Network and data security detection method, device, equipment, medium and program product
By generating an overlay of network asset topology and data flow graphs, unprotected or unsecured risk points in cyberspace are identified and assessed, solving the problems of assessment lag and low automation in existing technologies, and achieving fast and accurate security assessment.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- HAOFU CIPHER DETECTION TECH (CHENGDU) CO LTD
- Filing Date
- 2026-05-13
- Publication Date
- 2026-07-10
Smart Images

Figure CN122372313A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of cryptographic security technology, and in particular to network and data security detection methods, devices, equipment, media, and program products. Background Technology
[0002] With the deep integration of digital transformation and the Industrial Internet, the boundaries of cyberspace assets are becoming increasingly blurred, exhibiting highly dynamic and fragmented characteristics. Cryptographic technology, as a core cornerstone for ensuring network and data security, has made the compliance, correctness, and effectiveness assessment of its application a top priority for security supervision. Existing asset detection technologies mainly rely on traditional methods such as periodic proactive scanning tools, static configuration management databases (CMDBs), and manual review of system documentation. These methods use separate traffic analysis tools to capture and analyze packets at specific business points, attempting to build an asset inventory and verify whether appropriate encryption protection measures have been implemented.
[0003] However, this traditional detection and assessment model reveals serious lag and limitations in complex environments: on the one hand, there are obvious information silos between asset identification and security protection, and the static asset view is difficult to map the dynamic changes of business data flow and protection flow in real time, making "shadow assets" and unencrypted "protection vacuum zones" easy to become security blind spots; on the other hand, due to the lack of deep integration and correlation between assets, business logic and cryptographic protection flow, the assessment process is highly dependent on expert experience and has a low degree of automation, making it impossible to intuitively and quickly locate the protection failure links, and it is difficult to meet the efficiency requirements of continuous compliance monitoring in large-scale network environments. Summary of the Invention
[0004] The main purpose of this application is to provide a network and data security testing method, apparatus, equipment, medium, and program product, which aims to solve the technical problem that related technologies cannot quickly evaluate the effectiveness of cryptography in protecting network and data security.
[0005] To achieve the above objectives, this application proposes a network and data security detection method, the method comprising: Perform asset detection on the target cyberspace, identify cyberspace asset information, and generate a network asset topology map; Data flow identification is performed on the target network space to identify business data flow and protection measure data flow, and a data flow graph containing business data flow paths and protection measure data flow paths is generated. The network asset topology diagram is overlaid with the data flow diagram to generate an overlay diagram. The overlay diagram is used to show the correspondence between network space asset information, business data flow, and protection measure data flow. Based on the overlay diagram, the cryptographic and non-cryptographic protection measures corresponding to each asset node are sorted out and compared with the preset database of objects to be protected to determine the comparison results; Based on the comparison results, identify risk points that are unprotected or lack password protection, and output security assessment results.
[0006] In one embodiment, the steps of asset probing of the target cyberspace, identifying cyberspace asset information and their connectivity, and generating a network asset topology map include: Collect data and compile an asset inventory for the targets in the target cyberspace; The asset list is verified and supplemented by at least one of the following methods: active scanning, passive monitoring, and / or cloud-based synchronous comparison, to determine the cyberspace asset information; Based on cyberspace asset information, draw a network asset topology map.
[0007] In one embodiment, the step of identifying data flow in the target network space, identifying service data flow and protection measure data flow, and generating a data flow graph containing service data flow paths and protection measure data flow paths includes: Based on the asset list, identify the core network assets, label the data source, destination, processing node and transmission direction, and construct a business data flow diagram; Determine the data flow path by deploying at least one of the following methods: traffic analysis probes, host-level monitoring, and / or database audit log analysis; Integrate business data flow diagrams and data flow paths to generate a business data flow diagram.
[0008] In one embodiment, the steps of identifying data flow in the target network space, identifying service data flows and protection measure data flows, and generating data flow graphs containing service data flow paths and protection measure data flow paths include: Identify all network security-related devices in the target cyberspace; Configuration analysis of access control policies, encryption and authentication configurations, and auditing policies for network security related devices. By using traffic mirroring and authorization testing, the configuration and analysis of security protocol interactions are performed to verify the authenticity of certificate exchange and key negotiation processes and determine the deployment location and action path of security-related control policies. Simulate malicious requests or authentication failures to track the flow and lifecycle of alert logs and audit records within the encryption system; Draw a protection measure flow diagram that includes the nodes of security data generation, transmission, storage and consumption. Overlay the protection measure flow diagram with the business data flow diagram to determine the protection measures for each link of the business data flow, and generate a data flow diagram that includes the business data flow path and the protection measure data flow path.
[0009] In one embodiment, the steps of sorting out the cryptographic protection measures and non-cryptographic protection measures corresponding to each asset node based on the overlay graph, and comparing them with a preset database of protected objects to determine the comparison results include: Based on the overlay graph, the relationship between protection measures and protected cyberspace assets in the target cyberspace is determined, and the actual protection status of the protected cyberspace assets is determined; the actual protection status includes no protection status, no password protection status, and password protection status.
[0010] The actual protection status is compared with the database of objects to be protected to determine the objects that are in a non-password protected state or have no protection.
[0011] In one embodiment, the step of identifying unprotected or password-protected risk points based on the comparison results and outputting security assessment results includes: If the object to be protected is in an unprotected state, then output that there is a security problem. If the object to be protected is in a non-password protected state, then the protection measures for the object to be protected will be analyzed to determine and output the risk level of the current protection measures.
[0012] Secondly, to achieve the above objectives, this application further provides a network and data security detection device, the device comprising: The asset detection module is used to detect assets in the target cyberspace, identify cyberspace asset information, and generate a network asset topology map. The identification module is used to identify data flow in the target network space, identify business data flow and protection measure data flow, and generate a data flow diagram containing business data flow path and protection measure data flow path. The overlay module is used to overlay the network asset topology diagram with the data flow diagram to generate an overlay diagram. The overlay diagram is used to show the correspondence between network space asset information, business data flow, and protection measure data flow. The comparison module is used to sort out the password protection measures and non-password protection measures corresponding to each asset node, and compare them with the preset database of objects to be protected to determine the comparison results; The output module is used to identify unprotected or password-free risk points and output security assessment results.
[0013] Thirdly, to achieve the above objectives, this application further provides a network and data security detection device, the device comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor, the computer program being configured to implement the steps of the network and data security detection method described above.
[0014] Fourthly, to achieve the above objectives, this application further provides a storage medium that is a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, it implements the steps of the above-described network and data security detection method.
[0015] Fifthly, to achieve the above objectives, this application further provides a computer program product, which includes a computer program that, when executed by a processor, implements the steps of the above-described technical opportunity recommendation method.
[0016] One or more technical solutions proposed in this application have at least the following technical effects: This application constructs the correlation between assets, business data, and security protection by uniformly identifying and overlaying network space asset topology with business data flow and protection measure data flow. This enables a dynamic and visual assessment of network and data security protection status from a holistic perspective. Compared to traditional detection methods relying on static asset lists and manual analysis, this solution can simultaneously identify the actual operational paths of business data flow and security protection measures in complex network environments. It automatically locates risk nodes that are unprotected or lack cryptographic protection, and performs mechanism analysis and risk classification for non-cryptographic protection measures. This significantly improves the automation and accuracy of network and data security assessments, enabling rapid and intuitive evaluation of cryptographic protection effectiveness and enhancing the efficiency and reliability of security compliance testing in large-scale network environments. Attached Figure Description
[0017] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.
[0018] To more clearly illustrate the technical solutions in the embodiments of this application or related technologies, the accompanying drawings used in the description of the embodiments or related technologies will be briefly introduced below. Obviously, for those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0019] Figure 1 This is a flowchart illustrating an embodiment of the network and data security detection method of this application.
[0020] Figure 2 This is a first scenario example diagram provided for an embodiment of the network and data security detection method of this application.
[0021] Figure 3 This is a second scenario example diagram provided for an embodiment of the network and data security detection method of this application.
[0022] Figure 4This is a schematic diagram of the network and data security detection device of this application.
[0023] Figure 5 This is a schematic diagram illustrating the results of the network and data security testing equipment used in this application.
[0024] The purpose, features, and advantages of this application will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation
[0025] It should be understood that the specific embodiments described herein are merely illustrative of the technical solutions of this application and are not intended to limit this application.
[0026] To better understand the technical solution of this application, a detailed description will be provided below in conjunction with the accompanying drawings and specific implementation methods.
[0027] The main solution of this application embodiment is as follows: Asset detection is performed on the target network space to identify network space asset information and generate a network asset topology map; further, business data flows and protection measure data flows in the network space are identified, and a data flow map containing business data flow paths and protection measure data flow paths is constructed; the network asset topology map and the data flow map are overlaid to form an overlay map that displays the correspondence between network space assets, business data flows, and protection measures; based on the overlay map, the cryptographic and non-cryptographic protection measures corresponding to each asset node are sorted out and compared with a preset database of protected objects to determine the actual protection status of each asset node; on this basis, risk points without protection or without cryptographic protection are identified, and corresponding security assessment results are output, thereby achieving automated detection and evaluation of the effectiveness of network and data security protection.
[0028] Cryptography protects both cyberspace and data security. Therefore, to effectively protect both cyberspace and data security, security testing of cryptography for these purposes should be conducted, both technically and legally. This security includes the security of the cryptography itself, its compatibility with cyberspace and data flow, use, and storage, and the effectiveness of the cryptography in providing security protection.
[0029] Currently, there are separate testing methods for cryptographic products, separate security assessments of cryptographic applications in cyberspace, and isolated testing methods that do not consider data security from a cryptographic perspective. These methods have the following main problems: 1. As cryptographic products at the foundational level continue to emerge with new technologies, forms, and functions, testing and evaluation based solely on basic cryptographic requirements cannot effectively assess their suitability for cyberspace and data security.
[0030] 2. From the perspective of user needs, the rapid development of network technology, communication technology, data technology, etc., makes it impossible to accurately assess the adaptability of passwords.
[0031] 3. The detection methods are independent of each other, and the compliance, correctness, and effectiveness of password use in cyberspace cannot be guaranteed. There is a lack of systematic consideration regarding the security and efficiency of data flow in cyberspace.
[0032] 4. Choosing a reasonable password lacks an assessment of its security effectiveness.
[0033] 5. Once passwords are embedded in cyberspace and data applications, they are difficult to modify or replace.
[0034] 6. Current data security assessments do not systematically implement technologies for cryptographic protection throughout the entire data lifecycle.
[0035] 7. Emerging privacy computing technologies for data security: These new cryptographic technologies, which are highly integrated with data use, lack security testing methods.
[0036] Based on this, embodiments of this application provide a network and data security detection method, referring to... Figure 1 , Figure 1 This is a flowchart illustrating the first embodiment of the network and data security detection method of this application.
[0037] In this embodiment, the network and data security detection method includes steps S10 to S50: Step S10: Perform asset detection on the target cyberspace, identify cyberspace asset information, and generate a network asset topology map; Step S20: Identify data flow in the target network space, identify business data flow and protection measure data flow, and generate a data flow diagram containing business data flow paths and protection measure data flow paths; Step S30: Overlay the network asset topology map with the data flow map to generate an overlay map. The overlay map is used to show the correspondence between network space asset information, business data flow and protection measure data flow. Step S40: Based on the overlay diagram, sort out the cryptographic protection measures and non-cryptographic protection measures corresponding to each asset node, and compare them with the preset database of objects to be protected to determine the comparison results; Step S50: Based on the comparison results, identify risk points that are unprotected or without password protection, and output the security assessment results.
[0038] Specifically, cyberspace assets refer to all valuable and perceptible entities and virtual objects within the target network, including hardware devices, software systems, and the data they carry. This embodiment visualizes these assets scattered within the network boundary and their logical / physical connections through active and passive detection methods. The resulting network asset topology map serves as a high-definition base, clearly outlining who is where and connected to whom.
[0039] The subsequent data flow identification infuses the static topology with a dynamic soul. It breaks down traffic into business data flows and protection data flows. Business data flows are the main drivers of core functions, such as user commands or transaction data; protection data flows are the bodyguards that accompany the business, recording security signaling such as certificate exchange, key negotiation, and audit alarms. The generated data flow graph fully reproduces the end-to-end flow trajectory and logical path of these data between nodes.
[0040] The most innovative part of the solution lies in the overlay diagram constructed in step S30. This is not a simple stacking of drawings, but a logical alignment of multi-dimensional data—forcibly linking the "location" of assets, the "path" of business operations, and the "network" of protective measures. Through this "three-diagram integration," the subsequent evaluation process can intuitively see in a single view what kind of protective layer surrounds a core asset when it carries a specific business, thereby eliminating the long-standing information silos between asset management and security assessment.
[0041] In the final assessment phase, the system uses a database of protected objects as a benchmark, defining which assets and channels must be protected under compliance requirements. By automatically comparing the measured status in the overlay diagram with this benchmark, it can accurately identify risk points that should be protected but are not. It not only distinguishes between cryptographic protection measures (such as encryption and digital signatures) and non-cryptographic protection measures (such as access control and isolation), but also directly identifies protection vacuums through comparison results, ultimately outputting a high-confidence security assessment result based on "real-world flow" rather than "static ledgers."
[0042] In one feasible implementation, step S10 includes steps A10 to A30: Step A10: Collect data and compile an asset list for the target network space to be detected.
[0043] Step A20: Verify and supplement the asset list by using at least one of the following methods: active scanning, passive monitoring, and / or cloud-based synchronous comparison, to determine the cyberspace asset information; Step A30: Draw the network asset topology map based on the network space asset information.
[0044] Step S20 includes steps B10 to B80: Step B10: Based on the asset list, identify the core network assets, label the data source, destination, processing node and transmission direction, and construct a business data flow diagram.
[0045] Step B20 involves determining the data flow path by deploying at least one of the following methods: traffic analysis probes, host-level monitoring, and / or database audit log analysis.
[0046] Step B30: Integrate the business data flow diagram and the data flow path to generate a business data flow diagram.
[0047] Step B40: Identify all network security-related devices in the target cyberspace.
[0048] Step B50 involves configuring and analyzing the access control policies, encryption and authentication configurations, and auditing policies of the network security-related devices. Step B60: Utilize traffic mirroring and authorization testing methods to analyze the configuration of security protocol interactions, verify the authenticity of certificate exchange and key negotiation processes, and determine the deployment location and action path of security-related control policies. Step B70: Simulate malicious requests or authentication failures to track the flow logic and lifecycle of alarm logs and audit records in the encryption system; Step B80: Draw a protection measure flow diagram containing nodes for the generation, transmission, storage, and consumption of security data; overlay the protection measure flow diagram with the business data flow diagram to determine the protection measures for each link of the business data flow; and generate a data flow diagram containing the business data flow path and the protection measure data flow path.
[0049] Step S40 includes steps C10 to C20: Step C10: Based on the overlay graph, determine the association between the protection measures and the protected cyberspace assets in the target cyberspace, and determine the actual protection status of the protected cyberspace assets; the actual protection status includes no protection status, no password protection status, and password protection status.
[0050] Step C20: Compare the actual protection status with the database of objects to be protected to determine the objects to be protected that are in a non-password protected state or an unprotected state.
[0051] Step S50 includes steps D10 to D20: Step D10: If the object to be protected is in an unprotected state, output that there is a security problem.
[0052] Step D20: If the object to be protected is in a non-password protected state, then perform a mechanism analysis on the protection measures for the object to be protected, determine and output the risk level of the current protection measures.
[0053] Specifically, this implementation method, within the overall framework of the solution, strengthens the data foundation during the asset detection phase by adopting a logic of reconciliation before implementation. First, an asset list is created through data identification. Then, a multi-source fusion approach is employed, utilizing active scanning to acquire fingerprints, passive listening to capture active heartbeats, and cloud-based synchronization of logical resources, to verify and dynamically supplement the list in real time. This process not only eliminates information lag but also creates a network asset topology map based on the identified asset attributes, visually demonstrating the physical and logical connections between assets and providing a spatially relevant reference system for subsequent in-depth analysis.
[0054] The data flow identification process achieves a comprehensive reconstruction from path to logic through a dual-driven model of business modeling and security mapping. At the business level, traffic analysis probes and host-level monitoring technology are used to track end-to-end interactions between core assets, concretizing the abstract data flow into a business data flow graph that includes source, destination, and processing nodes. At the security level, the solution deeply analyzes the configuration of network security-related devices, uses traffic mirroring to verify the authenticity of certificate exchange and key negotiation, and simulates the flow cycle of abnormal behavior tracking alarm logs. This dual-flow parallel analysis approach ultimately overlays the node information of security data (policies, keys, logs, etc.) onto the business path, generating a data flow graph with deep defense awareness.
[0055] The overlay analysis phase is the core logical step in identifying protection vacuums. Based on the aforementioned overlay diagram, the algorithm automatically analyzes the mapping relationship between protection measures and various asset nodes, thereby pinpointing the actual protection status of the assets. This status is finely divided into no protection, non-cryptographic protection (such as simple firewall filtering), and cryptographic protection (such as encryption using national cryptographic algorithms). By automatically comparing these real-time perceived statuses with a database of protected objects under compliance benchmarks, the system can quickly locate those protected objects that are in a state of protection deficiency or degraded protection measures, realizing the correlation transformation of security vulnerabilities from discrete points to logical chains.
[0056] In the final risk output stage, the solution introduces a deep analysis mechanism based on compensatory controls. If an identified object requiring protection is completely unprotected, it is judged as a high-risk security vulnerability and directly output. For objects not protected by cryptography, the solution does not treat them all the same, but rather uses a mechanism analysis to assess whether existing protection measures (such as network isolation and access control policies) can partially mitigate the risks caused by the lack of cryptographic technology. Through this qualitative and quantitative analysis of protection effectiveness, the system can scientifically determine and output the risk level of current protection measures, providing decision support for subsequent refined testing or reinforcement implementation.
[0057] Overall, this implementation method transforms the previously fragmented tool detection into a logically self-consistent evaluation system through a pipeline operation of "topology base - dual-stream modeling - overlay comparison - hierarchical judgment". It not only solves the problem of assets being "unseen", but also achieves a precise profile of the compliance and security status of cryptographic applications through in-depth deconstruction of business and protection measures.
[0058] To better understand this application, a complete implementation example is provided below to illustrate this application in detail.
[0059] For example, for the detection targets that can collect cyberspace assets, data is collected, an asset list is compiled, tools are used to implement the list content one by one within the network boundary, and a network topology map is drawn, including a visual display of assets and their logical / physical connections, detailed attributes of all assets, tags and core libraries of related relationships, etc.
[0060] Establish the objects that should be protected, such as servers, communication channels, application systems, and stored data.
[0061] Subsequently, a multi-source fusion technology stack of "active scanning + passive monitoring + cloud log / API integration" was adopted. Among them, the need for "cloud log / API integration" was determined based on the actual situation of the object being inspected.
[0062] Proactive Probeing: Perform full port scans using detection tools to identify open ports and basic service fingerprints. With authorization, use scanners to log in to assets using configured credentials to obtain more detailed system information, installed software lists, and precise vulnerability information. Use detection tools to perform deep crawling and vulnerability detection on websites and APIs. Specifically identify industrial control protocols (such as S7 and Modbus) and Internet of Things (IoT) protocols (such as MQTT and CoAP).
[0063] Passive monitoring: Deploy probes on core switches to automatically discover active assets, services, and their communication relationships by analyzing network traffic. Collect DNS resolution logs and web proxy logs to discover internal and external assets accessed via domain names.
[0064] Cloud and Configuration Management Library Integration: Automatically synchronizes asset information such as cloud hosts, storage, databases, and load balancers by calling cloud APIs. Interacts with existing configuration management databases or IT service management systems to obtain official asset ledgers and compare them for verification, identifying "shadow assets." Matches scan results with a robust fingerprint database to accurately identify asset types, manufacturers, models, version numbers, and component information. Collects logs and backup data of the inspected objects; analyzes these logs and backup data to conduct cyberspace asset detection.
[0065] Finally, through data identification and tool detection, a network asset topology diagram can be output, including a visual representation of assets and their logical and physical connections. This includes a core dynamic asset database containing detailed attributes, tags, and relationships of all assets, as well as an asset list and risk assessment report categorized by type, along with risk levels, vulnerability details, and remediation suggestions.
[0066] Data flows are divided into business data flows and protection data flows. Business data flows include application data that carries core business functions (such as user requests, transaction instructions, production data, and management information), end-to-end flow paths in the network, logical relationships, and key nodes.
[0067] The protection measures data flow includes the flow path and mechanism of security data (such as certificate exchange, authentication tokens, key negotiation, audit logs, and alarm information) generated by various security technical measures (such as encryption, authentication, access control, and auditing) deployed to ensure the security of business data flow.
[0068] First, collect business descriptions to determine the business data flow. This mainly includes functional introductions and protection measures. Based on these, execute the functions separately and use tools to test them, ultimately determining the accurate business data flow and protection measure data flow. A methodology of "business-driven, dual-flow parallel, dynamic and static combination" is adopted. Starting with the core business process, the generation, transmission, processing, and destruction of data are tracked. The business flow and its corresponding security protection measure flow are analyzed simultaneously to clarify "where the data is" and "how to protect it." Static configuration analysis and dynamic traffic capture are combined to ensure the completeness and accuracy of the identification. Passive methods such as traffic mirroring and log querying are prioritized, supplemented by authorized active probing when necessary.
[0069] Business data flow identification process: Phase 1: Preparation and Modeling Asset and Relationship Analysis: Based on the asset list, identify core assets such as critical business application servers, databases, and API gateways.
[0070] Business interviews and document analysis: Communicate with business, R&D, and operations teams to understand core business scenarios (such as user login, order submission, and document approval), and obtain architecture diagrams, API documentation, and deployment instructions.
[0071] Establish an initial data flow model: Draw a high-order business data flow diagram, and label the preset data source, destination, processing node and transmission direction.
[0072] Phase Two: Dynamic Discovery and Validation Network traffic analysis: Deploy traffic analysis probes on critical links (such as core switches, DMZ boundaries, and application server front-ends) to capture real traffic. Use tools such as Wireshark to analyze TCP / IP sessions and identify major communication pairs, application layer protocols, API endpoints, and data interaction patterns.
[0073] Host / Application Layer Monitoring: Under authorized access, monitor active connections and listening ports using critical server commands. Analyze web server access logs and application logs to reconstruct the user request and backend service call chain. Database Audit Log Analysis: Examine database audit logs to identify access sources, operation types, and target tables, and pinpoint data aggregation points.
[0074] Phase Three: Integration and Mapping Data stream synthesis: Compare, correct, and refine the dynamic findings with the initial model.
[0075] Draw a detailed data flow diagram: Use drawing tools to clearly label the data. Data entities: users, clients, services, databases.
[0076] Flow and Protocol: Lines with arrows indicate the protocol / port (e.g., HTTPS / 443 → API Gateway).
[0077] Data nature: It can be marked that the transmitted data is personal information, transaction records, or configuration data.
[0078] Critical Path: Highlights the complete path of the core business transaction.
[0079] Protection measures data stream identification process Phase 1: Strategy and Configuration Audit Security Equipment / Software List: Identify and list all network security equipment (firewalls, WAFs, IDS / IPS, VPN gateways), cryptographic devices (server cryptographic machines, digital certificate systems), identity management (IAM / AD), auditing platforms, etc.
[0080] Configuration Analysis: Access Control Policies: Analyze the policy rules of firewalls, WAFs, and API gateways to clarify the paths and conditions for allowing / denying traffic.
[0081] Encryption and authentication configuration: Check VPN configuration (IPsec / SSL), web server TLS / SSL configuration (certificate, protocol version, cipher suite), and application system authentication methods (password, token, digital certificate, biometrics).
[0082] Audit strategy: Check the audit log configuration and centralized forwarding path (such as Syslog → SIEM) of each device, operating system, and database.
[0083] Phase Two: Dynamic Interaction and Effect Verification Security protocol interaction analysis: Decrypt or analyze HTTPS / TLS handshake traffic (if a pre-configured key is available) to verify certificate exchange and key negotiation processes. Analyze the interaction flow of VPN tunnel establishment traffic and authentication protocols.
[0084] Protection measure trigger testing (conducted cautiously and with authorization): Simulate malicious requests to verify whether the WAF and IDS generate alarm logs, and trace the flow of these logs (e.g., Console → Syslog Server → SIEM). Test the authentication failure process and trace the audit records generated by the authentication system.
[0085] Key and Certificate Flow Analysis: Identify the application, issuance, deployment, and update processes of digital certificates; analyze the data flow of key generation, distribution, storage, use, and destruction in the encryption system.
[0086] Phase 3: Mapping and Association Draw a protection measure flow diagram: Independently draw a diagram of the nodes for the generation, transmission, storage, and consumption of security data (policies, certificates, keys, logs, alarms).
[0087] Dual-flow correlation analysis: Overlay the protection measures flow diagram onto the business data flow diagram to clearly indicate which protection measures (such as "two-way TLS authentication + dynamic token") are injected at which stage of the business flow (such as the "user login" stage).
[0088] How security incident data (such as attack alerts) flows from the detection point to the analysis and response center.
[0089] Based on the above operations, the following can be output: a detailed business data flow diagram and explanation; a detailed protection measure data flow diagram and explanation; and a correlation and comparison analysis table / graph, which visually displays the security control measures corresponding to each key business link and their effectiveness status.
[0090] After completing the above steps, the topology map formed by network space asset surveying and detection and the data flow map formed by data flow identification are overlaid to create a comprehensive map covering network space assets, business data flow, and protection measure data flow, which is called the overlay map, along with corresponding explanations.
[0091] The overlay diagram outlines the protection measures, including cryptographic protection products and technologies, as well as non-cryptographic protection products and technologies. It also establishes the correspondence between each protection measure and the protected cyberspace assets, including protection measures for communication channels.
[0092] Based on the results of the password identification steps, the system outputs protected objects without any protection measures and protected objects without password protection measures. These are then compared with the protected objects identified based on cyberspace assets. Objects that should be protected but lack protection measures are identified as having security issues. Further security checks are then performed on objects that should be protected but lack password protection measures.
[0093] For measures without password protection, the mechanism of the measures is analyzed to determine whether the severity of the lack of password protection measures can be reduced, and the judgment result is output.
[0094] For systems where the security and compliance of password protection measures are satisfactory, a rapid test can be performed, the above test results output, and the test ends. If further, more accurate testing is required, or if there are doubts about the security and compliance of password protection measures, then more detailed testing should be conducted.
[0095] Check the compliance documentation for password protection measures. Non-compliance indicates a security issue with the output.
[0096] Check the configuration information of password protection measures and assess compliance and security through cryptographic technology standards and common security vulnerability databases.
[0097] Based on the business functions, business data flow, and protection measure data flow, design a test plan and conduct testing. For those that fail to correctly implement encryption protection and security authentication, identify security issues.
[0098] For cryptographic algorithms, protocols, products, or modules for which there are no cryptographic standards, design test plans based on their design schemes, conduct tests, output test correctness results, and identify any security issues.
[0099] In another example, consider a scenario where passwords are used to protect network and data security. To evaluate the effectiveness of password protection for network and data security, it's necessary to collect system data, conduct usage and security requirements analysis, and then test and evaluate the protection effectiveness of the corresponding network space assets. The evaluation typically involves the following steps: 1. Manually verifying network space assets based on available data. This method is inefficient and may miss some assets. 2. Based on available data, creating task cases, running the system, conducting packet capture analysis and monitoring production logs, and checking each asset for password protection. 3. Verifying the password algorithms, protocols, and certificates in the captured data to ensure compliance and correctness. 4. Checking the correctness and compliance of password configurations. 5. Repeating the above steps in the next round of evaluation.
[0100] In yet another example, based on scenario data and requirements analysis, a network topology diagram and data flow diagram are drawn, such as... Figure 2 As shown.
[0101] Active scanning tools can be installed on the device side, and passive monitoring tools can be deployed on the core router to proactively discover cyberspace assets and monitor them. Figure 2 Make corrections. Using the password-related information obtained from the deployed tools, verify the password application information in the scenario documentation to quickly determine consistency and actual application status. Figure 2 Based on this, cryptographic-related information, such as cryptographic devices and the protection of channels by cryptography, is drawn into... Figure 3 .
[0102] pass Figure 2 and Figure 3 By comparing data, the system directly determines whether each cyberspace asset is password protected, and automatically analyzes the compliance and correctness of the passwords used based on data acquired through active scanning and passive monitoring. A rapid evaluation report is then generated.
[0103] For non-standardized assets, or in other situations, a detailed assessment can be conducted for a specific asset. For example, regarding... Figure 2 To determine whether important data stored on the database server is encrypted, the following steps can be taken: Analyze whether cryptographic devices are used for protection; check if the cryptographic device configuration is compliant and correct; compile task data for storage and check if it has been converted from plaintext to ciphertext; perform encryption and decryption analysis on the ciphertext to determine if the cryptographic algorithm used is compliant and correct; and output an evaluation report. The next round of evaluation can quickly and automatically repeat the above steps.
[0104] It should be noted that the above examples are only for understanding this application and do not constitute a limitation on the network and data security detection method of this application. Any simple modifications based on this technical concept are within the protection scope of this application.
[0105] This application also provides a network and data security detection device; please refer to [reference needed]. Figure 4 Network and data security detection devices include: The asset detection module 10 is used to detect assets in the target network space, identify network space asset information, and generate a network asset topology map.
[0106] The identification module 20 is used to identify data flow in the target network space, identify business data flow and protection measure data flow, and generate a data flow diagram containing business data flow path and protection measure data flow path.
[0107] The overlay module 30 is used to overlay the network asset topology map with the data flow map to generate an overlay map. The overlay map is used to show the correspondence between network space asset information, business data flow and protection measure data flow.
[0108] The comparison module 40 is used to sort out the password protection measures and non-password protection measures corresponding to each asset node, and compare them with the preset database of objects to be protected to determine the comparison results.
[0109] Output module 50 is used to identify unprotected or password-free risk points and output security assessment results.
[0110] The network and data security detection device provided in this application, employing the network and data security detection method described in the above embodiments, can solve the technical problem that related technologies cannot quickly evaluate the effectiveness of cryptography in protecting network and data security. Compared with related technologies, the beneficial effects of the network and data security detection device provided in this application are the same as those of the network and data security detection method provided in the above embodiments, and other technical features in the network and data security detection device are the same as those disclosed in the methods of the above embodiments, and will not be repeated here.
[0111] This application provides a network and data security detection device, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the network and data security detection method described in the above embodiments.
[0112] The following is for reference. Figure 5This document illustrates a structural diagram of a network and data security detection device suitable for implementing embodiments of this application. The network and data security detection device in the embodiments of this application may include, but is not limited to, mobile terminals such as mobile phones, laptops, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Portable Application Description), PMPs (Portable Media Players), in-vehicle terminals (e.g., in-vehicle navigation terminals), and fixed terminals such as digital TVs and desktop computers. Figure 5 The network and data security detection device shown is merely an example and should not impose any limitations on the functionality and scope of application of the embodiments of this application.
[0113] like Figure 5 As shown, the network and data security detection device may include a processing unit 1001 (e.g., a central processing unit, a graphics processing unit, etc.), which can perform various appropriate actions and processes according to a program stored in the read-only memory 1002 (ROM) or a program loaded from the storage device 1003 into the random access memory 1004 (RAM). The random access memory 1004 also stores various programs and data required for the operation of the instructional video generation device. The processing unit 1001, the read-only memory 1002, and the random access memory 1004 are interconnected via a bus 1005. An input / output interface 1006 (I / O interface) is also connected to the bus 1005. Typically, the following systems can be connected to the input / output interface 1006: input devices 1007 including, for example, a touchscreen, touchpad, keyboard, mouse, image sensor, microphone, accelerometer, gyroscope, etc.; output devices 1008 including, for example, a liquid crystal display (LCD), speaker, vibrator, etc.; storage devices 1003 including, for example, magnetic tape, hard disk, etc.; and communication devices 1009. Communication device 1009 allows the instructional video generation device to communicate wirelessly or wiredly with other devices to exchange data. Although instructional video generation devices with various systems are shown in the figure, it should be understood that it is not required to implement or possess all the systems shown. More or fewer systems can be implemented alternatively.
[0114] Specifically, according to the embodiments disclosed in this application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments disclosed in this application include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication device, or installed from storage device 1003, or installed from ROM 1002. When the computer program is executed by processing device 1001, it performs the functions defined in the methods of the embodiments disclosed in this application.
[0115] The network and data security testing device provided in this application, employing the network and data security testing method described in the above embodiments, can solve the technical problem that related technologies cannot quickly evaluate the effectiveness of cryptography in protecting network and data security. Compared with related technologies, the beneficial effects of the network and data security testing device provided in this application are the same as those of the network and data security testing method provided in the above embodiments, and other technical features in this network and data security testing device are the same as those disclosed in the previous embodiment method, and will not be repeated here.
[0116] It should be understood that the various parts disclosed in this application can be implemented using hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics can be combined in any suitable manner in one or more embodiments or examples.
[0117] The above are merely specific embodiments of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
[0118] This application provides a computer-readable storage medium having computer-readable program instructions (i.e., a computer program) stored thereon, the computer-readable program instructions being used to execute the network and data security detection methods described in the above embodiments.
[0119] The computer-readable storage medium provided in this application may be, for example, a USB flash drive, but is not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or any combination thereof. More specific examples of computer-readable storage media may include, but are not limited to: electrical connections having one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this embodiment, the computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, system, or device. The program code contained on the computer-readable storage medium may be transmitted using any suitable medium, including but not limited to: wires, optical cables, RF (Radio Frequency), etc., or any suitable combination thereof.
[0120] The aforementioned computer-readable storage medium may be included in network and data security testing equipment; or it may exist independently and not be assembled into network and data security testing equipment.
[0121] The aforementioned computer-readable storage medium carries one or more programs. When these programs are executed by the network and data security detection device, the network and data security detection device performs the following actions: asset detection of the target network space, identifies network space asset information, and generates a network asset topology map; data flow identification of the target network space, identifies business data flows and protection measure data flows, and generates a data flow map containing business data flow paths and protection measure data flow paths; overlays the network asset topology map with the data flow map to generate an overlay map, which is used to display the correspondence between network space asset information, business data flows, and protection measure data flows; based on the overlay map, it sorts out the cryptographic and non-cryptographic protection measures corresponding to each asset node and compares them with a preset database of objects to be protected to determine the comparison results; based on the comparison results, it identifies risk points without protection or cryptographic protection and outputs security assessment results.
[0122] Computer program code for performing the operations of this application can be written in one or more programming languages or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, and C++, and conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a Local Area Network (LAN) or a Wide Area Network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0123] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.
[0124] The modules described in the embodiments of this application can be implemented in software or hardware. The names of the modules do not necessarily limit the functionality of the unit itself.
[0125] The readable storage medium provided in this application is a computer-readable storage medium that stores computer-readable program instructions (i.e., computer programs) for executing the above-described network and data security detection methods. This solves the technical problem that related technologies cannot quickly evaluate the effectiveness of cryptography in protecting network and data security. Compared with related technologies, the beneficial effects of the computer-readable storage medium provided in this application are the same as those of the network and data security detection methods provided in the above embodiments, and will not be elaborated upon here.
[0126] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the steps of the network and data security detection method described above.
[0127] The computer program product provided in this application can solve the technical problem that related technologies cannot quickly evaluate the effectiveness of cryptography in protecting network and data security. Compared with related technologies, the beneficial effects of the computer program product provided in this application are the same as those of the network and data security detection methods provided in the above embodiments, and will not be repeated here.
[0128] The above are only some embodiments of this application and do not limit the patent scope of this application. All equivalent structural transformations made under the technical concept of this application and using the contents of the specification and drawings of this application, or direct / indirect applications in other related technical fields, are included in the patent protection scope of this application.
Claims
1. A network and data security detection method, characterized in that, The method includes: Perform asset detection on the target cyberspace, identify cyberspace asset information, and generate a network asset topology map; Data flow identification is performed on the target network space to identify business data flow and protection measure data flow, and a data flow graph containing business data flow paths and protection measure data flow paths is generated. The network asset topology map is overlaid with the data flow map to generate an overlay map, which is used to show the correspondence between network space asset information, business data flow and protection measure data flow; Based on the overlay diagram, the cryptographic and non-cryptographic protection measures corresponding to each asset node are sorted out and compared with the preset database of objects to be protected to determine the comparison results; Based on the comparison results, risk points that are unprotected or lack password protection are identified, and security assessment results are output.
2. The network and data security detection method as described in claim 1, characterized in that, The steps of asset detection in the target cyberspace, identifying cyberspace asset information and their connectivity relationships, and generating a network asset topology map include: For the targets in the target cyberspace, collect data and compile an asset list; The asset list is verified and supplemented by at least one of the following methods: active scanning, passive monitoring, and / or cloud-based synchronous comparison, to determine the cyberspace asset information; Based on the cyberspace asset information, a network asset topology map is drawn.
3. The network and data security detection method as described in claim 2, characterized in that, The steps of identifying data flow in the target network space, identifying business data flow and protection measure data flow, and generating a data flow graph containing business data flow paths and protection measure data flow paths include: Based on the asset list, identify the core network assets, label the data source, destination, processing node and transmission direction, and construct a business data flow diagram; Determine the data flow path by deploying at least one of the following methods: traffic analysis probes, host-level monitoring, and / or database audit log analysis; Integrate the business data flow diagram and the data flow path to generate a business data flow diagram.
4. The network and data security detection method as described in claim 3, characterized in that, The steps of identifying data flow in the target network space, identifying business data flow and protection measure data flow, and generating data flow graphs containing business data flow paths and protection measure data flow paths include: Identify all network security-related devices in the target cyberspace; The access control policies, encryption and authentication configurations, and audit policies of the aforementioned network security-related devices are configured and analyzed. By using traffic mirroring and authorization testing, the configuration and analysis of security protocol interactions are performed to verify the authenticity of certificate exchange and key negotiation processes and determine the deployment location and action path of security-related control policies. Simulate malicious requests or authentication failures to track the flow and lifecycle of alert logs and audit records within the encryption system; Draw a protection measure flow diagram containing nodes for the generation, transmission, storage, and consumption of security data. Overlay the protection measure flow diagram with the business data flow diagram to determine the protection measures for each link of the business data flow, and generate a data flow diagram containing the business data flow path and the protection measure data flow path.
5. The network and data security detection method as described in claim 1, characterized in that, The steps of sorting out the cryptographic and non-cryptographic protection measures corresponding to each asset node based on the overlay diagram, comparing them with a preset database of protected objects, and determining the comparison results include: Based on the overlay graph, the association between the protection measures and the protected cyberspace assets in the target cyberspace is determined, and the actual protection status of the protected cyberspace assets is determined; the actual protection status includes no protection status, no password protection status, and password protection status. The actual protection status is compared with the database of objects to be protected to determine the objects to be protected that are in a non-password protected state or an unprotected state.
6. The network and data security detection method as described in claim 5, characterized in that, The steps for identifying unprotected or password-free risk points based on the comparison results and outputting security assessment results include: If the object to be protected is in an unprotected state, then output that there is a security problem. If the object to be protected is in a non-password protected state, then the protection measures for the object to be protected are analyzed to determine and output the risk level of the current protection measures.
7. A network and data security detection device, characterized in that, The device includes: The asset detection module is used to detect assets in the target cyberspace, identify cyberspace asset information, and generate a network asset topology map. The identification module is used to identify data flow in the target network space, identify business data flow and protection measure data flow, and generate a data flow diagram containing business data flow paths and protection measure data flow paths. The overlay module is used to overlay the network asset topology map with the data flow map to generate an overlay map, which is used to show the correspondence between network space asset information, business data flow and protection measure data flow; The comparison module is used to sort out the password protection measures and non-password protection measures corresponding to each asset node, and compare them with the preset database of objects to be protected to determine the comparison results; The output module is used to identify unprotected or password-free risk points and output security assessment results.
8. A network and data security detection device, characterized in that, The device includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, the computer program being configured to implement the steps of the network and data security detection method as described in any one of claims 1 to 6.
9. A storage medium, characterized in that, The storage medium is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by a processor, it implements the steps of the network and data security detection method as described in any one of claims 1 to 6.
10. A computer program product, characterized in that, The computer program product includes a computer program that, when executed by a processor, implements the steps of the technical opportunity recommendation method as described in any one of claims 1 to 6.