A method for handling vulnerabilities, a management device, and a gateway device
Through the coordinated work of management equipment and gateway equipment, and using packet capture rules and blocking strategies, the problem of inaccurate vulnerability threat assessment in the existing technology is solved, accurate assessment and effective handling of vulnerability threats is achieved, and normal communication and security of network equipment are ensured.
Patent Information
- Application Number
- CN202211072505.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2019-11-11
- Publication Date
- 2025-06-27
- Estimated Expiration
- 2039-11-11
AI Technical Summary
Existing security management devices cannot accurately assess the threat of vulnerabilities, resulting in possible network security accidents or affecting the normal communication of the device.
Obtain vulnerability information of the device through the management device, generate targeted packet capture rules, and send them to the gateway device. The gateway device intercepts the packets of the target session according to the packet capture rules and sends them back to the management device. The management device determines the threat of the vulnerability based on the information in the message and decides whether to send a blocking policy to the gateway device.
Accurate assessment of the threat of vulnerabilities is achieved, security accidents or business impacts caused by misjudgment are avoided, and normal communication of equipment is ensured.
Smart Images

Figure CN115643041B_ABST
Abstract
Description
[0001] This application is a divisional application of the application document with the application number 201911095412.7, the application date of November 11, 2019, and the title of "A Method for Handling Vulnerabilities, a Management Device, and a Gateway Device". Technical Field
[0002] Embodiments of this application relate to the field of communications, and in particular, to a method for handling vulnerabilities. Background Art
[0003] A vulnerability, also known as a weakness (Vulnerability), refers to a defect in the security of a computer system, which poses threats to the confidentiality, integrity, availability, access control, etc. of the computer system or its application data. The above-mentioned defects include defects in computer hardware, software, and the specific implementation or security policy of computer communication protocols. Vulnerability scanning tools are an important type of network security technology. By applying vulnerability scanning tools to scan each device in the network, network administrators can understand the security settings of each device in the network and the application services running, timely discover security vulnerabilities in network devices, and objectively evaluate the network risk level. If the firewall is a passive defense measure, then vulnerability scanning tools are an active preventive measure, which can effectively avoid hacker attacks and prevent problems before they occur. A patch refers to a small program released by software manufacturers or third-party patch providers to solve problems exposed during the use of a computer. To improve network security, many companies or organizations deploy patch management tools in their internal networks. The patch management tool in the network is used to collect patches and distribute them to terminals to repair vulnerabilities.
[0004] Existing security software manufacturers integrate the above-mentioned vulnerability scanning tools and patch management tools into the same management device. After the management device uses the vulnerability scanning tool to scan the devices in the network, if a vulnerability is found in the software installed on the device, the vulnerability scanning tool reports the discovered vulnerability information to the patch management tool. The patch management tool finds the patch corresponding to the vulnerability according to the discovered vulnerability information, and this patch can make up for the defects brought by the vulnerability. In addition, after the management device obtains the vulnerability information, it will also block the session of the software with the vulnerability.
[0005] However, vulnerability scanning tools often report a large amount of vulnerability information to the management device. The management device cannot accurately evaluate the threat level of vulnerabilities, which may lead to network security incidents or affect the business of network devices. For example, security incidents caused by untimely patching of vulnerabilities, or normal communication of devices is affected by blocking relevant sessions of software on the device due to overestimating the threat of vulnerabilities. Summary of the Invention
[0006] The embodiments of the present application provide a method for handling vulnerabilities, a management device, and a gateway device, which can enable devices to communicate normally.
[0007] In the first aspect of the embodiments of the present application, a method for handling vulnerabilities is provided. The method includes: the management device obtains vulnerability information of a first device, and the vulnerability information of the first device is usually used to indicate that there is a first vulnerability in a first software. Then the management device obtains a corresponding packet capture rule according to the obtained vulnerability information of the first device. The packet capture rule obtained by the management device can be used to identify packets with the risk of the first vulnerability. After the management device obtains the packet capture rule, it will send the packet capture rule to the gateway device. The management device receives the packets of the target session transmitted by the first device sent by the gateway device, and there is a risk of the first vulnerability in the packets. Therefore, the management device can determine the threat level of the first vulnerability according to the packets of the target session transmitted by the first device, and determine whether to send a blocking policy to the gateway device according to the threat level of the first vulnerability.
[0008] In this first aspect, the management device manages the internal network devices. When a communication connection is established between an internal network device and an external network device, the gateway device forwards the data transmitted between the internal network device and the external network device. If one or more software installed on the internal network device has vulnerabilities, one of the vulnerabilities is called the first vulnerability. The software with the first vulnerability is called the first software, the internal network device installed with the first software is called the first device, the first software communicates with other devices using a network protocol, and the first device is managed by the management device.
[0009] In the embodiments of the present application, the management device first issues a targeted packet capture rule to the gateway device according to the vulnerability information related to the first device, and receives the packets of the target session transmitted by the first device captured according to the packet capture rule returned by the gateway device. The management device determines the threat level of the first vulnerability according to the packets of the target session transmitted by the first device, and then determines whether to send a blocking policy to the gateway device according to the threat level. When the first vulnerability is not threatening, no blocking policy is sent to avoid affecting the normal services on the first device due to the blocking policy. When the first vulnerability is threatening, a blocking policy is sent to timely reduce the harm of the first vulnerability and reduce the probability of security incidents.
[0010] In a possible implementation of the first aspect, the above steps: The message with the risk of the first vulnerability includes a message with a specified port number and protocol type. The management device determines the threat level of the first vulnerability based on the message of the target session transmitted by the first device, and determines whether to send a blocking policy to the gateway device according to the threat level, including: The management device determines whether there are sequentially occurring vulnerability exploitation request messages corresponding to the first vulnerability and vulnerability exploitation response messages corresponding to the first vulnerability in the message of the target session transmitted by the first device according to the correspondence between the vulnerability exploitation request messages corresponding to the first vulnerability and the vulnerability exploitation response messages corresponding to the first vulnerability included in the first vulnerability database; if there are no sequentially occurring vulnerability exploitation request messages corresponding to the first vulnerability and vulnerability exploitation response messages corresponding to the first vulnerability in the message of the target session transmitted by the first device, the management device does not send the blocking policy to the gateway device; if there are sequentially occurring vulnerability exploitation request messages corresponding to the first vulnerability and vulnerability exploitation response messages corresponding to the first vulnerability in the message of the target session transmitted by the first device, the management device sends the blocking policy to the gateway device.
[0011] In this possible implementation, if the message with the risk of the first vulnerability received by the management device includes a message with a specified port number and protocol type, the management device calls the first vulnerability database and determines whether the message of the target session transmitted by the first device includes sequentially occurring vulnerability exploitation request messages corresponding to the first vulnerability and vulnerability exploitation response messages corresponding to the first vulnerability according to the correspondence in the first vulnerability database. If the management device determines that there are no sequentially occurring vulnerability exploitation request messages corresponding to the first vulnerability and vulnerability exploitation response messages corresponding to the first vulnerability in the message of the target session transmitted by the first device, it proves that the first vulnerability is not threatening. Therefore, the management device does not need to send a blocking policy to the gateway device. If the management device determines that there are sequentially occurring vulnerability exploitation request messages corresponding to the first vulnerability and vulnerability exploitation response messages corresponding to the first vulnerability in the message of the target session transmitted by the first device, it proves that the first vulnerability is threatening. Therefore, the management device sends a blocking policy to the gateway device, and the gateway device blocks the target session transmitted by the first device. This possible implementation improves the accuracy of determining the threat level of vulnerabilities.
[0012] In a possible implementation of the first aspect, the above steps: The packet with the risk of the first vulnerability includes a specified port number and a protocol type. The management device determines the threat level of the first vulnerability based on the packets of the target session transmitted by the first device, and determines whether to send a blocking policy to the gateway device according to the threat level, including: The management device determines whether there are sequentially occurring vulnerability exploitation request packets corresponding to the first vulnerability and vulnerability exploitation response packets corresponding to the first vulnerability in the packets of the target session transmitted by the first device according to the correspondence between the vulnerability exploitation request packets corresponding to the first vulnerability and the vulnerability exploitation response packets corresponding to the first vulnerability included in the first vulnerability database; if there are no sequentially occurring vulnerability exploitation request packets corresponding to the first vulnerability and vulnerability exploitation response packets corresponding to the first vulnerability in the packets of the target session transmitted by the first device, the management device does not send a blocking policy to the gateway device; if there are sequentially occurring vulnerability exploitation request packets corresponding to the first vulnerability and vulnerability exploitation response packets corresponding to the first vulnerability in the packets of the target session transmitted by the first device, the management device determines whether the packets of the target session transmitted by the first device include abnormal data; if the packets of the target session transmitted by the first device further include the abnormal data, the management device sends a blocking policy to the gateway device.
[0013] In this possible implementation, if the packet with the risk of the first vulnerability received by the management device includes a packet with a specified port number and a protocol type, the management device can call the first vulnerability database, which includes the correspondence between the vulnerability exploitation request packets corresponding to the first vulnerability and the vulnerability exploitation response packets corresponding to the first vulnerability. Based on this correspondence, the management device can determine that if there are sequentially occurring vulnerability exploitation request packets corresponding to the first vulnerability and vulnerability exploitation response packets corresponding to the first vulnerability in the packets of the target session transmitted by the first device, at this time, the management device continues to determine whether the target session transmitted by the first device includes abnormal data. If the target session transmitted by the first device includes abnormal data, then the management device believes that the first vulnerability has been exploited by the attacking device, and the management device sends a blocking policy to the gateway device. This possible implementation provides a more accurate way to determine the threat level.
[0014] In a possible implementation of the first aspect, the above steps: the packet with the risk of the first vulnerability includes an exploit request packet corresponding to the first vulnerability. The management device determines the threat level of the first vulnerability based on the packets of the target session transmitted by the first device, and determines whether to send a blocking policy to the gateway device according to the threat level, including: the management device determines whether the packets of the target session transmitted by the first device further include an exploit response packet corresponding to the first vulnerability according to the correspondence between the exploit request packet corresponding to the first vulnerability and the exploit response packet corresponding to the first vulnerability included in the first vulnerability database; if the packets of the target session transmitted by the first device do not include an exploit response packet corresponding to the first vulnerability, the management device does not send a blocking policy to the gateway device; if the packets of the target session transmitted by the first device include an exploit response packet corresponding to the first vulnerability, the management device sends a blocking policy to the gateway device.
[0015] In this possible implementation, if the packet with the risk of the first vulnerability includes an exploit request packet corresponding to the first vulnerability, the management device can call the first vulnerability database. The management device can determine whether the packets of the target session transmitted by the first device further include an exploit response packet corresponding to the first vulnerability according to the first vulnerability database. If the management device determines that there is an exploit response packet corresponding to the first vulnerability, the management device can consider that there is a risk of the first vulnerability being exploited. Then the management device can send a blocking policy to the gateway device, and the blocking policy is used to block the target session transmitted by the first device. This possible implementation provides a more accurate way to determine the threat level.
[0016] In a possible implementation of the first aspect, in the above steps: the packet with the risk of the first vulnerability includes an exploit request packet corresponding to the first vulnerability. The management device determines the threat level of the first vulnerability based on the packets of the target session transmitted by the first device, and determines whether to send a blocking policy to the gateway device according to the threat level, including: the management device determines whether the packet of the target session transmitted by the first device further includes an exploit response packet corresponding to the first vulnerability according to the correspondence between the exploit request packet corresponding to the first vulnerability and the exploit response packet corresponding to the first vulnerability included in the first vulnerability database; if the packet of the target session transmitted by the first device does not include the exploit response packet corresponding to the first vulnerability, the management device does not send a blocking policy to the gateway device; if the packet of the target session transmitted by the first device includes the exploit response packet corresponding to the first vulnerability, the management device determines whether the packet of the target session transmitted by the first device includes the abnormal data; if the packet of the target session transmitted by the first device further includes the abnormal data, the management device sends a blocking policy to the gateway device.
[0017] In this possible implementation, if the packet with the risk of the first vulnerability includes an exploit request packet corresponding to the first vulnerability, the management device can call the first vulnerability database, and the management device can determine whether the packet of the target session transmitted by the first device further includes an exploit response packet corresponding to the first vulnerability according to the first vulnerability database. If the management device determines that there is an exploit response packet corresponding to the first vulnerability, the management device can consider that there is a risk of the first vulnerability being exploited. At this time, the management device can also confirm whether the packet of the target session transmitted by the first device includes abnormal data. If the packet of the target session includes abnormal data, it proves that the first vulnerability has been exploited and the first vulnerability is dangerous. Then the management device sends a blocking policy to the gateway device so that the gateway device can timely block the target session transmitted by the first device according to the blocking policy. If the management device confirms that the packet of the target session transmitted by the first device does not include abnormal data, it proves that although there is a risk of the first vulnerability being exploited, the attacking device has not exploited the first vulnerability at present. At this time, the management device can not send a blocking policy to the gateway device to avoid affecting the normal services on the first device.
[0018] In a possible implementation of the first aspect, when the vulnerability information of the first device includes the identification information of the first vulnerability, the steps for the management device to obtain the packet capture rule according to the vulnerability information of the first device include: the management device obtains the packet capture rule corresponding to the first vulnerability from the local rule database according to the identification information of the first vulnerability, and the local rule database includes the identification information of the first vulnerability and the corresponding packet capture rule.
[0019] In this possible implementation, the local rule library on the management device may include the identification information of the first vulnerability and the corresponding packet capture rules. The management device can obtain the packet capture rules from the local packet capture rule library according to the identification information of the vulnerability, without having to obtain the packet capture rules from other devices. This possible implementation reduces the latency in handling vulnerabilities.
[0020] In a possible implementation of the first aspect, when the vulnerability information of the first device includes the identification information of the first vulnerability, the step of the management device obtaining the packet capture rules according to the vulnerability information of the first device includes: the management device sends the identification information of the first vulnerability to the first cloud device, and the identification information of the first vulnerability is used for the first cloud device to obtain the packet capture rules corresponding to the first vulnerability from the cloud rule library, and the cloud rule library includes the identification information of the first vulnerability and the corresponding packet capture rules; the management device receives the packet capture rules corresponding to the first vulnerability sent by the first cloud device.
[0021] In this possible implementation, the first cloud device may include a cloud rule library, and the cloud rule library may include the identification information of the first vulnerability and the corresponding packet capture rules. Therefore, the management device can obtain the packet capture rules from the first cloud device, without having to obtain the packet capture rules from the local. This possible implementation saves the storage space of the management device.
[0022] In a possible implementation of the first aspect, the above step: the management device obtains the vulnerability information of the first device includes: the management device sends a detection message to the first device; the management device obtains the response message returned by the first device for the detection message, and the response message includes the risk of the first vulnerability; the management device obtains the vulnerability information corresponding to the response message from the second vulnerability library according to the response message, so as to determine the vulnerability information of the first device, and the second vulnerability library includes the corresponding relationship between the response message and the vulnerability information.
[0023] In this possible implementation, the management device may include a vulnerability scanning tool. The vulnerability scanning tool in the management device can send a detection message to the first device, and then receive the response message corresponding to the detection message sent by the first device. By matching the relevant identification of the first vulnerability included in the response message with the vulnerability information in the second vulnerability library, the management device can determine the vulnerability information of the first device. The management device obtains the vulnerability information of the first device by means of vulnerability scanning. This possible implementation improves the feasibility of the solution.
[0024] In a possible implementation of the first aspect, the above steps are as follows: The management device sends a first software information acquisition instruction to the network management system, and the first software information acquisition instruction is used to instruct the network management system to acquire the software information of the software installed on the first device; the management device receives the software information returned by the network management system according to the first software information acquisition instruction; the management device sends the software information to the second cloud device, so that the second cloud device acquires the associated vulnerability information according to the software information and the third vulnerability database, and the third vulnerability database includes the association relationship between the software information and the vulnerability information; the management device receives the associated vulnerability information sent by the second cloud device, thereby determining the vulnerability information of the first device.
[0025] In this possible implementation, the management device sends a first software information acquisition instruction to the network management system, then the management device receives the software information sent by the network management system, and the management device sends the software information to the second cloud device. As a result, the second cloud device can match the software information with the third vulnerability database to obtain the vulnerability information corresponding to the software information. The management device receives the associated vulnerability information sent by the second cloud device, and the management device confirms the vulnerability information of the first device according to the associated vulnerability information sent by the second cloud device. There is no need to install a vulnerability scanning tool on the management device, and this possible implementation saves the storage space of the management device.
[0026] In a possible implementation of the first aspect, the above steps of the management device acquiring the vulnerability information of the first device include: The management device sends a second software information acquisition instruction to the first device, and the second software information acquisition instruction is used to instruct the first device to acquire the software information of the software installed on the first device; the management device receives the software information returned by the first device according to the second software information acquisition instruction; the management device sends the software information to the second cloud device, so that the second cloud device acquires the associated vulnerability information according to the software information and the third vulnerability database, and the third vulnerability database includes the association relationship between the first software information and the vulnerability information; the management device receives the associated vulnerability information sent by the second cloud device, thereby determining the vulnerability information of the first device.
[0027] In this possible implementation, the management device sends a second software information acquisition instruction to the first device. Since the first device is equipped with an agent, the management device can receive the software information sent by the first device. The management device sends the software information to the second cloud device, so that the second cloud device can match the software information with the third vulnerability database to obtain the vulnerability information associated with the software information. The management device receives the associated vulnerability information sent by the second cloud device, and the management device confirms the vulnerability information of the first device according to the associated vulnerability information sent by the second cloud device. Since there is no need to install a vulnerability scanning tool on the management device, this possible implementation saves the storage space of the management device.
[0028] In a possible implementation of the first aspect, for the above steps, if the blocking policy is an access control list, before the management device sends the blocking policy to the gateway device, it may further include: the management device obtains the five-tuple information of the target session according to the packet of the target session transmitted by the first device, and the five-tuple information includes the Internet Protocol (IP) address of the attacking device, the port number of the attacking device, the type of transmission protocol between the attacking device and the first device, the IP address of the first device, and the port number of the first device; the management device generates an entry containing the five-tuple information and adds the generated entry to the access control list, and the access control list is used to block the traffic indicated by the entries contained in the access control list.
[0029] In this possible implementation, the management device obtains the five-tuple information of the target session according to the packet of the target session transmitted by the first device, and then the management device generates an access control list according to the five-tuple information, and this access control list is the blocking policy. This possible implementation improves the feasibility of the solution.
[0030] In a possible implementation of the first aspect, the above steps are as follows: The management device rates the first vulnerability as a first-level vulnerability; the management device calls the first vulnerability database; if the management device determines from the first vulnerability database that there are vulnerability exploitation request messages corresponding to the first vulnerability and vulnerability exploitation response messages corresponding to the first vulnerability that appear in sequence in the packets of the target session transmitted by the first device, then the management device rates the first vulnerability as a second-level vulnerability, and the handling priority of the second-level vulnerability is higher than that of the first-level vulnerability; the terminal sends a first warning prompt message of the first vulnerability to the first device according to the second-level vulnerability. If the management device determines from the first vulnerability database that the packets of the target session transmitted by the first device include vulnerability exploitation request messages corresponding to the first vulnerability and vulnerability exploitation response messages corresponding to the first vulnerability that appear in sequence, and the management device determines that there is abnormal data in the packets of the target session transmitted by the first device, then the management device rates the first vulnerability as a third-level vulnerability, and the handling priority of the third-level vulnerability is higher than that of the second-level vulnerability; the terminal sends a second warning prompt message of the first vulnerability to the first device according to the third-level vulnerability, and the handling priority of the second warning prompt message is higher than that of the first warning prompt message.
[0031] In this possible implementation, the management device first rates the first vulnerability as a first-level vulnerability, and the first-level vulnerability represents a relatively low threat level of the vulnerability. When the management device determines from the first vulnerability database that the second vulnerability database includes vulnerability exploitation request messages corresponding to the first vulnerability and vulnerability exploitation response messages corresponding to the first vulnerability that appear in sequence, the management device rates the first vulnerability as a second-level vulnerability and sends a first warning prompt message to the first device. The first warning prompt message is used to indicate that the threat level of the second-level vulnerability is relatively high. After the packets of the target session transmitted by the first device include vulnerability exploitation request messages corresponding to the first vulnerability and vulnerability exploitation response messages corresponding to the first vulnerability that appear in sequence, if the management device determines that there is abnormal data in the target session and the management device sends a second warning prompt message to the first device, the second warning prompt message can be used to indicate that the attacking device has successfully exploited the first vulnerability. Rating the first vulnerability in this possible implementation can improve the accuracy of the management device in handling the first vulnerability.
[0032] In a possible implementation of the first aspect, the above steps: the management device obtaining the vulnerability information of the first device includes: the management device sending an asset information acquisition instruction to the network management system, the asset information acquisition instruction being used to instruct the network management system to acquire the asset information of the assets installed on the first device; the management device receiving the asset information returned by the network management system according to the asset information acquisition instruction; the management device sending the asset information to the second cloud device, so that the second cloud device acquires the associated vulnerability information according to the asset information and the third vulnerability database, and the third vulnerability database includes the association relationship between the asset information and the vulnerability information; the management device receiving the associated vulnerability information sent by the second cloud device, so as to determine the vulnerability information of the first device.
[0033] In this possible implementation, an asset is used to represent the hardware, software, and services provided in the network, and the asset information is used to represent the model and version of the assets of the first device. The management device sends an asset information acquisition instruction to the network management system, and then the management device receives the asset information sent by the network management system. The management device sends the asset information to the second cloud device, and the third vulnerability database includes the association relationship between the asset information and the vulnerability information, so that the second cloud device can match the asset information with the third vulnerability database and obtain the vulnerability information corresponding to the asset information. The management device receives the associated vulnerability information sent by the second cloud device, and the management device determines the vulnerability information of the first device according to the associated vulnerability information sent by the second cloud device. There is no need to install a vulnerability scanning tool on the management device, and this possible implementation saves the storage space of the management device.
[0034] In a possible implementation of the first aspect, the above steps: the management device obtaining the vulnerability information of the first device includes: the management device sending an asset information acquisition instruction to the first device, the asset information acquisition instruction being used to instruct the first device to acquire the asset information of the assets installed on the first device; the management device receiving the asset information returned by the first device according to the asset information acquisition instruction; the management device sending the asset information to the second cloud device, so that the second cloud device acquires the associated vulnerability information according to the asset information and the third vulnerability database, and the third vulnerability database includes the association relationship between the asset information and the vulnerability information; the management device receiving the associated vulnerability information sent by the second cloud device, so as to determine the vulnerability information of the first device.
[0035] In this possible implementation, assets are used to represent the hardware, software, and services provided in the network, while asset information is used to represent the model and version of the assets. The management device sends an asset information acquisition instruction to the first device. Since a client (agent) is installed on the first device, the management device can receive the asset information sent by the first device. The management device sends the asset information to the second cloud device. The third vulnerability database includes the association relationship between the asset information and the vulnerability information. Thus, the second cloud device can match the asset information with the third vulnerability database to obtain the vulnerability information associated with the asset information. The management device receives the associated vulnerability information sent by the second cloud device, and the management device determines the vulnerability information of the first device based on the associated vulnerability information sent by the second cloud device. There is no need to install a vulnerability scanning tool on the management device, and this possible implementation saves the storage space of the management device.
[0036] In a second aspect of the embodiments of the present application, a method for processing vulnerabilities is provided. The method includes: The gateway device receives a packet capture rule sent by the management device. The gateway device is used to transmit the packets of the first device. There is a first vulnerability in the first software on the first device, and the first software uses the first protocol for network communication. The gateway device intercepts the packets of the target session transmitted by the first device according to the packet capture rule. The packets of the target session contain the packets of the risk of the first vulnerability. The gateway device sends the packets of the target session transmitted by the first device to the management device. The packets of the target session transmitted by the first device are used for the management device to determine the threat level of the first vulnerability, and the threat level is used to indicate whether the management device sends a blocking policy.
[0037] In the embodiments of the present application, the gateway device receives a packet capture rule sent by the management device. The gateway device intercepts the packets of the target session transmitted by the first device according to the packet capture rule. The gateway device sends the intercepted packets of the target session transmitted by the first device to the management device, so that the management device does not send a blocking policy when the first vulnerability is not threatening, avoiding affecting the normal services on the first device due to the blocking policy. When the first vulnerability is threatening, a blocking policy is sent to timely reduce the harm of the first vulnerability and reduce the probability of security incidents occurring.
[0038] In a possible implementation of the second aspect, the above step: The packets of the risk of the first vulnerability include packets with a specified port number and protocol type, or include the vulnerability exploitation request packets corresponding to the first vulnerability. The vulnerability exploitation request packets corresponding to the first vulnerability are identified by a specified string.
[0039] In this possible implementation, the packet capture rule includes the transport protocol type of the target session, the IP protocol for interconnecting the destination networks, and the port number of the first device. Based on the transport protocol type, the IP address of the first device, and the port number of the first device, the gateway device can intercept the packets of the target session transmitted by the first device according to the above parameters. The packets of the target session transmitted by the first device are the two-way traffic packets transmitted by the first protocol adopted on the first software of the first device. If the gateway device identifies the exploit request packet corresponding to the first vulnerability through a specified string, the gateway device can capture the packets with the load characteristics of the first vulnerability according to the specified string. This possible implementation improves the accuracy of intercepting packets.
[0040] In a possible implementation of the second aspect, after the above step: the gateway device sends the packets of the target session transmitted by the first device to the management device, it further includes: the gateway device receives the blocking policy sent by the management device; the gateway device blocks the target session of the first device according to the blocking policy.
[0041] In this possible implementation, when the gateway device receives the blocking policy sent by the management device and blocks the target session of the first device according to the blocking policy, it can prevent the first device from being continuously attacked by the attacking device.
[0042] In a possible implementation of the second aspect, in the above step: when the blocking policy is an access control list, the gateway device blocking the target session of the first device according to the blocking policy includes: the gateway device obtains the entry including the five-tuple information according to the access control list, and the five-tuple information includes the IP address of the attacking device, the port number of the attacking device, the transport protocol type between the attacking device and the first device, the IP address of the first device, and the port number of the first device; the gateway device blocks the traffic indicated by the entry.
[0043] In this possible implementation, since the access control list includes the five-tuple information entries, the gateway device can block the traffic indicated by the entries according to the five-tuple information entries in the access control list. This possible implementation improves the feasibility of the solution.
[0044] The third aspect of the present application provides a management device for executing the method in the first aspect or any possible implementation of the first aspect. Specifically, the device includes modules or units for executing the method in the first aspect or any possible implementation of the first aspect.
[0045] The fourth aspect of this application provides a gateway device for executing the method in the second aspect or any possible implementation manner of the second aspect. Specifically, the device includes a module or unit for executing the method in the second aspect or any possible implementation manner of the second aspect.
[0046] The fifth aspect of this application provides a management device, which includes at least one processor, a memory, and a communication interface. The processor is coupled to the memory and the communication interface. The memory is used for storing instructions, the processor is used for executing the instructions, and the communication interface is used for communicating with other network elements under the control of the processor. When the instructions are executed by the processor, the processor executes the method in the first aspect or any possible implementation manner of the first aspect.
[0047] The sixth aspect of this application provides a gateway device, which includes at least one processor, a memory, and a communication interface. The processor is coupled to the memory and the communication interface. The memory is used for storing instructions, the processor is used for executing the instructions, and the communication interface is used for communicating with other network elements under the control of the processor. When the instructions are executed by the processor, the processor executes the method in the second aspect or any possible implementation manner of the second aspect.
[0048] The seventh aspect of this application provides a computer-readable storage medium, which stores a program that enables the management device to execute the method in the first aspect or any possible implementation manner of the first aspect.
[0049] The eighth aspect of this application provides a computer-readable storage medium, which stores a program that enables the gateway device to execute the method in the second aspect or any possible implementation manner of the second aspect.
[0050] The ninth aspect of this application provides a vulnerability processing system, which includes a management device, a gateway device, at least one internal network device, and at least one external network device. The management device is the management device that implements the method in the first aspect or any possible implementation manner of the first aspect, and the gateway device is the gateway device that implements the method in the second aspect or any possible implementation manner of the second aspect.
[0051] Among them, the technical effects brought by the third, fifth, seventh aspects or any possible implementation manner thereof can be referred to the technical effects brought by the first aspect or different possible implementation manners of the first aspect, which will not be elaborated here.
[0052] Among them, the technical effects brought by the fourth, sixth, eighth aspects or any possible implementation manner thereof can be referred to the technical effects brought by the second aspect or different possible implementation manners of the second aspect, which will not be elaborated here. Description of the Drawings
[0053] Figure 1 It is a schematic diagram of the application scenario of the vulnerability processing system provided by the embodiments of the present application;
[0054] Figure 2 It is a schematic diagram of an embodiment of the vulnerability processing method provided by the embodiments of the present application;
[0055] Figure 3 It is a schematic diagram of another embodiment of the vulnerability processing method provided by the embodiments of the present application;
[0056] Figure 4 It is a schematic diagram of another embodiment of the vulnerability processing method provided by the embodiments of the present application;
[0057] Figure 5a It is a schematic diagram of another embodiment of the vulnerability processing method provided by the embodiments of the present application;
[0058] Figure 5b It is a schematic diagram of another embodiment of the vulnerability processing method provided by the embodiments of the present application;
[0059] Figure 5c It is a schematic diagram of another embodiment of the vulnerability processing method provided by the embodiments of the present application;
[0060] Figure 5d It is a schematic diagram of another embodiment of the vulnerability processing method provided by the embodiments of the present application;
[0061] Figure 6 It is a schematic diagram of another embodiment of the vulnerability processing system provided by the embodiments of the present application;
[0062] Figure 7 It is a schematic diagram of an embodiment of the management device provided by the embodiments of the present application;
[0063] Figure 8 It is a schematic diagram of an embodiment of the gateway device provided by the embodiments of the present application;
[0064] Figure 9 It is a schematic diagram of another embodiment of the management device provided by the embodiments of the present application;
[0065] Figure 10 It is a schematic diagram of another embodiment of the gateway device provided by the embodiments of the present application. Detailed implementation manners
[0066] Next, in combination with the accompanying drawings, the embodiments of the present application will be described. It can be known to those of ordinary skill in the art that with the development of technology and the emergence of new scenarios, the technical solutions provided by the embodiments of the present application are equally applicable to similar technical problems.
[0067] In the description and claims of this application and the above-mentioned drawings, terms such as "first" and "second" are used to distinguish similar objects and do not necessarily describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances so that the embodiments described here can be implemented in an order other than that illustrated or described here.
[0068] The embodiments of this application provide a method for handling vulnerabilities, a management device, and a gateway device, which can enable the devices to communicate normally.
[0069] Figure 1 It is a schematic diagram of the application scenario of the vulnerability handling system provided by the embodiments of this application.
[0070] Please refer to Figure 1 , the vulnerability handling system provided by the embodiments of this application includes: internal network devices 101, 102, and 103, access network devices 104, 106, 108, and 112, a management device 105, gateway devices 107, external network devices 109, 110, and 111.
[0071] Among them, the internal network devices 101, 102, and 103 are connected to the management device 105 through the access network device 104, the internal network devices 101, 102, and 103 are connected to the gateway device 107 through the access network device 106, the gateway device 107 is connected to the external network devices 109, 110, and 111 through the access network device 108, and the management device 105 can be connected to the gateway device 107 through the access network device 112.
[0072] In the embodiments of this application, only three internal network devices 101, 102, and 103, four access network devices 104, 106, 108, and 112, one management device 105, one gateway device 107, and three external network devices 109, 110, and 111 are taken as examples for illustration.
[0073] Optionally, in actual applications, the application scenario of the embodiments of this application may have more or fewer internal network devices, access network devices, management devices, gateway devices, and external network devices than the scenario exemplified.
[0074] Each internal network device can be either a terminal or a server, and each external network device can also be either a terminal or a server. The internal network devices establish communication connections with the external network devices.
[0075] The access network devices 104, 106, 108, and 112 are generally connected to the internal network devices, gateway devices, external network devices, and management devices through a wireless network. Of course, they can also be connected through a wired network. If it is connected through a wireless network, the specific connection form can be a cellular wireless network, or a WiFi network, or other types of wireless networks.
[0076] The access network devices 104, 106, 108, and 112 are generally connected to the internal network devices, gateway devices, external network devices, and management devices through a wireless network, or can also be connected through a wired network. If it is connected through a wired network, the general connection form is a fiber optic network.
[0077] The gateway device 107 is a data forwarding device for internal network devices. After the internal network devices and the external network devices establish a communication connection, data packets are sent between the internal network devices and the external network devices, and the gateway device is used to forward the data packets to assist the internal network devices and the external network devices in communicating.
[0078] The management device can plan, control, and monitor the network. The management device manages the internal network devices, discovers software vulnerabilities in the internal network devices, and processes the vulnerabilities to ensure the normal operation of the network.
[0079] Based on Figure 1 the described vulnerability processing system, the vulnerability processing method provided in the embodiments of the present application will be described:
[0080] Please refer to Figure 2 , an embodiment of the vulnerability processing method in the embodiments of the present application includes:
[0081] 201. The management device obtains the vulnerability information of the first device.
[0082] In the embodiments of the present application, optionally, the vulnerability information may include parameters related to the vulnerability such as the vulnerability identity number (identity, ID), and specific details are not limited here. The vulnerability information of the first device is used to indicate that there is a first vulnerability in the first software on the first device. The internal network device is a network device managed by the management device. When one or more software installed on the internal network device has a vulnerability, one of the vulnerabilities is called the first vulnerability, the internal network device is called the first device, the software with the first vulnerability is called the first software, the first software communicates with other devices using a network protocol, and the first device is managed by the management device.
[0083] 202. The management device obtains a packet capture rule according to the vulnerability information of the first device.
[0084] In the embodiments of the present application, the packet capture rule can be used to identify packets with the risk of the first vulnerability.
[0085] Optionally, the packets with the risk of the first vulnerability may include vulnerability exploitation request packets corresponding to the first vulnerability, and the packets with the risk of the first vulnerability may also include packets with a specified port number and protocol type. It can be understood that other types of packets may also be included, for example, vulnerability exploitation response packets corresponding to the first vulnerability and abnormal data, and specific details are not limited here.
[0086] 203. The management device sends a packet capture rule to the gateway device and indicates that the implementation object of the packet capture rule is the first device.
[0087] In the embodiments of the present application, the gateway device is a data forwarding device of the first device and can be used to forward the packets transmitted by the first device. The management device sends the obtained targeted packet capture rule to the gateway device.
[0088] Optionally, there are multiple ways for the management device to indicate that the implementation object of the packet capture rule is the first device. For example, the management device sends the Internet Protocol (IP) address of the first device and the packet capture rule to the gateway device together, so that the gateway device can determine that the implementation object of the packet capture rule is the first device.
[0089] Alternatively, the management device adds the IP address of the first device to the packet capture rule, that is, adds a packet capture condition to the packet capture rule. The added packet capture condition is that the source IP address and / or destination IP address of the packet is the IP address of the first device. The management device sends the packet capture rule added with the IP address of the first device to the gateway device, so that the gateway device can also determine that the implementation object of the packet capture rule is the first device.
[0090] 204. The gateway device intercepts the packets of the target session transmitted by the first device according to the packet capture rule.
[0091] In the embodiments of the present application, the gateway device can intercept the packets of the target session transmitted by the first device according to the received targeted packet capture rule. The packets of the target session transmitted by the first device include the packets with the first vulnerability risk.
[0092] 205. The gateway device sends the packets of the target session transmitted by the first device to the management device.
[0093] 206. The management device determines the threat level of the first vulnerability according to the packets of the target session transmitted by the first device, and determines whether to send a blocking policy to the gateway device according to the threat level.
[0094] In this embodiment, the management device first sends a targeted packet capture rule to the gateway device according to the vulnerability information related to the first device, and receives the packets of the target session transmitted by the first device captured according to the packet capture rule returned by the gateway device. The management device determines the threat level of the first vulnerability according to the packets of the target session transmitted by the first device.
[0095] Furthermore, based on this threat level, it is determined whether to send a blocking policy to the gateway device. When the first vulnerability is not threatening, the blocking policy is not sent to avoid affecting the normal services on the first device due to the blocking policy. When the first vulnerability is threatening, the blocking policy is sent in a timely manner to reduce the harm of the first vulnerability and the probability of security incidents.
[0096] In the embodiments of the present application, the methods for the management device to obtain the vulnerability information of the first device mentioned in steps 201 and 202, and the method for the management device to obtain the packet capture rule based on the vulnerability information of the first device are not limited to one, but there are multiple acquisition methods. The specific acquisition methods will be elaborated in detail in the following embodiments. In step 206, the management device determines the threat level of the first vulnerability based on the packets of the target session transmitted by the first device, and then determines whether to send a blocking policy to the gateway device according to this threat level, which also has multiple cases. Different cases will also be described in detail in the following embodiments.
[0097] In the above step 201, the management device can obtain the vulnerability information of the first device from different devices and systems in the following several ways, which will be described separately below:
[0098] 1. The management device obtains the vulnerability information of the first device by means of vulnerability scanning.
[0099] The management device sends a detection packet to the first device.
[0100] The management device obtains the response packet returned by the first device for the detection packet.
[0101] After the management device sends a detection packet to the first device, the management device records the response packet sent by the first device, so as to remotely detect the service of the specified port of the first device. This response packet is a packet with the risk of the first vulnerability, and this response packet includes the specified port number of the first device and the relevant information of the network access service of the first software.
[0102] Optionally, the specified port number can be the port number of the Transmission Control Protocol / Internet Protocol (TCP / IP) port, or the port number of other ports, and specific limitations are not made here.
[0103] Optionally, the relevant information of the network access service may be whether the first software can be logged in anonymously, whether there is a writable File Transfer Protocol (FTP) directory, and whether Telnet can be used. It can be imagined that the relevant information of the first device included in the response message may also be other information. For example, whether httpd is running as root, etc. Specifically, it is not limited here.
[0104] The management device obtains the vulnerability information corresponding to the response message from the second vulnerability database according to the response message, so as to determine the vulnerability information of the first device.
[0105] After obtaining the response message of the first device, the management device matches the response message with the vulnerability information in the second vulnerability database. The second vulnerability database includes the corresponding relationship between the response message and the vulnerability information. By matching the relevant identifier of the first vulnerability included in the response message with the vulnerability information in the second vulnerability database, the vulnerability information corresponding to the response message is obtained.
[0106] The second vulnerability database is provided by the vulnerability scanning tool in the management device. The second vulnerability database is a system vulnerability database comprehensively formed by security experts based on the analysis of network system security vulnerabilities, hacker attack cases, the practical experience of system administrators regarding network system security configurations, and other contents. Specifically, it is not limited here. Then, corresponding matching rules are formed on the basis of the second vulnerability database.
[0107] In terms of the matching principle, the management device adopts a rule-based matching technology, and the rule is a rule predefined by expert experience. Exemplarily, in the scan of TCP port 80, if / cgi-bin / phf / cgi-bin / Count.cgi is found, according to expert experience and the sharing and standardization of CGI programs, it can be inferred that there are two CGI vulnerabilities in the WWW service. It can be understood that this is only an example here, and there may be other matching methods. Specifically, it is not limited here.
[0108] 2. The management device obtains the vulnerability information of the first device from the network management system by matching the first software information with the vulnerability information of the first device.
[0109] The process of obtaining the vulnerability information of the first device can refer to Figure 3 for understanding. As Figure 3 shown, the process of the management device provided by the embodiment of the present application obtaining the vulnerability information of the first device through software and vulnerability matching through the network management system includes:
[0110] 2001. The management device sends a first software information acquisition instruction to the network management system.
[0111] The first software information acquisition instruction is used to instruct the network management system to acquire software information, and the first software information acquisition instruction is used to instruct the network management system to acquire the software information of the software installed on the first device.
[0112] 2002. The management device receives the software information returned by the network management system according to the first software information acquisition instruction.
[0113] The management device receives the software information sent by the network management system. The software information includes the ID of the first software, the model of the software, the version number of the software, and other software-related parameters, which are not specifically limited here.
[0114] 2003. The management device sends the software information to the second cloud device.
[0115] The management device sends the first software information to the second cloud device. The second cloud device contains a third vulnerability database, and the third vulnerability database includes the association relationship between software information and vulnerability information. The second cloud device obtains the vulnerability information included in the third vulnerability database according to the first software information and the association relationship between the first software information and the vulnerability information of the first device.
[0116] The second cloud device obtains the association relationship between software and vulnerability information according to the software-related parameters of the software included in the software information, such as the ID of the software, the model of the software, and the version number of the software.
[0117] Exemplarily, if the first software is Google Chrome and the version number of the first software is 8.0.11. The third vulnerability database includes a list of the association relationship between vulnerability "A" and Google Chrome with version number 8.0.11, and the ID of vulnerability "A". This association relationship list indicates that Google Chrome with version number 8.0.11 corresponds to vulnerability "A".
[0118] The management device sends software information to the second cloud device, and the software information includes Google Chrome with version number 8.0.11. After receiving the software information, the second cloud device matches the software information with the third vulnerability database and obtains the ID of vulnerability "A" corresponding to Google Chrome with version number 8.0.11 in the third vulnerability database. The ID of this vulnerability "A" is the vulnerability information.
[0119] It can be understood that this is only for illustrative purposes here. In actual applications, optionally, the software information may include the ID of the software, the model of the software, and the version number of the software. The software information may also include other software-related parameters, which are not specifically limited here. Optionally, the third vulnerability database may not only include the association relationship between software information and vulnerability information, but may also include other information, which is not specifically limited here.
[0120] In 2004, the management device receives the associated vulnerability information sent by the second cloud device.
[0121] In 2005, determine the vulnerability information of the first device.
[0122] After the management device receives the associated vulnerability information sent by the second cloud device, it combines the associated vulnerability information sent by the second cloud device with the relevant information of the first device to form the vulnerability information of the first device. Optionally, the relevant information of the first device can be the IP address of the first device, or the identifier that proves the identity information of the first device, or other information related to the first device, which is not specifically limited here.
[0123] 3. The management device obtains the vulnerability information of the first device from the first device by matching the first software information with the vulnerability information of the first device.
[0124] The process of obtaining the vulnerability information can refer to Figure 4 for understanding. As Figure 4 shown, the process of the management device provided in the embodiment of the present application obtaining the vulnerability information of the first device through software and vulnerability matching includes:
[0125] The management device sends a second software information acquisition instruction to the first device.
[0126] The management device receives the software information returned by the first device according to the second software information acquisition instruction.
[0127] After the management device sends a second software information acquisition instruction to the first device, a client (agent) is installed on the first device. The agent obtains software information from the first device. It can be understood that the software information in this embodiment is similar to the software information in step 2002, which is not specifically described here.
[0128] The management device sends the software information to the second cloud device.
[0129] In this embodiment, this step is similar to the embodiment 2003 shown in the foregoing Figure 3 and will not be elaborated here.
[0130] The management device receives the associated vulnerability information sent by the second cloud device.
[0131] In this embodiment, this step is similar to the embodiment 2004 shown in the foregoing Figure 3 and will not be elaborated here.
[0132] Determine the vulnerability information of the first device.
[0133] In this embodiment, this step is similar to the foregoing Figure 3It is similar to the shown Example 2005, and the details are not described here again.
[0134] In the above embodiments, there are various ways to obtain the vulnerability information of the first device. The vulnerability information of the first device can be obtained through vulnerability scanning, or through the matching of the first software information and the vulnerability information of the first device to obtain the vulnerability information of the first device through the network management system, or through the matching of the first software information and the vulnerability information of the first device to obtain the vulnerability information of the first device through the first device. It can be understood that there are other ways to obtain the vulnerability information of the first device, and the details are not limited here.
[0135] In the embodiments of the present application, in step 202, the management device obtains the packet capture rule according to the vulnerability information of the first device, and the following several ways can be adopted, which are described separately below:
[0136] 1. The management device obtains the packet capture rule corresponding to the first vulnerability from the local rule library according to the identification information of the first vulnerability.
[0137] In this embodiment, the management device can obtain the packet capture rule corresponding to the first vulnerability from the local rule library according to the identification information of the first vulnerability. The identification information of the first vulnerability may include the ID of the first vulnerability and other identifiers used to represent the identity of the first vulnerability, and the details are not limited here. The local rule library is a corresponding library of the identification information of the first vulnerability and the packet capture rule.
[0138] 2. The management device obtains the packet capture rule corresponding to the first vulnerability from the cloud rule library according to the identification information of the first vulnerability.
[0139] In this embodiment, optionally, the management device can also obtain the packet capture rule in other ways.
[0140] The management device sends the identification information of the first vulnerability to the first cloud device. Optionally, the identification information of the first vulnerability may include the ID of the first vulnerability, the label of the first vulnerability, and other identifiers used to represent the identity of the first vulnerability, and the details are not limited here. The identification information of the first vulnerability is used to instruct the first cloud device to obtain the packet capture rule corresponding to the identification information of the first vulnerability from the cloud rule library. The cloud rule library is a corresponding library of the identification information of the first vulnerability and the packet capture rule, which includes the identification information of the first vulnerability and the corresponding packet capture rule.
[0141] The management device receives the packet capture rule corresponding to the first vulnerability obtained by the first cloud device from the cloud rule library.
[0142] In addition to the packet capture rule acquisition methods mentioned in the above embodiments, optionally, the management device can also obtain the packet capture rule in other different ways, and the details are not limited here.
[0143] In this embodiment, in step 204, the gateway device intercepts the message of the target session transmitted by the first device according to the packet capture rule. Optionally, the message of the target session transmitted by the first device includes a message with a specified port number and protocol type, or includes a vulnerability exploitation request message corresponding to the first vulnerability. The gateway device can intercept the message of the target session transmitted by the first device in different ways according to different packet capture rules, which can be divided into the following situations, which are described below:
[0144] 1. Messages with the risk of the first vulnerability include messages with a specified port number and protocol type.
[0145] The gateway device obtains the protocol type and the specified port number of the target session in the packet capture rule.
[0146] The gateway device captures the message corresponding to the packet capture rule from the message of the target session transmitted by the first device according to the protocol type of the target session in the packet capture rule and the designated port number.
[0147] In this embodiment, the first software with the first vulnerability on the first device communicates with other devices using a network protocol. Optionally, the first vulnerability may be specific to the network protocol.
[0148] Exemplarily, if the first vulnerability with ID X is a vulnerability for a certain network protocol. Therefore, the management device can obtain a five-tuple packet capture rule: the source IP address and source port number in the five-tuple packet capture rule are set to all (any), and all bidirectional traffic of this protocol type to the IP address of the first device and the port number of the first device are captured. The destination IP address in the five-tuple packet capture rule is the IP address of the first device included in the vulnerability information of the first device, and the destination port number in the five-tuple packet capture rule is the port number of the network protocol in which the vulnerability occurs in the first device. The management device sends the packet capture rule to the gateway device, and the gateway device captures all bidirectional traffic of this transmission protocol type to the IP address of the first device and the port number of the first device according to the packet capture rule.
[0149] 2. The message having the risk of the first vulnerability includes a vulnerability exploitation request message corresponding to the first vulnerability, and the vulnerability exploitation request message corresponding to the first vulnerability is identified by a specified character string.
[0150] The gateway device obtains the specified character string corresponding to the first vulnerability in the packet capture rule.
[0151] If the exploit program for the first vulnerability must send an exploit request message corresponding to the first vulnerability to conduct an attack, and the exploit request message corresponding to the first vulnerability includes a certain specified string, then feature packet capture can be performed. The feature packet capture rule includes the specified string, and the specified string corresponds to the exploit request message corresponding to the first vulnerability. The gateway device will obtain the specified string in the packet capture rule.
[0152] The gateway device intercepts all packets with the specified string according to the specified string.
[0153] In this embodiment, after the gateway device obtains the specified string in the packet capture rule, the gateway device can intercept the packets of the target session transmitted by the first device according to the specified string.
[0154] Optionally, the specified string can be a certain ordinary string or a certain function variable, or other types of specified strings, and specific details are not limited here.
[0155] If the exploit request message corresponding to the first vulnerability includes the specified string "ABC", the attack device can attack the first device only when the exploit request message with the specified string "ABC" is included in the message for the attack device to communicate with the first device. Optionally, the specified string "ABC" here is only used for illustration, and it can also be the specified string "ABD", or other specified strings, and specific details are not limited here.
[0156] The gateway device monitors all packets of the specified protocol to the IP address and port number of the first device. If the packets monitored by the gateway device have the specified string included in the packet capture rule, that is, the specified string "ABC", then the gateway device will intercept the packet with the specified string "ABC".
[0157] If the specified string included in the exploit request message corresponding to the first vulnerability is a certain function variable, the attack device can attack the first device only when the function variable is included in the packets of the target session for the attack device to communicate with the first device. At this time, the packet capture rule corresponding to the exploit request message corresponding to the first vulnerability includes a regular expression, and the regular expression corresponds to the function variable. The gateway device monitors all packets of the specified protocol to the IP address of the first device and the port number of the first device. If the packets monitored by the gateway device have the function variable corresponding to the regular expression included in the packet capture rule, then the gateway device will intercept the packet with the function variable.
[0158] In the embodiment of the present application, in step 206, the management device determines the threat level of the first vulnerability based on the packets of the target session transmitted by the first device, and determines whether to send a blocking policy to the gateway device according to the threat level. Among them, the gateway device captures packets according to the five-tuple packet capture rule, and the packets intercepted by the gateway device are packets with the risk of the first vulnerability. The packets with the risk of the first vulnerability may include packets with a specified port number and protocol type, or the packets with the risk of the first vulnerability may include vulnerability exploitation request packets corresponding to the first vulnerability. According to different packet capture rules, step 206 can be specifically divided into the following situations, which will be described separately below.
[0159] I. The gateway device captures packets according to the five-tuple packet capture rule, and the packets intercepted by the gateway device are packets with the risk of the first vulnerability. The packets with the risk of the first vulnerability may include packets with a specified port number and protocol type.
[0160] The management device can determine whether to send a blocking policy to the gateway device according to different conditions, which will be described in detail separately below:
[0161] 1. If there is no sequentially occurring vulnerability exploitation request packet corresponding to the first vulnerability and vulnerability exploitation response packet corresponding to the first vulnerability in the packets of the target session transmitted by the first device, the management device does not send a blocking policy to the gateway device.
[0162] The management device calls the first vulnerability library, which includes the correspondence between the vulnerability exploitation request packet corresponding to the first vulnerability and the vulnerability exploitation response packet corresponding to the first vulnerability. The management device determines whether the packets of the target session transmitted by the first device contain sequentially occurring vulnerability exploitation request packets corresponding to the first vulnerability and vulnerability exploitation response packets corresponding to the first vulnerability according to the correspondence. If there is no sequentially occurring vulnerability exploitation request packet corresponding to the first vulnerability and vulnerability exploitation response packet corresponding to the first vulnerability in the packets of the target session transmitted by the first device, then the management device does not send a blocking policy to the gateway device. If there are sequentially occurring vulnerability exploitation request packets corresponding to the first vulnerability and vulnerability exploitation response packets corresponding to the first vulnerability in the packets of the target session transmitted by the first device, the management device sends a blocking policy to the gateway device. For specific understanding, please refer to the Figure 5a process. As shown in Figure 5a the process of step 206 includes:
[0163] 3001. The management device determines whether there are vulnerability exploitation request messages corresponding to the first vulnerability and vulnerability exploitation response messages corresponding to the first vulnerability that appear sequentially in the messages of the target session transmitted by the first device based on the correspondence between the vulnerability exploitation request messages corresponding to the first vulnerability and the vulnerability exploitation response messages corresponding to the first vulnerability included in the first vulnerability library.
[0164] In this embodiment, the first vulnerability library is a preset vulnerability library. The first vulnerability library may include a corresponding relationship between a vulnerability exploitation request message corresponding to the first vulnerability and a vulnerability exploitation response message corresponding to the first vulnerability. Optionally, the first vulnerability library may also include other content related to the first vulnerability, which is not specifically limited here.
[0165] For example, if the first software is a browser, taking the browser as an example, the vulnerability exploitation request message corresponding to the first vulnerability existing on the browser may include the string "ABC", and the string "ABC" may be used to represent the vulnerability exploitation request of the attack device, and the vulnerability exploitation response message corresponding to the first vulnerability corresponding to the first vulnerability may include the string "DEF", and the existence of the string "DEF" indicates that the first vulnerability does exist and can be exploited. There is a unique correspondence between the string "ABC" and the string "DEF". The correspondence between the vulnerability exploitation request message corresponding to the first vulnerability included in the first vulnerability library and the vulnerability exploitation response message corresponding to the first vulnerability is the correspondence between the string "ABC" and the string "DEF".
[0166] The management device determines, based on the corresponding relationship, whether there is a vulnerability exploitation request message corresponding to the first vulnerability and a vulnerability exploitation response message corresponding to the first vulnerability that appear in sequence in the message of the target session transmitted by the first device.
[0167] The first vulnerability library may include a correspondence between a vulnerability exploitation request message corresponding to the first vulnerability and a vulnerability exploitation response message corresponding to the first vulnerability. The management device can determine whether there is a vulnerability exploitation request message corresponding to the first vulnerability in the message of the target session transmitted by the first device based on the first vulnerability library.
[0168] If the target session includes an exploit request message corresponding to the first vulnerability, and the exploit request message corresponding to the first vulnerability includes the string "ABC". If the response message of the target session includes not the string "DEF" but the string "EFG", and the vulnerability response message corresponding to the first vulnerability with the string "EFG" does not correspond to the exploit request message corresponding to the first vulnerability with the string "ABC", it proves that there is no exploit response message corresponding to the first vulnerability in the response message of the target session, and the threat level of the first vulnerability is relatively low. If the string "DEF" exists in the response message of the target session, it is considered that there is an exploit response message corresponding to the first vulnerability in the target session, and then the target session transmitted by the first device includes the exploit request message corresponding to the first vulnerability and the exploit response message corresponding to the first vulnerability that appear in sequence.
[0169] Optionally, the strings "ABC", "DEF", and "EFG" here are only used for illustration, and can also be the characteristic strings "ABDM" and "EFKN", or other types of strings. Specifically, they are not limited here.
[0170] If it is determined that there is an exploit request message corresponding to the first vulnerability in the message of the target session transmitted by the first device, the management device can rate the first vulnerability as a first-level vulnerability. A first-level vulnerability represents that there is a certain risk in the vulnerability. If there is no exploit request message corresponding to the first vulnerability in the message of the target session transmitted by the first device, the first vulnerability is not rated and no processing is performed on the first vulnerability.
[0171] Optionally, the management device can rate the first vulnerability or not rate the first vulnerability. The management device not rating the first vulnerability does not affect the execution of other steps.
[0172] In this embodiment, after the management device rates the first vulnerability as a first-level vulnerability, the management device can also send a first-level vulnerability prompt message to the first device, and the first-level vulnerability prompt message is used to remind the user that the first vulnerability has a certain risk.
[0173] It can be understood that the management device can send a prompt message to the first device or not send a prompt message to the first device. If the management device does not send a prompt message to the first device, it does not affect the execution of other steps.
[0174] 3002. If there is no exploit request message corresponding to the first vulnerability and the exploit response message corresponding to the first vulnerability that appear in sequence in the message of the target session transmitted by the first device, the management device does not send the blocking policy to the gateway device.
[0175] The management device determines whether there is an exploit request message corresponding to the first vulnerability and the corresponding exploit response message corresponding to the first vulnerability in the packets of the target session according to the first vulnerability database. If the management device determines that there is no exploit request message corresponding to the first vulnerability in the target session, or if the management device determines that there is only an exploit request message corresponding to the first vulnerability in the target session but no exploit response message corresponding to the first vulnerability, the management device does not send a blocking policy to the gateway device.
[0176] 3003. If there are an exploit request message corresponding to the first vulnerability and an exploit response message corresponding to the first vulnerability that appear in sequence in the packets of the target session transmitted by the first device, the management device obtains the five-tuple information of the target session according to the packets of the target session transmitted by the first device.
[0177] The management device determines whether there is an exploit request message corresponding to the first vulnerability and the corresponding exploit response message corresponding to the first vulnerability in the packets of the target session transmitted by the first device according to the first vulnerability database. If the management device determines that there are an exploit request message corresponding to the first vulnerability and an exploit response message corresponding to the first vulnerability that appear in sequence in the target session, the management device considers the first vulnerability to be threatening. The management device can send a blocking policy to the gateway device.
[0178] If the target session contains an exploit request message corresponding to the first vulnerability and an exploit response message corresponding to the first vulnerability that appear in sequence, the first vulnerability can be rated as a second-level vulnerability, and the disposal priority of the second-level vulnerability is higher than that of the first-level vulnerability.
[0179] Optionally, the management device can rate the first vulnerability or not. If the management device does not rate the first vulnerability, it does not affect the execution of other steps.
[0180] After the management device rates the first vulnerability as a second-level vulnerability, the management device can also send a second-level vulnerability prompt message to the first device, and the second-level vulnerability prompt message is used to remind the user that the second-level vulnerability has relatively serious risks.
[0181] Optionally, the management device can send a prompt message to the first device or not. If the management device does not send a prompt message to the first device, it does not affect the execution of other steps.
[0182] The management device obtains the five-tuple information of the target session according to the packets of the target session transmitted by the first device
[0183] The five-tuple information includes the IP address of the attacking device, the port number of the attacking device, the type of transmission protocol between the attacking device and the first device, the IP address of the first device, and the port number of the first device.
[0184] 3004. The management device generates an entry containing the five-tuple information and adds the generated entry to the access control list.
[0185] In this embodiment, optionally, the blocking policy generated by the management device can be either an access control list or other means, which is not specifically limited here. The access control list generated by the management device is used to block the traffic indicated by the entries included in the access control list.
[0186] 3005. The management device sends the blocking policy to the gateway device.
[0187] The management device sends the blocking policy to the gateway device. Optionally, the blocking policy can be an access control list or other types of policies that can block the target session transmitted by the first device, which is not elaborated here.
[0188] In the above embodiment, if there is no vulnerability exploitation request message corresponding to the first vulnerability and / or vulnerability exploitation response message corresponding to the first vulnerability that appear in sequence in the packet of the target session transmitted by the first device, then the management device does not send the blocking policy to the gateway device. In practical applications, of course, it can also be another situation. If there is no abnormal data in the target session, then the management device does not send the blocking policy to the gateway device, which is described in detail below:
[0189] 2. If there is no abnormal data in the target session, then the management device does not send the blocking policy to the gateway device:
[0190] The process of this implementation manner can be referred to Figure 5b for understanding. As Figure 5b shown, an implementation manner provided by an embodiment of the present application includes:
[0191] 4001. The management device determines whether there is a vulnerability exploitation request message corresponding to the first vulnerability and a vulnerability exploitation response message corresponding to the first vulnerability that appear in sequence in the packet of the target session transmitted by the first device according to the correspondence between the vulnerability exploitation request message corresponding to the first vulnerability and the vulnerability exploitation response message corresponding to the first vulnerability included in the first vulnerability database.
[0192] In this embodiment, this step is similar to step 3001 of the foregoing embodiment, and will not be elaborated here.
[0193] 4002. If there is no exploit request message corresponding to the first vulnerability and exploit response message corresponding to the first vulnerability that appear in sequence in the packets of the target session transmitted by the first device, the management device does not send the blocking policy to the gateway device.
[0194] In this embodiment, this step is similar to step 3002 in the foregoing embodiment, and details are not described herein again.
[0195] 4003. If there is an exploit request message corresponding to the first vulnerability and an exploit response message corresponding to the first vulnerability that appear in sequence in the packets of the target session transmitted by the first device, the management device determines whether the packets of the target session transmitted by the first device include abnormal data.
[0196] The exploit request message corresponding to the first vulnerability includes the string "ABC". The management device analyzes the packets of the target session transmitted by the first device according to the first vulnerability database. If the request packet of the target session includes the string "ABC", then the packet with the string "ABC" is considered as the exploit request message corresponding to the first vulnerability. Then, the packets of the target session transmitted by the first device include the exploit request message corresponding to the first vulnerability. Similarly, if the exploit response message corresponding to the first vulnerability includes the string "DEF" and the packets of the target session transmitted by the first device include the string "DEF", then the response packet with the string "DEF" is considered as the exploit response message corresponding to the first vulnerability. Then, the packets of the target session transmitted by the first device include the exploit response message corresponding to the first vulnerability. At this time, it can be considered that there are an exploit request message corresponding to the first vulnerability and an exploit response message corresponding to the first vulnerability that appear in sequence in the packets of the target session transmitted by the first device.
[0197] Optionally, the feature strings "ABC" and "DEF" are only used for illustration here, and can also be feature strings "ABDG" and "EFKO", or other types of feature strings. Specific details are not limited here.
[0198] After the management device determines that there are an exploit request message corresponding to the first vulnerability and an exploit response message corresponding to the first vulnerability that appear in sequence in the packets of the target session transmitted by the first device according to the first vulnerability database, the management device can determine whether the packets of the target session transmitted by the first device include abnormal data.
[0199] The management device determines whether there is abnormal data in the packets of the target session transmitted by the first device through multiple anomaly determinations. For example, optionally, the anomaly determination may be that the management device confirms whether the packets of the target session transmitted by the first device include a string for uploading a script, or that the management device confirms whether the packets of the target session transmitted by the first device include a string for uploading an executable program. There may also be other ways of anomaly determination, which are not specifically limited here. If the management device determines that the target session includes abnormal data, then the management device determines that the first vulnerability has been successfully exploited by the attacking device.
[0200] Exemplarily, if the first software is a browser on the first device, when the management device determines that there are a vulnerability exploitation request packet corresponding to the first vulnerability and a vulnerability exploitation response packet corresponding to the first vulnerability that appear in sequence in the packets of the target session transmitted by the first device, the management device determines through anomaly determination whether the packets of the target session transmitted by the first device include the string "XYZ". The string "XYZ" may represent a certain upload program. If the string "XYZ" exists, it can prove that the target session transmitted by the first device includes abnormal data. The fact that the target session transmitted by the first device includes abnormal data indicates that the first vulnerability has been exploited, and the first vulnerability is extremely dangerous.
[0201] Optionally, the feature string "XYZ" here is only used for illustration. It may also be the feature strings "ABCD" and "EF", or other feature strings, which are not specifically limited here.
[0202] If the target session contains a vulnerability exploitation request packet corresponding to the first vulnerability and a vulnerability exploitation response packet corresponding to the first vulnerability that appear in sequence, then the first vulnerability can be rated as a level-two vulnerability. The disposal priority of a level-two vulnerability is higher than that of a level-one vulnerability. If the vulnerability exploitation response packet corresponding to the first vulnerability does not exist in the response packet of the target session, then the first vulnerability is processed as a level-one vulnerability.
[0203] It can be understood that the management device may rate the first vulnerability or may not rate the first vulnerability. The management device not rating the first vulnerability does not affect the execution of other steps.
[0204] In this embodiment, if the management device determines that the target session transmitted by the first device includes abnormal data, then the management device may rate the first vulnerability as a level-three vulnerability. A level-three vulnerability means that the first vulnerability has been successfully exploited by the attacking device, and the first vulnerability is extremely dangerous.
[0205] Optionally, when the management device determines that the target session includes abnormal data, it may rate the first vulnerability or may not rate the first vulnerability, which is not specifically limited here. Not rating the first vulnerability does not affect the implementation of other steps.
[0206] In this embodiment, after the management device rates the first vulnerability as a level-three vulnerability, the management device may also send a level-three vulnerability prompt message to the first device. The level-three vulnerability prompt message is used to remind the user that the first vulnerability has been exploited and that the first vulnerability poses a very high risk.
[0207] Optionally, the management device may or may not send a prompt message to the first device, and no specific limitation is imposed here. The management device not sending a prompt message to the first device does not affect the execution of other steps.
[0208] 4004. If the management device determines that the packet of the target session transmitted by the first device does not include abnormal data, the management device does not send a blocking policy to the gateway device.
[0209] 4005. If the management device determines that the packet of the target session transmitted by the first device includes abnormal data, the management device obtains the five-tuple information of the target session according to the packet of the target session transmitted by the first device.
[0210] In this embodiment, the manner in which the management device obtains the five-tuple information of the target session transmitted by the first device is similar to step 3003 of the foregoing embodiment, and details are not described herein again.
[0211] 4006. The management device generates an entry containing the five-tuple information and adds the generated entry to the access control list.
[0212] In this embodiment, this step is similar to step 3004 of the foregoing embodiment, and details are not described herein again.
[0213] 4007. The management device sends the blocking policy to the gateway device.
[0214] In this embodiment, this step is similar to step 3005 of the foregoing embodiment, and details are not described herein again.
[0215] 1. The gateway device performs packet capture according to the feature packet capture rule. The packet intercepted by the gateway device is a packet with the risk of the first vulnerability, and the packet with the risk of the first vulnerability includes a vulnerability exploitation request packet corresponding to the first vulnerability.
[0216] The management device may determine whether to send a blocking policy to the gateway device according to different conditions, which are described in detail below:
[0217] 1. If the packet of the target session transmitted by the first device does not have the vulnerability exploitation request packet corresponding to the first vulnerability and the vulnerability exploitation response packet corresponding to the first vulnerability that appear in sequence, the management device does not send a blocking policy to the gateway device.
[0218] The process of this implementation manner can be referred to Figure 5c for understanding. For example, Figure 5c as shown, an implementation manner provided by an embodiment of the present application includes:
[0219] 5001. The management device determines whether the packet of the target session transmitted by the first device further includes the vulnerability exploitation response packet corresponding to the first vulnerability according to the correspondence between the vulnerability exploitation request packet corresponding to the first vulnerability and the vulnerability exploitation response packet corresponding to the first vulnerability included in the first vulnerability database.
[0220] In this embodiment, the first vulnerability database in this step is similar to the above step 3001, and details are not described here specifically.
[0221] The packet with the risk of the first vulnerability includes the vulnerability exploitation request packet corresponding to the first vulnerability. Therefore, the management device determines whether the packet of the target session transmitted by the first device includes the vulnerability exploitation response packet corresponding to the first vulnerability according to the first vulnerability database, that is, it can determine whether there is a risk that the first vulnerability is exploited. If there is no vulnerability exploitation response packet corresponding to the first vulnerability, it proves that there is no risk that the first vulnerability is exploited. On the contrary, if there is a vulnerability exploitation response packet corresponding to the first vulnerability, it proves that the attacking device can attack the first vulnerability and there is a risk that the first vulnerability is exploited.
[0222] Exemplarily, if the first software is a browser, taking the browser as an example. The vulnerability exploitation request packet corresponding to the first vulnerability existing on the browser may include the string "ABC", and the string "ABC" can be used to represent the vulnerability exploitation request of the attacking device. The vulnerability exploitation response packet corresponding to the first vulnerability may include the string "DEF", and the string "DEF" can be used to represent that the first vulnerability actually exists and can be exploited. The target session transmitted by the first device already includes the vulnerability exploitation request packet corresponding to the first vulnerability. There is a unique correspondence between the string "ABC" and the string "DEF", and the correspondence between the vulnerability exploitation request packet corresponding to the first vulnerability and the vulnerability exploitation response packet corresponding to the first vulnerability included in the first vulnerability database is the correspondence between the string "ABC" and the string "DEF". Therefore, the management device can determine whether the target session transmitted by the first device includes a packet with the string "DEF" according to this correspondence, and the packet with the string "DEF" is the vulnerability exploitation response packet corresponding to the first vulnerability.
[0223] If the message of the target session transmitted by the first device does not include the string "DEF" but the string "EFG", and the response message with the string "EFG" does not correspond to the exploit request message corresponding to the first vulnerability with the string "ABC", it proves that there is no exploit response message corresponding to the first vulnerability in the response message of the target session, and the threat level of the first vulnerability is relatively low. If the string "DEF" exists in the response message of the target session, it is considered that there is an exploit response message corresponding to the first vulnerability in the target session. Then, the target session transmitted by the first device includes the exploit request message corresponding to the first vulnerability and the exploit response message corresponding to the first vulnerability that appear in sequence.
[0224] Here, the characteristic strings "ABC", "DEF", and "EFG" are only used for illustration. Optionally, they can also be the characteristic strings "ABDM", "EFKN", and "DEFK", or other types of characteristic strings, which are not specifically limited here.
[0225] 5002. If there is no exploit response message corresponding to the first vulnerability in the message of the target session transmitted by the first device, the management device does not send a blocking policy to the gateway device.
[0226] If the management device confirms that there is no exploit response message corresponding to the first vulnerability in the message of the target session transmitted by the first device, then the management device can consider that there is no risk of the first vulnerability being exploited. Therefore, the management device can not send a blocking policy to the gateway device, and the first software on the first device can communicate normally.
[0227] 5003. If there is an exploit response message corresponding to the first vulnerability in the message of the target session transmitted by the first device, the management device obtains the five-tuple information of the target session according to the message of the target session transmitted by the first device.
[0228] If there is an exploit response message corresponding to the first vulnerability, then the management device can consider that there is a risk of the first vulnerability being exploited. Therefore, the management device can send a blocking policy to the gateway device.
[0229] If it is determined that there is an exploit response message corresponding to the first vulnerability in the message of the target session transmitted by the first device, the management device can rate the first vulnerability as a first-level vulnerability. A first-level vulnerability represents that there is a risk of the first vulnerability being exploited by an attacking device. If there is no exploit response message corresponding to the first vulnerability in the message of the target session transmitted by the first device, the first vulnerability is not rated and no processing is performed on the first vulnerability.
[0230] Optionally, the management device may rate the first vulnerability or may not rate the first vulnerability. The management device not rating the first vulnerability does not affect the execution of other steps.
[0231] In this embodiment, after the management device determines that the first vulnerability is a level-1 vulnerability, the management device may further send a level-1 vulnerability prompt message to the first device. The level-1 vulnerability prompt message is used to remind the user that the first vulnerability poses a risk.
[0232] Optionally, the management device may send a prompt message to the first device or may not send a prompt message to the first device. The management device not sending a prompt message to the first device does not affect the execution of other steps.
[0233] The management device obtains the five-tuple information of the target session according to the packet.
[0234] In this embodiment, the process in which the management device obtains the five-tuple information of the target session according to the packet intercepted by the gateway device is similar to step 3003 above, and will not be elaborated here.
[0235] 5004. The management device generates an entry containing the five-tuple information and adds the generated entry to the access control list.
[0236] In this embodiment, this step is similar to step 3004 in the foregoing embodiment, and will not be elaborated here.
[0237] 5005. The management device sends a blocking policy to the gateway device.
[0238] In this embodiment, this step is similar to step 3005 in the foregoing embodiment, and will not be elaborated here.
[0239] 2. If there is no abnormal data in the target session, then the management device does not send a blocking policy to the gateway device:
[0240] The process of this implementation manner can be referred to Figure 5d for understanding. As Figure 5d shown, an implementation manner provided in an embodiment of the present application includes:
[0241] 6001. The management device determines whether the packet of the target session transmitted by the first device contains the vulnerability exploitation response packet corresponding to the first vulnerability according to the correspondence between the vulnerability exploitation request packet corresponding to the first vulnerability and the vulnerability exploitation response packet corresponding to the first vulnerability included in the first vulnerability database.
[0242] In this embodiment, the first vulnerability database in this step is similar to step 5001 above, and will not be elaborated here.
[0243] 6002. If there is no exploit response message corresponding to the first vulnerability in the packets of the target session transmitted by the first device, the management device does not send a blocking policy to the gateway device.
[0244] In this embodiment, the first vulnerability database in this step is similar to the above step 5002, and details are not described here specifically.
[0245] 6003. If there is an exploit response message corresponding to the first vulnerability in the packets of the target session transmitted by the first device, the management device determines whether the packets of the target session transmitted by the first device include the abnormal data.
[0246] The management device determines, according to the first vulnerability database, that there is an exploit response message corresponding to the first vulnerability in the packets of the target session transmitted by the first device. At this time, the management device can determine whether the packets of the target session transmitted by the first device include abnormal data.
[0247] The manner in which the management device determines whether there is abnormal data is similar to the above step 4003, and details are not described here specifically.
[0248] 6004. If the management device determines that the target session transmitted by the first device does not include abnormal data, the management device does not send a blocking policy to the gateway device.
[0249] If the management device determines that there is an exploit response message in the target session transmitted by the first device, but the target session transmitted by the first device does not include abnormal data, the management device believes that although the attacking device can attack the first vulnerability, the first vulnerability has not been exploited. Therefore, the management device does not send a blocking policy to the gateway device.
[0250] 6005. If the management device determines that the target session transmitted by the first device includes abnormal data, the management device obtains the five-tuple information of the target session according to the packets of the target session transmitted by the first device.
[0251] The management device determines whether the target session transmitted by the first device includes abnormal data. If there is abnormal data, it is considered that the attacking device has successfully exploited the first vulnerability, and the management device can send a blocking policy to the gateway device. If there is no abnormal data, it is considered that the attacking device has not exploited the first vulnerability, and the management device can not send a blocking policy to the gateway device.
[0252] If the target session contains an exploit request message corresponding to the first vulnerability and an exploit response message corresponding to the first vulnerability that appear in sequence, the first vulnerability can be rated as a first-level vulnerability. If there is no exploit response message corresponding to the first vulnerability in the response packets of the target session, no processing is performed on the vulnerability.
[0253] Optionally, the management device may rate the first vulnerability or may not rate the first vulnerability. The management device not rating the first vulnerability does not affect the execution of other steps.
[0254] In this embodiment, if the management device determines that there is abnormal data in the target session transmitted by the first device, the management device considers that the first vulnerability has been successfully exploited by the attacking device. Then the management device may rate the first vulnerability as a level-two vulnerability, and the handling priority of a level-two vulnerability is higher than that of a level-one vulnerability. A level-two vulnerability indicates that the first vulnerability has been successfully exploited by the attacking device, and the first vulnerability is extremely dangerous.
[0255] Optionally, when the management device determines that the target session includes abnormal data, it may rate the first vulnerability or may not rate the first vulnerability, and specific details are not limited here. Not rating the first vulnerability does not affect the implementation of other steps.
[0256] In this embodiment, after the management device rates the first vulnerability as a level-two vulnerability, the management device may further send a level-two vulnerability prompt message to the first device. The level-two vulnerability prompt message is used to remind the user that the first vulnerability has been successfully exploited by the attacking device and the first vulnerability has extremely high risk.
[0257] Optionally, the management device may send a prompt message to the first device or may not send a prompt message to the first device, and specific details are not limited here. The management device not sending a prompt message to the first device does not affect the execution of other steps.
[0258] The management device obtains the five-tuple information of the target session according to the packet.
[0259] In this embodiment, the step of the management device obtaining the five-tuple information of the target session according to the packet is similar to step 3003 of the foregoing embodiment, and specific details are not elaborated here.
[0260] 6005. The management device generates an entry containing the five-tuple information and adds the generated entry to the access control list.
[0261] In this embodiment, this step is similar to step 3004 of the foregoing embodiment, and specific details are not elaborated here.
[0262] 6006. The management device sends a blocking policy to the gateway device.
[0263] In this embodiment, this step is similar to step 3005 of the foregoing embodiment, and specific details are not elaborated here.
[0264] Such as Figure 6As shown in the figure, in an embodiment of the vulnerability management system provided by the embodiments of the present application, the vulnerability management system includes: a management device, a gateway device, a first device, and a first cloud device.
[0265] Among them, the management device is integrated with a vulnerability scanning module, a monitoring module, an analysis module, a connection module, and a control response module.
[0266] The vulnerability scanning module obtains the vulnerability information of the first device. The vulnerability information of the first device can indicate that there is a first vulnerability in the first software. The first software communicates with other devices using a network protocol, and the first device is a network device managed by the management device.
[0267] The analysis module instructs the connection module to obtain a packet capture rule from the first cloud device according to the vulnerability information of the first device. The packet capture rule is used to identify packets at risk of having the first vulnerability.
[0268] The analysis module instructs the monitoring module to send the packet capture rule to the gateway device related to the first device. The gateway device is used to forward the packets transmitted by the first device. The packet capture rule is used for the gateway device to intercept the packets of the target session transmitted by the first device. The target session contains packets at risk of having the first vulnerability.
[0269] The monitoring module receives the packets of the target session transmitted by the first device sent by the gateway device.
[0270] The analysis module determines the threat level of the first vulnerability according to the packets of the target session transmitted by the first device, and determines whether to send a blocking policy to the gateway device according to the threat level.
[0271] As Figure 7 shown, an embodiment of the management device 30 provided by the embodiments of the present application includes:
[0272] The processing unit 301 is used for:
[0273] Obtain the vulnerability information of the first device. The vulnerability information of the first device is used to indicate that there is a first vulnerability in the first software. The first software communicates with other devices using a network protocol, and the first device is a network device managed by the management device;
[0274] Obtain a packet capture rule according to the vulnerability information of the first device. The packet capture rule is used to identify packets at risk of having the first vulnerability;
[0275] The sending unit 302 is used to send the packet capture rule to the gateway device related to the first device, and instruct that the implementation object of the packet capture rule is the first device. The gateway device is used to forward the packets transmitted by the first device. The packet capture rule is used for the gateway device to intercept the packets of the target session. The target session contains packets at risk of having the first vulnerability.
[0276] A receiving unit 303, configured to receive packets of a target session transmitted by the first device sent by the gateway device;
[0277] The processing unit is further configured to determine the threat level of the first vulnerability according to the packets of the target session transmitted by the first device, and determine whether to send a blocking policy to the gateway device according to the threat level.
[0278] In the solution provided by the embodiment of the present application, the processing unit 301 first issues a targeted packet capture rule to the gateway device according to the vulnerability information related to the first device, and the receiving unit 303 receives the packets of the target session transmitted by the first device captured by the gateway device according to the packet capture rule. The processing unit determines the threat level of the first vulnerability according to the packets of the target session transmitted by the first device, and then determines whether to send a blocking policy to the gateway device according to the threat level. When the first vulnerability is not threatening, the blocking policy is not sent to avoid affecting the normal services on the first device due to the blocking policy; when the first vulnerability is threatening, the blocking policy is sent to timely reduce the harm of the first vulnerability and reduce the probability of security incidents.
[0279] In a possible embodiment, the packets having the risk of the first vulnerability include a specified port number and a protocol type, and the processing unit 301 is configured to,
[0280] According to the correspondence relationship between the vulnerability exploitation request packet corresponding to the first vulnerability and the vulnerability exploitation response packet corresponding to the first vulnerability included in the first vulnerability database, determine whether there are sequentially appearing the vulnerability exploitation request packet corresponding to the first vulnerability and the vulnerability exploitation response packet corresponding to the first vulnerability in the packets of the target session transmitted by the first device;
[0281] If there are no sequentially appearing the vulnerability exploitation request packet corresponding to the first vulnerability and the vulnerability exploitation response packet corresponding to the first vulnerability in the packets of the target session transmitted by the first device, the sending unit 302 does not send the blocking policy to the gateway device;
[0282] If there are sequentially appearing the vulnerability exploitation request packet corresponding to the first vulnerability and the vulnerability exploitation response packet corresponding to the first vulnerability in the packets of the target session transmitted by the first device, the sending unit 302 sends the blocking policy to the gateway device.
[0283] In a possible embodiment, the packets having the risk of the first vulnerability include a specified port number and a protocol type, and the processing unit 301 is configured to,
[0284] Determine whether there are, in the packets of the target session transmitted by the first device, the exploit request packet corresponding to the first vulnerability and the exploit response packet corresponding to the first vulnerability that appear in sequence, according to the correspondence between the exploit request packet corresponding to the first vulnerability and the exploit response packet corresponding to the first vulnerability included in the first vulnerability database;
[0285] If there are no, in the packets of the target session transmitted by the first device, the exploit request packet corresponding to the first vulnerability and the exploit response packet corresponding to the first vulnerability that appear in sequence, the sending unit 302 does not send a blocking policy to the gateway device;
[0286] If there are, in the packets of the target session transmitted by the first device, the exploit request packet corresponding to the first vulnerability and the exploit response packet corresponding to the first vulnerability that appear in sequence, the sending unit 302 determines whether the packets of the target session transmitted by the first device include abnormal data;
[0287] If the packets of the target session transmitted by the first device further include the abnormal data, the sending unit sends a blocking policy to the gateway device.
[0288] In a possible embodiment, the packet with the risk of the first vulnerability includes the exploit request packet corresponding to the first vulnerability, and the processing unit 301 is configured to,
[0289] Determine whether the packets of the target session transmitted by the first device further contain the exploit response packet corresponding to the first vulnerability, according to the correspondence between the exploit request packet corresponding to the first vulnerability and the exploit response packet corresponding to the first vulnerability included in the first vulnerability database;
[0290] If the packets of the target session transmitted by the first device do not contain the exploit response packet corresponding to the first vulnerability, the sending unit 302 does not send a blocking policy to the gateway device;
[0291] If the packets of the target session transmitted by the first device contain the exploit response packet corresponding to the first vulnerability, the sending unit 302 sends a blocking policy to the gateway device.
[0292] In a possible embodiment, the packet with the risk of the first vulnerability includes the exploit request packet corresponding to the first vulnerability, and the processing unit is configured to,
[0293] Determine whether the packets of the target session transmitted by the first device further contain the exploit response packet corresponding to the first vulnerability, according to the correspondence between the exploit request packet corresponding to the first vulnerability and the exploit response packet corresponding to the first vulnerability included in the first vulnerability database;
[0294] If there is no exploit response packet corresponding to the first vulnerability in the packets of the target session transmitted by the first device, the sending unit 302 does not send a blocking policy to the gateway device;
[0295] If there is an exploit response packet corresponding to the first vulnerability in the packets of the target session transmitted by the first device, the management device determines whether the abnormal data is included in the packets of the target session transmitted by the first device;
[0296] If the abnormal data is further included in the packets of the target session transmitted by the first device, the sending unit 302 sends a blocking policy to the gateway device.
[0297] In a possible embodiment, the vulnerability information of the first device includes the identification information of the first vulnerability, and the processing unit 301 is configured to obtain the packet capture rule corresponding to the first vulnerability from the local rule library according to the identification information of the first vulnerability. The local rule library includes the identification information of the first vulnerability and the corresponding packet capture rule.
[0298] In a possible embodiment, the vulnerability information of the first device includes the identification information of the first vulnerability, and the sending unit 302 is configured to send the identification information of the first vulnerability to the first cloud device. The identification information of the first vulnerability is used for the first cloud device to obtain the packet capture rule corresponding to the first vulnerability from the cloud rule library. The cloud rule library includes the identification information of the first vulnerability and the corresponding packet capture rule;
[0299] The receiving unit 303 is configured to receive the packet capture rule corresponding to the first vulnerability sent by the first cloud device.
[0300] In a possible embodiment, the sending unit 302 is configured to send a probe packet to the first device;
[0301] The receiving unit 303 is configured to obtain the response packet returned by the first device for the probe packet. The response packet includes the risk of the first vulnerability;
[0302] The processing unit 301 obtains the vulnerability information corresponding to the response packet from the second vulnerability library according to the response packet, so as to determine the vulnerability information of the first device. The second vulnerability library includes the correspondence between the response packet and the vulnerability information.
[0303] In a possible embodiment, the sending unit 302 is configured to send a first software information acquisition instruction to the network management system. The first software information acquisition instruction is used to instruct the network management system to acquire the software information of the software installed on the first device;
[0304] The receiving unit 303 is configured to receive the software information returned by the network management system according to the first software information acquisition instruction;
[0305] The sending unit 302 is configured to send the software information to a second cloud device, so that the second cloud device obtains associated vulnerability information according to the software information and a third vulnerability database, where the third vulnerability database includes the association relationship between the software information and the vulnerability information;
[0306] The receiving unit 303 is configured to receive the associated vulnerability information sent by the second cloud device, so that the processing unit 301 determines the vulnerability information of the first device.
[0307] In a possible embodiment, the sending unit 302 is configured to send a second software information acquisition instruction to the first device, and the second software information acquisition instruction is used to instruct the first device to acquire the software information of the software installed on the first device;
[0308] The receiving unit 303 is configured to receive the software information returned by the first device according to the second software information acquisition instruction;
[0309] The sending unit 302 is configured to send the software information to a second cloud device, so that the second cloud device obtains associated vulnerability information according to the software information and a third vulnerability database, where the third vulnerability database includes the association relationship between the first software information and the vulnerability information;
[0310] The receiving unit 303 is configured to receive the associated vulnerability information sent by the second cloud device, so that the processing unit 301 determines the vulnerability information of the first device.
[0311] In a possible embodiment, the processing unit 301 is further configured to,
[0312] Obtain five-tuple information of a target session according to a packet of the target session transmitted by the first device, where the five-tuple information includes the IP address of an attacking device, the port number of the attacking device, the type of transmission protocol between the attacking device and the first device, the IP address of the first device, and the port number of the first device;
[0313] Generate an entry including the five-tuple information, and add the generated entry to an access control list, where the access control list is used to block the traffic indicated by the entry included in the access control list.
[0314] It should be noted that, regarding the information interaction, execution process, etc. among the various modules of the above management device 30, since they are based on the same concept as the method embodiment of the present application, the technical effects brought by them are the same as those of the method embodiment of the present invention. For specific content, reference can be made to the description in the method embodiment shown above in the present application, and details will not be repeated here.
[0315] As Figure 8 shown, an embodiment of the gateway device 40 provided by the embodiment of the present application includes:
[0316] A receiving unit 401, configured to receive a packet capture rule sent by a management device and an indication that the implementation object of the packet capture rule is a first device. A sending unit 403 is configured to forward a packet transmitted by the first device. The packet capture rule is used for a processing unit 402 to intercept packets of a target session, and the target session includes packets with a risk of a first vulnerability. The first vulnerability exists in a first software on the first device, and the first software uses a first protocol for network communication;
[0317] A processing unit 402, configured to intercept, according to the packet capture rule and the indication, packets of the target session transmitted by the first device, where the target session includes packets with a risk of the first vulnerability;
[0318] A sending unit 403, configured to send packets of the target session transmitted by the first device to the management device, and the packets of the target session transmitted by the first device are used for the management device to determine whether to send a blocking policy.
[0319] In the embodiment of the present application, the receiving unit 401 receives a packet capture rule sent by a management device, the processing unit 402 intercepts packets of the target session transmitted by the first device according to the packet capture rule, and the sending unit 403 sends the intercepted packets of the target session transmitted by the first device to the management device, so that the management device does not send a blocking policy when the first vulnerability is not threatening, and avoids affecting normal services on the first device due to the blocking policy. When the first vulnerability is threatening, a blocking policy is sent in a timely manner to reduce the harm of the first vulnerability and reduce the probability of occurrence of security incidents.
[0320] In a possible embodiment, the packets with a risk of the first vulnerability include packets with a specified port number and protocol type, or include a vulnerability exploitation request packet corresponding to the first vulnerability, and the vulnerability exploitation request packet corresponding to the first vulnerability is identified by a specified string.
[0321] In a possible embodiment, the receiving unit 401 is further configured to receive a blocking policy sent by the management device;
[0322] The processing unit is further configured to block the target session of the first device according to the blocking policy.
[0323] Obtain an entry including five-tuple information according to the access control list, where the five-tuple information includes the IP address of the attacking device, the port number of the attacking device, the type of transmission protocol between the attacking device and the first device, the IP address of the first device, and the port number of the first device;
[0324] Block the traffic indicated by the entry.
[0325] It should be noted that for the information interaction, execution process, etc. between the modules of the above gateway device 40, since they are based on the same concept as the method embodiment of the present application, the technical effects brought by them are the same as those of the method embodiment of the present invention. For the specific content, please refer to the description in the method embodiment shown above in the present application, and details will not be repeated here.
[0326] As Figure 9 shown, it is a schematic structural diagram of another device in the embodiment of the present application, and this device is a management device.
[0327] Figure 9 It is a schematic structural diagram of a management device provided by an embodiment of the present application. The management device 500 may include one or more processors (central processing units, CPU) 501 and a memory 502, and one or more operating systems and / or program codes are stored in the memory 502.
[0328] Among them, the memory 502 may be volatile storage or persistent storage. The program stored in the memory 502 may include one or more modules, and each module may include a series of instruction operations on the management device. Further, the processor 501 may be configured to communicate with the memory 502 and execute a series of instruction operations in the memory 502 on the management device 500.
[0329] The management device 500 may further include one or more power supplies, one or more wired or wireless network interfaces 503, one or more input / output interfaces 504. The input / output interface 504 is connected to an output device such as a display 505, and one or more operating systems, such as Windows ServerTM, Mac OS XTM, UnixTM, LinuxTM, FreeBSDTM, etc.
[0330] The processor 501 may execute the operations performed by the management device in the foregoing Figure 7 shown embodiment, and details will not be repeated here.
[0331] In some embodiments, the processor 501 of the management device may execute Figure 7The actions performed by the middle processing unit 301, and the network interface 503 in the management device can perform Figure 7 The actions performed by the sending unit 302 and the receiving unit 303 in the middle, and their implementation principles and technical effects are similar, so they will not be elaborated here.
[0332] Such as Figure 10 As shown, it is a schematic structural diagram of another device according to an embodiment of the present application, and this device is a gateway device. The gateway device 600 may include one or more central processing units (CPUs) 601 and a memory 605, and one or more application programs or data are stored in the memory 605.
[0333] Among them, the memory 605 may be volatile storage or persistent storage. The program stored in the memory 605 may include one or more modules, and each module may include a series of instruction operations on the gateway device. Further, the central processor 601 may be set to communicate with the memory 605 and execute a series of instruction operations in the memory 605 on the gateway device 600.
[0334] The gateway device 600 may further include one or more power supplies 602, one or more wired or wireless network interfaces 603, one or more input / output interfaces 604, and / or one or more operating systems, such as Windows ServerTM, Mac OS XTM, UnixTM, LinuxTM, FreeBSDTM, etc.
[0335] In some embodiments, the central processor 601 of the gateway device may execute Figure 8 The actions performed by the middle processing unit 402, and the wired or wireless network interface 603 or the input / output interface 604 in the gateway device can perform Figure 8 The actions performed by the receiving unit 401 and the sending unit 403 in the middle, and their implementation principles and technical effects are similar, so they will not be elaborated here.
[0336] The present application also provides a vulnerability processing system, which includes a processor for supporting the above-mentioned management device to implement the functions it involves, for example, receiving or processing the data involved in the above method embodiments. In a possible design, the vulnerability processing system further includes a memory for storing the necessary program instructions and data of the management device. This vulnerability processing system may include chips and other discrete devices.
[0337] In another embodiment of the present application, a computer-readable storage medium is further provided. The computer-readable storage medium stores computer-executable instructions. When at least one processor of the device executes the computer-executable instructions, the device executes the above-mentioned Figures 2 to 5d method described in some of the embodiments.
[0338] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. A professional technician can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the embodiments of the present application.
[0339] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.
[0340] In several embodiments provided by the embodiments of the present application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed mutual coupling, direct coupling, or communication connection can be through some interfaces. The indirect coupling or communication connection of the devices or units can be in an electrical, mechanical, or other form.
[0341] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place, or they can be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0342] In addition, the functional units in each embodiment of the embodiments of the present application can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit.
[0343] When the above-mentioned functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the embodiments of the present application, in essence, or the part that contributes to the prior art, or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the embodiments of the present application. The foregoing storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard disks, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical discs.
[0344] As described above, the above is only the specific implementation manner of the embodiments of the present application, but the protection scope of the embodiments of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed in the embodiments of the present application can easily think of changes or substitutions, which should all be covered within the protection scope of the embodiments of the present application. Therefore, the protection scope of the embodiments of the present application shall be subject to the protection scope of the claims.
Claims
1. A method for handling vulnerabilities, characterized in that Including: The management device obtains vulnerability information of the first device. The vulnerability information is used to indicate that there is a first vulnerability in the first software. The first software communicates with other devices using a network protocol. The first device is a network device managed by the management device. The management device obtains a packet capture rule according to the vulnerability information of the first device. The packet capture rule is used to identify packets at risk of having the first vulnerability. The packet capture rule includes a protocol type and a specified port number. The management device sends the packet capture rule to the gateway device related to the first device and indicates that the implementation object of the packet capture rule is the first device. The first device is an internal network device. The gateway device is used to forward packets transmitted between the first device and an external network device. The packet capture rule is used for the gateway device to intercept packets of a target session from the packets transmitted between the first device and the external network device. The target session contains packets at risk of having the first vulnerability. The management device receives the packets of the target session transmitted by the first device sent by the gateway device. The management device determines the threat level of the first vulnerability according to the packets of the target session transmitted by the first device.
2. The method according to claim 1, wherein After determining the threat level of the first vulnerability, it further includes: Determining whether to send a blocking policy to the gateway device according to the threat level of the first vulnerability.
3. The method according to claim 2, characterized in that, The determining whether to send a blocking policy to the gateway device according to the threat level of the first vulnerability includes: If the first vulnerability is not threatening, do not send the blocking policy to the gateway device, and If the first vulnerability is threatening, send the blocking policy to the gateway device.
4. The method for processing loopholes according to claim 2, characterized in that, The packets at risk of having the first vulnerability include packets with the specified port number and the protocol type. The management device determines the threat level of the first vulnerability according to the packets of the target session transmitted by the first device, and determines whether to send a blocking policy to the gateway device according to the threat level of the first vulnerability, including: The management device determines whether there are sequentially occurring vulnerability exploitation request packets corresponding to the first vulnerability and vulnerability exploitation response packets corresponding to the first vulnerability in the packets of the target session transmitted by the first device according to the correspondence between the vulnerability exploitation request packets corresponding to the first vulnerability and the vulnerability exploitation response packets corresponding to the first vulnerability included in the first vulnerability library. If there are no sequentially occurring vulnerability exploitation request packets corresponding to the first vulnerability and vulnerability exploitation response packets corresponding to the first vulnerability in the packets of the target session transmitted by the first device, the management device does not send the blocking policy to the gateway device. If there are sequentially occurring vulnerability exploitation request packets corresponding to the first vulnerability and vulnerability exploitation response packets corresponding to the first vulnerability in the packets of the target session transmitted by the first device, the management device sends the blocking policy to the gateway device.
5. The method for handling loopholes according to claim 2, characterized in that, The packets with the risk of the first vulnerability include the packets with the specified port number and the protocol type. The management device determines the threat level of the first vulnerability based on the packets of the target session transmitted by the first device, and determines whether to send a blocking policy to the gateway device according to the threat level of the first vulnerability, including: The management device determines whether there are the vulnerability exploitation request packet corresponding to the first vulnerability and the vulnerability exploitation response packet corresponding to the first vulnerability that appear in sequence in the packets of the target session transmitted by the first device according to the correspondence between the vulnerability exploitation request packet corresponding to the first vulnerability and the vulnerability exploitation response packet corresponding to the first vulnerability included in the first vulnerability database; If there are no the vulnerability exploitation request packet corresponding to the first vulnerability and the vulnerability exploitation response packet corresponding to the first vulnerability that appear in sequence in the packets of the target session transmitted by the first device, the management device does not send a blocking policy to the gateway device; If there are the vulnerability exploitation request packet corresponding to the first vulnerability and the vulnerability exploitation response packet corresponding to the first vulnerability that appear in sequence in the packets of the target session transmitted by the first device, the management device determines whether the packets of the target session transmitted by the first device include abnormal data; If the packets of the target session transmitted by the first device also include the abnormal data, the management device sends a blocking policy to the gateway device.
6. The method for processing a vulnerability according to any one of claims 1 to 5, characterized in that, The management device obtains the vulnerability information of the first device including: The management device sends a detection packet to the first device; The management device obtains the response packet returned by the first device for the detection packet, and the response packet includes the risk of the first vulnerability; The management device obtains the vulnerability information corresponding to the response packet from the second vulnerability database according to the response packet, so as to determine the vulnerability information of the first device, and the correspondence between the response packet and the vulnerability information is included in the second vulnerability database.
7. The method for handling a vulnerability according to any one of claims 1 to 5, characterized in that, The management device obtains the vulnerability information of the first device including: The management device sends a first software information acquisition instruction to the network management system, and the first software information acquisition instruction is used to instruct the network management system to acquire the software information of the software installed on the first device; The management device receives the software information returned by the network management system according to the first software information acquisition instruction; The management device sends the software information to the second cloud device, so that the second cloud device obtains the associated vulnerability information according to the software information and the third vulnerability database, and the association relationship between the software information and the vulnerability information is included in the third vulnerability database; The management device receives the associated vulnerability information sent by the second cloud device, so as to determine the vulnerability information of the first device.
8. The method for processing a vulnerability according to any one of claims 1 to 5, characterized in that, The management device obtains the vulnerability information of the first device including: The management device sends a second software information acquisition instruction to the first device, and the second software information acquisition instruction is used to instruct the first device to acquire the software information of the software installed on the first device; The management device receives the software information returned by the first device according to the second software information acquisition instruction; The management device sends the software information to a second cloud device, so that the second cloud device obtains associated vulnerability information according to the software information and a third vulnerability database, where the third vulnerability database includes the association relationship between the first software information and the vulnerability information; The management device receives the associated vulnerability information sent by the second cloud device, and thus determines the vulnerability information of the first device.
9. The method for processing a vulnerability according to any one of claims 2 to 5, characterized in that If the blocking policy is an access control list, before the management device sends the blocking policy to the gateway device, it further includes: The management device obtains the five-tuple information of the target session according to the packet of the target session transmitted by the first device, where the five-tuple information includes the Internet Protocol (IP) address of the attacking device's network interconnection, the port number of the attacking device, the transmission protocol type between the attacking device and the first device, the IP address of the first device, and the port number of the first device; The management device generates an entry containing the five-tuple information and adds the generated entry to the access control list, where the access control list is used to block the traffic indicated by the entries included in the access control list.
10. A method for handling vulnerabilities, characterized in that, It includes: The management device obtains the vulnerability information of a first device, where the vulnerability information is used to indicate that a first vulnerability exists in a first software, and the first software uses a network protocol to communicate with other devices, and the first device is a network device managed by the management device; The management device obtains a packet capture rule according to the vulnerability information of the first device, where the packet capture rule is used to identify packets at risk of having the first vulnerability, and the packet capture rule includes a specified string; The management device sends the packet capture rule to the gateway device associated with the first device and indicates that the implementation object of the packet capture rule is the first device. The first device is an internal network device, and the gateway device is used to forward the packets transmitted between the first device and an external network device. The packet capture rule is used for the gateway device to intercept the packets of the target session from the packets transmitted between the first device and the external network device, and the target session contains packets at risk of having the first vulnerability; The management device receives the packets of the target session transmitted by the first device sent by the gateway device; The management device determines the threat level of the first vulnerability according to the packets of the target session transmitted by the first device.
11. A method for handling vulnerabilities, characterized in that, It includes: The gateway device receives the packet capture rule sent by the management device and the indication that the implementation object of the packet capture rule is the first device. The first device is an internal network device, and the gateway device is used to forward the packets transmitted between the first device and an external network device. The packet capture rule is used for the gateway device to intercept the packets of the target session from the packets transmitted between the first device and the external network device, and the target session contains packets at risk of having a first vulnerability. The packet capture rule includes a protocol type and a specified port number, or the packet capture rule includes a specified string. The first vulnerability exists in the first software on the first device, and the first software uses a first protocol for network communication; The gateway device intercepts the packets of the target session transmitted by the first device from the packets transmitted between the first device and the external network device according to the packet capture rule and the instruction, and the packets of the target session contain the packets at risk of the first vulnerability; The gateway device sends the packets of the target session transmitted by the first device to the management device, and the packets of the target session transmitted by the first device are used for the management device to determine whether to send a blocking policy.
12. The method for processing a vulnerability according to claim 11, wherein The packets at risk of the first vulnerability include packets with a specified port number and protocol type, or include the vulnerability exploitation request packets corresponding to the first vulnerability, and the vulnerability exploitation request packets corresponding to the first vulnerability are identified by a specified string.
13. The method for processing a vulnerability according to any one of claims 11 to 12, characterized in that, After the gateway device sends the packets of the target session transmitted by the first device to the management device, it further includes: The gateway device receives the blocking policy sent by the management device; The gateway device blocks the target session of the first device according to the blocking policy.
14. The method for processing a vulnerability according to claim 13, wherein The blocking policy is an access control list, and the gateway device blocking the target session of the first device according to the blocking policy includes: The gateway device obtains an entry including five-tuple information according to the access control list, and the five-tuple information includes the IP address of the attacking device, the port number of the attacking device, the transmission protocol type between the attacking device and the first device, the IP address of the first device, and the port number of the first device; The gateway device blocks the traffic indicated by the entry.
15. A management device, characterized in that, It includes: A processing unit, configured to obtain vulnerability information of a first device, where the vulnerability information is used to indicate that a first vulnerability exists in a first software, the first software communicates with other devices using a network protocol, and the first device is a network device managed by the management device; obtain a packet capture rule according to the vulnerability information of the first device, where the packet capture rule is used to identify packets at risk of the first vulnerability, and the packet capture rule includes a protocol type and a specified port number; A sending unit, configured to send the packet capture rule to a gateway device related to the first device, and instruct that the implementation object of the packet capture rule is the first device, the first device is an internal network device, the gateway device is used to forward packets transmitted between the first device and the external network device, and the packet capture rule is used for the gateway device to intercept packets of a target session from the packets transmitted between the first device and the external network device, and the target session contains packets at risk of the first vulnerability; A receiving unit, configured to receive the packets of the target session transmitted by the first device sent by the gateway device; The processing unit is further configured to determine the threat level of the first vulnerability according to the packets of the target session transmitted by the first device.
16. A gateway device, characterized in that, It includes: A receiving unit, configured to receive a packet capture rule sent by a management device and an indication that the object to which the packet capture rule applies is a first device, where the first device is an internal network device, and a gateway device is configured to forward packets transmitted between the first device and an external network device, and the packet capture rule is used for the gateway device to intercept packets of a target session from the packets transmitted between the first device and the external network device, and the target session includes packets with a risk of a first vulnerability, and the packet capture rule includes a protocol type and a specified port number, or the packet capture rule includes a specified string. The first vulnerability exists in a first software on the first device, and the first software uses a first protocol for network communication. A processing unit, configured to intercept, according to the packet capture rule and the indication, packets of the target session transmitted by the first device from the packets transmitted between the first device and the external network device, where the target session includes packets with a risk of the first vulnerability. A sending unit, configured to send the packets of the target session transmitted by the first device to the management device, and the packets of the target session transmitted by the first device are used for the management device to determine whether to send a blocking policy.
17. A management device, characterized in that, Comprising: A processor, a memory, a bus, and an input / output interface; The processor is connected to the memory and the input / output interface; The bus is respectively connected to the processor, the memory, and the input / output interface; The processor executes the method according to any one of claims 1 to 10.
18. A gateway device, characterized in that, Comprising: A processor, a memory, a bus, and an input / output interface; The processor is connected to the memory and the input / output interface; The bus is respectively connected to the processor, the memory, and the input / output interface; The processor executes the method according to any one of claims 11 to 14.
19. A computer storage medium, characterized in that, Instructions are stored in the computer storage medium, and when the instructions are executed on a computer, the computer is caused to execute the method according to any one of claims 1 to 14.
20. A vulnerability processing system, characterized in that, Comprising: A management device, a gateway device, at least one internal network device, and at least one external network device, where the management device is the management device according to claim 15 or 17, and the gateway device is the gateway device according to claim 16 or 18.
Citation Information
Patent Citations
Vulnerability severity level distribution statistical method based on manufacturers, device and system
CN105635121A
Penetration test framework suitable for industrial control system
CN108809951A