Industrial control equipment vulnerability detection method and system combining firmware analysis and network scanning
By combining firmware analysis and network scanning, the static and dynamic fingerprints of industrial control equipment components are cross-verified, which solves the problems of false positives and false negatives in vulnerability detection, improves the accuracy and detection capability of vulnerability detection, especially the ability to discover hard-coded passwords and weak passwords, and generates customized vulnerability reports for industrial control scenarios.
Patent Information
- Application Number
- CN202511380422.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-25
- Publication Date
- 2026-01-16
AI Technical Summary
In existing technologies, vulnerability detection based on firmware analysis has a high false positive rate, while vulnerability detection based on network scanning has a high false negative rate, making it difficult to effectively detect specific types of vulnerabilities in industrial control equipment, such as hard-coded passwords and weak passwords.
By combining firmware analysis and network scanning methods, static and dynamic fingerprints of industrial control equipment components are extracted and cross-validated to eliminate unreachable vulnerabilities, discover hidden vulnerabilities, and detect and verify hard-coded and weak passwords, forming a structured vulnerability list.
It significantly reduced the false positive and false negative rates of vulnerability detection, improved the detection capabilities for hard-coded and weak passwords, and generated informative vulnerability reports.
Smart Images

Figure CN121356818A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The application belongs to the technical field of vulnerability detection, and particularly relates to an industrial control device vulnerability detection method and system combining firmware static analysis and network dynamic scanning. BACKGROUND
[0002] Vulnerability detection mainly includes two detection technologies of network scanning-based vulnerability detection and firmware analysis-based vulnerability detection. The network scanning-based vulnerability detection mainly includes two methods of rule feature-based and simulation attack-based. The firmware analysis-based vulnerability detection mainly includes a known vulnerability detection method of firmware sensitive information and a vulnerability detection method of firmware open source components.
[0003] The network scanning-based vulnerability detection mainly includes two methods of rule feature-based and simulation attack-based. The rule feature-based method obtains system feedback through packet interaction and analyzes vulnerabilities in a non-intrusive manner in combination with a vulnerability library (such as version comparison); the simulation attack-based method simulates hacker attack behavior and dynamically detects different vulnerabilities by using a plug-in technology.
[0004] The firmware analysis-based vulnerability detection mainly includes the following aspects: a known vulnerability detection method based on firmware sensitive information, a vulnerability detection method based on firmware open source components, and a known vulnerability detection method based on firmware Web interface. The known vulnerability detection method based on firmware sensitive information traverses the firmware file system by rule matching, matches preset sensitive features, and is used for quickly locating high-risk vulnerabilities such as weak passwords and key leakage. The vulnerability detection method based on firmware open source components scans and matches the open source components of firmware by using an existing vulnerability knowledge base to find open source components with vulnerabilities. The vulnerability detection based on firmware Web interface dynamically simulates the target running environment by using firmware simulation technology, reconstructs the Web service running condition, realizes interface interaction and vulnerability triggering verification.
[0005] The firmware static analysis-based vulnerability detection detects vulnerabilities by reverse engineering and code feature scanning, is suitable for closed-source firmware, has the advantages of low system dependency and resource consumption, and can efficiently identify specific vulnerability types; but the high false positive rate restricts its actual application. The network scanning-based vulnerability detection has high efficiency and low system impact, but there is a certain degree of false negative. SUMMARY
[0006] The application provides an industrial control device vulnerability detection method and system combining firmware analysis and network scanning, effectively combines the two technologies of firmware analysis and network scanning, makes them complement each other and verify each other, thereby significantly reducing the false positive rate of firmware analysis-based vulnerability detection and the false negative rate of network scanning-based vulnerability detection in the industrial control device vulnerability detection process, and improving the detection capability for specific types of vulnerabilities (such as hard-coded passwords and weak passwords).
[0007] The technical solutions adopted by the application are as follows:
[0008] A kind of industrial control equipment vulnerability detection method combined with firmware analysis and network scanning, comprising the following steps:
[0009] Extract the component static fingerprint of industrial control equipment by firmware reverse analysis;
[0010] Obtain the dynamic fingerprint of industrial control equipment by network traffic scanning;
[0011] Cross-verify the component static fingerprint and dynamic fingerprint, eliminate unreachable vulnerabilities and find hidden vulnerabilities through cross-verification, obtain component-level potential vulnerability information table;
[0012] Based on the results of cross-verification, detect and verify the hard-coded password and weak password of industrial control equipment, form a hard-coded password list and a weak password list;
[0013] According to the component-level potential vulnerability information table, the hard-coded password list and the weak password list, evaluate the vulnerability effectiveness, form a structured vulnerability list.
[0014] Further, the component static fingerprint of industrial control equipment is extracted by firmware reverse analysis, comprising:
[0015] Obtain the firmware image file of industrial control equipment;
[0016] Perform feature analysis on the firmware image file, obtain the software bill of materials of industrial control equipment according to the preset rules, identify the file system type and operating system architecture, and form the firmware basic feature information from the software bill of materials, file system type and operating system architecture;
[0017] Unpack, disassemble or decompile the firmware image file to extract analyzable code fragments and configuration files;
[0018] By analyzing the firmware content, identify the operating system, third-party components and their version numbers used by the industrial control equipment as static fingerprint information, and query the authoritative vulnerability database to obtain the known vulnerability list corresponding to the component version, form a preliminary component-level potential vulnerability information table.
[0019] Further, the dynamic fingerprint of industrial control equipment is obtained by network traffic scanning, comprising:
[0020] Network traffic and behavior data of the target industrial control equipment are collected by combining active probing with passive listening;
[0021] The active probing includes constructing protocol messages according to industrial control protocol specifications and general network protocols, sending probing requests to the target industrial control equipment, and capturing and analyzing the response messages;
[0022] The passive monitoring includes: bypassing the deployment of a traffic capture device to capture network traffic of the target industrial control device in a normal communication state, and analyzing and obtaining the open port, running service and version of the related component of the device by analyzing the protocol header and load characteristics.
[0023] Further, the cross verification of the static fingerprint and the dynamic fingerprint of the component includes:
[0024] For potential vulnerabilities found by firmware analysis, it is verified through network scanning results whether the corresponding component or service is actually running on the device and is network accessible; if a component exists in the firmware, but network scanning shows that the related service is not started, or the vulnerability exploitation path is not accessible at the network level, the vulnerability is removed from the component-level potential vulnerability information table or marked as low risk, thereby effectively reducing false positives;
[0025] For components identified by firmware analysis as existing but for which network scanning fails to find the corresponding service, attempts are made to activate the service by simulating device configuration, and after successful activation of the service, targeted vulnerability scanning and verification are performed to discover vulnerabilities that exist at the firmware level but are not visible by default at the network level, thereby reducing false negatives.
[0026] Further, the detection and verification of the hard-coded password and weak password of the industrial control device includes:
[0027] In the firmware analysis process, hard-coded passwords, keys, API Token information existing in the device firmware are detected;
[0028] For hard-coded passwords found by firmware analysis, attempts are made to log in to the open network services of the device through network scanning to verify their effectiveness, and for all identified open network services, a weak password dictionary is used for automated weak password brute force attempts;
[0029] Based on the results of firmware analysis and network verification, a hard-coded password list and a weak password list related to the network services of the device are formed.
[0030] Further, the evaluation of vulnerability effectiveness according to the component-level potential vulnerability information table, the hard-coded password list and the weak password list includes:
[0031] Exp scripts are written using publicly disclosed vulnerability information or publicly available scripts are directly used to scan and test vulnerabilities of third-party components of the industrial control device, and a component vulnerability list is output based on the vulnerability detection results;
[0032] Each type of vulnerability is associated with static feature information, dynamic verification screenshots and repair priority, and industrial control scene customization suggestions are attached, and finally a report list that can be directly used for security reinforcement is formed.
[0033] Furthermore, the dynamic verification screenshots include: screenshots of the identification results of network service scanning, screenshots of commands and responses attempting to activate the service, screenshots of successfully logging into the service using a weak password, and screenshots of successfully performing exploitation, etc.
[0034] A vulnerability detection system for industrial control equipment that combines firmware analysis and network scanning, comprising:
[0035] The firmware analysis module is used to extract static fingerprints of components in industrial control equipment through firmware reverse analysis.
[0036] The network scanning module is used to obtain the dynamic fingerprint of industrial control equipment by scanning network traffic;
[0037] The dynamic and static fingerprint cross-verification module is used to cross-verify the static and dynamic fingerprints of components. Through cross-verification, unreachable vulnerabilities are eliminated and hidden vulnerabilities are discovered, resulting in a component-level potential vulnerability information table.
[0038] The hard-coded password and weak password detection and verification module is used to detect and verify the hard-coded passwords and weak passwords of industrial control equipment based on the results of cross-validation, and to form a hard-coded password list and a weak password list.
[0039] The comprehensive assessment module is used to evaluate the effectiveness of vulnerabilities based on the component-level potential vulnerability information table, the hard-coded password list, and the weak password list, and to generate a structured vulnerability list.
[0040] Compared with the prior art, the beneficial effects of the present invention are as follows:
[0041] 1. Reduce false positives and false negatives. Through deep integration and cross-verification of firmware analysis and network scanning results, the accuracy of vulnerability detection results is ensured. Network scanning verifies the actual reachability of vulnerabilities analyzed by firmware, effectively eliminating false positives; firmware analysis guides network scanning to probe and verify potentially inactive services, significantly reducing false negatives and comprehensively improving vulnerability detection rate and accuracy.
[0042] 2. Enhance hard-coded and weak password detection. Staticly inspect hard-coded information at the firmware level, perform actual verification through network scanning, and combine this with weak password scanning of active services to form a closed loop from discovery to verification, thereby improving the detection capability of such vulnerabilities.
[0043] 3. Deep Adaptation to Industrial Control Systems. This method considers the characteristics of industrial control equipment during implementation, such as customized vulnerability verification scripts and dynamic fingerprint recognition supporting multiple industrial control protocols like S7Comm and DNP3. The final vulnerability report includes customized remediation suggestions for industrial control scenarios, making it more instructive and actionable. Attached Figure Description
[0044] Figure 1This is a flowchart of the industrial control equipment vulnerability detection method that combines firmware analysis and network scanning according to the present invention.
[0045] Figure 2 This is a flowchart of static fingerprint extraction.
[0046] Figure 3 This is a flowchart of the dynamic fingerprint extraction process.
[0047] Figure 4 This is a flowchart of hard-coded and weak password detection. Detailed Implementation
[0048] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, the present invention will be further described in detail below with reference to specific embodiments and accompanying drawings.
[0049] This invention provides a method for detecting vulnerabilities in industrial control equipment that combines firmware analysis and network scanning, such as... Figure 1 As shown, it includes the following steps:
[0050] 1. Extract component static fingerprints (such as version number and code characteristics) through firmware reverse engineering.
[0051] The static fingerprint extraction process is as follows: Figure 2 As shown. First, the firmware image file of the industrial control equipment is obtained. Preliminary feature analysis is performed on the firmware image file, such as recursively scanning the firmware structure, obtaining the software bill of materials of the industrial control equipment according to preset rules (such as file system feature libraries, magic number matching tables), identifying the file system type and operating system architecture, and constructing basic firmware feature information. The firmware image file is then unpacked, disassembled, or decompiled to extract analyzable code snippets and configuration files. By analyzing the firmware content (including binary files, scripts, configuration files, etc.), static fingerprint information such as the operating system used by the industrial control equipment, third-party components (such as library files, applications, web services), and their version numbers is identified. Simultaneously, authoritative vulnerability databases (such as NVD, CNVD, etc.) are queried to obtain a list of known vulnerabilities corresponding to the versions of these third-party components, forming a preliminary component-level potential vulnerability information table.
[0052] 2. Obtain dynamic fingerprints (such as protocol response characteristics and port services) through network traffic scanning.
[0053] The static fingerprint extraction process is as follows: Figure 3As shown, a combination of active probing and passive monitoring is used to collect network traffic and behavioral data from the target industrial control equipment (ICS). For active probing, protocol messages are constructed based on ICS protocol specifications (such as Modbus, S7Comm, DNP3, OPC UA, etc.) and common network protocols (TCP / IP, HTTP, etc.) to send probing requests to the target ICS, capturing and analyzing its response messages. For passive monitoring, a traffic capture device is deployed in a bypass manner to capture the network traffic of the target ICS under normal communication conditions. By parsing the protocol header and payload characteristics, dynamic fingerprint information such as the device's open ports, running services, and the versions of relevant components (if identifiable) is obtained.
[0054] 3. Cross-validation of static and dynamic fingerprints, mutual verification of results, elimination of unreachable vulnerabilities and discovery of hidden vulnerabilities, reducing false positives and false negatives.
[0055] The component-level potential vulnerability information table obtained from firmware analysis in step 1 is cross-validated with the service and dynamic fingerprint information obtained from network scanning in step 2.
[0056] Verifying reachability and reducing false positives: For potential vulnerabilities discovered through firmware analysis, network scanning results are used to verify whether the corresponding components or services are actually running on the device and are network reachable. If a component exists in the firmware, but network scanning shows that its related services are not running, or the exploit path is unreachable at the network level, the vulnerability is removed from the component-level potential vulnerability information table or marked as low-risk (unexploitable), thereby effectively reducing false positives.
[0057] Supplementary scanning to reduce false negatives: For components identified by firmware analysis but whose corresponding services were not found by network scanning (services are not enabled by default, are hidden, or are improperly configured), attempt to activate the services by simulating device configuration (based on the default configuration file or general configuration logic in the firmware, attempt to send configuration commands to the device to enable the relevant services, or load the configuration and start the services in the simulation environment). After successfully activating the services, perform targeted vulnerability scanning and verification to discover vulnerabilities that exist at the firmware level but are not visible to the network by default, thereby reducing false negatives.
[0058] 4. Hard-coded password and weak password detection and verification.
[0059] Step 4 utilizes the verification results from Step 3 to perform hard-coded and weak password detection and verification. Services verified as active and reachable in Step 3 are valid targets for weak password brute-force attacks and hard-coded password verification in Step 4. If Step 3 discovers a service that exists in the firmware but is unreachable by the network, there is no need to perform password testing on that service, thus avoiding invalid attempts and improving detection efficiency.
[0060] The hard-coding and weak password detection process is as follows:Figure 4 As shown. During the firmware analysis process in step 1, sensitive information such as hard-coded passwords, keys, and API tokens are specifically detected in the device firmware.
[0061] For hard-coded passwords discovered during firmware analysis, network scans are conducted to attempt to log in to the device's open network services (such as Telnet, SSH, FTP, and web management interfaces) using these passwords to verify their validity. Simultaneously, for all identified open network services, automated brute-force attacks are performed using a pre-defined weak password dictionary.
[0062] Based on the combined firmware analysis and network verification results, a list of hard-coded passwords and a list of weak passwords related to device network services are generated.
[0063] 5. Conduct a comprehensive assessment to confirm the effectiveness of the vulnerabilities and create a structured vulnerability list.
[0064] Based on the component-level potential vulnerability information table, hard-coded password list, and weak password list obtained from the above steps, the confirmed vulnerabilities are evaluated. Exploit scripts (exp) are written using publicly disclosed vulnerability information, or publicly available scripts are directly used to scan and test third-party components of industrial control equipment. Based on the vulnerability detection results, a component vulnerability list is output, and each type of vulnerability is associated with static characteristic information (such as code offset address), dynamic verification screenshots, and remediation priority (high-risk / medium-risk / low-risk), along with customized suggestions for the industrial control scenario (such as disabling dangerous protocol ports and enabling PLC instruction signing), ultimately forming a report list that can be directly used for security hardening.
[0065] The component-level potential vulnerability information table provided in step 3 is used in step 5 to determine the actual validity of the vulnerabilities. The hard-coded password list and weak password list provided in step 4 are used in step 5 to supplement and verify login and permission-related vulnerabilities.
[0066] Step 5 involves writing exploit scripts based on publicly disclosed vulnerability information or directly using publicly available scripts to further verify the validity of the vulnerability list obtained from the cross-validation in Step 3. The script testing is limited to component vulnerabilities confirmed in Step 3 (e.g., Step 3 identifies a device running OpenSSL version 1.0.2 with a Heartbleed vulnerability). A matching exploit script must be written or invoked based on the publicly available technical details of the vulnerability (e.g., vulnerability principles, exploitation conditions). If the test involves permissions, a valid password from Step 4 is further invoked to complete the pre-login process, ultimately confirming whether the vulnerability can be actually exploited (e.g., whether sensitive device data can be obtained or malicious commands can be executed through the exploit).
[0067] The vulnerability detection results mentioned in step 5 refer to: the vulnerabilities that were retained after cross-validation in step 3 and successfully exploited by EXP in step 5 (confirmed as real high-risk vulnerabilities), the valid hard-coded passwords and weak passwords discovered in step 4 (which are themselves vulnerabilities), and the false positive vulnerabilities excluded in steps 3 and 5 (marked as invalid or fixed).
[0068] The static feature information mentioned in step 5 is directly derived from step 1. Code offset addresses, the library file or application name, etc., are all component static fingerprint information extracted during firmware reverse engineering. Associating these with vulnerabilities can provide developers with fixes and location information.
[0069] The dynamic verification screenshots mentioned in step 5 mainly come from the verification processes in steps 2, 3, and 5. For example: screenshots of the identification results of the network service scan in step 2; screenshots of the command and response when attempting to activate the service in step 3; screenshots of successfully logging into the service using a weak password in step 4; and screenshots of successful exploitation in step 5 (such as the echo of successful command execution, proof of obtaining the content of a specific file, etc.).
[0070] The key point of this invention is:
[0071] 1) Vulnerability Detection Method Based on Mutual Verification of Firmware Analysis and Network Scanning Results. This method combines vulnerability detection based on firmware analysis with vulnerability detection based on network scanning, allowing for mutual verification and reducing false positive and false negative rates in industrial control equipment vulnerability detection. Static firmware analysis obtains information on device components and potential vulnerabilities, which is then cross-verified using information obtained from dynamic network scanning, including service and component activity status and network reachability. Network scanning verifies the reachability of vulnerabilities identified through firmware analysis, eliminating false positives caused by unused components or unreachable networks. Furthermore, supplementary scanning targets services present in the firmware but not directly exposed by the network, uncovering hidden vulnerabilities and reducing false negatives.
[0072] 2) A collaborative detection and verification method for hard-coded passwords and weak passwords, combining firmware analysis and network scanning. First, firmware analysis is used to deeply mine sensitive information such as hard-coded passwords and keys in the device; then, network scanning is used to verify the online connectivity of these hard-coded credentials and to detect weak passwords for all network services, forming a list of hard-coded passwords and weak passwords for the device.
[0073] Another embodiment of the present invention provides an industrial control equipment vulnerability detection system combining firmware analysis and network scanning, comprising:
[0074] The firmware analysis module is used to extract static fingerprints of components in industrial control equipment through firmware reverse analysis.
[0075] The network scanning module is used to obtain the dynamic fingerprint of industrial control equipment by scanning network traffic;
[0076] The dynamic and static fingerprint cross-verification module is used to cross-verify the static and dynamic fingerprints of components. Through cross-verification, unreachable vulnerabilities are eliminated and hidden vulnerabilities are discovered, resulting in a component-level potential vulnerability information table.
[0077] The hard-coded password and weak password detection and verification module is used to detect and verify the hard-coded passwords and weak passwords of industrial control equipment based on the results of cross-validation, and to form a hard-coded password list and a weak password list.
[0078] The comprehensive assessment module is used to evaluate the effectiveness of vulnerabilities based on the component-level potential vulnerability information table, the hard-coded password list, and the weak password list, and to generate a structured vulnerability list.
[0079] The above division of modules is merely illustrative. In practical applications, the functions described above can be assigned to different functional modules as needed to complete all or part of the functions described in the aforementioned method. The specific working process of each module can be found in the corresponding process in the aforementioned method embodiments, and will not be repeated here.
[0080] Another embodiment of the present invention provides a computer device (computer, server, smartphone, etc.) including a memory and a processor, the memory storing a computer program configured to be executed by the processor, the computer program including instructions for performing steps of the method of the present invention.
[0081] Another embodiment of the present invention provides a computer-readable storage medium (such as ROM / RAM, disk, optical disk) that stores a computer program, which, when executed by a computer, implements the steps of the method of the present invention.
[0082] Another embodiment of the present invention provides a computer program product, the computer program product including a computer program, which, when executed by a computer, implements the steps of the method of the present invention.
[0083] The specific embodiments of the present invention disclosed above are intended to help understand the content of the present invention and to implement it accordingly. Those skilled in the art will understand that various substitutions, changes, and modifications are possible without departing from the spirit and scope of the present invention. The present invention should not be limited to the content disclosed in the embodiments of this specification; the scope of protection of the present invention is defined by the claims.
Claims
1. A method for detecting vulnerabilities of industrial control devices by combining firmware analysis and network scanning, characterized in that, The method comprises the following steps: extracting component static fingerprints of the industrial control equipment through firmware reverse analysis; obtaining dynamic fingerprints of the industrial control equipment through network flow scanning; cross-verification of the component static fingerprints and the dynamic fingerprints, removing unreachable vulnerabilities through cross-verification and discovering hidden vulnerabilities to obtain a component-level potential vulnerability information table; based on the cross-verification result, detecting and verifying hard-coded passwords and weak passwords of the industrial control equipment to form a hard-coded password list and a weak password list; based on the component-level potential vulnerability information table, the hard-coded password list and the weak password list, evaluating vulnerability effectiveness to form a structured vulnerability list.
2. The method of claim 1, wherein, The extracting of the component static fingerprints of the industrial control equipment through firmware reverse analysis comprises: obtaining a firmware image file of the industrial control equipment; performing feature analysis on the firmware image file, obtaining a software bill of materials of the industrial control equipment according to a preset rule, identifying a file system type and an operating system architecture, and constructing firmware basic feature information from the software bill of materials, the file system type and the operating system architecture; unpacking, disassembling or decompiling the firmware image file to extract analyzable code segments and configuration files; through analysis of the firmware content, identifying an operating system, third-party components and their version numbers adopted by the industrial control equipment as static fingerprint information, and simultaneously querying an authoritative vulnerability database to obtain a known vulnerability list corresponding to the component versions to form a preliminary component-level potential vulnerability information table.
3. The method of claim 1, wherein, The obtaining of the dynamic fingerprints of the industrial control equipment through network flow scanning comprises: adopting a combination of active detection and passive monitoring to collect network flow and behavior data of the target industrial control equipment; the active detection comprises: constructing protocol messages according to industrial protocol specifications and general network protocols, sending a detection request to the target industrial control equipment, and capturing and analyzing response messages thereof; the passive monitoring comprises: bypassing deployment of a flow capture device to capture network flow of the target industrial control equipment in a normal communication state, and analyzing and obtaining opened ports, running services and related component versions of the equipment through analysis of protocol header and load characteristics.
4. The method of claim 1, wherein, The cross-verification of the component static fingerprints and the dynamic fingerprints comprises: for a potential vulnerability discovered through firmware analysis, verifying whether a corresponding component or service thereof is actually running on the equipment and is network-accessible through network scanning results; if a component exists in the firmware but network scanning shows that a related service thereof is not started or a vulnerability exploitation path is not reachable at a network level, the vulnerability is removed from the component-level potential vulnerability information table or is marked as low risk, thereby effectively reducing false positives; for a component that is identified as existing through firmware analysis but for which a corresponding service is not discovered through network scanning, attempting to activate the service by simulating device configuration, after successful activation of the service, performing targeted vulnerability scanning and verification on the service to discover a vulnerability that exists at a firmware level but is not visible by default at a network level, thereby reducing false negatives.
5. The method of claim 1, wherein, The detecting and verifying of the hard-coded passwords and the weak passwords of the industrial control equipment comprises: detecting hard-coded passwords, keys and API Token information existing in the firmware of the equipment during firmware analysis; For the hard-coded password found by firmware analysis, the network scanning is used to attempt to log in the open network service of the device to verify its validity, and for all identified open network services, the preset weak password dictionary is used for automatic weak password brute force attempt; The firmware analysis and network verification results are integrated to form a hard-coded password list and a weak password list related to the network service of the device.
6. The method of claim 1, wherein, The vulnerability effectiveness is evaluated according to the component-level potential vulnerability information table, the hard-coded password list and the weak password list, including: Exp scripts are written by using the publicly disclosed vulnerability information or the public scripts are directly used to scan and test the third-party components of the industrial control device, and a component vulnerability list is output according to the vulnerability detection result. Each type of vulnerability is associated with static feature information, dynamic verification screenshots and repair priority, and industrial control scene customization suggestions are attached, and finally a report list directly used for security reinforcement is formed.
7. The method of claim 6, wherein, The dynamic verification screenshots include: the identification result screenshots of the network service scanning, the command and response screenshots of the attempt to activate the service, the screenshots of the successful login to the service by using the weak password, and the screenshots of the successful EXP utilization.
8. An industrial control device vulnerability detection system combining firmware analysis and network scanning, characterized in that, Including: The firmware analysis module is used to extract the component static fingerprint of the industrial control device by firmware reverse analysis; The network scanning module is used to obtain the dynamic fingerprint of the industrial control device by network traffic scanning; The dynamic and static fingerprint cross verification module is used to cross verify the component static fingerprint and the dynamic fingerprint, to eliminate unreachable vulnerabilities and find hidden vulnerabilities through cross verification, and to obtain a component-level potential vulnerability information table; The hard-coded password and weak password detection and verification module is used to detect and verify the hard-coded password and the weak password of the industrial control device based on the cross verification result, to form a hard-coded password list and a weak password list; The comprehensive evaluation module is used to evaluate the vulnerability effectiveness according to the component-level potential vulnerability information table, the hard-coded password list and the weak password list, to form a structured vulnerability list.
9. A computer device, comprising: The computer readable storage medium stores a computer program, and the computer program is configured to be executed by the processor, and the computer program includes instructions for executing the method in any one of claims 1-7.
10. A computer-readable storage medium, characterized in that, The computer readable storage medium stores a computer program, and the computer program is configured to be executed by the processor, and the computer program includes instructions for executing the method in any one of claims 1-7.
Citation Information
Patent Citations
User data deep forensic analysis method and system oriented to Internet of Things equipment
CN114884717A
Vulnerability mining method based on equipment firmware simulation under novel power system and storage medium
CN115062309A
Security analysis system
CN118802230A
Network equipment vulnerability mining method based on large model and knowledge graph
CN120151033A