, and the target intersection path, the auxiliary measurement path one, the auxiliary measurement path two are in complete non-coincidence relationship, then the third to be measured risk characteristic data is counted, according to three kinds of to be measured risk characteristic data, the comprehensive vulnerability evaluation of the to be measured network path is evaluated, and the corresponding position of the vulnerability simulation attack scanning is output after the vulnerability detection result.

[0018] Specifically, by counting whether there are cross-convergence points in the network paths within the network device, because the existence of cross-convergence points between network paths will cause conflicts between encryption configurations, which will in turn lead to the weakening and degradation of encryption configurations, making it easier for external attackers to crack encrypted information, the diversity of influencing factor characteristic data that induce vulnerability risk values ​​under different cross-convergence situations between network paths is statistically analyzed and analyzed, among which the different cross-convergence situations are: the first situation is that the target cross-path has some overlap with the auxiliary test path one and auxiliary test path two at the cross-convergence points, wherein the target cross-path has a partial overlap with the auxiliary test path, and the target cross-path has no overlap with the auxiliary test path two. In this case, the degree of induction of the vulnerability risk value is the greatest (that is, the relevant influencing factor is the greatest), and the second situation is that the target cross-path has some overlap with the auxiliary test path two. The convergence points overlap, and there is partial overlap of intersection convergence points between auxiliary test path one and auxiliary test path two, and the target cross path, auxiliary test path one and auxiliary test path two are in a completely non-overlapping relationship with each other. In this case, the degree of induction of vulnerability risk value is second only to that in the third case. The target cross path has intersection convergence points overlap with auxiliary test path one and auxiliary test path two, and the target cross path, auxiliary test path one and auxiliary test path two are in a completely non-overlapping relationship with each other. In this case, the degree of induction of vulnerability risk value is the smallest. By conducting a step-by-step analysis of differentiated situations, the rigor and orderliness of the vulnerability assessment processing steps of network equipment are enhanced, and the severity level of the vulnerability risk assessment value is further refined, so as to facilitate the subsequent targeted differentiated response measures, avoiding the waste of resources and inefficiency caused by direct vulnerability simulation attack scanning without prior vulnerability assessment prediction in traditional technologies.

[0019] The specific step S1 includes the following sub-steps: The network paths in the network device are detected and the network paths to be tested are output. If there are cross-junctions in the network paths to be tested, the network path with the largest number of cross-junctions is selected from the network paths to be tested and the target cross-junction is output.

[0020] Auxiliary test path 1 and auxiliary test path 2 that have an intersection relationship with the target cross path are extracted from the network path to be tested. Auxiliary test path 1 is a network path that has an intersection point with the target cross path, and auxiliary test path 2 is a network path excluding auxiliary test path 1 and has an intersection point with the target cross path.

[0021] If the target cross path partially overlaps with the auxiliary test path 1 and the auxiliary test path 2 at intersection points, output preprocessing situation 1, in which the target cross path partially overlaps with the auxiliary test path, and the target cross path does not overlap with the auxiliary test path 2 at all.

[0022] According to the preprocessing case 1, the number of intersection points on the target intersection path is counted to obtain the number of target intersection points.

[0023] Obtain historical vulnerability detection data of network device encryption configuration being weakened and downgraded in historical periods, extract the number of historical path intersection points and historical vulnerability risk values ​​from the historical vulnerability detection data, perform statistics on the risk correlation coefficient between the number of historical path intersection points and historical vulnerability risk values, and output the risk correlation factor.

[0024] Multiply the target number of sinks by the risk correlation factor to obtain the estimated vulnerability risk of the configuration being weakened and degraded, and output the vulnerability risk estimate of one.

[0025] Specifically, the vulnerability assessment mentioned in the present invention is a vulnerability assessment of the weakening and degradation of the encryption configuration, the network path to be tested (the network path refers to the route for data transmission in the network device, which may involve multiple physical or logical channels: such as routers, switches, servers, etc.), the target cross path, the auxiliary test path 1 and the auxiliary test path 2 (if multiple network paths in the device intersect, it is very likely to cause synchronization conflicts of the encryption configuration, causing the encryption configuration to be weakened and degraded, which is more conducive to the invasion of external attackers. If the target cross path is L1, the auxiliary test path 1 is L2, and the auxiliary test path 2 is L3), the preprocessing situation 1 ( For example, if L1, L2, and L3 overlap and there are two intersection points, if they are D1 and D2 respectively (intersection intersection: multiple network paths may intersect with specific functional modules or processing nodes to form a "intersection point". The intersection point is essentially a key location for vulnerability mining, because attackers may use these intersection paths to implement unauthorized access or data tampering. For example, in router firmware, default credentials or firmware vulnerabilities may cause the intersection point to be exploited, causing service interruption or traffic hijacking), for example, the path between D1 and D2 for L1 and L2 is the same, that is, the target intersection path and part of the auxiliary test path overlap. , there is no path overlap between L1 and L3, only a cross-convergence relationship. In this case, L2 has a greater risk impact on L1), the number of target convergence points (if there are i (as in the above example, there are two convergence points (D1 and D2) on L1), the number of cross-convergence points is positively correlated with the risk of weakening the encryption configuration. An increase in cross-convergence points may lead to management omissions, such as encryption policies not being deployed uniformly, and some nodes (i.e., convergence points) becoming weak links), risk association factors (historical vulnerability detection data (such as CVSS score: using the v4.0 standard, from the attack vector (AV), attack complexity ( AC), impact area (IA), and other dimensions (0-10 points). For historical vulnerability risk values, if they are R1, R2, or Rn: For example, they are determined by the product of the probability of a security incident and the potential loss. For historical path intersections, if they are H1, H2, or Hn, plot the correlation between the historical vulnerability risk value and the number of historical path intersections using R as the y-axis and H as the x-axis. Average values ​​are calculated using (R2-R1) / (H2-H1) and (Rn-Rm) / (Hn-Hm), where nm = 1. If Z is the risk correlation factor, the vulnerability risk estimate is one (i.e., i*Z is G1).

[0026] The specific step S2 includes the following sub-steps: The logical distance between two adjacent intersection points in the preprocessing case 1 is counted, and the intersection point distribution logical distance is output. The average of all logical distance values ​​in the intersection point distribution logical distance is calculated, and the intersection point risk logical distance is output.

[0027] The path distribution area of each intersection in the pre-processing condition one is counted to obtain the path coverage area, and the path distribution quantity in the path coverage area is counted to obtain the path publication quantity. The path distribution quantity and the path coverage area are compared to obtain the intersection risk density.

[0028] If the auxiliary measurement path one still exists a non-coincidence intersection in addition to the pre-processing condition one, the pre-processing condition two is output, the path length of the intersection in the pre-processing condition two to the starting data output end is counted, and the measured distance value one is output.

[0029] The path length of the intersection on the target intersection path to the starting data output end is counted, and the shortest path length is extracted to output the measured distance value two. The measured distance value two and the measured distance value one are compared to obtain the intersection risk correlation distance ratio one.

[0030] The intersection risk logical distance, the intersection risk density, and the intersection risk correlation distance ratio one are combined to obtain the first measured risk feature data.

[0031] Specifically, for example, the logical distance of the convergence point risk logic distance (the logical distance is the path length or the number of hops that the data packet passes through in the network transmission process (such as the logical distance statistics in the present application: determining the nearest common node of two cross convergence points in the network topology, which is the subsequent starting data output end (such as data center, cluster, etc.), then adding the common path length from each cross convergence point to the starting data output end, and the sum is the logical distance. For example, if the common ancestor is a data center, the distance from the cross convergence point D1 to the starting data output end is 3, and the distance from the cross convergence point D2 to the starting data output end is 3, then the logical distance is 3+3=6, and if b1 represents the logical distance of the convergence point distribution between D1 and D2. At this time, there is no need to average, if L1 has 3 cross convergence points, and the third is D3, then by analogy, the logical distance of the convergence point distribution between D2 and D3 is calculated, and if it is b2, then the average value (b1+b2) / 2 is B, which is the logical distance of the convergence point risk), the logical distance is more directly related to the attenuation (weakening degradation) of the encryption strength (the update strength of the encryption configuration) and the increase of the vulnerability risk value), the path coverage area (such as the area covered by L1 and L2 distribution of D1 cross convergence point, if it is S1), the path publishing quantity (such as L1 and L2 are two, represented by N), the convergence point risk density (S1 / N if it is P1, by analogy, for L1 and L3 of D2 cross convergence point, if it is P2, then (P1+P2) / 2 if it is Pi), the pre-processing condition two (for example, there are other cross convergence points d on L2 (not coinciding with L1 and L3), because L2 has an associated vulnerability risk impact on L1, the more cross convergence points on L2, the more the associated vulnerability risk value of L1 is increased), the first to-be-measured distance value (such as the convergence point distribution logical distance statistics described above, by analogy, if it is j1, it should be noted that the first to-be-measured distance value here is the path length between d and the starting data output end), the second to-be-measured distance value (if D1 and D2 are j2 and j3 respectively, if j2 is the shortest, then j2 is selected as the second to-be-measured distance value), the first convergence point risk associated distance ratio (j2 / j1 if it is Ji1).

[0032] The specific step S3 includes the following sub-steps: If the target cross path and the auxiliary measurement path two have some cross convergence points coinciding, the auxiliary measurement path one and the auxiliary measurement path two have some cross convergence points coinciding, and the target cross path, the auxiliary measurement path one and the auxiliary measurement path two are in a completely non-coinciding relationship, then the path lengths of the auxiliary measurement path one and the auxiliary measurement path two from the coinciding cross convergence points to the starting data output end are respectively calculated, and the third to-be-measured distance value is output.

[0033] The ratio of the third to-be-measured distance value and the first to-be-measured distance value is calculated to obtain the second convergence point risk associated distance ratio, and the second to-be-measured risk feature data is combined from the convergence point risk logical distance and the second convergence point risk associated distance ratio.

[0034] If the target cross-path overlaps with the auxiliary test path one or the auxiliary test path two at an intersection point, and the target cross-path, the auxiliary test path one, and the auxiliary test path two are completely non-overlapping with each other, the intersection point risk logical distance is used as the third risk feature data to be measured.

[0035] The first risk feature data to be measured, the second risk feature data to be measured, and the third risk feature data to be measured are combined into pre-processed comprehensive risk feature data.

[0036] According to the risk feature data to be tested, historical risk feature data and corresponding historical comprehensive associated risk values ​​are extracted from historical vulnerability detection data, and a vulnerability associated risk prediction model is established based on the historical risk feature data and the corresponding historical comprehensive associated risk values.

[0037] The pre-processed comprehensive risk feature data is input into the vulnerability association risk prediction model for testing to obtain vulnerability risk valuation 2.

[0038] Summing vulnerability risk valuation 1 and vulnerability risk valuation 2, we can obtain the vulnerability estimation value of the target cross-path. Based on the vulnerability estimation value, we can obtain the comprehensive vulnerability estimation value of the network path with the cross-junction in the network path to be tested.

[0039] Based on the comprehensive vulnerability estimation value, a vulnerability simulation attack scan is performed on the corresponding location, and the vulnerability exploitation detection results are output.

[0040] Specifically, if the target cross-path and the auxiliary test path 2 partially overlap at their intersection points, the auxiliary test path 1 and the auxiliary test path 2 partially overlap at their intersection points, and the target cross-path, the auxiliary test path 1, and the auxiliary test path 2 are completely non-overlapping (for example, the intersection relationship between L1, L2, and L3 is in the form of "≠", if the intersection points are represented as w1 and w2, the vulnerability risk value in this case is lower than the first case above, so the statistical vulnerability risk influencing factor data is lower than the first case above), the distance value to be measured is j4 (for example, if the distance value to be measured between w1 and w2 in L1 and L2 is j4, if the distance value to be measured between w1 and w2 in L1 and L3 is also j4, then the distance value to be measured is j4).The intersection risk correlation distance ratio is 2 (if j4 / j1 is Ji2), if the target cross-path overlaps with the auxiliary test path 1 or auxiliary test path 2 at the intersection, and the target cross-path, auxiliary test path 1, and auxiliary test path 2 are in a completely non-overlapping relationship with each other (such as L1 and L2 have an intersection w3, and L3 itself also has an intersection, but has no direct cross-correlation with L1 and L2 (L3 and other network paths have intersections, and at this time, it does not participate in the consideration of the impact on the vulnerability risk value of L1), the vulnerability risk value in this case is inferior to the second case above, so the statistical vulnerability risk influencing factor data is inferior to the second case above. At this time, what needs to be considered is the impact of the logical distance of the intersection risk on L1 on the improvement of the vulnerability risk value). Historical comprehensive associated risk value (for example, taking the first risk feature data to be tested as an example: Y1=ax+by+cz, where Y1 refers to the historical comprehensive associated risk value, a refers to the sink risk logic distance B, x refers to the correlation factor between the sink risk logic distance and the historical comprehensive associated risk value, b refers to the sink risk density Pi, y refers to the correlation factor between the sink risk density and the historical comprehensive associated risk value, c refers to the sink risk association distance ratio Ji1, z refers to the correlation factor between the sink risk association distance ratio and the historical comprehensive associated risk value, substitute the known historical risk feature data and the corresponding historical comprehensive associated risk value for training to obtain x, y, and z, that is, the trained Vulnerability association risk prediction model: Y1=ax+by+cz, and so on, taking the second risk feature data to be tested as an example: Y2=ax+cz, it should be noted that: here c refers to the sink risk association distance ratio 2, and here z refers to the correlation factor between the sink risk association distance ratio 2 and the historical comprehensive association risk value. Similarly, taking the third risk feature data to be tested as an example: Y3=ax), vulnerability risk valuation 2 (if the first risk feature data to be tested is used as an example, the vulnerability risk valuation 2 is G2), vulnerability estimated value (if G1+G2 is Gi1, the comprehensive vulnerability estimated value is: that is, the vulnerability risk values ​​of other network paths with cross-sinks in the network device except L1 are evaluated (for example If L2 and L3 are Gi2 and Gi3, the same processing steps are performed, that is, Gi1, Gi2, Gi3, and Gin are summed. If it is Gz), vulnerability exploitation detection results (such as risk level classification based on the comprehensive vulnerability estimate value, and comparison with the historical vulnerability risk level value. If the comprehensive vulnerability estimate value is greater than or equal to the historical vulnerability risk level value, it is determined to be a medium-low risk vulnerability. If the comprehensive vulnerability estimate value is less than the historical vulnerability risk level value, it is determined to be a high-risk vulnerability). For high-risk vulnerabilities, perform a full-port and full-protocol deep scan to cover all network device interfaces. For medium- and low-risk vulnerabilities, use sampling scans to focus on vulnerability simulation attack scans such as key service ports, and record vulnerability exploitation detection results).

[0041] The above are all preferred embodiments of the present application, and are not intended to limit the scope of protection of the present application. Therefore, any equivalent changes made based on the structure, shape, and principle of the present application should be included in the scope of protection of the present application.

Claims

1. A network device vulnerability assessment method, characterized in that: The following steps are involved: Step S1: Select a target cross-path, auxiliary test path 1, and auxiliary test path 2 from network paths with cross-junctions within the network device. If the target cross-path has some overlap with auxiliary test path 1 and auxiliary test path 2, output preprocessing condition 1. Based on preprocessing condition 1, evaluate the correlation impact value between the number of cross-junctions on the target cross-path and the vulnerability risk, and output vulnerability risk estimation value 1. Step S2: Calculate the logical distance between two adjacent intersections in pre-processing case 1 to obtain a logical distance of intersection risk, and calculate the ratio between the number of paths distributed and the area of ​​each intersection in pre-processing case 1 to obtain a concentration of intersection risk. If the auxiliary test path 1 still contains non-overlapping intersections excluding the conditions of pre-processing case 1, output pre-processing case 2. Calculate the first risk feature data to be tested based on pre-processing case 2, vulnerability risk estimation 1, logical distance of intersection risk, and concentration of intersection risk. Step S3: If there is some overlap between the target cross-path and the auxiliary test path 2, and there is some overlap between the auxiliary test path 1 and the auxiliary test path 2, then the second risk feature data to be tested belonging to the intersection convergence is counted; if there is some overlap between the target cross-path and the auxiliary test path 1 or the auxiliary test path 2, and the target cross-path, the auxiliary test path 1, and the auxiliary test path 2 are completely non-overlapping, then the third risk feature data to be tested is counted; based on the three risk feature data to be tested, the comprehensive vulnerability estimate value of the network path to be tested is evaluated, and the vulnerability simulation attack scan of the corresponding position is performed to output the vulnerability exploitation detection result.

2. A network device vulnerability assessment method according to claim 1, characterized in that: Step S1 includes: Detecting the network paths within the network device and outputting the network paths to be tested. If there are cross junctions in the network paths to be tested, selecting the network path with the largest number of cross junctions from the network paths to be tested and outputting the target cross junction; Auxiliary test path 1 and auxiliary test path 2 that have an intersection relationship with the target cross path are extracted from the network path to be tested, the auxiliary test path 1 is a network path that has an intersection point with the target cross path, and the auxiliary test path 2 is a network path excluding the auxiliary test path 1 and has an intersection point with the target cross path.

3. A network device vulnerability assessment method according to claim 2, characterized in that: Step S1 further includes: If the target cross-path partially overlaps with the auxiliary test path 1 and the auxiliary test path 2, output pre-processing situation 1, in which the target cross-path partially overlaps with the auxiliary test path, and the target cross-path does not overlap with the auxiliary test path 2 at all; According to the first preprocessing condition, the number of intersection points on the target intersection path is counted to obtain the number of target intersection points; Obtain historical vulnerability detection data indicating that encryption configurations of network devices have been weakened and degraded over historical periods, extract the number of historical path intersection points and historical vulnerability risk values ​​from the historical vulnerability detection data, perform statistical analysis on risk correlation coefficients between the number of historical path intersection points and the historical vulnerability risk values, and output a risk correlation factor; Multiply the target number of sinks by the risk correlation factor to obtain an estimated vulnerability risk value of a configuration being weakened and degraded, and output a vulnerability risk estimate of one.

4. A network device vulnerability assessment method according to claim 3, characterized in that: Step S2 includes: Counting the logical distances between two adjacent intersection points in the preprocessing case 1, outputting the intersection point distribution logical distance, averaging all logical distance values ​​in the intersection point distribution logical distance, and outputting the intersection point risk logical distance; The path distribution area of ​​each intersection in the preprocessing case 1 is counted to obtain the path coverage area, and the number of path releases within the path coverage area is counted to obtain the number of path releases. The ratio of the path distribution number and the path coverage area is calculated to obtain the intersection risk density.

5. A network device vulnerability assessment method according to claim 4, characterized in that: Step S2 further includes: If the auxiliary measurement path 1 still has non-coincident intersection points excluding the preprocessing condition 1, the preprocessing condition 2 is output, the path length of the intersection points in the preprocessing condition 2 to the starting data output terminal is counted, and the distance value to be measured is outputted as 1; The path lengths from the intersection point on the target intersection path to the starting data output terminal are counted, and the shortest path length is extracted. The second distance value to be measured is output, and the ratio of the second distance value to be measured and the first distance value to be measured is calculated to obtain the intersection point risk association distance ratio 1; The sink point risk logic distance, sink point risk density and sink point risk association distance ratio are combined into a group of first risk feature data to be measured.

6. A network device vulnerability assessment method according to claim 5, characterized in that: Step S3 includes: If the target cross-path and the auxiliary test path 2 partially overlap at their intersection points, and the auxiliary test path 1 and the auxiliary test path 2 partially overlap at their intersection points, and the target cross-path, the auxiliary test path 1, and the auxiliary test path 2 are completely non-overlapping, then the path lengths from the overlapping intersection points of the auxiliary test path 1 and the auxiliary test path 2 to the starting data output terminal are counted respectively, and the third distance value to be measured is output; Calculate the ratio of the third distance value to be measured to the first distance value to be measured to obtain a second sink point risk association distance ratio, and combine the sink point risk logical distance and the second sink point risk association distance ratio to form the second risk feature data to be measured; If the target cross-path coincides with the auxiliary test path 1 or auxiliary test path 2 at a cross-point, and the target cross-path, auxiliary test path 1, and auxiliary test path 2 do not overlap with each other, the cross-point risk logic distance is used as the third risk feature data to be measured; The first risk feature data to be measured, the second risk feature data to be measured and the third risk feature data to be measured are combined into pre-processed comprehensive risk feature data.

7. A network device vulnerability assessment method according to claim 6, characterized in that: Step S3 further includes: Extracting historical risk feature data and corresponding historical comprehensive associated risk values ​​from historical vulnerability detection data based on the risk feature data to be tested, and establishing a vulnerability associated risk prediction model based on the historical risk feature data and the corresponding historical comprehensive associated risk values; Input the pre-processed comprehensive risk feature data into the vulnerability association risk prediction model for testing to obtain vulnerability risk estimation 2; Summing the vulnerability risk estimation value 1 and the vulnerability risk estimation value 2 to obtain a vulnerability estimation value of the target cross-path, and obtaining a comprehensive vulnerability estimation value of the network path with the cross-junction in the network path to be tested based on the vulnerability estimation value; Based on the comprehensive vulnerability estimation value, a vulnerability simulation attack scan is performed on the corresponding location, and a vulnerability exploitation detection result is output.

Citation Information

Patent Citations

  • Attack deduction graph generation method and system based on network security evaluation process

    CN114915476A

  • Block chain-based big data analysis decision method and system

    CN120088068A

  • Assessment apparatus and assessment method

    US20250190584A1