Method and apparatus for acquiring internet exposure surface of local area network

By identifying traffic at the local area network boundary and utilizing passive asset traffic discovery technology and accessibility overlay terminal security open service analysis, the Internet exposure surface is obtained, solving the problem of network resource consumption by vulnerability scanning technology and achieving burden-free acquisition of Internet exposure surface.

CN116015835BActive Publication Date: 2026-05-29BEIJING TOPSEC NETWORK SECURITY TECH +2

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
BEIJING TOPSEC NETWORK SECURITY TECH
Filing Date
2022-12-21
Publication Date
2026-05-29

AI Technical Summary

Technical Problem

Existing technologies require the use of leak detection techniques when probing the internet exposure surface of a local area network, which increases network resource consumption and network burden.

Method used

By identifying traffic at the local area network boundary, and combining passive asset traffic discovery technology with accessibility overlay terminal security open service analysis, information on exposed surfaces and potential risk exposure surfaces can be obtained without using vulnerability scanning technology.

Benefits of technology

It enables the determination of the internet exposure surface without consuming network resources, thus solving the problem of network burden.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116015835B_ABST
    Figure CN116015835B_ABST
Patent Text Reader

Abstract

The embodiment of the application provides a kind of local area network internet exposure surface acquisition method and device, it is related to network security technical field.The method comprises identifying traffic at local area network boundary, obtains exposed surface information;Potential risk exposure surface information is obtained based on boundary access control information and local area network boundary NAT information;Internet exposure surface information is obtained based on the exposed surface information and the potential risk exposure surface information.The method can determine internet exposure surface without using leak scanning technology, solve the problem that using leak scanning technology will occupy network resources and increase network burden.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technology, and more specifically, to a method and apparatus for obtaining the Internet exposure surface of a local area network. Background Technology

[0002] With the increasing prevalence of cyberattacks, most networks have implemented relevant network protection measures. Before launching an attack, attackers typically probe the internet exposure surface of a local area network (LAN) to target that surface. Therefore, obtaining internet exposure surface information allows security personnel to effectively protect against attacks. Currently, vulnerability scanning techniques are commonly used to probe the internet exposure surface of LANs. However, many LANs detect and block vulnerability scanning, rendering it unusable. Furthermore, this method consumes network resources, increasing network overhead. Summary of the Invention

[0003] The purpose of this application is to provide a method and apparatus for obtaining the Internet exposure surface of a local area network, which can determine the Internet exposure surface without using the missed scan technique, thus solving the problem that using the missed scan technique will occupy network resources and increase the network burden.

[0004] This application provides a method for obtaining the Internet exposure surface of a local area network (LAN), the method comprising:

[0005] Traffic is identified at the local area network boundary to obtain information about the exposed surface;

[0006] Information on potential risk exposure surfaces is obtained based on boundary access control information and LAN boundary NAT information.

[0007] Internet exposure information is obtained based on the already exposed surface information and the potential risk exposure surface information.

[0008] In the above implementation process, the Internet exposure surface consists of potential risk exposure surface and exposed surface. The exposed surface can be determined by analyzing traffic through passive asset traffic discovery technology; the potential risk exposure surface can be obtained by overlaying the accessibility and terminal security open service analysis method. The Internet exposure surface can be determined without the use of leak scanning technology, which solves the problem that using leak scanning technology will occupy network resources and increase the network burden.

[0009] Furthermore, the step of identifying traffic at the local area network boundary to obtain exposed surface information includes:

[0010] If the traffic is non-TCP traffic and is external network access to internal network traffic, then obtain the internal network IP and destination port number;

[0011] Set the non-TCP traffic packets in the pre-established exposed surface information table to 1.

[0012] In the above implementation process, the exposed surface refers to the open services that have already engaged in traffic communication. It can identify non-TCP traffic initiated from the external network and mark it in a pre-established exposed surface information table.

[0013] Furthermore, the step of identifying traffic at the local area network boundary to obtain exposed surface information includes:

[0014] If the traffic is non-TCP traffic and is not external network access to internal network traffic, determine whether the non-TCP traffic packet flag bit in the exposed surface information table corresponding to the internal network IP is 1;

[0015] If so, set the confirmed exposure flag in the exposed face information table to 1.

[0016] In the above implementation process, it can be determined whether communication with the local area network IP has been completed, and then whether it has been exposed. If exposed, it is marked in the exposed surface information table.

[0017] Furthermore, the step of identifying traffic at the local area network boundary to obtain exposed surface information includes:

[0018] If the traffic is TCP traffic, then determine whether the TCP traffic has completed the three-way handshake;

[0019] If so, obtain the internal IP address and destination port number of the TCP traffic;

[0020] Set the confirmed exposure flag in the pre-established exposed surface information table to 1.

[0021] In the above implementation process, if the three-way handshake is completed, it means that communication with the IP in the local area network has been completed, and it can be marked in the exposed surface information table.

[0022] Furthermore, the acquisition of potential risk exposure surface information based on boundary access control information and local area network boundary NAT information includes:

[0023] Obtain overlapping data of the boundary access control information and the local area network boundary NAT information;

[0024] Based on the overlapping data, obtain lateral movement accessibility information;

[0025] Potential risk exposure surface information is generated based on the overlapping data and the lateral movement accessibility information.

[0026] In the above implementation process, the potential risk exposure surface is determined by the method of superimposing lateral movement detection and boundary protection equipment accessibility with terminal security open service analysis.

[0027] Furthermore, the overlapping data obtained from acquiring boundary access control information and local area network boundary NAT information includes:

[0028] The first set of accessible internal network IPs and the first set of open service ports are obtained based on the access control set of the boundary security device.

[0029] Based on the NAT policy set at the LAN boundary, obtain the second set of accessible internal network IPs and the second set of open service ports;

[0030] Obtain the overlapping intranet IP data of the first accessible intranet IP set and the second accessible intranet IP set;

[0031] Obtain the overlapping data of open service ports of the first open service port set and the second open service port set.

[0032] In the above implementation process, the overlapping data of open service ports of the first open service port set and the second open service port set is obtained. This overlapping data contains all local area network IP addresses that can access the Internet and can also be accessed through NAT.

[0033] Further, obtaining lateral movement accessibility information based on the overlapping data includes:

[0034] Accessible internal network IPs are obtained based on the aforementioned internal network IP overlap data;

[0035] The set of accessible open service ports is obtained based on the open service port overlap data.

[0036] In the above implementation process, the set of IP addresses and the set of open services within the local area network that can be accessed are obtained through the internal network IP overlap data.

[0037] This application embodiment also provides a device for obtaining the Internet exposure surface of a local area network, the device comprising:

[0038] The exposed surface information acquisition module is used to identify traffic at the local area network boundary and obtain exposed surface information;

[0039] The potential risk exposure surface information acquisition module is used to acquire potential risk exposure surface information based on boundary access control information and local area network boundary NAT information;

[0040] The Internet exposure surface information acquisition module is used to acquire Internet exposure surface information based on the already exposed surface information and the potential risk exposure surface information.

[0041] In the above implementation process, the Internet exposure surface consists of potential risk exposure surface and exposed surface. The exposed surface can be determined by analyzing traffic through passive asset traffic discovery technology; the potential risk exposure surface can be obtained by overlaying the accessibility and terminal security open service analysis method. The Internet exposure surface can be determined without the use of leak scanning technology, which solves the problem that using leak scanning technology will occupy network resources and increase the network burden. Attached Figure Description

[0042] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments of this application will be briefly introduced below. It should be understood that the following drawings only show some embodiments of this application and should not be regarded as a limitation of the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.

[0043] Figure 1 A flowchart illustrating a method for obtaining the Internet exposure surface of a local area network (LAN) as provided in this application embodiment;

[0044] Figure 2 A flowchart for obtaining exposed surface information provided in this application embodiment;

[0045] Figure 3 A flowchart illustrating the non-TCP traffic packet marking process provided in this application embodiment;

[0046] Figure 4 A flowchart illustrating the marking of exposed surface information provided in this application embodiment;

[0047] Figure 5 A flowchart illustrating the TCP traffic identification process provided in this application embodiment;

[0048] Figure 6 A flowchart illustrating the process of obtaining potential risk exposure information as provided in this application embodiment;

[0049] Figure 7 A flowchart illustrating the generation of potential risk exposure surface information provided in this application embodiment;

[0050] Figure 8 A flowchart for obtaining overlapping data provided in an embodiment of this application;

[0051] Figure 9 A flowchart illustrating the process of obtaining lateral movement accessibility information provided in this application embodiment;

[0052] Figure 10 A structural block diagram of a local area network (LAN) Internet exposure surface acquisition device provided in this application embodiment;

[0053] Figure 11This is a structural block diagram of another local area network (LAN) Internet exposure surface acquisition device provided in an embodiment of this application.

[0054] icon:

[0055] 100 - Exposed surface information acquisition module; 110 - First non-TCP traffic identification module; 120 - Second non-TCP traffic identification module; 130 - TCP traffic identification module; 200 - Potential risk exposure surface information acquisition module; 210 - Overlapping data acquisition module; 220 - Laterally accessible information acquisition module; 230 - Potential risk exposure surface information generation module; 300 - Internet exposure surface information acquisition module. Detailed Implementation

[0056] The technical solutions in the embodiments of this application will now be described with reference to the accompanying drawings.

[0057] It should be noted that similar reference numerals and letters in the following figures indicate similar items; therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures. Furthermore, in the description of this application, terms such as "first," "second," etc., are used only to distinguish descriptions and should not be construed as indicating or implying relative importance.

[0058] Example 1

[0059] Please refer to Figure 1 , Figure 1 This document presents a flowchart illustrating a method for obtaining the Internet exposure surface of a local area network (LAN) according to an embodiment of this application. The Internet exposure surface consists of a potential risk exposure surface and an already exposed surface. The already exposed surface refers to publicly accessible services where traffic communication has already occurred. The exposure surface is determined by analyzing traffic using passive asset traffic discovery technology. For potential risk exposure surfaces, a method combining lateral movement detection and boundary protection device connectivity overlay with terminal security open service analysis is employed to determine them. The method specifically includes the following steps:

[0060] Step S100: Identify traffic at the local area network boundary to obtain exposed surface information;

[0061] Step S200: Obtain potential risk exposure surface information based on boundary access control information and LAN boundary NAT information;

[0062] Step S300: Obtain Internet exposure information based on the exposed surface information and the potential risk exposure surface information.

[0063] This method achieves the acquisition of the Internet exposure surface of a local area network by combining the accessibility overlay terminal security open service analysis method and passive asset traffic discovery technology. It solves the problems of not being able to acquire the Internet exposure surface in scenarios where vulnerability scanning technology cannot be used and network resource load is high, as well as the problem that using vulnerability scanning technology will consume network resources and increase network burden.

[0064] Specifically, a potential risk exposure information table and an exposed exposure information table are created in advance and initialized; entries in the exposed exposure information table are added according to the actual data flow, and the exposed exposure information table is confirmed according to the status of the data flow.

[0065] like Figure 2 The diagram shown is a flowchart for obtaining exposed surface information. Among other things, as... Figure 3 The diagram shown is a flowchart of the non-TCP traffic packet marking process. The implementation process of step S100 specifically includes the following steps:

[0066] Step S111: If the traffic is non-TCP traffic and is external network access to internal network traffic, then obtain the internal network IP and destination port number;

[0067] Step S112: Set the non-TCP traffic packets in the pre-established exposed surface information table to 1.

[0068] When creating the Potential Risk Exposure Surface Information Table and the Exposed Surface Information Table, the Potential Risk Exposure Surface Information Table entries include: IP address, destination port; the Exposed Surface Information Table entries include: IP address, destination port, TCP protocol flag, acknowledgment of exposure flag, non-TCP traffic packet flag, and all table entry elements are initialized to 0.

[0069] When obtaining exposed surface information, traffic information is recorded at the local area network boundary:

[0070] Identify non-TCP traffic originating from the external network, create an entry in the exposed surface information table, and record elements including IP address and destination port number. If the data packet corresponding to the current traffic is an Internet access to the local area network, then mark the corresponding non-TCP traffic packet as 1.

[0071] like Figure 4 The diagram shown is a flowchart of the process for marking exposed surface information. Specifically:

[0072] Step S121: If the traffic is non-TCP traffic and is not external network access to internal network traffic, determine whether the non-TCP traffic packet flag bit in the exposed surface information table corresponding to the internal network IP is 1;

[0073] Step S122: If yes, set the confirmed exposure flag in the exposed face information table to 1.

[0074] If the non-TCP traffic has a reverse packet return, it means that the non-TCP traffic has completed communication with the IP in the local area network, which means it belongs to the exposed surface information. The confirmed exposure flag in the exposed surface information table can be set to 1; otherwise, the flag is not set.

[0075] like Figure 5 The diagram shown is a flowchart of the TCP traffic identification process. Specifically:

[0076] Step S131: If the traffic is TCP traffic, determine whether the TCP traffic has completed the three-way handshake;

[0077] Step S132: If yes, then obtain the internal network IP and destination port number of the TCP traffic;

[0078] Step S133: Set the confirmed exposure flag in the pre-established exposed surface information table to 1.

[0079] Identify TCP traffic originating from the external network, create an entry in the exposed surface information table, and record elements including IP address and destination port number. If the TCP three-way handshake for the connection is completed, set the exposed flag of the entry to 1; otherwise, do not set the flag.

[0080] The above steps determine whether TCP / non-TCP traffic has completed communication with an IP address within the local area network, thus determining whether the target has been exposed. The exposed surface information table is then marked using the above method and recorded for a certain period of time until the exposed surface information table is complete.

[0081] The recording time can be set as needed. Theoretically, the longer the recording time, the more comprehensive the information on the exposed surfaces can be obtained.

[0082] For potential risk exposure surfaces, the overlapping portion of boundary access control information and NAT information is identified. Based on this overlapping portion, lateral movement accessibility information is obtained through endpoint security information. The sum of the overlapping portion and the lateral movement accessibility information constitutes the potential risk exposure surface. Figure 6 The diagram shown is a flowchart for obtaining information on potential risk exposure surfaces.

[0083] Among them, such as Figure 7 The diagram shows the flowchart for generating potential risk exposure information. Step S200 specifically includes the following steps:

[0084] Step S210: Obtain overlapping data of the boundary access control information and the local area network boundary NAT information;

[0085] Step S220: Obtain lateral movement accessibility information based on the overlapping data;

[0086] Step S230: Generate potential risk exposure surface information based on the overlapping data and the lateral movement accessibility information.

[0087] like Figure 8 The diagram shown is a flowchart for acquiring overlapping data. The implementation process of step S210 may specifically include the following steps:

[0088] Step S211: Obtain the first set of accessible intranet IP addresses and the first set of open service ports based on the boundary security device access control set;

[0089] At the boundary, based on access control policies, determine the set of IP addresses α1 that can access the Internet within the local area network (LAN) and the set of open services β1. α1 is the first set of accessible internal network IP addresses, and β1 is the first set of open service ports. α1 contains the Internet-accessible IP addresses within the LAN, and β1 contains the open service ports within the LAN.

[0090] Step S212: Obtain the second set of accessible internal network IPs and the second set of open service ports based on the NAT policy set at the local area network boundary;

[0091] In the NAT policy boundary determination, the set of LAN IP addresses accessible to the Internet (α2) and the set of open services (β2) are defined. α2 is the second set of accessible LAN IP addresses, and β2 is the second set of open service ports. α2 contains LAN IP addresses accessible to the Internet via NAT, and β2 contains LAN service ports accessible to the Internet via NAT.

[0092] Step S213: Obtain the overlapping intranet IP data of the first accessible intranet IP set and the second accessible intranet IP set;

[0093] Obtain the overlapping portion α3 of α1 and α2. α3 represents the internal network IP overlap data. α3 contains all local area network (LAN) IP addresses that can access the internet and also be accessed via NAT.

[0094] Step S214: Obtain the open service port overlap data of the first open service port set and the second open service port set.

[0095] Obtain the overlapping portion β3 of β1 and β2; β3 represents the overlapping data of open service ports. β3 contains the ports within the local area network that are open to the Internet.

[0096] like Figure 9 The diagram shows the flowchart for obtaining information accessible by lateral movement. The implementation process of step S220 specifically includes the following steps:

[0097] Step S221: Obtain accessible internal network IPs based on the internal network IP overlap data;

[0098] Step S222: Obtain the set of accessible open service ports based on the open service port overlap data.

[0099] Based on the access control policy, obtain the set of IPs α4 and the set of open services β4 that are accessible within the local area network from the addresses in α3. α4 is the accessible internal network IP, and β4 is the set of open service ports.

[0100] α4 contains all the IP addresses within the local area network that can be accessed by α3, and β4 contains all the service ports within the local area network that can be accessed by the addresses in α3.

[0101] The sum of α3 and β3, and α4 and β4, represents the potential risk exposure surface information. The sum of the potential risk exposure surface information and the already exposed surface information equals the local area network (LAN) exposure surface information.

[0102] This method obtains the Internet exposure surface of a local area network by combining accessibility overlay terminal security open service analysis and passive asset traffic discovery technology, without the need for vulnerability scanning technology, thus avoiding the problem of consuming network resources and increasing network burden.

[0103] Example 2

[0104] This application provides a device for obtaining the Internet exposure surface of a local area network (LAN), applied to the method for obtaining the Internet exposure surface of a LAN described in Embodiment 1, such as... Figure 10 The diagram shown is a structural block diagram of a local area network (LAN) Internet exposure surface acquisition device, which includes, but is not limited to:

[0105] The exposed surface information acquisition module 100 is used to identify traffic at the local area network boundary and obtain exposed surface information;

[0106] The potential risk exposure surface information acquisition module 200 is used to acquire potential risk exposure surface information based on boundary access control information and local area network boundary NAT information.

[0107] The Internet exposure surface information acquisition module 300 is used to acquire Internet exposure surface information based on the already exposed surface information and the potential risk exposure surface information.

[0108] like Figure 11 The diagram shown is a structural block diagram of another local area network (LAN) Internet exposure surface acquisition device. The exposed surface information acquisition module 100 includes a first non-TCP traffic identification module 110, used for:

[0109] If the traffic is non-TCP traffic and is external network access to internal network traffic, then obtain the internal network IP and destination port number;

[0110] Set the non-TCP traffic packets in the pre-established exposed surface information table to 1.

[0111] The exposed surface information acquisition module 100 also includes a second non-TCP traffic identification module 120, used to: if the traffic is non-TCP traffic and is not external network access to internal network traffic, determine whether the non-TCP traffic packet flag bit corresponding to the exposed surface information table of the internal network IP is 1;

[0112] If so, set the confirmed exposure flag in the exposed face information table to 1.

[0113] The exposed surface information acquisition module 100 also includes a TCP traffic identification module 130, used for:

[0114] If the traffic is TCP traffic, then determine whether the TCP traffic has completed the three-way handshake;

[0115] If so, obtain the internal IP address and destination port number of the TCP traffic;

[0116] Set the confirmed exposure flag in the pre-established exposed surface information table to 1.

[0117] The potential risk exposure information acquisition module 200 includes:

[0118] The overlapping data acquisition module 210 is used to acquire overlapping data of the boundary access control information and the local area network boundary NAT information.

[0119] The specific implementation process of the overlapping data acquisition module 210 is as follows:

[0120] The first set of accessible internal network IPs and the first set of open service ports are obtained based on the access control set of the boundary security device.

[0121] Based on the NAT policy set at the LAN boundary, obtain the second set of accessible internal network IPs and the second set of open service ports;

[0122] Obtain the overlapping intranet IP data of the first accessible intranet IP set and the second accessible intranet IP set;

[0123] Obtain the overlapping data of open service ports of the first open service port set and the second open service port set.

[0124] Lateral movement accessibility information acquisition module 220 is used to acquire lateral movement accessibility information based on the overlapping data;

[0125] The specific implementation process of the laterally movable accessible information acquisition module 220 is as follows:

[0126] Accessible internal network IPs are obtained based on the aforementioned internal network IP overlap data;

[0127] The set of accessible open service ports is obtained based on the open service port overlap data.

[0128] Potential risk exposure surface information generation module 230 is used to generate potential risk exposure surface information based on the overlapping data and the lateral movement accessibility information.

[0129] In this device, the exposed surface can be determined by analyzing traffic through passive asset traffic discovery technology; the potential risk exposure surface can be obtained by overlaying the accessibility and terminal security open service analysis method. The Internet exposure surface can be determined without the use of leak detection technology, which solves the problem that the use of leak detection technology will occupy network resources and increase the network burden.

[0130] This application also provides an electronic device, which includes a memory and a processor. The memory stores a computer program, and the processor runs the computer program to enable the electronic device to perform the method for obtaining the Internet exposure surface of a local area network as described in Embodiment 1.

[0131] This application also provides a readable storage medium storing computer program instructions. When the computer program instructions are read and executed by a processor, the method for obtaining the Internet exposure surface of a local area network as described in any one of Embodiment 1 is performed.

[0132] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can also be implemented in other ways. The apparatus embodiments described above are merely illustrative. For example, the flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of apparatus, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than those marked in the drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram and / or flowchart, and combinations of blocks in block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or action, or using a combination of dedicated hardware and computer instructions.

[0133] In addition, the functional modules in the various embodiments of this application can be integrated together to form an independent part, or each module can exist independently, or two or more modules can be integrated to form an independent part.

[0134] If the aforementioned functions are implemented as software functional modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0135] The above description is merely an embodiment of this application and is not intended to limit the scope of protection of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application. It should be noted that similar reference numerals and letters in the following figures indicate similar items; therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures.

[0136] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

[0137] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

Claims

1. A method for obtaining the Internet exposure surface of a local area network, characterized in that, The method includes: Traffic is identified at the local area network boundary to obtain information about the exposed surface; Obtaining potential risk exposure surface information based on boundary access control information and LAN boundary NAT information specifically includes: obtaining overlapping data of the boundary access control information and the LAN boundary NAT information; obtaining lateral mobility accessibility information based on the overlapping data; and generating potential risk exposure surface information based on the overlapping data and the lateral mobility accessibility information. Specifically, obtaining the overlapping data includes: obtaining a first set of accessible internal network IPs and a first set of open service ports based on the boundary security device access control set; obtaining a second set of accessible internal network IPs and a second set of open service ports based on the LAN boundary NAT policy set; obtaining overlapping data of internal network IPs of the first set of accessible internal network IPs and the second set of accessible internal network IPs; obtaining overlapping data of open service ports of the first set of open service ports and the second set of open service ports; obtaining lateral mobility accessibility information includes: obtaining accessible internal network IPs based on the overlapping internal network IP data; and obtaining a set of accessible open service ports based on the overlapping open service port data. Internet exposure information is obtained based on the already exposed surface information and the potential risk exposure surface information.

2. The method for obtaining the Internet exposure surface of a local area network according to claim 1, characterized in that, The process of identifying traffic at the local area network boundary to obtain exposed surface information includes: If the traffic is non-TCP traffic and is external network access to internal network traffic, then obtain the internal network IP and destination port number; Set the non-TCP traffic packets in the pre-established exposed surface information table to 1.

3. The method for obtaining the Internet exposure surface of a local area network according to claim 2, characterized in that, The process of identifying traffic at the local area network boundary to obtain exposed surface information includes: If the traffic is non-TCP traffic and is not external network access to internal network traffic, determine whether the non-TCP traffic packet flag bit in the exposed surface information table corresponding to the internal network IP is 1; If so, set the confirmed exposure flag in the exposed face information table to 1.

4. The method for obtaining the Internet exposure surface of a local area network according to claim 1, characterized in that, The process of identifying traffic at the local area network boundary to obtain exposed surface information includes: If the traffic is TCP traffic, then determine whether the TCP traffic has completed the three-way handshake; If so, obtain the internal IP address and destination port number of the TCP traffic; Set the confirmed exposure flag in the pre-established exposed surface information table to 1.

5. A device for obtaining the Internet exposure surface of a local area network, characterized in that, The device includes: The exposed surface information acquisition module is used to identify traffic at the local area network boundary and obtain exposed surface information; The potential risk exposure surface information acquisition module is used to acquire potential risk exposure surface information based on boundary access control information and local area network boundary NAT information. Specifically, it includes: acquiring overlapping data of the boundary access control information and the local area network boundary NAT information; acquiring lateral mobility accessibility information based on the overlapping data; and generating potential risk exposure surface information based on the overlapping data and the lateral mobility accessibility information. Acquiring the overlapping data includes: obtaining a first set of accessible internal network IPs and a first set of open service ports based on the boundary security device access control set; obtaining a second set of accessible internal network IPs and a second set of open service ports based on the local area network boundary NAT policy set; acquiring overlapping data of internal network IPs in the first and second accessible internal network IP sets; acquiring overlapping data of open service ports in the first and second open service port sets; and acquiring lateral mobility accessibility information includes: acquiring accessible internal network IPs based on the overlapping internal network IP data; and acquiring a set of accessible open service ports based on the overlapping open service port data. The Internet exposure surface information acquisition module is used to acquire Internet exposure surface information based on the already exposed surface information and the potential risk exposure surface information.

6. An electronic device, characterized in that, The electronic device includes a memory and a processor, the memory being used to store a computer program, and the processor running the computer program to cause the electronic device to perform the method for obtaining the Internet exposure surface of a local area network according to any one of claims 1 to 4.

7. A readable storage medium, characterized in that, The readable storage medium stores computer program instructions, which, when read and executed by a processor, perform the method for obtaining the Internet exposure surface of a local area network as described in any one of claims 1 to 4.