Automated penetration testing system, method, and computer equipment for power grid systems
Through the automated penetration testing system of the power grid system, using information collection, penetration point detection and utilization modules and decision-making scheduling modules, combined with expert systems and knowledge graphs, the security risks and low detection efficiency of penetration testing tools in the power monitoring system are solved, and accurate judgment and efficient detection of security vulnerabilities in the power grid system are achieved.
Patent Information
- Application Number
- CN202111375110.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-11-17
- Publication Date
- 2025-09-12
- Estimated Expiration
- 2041-11-17
AI Technical Summary
Existing penetration testing tools pose security risks to power monitoring systems, have low detection efficiency, and require high professional capabilities from implementation personnel, making it difficult to accurately determine the location and type of security vulnerabilities in the target system.
An automated penetration testing system for power grid systems is provided, which includes an information collection module, a penetration point detection and utilization module, and a decision-making and scheduling module. It uses expert systems and knowledge graphs to perform correlation analysis, determine target penetration paths, and accurately determine the location and type of security vulnerabilities in power grid systems.
It improves the detection efficiency of penetration testing, shortens the detection time, reduces the false alarm rate, and improves the network security detection and protection level of the power monitoring system.
Smart Images

Figure CN114036059B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of power grid technology, and in particular to an automated penetration testing method, system, and computer equipment for a power grid system. Background Art
[0002] Penetration testing is a security testing and assessment method. It simulates real-world hacker attack scenarios, gains control of the target host, and identifies potential security vulnerabilities in the target, enabling timely countermeasures to be implemented, thereby improving system security. The penetration testing process typically involves proactive detection and analysis of the target system to uncover security vulnerabilities and vulnerability to social engineering tactics like phishing attacks. Penetration testing has become a component of overall system security assessments. For example, standards such as the Payment Industry Data Security Standard (PCIDSS) include penetration testing as a mandatory form of security testing.
[0003] The power monitoring system has high requirements for stable operation. Currently, there are many and diverse penetration testing tools on the market. Penetration testing tools are dangerous and may bring security risks to the target system. In addition, penetration testing requires high professional capabilities of the implementers and has the problem of low detection efficiency. Summary of the Invention
[0004] Based on this, it is necessary to provide an automated penetration testing method for the security of the power grid system to address the above technical problems, which can select POC detection with less impact on the business, and can accurately determine the location and type of security vulnerabilities in the target system, shorten the detection time, and improve the efficiency of vulnerability mining, an automated penetration testing system method, computer equipment, computer-readable storage medium and computer program product for the power grid system.
[0005] In a first aspect, the present application provides an automated penetration testing system for power grid systems. The system includes an information collection module, a penetration point detection and utilization module, and a decision-making and scheduling module, wherein:
[0006] The information collection module is used to collect information about the target system and obtain basic information about the target system;
[0007] The penetration point detection and exploitation module is used to detect penetration entrances and exploit penetration points of the target system based on the basic information, and obtain vulnerability verification and exploitation results of the target system;
[0008] The decision scheduling module is used to perform correlation analysis on the vulnerability verification and utilization results of the target system based on the constructed expert system and knowledge graph to determine the target penetration path.
[0009] In one embodiment, the penetration point detection and exploitation module includes a scanning detection module and a penetration point exploitation module, wherein:
[0010] The scanning detection module is used to perform at least one of port detection, WEB fingerprint detection, WEB path detection, heuristic crawler and middleware detection on the target system according to the basic information to obtain a detection result;
[0011] The penetration point utilization module is used to verify and exploit vulnerabilities of the target system based on the basic information and the detection results, and obtain corresponding vulnerability verification and utilization results.
[0012] In one embodiment, the decision scheduling module includes a permeation path determination module and a storage scheduling module, wherein:
[0013] The storage scheduling module is used to trigger the calling interface to obtain and store the vulnerability verification and exploitation results;
[0014] The penetration path determination module, based on the constructed expert system, associates the knowledge graph with the vulnerability verification and utilization results stored in the storage scheduling module, obtains the corresponding nodes in the knowledge graph, and determines the target penetration path according to the association weights between the nodes.
[0015] In one embodiment, the system further includes a graph construction module, wherein the graph construction module
[0016] Used to collect software information, hardware information, known software and hardware vulnerability information, and attack information based on various known vulnerabilities used in the target network;
[0017] Entity extraction, relationship extraction and attribute extraction are performed on the software information, hardware information, vulnerability information and attack information, and a knowledge graph is determined based on the obtained association relationships.
[0018] In one embodiment, the system further includes a penetration testing module, wherein the penetration testing module is configured to perform a post-penetration test on the target system according to the target penetration path and generate a penetration testing report.
[0019] In one embodiment, the system further includes a data display module, and the data display module is used to display the target penetration path and the penetration test report.
[0020] In a second aspect, the present application also provides an automated penetration method for a power grid system. The method comprises:
[0021] Collect information on the target system to be infiltrated to obtain basic information about the target system;
[0022] Perform penetration entry detection and penetration point exploitation on the target system based on the basic information to obtain vulnerability verification and exploitation results of the target system;
[0023] Based on the constructed expert system and knowledge graph, the vulnerability verification and utilization results of the target system are correlated and analyzed to determine the target penetration path.
[0024] In a third aspect, the present application further provides a computer device. The computer device includes a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, the following steps are performed:
[0025] Collect information on the target system to be infiltrated to obtain basic information of the target system; detect infiltration entrances and exploit infiltration points on the target system based on the basic information to obtain vulnerability verification and exploitation results of the target system;
[0026] Based on the constructed expert system and knowledge graph, the vulnerability verification and utilization results of the target system are correlated and analyzed to determine the target penetration path.
[0027] In a fourth aspect, the present application further provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the following steps:
[0028] Collect information on the target system to be infiltrated to obtain basic information of the target system; detect infiltration entrances and exploit infiltration points on the target system based on the basic information to obtain vulnerability verification and exploitation results of the target system;
[0029] Based on the constructed expert system and knowledge graph, the vulnerability verification and utilization results of the target system are correlated and analyzed to determine the target penetration path.
[0030] In a fifth aspect, the present application further provides a computer program product. The computer program product includes a computer program that, when executed by a processor, implements the following steps:
[0031] Collect information on the target system to be infiltrated to obtain basic information of the target system; detect infiltration entrances and exploit infiltration points on the target system based on the basic information to obtain vulnerability verification and exploitation results of the target system;
[0032] Based on the constructed expert system and knowledge graph, the vulnerability verification and utilization results of the target system are correlated and analyzed to determine the target penetration path.
[0033] The above-mentioned automated penetration system, method, computer equipment, storage medium and computer program product for power grid systems determine the target system to be penetrated and collect basic information of the target system; based on the collected information, the target system is penetrated by detecting penetration entrances and utilizing penetration points, and deep penetration is achieved based on the constructed expert system and knowledge graph. According to the determined target penetration path, the location and type of security vulnerabilities in the target system are more accurately determined, thereby shortening the detection time, thereby improving the efficiency of vulnerability mining and reducing the false alarm rate. BRIEF DESCRIPTION OF THE DRAWINGS
[0034] Figure 1 A schematic diagram of an automated penetration testing system for a power grid system according to an embodiment;
[0035] Figure 2 A schematic diagram of an automated penetration testing system for a power grid system in another embodiment;
[0036] Figure 3 This is an architecture diagram of an automated penetration testing system platform for a power grid system in one embodiment;
[0037] Figure 4 1 is a flow chart of an automated penetration testing method for a power grid system according to an embodiment;
[0038] Figure 5 FIG. 1 is a diagram showing the internal structure of a computer device in one embodiment. DETAILED DESCRIPTION
[0039] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.
[0040] In one embodiment, Figure 1 As shown, an automated penetration system for a power grid system is provided, the system comprising an information collection module, a penetration point detection and utilization module, and a decision-making and scheduling module, wherein:
[0041] The information collection module is used to collect information about the target system to be infiltrated and obtain basic information about the target system.
[0042] The basic information includes at least one of domain name information, host information, host survival status, operating system type and version information, etc.
[0043] The penetration point detection and utilization module is used to detect penetration entry points and utilize penetration points of the target system to obtain vulnerability verification and utilization results of the target system.
[0044] The resource layer also includes a penetration point detection and exploitation module. Penetration entry point detection includes port detection, web fingerprint detection, web path detection, heuristic crawlers, and middleware detection. Port detection involves probing the target system's ports to obtain information about open ports and identify the corresponding services and versions. Web fingerprint detection involves loading relevant plug-ins to identify web page keywords, specific file MD5 comparisons, specified URL keywords, and the tag pattern of specified URLs to identify the current web application and its version.
[0045] Through the WEB path detection module, it is a security testing tool used to discover sensitive directories and content of the website, and to perform detection by analyzing the server's response; through the heuristic crawler, it performs task scheduling and event management, and can first preload the target interface, wait in the network idle state, hijack the website content, jump to the page or close the interception, etc.; through the middleware identification detection function, it can discover and identify the middleware used by the target system.
[0046] Penetration point exploitation refers to the targeted vulnerability verification and exploitation of the target system based on the penetration point exploitation functional framework, the basic information collected, and scanning detection. The penetration point exploitation functional framework includes common OWASP general vulnerability categories, including injection vulnerabilities, security configuration error vulnerabilities, invalid access control vulnerabilities, invalid authentication vulnerabilities, XML external entity reference vulnerabilities, deserialization vulnerabilities, cross-site scripting vulnerabilities, sensitive data exposure, etc. Common component vulnerability categories include: Aix class, Arm class, Webapps class, Local class, Beos class, Bsd class, Remote class, Cfm class, Cgi class, operating system class, language script class, etc., as well as vulnerabilities targeting power system professional equipment (including but not limited to common power system professional equipment vulnerabilities).
[0047] Specifically, the scanning detection module in the penetration point detection and utilization module is used to perform at least one of port detection, WEB fingerprint detection, WEB path detection, heuristic crawler and middleware detection on the target system according to the basic information to obtain the detection result; the penetration point utilization module is used to perform vulnerability verification and exploitation on the target system according to the basic information and the detection result to obtain the corresponding vulnerability verification and utilization result.
[0048] The decision scheduling module is used to perform correlation analysis on the vulnerability verification and utilization results of the target system based on the constructed expert system and knowledge graph to determine the target penetration path.
[0049] The expert system includes correlation decision-making and an expert database. Correlation decision-making involves linking collected information and current status with the knowledge graph to determine and analyze the correlations between the information. The expert database includes reasoning analysis and infiltration experience decision-making. Reasoning analysis infers infiltration strategies based on correlations within the knowledge graph, and then conducts in-depth analysis based on infiltration experience to determine the most likely next infiltration path. The expert system is a decision-making model trained using historical infiltration experience data.
[0050] A knowledge graph is a semantic network that displays the relationships between entities and provides a formal description of real-world objects and relationships. A knowledge graph is generally represented by a triple: D = (E, R, S), where D represents the knowledge base; E represents the set of entities in D; R represents the set of relationships in D; and S identifies attribute values. There are a total of |R| different relationships in the relationship set. The basic forms of a triple are mainly <concept, attribute, attribute value> and <entity 1, relationship, entity 2>. Entities are the most basic elements in D, and different entities have different relationships. Concepts mainly include categories of things, object types, and collections, such as place names and people; attributes mainly refer to the characteristics and features that an object may have, such as birthplace and date of birth; and attribute values are mainly the values of attributes specified by entities or relationships, such as Beijing. Each entity can be identified by a globally unique ID. Each attribute and attribute value can be used to describe the intrinsic characteristics of the entity. Relationships connect two entities to indicate the relationship between them.
[0051] Specifically, according to the storage scheduling module in the decision scheduling module, the calling interface is triggered to obtain and store the vulnerability verification and utilization results; through the penetration path determination module, based on the constructed expert system, the knowledge graph is associated with the vulnerability verification and utilization results stored in the storage scheduling module to obtain the corresponding nodes in the knowledge graph, and the target penetration path is determined according to the association weights between the nodes.
[0052] The above-mentioned automated penetration system for power grid systems determines the target system to be penetrated in the power grid system, and collects at least one of the domain name information, host information, host survival status, operating system type and version information of the target system; detects penetration entries and exploits penetration points of the target system based on the collected information, and achieves in-depth penetration based on the constructed expert system and knowledge graph, and more accurately determines the location and type of security vulnerabilities in the target system based on the determined target penetration path, shortens the detection time, and thus improves the efficiency of vulnerability mining, reduces the false alarm rate, and further improves the network security detection and protection level of the power monitoring system.
[0053] In another embodiment, Figure 2As shown, an automated penetration system for power grid systems is provided, which includes an information collection module, a penetration point detection and utilization module, a decision-making scheduling module, a penetration testing module and a data display module, wherein the penetration point detection and utilization module includes a scanning detection module and a penetration point utilization module, and the decision-making scheduling module includes a penetration path determination module and a storage scheduling module.
[0054] The storage scheduling module is used to trigger the calling interface, obtain the vulnerability verification and utilization results and store them.
[0055] The penetration path determination module, based on the constructed expert system, associates the knowledge graph with the vulnerability verification and exploitation results stored in the storage scheduling module to obtain corresponding nodes in the knowledge graph, and determines the target penetration path based on the association weights between the nodes. In other words, based on the constructed expert system, the knowledge graph is associated with the vulnerability verification and exploitation results stored in the storage scheduling module to obtain corresponding nodes in the knowledge graph, different penetration test paths are determined based on each node, the weight values between each node are calculated, and the optimal penetration path, i.e., the target penetration path, is determined from the determined different penetration test paths based on the weights between the nodes.
[0056] The penetration testing module is used to perform a post-penetration test on the target system according to the target penetration path and generate a penetration testing report.
[0057] Among them, when conducting post-penetration testing on the target system according to the target penetration path, verification code recognition, crawling page classification, web fingerprint recognition, and generation of WEB vulnerability attack packages are performed, and a penetration test report is generated. Among them, verification code recognition is implemented based on the neural network. Verification code recognition is performed through the trained neural network to avoid the problem of overlapping or connected characters in the verification code that cannot be verified when the user performs operations such as login blasting; the accuracy of verification code recognition is improved.
[0058] Web fingerprint recognition is achieved through the k-nearest neighbor algorithm. When obtaining the web fingerprint of the target system, the corresponding head package content, partial website structure information, web page content and other related environmental information are extracted, and compared with the characteristic information of the known site (i.e., the website) (including head package content, partial website structure, web page content and other related environmental information, as well as the corresponding CMS type or web service component of each), and the difference between the two is calculated. The CMS type or web service component of the target system is determined based on the CMS type or web service component corresponding to the n data with the smallest relative difference value; the web fingerprint recognition has a higher recognition ability for websites that have erased key information, and has a certain recognition anti-interference ability.
[0059] Crawling page classification, obtaining link pages obtained by crawlers, analyzing the relevant information of the link pages, extracting features, and using the k-means clustering algorithm to determine the label based on the calculated distance from different cluster centers, determine the category to which the link page belongs; it can classify a large number of crawler results quickly and accurately, and can quickly find different attack surfaces.
[0060] Generate a WEB vulnerability attack package, that is, extract features from the request package crawled by the crawler to obtain feature data; determine the variable name that needs to be modified based on the feature data, and obtain the label of the request package; input the classification model established based on random forest according to the features, feature values and corresponding labels of the request package for training. After the training is completed, the model obtained can be used to determine the label corresponding to the unknown message by extracting the message features, and generate the corresponding payload that can be used for attack; it can automatically generate the payload for attack according to the request sent by the crawler, realizing the ability to perform automated penetration testing during the crawling process
[0061] Specifically, the information collection module collects information about the target system to be infiltrated, and obtains basic information such as the target system's domain name information, host information, host survival status, operating system type and version information; the scanning detection module is used to perform at least one of port detection, WEB fingerprint detection, WEB path detection, heuristic crawler and middleware detection on the target system based on the basic information to obtain the detection results;
[0062] Through the penetration point utilization module, the vulnerability of the target system is verified and exploited according to the basic information and detection results, and the corresponding vulnerability verification and exploitation results are obtained; and the storage scheduling module triggers the call interface to obtain the vulnerability verification and exploitation results and store them; through the penetration path determination module, based on the constructed expert system, the knowledge graph is associated with the vulnerability verification and exploitation results stored in the storage scheduling module to obtain the corresponding nodes in the knowledge graph, and the target penetration path is determined according to the association weights between the nodes; the target system is post-penetration tested according to the target penetration path, and a penetration test report is generated, and the penetration test report is displayed through the data display module.
[0063] Furthermore, the automated penetration system for power grid systems also includes a graph construction module, which is used to construct a knowledge graph. This knowledge graph construction involves information acquisition and graph construction. Information acquisition involves extracting information about software and hardware, known vulnerabilities in the target network, and attack information about known software and hardware vulnerabilities. Graph construction involves extracting entities, relationships, and attributes from these software, hardware, vulnerability, and attack information, and then determining a knowledge graph based on the resulting relationships. Attribute extraction includes information about the software name and version, hardware manufacturer and model, vulnerability ID, and attack method, difficulty, and benefits. Relationship extraction includes the relationship between vulnerabilities and software and hardware, and the relationship between attack attributes and vulnerabilities.
[0064] The following is an architecture diagram of the automated penetration system platform in one embodiment. Figure 3 As shown in the figure, the architecture diagram includes a resource layer, a decision-making and scheduling layer, and a human-computer interaction layer. The human-computer interaction layer is used for data display and data interaction. Data display includes the display of task status, target basic information, and operation logs; data interaction includes the entry of penetration plans, tool entry, penetration configuration management, etc.
[0065] The decision-making and scheduling layer is used for analytical decision-making and storage scheduling; analytical decision-making refers to data decision-making and data storage for the collected data. Data decision-making includes penetration path planning and task status analysis operations, that is, decision reasoning, path planning and data analysis based on the constructed expert system and knowledge graph; scheduling includes the interface with the resource layer and calling the modules of the resource layer; data storage content includes penetration test results, penetration tasks, system logs, etc.
[0066] The expert system includes association decision-making and an expert database. Association decision-making involves associating collected information and the current state with the knowledge graph to determine and analyze the relevance of this information. The expert database includes reasoning analysis and penetration experience decision-making. Reasoning analysis infers penetration strategies based on the relevance of the knowledge graph, and then conducts in-depth analysis based on penetration experience to determine the most likely next penetration path.
[0067] Analysis and decision-making also include machine learning, which is used for CAPTCHA recognition in the login module, information classification, and intelligent generation of web exploit kits. CAPTCHA recognition uses a convolutional neural network to identify image CAPTCHAs during login. During penetration testing, collected information is classified using a classification algorithm to uncover attack surface information. Web exploit kits use pre-trained models to automatically and intelligently generate attack payloads based on crawler request packets.
[0068] The resource layer includes tool libraries, vulnerability libraries, penetration test solution libraries, penetration point utilization function frameworks, etc. Information collection and scanning detection are performed through the tool libraries to collect information such as the port service name, operating system type and version, system running services, open ports, etc. of the target system.
[0069] The penetration point utilization function framework is to conduct targeted vulnerability verification and exploitation on the target based on information collection and scanning detection, targeting OWASP common vulnerability classes, such as injection vulnerabilities, security configuration error vulnerabilities, invalid access control vulnerabilities, invalid authentication vulnerabilities, XML external entity reference vulnerabilities, deserialization vulnerabilities, cross-site scripting vulnerabilities, sensitive data exposure, etc.; targeting component vulnerability classes, such as Aix class, Arm class, Webapps class, Local class, Beos class, Bsd class, Remote class, Cfm class, Cgi class, operating system class, language script class, etc.; targeting power system professional equipment vulnerabilities (including but not limited to power operating system vulnerabilities and related web application vulnerabilities).
[0070] The above-mentioned automated penetration system for power grid systems determines the target system to be penetrated and collects information on the target system; it also detects penetration entries and exploits penetration points in the target system, and determines different penetration test paths based on the constructed expert system and knowledge graph, and determines the best penetration path based on the correlation weights between nodes, and completes the penetration test based on the best penetration path; based on the correlation between knowledge graph nodes, multiple low-risk vulnerabilities can be combined into high-risk vulnerabilities, realizing flexible adjustment of the penetration test process, improving the comprehensiveness of the penetration test, and more accurately judging the location and type of security vulnerabilities in the target system during the network information system penetration test, shortening the detection time, and reducing the false alarm rate.
[0071] Based on the same inventive concept, the embodiments of the present application also provide an automated penetration testing method for a power grid system for implementing the aforementioned automated penetration testing system for a power grid system. The implementation solution provided by this method is similar to the implementation solution described in the aforementioned system. Therefore, the specific limitations in one or more embodiments of the automated penetration testing method for a power grid system provided below can be found in the above-mentioned limitations on the automated penetration testing system for a power grid system, and will not be repeated here.
[0072] In one embodiment, Figure 4 As shown, an automated penetration method for a power grid system is provided. This embodiment uses the method applied to a terminal as an example for illustration. It is understandable that the method can also be applied to a server, or to a system including a terminal and a server, and implemented through the interaction between the terminal and the server. In this embodiment, the method includes the following steps:
[0073] Step 402: collect information about the target system to be infiltrated to obtain basic information about the target system.
[0074] The basic information includes at least one of the following information: host survival status, operating system type and version, system running services, open ports, etc.
[0075] Step 404: Detect penetration entry points and exploit penetration points of the target system based on the basic information to obtain vulnerability verification and exploitation results of the target system.
[0076] Specifically, based on the basic information, at least one of port detection, WEB fingerprint detection, WEB path detection, heuristic crawler and middleware detection is performed on the target system to obtain a detection result; based on the basic information and the detection result, vulnerability verification and exploitation are performed on the target system to obtain corresponding vulnerability verification and exploitation results.
[0077] Optionally, in one embodiment, at least one of port detection, WEB fingerprint detection, WEB path detection, heuristic crawler and middleware detection is performed on the target system based on the basic information to obtain a detection result; vulnerability verification and exploitation are performed on the target system based on the basic information and the detection result to obtain corresponding vulnerability verification and exploitation results.
[0078] Step 406: perform correlation analysis on the vulnerability verification and exploitation results of the target system based on the constructed expert system and knowledge graph to determine the target penetration path.
[0079] Specifically, by triggering the calling interface, the vulnerability verification and exploitation results are obtained and stored; through the penetration path determination module, based on the constructed expert system, the knowledge graph is associated with the vulnerability verification and exploitation results stored in the storage scheduling module to obtain the corresponding nodes in the knowledge graph, and the target penetration path is determined according to the association weights between the nodes; wherein, the target penetration path determined according to the association weights between the nodes can be, but is not limited to, the one with the largest weight.
[0080] Optionally, in one embodiment, the vulnerability verification and exploitation results are obtained and stored by triggering a call interface; based on the constructed expert system, the knowledge graph is associated with the vulnerability verification and exploitation results stored in the storage scheduling module to obtain corresponding nodes in the knowledge graph, and the target penetration path is determined based on the association weights between the nodes. The knowledge graph is constructed by extracting entities, relationships, and attributes from the software, hardware, vulnerability, and attack information of various known vulnerabilities used in the target network, and determining the target penetration path based on the resulting associations.
[0081] Optionally, in one embodiment, a post-penetration test is performed on the target system according to the target penetration path, and a penetration test report is generated.
[0082] Optionally, in one embodiment, the penetration test report and the target penetration path are displayed to facilitate intuitive acquisition of penetration test result data and penetration path.
[0083] In the above-mentioned automated penetration method for power grid systems, by determining the target system to be penetrated in the power grid system, information of the target system is collected, such as the host survival status, operating system type and version, system running services, open ports and other information; based on the collected information, the target system is penetrated by detection of penetration entrances and utilization of penetration points, and in-depth penetration is achieved based on the constructed expert system and knowledge graph. According to the determined target penetration path, the location and type of security vulnerabilities in the target system are more accurately judged, the detection time is shortened, and the efficiency of vulnerability mining is improved, the false alarm rate is reduced, and the network security detection and protection level of the power monitoring system is further improved.
[0084] It should be understood that, although the various steps in the flowcharts involved in the various embodiments described above are displayed in sequence according to the instructions of the arrows, these steps are not necessarily executed in sequence in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and these steps can be executed in other orders. Moreover, at least a portion of the steps in the flowcharts involved in the various embodiments described above can include multiple steps or multiple stages, and these steps or stages are not necessarily executed and completed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily to be carried out in sequence, but can be executed in turn or alternately with other steps or at least a portion of steps or stages in other steps.
[0085] Each module in the automated penetration system described above can be implemented in whole or in part through software, hardware, or a combination thereof. Each module can be embedded in or independent of a processor in a computer device in hardware form, or can be stored in a computer device's memory in software form, so that the processor can call and execute the corresponding operations of each module.
[0086] In one embodiment, a computer device is provided. The computer device may be a terminal, and its internal structure diagram may be as follows: Figure 5 As shown. The computer device includes a processor, memory, communication interface, display screen and input system connected via a system bus. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and computer program in the non-volatile storage medium. The communication interface of the computer device is used to communicate with an external terminal in a wired or wireless manner, and the wireless manner can be achieved through WIFI, mobile cellular network, NFC (near field communication) or other technologies. When the computer program is executed by the processor, an automated penetration method for a power grid system is implemented. The display screen of the computer device can be a liquid crystal display screen or an electronic ink display screen, and the input system of the computer device can be a touch layer covering the display screen, or a button, trackball or touchpad provided on the computer device housing, or an external keyboard, touchpad or mouse.
[0087] Those skilled in the art will understand that Figure 5 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.
[0088] In one embodiment, a computer device is further provided, including a memory and a processor. The memory stores a computer program, and the processor implements the steps in the above-mentioned system embodiments when executing the computer program.
[0089] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps in the above-mentioned system embodiments are implemented.
[0090] In one embodiment, a computer program product is provided, including a computer program. When the computer program is executed by a processor, the steps in the above-mentioned system embodiments are implemented.
[0091] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties.
[0092] Those skilled in the art will appreciate that all or part of the processes in the above-mentioned embodiment methods can be implemented by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, database or other media used in the embodiments provided in this application may include at least one of non-volatile and volatile memory. Non-volatile memory may include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory may include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The database involved in the various embodiments provided herein may include at least one of a relational database and a non-relational database. Non-relational databases may include, but are not limited to, distributed databases based on blockchains. The processor involved in the various embodiments provided herein may be, but are not limited to, a general-purpose processor, a central processing unit, a graphics processing unit, a digital signal processor, a programmable logic unit, a data processing logic unit based on quantum computing, and the like.
[0093] The technical features of the above embodiments can be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0094] The above-described embodiments merely represent several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present application. It should be noted that a person of ordinary skill in the art may make various modifications and improvements without departing from the spirit of the present application, and these modifications and improvements fall within the scope of protection of the present application. Therefore, the scope of protection of the present application shall be determined by the appended claims.
Claims
1. An automated penetration system for power grid systems, characterized in that: The system includes an information collection module, a penetration point detection and utilization module, and a decision-making and scheduling module, wherein: The information collection module is used to collect information about the target system to be infiltrated and obtain basic information about the target system; The penetration point detection and utilization module includes a scanning detection module and a penetration point utilization module; The scanning detection module is used to perform at least one of port detection, WEB fingerprint detection, WEB path detection, heuristic crawler and middleware detection on the target system based on the basic information to obtain a detection result; wherein, the WEB fingerprint detection is used to judge the web page keywords, specific file MD5 comparison, specified URL keywords, and TAG mode of the specified URL by loading relevant plug-ins to identify the current web application and related versions; the WEB path detection is used to discover security testing tools for sensitive directories and contents of the website, and to detect by analyzing the response of the server; the heuristic crawler is used to perform task scheduling and event management, and to preload the interface of the target, wait for the network idle state, hijack the website content, and jump or close the page; the middleware detection is used to discover and identify the middleware used by the target system; The penetration point exploitation module is used to verify and exploit vulnerabilities in the target system based on the basic information and the detection results, and obtain corresponding vulnerability verification and exploitation results; The decision-making scheduling module is used to perform correlation analysis on the vulnerability verification and utilization results of the target system based on the constructed expert system and knowledge graph to determine the target penetration path; the expert system includes correlation decision-making and an expert library; the correlation decision is to associate the collected information and the current status with the knowledge graph to determine the correlation between the analyzed information; the expert library includes reasoning analysis and penetration experience decision-making. The reasoning analysis infers the penetration idea based on the correlation of the knowledge graph, and then conducts in-depth analysis based on the penetration experience to decide the next penetration path.
2. The system according to claim 1, wherein: The decision scheduling module includes a permeation path determination module and a storage scheduling module, wherein: The storage scheduling module is used to trigger the calling interface to obtain and store the vulnerability verification and exploitation results; The penetration path determination module, based on the constructed expert system, associates the knowledge graph with the vulnerability verification and utilization results stored in the storage scheduling module, obtains the corresponding nodes in the knowledge graph, and determines the target penetration path according to the association weights between the nodes.
3. The system according to claim 2, characterized in that The system also includes a graph construction module, The graph construction module is used to build software information and hardware information with known vulnerabilities used in the target network, as well as vulnerability information and attack information of known software and hardware; Based on the network structure of the power grid monitoring system, entity extraction, relationship extraction and attribute extraction are performed on the software information, hardware information, vulnerability information and attack information, and a knowledge graph is determined according to the obtained association relationships.
4. The system according to claim 1, wherein: The system further includes a penetration testing module, which is configured to perform a post-penetration test on the target system according to the target penetration path and generate a penetration testing report.
5. The system according to claim 1, wherein: The system further includes a data display module, which is used to display the penetration test report and the target penetration path.
6. An automated penetration method for a power grid system, characterized in that: The method comprises: Collect information on the target system to be infiltrated to obtain basic information of the target system; perform at least one of port detection, WEB fingerprint detection, WEB path detection, heuristic crawler and middleware detection on the target system based on the basic information to obtain detection results; verify and exploit vulnerabilities of the target system based on the basic information and the detection results to obtain corresponding vulnerability verification and utilization results; wherein, the WEB fingerprint detection is used to judge web page keywords, specific file MD5 comparison, specified URL keywords, and TAG mode of specified URL by loading relevant plug-ins, and identify the current web application and related versions; the WEB path detection is a security testing tool for discovering sensitive directories and contents of the website, and detection is performed by analyzing the response of the server; the heuristic crawler is used for task scheduling and event management, and performs interface preloading, network idle state waiting, website content hijacking, page jump or close interception on the target; the middleware detection is used to discover and identify the middleware used by the target system; Based on the constructed expert system and knowledge graph, the vulnerability verification and utilization results of the target system are correlated and analyzed to determine the target penetration path; the expert system includes correlation decision-making and an expert library; the correlation decision is to correlate the collected information and the current status with the knowledge graph to determine the correlation between the analyzed information; the expert library includes reasoning analysis and penetration experience decision-making. The reasoning analysis infers the penetration idea based on the correlation of the knowledge graph, and then conducts in-depth analysis based on the penetration experience to decide the next penetration path.
7. The method according to claim 6, characterized in that The vulnerability verification and utilization results of the target system are correlated and analyzed based on the constructed expert system and knowledge graph to determine the target penetration path, including: triggering a call interface to obtain and store the vulnerability verification and utilization results; based on the constructed expert system, associating the knowledge graph with the vulnerability verification and utilization results stored in the storage scheduling module to obtain the corresponding nodes in the knowledge graph, and determining the target penetration path according to the correlation weights between the nodes.
8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to claim 6 or 7 are implemented.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to claim 6 or 7 are implemented.
10. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to claim 6 are implemented.
Citation Information
Patent Citations
Quantitative evaluation method of industrial control network security situation based on knowledge map
CN109639670A
Automatic penetration test system and method based on artificial intelligence
CN110968873A