An Optimal Path Selection Method, System, Storable Medium and Electronic Device Based on a Knowledge Graph
By constructing a penetration knowledge map and calculating the shortest penetration test path, the problems of high energy consumption and low efficiency in the penetration process of target hosts in the target network are solved, and more efficient and successful penetration operations are achieved.
Patent Information
- Application Number
- CN202111574461.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-21
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2041-12-21
AI Technical Summary
Existing penetration tools have high energy consumption and low efficiency problems during the penetration process of target hosts in the target network, and most of the penetration information obtained is invalid information, resulting in waste of resources.
Using the optimal path selection method based on the knowledge graph, the penetration knowledge graph is used to optimize the penetration process by constructing the penetration knowledge graph, computing the penetration test path, and selecting the shortest penetration test path.
Reduce penetration operations, improve penetration efficiency and success rate, avoid resource waste, and optimize host penetration process within the network.
Smart Images

Figure CN114499939B_ABST
Abstract
Description
Technical Field
[0001] The present invention specifically relates to an optimal path selection method, system, storage medium and electronic device based on a knowledge graph, and belongs to the field of automated penetration in network security. Background Art
[0002] With the rapid development of information technology and the continuous expansion of the scope of network applications, while bringing great convenience to people, it also exposes people to threats of network security risks. These threats include viruses, worms, Trojans, etc., and the main way they launch attacks is through security vulnerabilities in system applications. To prevent these threats, it is necessary to detect security problems existing in computer systems early and determine the severity of the existing vulnerabilities. Therefore, it is necessary to periodically perform penetration tests on computer network systems in enterprise networks and perform security repairs on the systems according to the results of the penetration tests.
[0003] Penetration test is an evaluation method that assesses the security of a computer network system by simulating the attack methods of malicious hackers. This process includes the active analysis of any weaknesses, technical defects or vulnerabilities in the system. This analysis is carried out from the possible positions of an attacker, and from this position, there are conditions to actively exploit security vulnerabilities to achieve a certain level of control authority, thereby obtaining the assets of the target system.
[0004] Existing penetration tools usually can only discover and exploit vulnerabilities for the discovered service components, and at the same time perform comprehensive scans on all components. Although this can discover existing vulnerabilities as much as possible, due to the reason that all services are scanned comprehensively, the scanning time and scanning depth of a single penetration target will consume a large amount of resources, while the proportion of relevant information required for penetration targets such as privilege escalation is very low. That is to say, most of the large amount of penetration information obtained is invalid information that is not helpful for penetration, resulting in a waste of resources.
[0005] In the entire target network, in order to penetrate the target host in the target network, we also need to discover the nearest penetration path to the target host to achieve the purpose of low-cost and high-efficiency penetration. Summary of the Invention
[0006] Aiming at the defects of high energy consumption and low efficiency in the penetration of the target host in the target network existing in the prior art, the embodiments of the present invention provide an optimal path selection method based on a knowledge graph.
[0007] To solve the above technical problems, the embodiments of the present invention adopt the following technical solutions:
[0008] In a first aspect, an embodiment of the present invention provides an optimal path selection method based on a knowledge graph, which is characterized by including the following steps:
[0009] S11: Construct a penetration knowledge graph for the target penetration;
[0010] S12: Calculate the penetration test path according to the penetration knowledge graph;
[0011] S13: Select the shortest penetration test path for the target penetration.
[0012] Preferably, step S11 specifically includes:
[0013] S1101: Determine the penetration test data entity and triple;
[0014] S1102: Obtain the triple data related to penetration;
[0015] S1103: Use the triple data to construct a knowledge graph.
[0016] Preferably, the target penetration includes target host penetration, and the target host penetration specifically includes the following steps:
[0017] S1201: Collect basic information;
[0018] S1202: Obtain an initial penetration flow chart;
[0019] S1203: Remove the invalid penetration steps in the initial flow chart, and add different penetration processes inferred from the existing content;
[0020] S1204: Calculate the penetration weights of the different penetration processes, and determine the execution order of different penetration paths according to the levels of the penetration weights.
[0021] Preferably, for each of the penetration paths, the weight of the whole path is:
[0022]
[0023] When using the path calculation module of the knowledge graph to obtain the optimal penetration path of the penetration target, for each penetration triple (X i-1 , lane, X i ) in the obtained penetration path graph, where , X i-1 , X i corresponds to the penetration tuple, lane corresponds to the relationship between two penetration tuples, and there is a value v(X i |X i-1 ) representing the weight of this single-step operation, indicating the achievement of the next node target X ithe possibility, where X i-1 represents the start node of a single-step operation in the penetration path, X i represents the end node of a single-step operation in the penetration path.
[0024] Preferably, the target penetration further includes target network penetration, and the steps of the target network penetration are as follows:
[0025] S1211: Calculate the penetration weights of all hosts in the target network penetration;
[0026] S1212: Construct a target network penetration weight table;
[0027] S1213: Use the greedy algorithm to calculate the shortest path from the starting host to the target host.
[0028] Preferably, using the weight table and the greedy algorithm, calculate the shortest path from the starting host, through the intermediate host as a springboard, and finally reach the target host to complete the penetration of the target host, that is, the path with the highest weight, that is:
[0029] V(C) = maxП l V(C l )
[0030] That is, the weight of the entire path is the product of all sub-paths included in this path, that is, the weights between hosts in all paths. Where C represents the target host, and C l represents the host included in the penetration path l, and V(C) represents the weight of reaching the target host C.
[0031] In a second aspect, an embodiment of the present invention provides an optimal path selection system based on a knowledge graph, including: a knowledge graph construction module, a target host penetration module, and a target network penetration module;
[0032] The knowledge graph module is configured to collect existing penetration information, construct the association relationship between penetration entities, and thus establish a penetration knowledge graph;
[0033] The target host penetration module is configured to perform penetration operations on the target host and optimize the penetration process with the help of the penetration knowledge graph during the penetration process;
[0034] The target network penetration module is configured to perform penetration operations on the target network and select the shortest host penetration path during the penetration process.
[0035] In a third aspect, a computer-readable storage medium stores a computer program, and the computer program implements the method described in any one of the above when running.
[0036] Fourth aspect, an electronic device, the electronic device comprising: a processor;
[0037] a memory for storing executable instructions executable by the processor;
[0038] The processor is configured to read the executable instructions from the memory and execute the instructions to implement the method described in any one of the above.
[0039] The present invention has the following effects:
[0040] 1. The knowledge graph is mainly responsible for collecting existing penetration information, constructing the association relationships between penetration entities, thereby establishing a penetration knowledge graph to guide the system to perform automated intelligent penetration operations on the target host or target network. The target host penetration is mainly responsible for performing penetration operations on the target host, and optimizing the penetration process with the help of the penetration knowledge graph during the penetration process, reducing penetration operations, and improving penetration efficiency and success rate.
[0041] 2. Based on the realization of host-to-host penetration by the target host penetration, the target network penetration is responsible for performing penetration operations on the target network, selecting the shortest host penetration path during the penetration process, optimizing the host penetration process within the network, reducing the host penetration operations within the network, and improving penetration efficiency and success rate. BRIEF DESCRIPTION OF THE DRAWINGS
[0042] Figure 1 It is a schematic flowchart of a method for selecting an optimal path based on a knowledge graph provided by an embodiment of the present invention;
[0043] Figure 2 It is a schematic flowchart of constructing a penetration knowledge graph provided by an embodiment of the present invention;
[0044] Figure 3 It is a schematic flowchart of target host penetration provided by an embodiment of the present invention;
[0045] Figure 4 It is a schematic flowchart of target network penetration provided by an embodiment of the present invention;
[0046] Figure 5 It is a module diagram of an optimal path selection system based on a knowledge graph provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0047] The following combines the drawings and embodiments to further describe in detail the specific implementation manners of the present invention. The following embodiments are used to illustrate the present invention, but are not used to limit the scope of the present invention.
[0048] Embodiment 1
[0049] As Figure 1As shown in FIG. 4, an embodiment of the present invention provides an optimal path selection method based on a knowledge graph, including the following steps:
[0050] Construct a penetration knowledge graph for target penetration, calculate the penetration test path according to the penetration knowledge graph, and select the shortest penetration test path for target penetration.
[0051] A knowledge graph is a modern theory that combines the theories and methods of disciplines such as applied mathematics, graphics, information visualization technology, and information science with methods such as bibliometric citation analysis and co-occurrence analysis, and uses a visual graph to vividly display the core structure, development history, frontier fields, and overall knowledge architecture of a discipline to achieve the purpose of multi-disciplinary integration. The penetration knowledge graph refers to the graphing of penetration paths in the field of automated penetration in network security, making the penetration paths clearly distinguishable, and finding the required penetration paths from multiple penetration paths.
[0052] The penetration knowledge graph is also a process of continuous improvement. Collect existing penetration information, construct the association relationships between penetration entities, and thus establish a penetration knowledge graph. The lengths of the penetration test paths are different and need to be tested and calculated separately before being used. Find the shortest penetration test path from the penetration knowledge graph, and thus utilize this shortest path. This method optimizes the penetration process by means of the penetration knowledge graph in the penetration process, reduces penetration operations, improves the penetration efficiency and success rate, and makes it easier to find network security vulnerabilities, so as to repair and improve the vulnerabilities.
[0053] The specific operation of constructing the knowledge graph for target penetration is as follows:
[0054] S1101, determine the penetration test data entities and triples.
[0055] During the penetration test, the collection of information usually focuses on the application layer, support layer, service layer, system layer, and hardware layer. According to the data information and possible vulnerability information existing therein, here we classify the entities into five categories: system, service, application, vulnerability, and exploitation script. The entities contain data such as name, manufacturer, category, and version as their attributes.
[0056] In the penetration knowledge graph constructed in this patent, the triples composed of entities include system-vulnerability relationship, service-vulnerability relationship, application-vulnerability relationship, system-service relationship, system-application relationship, and vulnerability-exploitation script relationship. There are weights in different relationships, and this weight represents the possibility of the existence of the corresponding relationship.
[0057] S1102, obtain the triple data related to penetration.
[0058] After the entities and triples in the penetration knowledge graph are confirmed, relevant penetration information is collected according to the triples to supplement the content of the penetration knowledge graph. Two collection methods are used here: First, penetration experts record and collect the data generated daily during daily penetration work. The data collected by this method is relatively accurate and can intuitively and realistically display the relationship between entities. However, since it is a pure manual information collection method, the number of triple data obtained by this method is small. Second, information existing in relevant penetration websites (CVE, NVD, Exploit-DB) on the Internet is crawled through the crawler method. The data collected by this method is large in quantity and can cover many aspects. However, since the crawling is done by machines, the proportion of valid information cannot be guaranteed, and the accuracy rate is lower compared to the method of manually crawling information. Here, we adopt a combination of manual and machine crawling to obtain penetration-related triple data, mainly using the crawler and supplementing with manual work to collect data. For the problem of low accuracy of the information crawled from relevant websites, it is solved by manually checking and modifying.
[0059] S1103, construct a knowledge graph using the triple data.
[0060] After obtaining the penetration-related triple data, a knowledge graph is constructed based on this data. The information name is used as the entity name, the relevant attributes of the information are used as entity attributes, and the existing association relationships between the information are used as the relationships between entities. For example, we obtain a formatted data from a penetration website: MySQL 3.23.x / 4.0.x - Remote Buffer Overflow - CVE - 2003 - 0780. When entering this penetration information into the knowledge graph, we first create a MySQL service node, then create a service version node 3.32.x / 4.0.x and connect it to the MySQL service node, with the connection relationship being the version number. Then create a vulnerability node MySQL 3.23.x / 4.0.x - Remote Buffer Overflow and connect this vulnerability node to the previous version node, with the connection relationship being having a vulnerability. Enter the obtained penetration information into the penetration knowledge graph in this form to expand the content of the penetration knowledge graph.
[0061] Target penetration includes target host penetration, and the specific steps of target host penetration are as follows:
[0062] S1201, collect basic information.
[0063] Obtain the basic information of the penetration target, including but not limited to port information, service information, fingerprint information, middleware information, system information. If the target site has a domain name, its domain name information, email information, WHOIS information, sensitive path information, and crawler information should also be collected. Among them, the domain name information includes the IP to which the domain name belongs and other sub-domains corresponding to the main domain name; the email information is the email address of the relevant staff obtained by regular expression matching from the website content; in the collected crawler information, the URLs obtained by the crawler will be classified, and different tags will be assigned to the URLs obtained by the crawler according to different categories.
[0064] S1202, obtain the initial penetration flow chart.
[0065] Based on the basic information of the existing site, including the port, service, application, and middleware information where the site is located, as well as the email information, sensitive paths, and administrator names contained in the web page content corresponding to the site. Input these basic information into the network penetration knowledge graph. Here, the knowledge graph is a pre-collected and established knowledge graph storing network penetration-related information and association relationships, which contains the attributes of specific penetration tuples and the relationships between penetration tuples and penetration tuples. For example, if the WordPress application is based on PHP service and MySQL service, then there are two triple relationships in this knowledge graph: (WordPress, depends on, PHP) and (WordPress, depends on, MySQL). In this network penetration knowledge graph, use the tuples corresponding to the previously collected basic information as different starting points, follow all existing triple relationships that are connected, start from the penetration tuples at the starting point, and search for the remaining penetration tuples that can be reached. These connected penetration triples are the penetration path graphs that can be obtained from this basic information.
[0066] S1203, remove the invalid penetration steps in the initial flow chart and add different penetration processes inferred from the existing content.
[0067] First, according to the penetration requirements, remove the ineffective penetration steps, which include: First, some conclusions that can be deduced and no longer need to be obtained by scanning the observation results. Therefore, the corresponding scanning steps in the target penetration flow chart can be removed. For example, the WordPress application is based on PHP service and MySQL service. Now, we scan a component NextGEN in the penetration target, and this component belongs to WordPress. Thus, even if we do not directly scan for PHP and MySQL services, we can still determine the existence of these two services in the penetration target. Second, some vulnerabilities corresponding to basic information cannot play a role in our penetration target behaviors such as uploading a shell or privilege escalation. Therefore, we can skip the corresponding scanning of this basic information, reduce the losses caused by ineffective scanning, and directly remove the relevant subsequent processes corresponding to this basic information in the generated penetration flow chart. For example, if we scan the latest version of Nginx service in the penetration target and there are currently no exploitable vulnerabilities for this service, then we do not need to perform subsequent penetration operations on this service.
[0068] S1204, calculate the penetration weights of the different penetration processes, and determine the execution order of different penetration paths according to the high and low of the penetration weights.
[0069] When obtaining the optimal penetration path of the penetration target using the path calculation module of the knowledge graph, for each penetration triple (X i-1 ,lane,X i ) in the obtained penetration path graph, where X i-1 ,X i correspond to penetration tuples, lane corresponds to the relationship between two penetration tuples, and there is a value v(X i |X i-1 ) representing the weight of this single-step operation, indicating the possibility of achieving the next node target X i . Among them, X i-1 represents the start node of the single-step operation in the penetration path, and X i represents the end node of the single-step operation in the penetration path. Then, for each penetration path, the weight of the entire path is:
[0070]
[0071] As shown in the above formula, the weights of all penetration path graphs calculated by the path calculation module, and the success probabilities of completing penetration under different penetration paths are obtained according to the high and low of the weights and returned to the target host penetration module. The target host penetration module penetrates the target in the order of high and low weights to complete the method of quickly and efficiently penetrating the target host. At the same time, the highest weight is also used as the weight from the source host to the target host.
[0072] Target penetration also includes target network penetration, and the steps of target network penetration are as follows:
[0073] S1211. Calculate the penetration weights of all hosts in the target network penetration.
[0074] According to the method mentioned above, calculate the weights from all source hosts to the target host in the target network. Here, it should be noted that if two hosts are not directly connected before, or there is no known penetration method that can successfully penetrate the target host, the weight value between the two hosts is set to 0.
[0075] S1212. Construct a target network penetration weight table.
[0076] According to the weights from all source hosts to the destination host, construct a penetration weight value table for the target network, where the abscissa of the table represents the source host, the ordinate represents the target host, and the corresponding value is the weight value from the source host to the target host, that is, the success rate of penetrating from the source host to the target host.
[0077] S1213. Use the greedy algorithm to calculate the shortest path from the starting host to the target host.
[0078] After obtaining the weight table between all different hosts, determine the starting host of the entire penetration process and the target host that finally needs to complete the penetration task in the target network, and then use the weight table and the greedy algorithm to calculate the shortest path from the starting host, through intermediate hosts as springboards, and finally reach the target host to complete the penetration of the target host, that is, the path with the highest weight. Here, the path weight is:
[0079] V(C) = maxΠ l V(C l )
[0080] That is, the weight of the entire path is the product of all sub-paths included in the path, that is, the product of the weights between hosts in all paths. Where C represents the target host, and C l represents the hosts included in the penetration path l, and V(C) represents the weight of reaching the target host C.
[0081] Embodiment 2
[0082] As Figure 5 shown, the embodiment of the present invention provides an optimal path selection system based on a knowledge graph, which includes: a knowledge graph construction module, a target host penetration module, and a target network penetration module.
[0083] The knowledge graph module is configured to collect existing penetration information, construct the association relationships between penetration entities, and thus establish a penetration knowledge graph. The target host penetration module is configured to perform penetration operations on the target host, and optimize the penetration process by means of the penetration knowledge graph during the penetration process. The target network penetration module is configured to perform penetration operations on the target network, and select the shortest host penetration path during the penetration process.
[0084] This system is the operating carrier for executing the above method. The knowledge graph module is mainly responsible for collecting existing penetration information, constructing the association relationships between penetration entities, and thus establishing a penetration knowledge graph to guide the system to perform automated intelligent penetration operations on the target host or target network; the target host penetration module is mainly responsible for performing penetration operations on the target host, and optimizing the penetration process by means of the penetration knowledge graph during the penetration process, reducing penetration operations, and improving the penetration efficiency and success rate; based on the realization of host-to-host penetration by the target host penetration module, the target network penetration module is responsible for performing penetration operations on the target network, selecting the shortest host penetration path during the penetration process, optimizing the host penetration process within the network, reducing the host penetration operations within the network, and improving the penetration efficiency and success rate.
[0085] The present invention also provides a computer-readable storage medium, which stores a computer program. The computer program is used to execute the method of Embodiment 1 and run the system of Embodiment 2 when running.
[0086] The present invention also provides an electronic device, which includes a processor and a memory for storing processor-executable instructions.
[0087] The processor is used to read the executable instructions from the memory and execute the method of Embodiment 1 and run the system of Embodiment 2.
[0088] It can be understood that the relevant features in the above method and system can be referred to each other. In addition, the "first", "second", etc. in the above embodiments are used to distinguish each embodiment, and do not represent the advantages and disadvantages of each embodiment.
[0089] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the above-described system, device, and unit can refer to the corresponding processes in the foregoing method embodiments, and will not be described herein again.
[0090] The algorithms and displays provided herein are not inherently related to any particular computer, virtual system, or other device. A variety of general-purpose systems may also be used in conjunction with the teachings based herein. The structure required to construct such systems will be apparent from the above description. Additionally, the present invention is not directed to any particular programming language. It should be appreciated that the teachings of the present invention described herein can be implemented in a variety of programming languages, and the description of a particular language above is for the purpose of disclosing the best mode of the present invention.
[0091] In addition, the memory may include non-permanent memory in the form of computer-readable media, random access memory (RAM) and / or non-volatile memory such as read-only memory (ROM) or flash RAM, and the memory includes at least one memory chip.
[0092] Those skilled in the art will appreciate that the embodiments of the present application may be provided as a method, system, or computer program product. Accordingly, the present application may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present application may take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.
[0093] The present application is described with reference to the flowcharts and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the present application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and combinations of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processors of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing device to produce a machine, such that the instructions executed by the processors of the computer or other programmable data processing device generate means for implementing the functions specified in Figure 1 one or more of the flows Figure 1 or blocks or combinations of blocks.
[0094] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to operate in a particular manner, such that the instructions stored in the computer-readable memory produce a manufacture including instruction means that implement the functions specified in Figure 1 one or more of the flows Figure 1 or blocks or combinations of blocks.
[0095] These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one process Figure 1 one process or multiple processes and / or blocks Figure 1 steps of the functions specified in one block or multiple blocks.
[0096] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and memory.
[0097] The memory may include non-permanent memory in the computer-readable medium, in the form of random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash memory (flash RAM). The memory is an example of a computer-readable medium.
[0098] Computer-readable media includes permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology for information storage. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette tapes, magnetic tape magnetic disk storage or other magnetic storage devices, or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory computer-readable media, such as modulated data signals and carrier waves.
[0099] It should also be noted that the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, commodity or device. Without further limitation, an element defined by the statement "including one..." does not exclude the presence of additional identical elements in the process, method, commodity or device including the element.
[0100] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.
[0101] The above are only the embodiments of the present application and are not used to limit the present application. For those skilled in the art, various changes and modifications can be made to the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the scope of the claims of the present application.
[0102] It should be noted that the above embodiments do not limit the present invention in any form. Any technical solution obtained by using equivalent replacement or equivalent transformation falls within the protection scope of the present invention.
Claims
1. An optimal path selection method based on a knowledge graph, characterized in that, it includes the following steps: S11: Construct a penetration knowledge graph for target penetration, including: S1101: Determine penetration test data entities and triples; S1102: Obtain the triple data related to penetration; S1103: Use the triple data to construct a knowledge graph; The triples composed of entities include system-vulnerability relationships, service-vulnerability relationships, application-vulnerability relationships, system-service relationships, system-application relationships, and vulnerability-application script relationships; S12: Calculate the penetration test path according to the penetration knowledge graph, including: S1201: Collect basic information; S1202: Obtain an initial penetration flow chart; S1203: Remove the invalid penetration steps in the initial penetration flow chart and add different penetration processes inferred from the existing content; S1204: Calculate the penetration weights of the different penetration processes and determine the execution order of different penetration paths according to the high and low of the penetration weights; For each of the penetration paths, the weight of the whole path is: When obtaining the optimal penetration path of the penetration target using the path calculation module of the knowledge graph, for each penetration triple (X i-1 , lane, X i ) in the obtained penetration path graph, where X i-1 , X i corresponds to the penetration tuple, lane corresponds to the relationship between two penetration tuples, there is a value v(X i |X i-1 ) representing the weight of this single-step operation, indicating the possibility of achieving the next node target X i , where X i-1 represents the start node of the single-step operation in the penetration path, and X i represents the end node of the single-step operation in the penetration path; S13: Select the shortest penetration test path for target penetration.
2. The optimal path selection method based on a knowledge graph according to claim 1, characterized in that, the target penetration further includes target network penetration, and the steps of the target network penetration are as follows: S1211: Calculate the penetration weights of all hosts within the target network penetration; S1212: Construct a target network penetration weight table; S1213: Use the greedy algorithm to calculate the shortest path from the starting host to the target host.
3. The optimal path selection method based on a knowledge graph according to claim 2, characterized in that, using the weight table and the greedy algorithm, calculate the shortest path from the starting host, through the intermediate host as a springboard, and finally reach the target host to complete the penetration of the target host, that is, the path with the highest weight, that is: V(C) = max∏ l V(C l ) That is, the weight of the entire path is the product of the weights between hosts in all sub-paths included in this path. Among them, C represents the target host, and C l represents the hosts included in the penetration path l, and V(C) represents the weight to reach the target host C.
4. An optimal path selection system based on a knowledge graph, characterized in that, it includes: a knowledge graph construction module, a target host penetration module, and a target network penetration module; The knowledge graph construction module is configured to collect existing penetration information and construct the association relationship between penetration entities, so as to establish a penetration knowledge graph; The target host penetration module is configured to perform penetration operations on the target host and optimize the penetration process with the help of the penetration knowledge graph during the penetration process; The target network penetration module is configured to perform penetration operations on the target network and select the shortest host penetration path during the penetration process.
5. A computer-readable storage medium, characterized in that, the storage medium stores a computer program, and the computer program implements the method according to any one of claims 1-3 when running.
6. An electronic device, characterized in that, the electronic device includes: a processor; a memory for storing executable instructions of the processor; The processor is used to read the executable instructions from the memory and execute the instructions to implement the method according to any one of claims 1-3 above.
Citation Information
Patent Citations
Method and device for generating attack graph based on knowledge graph
CN108933793A
Multi-module penetration test system based on cooperative control
CN111143852A