Weak Password Detection Method, Device, Electronic Device and Storage Medium
By integrating network protocols, ACL, route, and NAT configurations with traffic analysis, the method effectively identifies weak passwords in network assets, enhancing asset discovery and security in production environments.
Patent Information
- Application Number
- CN202210930356.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-08-03
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2042-08-03
AI Technical Summary
The existing weak password detection methods are not rich enough in the actual production environment, and the blind spots cover a large number of blind spots, resulting in insufficient discovery capabilities and low timeliness. Especially in cloud virtual machine assets, it is difficult to achieve efficient and comprehensive weak password discovery.
By integrating network protocols, ACL configuration information, routing configuration information, firewall NAT configuration information and traffic analysis, combined with automation tools such as hydra and medusa, we realize the detection of network information assets, including IP addresses, ports and application services, and perform automated weak password detection and early warning.
It improves asset coverage and discovery capabilities, can efficiently and comprehensively discover weak passwords in the actual production environment, reduces dependence on third-party online detection, supports automated weak password detection in intranet, private network, and local area network, and improves monitoring efficiency and accuracy.
Smart Images

Figure CN115412302B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular, to a weak password detection method, a weak password detection device, an electronic device, and a computer-readable storage medium. Background Art
[0002] There is no strict and accurate definition for a weak password. Generally, passwords that are easily guessed by others or cracked by cracking tools are considered weak passwords. In actual production work, how network security maintenance personnel, business and equipment maintenance personnel can discover the weak passwords of various application services in a timely, comprehensive and efficient manner has become an urgent issue to be solved.
[0003] Existing weak password detection has problems such as insufficiently rich asset detection means and coverage blind spots. For example, network information is combined with communication traffic to achieve asset detection, and then weak password detection. However, for the actual production environment, the discovery ability of the overall assets is restricted, and the timeliness of discovering assets is not high. Summary of the Invention
[0004] In view of the above problems, embodiments of the present invention are proposed to provide a weak password detection method that overcomes the above problems or at least partially solves the above problems.
[0005] Embodiments of the present invention also provide a weak password detection device, an electronic device, and a storage medium to ensure the implementation of the above method.
[0006] To solve the above problems, embodiments of the present invention disclose a weak password detection method, and the method includes:
[0007] Detecting network information assets based on asset detection indication information; the asset detection indication information includes network protocols, and / or access control list (ACL) configuration information and routing configuration information, and / or network address translation (NAT) configuration information of a firewall, and / or traffic analysis; the network information assets include Internet protocol (IP) addresses, ports, and application services;
[0008] Detecting whether there are weak passwords in the IP addresses, ports, and application services;
[0009] If so, a weak password warning is issued.
[0010] Optionally, the detecting network information assets based on asset detection indication information includes:
[0011] When the asset detection indication information is a network protocol, determining whether it is necessary to detect all network information assets;
[0012] If so, load the planned network information assets; the planned network information assets include IP addresses;
[0013] Eliminate the IP addresses that match the blacklist network information asset IP library;
[0014] Use the eliminated IP addresses to detect network information assets.
[0015] Optionally, the detecting network information assets based on the asset detection indication information includes:
[0016] When the asset detection indication information is ACL configuration information and routing configuration information, obtain the ACL configuration information and routing configuration information; the ACL configuration information and routing configuration information include IP addresses;
[0017] Determine whether it is necessary to detect all network information assets;
[0018] If so, eliminate the IP addresses that match the blacklist network information asset IP library;
[0019] Use the eliminated IP addresses to detect network information assets.
[0020] Optionally, the using the eliminated IP addresses to detect network information assets includes:
[0021] Perform liveness detection on the eliminated IP addresses;
[0022] Output the surviving IP addresses as a list of surviving IP addresses;
[0023] Match the list of surviving IP addresses with the existing network information asset IP library;
[0024] Detect network information assets according to the matching result.
[0025] Optionally, the detecting network information assets according to the matching result includes:
[0026] When the matching result is that the list of surviving IP addresses is the same as the existing network information asset IP library, perform port scanning and service scanning on the IP addresses in the existing network information asset IP library in sequence to obtain the ports and application services corresponding to the IP addresses;
[0027] Determine the IP addresses, ports, and application services as network information assets.
[0028] Optionally, the detecting network information assets according to the matching result includes:
[0029] When the matching result shows that the list of surviving IP addresses is more than the existing IP library of network information assets, use the extra IP addresses in the list of surviving IP addresses to update the existing IP library of network information assets;
[0030] For the IP addresses in the updated existing IP library of network information assets, perform port scanning and service scanning in sequence to obtain the ports and application services corresponding to the IP addresses;
[0031] Determine the IP addresses, ports, and application services as network information assets.
[0032] Optionally, the detecting network information assets according to the matching result includes:
[0033] When the matching result shows that the list of surviving IP addresses is less than the existing IP library of network information assets, detect the status of the ACL access permission;
[0034] If the ACL access permission is in the unopened state, update the status of the ACL access permission;
[0035] Based on the updated ACL access permission, for the IP addresses in the existing IP library of network information assets, perform port scanning and service scanning in sequence to obtain the ports and application services corresponding to the IP addresses;
[0036] Determine the IP addresses, ports, and application services as network information assets.
[0037] Optionally, the if the ACL access permission is in the unopened state, then update the status of the ACL access permission includes:
[0038] If the ACL access permission is in the unopened state, determine whether to automatically update the status of the ACL access permission;
[0039] If so, match the missing IP addresses in the list of surviving IP addresses with the existing network information asset library to determine the devices corresponding to the missing IP addresses; the devices include host devices and network devices;
[0040] For the host devices, use the automated operation and maintenance tool ansible, or login script, or agent program agent to issue ACL configurations to open the ACL access permission;
[0041] For the network devices, mark the network devices that support the network configuration netconf protocol as the first network devices, and mark the network devices that do not support the network configuration netconf protocol as the second network devices;
[0042] For the first network device, use the netconf protocol or a login script to issue the ACL configuration to allow the ACL access permission.
[0043] For the second network device, use a login script to issue the ACL configuration to allow the ACL access permission.
[0044] Optionally, the detecting of network information assets based on the asset detection indication information includes:
[0045] When the asset detection indication information is the NAT configuration information of the firewall, obtain the five-tuple information of the NAT mapping configuration of the firewall; the five-tuple information includes the source IP address, source service port, destination IP address, destination service port, and service protocol.
[0046] Extract the destination IP address, destination service port, and service protocol from the five-tuple information.
[0047] Determine the destination IP address, destination service port, and service protocol as network information assets.
[0048] Optionally, the detecting of network information assets based on the asset detection indication information includes:
[0049] When the asset detection indication information is traffic analysis, obtain the five-tuple information in the communication traffic; the five-tuple information includes the source IP address, source service port, destination IP address, destination service port, and service protocol.
[0050] Extract the destination IP address, destination service port, and service protocol from the five-tuple information.
[0051] Determine the destination IP address, destination service port, and service protocol as network information assets.
[0052] An embodiment of the present invention also discloses a weak password detection device, and the device includes:
[0053] A network information asset detection module, configured to detect network information assets based on asset detection indication information; the asset detection indication information includes network protocols, and / or access control list (ACL) configuration information and routing configuration information, and / or network address translation (NAT) configuration information of a firewall, and / or traffic analysis; the network information assets include Internet protocol (IP) addresses, ports, and application services.
[0054] A weak password detection module, configured to detect whether there is a weak password in the IP address, port, and application service.
[0055] A weak password warning module, configured to perform a weak password warning if so.
[0056] Optionally, the network information asset detection module is specifically configured to:
[0057] When the asset detection indication information is a network protocol, determine whether it is necessary to detect all network information assets;
[0058] If so, load the planned network information assets; the planned network information assets include IP addresses;
[0059] Eliminate the IP addresses that match the blacklist of network information asset IPs;
[0060] Use the eliminated IP addresses to detect network information assets.
[0061] Optionally, the network information asset detection module is specifically configured to:
[0062] When the asset detection indication information is ACL configuration information and routing configuration information, obtain the ACL configuration information and routing configuration information; the ACL configuration information and routing configuration information include IP addresses;
[0063] Determine whether it is necessary to detect all network information assets;
[0064] If so, eliminate the IP addresses that match the blacklist of network information asset IPs;
[0065] Use the eliminated IP addresses to detect network information assets.
[0066] Optionally, the network information asset detection module is further configured to:
[0067] Perform liveness detection on the eliminated IP addresses;
[0068] Output the surviving IP addresses as a list of surviving IP addresses;
[0069] Match the list of surviving IP addresses with the existing network information asset IP library;
[0070] Detect network information assets according to the matching result.
[0071] Optionally, the network information asset detection module is further configured to:
[0072] When the matching result is that the list of surviving IP addresses is the same as the existing network information asset IP library, perform port scanning and service scanning on the IP addresses in the existing network information asset IP library in sequence to obtain the ports and application services corresponding to the IP addresses;
[0073] Determine the IP address, port, and application service as network information assets.
[0074] Optionally, the network information asset detection module is further configured to:
[0075] When the number of live IP addresses in the matching result is more than the existing network information asset IP library, use the extra IP addresses in the live IP address list to update the existing network information asset IP library;
[0076] For the IP addresses in the updated existing network information asset IP library, perform port scanning and service scanning in sequence to obtain the ports and application services corresponding to the IP addresses;
[0077] Determine the IP address, port, and application service as network information assets.
[0078] Optionally, the network information asset detection module is further configured to:
[0079] When the number of live IP addresses in the matching result is less than the existing network information asset IP library, detect the status of the ACL access permission;
[0080] If the ACL access permission is in the unopened state, update the status of the ACL access permission;
[0081] Based on the updated ACL access permission, for the IP addresses in the existing network information asset IP library, perform port scanning and service scanning in sequence to obtain the ports and application services corresponding to the IP addresses;
[0082] Determine the IP address, port, and application service as network information assets.
[0083] Optionally, the network information asset detection module is further configured to:
[0084] If the ACL access permission is in the unopened state, determine whether to automatically update the status of the ACL access permission;
[0085] If so, match the missing IP addresses in the live IP address list with the existing network information asset library to determine the devices corresponding to the missing IP addresses; the devices include host devices and network devices;
[0086] For the host devices, use the automated operation and maintenance tool ansible, or a login script, or an agent program agent to issue ACL configurations to open the ACL access permission;
[0087] For the network device, mark the network device that supports the network configuration netconf protocol as the first network device, and mark the network device that does not support the network configuration netconf protocol as the second network device;
[0088] For the first network device, use the netconf protocol or a login script to issue the ACL configuration to allow the ACL access permission;
[0089] For the second network device, use a login script to issue the ACL configuration to allow the ACL access permission.
[0090] Optionally, the network information asset detection module is specifically configured to:
[0091] When the asset detection indication information is the NAT configuration information of the firewall, obtain the five-tuple information of the NAT mapping configuration of the firewall; the five-tuple information includes the source IP address, source service port, destination IP address, destination service port, and service protocol;
[0092] Extract the destination IP address, destination service port, and service protocol from the five-tuple information;
[0093] Determine the destination IP address, destination service port, and service protocol as network information assets.
[0094] Optionally, the network information asset detection module is specifically configured to:
[0095] When the asset detection indication information is traffic analysis, obtain the five-tuple information in the communication traffic; the five-tuple information includes the source IP address, source service port, destination IP address, destination service port, and service protocol;
[0096] Extract the destination IP address, destination service port, and service protocol from the five-tuple information;
[0097] Determine the destination IP address, destination service port, and service protocol as network information assets.
[0098] An embodiment of the present invention also discloses an electronic device, including a processor, a communication interface, a memory, and a communication bus. Among them, the processor, the communication interface, and the memory complete communication with each other through the communication bus;
[0099] The memory is used to store a computer program;
[0100] When the processor is used to execute the program stored in the memory, it implements the method described in the embodiment of the present invention.
[0101] Embodiments of the present invention also disclose one or more computer-readable media, on which instructions are stored, which, when executed by one or more processors, cause the processors to execute the method as described in the embodiments of the present invention.
[0102] Compared with the prior art, the embodiments of the present invention include the following advantages:
[0103] In the embodiments of the present invention, based on asset detection indication information, network information assets are detected, where the asset detection indication information includes network protocols, and / or, ACL configuration information and routing configuration information, and / or, NAT configuration information of a firewall, and / or, traffic analysis, and the network information assets include IP addresses, ports, and application services. Then, it is detected whether there are weak passwords in the IP addresses, ports, and application services. If so, a weak password warning is issued. The embodiments of the present invention realize the detection of network information assets by integrating network protocols, ACL configuration information and routing configuration information, NAT configuration information of a firewall, and traffic analysis. Among them, the configuration information can perform asset detection for the actual production environment, thereby improving the asset coverage, strengthening the detection depth of assets, and effectively improving the asset discovery coverage and discovery ability. BRIEF DESCRIPTION OF THE DRAWINGS
[0104] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0105] Figure 1 is a flowchart of the steps of a weak password detection method provided by an embodiment of the present invention;
[0106] Figure 2 is a flowchart of the steps of a weak password detection method provided by an embodiment of the present invention;
[0107] Figure 3 is a flowchart of the automated inspection of ACL access permissions provided by an embodiment of the present invention;
[0108] Figure 4 is a flowchart of the automated update of ACL access permissions provided by an embodiment of the present invention;
[0109] Figure 5 is the overall flowchart of weak password detection provided by an embodiment of the present invention;
[0110] Figure 6 is the overall flowchart of weak password detection provided by an embodiment of the present invention;
[0111] Figure 7It is a structural block diagram of a weak password detection device provided by an embodiment of the present invention. Detailed implementation manners
[0112] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0113] In recent years, with the development of Internet technology and the change of the international situation, attacks and intrusions on Internet infrastructure and Internet information systems have become more frequent, and the security protection of Internet infrastructure and Internet information systems faces severe tests. In terms of network security attack means, among the methods of successful intrusion, the weak password breakthrough accounts for a relatively high proportion. In actual production work, how network security maintenance personnel, business and equipment maintenance personnel can discover the weak passwords of various application services in a timely, comprehensive and efficient manner has become an urgent issue to be solved.
[0114] Existing weak password detection has problems such as insufficiently rich asset detection means and coverage blind spots. For example, network information is combined with communication traffic to achieve asset detection, and then weak password detection. However, for the actual production environment, especially in terms of cloud virtual machine assets, the overall asset discovery ability is restricted, and the timeliness of asset discovery is not high.
[0115] In view of the above problems, an embodiment of the present invention provides a weak password detection method. In the embodiment of the present invention, network information assets are detected by fusing network protocols, ACL configuration information and routing configuration information, NAT configuration information of the firewall, and traffic analysis. Among them, the configuration information can detect assets for the actual production environment, thereby improving the asset coverage, strengthening the detection depth of assets, and effectively improving the asset discovery coverage and discovery ability.
[0116] Referring to Figure 1 , a step flow chart of a weak password detection method provided by an embodiment of the present invention is shown. The method may specifically include the following steps:
[0117] Step 101, detect network information assets based on asset detection indication information; the asset detection indication information includes network protocols, and / or access control list (ACL) configuration information and routing configuration information, and / or network address translation (NAT) configuration information of the firewall, and / or traffic analysis; the network information assets include Internet protocol (IP) addresses, ports, and application services.
[0118] In an embodiment of the present invention, asset detection indication information may be preset. The asset detection indication information may be used to indicate the detection method of network information assets. Among them, the asset detection indication information may include at least one of network protocols, ACL configuration information, routing configuration information, NAT configuration information of a firewall, and traffic analysis.
[0119] An ACL (Access Control List) is a list of instructions for router and switch interfaces, used to control the data packets entering and leaving the port.
[0120] NAT (Network Address Translation) belongs to the technology of accessing a wide area network (WAN). It is a conversion technology that converts private addresses into legal IP addresses. It is widely used in various types of Internet access methods and various types of networks.
[0121] Among them, the ACL configuration information, routing configuration information, and NAT configuration information of the firewall all belong to the information configured in network devices. The configuration information can perform asset detection for the actual production environment, especially for cloud resource pool nodes. In an embodiment of the present invention, asset detection can be performed based on the NAT configuration information of the firewall, so that the discovery ability of the overall assets can get rid of restrictions and greatly improve the timeliness of asset discovery.
[0122] In an embodiment of the present invention, network information assets are detected through network protocols, and / or ACL configuration information and routing configuration information, and / or NAT configuration information of a firewall, and / or traffic analysis, so as to improve the asset coverage, strengthen the detection depth of assets, and effectively improve the asset discovery coverage and discovery ability. Among them, network protocols, ACL configuration information, routing configuration information, NAT configuration information of the firewall, and traffic analysis can be processed in parallel.
[0123] Among them, network information assets may include IP (Internet Protocol Address) addresses, ports, and application services.
[0124] Step 102, detect whether there is a weak password in the IP address, port, and application service.
[0125] After detecting the IP address, port, and application service, a weak password detection process can be carried out. Weak password detection can use existing weak password feature libraries and weak password detection tools to detect the IP address, port, and application service.
[0126] The weak password feature library is the weak password feature library mastered by the enterprise. The data in the weak password feature library comes from the default accounts and passwords of application services publicly available in the market collected by the enterprise, common accounts and weak passwords collected in daily work, and application service accounts and passwords publicly known in the industry.
[0127] The weak password detection tool can include the open-source tool hydra (an automated brute-force tool), the open-source tool medusa (an open-source brute-force cracking tool), and other tools and scripts that can detect weak passwords.
[0128] In specific implementation, the existing weak password feature library and weak password detection tool can be loaded. The weak password detection tool uses the preset accounts and weak passwords in the weak password feature library to perform multiple simulated logins for the IP address, port, and application service to achieve the purpose of exhaustive brute force. If the login is successful, it indicates a weak password. In the program of the weak password detection tool, through programming language tools, the obtained IP address, exposed port number, and application service type are automatically loaded to realize the automated weak password detection of batch assets.
[0129] Step 103, if so, issue a weak password warning.
[0130] If a weak password is detected in the IP address, port, or application service, a warning message about the weak password detection result can be sent for weak password warning. Exemplarily, through the API (Application Programming Interface) interface, emails, text messages, etc. containing the warning message about the weak password detection result can be sent. Among them, the warning message can include information such as the weak password IP address, weak password asset name, exposed port, application service, weak password corresponding account, and specific weak password.
[0131] In the actual production, construction, business operation and maintenance, and network security maintenance work of the embodiments of the present invention, automated and wide-coverage weak password detection can be realized, the monitoring ability of weak password detection of enterprise assets can be improved and strengthened, the reinforcement guidance ability in the synchronous operation and use links at the network, information, and security levels can be improved, and the network security protection ability of the enterprise can be improved.
[0132] In summary, in the embodiments of the present invention, network information assets are detected through asset detection indication information, where the asset detection indication information includes network protocols, and / or ACL configuration information and routing configuration information, and / or NAT configuration information of a firewall, and / or traffic analysis. The network information assets include IP addresses, ports, and application services. Then, it is detected whether there are weak passwords in the IP addresses, ports, and application services. If so, a weak password warning is issued. In the embodiments of the present invention, by integrating network protocols, ACL configuration information and routing configuration information, NAT configuration information of a firewall, and traffic analysis, network information assets are detected, thereby improving the coverage of network information assets, strengthening the detection depth of network information assets, and effectively improving the asset discovery coverage and discovery ability.
[0133] Referring to Figure 2 , the flowchart of the steps of a weak password detection method provided by the embodiments of the present invention is shown. The method may specifically include the following steps:
[0134] Step 201, detecting network information assets based on asset detection indication information; the asset detection indication information includes network protocols, and / or access control list (ACL) configuration information and routing configuration information, and / or network address translation (NAT) configuration information of a firewall, and / or traffic analysis; the network information assets include Internet protocol (IP) addresses, ports, and application services.
[0135] In the embodiments of the present invention, asset detection indication information may be preset. The asset detection indication information may be used to indicate the detection method of network information assets. Among them, the asset detection indication information may include at least one of network protocols, ACL configuration information and routing configuration information, NAT configuration information of a firewall, and traffic analysis.
[0136] In the embodiments of the present invention, network information assets are detected through network protocols, and / or ACL configuration information and routing configuration information, and / or NAT configuration information of a firewall, and / or traffic analysis, thereby improving the asset coverage, strengthening the detection depth of assets, and effectively improving the asset discovery coverage and discovery ability. Among them, network protocols, ACL configuration information and routing configuration information, NAT configuration information of a firewall, and traffic analysis can be processed in parallel.
[0137] Among them, the network information assets may include IP addresses, ports, and application services.
[0138] In an alternative embodiment of the present invention, step 201 may include the following sub-steps:
[0139] Sub-step S11, when the asset detection indication information is a network protocol, determining whether it is necessary to detect all network information assets;
[0140] Sub-step S12, if so, load the planned network information assets; the planned network information assets include IP addresses.
[0141] Sub-step S13, eliminate the IP addresses that match the blacklist network information asset IP library.
[0142] Sub-step S14, use the eliminated IP addresses to detect network information assets.
[0143] When the asset detection indication information is a network protocol, it is possible to first determine whether it is necessary to cover all planned assets, that is, to determine whether it is necessary to detect all network information assets. If it is necessary to detect all network information assets, then the planned network information assets can be loaded. Among them, the planned network information assets can include IP addresses.
[0144] For the important IP addresses of some enterprises, the enterprises do not want to detect or do not need to detect them. In order to avoid causing performance failures of the devices / systems of the IP addresses and affecting the core business services of the enterprises, the embodiments of the present invention bypass the process for the IP addresses in the blacklist library and do not detect them by setting an optional item for the blacklist library.
[0145] In the case where it is necessary to detect all network information assets, the blacklist network information asset IP library can be loaded, and then the IP addresses in the planned network information assets are matched with the blacklist network information asset IP library, and then the IP addresses that match the blacklist network information asset IP library are eliminated, so as to use the eliminated IP addresses to detect network information assets.
[0146] In addition, if it is not necessary to detect all network information assets, then the existing network information asset IP library can be loaded, and then the IP addresses in the existing network information asset IP library are used to detect network information assets. Among them, the existing network information asset IP library is the detailed list of devices that the enterprise initially has, not all the planned network information assets.
[0147] In an optional embodiment of the present invention, step 201 may include the following sub-steps:
[0148] Sub-step S21, when the asset detection indication information is ACL configuration information and routing configuration information, obtain the ACL configuration information and routing configuration information; the ACL configuration information and routing configuration information include IP addresses.
[0149] Sub-step S22, determine whether it is necessary to detect all network information assets.
[0150] Sub-step S23, if so, eliminate the IP addresses that match the blacklist network information asset IP library.
[0151] Sub-step S24: Use the screened IP addresses to detect network information assets.
[0152] When the asset detection indication information is ACL configuration information and routing configuration information, the ACL configuration information and routing configuration information in the network device can be obtained first. Among them, the ACL configuration information and routing configuration information may include IP addresses.
[0153] In a specific implementation, methods such as ssh (secure shell) and telnet (remote terminal protocol) can be used to log in to the device, and then programs can be used to capture the ACL configuration information and routing configuration in the network device. Or protocols such as netconf (network configuration) can be used to directly retrieve the ACL configuration information and routing configuration, and then the IP addresses are extracted from the ACL configuration information and routing configuration, and then it is judged whether it is necessary to detect all network information assets.
[0154] In the case where it is necessary to detect all network information assets, the IP library of blacklist network information assets can be loaded, and then the IP addresses extracted from the ACL configuration information and routing configuration are matched with the IP library of blacklist network information assets, and then the IP addresses that match the IP library of blacklist network information assets are excluded, so as to use the screened IP addresses to detect network information assets.
[0155] In addition, if it is not necessary to detect all network information assets, then the existing IP library of network information assets can be loaded, and then the IP addresses in the existing IP library of network information assets are used to detect network information assets.
[0156] In an alternative embodiment of the present invention, sub-step S14 or sub-step S24 may include the following sub-steps:
[0157] Sub-step S31: Perform liveness detection on the screened IP addresses;
[0158] Sub-step S32: Output the live IP addresses as a list of live IP addresses;
[0159] Sub-step S33: Match the list of live IP addresses with the existing IP library of network information assets;
[0160] Sub-step S34: Detect network information assets according to the matching result.
[0161] The IP addresses in the planned network information assets are the information of the IP address segments planned to be used by the enterprise, and not all of them may be alive. Similarly, the IP addresses extracted from the ACL configuration information and routing configuration may not all be alive. Therefore, after removing the IP addresses in the blacklist library, asset IP address probing scans can be performed on the IP addresses without the blacklist.
[0162] Specifically, the open-source tool masscan (a penetration tool) or other tools that can detect the IP addresses of network information assets can be used to detect whether the IP addresses reply communication data packets. If there is an interactive reply packet, it means that the IP address is alive, thus distinguishing between the alive IP addresses and the non-alive IP addresses.
[0163] Among them, when using the tools for detecting the IP addresses of network information assets, the scanning rate can be adjusted to avoid network storms and the unavailability of network information assets.
[0164] In the embodiment of the present invention, the alive IP addresses can be output as a list of alive IP addresses, and then the list of alive IP addresses can be used to match with the existing network information asset IP library, so as to detect the network information assets according to the matching results.
[0165] In an optional embodiment of the present invention, sub-step S34 may include the following sub-steps:
[0166] Sub-step S41, when the matching result is that the list of alive IP addresses is consistent with the existing network information asset IP library, perform port scanning and service scanning on the IP addresses in the existing network information asset IP library in sequence to obtain the ports and application services corresponding to the IP addresses;
[0167] Sub-step S42, determine the IP addresses, ports, and application services as network information assets.
[0168] After matching the list of alive IP addresses with the existing network information asset IP library, if an IP address list consistent with the existing network information asset IP library is obtained, then there is no need to further process the IP address list. Instead, directly perform port scanning and service scanning on the IP addresses in the existing network information asset IP library in sequence to obtain the ports and application services corresponding to the IP addresses. Among them, the IP addresses, ports, and application services all belong to network information assets.
[0169] Specifically, for the IP addresses in the existing network information asset IP library, initiate the port liveness scan corresponding to the network information asset IP addresses to obtain the port liveness list corresponding to the network information asset IP addresses, and then initiate the service scan for the corresponding ports to obtain the application services corresponding to the ports of the network information asset IP addresses.
[0170] For port scanning, open-source tool masscan (penetration tool) or other detection tools that can detect exposed ports can be used to detect the open exposed ports corresponding to the network information asset IP addresses.
[0171] For service scanning, open-source tool nmap (network mapper) or other detection tools that can detect application service types can be used to conduct targeted application service type scans, and finally obtain the list of corresponding relationships between the application service types of the asset IP addresses and the opened ports. This corresponding relationship list can specifically include the surviving IP addresses, the exposed ports opened by the surviving IP addresses, and the application service types of the exposed ports opened by the surviving IP addresses.
[0172] Among them, when using the detection tools for exposed ports and the detection tools for application service types, the scanning rate can be adjusted to avoid network storms and the unavailability of network information assets.
[0173] Furthermore, before step 202, that is, before detecting whether there are weak passwords in the IP addresses, ports, and application services, the finally obtained corresponding relationship list can be cleaned and regularized through open-source programming language tools (such as Python, Java, etc.) to obtain an information list table in the format of asset names, surviving IP addresses, exposed ports opened by the surviving IP addresses, application service types of the exposed ports opened by the surviving IP addresses, etc., so as to facilitate the subsequent step 202 to conduct weak password detection using the cleaned and regularized data.
[0174] In an optional embodiment of the present invention, sub-step S34 may include the following sub-steps:
[0175] Sub-step S51, when the matching result shows that the list of surviving IP addresses is more than the existing network information asset IP library, use the extra IP addresses in the list of surviving IP addresses to update the existing network information asset IP library;
[0176] Sub-step S52, for the IP addresses in the updated existing network information asset IP library, conduct port scanning and service scanning in sequence to obtain the ports and application services corresponding to the IP addresses;
[0177] Sub-step S53: Determine the IP address, port, and application service as network information assets.
[0178] After matching the list of live IP addresses with the existing network information asset IP library, if there are more IP addresses in the list of IP addresses obtained from the match than in the existing network information asset IP library, then the list of IP addresses can be further processed.
[0179] The extra IP addresses in the list of live IP addresses can be determined as newly discovered network information assets, and then for the newly discovered network information assets, it is judged whether manual confirmation of asset ownership is required.
[0180] If manual confirmation of asset ownership is required, then the process of manually confirming whether the asset belongs to the enterprise can be carried out. The specific process is as follows: Judge whether the IP address of the newly discovered network information asset is the IP address of the network information asset in use by the enterprise; if it is the IP address of the network information asset in use by the enterprise, then the newly discovered and network information asset IP addresses that belong to the enterprise in use can be written into the existing network information asset IP library, thereby updating the existing network information asset IP library; if it is not the IP address of the network information asset in use by the enterprise, then the newly discovered but network information asset IP addresses that do not belong to the enterprise in use can be written into the blacklist network information asset IP library, thereby no longer detecting the liveness of this IP address and not carrying out the subsequent weak password detection process.
[0181] If manual confirmation of asset ownership is not required, then it can be automatically judged whether the newly discovered network information asset IP address needs to be written into the existing network information asset IP library. If writing is required, then the newly discovered and network information asset IP addresses that belong to the enterprise in use can be written into the existing network information asset IP library, thereby updating the existing network information asset IP library; if writing is not required, then the newly discovered network information asset IP address is discarded, thereby no longer detecting the liveness of this IP address and not carrying out the subsequent weak password detection process.
[0182] Use the IP addresses in the updated existing network information asset IP library to perform port scanning and service scanning in sequence, so as to obtain the ports and application services corresponding to the IP addresses. Among them, the IP address, port, and application service all belong to network information assets.
[0183] Among them, when using the detection tool for exposed surface ports and the detection tool for application service types, the scanning rate can be adjusted to avoid situations such as network storms and unavailability of network information assets.
[0184] Specifically, for the IP addresses in the updated existing network information asset IP library, initiate a port liveness scan for the IP addresses corresponding to the network information assets, so as to obtain a port liveness list corresponding to the IP addresses of the network information assets, and then initiate a service scan for the corresponding ports, so as to obtain the application services corresponding to the ports of the IP addresses of the network information assets.
[0185] For port scanning, open-source tool masscan (penetration tool) or other detection tools that can detect exposed ports can be used to detect the open exposed ports corresponding to the IP addresses of network information assets.
[0186] For service scanning, open-source tool nmap (network mapper) or other detection tools that can detect application service types can be used to conduct targeted application service type scans, and finally obtain a list of the corresponding relationships between the application service types of the asset IP addresses and the opened ports. The corresponding relationship list can specifically include the surviving IP addresses, the exposed ports opened by the surviving IP addresses, and the application service types of the exposed ports opened by the surviving IP addresses.
[0187] Further, before step 202, that is, before detecting whether there are weak passwords in the IP addresses, ports, and application services, open-source programming language tools (such as Python, Java, etc.) can be used to clean and regularize the finally obtained corresponding relationship list, so as to obtain an information list table in the format of asset names, surviving IP addresses, exposed ports opened by the surviving IP addresses, application service types of the exposed ports opened by the surviving IP addresses, etc., so that the subsequent step 202 can use the cleaned and regularized data to conduct weak password detection.
[0188] In an alternative embodiment of the present invention, sub-step S34 may include the following sub-steps:
[0189] Sub-step S61, when the matching result is that the list of surviving IP addresses is less than the existing network information asset IP library, detect the status of the ACL access permission;
[0190] Sub-step S62, if the ACL access permission is in an unopened state, update the status of the ACL access permission;
[0191] Sub-step S63, based on the updated ACL access permission, for the IP addresses in the existing network information asset IP library, perform port scanning and service scanning in sequence to obtain the ports and application services corresponding to the IP addresses;
[0192] Sub-step S64, determine the IP addresses, ports, and application services as network information assets.
[0193] After matching the list of live IP addresses with the existing IP database of network information assets, if the number of IP addresses obtained from the match is less than that in the existing IP database of network information assets, it indicates that some IP addresses in the existing IP database of network information assets cannot be detected. Then, ACL restriction judgment needs to be carried out to further process the IP address list. In other words, if some IP addresses cannot be detected by the scanner ACL, the status of the ACL access permission needs to be checked to find out the reason.
[0194] In the embodiment of the present invention, the status of the ACL access permission can be detected by automatically checking the ACL access permission. Specifically, referring to Figure 3 , the flowchart of automatically checking the ACL access permission provided by the embodiment of the present invention is shown. The IP addresses missing in the list of live IP addresses can be matched with the existing network information asset database to obtain device type information. Among them, the existing network information asset database includes the existing IP address database of network information assets. In addition, it also includes asset names and device type information. The device type information can include host devices, network devices supporting the netconf protocol, and network devices not supporting the netconf protocol.
[0195] As Figure 3 shown, for host devices, there are three methods to issue ACL configurations; for network devices supporting the netconf protocol, there are two methods to issue ACL configurations; for network devices not supporting the netconf protocol, there is one method to issue ACL configurations. Specifically, the host device can issue the ACL configuration by ansible (an automated operation and maintenance tool), or the host device can issue the ACL configuration by a login script, or the host device can issue the ACL configuration by triggering an agent (a proxy program); the network device supporting the netconf protocol can issue the ACL configuration by the netconf protocol, or the network device supporting the netconf protocol can issue the ACL configuration by a login script; the network device not supporting the netconf protocol can issue the ACL configuration by a login script. Through the means capable of issuing ACL configurations, the ability to automatically check the ACL access permission is completed, and then it is judged whether the ACL access permission has been enabled.
[0196] If it is judged that the ACL access permission is in an enabled state, then the IP addresses in the existing IP database of network information assets can be directly used to perform port scanning and service scanning in sequence to obtain the ports and application services corresponding to the IP addresses. Among them, IP addresses, ports, and application services all belong to network information assets.
[0197] Among them, when using detection tools for exposed surface ports and detection tools for application service types, the scanning rate can be adjusted to avoid network storms and the unavailability of network information assets.
[0198] If it is determined that the ACL access permission is in an unopened state, then the status of the ACL access permission needs to be updated. Then, based on the updated ACL access permission, port scanning and service scanning are sequentially performed on the IP addresses in the existing network information asset IP library to obtain the ports and application services corresponding to the IP addresses. Among them, the IP addresses, ports, and application services all belong to network information assets.
[0199] In an optional embodiment of the present invention, sub-step S62 may include the following sub-steps:
[0200] Sub-step S71, if the ACL access permission is in an unopened state, determine whether to automatically update the status of the ACL access permission;
[0201] Sub-step S72, if so, match the missing IP addresses in the list of alive IP addresses with the existing network information asset library to determine the devices corresponding to the missing IP addresses; the devices include host devices and network devices;
[0202] Sub-step S73, for the host devices, use the automated operation and maintenance tool ansible, or a login script, or an agent program agent to issue the ACL configuration to open the ACL access permission;
[0203] Sub-step S74, for the network devices, mark the network devices that support the network configuration netconf protocol as the first network devices, and mark the network devices that do not support the network configuration netconf protocol as the second network devices;
[0204] Sub-step S75, for the first network devices, use the netconf protocol, or a login script, to issue the ACL configuration to open the ACL access permission;
[0205] Sub-step S76, for the second network devices, use a login script to issue the ACL configuration to open the ACL access permission.
[0206] In the embodiment of the present invention, if the ACL access permission is in an unopened state, then the problem of being unable to detect some IP addresses can be solved by manually configuring the ACL access permission or by automatically updating the status of the ACL access permission.
[0207] Among them, the process of manually configuring ACL access permissions is as follows: Determine whether to enable the access permission of the detection scanner to this device; if the access permission of the detection scanner to this device has been enabled, then it is possible to return to sub-step S31 to re-detect the liveness of the IP address; if the access permission of the detection scanner to this device has not been enabled, then issue an upgrade warning "The manual configuration of ACL access permissions is not completed", and at this time, the security team personnel need to intervene for processing.
[0208] Among them, referring to Figure 4 , the flowchart of automatically updating ACL access permissions provided by the embodiments of the present invention is shown. The process of the status of automatically updating ACL access permissions is as follows: The IP addresses missing in the list of live IP addresses can be matched with the existing network information asset library to distinguish the device types; for devices belonging to the host device type, any one of ansible, login script, and agent can be used to issue the ACL configuration; for devices belonging to the network device type and supporting the netconf protocol, any one of the netconf protocol and login script can be used to issue the ACL configuration; for devices belonging to the network device type but not supporting the netconf protocol, the login script can be used to issue the ACL configuration. Through the means capable of issuing the ACL configuration, the ACL access permissions are all in the opened state, and then the port scanning is started.
[0209] In a specific implementation, when determining the status of automatically updating ACL access permissions, an operation of automatically issuing the ACL configuration is carried out so that the detection scanner can access the asset IP address. Specifically, the IP addresses missing in the list of live IP addresses are matched with the existing network information asset library, so as to match the host devices and network devices, and then the network devices supporting the netconf protocol are marked as the first network devices, and the network devices not supporting the netconf protocol are marked as the second network devices.
[0210] For host devices, an operation of automatically issuing the ACL configuration is carried out: issued by ansible built in the host device; or issued by the login script; or issued by the agent built in the host device; or other tools that can remotely configure the ACL. Thus, through such means capable of issuing the ACL configuration, the access permission of the network information asset detection scanner is opened in the host device.
[0211] For the first network devices supporting the netconf protocol, an operation of automatically issuing the ACL configuration is carried out: issued by the netconf protocol; or issued by the login script; or other tools that can remotely configure the ACL. Thus, through such means capable of issuing the ACL configuration, the access permission of the network information asset detection scanner is opened in the network device.
[0212] For the second network device that does not support the Netconf protocol, perform the operation of automatically distributing the ACL configuration: It is distributed by the login script. Thus, through such means that can distribute the ACL configuration, the access permission to the network information asset detection scanner is allowed within the network device.
[0213] In an optional embodiment of the present invention, step 201 may include the following sub-steps:
[0214] Sub-step S81, when the asset detection indication information is the NAT configuration information of the firewall, obtain the five-tuple information of the NAT mapping configuration of the firewall; the five-tuple information includes the source IP address, source service port, destination IP address, destination service port, and service protocol;
[0215] Sub-step S82, extract the destination IP address, destination service port, and service protocol from the five-tuple information;
[0216] Sub-step S83, determine the destination IP address, destination service port, and service protocol as network information assets.
[0217] When the asset detection indication information is the NAT configuration information of the firewall, detect the firewall IP address mapping NAT configuration information of the cloud resource pool to locate the specific active asset IP address and its corresponding exposed surface port and application service. In other words, obtain the five-tuple information of the NAT mapping configuration in the firewall, especially the cloud resource pool node. Among them, the five-tuple information may include the source IP address, source service port, destination IP address, destination service port, and service protocol.
[0218] In a specific implementation, it is possible to interface with the firewall device, use a device login program (such as ssh, telnet, etc.) to connect to the firewall device, or other ways that can connect to the firewall to extract data to connect to the firewall device. Then, a script program (such as the Netconf protocol) can be used to obtain the five-tuple information of the NAT mapping configuration of the firewall: source IP address, source service port, destination IP address, destination service port, and service protocol. Then, extract the destination IP address, destination service port, and service protocol from the obtained five-tuple information as the standard information library. That is, determine the destination IP address as the IP address in the network information asset, and determine the destination service port as the port in the network information asset. Since the application service includes a communication service protocol, determine the service protocol as the application service in the network information asset. Next, perform the weak password detection process in step 202.
[0219] In an optional embodiment of the present invention, step 201 may include the following sub-steps:
[0220] Sub-step S81: When the asset detection indication information is traffic analysis, obtain the five-tuple information in the communication traffic; the five-tuple information includes the source IP address, source service port, destination IP address, destination service port, and service protocol.
[0221] Sub-step S82: Extract the destination IP address, destination service port, and service protocol from the five-tuple information.
[0222] Sub-step S83: Determine the destination IP address, destination service port, and service protocol as network information assets.
[0223] When the asset detection indication information is traffic analysis, the five-tuple information in the communication traffic can be obtained by parsing the traffic in a traffic analysis instrument or unit. Among them, the five-tuple information can include the source IP address, source service port, destination IP address, destination service port, and service protocol.
[0224] In a specific implementation, it is possible to connect to the traffic collection device of a switch or router, use a device login program (such as ssh, telnet, etc.) to connect to the traffic collection device, or other ways to connect to the device to connect to the traffic collection device. Then extract the five-tuple information from the traffic analysis: source IP address, source service port, destination IP address, destination service port, and service protocol. Then extract the destination IP address, destination service port, and service protocol from the obtained five-tuple information as the standard information library. That is, determine the destination IP address as the IP address in the network information asset, and determine the destination service port as the port in the network information asset. Since the application service includes a communication service protocol, the service protocol is determined as the application service in the network information asset. Next, carry out the weak password detection process in step 202.
[0225] In the prior art, weak password detection is achieved by analyzing plaintext keywords in the traffic. However, if it is not plaintext, weak password detection will encounter difficulties or even fail. In the embodiment of the present invention, by analyzing the five-tuple information in the traffic, the IP address is obtained, and then weak password brute force is performed on the IP address. Therefore, in the traffic analysis of the embodiment of the present invention, weak password detection can be achieved without plaintext.
[0226] Step 202: Detect whether there is a weak password in the IP address, port, and application service.
[0227] After detecting the IP address, port, and application service, the weak password detection process can be carried out. Weak password detection can use existing weak password feature libraries and weak password detection tools to detect the IP address, port, and application service.
[0228] The weak password feature library is the weak password feature library mastered by the enterprise. The data in the weak password feature library comes from the default accounts and passwords of application services publicly available in the market collected by the enterprise, common accounts and weak passwords collected in daily work, and application service accounts and passwords publicly known in the industry.
[0229] The weak password detection tool can include the open-source tool hydra, the open-source tool medusa, and other tools and scripts that can detect weak passwords.
[0230] In specific implementation, the existing weak password feature library and weak password detection tool can be loaded. The weak password detection tool uses the preset accounts and weak passwords in the weak password feature library to perform multiple simulated logins for the IP address, port, and application service to achieve the purpose of brute-force cracking. If the login is successful, a weak password is prompted. In the program of the weak password detection tool, the obtained IP address, exposed port number, and application service type are automatically loaded through programming language tools to realize the weak password detection of automated batch assets.
[0231] Step 203, if so, perform weak password early warning.
[0232] If a weak password is detected in the IP address, port, and application service, a weak password detection result early warning message can be sent for weak password early warning. Exemplarily, an email, short message, etc. containing the weak password detection result early warning message can be sent through the API interface. Among them, the early warning message can include information such as the weak password IP address, weak password asset name, exposed port, application service, weak password corresponding account, and specific weak password.
[0233] It can be seen that in the embodiment of the present invention, by detecting the IP address of the network information assets of the enterprise, locating the active assets, discriminating the detected surviving network information assets, and mining the blind area of the IP address of the enterprise's maintenance assets; by marking the newly discovered network information assets, updating and improving the existing network information asset IP library of the enterprise; by strengthening the ACL configuration of the asset devices, improving the success rate of the enterprise's asset devices against the network information asset detection scanner; based on the improvement of the asset discovery coverage rate, matching the asset IP address, exposed port number, and application service type, and automatically loading the matched IP address, exposed port number, and application service type into the weak password detection program through programming tools to realize the automated weak password detection of batch assets, improving the weak password detection efficiency and accuracy of the asset devices; the embodiment of the present invention not only improves the flexibility and scalability of the weak password monitoring architecture, but also greatly focuses on the purposefulness of the active assets detected for weak passwords, synchronously improving the weak password monitoring efficiency, supporting the enterprise's large-scale asset devices to independently carry out weak password monitoring work, and improving the security protection ability.
[0234] In summary, in the embodiments of the present invention, network information assets are detected through asset detection indication information, where the asset detection indication information includes network protocols, and / or ACL configuration information and routing configuration information, and / or NAT configuration information of the firewall, and / or traffic analysis. The network information assets include IP addresses, ports, and application services. Then, it is detected whether there are weak passwords in the IP addresses, ports, and application services. If so, a weak password warning is given. In the embodiments of the present invention, by integrating network protocols, ACL configuration information and routing configuration information, NAT configuration information of the firewall, and traffic analysis to detect network information assets, the coverage of network information assets can be improved, the detection depth of network information assets can be strengthened, and the asset discovery coverage and discovery ability can be effectively improved.
[0235] In addition to being able to solve the problems of insufficiently rich asset detection means and methods and coverage blind spots existing in the prior art mentioned in the background art, the embodiments of the present invention can also solve the following problems existing in the prior art:
[0236] A. In the prior art, there is a problem of relying on third-party online space mapping websites to collect the survival of the enterprise's asset IP addresses and the exposure of network information assets:
[0237] A1. The space mapping website relies on third-party online detection. When the third-party online detection stops service or the service changes, the source of asset information for weak password detection will be blocked, resulting in the failure of weak password detection.
[0238] A2. At the same time, it will cause the weak password monitoring method to be inapplicable to the enterprise intranet, restricting both the enterprise's autonomy and flexibility in extended applications, and the scalability is also restricted by the third party.
[0239] In response to this, the embodiments of the present invention propose a method for automated weak password monitoring based on the basis of independently and automatically discovering assets, which can solve the problems of such independent deployment and automated batch detection of weak passwords.
[0240] Specifically, for problem A1, the embodiments of the present invention carry out the process of automatically detecting network information assets based on network protocols, ACL configuration information and routing configuration information, NAT configuration information of the firewall, and traffic analysis. The obtained information is extracted using a programming language (such as Python and other programming languages): IP addresses, service ports, and service protocols. Then, the obtained IP addresses, service ports, and service protocols are used as command parameters for the open-source tools "hydra or medusa" to achieve automated weak password cracking.
[0241] As can be seen, the above solution for A1 illustrates the method of the embodiment of the present invention for independently and automatically discovering assets, which is different from the method of discovering assets by using a spatial mapping website. The embodiment of the present invention can get rid of the dependence on third-party online detection. Especially when the asset discovery function becomes unavailable due to reasons such as maintenance, service suspension, or change of third-party online detection, the method of detecting weak passwords by relying on third-party online spatial mapping websites will fail, resulting in obstacles to obtaining network information assets. Since the embodiment of the present invention does not rely on third-party websites to obtain network asset information, this problem does not exist in the embodiment of the present invention.
[0242] Specifically, for problem A2, based on the principle of obtaining assets in the embodiment of the present invention, it can be deployed within the enterprise intranet, private network, and local area network, and asset discovery and weak password detection can be carried out within the intranet, private network, and local area network. Since the prior art relies on third-party asset mapping websites, a connection needs to be established with the third-party asset mapping website on the network. However, this is difficult to implement because many intranets, private networks, and local area networks do not have external connection outlets, so it is not certain that a connection can be established with the external network within the intranet, private network, and local area network. Moreover, if the third-party asset mapping website is to be deployed within the intranet, private network, and local area network, there will be problems such as authorization of the third-party asset mapping website, source code deployment, and adaptation.
[0243] B. In the prior art, there is only automated monitoring of weak passwords for a certain service, but it is impossible to achieve automated weak password detection and monitoring for automatically discovering multiple types of services in the face of a large number of network information assets, and the efficiency of weak password detection and monitoring is relatively low.
[0244] In this regard, the embodiment of the present invention can solve the problems of automatically discovering multiple types of services, automatically detecting weak passwords, and improving the efficiency of weak password monitoring.
[0245] Specifically, the embodiment of the present invention performs batch detection of service ports (exposed surfaces) and service protocols for multiple assets (based on network protocols, ACL configuration information, routing configuration information, NAT configuration information of the firewall, and traffic analysis), obtains multiple service ports (exposed surfaces) and service protocol information of multiple assets, and then performs unified batch automated detection based on these large amounts of data (such as using open-source tools such as hydra and medusa), achieving weak password automated detection for multiple service ports and multiple service protocols of multiple assets, rather than just detecting weak passwords for one service.
[0246] C. In the prior art, the situation where there is already a fortified ACL in the enterprise's assets is not considered, and there may be a blind spot in truly collecting the exposed surfaces of network information assets, resulting in the omission of application service types of the exposed surfaces of the network information assets, and further causing defects in the overall weak password detection work.
[0247] In this regard, the embodiments of the present invention can solve this problem.
[0248] Specifically, the existence of the ACL policy will limit the coverage of asset discovery. The embodiments of the present invention solve the problem of asset discovery limitation caused by the ACL policy through the implementation of sub-steps S41-S42, sub-steps S51-S53, and sub-steps S61-S64.
[0249] To enable those skilled in the art to better understand the embodiments of the present invention, the embodiments of the present invention will be described below through the following general process:
[0250] Reference Figure 5 , which shows the general flowchart of weak password detection provided by the embodiments of the present invention. The general process of weak password detection can be as follows:
[0251] a100: Start the overall detection work, and distinguish four asset detection processes: Process 1 "Based on network protocol", Process 2 "Based on ACL routing information and routing configuration information", Process 3 "Based on the NAT configuration information of the firewall", and Process 4 "Based on traffic analysis".
[0252] a200: Process 1 "Based on network protocol"; Access step s100: Start the weak password detection work.
[0253] a300: Process 2 "Based on ACL routing information and routing configuration information"; a3001: The object is the ACL configuration information and routing configuration information in the network device; a3002: Further extract the specific IP address information; Among them, steps a3001 and a3002 are the steps in process a300. After step a3002, access step s100: Start the weak password detection work.
[0254] a400: Process 3 "Based on the NAT configuration information of the firewall"; a4001: Obtain the five-tuple information of the NAT configuration in the firewall: source IP address, source service port, destination IP address, destination service port, service protocol; a602: Extract the asset IP address information, exposed port information, and application services; Among them, steps a4001 and a6002 are the steps in process a400. After step a6002, access step s204: Conduct weak password detection: Load the existing weak password feature library, load the weak password detection tool, and load the IP, port, and service.
[0255] a500: Process Four "Based on Traffic Analysis"; a5001: In a traffic analysis instrument or unit, obtain five-tuple information in traffic communication by parsing traffic: source IP address, source service port, destination IP address, destination service port, service protocol; a6002: Extract asset IP address information, exposed port information, and application services; among them, steps a5001 and a6002 are steps in process a500. After step a6002, access step s204: Conduct weak password detection: Load an existing weak password feature library, load a weak password detection tool, and load IPs, ports, and services.
[0256] Among them, processes a200, a300, a400, and a500 can be processed in parallel.
[0257] Reference Figure 6 , shows the overall flowchart of weak password detection provided by an embodiment of the present invention. Among them, Figure 6 is to access Figure 5 step s100 in
[0258] s100: Start weak password detection work;
[0259] J100: Detect asset liveness: Cover all planned assets, that is, determine whether it is necessary to detect all network information assets; if not, transfer to step s101; if so, transfer to step s102;
[0260] s101: Load an existing network information asset library (or an existing network information asset IP address library), and transfer to step s200;
[0261] s102: Load a blacklist network information asset library (or a blacklist network information asset IP library) to exclude IP addresses included in the blacklist network information asset library, and transfer to step s103;
[0262] s103: Start IP asset liveness detection;
[0263] s104: Obtain a list of surviving asset IP addresses;
[0264] s105: Match the list of surviving asset IP addresses with the existing network information asset IP address library;
[0265] s106: If a list of IP addresses consistent with the existing network information asset IP address library is obtained through matching, transfer to step s200;
[0266] s107: If a list of IP addresses more than the existing network information asset IP address library is obtained through matching, transfer to step s107.1;
[0267] s108: If the obtained IP address list has fewer IP addresses than the existing network information asset IP address library, then transfer to step s108.1;
[0268] s107.1: Determine the extra IP addresses obtained in step s107 as newly discovered network information assets, and transfer to step J300;
[0269] J300: Determine whether manual confirmation of asset ownership is required; if so, transfer to step s107.2; if not, transfer to step J302;
[0270] s107.2: Conduct manual confirmation of asset ownership to confirm whether the asset belongs to this enterprise, and transfer to step J301;
[0271] J301: Determine whether it is an asset IP address in use by the enterprise; if so, transfer to step s107.5; if not, transfer to step s107.3;
[0272] s107.3: Discard the newly discovered network information assets: Incorporate the newly discovered asset IP addresses that do not belong to the assets in use by this enterprise into the blacklist network information asset library, so as not to detect the viability of the asset IP addresses anymore, and do not conduct subsequent weak password detection processes;
[0273] J302: Determine whether it is necessary to write the newly discovered network information asset IP addresses into the existing network information asset library (or the existing network information asset IP address library): if so, transfer to step s107.5; if not, transfer to step s107.4;
[0274] s107.4: Discard the newly discovered network information assets: Incorporate the newly discovered asset IP addresses that do not need to be written into the blacklist network information asset library, so as not to detect the viability of the asset IP addresses anymore, and do not conduct subsequent weak password detection processes.
[0275] s107.5: Update the existing network information asset IP address library: Write the newly discovered asset IP addresses that belong to the assets in use by this enterprise into the existing network information asset IP address library, and transfer to step s200;
[0276] s108.1: Conduct automated inspection of ACL policy access permissions: Match the fewer IP addresses obtained in step s108 with the existing network information asset library to obtain device type information that distinguishes device types (for details, please refer to Figure 3 the shown automated inspection ACL access permission flowchart), and transfer to step J201;
[0277] J201: Determine whether the access permission of the detection scanner ACL has been released; if so, proceed to step s200; if not, proceed to step J202.
[0278] J202: Determine whether the access permission of the device ACL policy is modified automatically; if so, proceed to step s108.3; if not, proceed to step s108.2.
[0279] s108.2: Conduct manual configuration of the access permission of the ACL policy and proceed to step J203;
[0280] J203: Determine whether the ACL policy configuration is completed, that is, determine whether the access permission of the detection scanner to this device is allowed; if so, restart step s103 for the asset IP of the newly allowed ACL to start detecting asset liveness again; if not, proceed to step s108.4;
[0281] s108.4: Issue an upgrade warning "Manual configuration of the ACL policy is not completed". At this time, the security team personnel need to intervene and proceed to step s108.2;
[0282] s108.3: Start automatic distribution of the ACL policy to automatically update the access permission of the ACL policy so that the detection scanner can access the asset (for details, please refer to Figure 4 the flowchart of automatic update of the ACL access permission shown), and proceed to step s200;
[0283] s200: Start scanning of the application service ports, that is, start scanning the liveness of the ports corresponding to the IP address of the network information asset, and proceed to step s201;
[0284] s201: Obtain the matching relationship between the asset IP address and the open ports, that is, obtain the port liveness list corresponding to the IP address of the network information asset, and proceed to step s202;
[0285] s202: Start scanning of the application service types, that is, start scanning the services of the ports corresponding to the asset IP address, and proceed to step s203;
[0286] s203: Obtain the corresponding relationship between the ports of the asset IP address and the application service types, that is, obtain the open ports of the IP address of the network information asset and the corresponding application service names, and proceed to step s204;
[0287] s204: Conduct weak password detection: Load the existing weak password feature library, load the weak password detection tool, load the IP, ports, and services, and proceed to step J400;
[0288] J400: Determine whether a weak password is detected; if so, proceed to step s300; if not, return to step s100;
[0289] s300: Send a warning message about the weak password detection result: information such as the IP address with a weak password, asset name, exposed port, application service, account corresponding to the weak password, and specific weak password.
[0290] To enable those skilled in the art to better understand the embodiments of the present invention, the embodiments of the present invention are described below through Examples 1 to 5:
[0291] Example 1
[0292] It involves docking with a firewall device and a traffic collection device for a switch (or router). The specific process is as follows:
[0293] Step A1: Connect to the firewall device: It can be connected using a device login program (such as ssh, telnet, etc.), or other methods that can connect to the firewall to extract data; and connect to the network traffic collection device: It can be connected using a device login program (such as ssh, telnet, etc.), or other methods that can connect to the device.
[0294] Step A2: Obtain the NAT mapping five-tuple information of the firewall through a script or other program: The five-tuple information (source IP address, source service port, destination IP address, destination service port, service protocol) of the NAT mapping configuration can be obtained using the netconf protocol; and extract the five-tuple information (source IP address, source service port, destination IP address, destination service port, service protocol) from the traffic analysis.
[0295] Step A3: Extract "destination IP address, destination service port, service protocol" from the obtained five-tuple information of "source IP address, source service port, destination IP address, destination service port, service protocol" as the standard information library.
[0296] Step A4: Conduct weak password detection: Load the existing weak password feature library, load the weak password detection tool, and load the IP, port, and service.
[0297] Step A5: Determine whether a weak password is detected.
[0298] Step A6: If a weak password is detected, send a warning message about the weak password detection result; among them, the warning message can include information such as the weak password IP address, weak password asset name, exposed port, application service, account corresponding to the weak password, and specific weak password.
[0299] Example 2
[0300] It involves the existing network information asset library of the enterprise. This existing network information asset library contains the IP addresses of the network information assets in use by the enterprise, whether the assets are host devices or network devices, and whether the network devices support the netconf protocol. The specific process is as follows:
[0301] Step B1: Load the existing network information asset library;
[0302] Step B2: Conduct corresponding port liveness detection for the IP addresses of the network information assets in the existing network information asset library;
[0303] Step B3: Obtain the port liveness list corresponding to the IP addresses of the network information assets;
[0304] Step B4: Start the service scan for the ports corresponding to the asset IP addresses;
[0305] Step B5: Obtain the open ports of the IP addresses of the network information assets and the corresponding application service names;
[0306] Step B6: Conduct weak password detection: Load the existing weak password feature library, load the weak password detection tool, and load the IP, port, and service;
[0307] Step B7: Determine whether a weak password is found;
[0308] Step B8: If a weak password is found, send a warning message about the weak password detection result; among them, the warning message can include information such as the weak password IP address, the weak password asset name, the exposed surface port, the application service, the account corresponding to the weak password, and the specific weak password.
[0309] Example Three
[0310] It involves the network information assets planned by the enterprise. This planned network information asset contains the IP address segment information planned to be used by the enterprise. Moreover, it also involves the existing network information asset library of the enterprise. This existing network information asset library contains the IP addresses of the network information assets in use by the enterprise, whether the assets are host devices or network devices, and whether the network devices support the netconf protocol. The specific process is as follows:
[0311] Step C1: For the 'IP address segment information planned to be used by the enterprise', start the detection of all network information assets, that is, remove the IP addresses in the blacklist from the 'IP address segment information planned to be used by the enterprise' to obtain the 'list of planned IP addresses after removing the blacklist';
[0312] Step C2: Start the liveness scan of the asset IP addresses for the 'list of planned IP addresses after removing the blacklist';
[0313] Step C3: Obtain the list of IP addresses of network information assets that survived after probing for liveness;
[0314] Step C4: Match the "list of IP addresses of network information assets that survived after probing for liveness" with the "existing network information asset library" to obtain three types of IP address lists: The first type of IP address list is the "IP address list that is the same as the 'existing network information asset library'" (perform Step C5.1); The second type of IP address list is the "IP address list that is more than the 'existing network information asset library'", that is, the 'newly discovered network information assets' (perform Step C5.2); The third type of IP address list is the "IP address list that is less than the 'existing network information asset library'", that is, the 'network information assets that cannot be detected' (perform Step C5.3);
[0315] Step C5.1: For the first type of IP address list ("IP address list that is the same as the 'existing network information asset library'"), directly transfer to Step C6;
[0316] Step C5.2: For the second type of IP address list ("IP address list that is more than the 'existing network information asset library'"), perform matching of newly discovered IP address assets: Write the 'newly discovered network information assets' into the 'existing network information asset library' to complete the IP address update of the 'existing network information asset library'; Based on the updated 'existing network information asset library', transfer to Step C6;
[0317] Step C5.3: For the third type of IP address list ("IP address list that is less than the 'existing network information asset library'"), start automated inspection of the ACL configuration of the asset: Determine whether the ACL access permission for the probing scanner has been opened; If so, transfer to Step C6; If not, perform automated modification of the device ACL policy access permission. After the automated modification, the probing scanner can access the asset, and then transfer to Step C6;
[0318] Step C6: Start port scanning of the application service to obtain the open ports of the asset IP address; Perform application service type scanning on the open ports of the asset IP address to obtain the correspondence between the ports of the asset IP address and the application service types; Perform weak password detection on the asset IP address, ports, and application services to obtain the detection result of whether weak passwords exist; If weak passwords are found, give an early warning; If weak passwords are not found, restart the weak password detection work.
[0319] Example 4
[0320] In actual production work, it is necessary to consider multiple types and require manual participation to confirm complex operation scenarios in order to enhance the security of the system process and avoid affecting business performance and usage in production work. For example: In the IP address detection of assets, it is possible that the IP addresses within the planned network segment do not belong to the IP addresses actually used by the enterprise, but the network information asset IP addresses are lent out. Then, such IP addresses need to be excluded from the weak password detection process. Another example: When modifying the ACL configuration so that the asset network element can be accessed by the asset detection scanner, the action of automatically modifying the ACL has certain business usage risks and requires manual intervention to enhance the security of automatically modifying the ACL configuration. The specific process is as follows:
[0321] Step D1: According to actual production needs, select to conduct a full-scale detection of all network information assets according to the 'IP address segment information planned for use by the enterprise' to determine the usage status of asset IP addresses;
[0322] Step D2: Match all the detected asset IP addresses with the 'existing network information asset library' to obtain three types of IP address lists: The first type of IP address list is the 'IP address list that is consistent with the 'existing network information asset library'' (perform Step D3.1); The second type of IP address list is the 'IP address list that is more than the 'existing network information asset library'', that is, the 'newly discovered network information assets' (perform Step D3.2); The third type of IP address list is the 'IP address list that is less than the 'existing network information asset library'', that is, the 'network information assets that cannot be detected' (perform Step D3.3);
[0323] Step D3.1: For the first type of IP address list ('IP address list that is consistent with the 'existing network information asset library'), directly transfer to Step D4;
[0324] Step D3.2: For the second type of IP address list ('IP address list that is more than the 'existing network information asset library'), conduct matching of newly discovered IP address assets: Manually confirm the IP addresses of newly discovered network information assets; After manual confirmation, write the asset IP addresses that belong to the enterprise in use into the 'existing network information asset library'; After manual confirmation, write the asset IP addresses that do not belong to the enterprise in use into the 'blacklist network information asset library', and the asset IP addresses in the 'blacklist network information asset library' do not participate in all subsequent detection processes; Based on the updated 'existing network information asset library', transfer to Step D4;
[0325] Step D3.3: For the third type of IP address list ('IP address list that is less than the 'existing network information asset library'), start an automated check of the ACL configuration of the assets (for details, please refer to Figure 3The flowchart of automated inspection of ACL access rights as shown; determine whether to open the ACL access right of the probe scanner; if the ACL access right of the probe scanner has been opened, transfer to step D4; if the ACL access right of the probe scanner has not been opened, transfer to step D3.3.1;
[0326] Step D3.3.1: Further determine whether to automatically modify the ACL policy access right of the device;
[0327] Step D3.3.1.1: If it is not necessary to automatically modify the ACL policy access right of the asset and manual configuration of ACL is required, perform manual ACL policy configuration and further verify whether the manual configuration of the ACL policy is completed; if the manual ACL configuration has been completed, restart the detection of asset liveness; if the manual ACL configuration has not been completed, send a warning escalation email: prompt "The manual configuration of the ACL policy has not been completed", and at this time, security team personnel need to intervene and handle it;
[0328] Step D3.3.1.2: If it is necessary to automatically modify the ACL policy access right of the asset, start the automatic modification of the ACL configuration of the asset and transfer to step D4;
[0329] Step D4: Start the port scanning of the application service to obtain the open ports of the asset IP address; perform application service type scanning on the open ports of the asset IP address to obtain the correspondence between the ports of the asset IP address and the application service types; perform weak password detection on the asset IP address, ports, and application services to obtain the detection result of whether weak passwords exist; if weak passwords are found, give a warning; if no weak passwords are found, restart the weak password detection work.
[0330] Example Five
[0331] To simplify the production steps, in the actual application process, directly conduct detection from the existing network information asset library of the enterprise, complete the detection of network information asset liveness, exposed surface port detection, and corresponding application service type detection. After obtaining the surviving network information assets and their corresponding exposed surface ports and application service types, conduct weak password detection and give a warning about the detected weak password results. The specific process is as follows:
[0332] Step E1: Load the existing network information asset library;
[0333] Step E2: Conduct the liveness detection of the IP addresses of network information assets; after the liveness detection is completed, further conduct exposed surface port detection on the IP addresses of the surviving network information assets; further conduct application service type detection corresponding to the exposed surface ports of the IP addresses of network information assets;
[0334] Step E3: After obtaining the IP addresses, exposed ports, and application service types of the surviving network information assets, use the known weak password feature library to conduct weak password detection on the network information assets;
[0335] Step E4: If weak passwords are found, send a warning message about the weak password detection results; among them, the warning message may include information such as the weak password IP address, weak password asset name, exposed port, application service, weak password corresponding account, and specific weak password.
[0336] Reference Figure 7 , showing the structural block diagram of a weak password detection device provided by an embodiment of the present invention, which may specifically include the following modules:
[0337] Network information asset detection module 701, configured to detect network information assets based on asset detection indication information; the asset detection indication information includes network protocols, and / or, access control list ACL configuration information and routing configuration information, and / or, network address translation NAT configuration information of the firewall, and / or, traffic analysis; the network information assets include Internet protocol IP addresses, ports, and application services;
[0338] Weak password detection module 702, configured to detect whether there are weak passwords in the IP addresses, ports, and application services;
[0339] Weak password warning module 703, configured to, if so, perform weak password warning.
[0340] In an optional embodiment of the present invention, the network information asset detection module 701 is specifically configured to:
[0341] When the asset detection indication information is a network protocol, determine whether it is necessary to detect all network information assets;
[0342] If so, load the planned network information assets; the planned network information assets include IP addresses;
[0343] Eliminate the IP addresses that match the blacklist of network information asset IPs;
[0344] Use the eliminated IP addresses to detect network information assets.
[0345] In an optional embodiment of the present invention, the network information asset detection module 701 is specifically configured to:
[0346] When the asset detection indication information is ACL configuration information and routing configuration information, obtain the ACL configuration information and routing configuration information; the ACL configuration information and routing configuration information include IP addresses;
[0347] Determine whether it is necessary to detect all network information assets;
[0348] If so, exclude the IP addresses that match the blacklist of network information asset IPs;
[0349] Use the excluded IP addresses to detect network information assets.
[0350] In an alternative embodiment of the present invention, the network information asset detection module 701 is further configured to:
[0351] Perform liveness detection on the excluded IP addresses;
[0352] Output the surviving IP addresses as a list of surviving IP addresses;
[0353] Match the list of surviving IP addresses with the existing network information asset IP database;
[0354] Detect network information assets according to the matching result.
[0355] In an alternative embodiment of the present invention, the network information asset detection module 701 is further configured to:
[0356] When the matching result is that the list of surviving IP addresses is the same as the existing network information asset IP database, perform port scanning and service scanning on the IP addresses in the existing network information asset IP database in sequence to obtain the ports and application services corresponding to the IP addresses;
[0357] Determine the IP addresses, ports, and application services as network information assets.
[0358] In an alternative embodiment of the present invention, the network information asset detection module 701 is further configured to:
[0359] When the matching result is that the list of surviving IP addresses is more than the existing network information asset IP database, use the extra IP addresses in the list of surviving IP addresses to update the existing network information asset IP database;
[0360] Perform port scanning and service scanning on the IP addresses in the updated existing network information asset IP database in sequence to obtain the ports and application services corresponding to the IP addresses;
[0361] Determine the IP addresses, ports, and application services as network information assets.
[0362] In an alternative embodiment of the present invention, the network information asset detection module 701 is further configured to:
[0363] When the matching result shows that the list of surviving IP addresses is less than the existing IP library of network information assets, detect the status of the ACL access permission;
[0364] If the ACL access permission is in an unopened state, update the status of the ACL access permission;
[0365] Based on the updated ACL access permission, perform port scanning and service scanning on the IP addresses in the existing IP library of network information assets in sequence to obtain the ports and application services corresponding to the IP addresses;
[0366] Determine the IP addresses, ports, and application services as network information assets.
[0367] In an alternative embodiment of the present invention, the network information asset detection module 701 is further configured to:
[0368] If the ACL access permission is in an unopened state, determine whether to automatically update the status of the ACL access permission;
[0369] If so, match the IP addresses missing in the list of surviving IP addresses with the existing network information asset library to determine the devices corresponding to the missing IP addresses; the devices include host devices and network devices;
[0370] For the host devices, use the automated operation and maintenance tool ansible, or a login script, or an agent program agent to issue the ACL configuration to open the ACL access permission;
[0371] For the network devices, mark the network devices that support the network configuration netconf protocol as the first network devices, and mark the network devices that do not support the network configuration netconf protocol as the second network devices;
[0372] For the first network devices, use the netconf protocol, or a login script, to issue the ACL configuration to open the ACL access permission;
[0373] For the second network devices, use a login script to issue the ACL configuration to open the ACL access permission.
[0374] In an alternative embodiment of the present invention, the network information asset detection module 701 is specifically configured to:
[0375] When the asset detection indication information is the NAT configuration information of the firewall, obtain the five-tuple information of the NAT mapping configuration of the firewall; the five-tuple information includes the source IP address, source service port, destination IP address, destination service port, and service protocol;
[0376] Extract the destination IP address, destination service port, and service protocol from the quintuple information;
[0377] Determine the destination IP address, destination service port, and service protocol as network information assets.
[0378] In an optional embodiment of the present invention, the network information asset detection module 701 is specifically configured to:
[0379] When the asset detection indication information is traffic analysis, obtain the quintuple information in the communication traffic; the quintuple information includes the source IP address, source service port, destination IP address, destination service port, and service protocol;
[0380] Extract the destination IP address, destination service port, and service protocol from the quintuple information;
[0381] Determine the destination IP address, destination service port, and service protocol as network information assets.
[0382] In summary, in the embodiments of the present invention, network information assets are detected through asset detection indication information, where the asset detection indication information includes network protocols, and / or, ACL configuration information and routing configuration information, and / or, NAT configuration information of the firewall, and / or, traffic analysis. Network information assets include IP addresses, ports, and application services. Then, it is detected whether there are weak passwords in the IP addresses, ports, and application services. If so, a weak password warning is issued. The embodiments of the present invention detect network information assets by integrating network protocols, ACL configuration information and routing configuration information, NAT configuration information of the firewall, and traffic analysis, thereby improving the coverage of network information assets, strengthening the detection depth of network information assets, and effectively improving the asset discovery coverage and discovery ability.
[0383] For the device embodiments, since they are basically similar to the method embodiments, the description is relatively simple. For the relevant parts, please refer to the partial description of the method embodiments.
[0384] The embodiments of the present invention also provide an electronic device, including: a processor, a memory, and a computer program stored on the memory and executable on the processor. When the computer program is executed by the processor, it implements each process of the above-mentioned weak password detection method embodiment and can achieve the same technical effects. To avoid repetition, it will not be elaborated here.
[0385] An embodiment of the present invention also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements each process of the above-mentioned weak password detection method embodiment and can achieve the same technical effect. To avoid repetition, it will not be elaborated here.
[0386] Each embodiment in this specification is described in a progressive manner. The key point of each embodiment is to illustrate the differences from other embodiments. The same or similar parts among the embodiments can be referred to each other.
[0387] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a device, or a computer program product. Therefore, the embodiments of the present invention can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the embodiments of the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0388] The embodiments of the present invention are described with reference to the flowcharts and / or block diagrams of the methods, terminal devices (systems), and computer program products according to the embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram can be implemented by computer program instructions, and the combination of the processes and / or blocks in the flowchart and / or block diagram can also be implemented. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing terminal devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing terminal devices generate a device for implementing the functions specified in one Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.
[0389] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing terminal device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured product including an instruction device, and the instruction device implements the functions specified in one Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.
[0390] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal device, so that a series of operation steps are executed on the computer or other programmable terminal device to generate a computer-implemented process. Therefore, the instructions executed on the computer or other programmable terminal device provide for implementing the functions in the process Figure 1steps of the functions specified in one or more processes and / or blocks Figure 1 and / or one or more blocks.
[0391] Although the preferred embodiments of the embodiments of the present invention have been described, those skilled in the art can make additional changes and modifications to these embodiments once they know the basic creative concept. Therefore, the appended claims are intended to be construed to include the preferred embodiments and all changes and modifications that fall within the scope of the embodiments of the present invention.
[0392] Finally, it should also be noted that in this text, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or terminal device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or elements inherent to such process, method, article or terminal device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or terminal device comprising the element.
[0393] The weak password detection method, device, electronic device and computer-readable storage medium provided by the present invention have been introduced in detail above. Specific examples are used in this text to illustrate the principle and implementation manner of the present invention. The description of the above embodiments is only used to help understand the method and its core idea of the present invention; at the same time, for those of ordinary skill in the art, according to the idea of the present invention, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to the present invention.
Claims
1. A weak password detection method, characterized in that The method includes: Detecting network information assets based on asset detection indication information; the asset detection indication information includes network protocols, access control list (ACL) configuration information, routing configuration information, network address translation (NAT) configuration information of the firewall, and traffic analysis; the network information assets include Internet Protocol (IP) addresses, ports, and application services; wherein, the network protocols, the ACL configuration information, the routing configuration information, the NAT configuration information of the firewall, and the traffic analysis are processed in parallel; Detecting whether there are weak passwords in the IP addresses, ports, and application services; If so, issuing a weak password warning; Wherein, when the asset detection indication information is ACL configuration information and routing configuration information, obtaining the ACL configuration information and routing configuration information; the ACL configuration information and routing configuration information include IP addresses; Judging whether it is necessary to detect all network information assets; If so, excluding the IP addresses that match the blacklist of network information asset IPs; Performing liveness detection on the excluded IP addresses; Outputting the surviving IP addresses as a list of surviving IP addresses; Matching the list of surviving IP addresses with the existing network information asset IP library; When the matching result is that the list of surviving IP addresses is less than the existing network information asset IP library, detecting the status of the ACL access permission; If the ACL access permission is in an unopened state, determining whether to automatically update the status of the ACL access permission; If so, matching the missing IP addresses in the list of surviving IP addresses with the existing network information asset library to determine the devices corresponding to the missing IP addresses; the devices include host devices and network devices; For the host devices, using the automated operation and maintenance tool ansible, or a login script, or an agent program, to issue the ACL configuration to open the ACL access permission; For the network devices, marking the network devices that support the network configuration netconf protocol as first network devices, and marking the network devices that do not support the network configuration netconf protocol as second network devices; For the first network devices, using the netconf protocol, or a login script, to issue the ACL configuration to open the ACL access permission; For the second network devices, using a login script to issue the ACL configuration to open the ACL access permission; Based on the updated ACL access permission, performing port scanning and service scanning on the IP addresses in the existing network information asset IP library in sequence to obtain the ports and application services corresponding to the IP addresses; Determining the IP addresses, ports, and application services as network information assets.
2. The method according to claim 1, characterized in that, The detecting of network information assets based on asset detection indication information includes: When the asset detection indication information is a network protocol, judging whether it is necessary to detect all network information assets; If so, load the planned network information assets; the planned network information assets include IP addresses; Exclude the IP addresses that match the blacklist network information asset IP library; Use the excluded IP addresses to detect network information assets.
3. The method according to claim 1, characterized in that, The method includes: When the matching result shows that the list of live IP addresses is the same as the existing network information asset IP library, perform port scanning and service scanning on the IP addresses in the existing network information asset IP library in sequence to obtain the ports and application services corresponding to the IP addresses; Determine the IP addresses, ports, and application services as network information assets.
4. The method according to claim 1, characterized in that The detecting network information assets based on the asset detection indication information includes: When the asset detection indication information is the NAT configuration information of the firewall, obtain the five-tuple information of the NAT mapping configuration of the firewall; the five-tuple information includes source IP address, source service port, destination IP address, destination service port, and service protocol; Extract the destination IP address, destination service port, and service protocol from the five-tuple information; Determine the destination IP address, destination service port, and service protocol as network information assets.
5. The method according to claim 1, characterized in that The detecting network information assets based on the asset detection indication information includes: When the asset detection indication information is traffic analysis, obtain the five-tuple information in the communication traffic; the five-tuple information includes source IP address, source service port, destination IP address, destination service port, and service protocol; Extract the destination IP address, destination service port, and service protocol from the five-tuple information; Determine the destination IP address, destination service port, and service protocol as network information assets.
6. A weak password detection device, characterized in that, The device includes: A network information asset detection module for detecting network information assets based on asset detection indication information; the asset detection indication information includes network protocol, access control list (ACL) configuration information, routing configuration information, network address translation (NAT) configuration information of the firewall, and traffic analysis; the network information assets include Internet protocol (IP) addresses, ports, and application services; among them, the network protocol, the access control list (ACL) configuration information, the routing configuration information, the network address translation (NAT) configuration information of the firewall, and the traffic analysis are processed in parallel; A weak password detection module for detecting whether there is a weak password in the IP addresses, ports, and application services; A weak password warning module for, if so, giving a weak password warning; Among them, the network information asset detection module is specifically used for: When the asset detection indication information is ACL configuration information and routing configuration information, obtain the ACL configuration information and routing configuration information; the ACL configuration information and routing configuration information include IP addresses; Judge whether it is necessary to detect all network information assets; If so, exclude the IP addresses that match the blacklist network information asset IP library; Perform liveness detection on the excluded IP addresses; Output the live IP addresses as a list of live IP addresses; Match the list of live IP addresses with the existing network information asset IP library; When the number of the matched live IP address list is less than that of the existing IP library of network information assets, detect the status of the ACL access permission; If the ACL access permission is in an unopened state, determine whether to automatically update the status of the ACL access permission; If so, match the missing IP addresses in the live IP address list with the existing network information asset library to determine the devices corresponding to the missing IP addresses; the devices include host devices and network devices; For the host devices, use the automated operation and maintenance tool ansible, or login script, or agent program to issue the ACL configuration to open the ACL access permission; For the network devices, mark the network devices that support the network configuration netconf protocol as the first network devices, and mark the network devices that do not support the network configuration netconf protocol as the second network devices; For the first network devices, use the netconf protocol, or login script, to issue the ACL configuration to open the ACL access permission; For the second network devices, use the login script to issue the ACL configuration to open the ACL access permission; Based on the updated ACL access permission, perform port scanning and service scanning on the IP addresses in the existing IP library of network information assets in sequence to obtain the ports and application services corresponding to the IP addresses; Determine the IP addresses, ports, and application services as network information assets.
7. An electronic device, characterized in that, Including: A processor, a memory, and a computer program stored on the memory and executable on the processor, where when the computer program is executed by the processor, the steps of the weak password detection method according to any one of claims 1 to 5 are implemented.
8. A computer-readable storage medium, characterized in that, A computer program is stored on the computer-readable storage medium, and when the computer program is executed by the processor, the steps of the weak password detection method according to any one of claims 1 to 5 are implemented.
Citation Information
Patent Citations
Asset increment automatic-detecting analysis method and apparatus
CN107579876A
Mixed asset analysis processing method and device, electronic equipment and storage medium
CN111090615A
Weak password detection method and device, readable storage medium and computer equipment
CN112351003A