System evaluation method, device, equipment and storage medium
By building an attack information database and a technical and tactical database and simulating complex attack actions, the problem of low system evaluation efficiency is solved and efficient and accurate system evaluation is achieved.
Patent Information
- Application Number
- CN202211263549.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-09
- Publication Date
- 2025-09-05
- Estimated Expiration
- 2042-10-09
AI Technical Summary
The system evaluation efficiency in the existing technology is low, and it is unable to simulate complex and large-scale attack actions and effectively deal with complex attack methods.
Build an attack information database, select attack factors and instantiate technical and tactical examples, execute technical and tactical examples and generate system evaluation results, and use the attack information database and technical and tactical database to simulate complex attack actions.
It improves the efficiency and accuracy of system evaluation, can effectively simulate complex and large-scale attack actions, and generate detailed evaluation reports.
Smart Images

Figure CN115632975B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technology, and in particular to a system evaluation method, device, equipment and storage medium. Background Art
[0002] In existing technologies, information infrastructure, information systems and services, and critical data are becoming increasingly important. Faced with increasingly sophisticated attack vectors, systematic and persistent attack security assessments are urgently needed to ensure the security of these assets. However, existing manual assessments are inefficient and cannot simulate complex, large-scale attacks.
[0003] The above content is only used to assist in understanding the technical solution of the present invention and does not constitute an admission that the above content is prior art. Summary of the Invention
[0004] The main purpose of the present invention is to provide a system evaluation method, device, equipment and storage medium, aiming to solve the technical problem of how to perform systematic and persistent offensive security evaluation.
[0005] To achieve the above object, the present invention provides a system evaluation method, which includes the following steps:
[0006] Build an attack information database based on preset attack information and technical and tactical database;
[0007] Selecting an attack factor from the attack information database and instantiating the attack factor to obtain a technique and tactic instance;
[0008] Execute the technical and tactical examples, and generate system evaluation results based on the execution information and execution results generated during the execution of the technical and tactical examples.
[0009] Optionally, the step of executing the technical and tactical example and generating a system evaluation result based on execution information and execution results generated during the execution of the technical and tactical example includes:
[0010] Execute the technical and tactical examples and record the execution information generated during the execution process in real time;
[0011] Performing feature extraction on the execution information to obtain a feature extraction result;
[0012] Instantiating the attack factors in the attack information database according to the feature extraction result;
[0013] Traversing the techniques and tactics library according to the attack information library, and determining whether the traversed techniques and tactics are executable;
[0014] If so, instantiate the traversed techniques and tactics to obtain a technique and tactics instance, and return to the step of executing the technique and tactics instance, and generate a system evaluation result based on the execution information and execution results generated during the execution of the technique and tactics instance.
[0015] Optionally, after the step of traversing the technique and tactics library according to the attack information library and determining whether the traversed technique and tactics are executable, the method further includes:
[0016] When the traversed techniques and tactics are not executable, obtaining execution information and execution results generated during the execution of each technique and tactic instance;
[0017] Generate a system evaluation result based on the execution information and the execution result.
[0018] Optionally, the step of selecting an attack factor from the attack information database and instantiating the attack factor to obtain a technique and tactic instance includes:
[0019] Selecting attack factors from the attack information library according to a preset global evaluation strategy, wherein the preset global evaluation strategy includes breadth-first and depth-first;
[0020] Instantiate the attack factor to obtain a technical and tactical instance.
[0021] Optionally, the step of selecting an attack factor from the attack information database and instantiating the attack factor to obtain a technique and tactic instance includes:
[0022] When the preset global evaluation strategy is depth-first, obtaining the execution depth of each attack factor in the attack information database;
[0023] selecting an attack factor according to the execution depth;
[0024] The attack factors are instantiated according to preset attack information to obtain technical and tactical instances.
[0025] Optionally, after the step of executing the technical and tactical example and generating a system evaluation result based on the execution information and execution results generated during the execution of the technical and tactical example, the step further includes:
[0026] Get the execution order of each technical and tactical instance;
[0027] According to the execution sequence, the environment of the system to be evaluated is rolled back in a first-in-last-out order.
[0028] Optionally, the step of generating a system evaluation result based on the execution information and execution results generated during the execution of the technical and tactical examples includes:
[0029] Determine the execution process of the technical and tactical instance according to the execution information generated during the execution of the technical and tactical instance, and generate an attack path tree graph topology;
[0030] Evaluate vulnerabilities in the execution of each technical and tactical instance based on the execution information;
[0031] Generate system evaluation results based on the attack path tree topology, the vulnerability situation and the execution results.
[0032] In addition, to achieve the above-mentioned purpose, the present invention further provides a system evaluation device, comprising:
[0033] An attack information database construction module is used to construct an attack information database based on preset attack information and technical and tactical database;
[0034] a technique and tactic instance determination module, configured to select an attack factor from the attack information database and instantiate the attack factor to obtain a technique and tactic instance;
[0035] The evaluation module is used to execute the technical and tactical examples and generate system evaluation results based on the execution information and execution results generated during the execution of the technical and tactical examples.
[0036] In addition, to achieve the above-mentioned purpose, the present invention also proposes a system evaluation device, which includes: a memory, a processor, and a system evaluation program stored on the memory and executable on the processor, wherein the system evaluation program is configured to implement the steps of the system evaluation method described above.
[0037] In addition, to achieve the above-mentioned purpose, the present invention also proposes a storage medium, on which a system evaluation program is stored. When the system evaluation program is executed by a processor, the steps of the system evaluation method described above are implemented.
[0038] The present invention constructs an attack information library based on preset attack information and a technique and tactics library; selects attack factors from the attack information library and instantiates the attack factors to obtain a technique and tactics instance; executes the technique and tactics instance, and generates a system evaluation result based on the execution information and execution results generated during the execution of the technique and tactics instance. Since the present invention selects attack factors from the attack information library and instantiates the attack factors to obtain a technique and tactics instance; executes the technique and tactics instance, and generates a system evaluation result based on the execution information and execution results generated during the execution of the technique and tactics instance. Compared with the existing method of manually conducting system evaluation, the above method of the present invention can simulate complex and large-scale attack actions, thereby improving the efficiency and accuracy of system evaluation. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] Figure 1Schematic diagram of the structure of a system evaluation device for a hardware operating environment according to an embodiment of the present invention;
[0040] Figure 2 This is a flow chart of the first embodiment of the system evaluation method of the present invention;
[0041] Figure 3 This is a flow chart of a second embodiment of the system evaluation method of the present invention;
[0042] Figure 4 This is a structural block diagram of the first embodiment of the system evaluation device of the present invention.
[0043] The purpose, features and advantages of the present invention will be further described with reference to the accompanying drawings and in conjunction with the embodiments. DETAILED DESCRIPTION
[0044] It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.
[0045] Reference Figure 1 , Figure 1 This is a schematic diagram of the structure of the system evaluation equipment for the hardware operating environment involved in the embodiment of the present invention.
[0046] like Figure 1 As shown, the system evaluation device may include: a processor 1001, such as a central processing unit (CPU), a communication bus 1002, a user interface 1003, a network interface 1004, and a memory 1005. Among them, the communication bus 1002 is used to realize the connection and communication between these components. The user interface 1003 may include a display screen (Display), an input unit such as a keyboard (Keyboard), and the user interface 1003 may optionally include a standard wired interface and a wireless interface. The network interface 1004 may optionally include a standard wired interface and a wireless interface (such as a wireless fidelity (Wireless-Fidelity, WI-FI) interface). The memory 1005 may be a high-speed random access memory (Random Access Memory, RAM) or a stable non-volatile memory (Non-Volatile Memory, NVM), such as a disk storage. The memory 1005 may optionally be a storage device independent of the aforementioned processor 1001.
[0047] Those skilled in the art will understand that Figure 1 The structure shown in does not constitute a limitation on the system evaluation equipment, and may include more or fewer components than shown in the figure, or a combination of certain components, or a different arrangement of components.
[0048] like Figure 1 As shown, the memory 1005 as a storage medium may include an operating system, a network communication module, a user interface module and a system evaluation program.
[0049] exist Figure 1 In the system evaluation device shown, the network interface 1004 is mainly used for data communication with the network server; the user interface 1003 is mainly used for data interaction with the user; the processor 1001 and the memory 1005 in the system evaluation device of the present invention can be set in the system evaluation device, and the system evaluation device calls the system evaluation program stored in the memory 1005 through the processor 1001, and executes the system evaluation method provided by the embodiment of the present invention.
[0050] Based on the above system evaluation device, the embodiment of the present invention provides a system evaluation method, referring to Figure 2 , Figure 2 This is a flow chart of the first embodiment of the system evaluation method of the present invention.
[0051] In this embodiment, the system evaluation method includes the following steps:
[0052] Step S10: Construct an attack information database based on the preset attack information and the technical and tactical database.
[0053] It should be noted that the execution subject of this embodiment can be a computing service device with data processing, network communication, and program execution functions, such as a mobile phone, tablet computer, personal computer, etc., or an electronic device or system evaluation device capable of performing the above functions. The following uses the system evaluation device as an example to illustrate this embodiment and the following embodiments.
[0054] It should be noted that the preset attack information can be pre-acquired basic information of the system to be evaluated, as well as existing vulnerability libraries, CWE vulnerability knowledge bases, attack tools, and information such as the inclusion relationship between fingerprints and vulnerabilities and weaknesses, and the relationship between attack tools and weapons. The preset attack information is updated and improved through regular crawling or subscription to maintain the availability and integrity of the information. For example, the preset attack information can be:
[0055] {Asset,FingerPrint,[Cwe,VUL,EXP,POC,Mitigation]}
[0056] Among them, Asset is used to represent assets, such as the database MySQL and the operating system Window7;
[0057] FingerPrint is used to represent fingerprints, such as the MD5 summary value of the version, or the version number, for example, corresponding to MySQL version v5.27;
[0058] CWE is used to characterize existing weaknesses, such as relative path traversal issues;
[0059] VUL is used to characterize the CVE number or CNVD information of the asset vulnerability;
[0060] EXP is used to represent the brute force tools and exploitation methods that can be used to maliciously exploit this vulnerability;
[0061] POC: Same as EXP, used to characterize proof-of-concept tools and methods;
[0062] Mitigation: Mitigation measures corresponding to vulnerability weaknesses can be used to determine whether the vulnerability is exploitable and to form improvement suggestions after evaluation.
[0063] It should be noted that the technical and tactical library may include a set of preconditions required for the attack, as well as the attack tools and weapons used, the operating environment, the required permissions, the asset fingerprint vulnerability information exploited, its importance, the timeout period, the technical and tactical phase, the cleanup and rollback strategy, etc. For example, the technical and tactical library may be:
[0064] {Prerequisites, Tools, Env, Assets, Timeout, Tactics, Rollback}
[0065] Prerequisites are used to represent the prerequisites required for an attack. For example, for a scan action, the prerequisites are the target IP address and port (optional); for a breakthrough attack action, the prerequisites are the target address, port, and a specified vulnerability CVE.
[0066] Tools is used to represent tactical tools, such as nmap that may be used for scanning; or publicly available CVE vulnerability exploitation scripts;
[0067] Env is used to represent the execution environment of tactical tools or scripts;
[0068] Assets is used to represent the asset list targeted by the tactical script. For example, for log4j vulnerabilities, applicable assets include 2.0 <= Apache log4j2 <= 2.14.1.
[0069] Timeout is used to indicate the execution timeout of the tactical tool. If the specified time is not exceeded, the breakthrough will be stopped.
[0070] Tactics: corresponding ATT&CK tactics and technical information;
[0071] Rollback: A rollback script or tool. For example, if a service or port is opened during evaluation, or a reverse connection is configured, the environment needs to be cleaned up after the evaluation to avoid damage to the original environment.
[0072] It should be noted that the attack information library can be a collection of instance combinations that can be used to attack the system, generated based on the preset attack information and the technique and tactics library. The attack information library contains attack factors. After the attack factors are instantiated, the instantiated attack factors can be used to attack the system to be evaluated, thereby generating evaluation results for the system to be evaluated based on the information during the attack and the attack results.
[0073] Step S20: selecting attack factors from the attack information database and instantiating the attack factors to obtain technical and tactical instances.
[0074] It should be noted that selecting an attack factor from the attack information database may include traversing the attack factors in the attack information database and instantiating the traversed attack factors. Instantiating the attack factor may include instantiating the attack factor based on pre-set attack information or relevant information of the system to be evaluated in the preset attack information, thereby obtaining a technical and tactical example that can be used to perform an attack evaluation on the system to be evaluated.
[0075] Furthermore, in order to improve the evaluation efficiency, the step S20 may include: selecting attack factors from the attack information library according to a preset global evaluation strategy, wherein the preset global evaluation strategy includes breadth-first and depth-first; instantiating the attack factors to obtain technical and tactical instances.
[0076] It should be noted that depth-first strategy can be used to fully utilize a single valid piece of information, and only execute other tactics after no further valid information can be extracted; breadth-first strategy can be used to fully execute the current tactic first, and then schedule the next tactic. When the preset global evaluation strategy is depth-first, the execution depth of each attack factor in the attack information library is obtained; an attack factor is selected based on the execution depth; and the attack factor is instantiated based on the preset attack information to obtain a tactical and technical instance. When the preset global evaluation strategy is breadth-first, the attack factors in the attack information library are directly traversed, instantiated, and then executed. After all executions are completed, executable tactical and technical instances are generated based on the generated execution information and execution results.
[0077] Step S30: Execute the technical and tactical examples, and generate system evaluation results based on the execution information and execution results generated during the execution of the technical and tactical examples.
[0078] It should be noted that executing the tactics and techniques examples may involve conducting a simulated attack on the system being evaluated based on the tactics and techniques examples, thereby generating a system evaluation result based on the information generated during the attack and the attack results. If multiple tactics and techniques examples exist, they may be added to an execution queue and executed through multi-threaded scheduling. The system evaluation result may include vulnerability information and weakness information of the system being evaluated, such as discovered during a simulated attack on the system being evaluated based on the tactics and techniques examples.
[0079] Furthermore, in order to make it more convenient for users to view the system evaluation results, the step S30 includes: determining the execution process of the technical and tactical instance based on the execution information generated during the execution of the technical and tactical instance, and generating an attack path tree graph topology; evaluating the vulnerability situation during the execution of each technical and tactical instance based on the execution information; and generating a system evaluation result based on the attack path tree graph topology, the vulnerability situation and the execution result.
[0080] In specific implementation, the system evaluation equipment collects all execution information during the execution of each technical and tactical instance, and outputs the execution process of the technical and tactical instance based on the source relationship of the execution information to form an attack path tree diagram topology; combined with the ATT&CK attack matrix block diagram, the technical and tactical instances and tactical execution results of the attack are rendered in the attack matrix diagram to intuitively display the technical and tactical coverage of the automatic evaluation; based on the execution information, the asset information, asset fingerprints, exploited vulnerabilities, weakness information, execution logs, etc. utilized in each attack step are extracted; the above-mentioned attack path tree diagram topology, attack matrix diagram, asset information, asset fingerprints, exploited vulnerabilities, weakness information, execution logs and other information utilized in each attack step are integrated to form a comprehensive evaluation report from the aspects of asset value, existing weaknesses, threats faced, risks, etc., and provide suggestions for mitigation measures for weaknesses and risks.
[0081] Furthermore, after a simulated attack on the system to be evaluated, some redundant data may be generated or there may be changes to the system configuration information. Therefore, after the simulated attack, it is necessary to perform an environmental rollback on the system to be evaluated. Therefore, after step S30, it also includes: obtaining the execution order of each technical and tactical instance; and performing an environmental rollback on the system to be evaluated in a first-in-last-out order according to the execution order.
[0082] It should be noted that, in order to ensure the accuracy of the environment rollback, the environment rollback of the system to be evaluated needs to be carried out in the order of first-in-last-out according to the execution order of technical and tactical instances.
[0083] In practice, the system evaluation equipment first determines the service information being tested, such as the machine's IP address. Based on the tactical database, it scans for available techniques and tactics, such as nmap, to scan the system's open ports and services, obtaining information about ports and protocols. For example, nmap scan results reveal the scan results, including open ports and port protocols. Based on the attack information database, the newly discovered open port 445 and the exploitable CVE-2017-0143 vulnerability are used to create new tactical instances, such as "445 Port SMB Protocol Exploitable" and "CVE-2017-0143." Based on port 445 and the IP address "CVE-2017-0143," the vulnerability tactic "Eternal Blue" is determined to be exploitable. The "Eternal Blue" attack exploit is executed against the IP address. Analysis of the "Eternal Blue" execution results reveals success, with the information "System Highest Permissions Obtained" being obtained. Based on the obtained system highest permissions, the "System Highest Permissions" information factor is analyzed and used to trigger the tactical actions "Scan Local Sensitive Information Files" and "Upload and Retrieve Software." Scanning tactics are used to execute sensitive files and data on the system; upload and transmit software, execute transmission actions, and remotely deliver the software via WGET, CURL, and other methods, generating information indicating "capable of transmitting back." This information is analyzed, and if sensitive information is present, the tactical action "transmission" is triggered in conjunction with the "capable of transmitting back." The "transmission" action is executed to transmit sensitive files and information back to the local computer. If the tactic has no output and no information reuse factors, the action is completed, and only the "upload and transmit software" needs to be rolled back. The software cleanup action is executed to complete the cleanup. Based on the aforementioned execution path, actions, tools, and input and output information, an attack path diagram is generated. Based on the attack results, information is output, and combined with measures to address vulnerabilities and weaknesses, an assessment report is generated, including weaknesses and improvement measures.
[0084] This embodiment constructs an attack information library based on preset attack information and a technique and tactics library; selects attack factors from the attack information library and instantiates the attack factors to obtain technique and tactics instances; executes the technique and tactics instances, and generates system evaluation results based on the execution information and execution results generated during the execution of the technique and tactics instances. Since this embodiment selects attack factors from the attack information library and instantiates the attack factors to obtain technique and tactics instances; executes the technique and tactics instances, and generates system evaluation results based on the execution information and execution results generated during the execution of the technique and tactics instances. Compared with the existing method of manually conducting system evaluation, the above method of this embodiment can simulate complex and large-scale attack actions, thereby improving the efficiency and accuracy of system evaluation.
[0085] refer to Figure 3 , Figure 3 Schematic diagram of the flow chart of the second embodiment of the system evaluation method of the present invention.
[0086] Based on the above first embodiment, in this embodiment, step S30 includes:
[0087] Step S301: Execute the technical and tactical instance, and record the execution information generated during the execution process in real time.
[0088] Step S302: performing feature extraction on the execution information to obtain a feature extraction result.
[0089] It should be noted that the feature extraction of the execution information can be to extract the exploitable information in the execution information, specifically, to match the execution information with the fingerprint assets, vulnerabilities, and weaknesses in the preset attack information to obtain deep exploitable information, and then store the extracted information in the preset attack information, and then further generate attack factors for deeper attacks or instantiate existing attack factors in the attack information library so that the instantiated attack factors can be used to simulate attacks.
[0090] Step S303: instantiating attack factors in the attack information database according to the feature extraction result.
[0091] It should be noted that the attack factors in the attack information library may require necessary execution preconditions, such as IP, Port, password, etc. The execution information or execution results generated when executing the technical and tactical examples may include the above information. At this time, the execution information or execution results generated when executing the technical and tactical examples can be used to instantiate the attack factors in the attack information library.
[0092] Step S304: traverse the technique and tactics library according to the attack information library, and determine whether the traversed technique and tactics are executable.
[0093] It should be noted that traversing the techniques and tactics library according to the attack information library can be to judge whether the techniques and tactics in the techniques and tactics library can be executed based on the relevant information of the system to be evaluated or the attack factors in the attack information library, that is, whether techniques and tactics instances can be generated based on the techniques and tactics in the techniques and tactics for simulated attacks on the system to be evaluated.
[0094] Step S305: If so, instantiate the traversed techniques and tactics to obtain a technique and tactics instance, and return to the step of executing the technique and tactics instance, and generate a system evaluation result based on the execution information and execution results generated during the execution of the technique and tactics instance.
[0095] It should be noted that if there are still techniques and tactics that can be used to simulate attacks on the system to be evaluated, the techniques and tactics that can be used to simulate attacks on the system to be evaluated can be instantiated according to the preset attack information and pre-set attack information to obtain technique and tactics instances, and the technique and tactics instances are executed to obtain system evaluation results. If there are no techniques and tactics that can be used to simulate attacks on the system to be evaluated, the system evaluation results are generated according to the execution information and execution results obtained from the previous execution of the technique and tactics instances.
[0096] This embodiment executes the technique and tactics instance and records the execution information generated during the execution process in real time; performs feature extraction on the execution information to obtain feature extraction results; instantiates the attack factors in the attack information library based on the feature extraction results; traverses the technique and tactics library based on the attack information library and determines whether the traversed technique and tactics are executable; if so, instantiates the traversed technique and tactics to obtain a technique and tactics instance, and returns to the step of executing the technique and tactics instance, and generating a system evaluation result based on the execution information and execution results generated during the execution of the technique and tactics instance. This embodiment makes full use of the information generated during the execution of each technique and tactics instance to generate a new technique and tactics instance for simulating attacks on the system to be evaluated, and can perform a comprehensive attack evaluation on the system to be evaluated and obtain accurate evaluation results.
[0097] Reference Figure 4 , Figure 4 This is a structural block diagram of the first embodiment of the system evaluation device of the present invention.
[0098] like Figure 4 As shown, the system evaluation device proposed in the embodiment of the present invention includes:
[0099] An attack information database construction module 10 is used to construct an attack information database based on preset attack information and a technical and tactical database;
[0100] a technique and tactic instance determination module 20, configured to select attack factors from the attack information database and instantiate the attack factors to obtain technique and tactic instances;
[0101] The evaluation module 30 is used to execute the technical and tactical examples and generate system evaluation results based on the execution information and execution results generated during the execution of the technical and tactical examples.
[0102] This embodiment constructs an attack information library based on preset attack information and a technique and tactics library; selects attack factors from the attack information library and instantiates the attack factors to obtain technique and tactics instances; executes the technique and tactics instances, and generates system evaluation results based on the execution information and execution results generated during the execution of the technique and tactics instances. Since this embodiment selects attack factors from the attack information library and instantiates the attack factors to obtain technique and tactics instances; executes the technique and tactics instances, and generates system evaluation results based on the execution information and execution results generated during the execution of the technique and tactics instances. Compared with the existing method of manually conducting system evaluation, the above method of this embodiment can simulate complex and large-scale attack actions, thereby improving the efficiency and accuracy of system evaluation.
[0103] It should be noted that the workflow described above is merely illustrative and does not limit the scope of protection of the present invention. In practical applications, technicians in this field can select part or all of it according to actual needs to achieve the purpose of the embodiment scheme, and no limitation is made here.
[0104] In addition, for technical details not fully described in this embodiment, please refer to the system evaluation method provided in any embodiment of the present invention, and will not be repeated here.
[0105] Based on the above-mentioned first embodiment of the system evaluation device of the present invention, a second embodiment of the system evaluation device of the present invention is proposed.
[0106] In this embodiment, the evaluation module 30 is further used to execute the technical and tactical examples and record the execution information generated during the execution process in real time;
[0107] Performing feature extraction on the execution information to obtain a feature extraction result;
[0108] Instantiating the attack factors in the attack information database according to the feature extraction result;
[0109] Traversing the techniques and tactics library according to the attack information library, and determining whether the traversed techniques and tactics are executable;
[0110] If so, instantiate the traversed techniques and tactics to obtain a technique and tactics instance, and return to the step of executing the technique and tactics instance, and generate a system evaluation result based on the execution information and execution results generated during the execution of the technique and tactics instance.
[0111] Furthermore, the evaluation module 30 is further configured to obtain execution information and execution results generated during the execution of each technique and tactic instance when the traversed technique and tactic is not executable;
[0112] Generate a system evaluation result based on the execution information and the execution result.
[0113] Furthermore, the technical and tactical example determination module 20 is further configured to select attack factors from the attack information database according to a preset global evaluation strategy, wherein the preset global evaluation strategy includes breadth-first and depth-first.
[0114] Instantiate the attack factor to obtain a technical and tactical instance.
[0115] Furthermore, the technical and tactical example determination module 20 is further configured to obtain the execution depth of each attack factor in the attack information database when the preset global evaluation strategy is depth-first;
[0116] selecting an attack factor according to the execution depth;
[0117] The attack factors are instantiated according to preset attack information to obtain technical and tactical instances.
[0118] Furthermore, the evaluation module 30 is also used to obtain the execution order of each technical and tactical instance;
[0119] According to the execution sequence, the environment of the system to be evaluated is rolled back in a first-in-last-out order.
[0120] Furthermore, the evaluation module 30 is further configured to determine the execution process of the technique and tactic instance based on the execution information generated during the execution of the technique and tactic instance, and generate an attack path tree graph topology;
[0121] Evaluate vulnerabilities in the execution of each technical and tactical instance based on the execution information;
[0122] Generate system evaluation results based on the attack path tree topology, the vulnerability situation and the execution results.
[0123] Other embodiments or specific implementations of the system evaluation device of the present invention can refer to the above-mentioned method embodiments and will not be repeated here.
[0124] In addition, an embodiment of the present invention further provides a storage medium on which a system evaluation program is stored. When the system evaluation program is executed by a processor, the steps of the system evaluation method described above are implemented.
[0125] It should be noted that, in this document, the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, article, or system comprising a series of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or system. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or system comprising the element.
[0126] The serial numbers of the above embodiments of the present invention are for description only and do not represent the advantages or disadvantages of the embodiments.
[0127] Through the description of the above embodiments, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus the necessary general hardware platform, and of course can also be implemented by hardware, but in many cases the former is a better embodiment. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product, which is stored in a storage medium (such as read-only memory / random access memory, magnetic disk, optical disk), and includes a number of instructions for enabling a terminal device (which can be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in each embodiment of the present invention.
[0128] The above are only preferred embodiments of the present invention and are not intended to limit the patent scope of the present invention. Any equivalent structure or equivalent process transformation made using the contents of the present invention description and drawings, or directly or indirectly applied in other related technical fields, are also included in the patent protection scope of the present invention.
Claims
1. A system evaluation method, characterized in that: The system evaluation method comprises the following steps: Build an attack information database based on preset attack information and technical and tactical database; Selecting an attack factor from the attack information database and instantiating the attack factor to obtain a technique and tactic instance; Executing the technical and tactical examples, and generating system evaluation results based on execution information and execution results generated during the execution of the technical and tactical examples; The technical and tactical library includes the set of preconditions required for the attack, the attack tools used, weapons, operating environment, required permissions for operation, asset fingerprint vulnerability information exploited, importance, timeout period, technical and tactical phase, and cleanup and rollback strategies; The step of selecting an attack factor from the attack information database and instantiating the attack factor to obtain a technique and tactic instance includes: According to the preset global evaluation strategy, attack factors are selected from the attack information library, the attack factors are instantiated, and technical and tactical instances are obtained. The preset global evaluation strategy includes breadth-first and depth-first. The depth-first strategy is to make full use of valid information and execute other tactics after no other valid information can be extracted. The breadth-first strategy is to fully execute the current tactics first, and then uniformly schedule the next tactic. When executing the next tactic, the execution information and execution results generated by the previous tactic are used to regenerate executable technical and tactical instances.
2. The system evaluation method according to claim 1, wherein: The step of executing the technical and tactical examples and generating system evaluation results based on execution information and execution results generated during the execution of the technical and tactical examples includes: Execute the technical and tactical examples and record the execution information generated during the execution process in real time; Performing feature extraction on the execution information to obtain a feature extraction result; Instantiating the attack factors in the attack information database according to the feature extraction result; Traversing the techniques and tactics library according to the attack information library, and determining whether the traversed techniques and tactics are executable; If so, instantiate the traversed techniques and tactics to obtain a technique and tactics instance, and return to the step of executing the technique and tactics instance, and generate a system evaluation result based on the execution information and execution results generated during the execution of the technique and tactics instance.
3. The system evaluation method according to claim 2, wherein: After the step of traversing the technique and tactics library according to the attack information library and determining whether the traversed technique and tactics are executable, the method further includes: When the traversed techniques and tactics are not executable, obtaining execution information and execution results generated during the execution of each technique and tactic instance; Generate a system evaluation result based on the execution information and the execution result.
4. The system evaluation method according to claim 1, wherein: The step of selecting an attack factor from the attack information database and instantiating the attack factor to obtain a technique and tactic instance includes: When the preset global evaluation strategy is depth-first, obtaining the execution depth of each attack factor in the attack information database; selecting an attack factor according to the execution depth; The attack factors are instantiated according to preset attack information to obtain technical and tactical instances.
5. The system evaluation method according to any one of claims 1 to 4, characterized in that: After the step of executing the technical and tactical example and generating a system evaluation result based on the execution information and execution results generated during the execution of the technical and tactical example, the method further includes: Get the execution order of each technical and tactical instance; According to the execution sequence, the environment of the system to be evaluated is rolled back in a first-in-last-out order.
6. The system evaluation method according to any one of claims 1 to 4, characterized in that: The step of generating a system evaluation result based on the execution information and execution results generated during the execution of the technical and tactical examples includes: Determine the execution process of the technical and tactical instance according to the execution information generated during the execution of the technical and tactical instance, and generate an attack path tree graph topology; Evaluate vulnerabilities in the execution of each technical and tactical instance based on the execution information; Generate system evaluation results based on the attack path tree topology, the vulnerability situation and the execution results.
7. A system evaluation device, characterized in that: The system evaluation device includes: An attack information database construction module is used to construct an attack information database based on preset attack information and technical and tactical database; a technique and tactic instance determination module, configured to select an attack factor from the attack information database and instantiate the attack factor to obtain a technique and tactic instance; An evaluation module, configured to execute the technical and tactical examples and generate system evaluation results based on execution information and execution results generated during the execution of the technical and tactical examples; The technical and tactical library includes the set of preconditions required for the attack, the attack tools used, weapons, operating environment, required permissions for operation, asset fingerprint vulnerability information exploited, importance, timeout period, technical and tactical phase, and cleanup and rollback strategies; The technical and tactical instance determination module is also used to select attack factors from the attack information library according to a preset global evaluation strategy, instantiate the attack factors, and obtain technical and tactical instances. The preset global evaluation strategy includes breadth-first and depth-first. The depth-first is to make full use of valid information and execute other tactics after no other valid information can be extracted. The breadth-first is to fully execute the current tactics first, and then uniformly schedule the next tactic. When executing the next tactic, the execution information and execution results generated by the previous tactic are used to regenerate executable technical and tactical instances.
8. A system evaluation device, characterized in that: The device includes: a memory, a processor, and a system evaluation program stored in the memory and executable on the processor, wherein the system evaluation program is configured to implement the steps of the system evaluation method according to any one of claims 1 to 6.
9. A storage medium, characterized in that: The storage medium stores a system evaluation program, which, when executed by a processor, implements the steps of the system evaluation method according to any one of claims 1 to 6.
Citation Information
Patent Citations
Automatic penetration testing method for information system security
CN103532793A