An automated penetration testing method, system, device, and storage medium based on an asynchronous processing algorithm for information flow

The information flow asynchronous processing algorithm enhances network security testing by enabling concurrent and cluster scanning, reducing scanning time and improving precision through adaptive thread management.

CN116155539BActive Publication Date: 2025-07-15JILIN PROVINCE JILIN XIANGYUN INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211555860.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-06
Publication Date
2025-07-15
Estimated Expiration
2042-12-06

AI Technical Summary

Technical Problem

The existing penetration testing system cannot perform concurrent and clustered scanning, resulting in slow scanning speed during large-scale network security inspections and the task cannot be completed quickly.

Method used

The automated penetration testing method based on the information flow asynchronous processing algorithm is adopted. The thread pool is initialized by the hardware and system initialization module, and the task scheduling module prioritizes the processing of high-risk ports. The asynchronous asset discovery, service discovery, vulnerability detection and verification modules independently handle the targets to achieve concurrent and cluster scanning.

Benefits of technology

Fast scanning of the same or multiple targets is achieved, improving scanning efficiency and accuracy, and shortening scanning time.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116155539B_ABST
    Figure CN116155539B_ABST
Patent Text Reader

Abstract

An automated penetration testing method, system, device, and storage medium based on an information flow asynchronous processing algorithm, belonging to the field of network security technology. By using the information flow asynchronous processing algorithm, an information flow asynchronous processing bus is implemented, changing the execution of penetration testing steps to parallel scanning, and realizing concurrent and cluster scanning of the same or multiple targets. The port scanning is decomposed into rapid port discovery and port service termination to achieve rapid asset discovery. The blocking penetration testing mode of scanning first and then verifying is changed to an asynchronous mode of concurrent scanning and concurrent verification that is independent of the order. Each scanning function module uses stateless encapsulation and is decoupled from the system, enabling multiple modules to automatically adjust the concurrency number of each module according to the actual situation of the scanning task, maximizing the scanning efficiency per unit time, greatly shortening the scanning time, and improving the scanning accuracy.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and particularly relates to an automated penetration testing method, system, device, and storage medium based on an information flow asynchronous processing algorithm. Background Art

[0002] At present, the penetration testing system in the field of network security detects the services of different ports of the target host TCP / IP remotely, and matches the responses of the target with the vulnerability library provided by the penetration testing system. If the matching conditions are met, it is regarded as the existence of a vulnerability. The mechanized vulnerability library matching of the existing penetration testing system is prone to a large number of false vulnerability reports. At the same time, there are strict working procedures, the penetration speed is slow, and it is impossible to perform concurrent and cluster scans on the same or multiple targets. When facing large-scale network security inspections, it is often impossible to quickly complete the scanning task.

[0003] Therefore, the defect of the existing technology is that since it is impossible to perform concurrent and cluster scans on the same or multiple targets, when facing large-scale network security inspections, it is often impossible to quickly complete the scanning task. Summary of the Invention

[0004] The present invention solves the problem that the existing technology often cannot quickly complete the scanning task when facing large-scale network security inspections because it is impossible to perform concurrent and cluster scans on the same or multiple targets.

[0005] An automated penetration testing method based on an information flow asynchronous processing algorithm according to the present invention includes the following steps:

[0006] Step S1, the hardware and system initialization module initializes the thread pools of each module according to the hardware configuration information, and each module registers the online status and thread pool parameters with the task scheduling module. The above-mentioned modules include an asynchronous asset rapid discovery module, an asynchronous service accurate discovery module, an asynchronous vulnerability detection module, and an asynchronous vulnerability verification module;

[0007] Step S2, after the task scheduling module receives the target address range input by the user and disassembles it into unit target addresses in units of IP + ports, it inputs them to the bus module. If the unit target addresses contain high-risk ports, the priorities of these unit target addresses are set to high;

[0008] Step S3, the task scheduling module obtains the information of the unit target addresses to be processed from the bus module according to the priorities of the unit target addresses and the workload conditions of each module, and distributes them to each module according to the types of the unit target addresses, and marks the status of the unit target addresses. Each module independently starts the corresponding threads to process the unit target addresses;

[0009] Step S4, the asynchronous vulnerability verification module monitors the requests of the detected target, decodes the ID information from the request data, injects the ID information back into the bus module. The asynchronous vulnerability detection module receives the ID information from the bus module, matches the specific vulnerability detection payloads, determines the vulnerability information, and then injects the vulnerability information back into the bus module;

[0010] Step S5, the vulnerability alert module obtains the vulnerability information from the bus module in real time, generates a vulnerability information briefing, sends it to the user's email address through the email system, and marks the warning status of the vulnerability information.

[0011] Further, in an embodiment of the present invention, the high-risk ports include 22, 80, 3306, and 3389.

[0012] An automated penetration testing system based on an information flow asynchronous processing algorithm according to the present invention is implemented by using an automated penetration testing method based on an information flow asynchronous processing algorithm described in any one of the above methods. The system includes a hardware and system initialization module, a task scheduling module, a bus module, an asynchronous asset rapid discovery module, an asynchronous service accurate discovery module, an asynchronous vulnerability detection module, an asynchronous vulnerability verification module, and a vulnerability alert module;

[0013] The hardware and system initialization module reads the hardware information, initializes the thread pools of each module according to the hardware performance data, and starts each module. The hardware and system initialization module starts the bus module according to the IP and port configuration of the bus module, writes the thread pool parameters of each module into the bus module, and the hardware and system initialization module writes the detected target range address into the bus module;

[0014] The task scheduling module reads the detected target range address from the bus module, disassembles it into the form of IP + port. If the port is high-risk, it is marked as a priority. The task scheduling module obtains the working status of the bus module every 3 seconds, and reads the thread pools and thread working status of each module. The task scheduling module adjusts the ratio of the number of running threads of each module every 60 seconds according to the degree of the unit target address queue to be processed in the bus module;

[0015] The bus module is used to implement the query and persistence of the running status and the number of threads of each module, the unit target address queue to be processed, and the vulnerability results, and constructs a bus interface service;

[0016] The asynchronous asset rapid discovery module queries and obtains the targets to be rapidly discovered from the bus module according to the number of its own idle threads, sends a SYN request to the target end to establish a connection, and updates the online status of the target to the bus module after receiving an ACK response within the waiting time;

[0017] The asynchronous service accurate discovery module queries and obtains the target to be served from the bus module according to its own number of idle threads, attempts to establish a connection with the target end. During the waiting time, it receives the Welcome Banner information sent by the target, compares it with the fingerprint database to determine the port service information, and updates the service information of the target to the bus module;

[0018] The asynchronous vulnerability detection module queries and obtains the target to be vulnerability detected from the bus module according to its own number of idle threads. According to the characteristic information of the target, it selects targeted vulnerability detection scripts and general vulnerability scripts. Before each penetration of the detection script, it applies for a penetration batch ID from the bus module. After binding the ID with the detection script, it sends the detection payload to the target to be penetrated. At the same time, during the waiting time, it queries the bus module whether the batch ID has been successfully penetrated and writes the successful detection result information to the bus module;

[0019] The asynchronous vulnerability verification module enables the listening service according to the configured listening information, generates an ID according to the length of the ID queue in the bus module and writes it into the bus module ID queue. In the listening service, it listens to and decodes the ID information received from the target to be detected and updates the penetration result of the ID to the bus module;

[0020] The vulnerability warning module periodically obtains the vulnerability result information from the bus module, embeds it into a preset report template, and sends the synthesized warning email according to the warning email address.

[0021] Further, in an embodiment of the present invention, the hardware information includes the number of CPU cores, the memory size, and the network card performance.

[0022] Further, in an embodiment of the present invention, the task scheduling module adjusts the ratio of the number of running threads of each functional module, specifically:

[0023] When the length of the target queue to be detected exceeds 50 each time, the number of threads of the asynchronous service accurate discovery module is reduced by 10%;

[0024] When the length of the target queue to be detected is 0, the number of threads of the asynchronous service accurate discovery module is increased by 10%;

[0025] When the length of the target queue discovered by the asynchronous service accurate discovery module exceeds 30 each time, the number of threads of the asynchronous asset rapid discovery module is reduced by 10%;

[0026] When the length of the target queue discovered by the asynchronous service accurate discovery module is 0, the number of threads of the asynchronous asset rapid discovery module is increased by 10%;

[0027] The number of threads of the asynchronous vulnerability verification module is fixed at 1.

[0028] Further, in an embodiment of the present invention, the monitoring service includes icmplog, tcplog, udplog, httplog, and dnslog.

[0029] Further, in an embodiment of the present invention, the bus module is used to implement the query and persistence of the operating states of each module, the thread pool, the queue of unit target addresses to be processed, and the vulnerability results based on redis;

[0030] The bus module constructs the bus interface service based on TCP and RSA algorithms.

[0031] An electronic device according to the present invention includes a processor, a communication interface, a memory, and a communication bus. Among them, the processor, the communication interface, and the memory complete mutual communication through the communication bus;

[0032] The memory is used to store a computer program;

[0033] The processor, when executing the program stored on the memory, implements the method steps described in any one of the above methods.

[0034] A computer-readable storage medium according to the present invention stores a computer program therein, and when the computer program is executed by a processor, it implements the method steps described in any one of the above methods.

[0035] The present invention solves the problem that in the prior art, due to the inability to perform concurrent and cluster scans on the same or multiple targets, it is often impossible to quickly complete the scan task when facing large-scale network security inspections. The specific beneficial effects include:

[0036] An automated penetration testing method based on an information flow asynchronous processing algorithm according to the present invention adopts the information flow asynchronous processing algorithm to implement an information flow asynchronous processing bus, changes the execution of penetration testing steps to concurrent scanning, and realizes concurrent and cluster scans on the same or multiple targets. The port scan is decomposed into fast port discovery and port service termination to achieve fast asset discovery. The blocking of the penetration testing mode from scanning first and then verifying is changed to an asynchronous mode of concurrent scanning and concurrent verification regardless of order. Each scanning function module adopts stateless encapsulation and decoupling from the system, and can automatically adjust the concurrency number of each module according to the actual situation of the scanning task, maximizing the scanning efficiency per unit time, greatly shortening the scanning time and improving the scanning accuracy. BRIEF DESCRIPTION OF THE DRAWINGS

[0037] The above and / or additional aspects and advantages of the present invention will become apparent and easy to understand from the following description of the embodiments in conjunction with the drawings, where:

[0038] Figure 1 It is a flowchart of an automated penetration testing method based on an information flow asynchronous processing algorithm described in the specific implementation manner.

[0039] Figure 2 It is a system diagram of an automated penetration testing system based on an information flow asynchronous processing algorithm described in the specific implementation manner. Specific implementation manner

[0040] The following will clearly and completely describe various implementation manners of the present invention with reference to the accompanying drawings. The embodiments described by referring to the accompanying drawings are exemplary and are intended to explain the present invention, and should not be construed as a limitation to the present invention.

[0041] An automated penetration testing method based on an information flow asynchronous processing algorithm described in this implementation manner includes the following steps:

[0042] Step S1, the hardware and system initialization module initializes the thread pools of each module according to the hardware configuration information, and each module registers its online status and thread pool parameters with the task scheduling module. The above-mentioned each module includes an asynchronous asset rapid discovery module, an asynchronous service accurate discovery module, an asynchronous vulnerability detection module, and an asynchronous vulnerability verification module;

[0043] Step S2, after the task scheduling module receives the target address range input by the user and disassembles it into unit target addresses in units of IP + port, it inputs them to the bus module. If the unit target address contains high-risk ports, the priorities of these unit target addresses are set to high;

[0044] Step S3, the task scheduling module obtains the information of the unit target addresses to be processed from the bus module according to the priorities of the unit target addresses and the workload of each module, and distributes them to each module according to the types of the unit target addresses, and marks the status of the unit target addresses. Each module independently starts the corresponding threads to process the unit target addresses;

[0045] Step S4, the asynchronous vulnerability verification module listens to the requests of the detected targets, decodes the ID information from the request data, and injects the ID information back into the bus module. The asynchronous vulnerability detection module system receives the ID information from the bus module, matches the specific vulnerability detection payloads to determine the vulnerability information, and then injects the vulnerability information back into the bus module;

[0046] Step S5, the vulnerability warning module obtains the vulnerability information from the bus module in real time, generates a vulnerability information brief, sends it to the user's email address through the email system, and marks the warning status of the vulnerability information.

[0047] In this implementation manner, the high-risk ports include 22, 80, 3306, and 3389.

[0048] This embodiment is based on an automated penetration testing method, system, device, and storage medium based on the information flow asynchronous processing algorithm described in the present invention. In combination with Figure 1 To better understand this embodiment, a practical embodiment is provided:

[0049] Step S1: The hardware and system initialization module initializes the thread pools of each functional module in a single machine or a cluster according to the hardware configuration information. Each functional module registers its online status and thread pool parameters with the task scheduling module;

[0050] Step S2: The task scheduling module receives the target address range input by the user, decomposes it into unit target addresses in units of IP + ports, and inputs them to the bus module. If the unit target addresses contain the TOP100 common high-risk ports such as 22, 80, 3306, and 3389, the processing priority of these unit target addresses is set to high;

[0051] Step S3: The task scheduling module obtains the target information to be processed from the bus module according to the target priority and the workload of each module, allocates it to functional modules such as asset information scanning and penetration testing according to the type of the unit target address, and marks the status of the unit target address. Each functional module independently starts the corresponding thread to process the unit target address;

[0052] Step S4: The asynchronous vulnerability verification module listens to the requests of the detected target host, decodes the ID information from the request data, and injects the ID information back into the bus module. The penetration testing system receives the ID information from the bus, matches the specific vulnerability detection payload, determines information such as the vulnerability name, and then injects the vulnerability information back into the bus module;

[0053] Step S5: The vulnerability warning module obtains the vulnerability information from the bus module in real time, generates a vulnerability information briefing, sends it to the user's email address through the email system, and marks the warning status of the vulnerability information.

[0054] An automated penetration testing system based on the information flow asynchronous processing algorithm described in this embodiment. The system is implemented by using an automated penetration testing method based on the information flow asynchronous processing algorithm described in the above embodiment. The system includes a hardware and system initialization module, a task scheduling module, a bus module, an asynchronous asset rapid discovery module, an asynchronous service accurate discovery module, an asynchronous vulnerability detection module, an asynchronous vulnerability verification module, and a vulnerability warning module;

[0055] The hardware and system initialization module reads hardware information, initializes the thread pools of each module according to the hardware performance data, and starts each module. The hardware and system initialization module starts the bus module according to the IP and port configuration of the bus module, writes the thread pool parameters of each module into the bus module, and writes the detected target range address into the bus module.

[0056] The task scheduling module reads the detected target range address from the bus module and disassembles it into the form of IP + ports. If the port is a high-risk port, it is marked as a priority. The task scheduling module obtains the working status of the bus module every 3 seconds and reads the thread pools and thread working status of each module. The task scheduling module adjusts the ratio of the number of running threads of each module every 60 seconds according to the degree of the unit target address queue to be processed in the bus module.

[0057] The bus module is used to implement the query and persistence of the running status and the number of threads of each module, the unit target address queue to be processed, and the vulnerability results, and to build a bus interface service.

[0058] The asynchronous asset rapid discovery module queries and obtains the targets to be rapidly discovered from the bus module according to its own number of idle threads, sends a SYN request to the target end to establish a connection, and updates the online status of the target to the bus module after receiving an ACK reply within the waiting time.

[0059] The asynchronous service accurate discovery module queries and obtains the service targets to be served from the bus module according to its own number of idle threads, attempts to establish a connection with the target end, receives the Welcome Banner information sent by the target within the waiting time, compares it with the fingerprint library to determine the port service information, and updates the service information of the target to the bus module.

[0060] The asynchronous vulnerability detection module queries and obtains the targets to be vulnerability detected from the bus module according to its own number of idle threads, selects targeted vulnerability detection scripts and general vulnerability scripts according to the characteristic information of the target, applies for a penetration batch ID from the bus module before each detection script penetration, binds the ID to the detection script, and sends a detection payload to the target to be penetrated. At the same time, within the waiting time, it queries the bus module whether the batch ID has been penetrated successfully and writes the detection success result information into the bus module.

[0061] The asynchronous vulnerability verification module starts the listening service according to the configured listening information, generates an ID according to the length of the ID queue in the bus module and writes it into the bus module ID queue. In the listening service, it listens and decodes the ID information received from the target to be detected and updates the penetration result of the ID to the bus module.

[0062] The vulnerability warning module periodically obtains vulnerability result information from the bus module, embeds it into a preset report template, and sends the synthesized warning email according to the warning email address.

[0063] In this embodiment, the hardware information includes the number of CPU cores, the memory size, and the network card performance.

[0064] In this embodiment, the task scheduling module adjusts the ratio of the number of running threads of each functional module, specifically:

[0065] When the length of the target queue to be detected exceeds 50 each time, the number of threads of the asynchronous service accurate discovery module is reduced by 10%;

[0066] When the length of the target queue to be detected is 0, the number of threads of the asynchronous service accurate discovery module is increased by 10%;

[0067] When the asynchronous service accurate discovery module finds that the length of the target queue exceeds 30 each time, the number of threads of the asynchronous asset rapid discovery module is reduced by 10%;

[0068] When the asynchronous service accurate discovery module finds that the length of the target queue is 0, the number of threads of the asynchronous asset rapid discovery module is increased by 10%;

[0069] The number of threads of the asynchronous vulnerability verification module is fixed at 1.

[0070] In this embodiment, the listening service includes icmplog, tcplog, udplog, httplog, and dnslog.

[0071] In this embodiment, the bus module is used to implement the query and persistence of the running status of each module, the thread pool, the unit target address queue to be processed, and the vulnerability results based on redis;

[0072] The bus module constructs the bus interface service based on TCP and RSA algorithms.

[0073] This embodiment is based on the automated penetration testing system of the kind based on the information flow asynchronous processing algorithm described in the present invention, combined with Figure 2 To better understand this embodiment, a practical embodiment is provided:

[0074] Hardware and system initialization module: This module reads hardware information such as the number of CPU cores, the memory size, and the network card performance, initializes the number of threads of each functional module according to the hardware performance data, and starts each functional module. According to the IP and port configuration of the bus module, the bus module service is started. The parameters such as the number of threads of each functional module are written into the bus module. The target range address to be detected is written into the bus.

[0075] Task Scheduling Module: This module reads the detected target range address from the bus module, disassembles it into the form of IP + port, and marks the priority according to whether the port is high-risk. The task scheduling module obtains the targets to be quickly discovered, precisely discovered, detected, and verified from the bus module every 3 seconds, and reads the number of threads and thread working status of each functional module. The task scheduling module adjusts the ratio of the number of running threads of each functional module every 60 seconds according to the degree of each target queue to be processed in the bus module. The adjustment method is as follows: when the length of the detected target queue exceeds 50 each time, reduce the threads of the asynchronous service accurate discovery module by 10%; when the length of the detected target queue is 0, increase the threads of the asynchronous service accurate discovery module by 10%. When the length of the precisely serviced discovery target queue exceeds 30 each time, reduce the threads of the asynchronous asset rapid discovery module by 10%; when the length of the precisely serviced discovery target queue is 0, increase the threads of the asynchronous asset rapid discovery module by 10%. The number of threads of the asynchronous vulnerability verification module is fixed at 1.

[0076] Bus Module: Based on Redis, it realizes the operation status and number of threads of each functional module, the target queue to be processed, the query and persistence of vulnerability results, and constructs a bus interface service based on TCP and RSA algorithms.

[0077] Asynchronous Asset Rapid Discovery: This module queries and obtains the targets to be quickly discovered from the bus module according to its own idle thread number. Sends a SYN request to the target end to establish a connection. After receiving an ACK response within the waiting time, updates the online status of this target to the bus module.

[0078] Asynchronous Service Precise Discovery: This module queries and obtains the targets to be precisely discovered for the service from the bus module according to its own idle thread number. Tries to establish a connection with the target end. After receiving the WelcomeBanner information sent by the target machine within the waiting time, compares it with the fingerprint database to determine the port service information, and updates the service information of this target to the bus module.

[0079] Asynchronous Vulnerability Detection Module: This module queries and obtains the targets to be detected for vulnerabilities from the bus module according to its own idle thread number. Selects targeted vulnerability detection scripts and general vulnerability scripts according to the characteristic information of the target. Before each penetration of the detection script, applies for a penetration batch ID from the bus module, binds the ID to the detection script, and then sends a detection payload to the target to be penetrated. At the same time, within the waiting time, queries the bus module to check whether the batch ID has been successfully penetrated, and writes the successful detection result information into the bus module.

[0080] Asynchronous Vulnerability Verification Module: This module enables the icmplog, tcplog, udplog, httplog, and dnslog listening services according to the configured listening configuration information. Generates an ID based on the length of the available ID queue in the bus module and writes it into the bus ID queue. In the listening service, listens for and decodes the ID information received from the detected target, and updates the penetration result of this ID to the bus module.

[0081] Vulnerability Alarm Module: This module periodically obtains vulnerability result information from the bus module, embeds it into a preset report template, and sends the synthesized alarm email according to the alarm email address.

[0082] An electronic device according to this embodiment includes a processor, a communication interface, a memory, and a communication bus. Among them, the processor, the communication interface, and the memory complete mutual communication through the communication bus;

[0083] The memory is used to store computer programs;

[0084] The processor, when executing the program stored on the memory, implements the method steps described in any one of the above embodiments.

[0085] A computer-readable storage medium according to this embodiment stores a computer program in the computer-readable storage medium, and when the computer program is executed by a processor, it implements the method steps described in any one of the above embodiments.

[0086] The memory in the embodiments of the present application may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read only memory (ROM), a programmable ROM (PROM), an erasable PROM (EPROM), an electrically erasable PROM (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of RAM are available, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchlink DRAM (SLDRAM), and direct rambus RAM (DR RAM). It should be noted that the memory of the method described in the present invention is intended to include but not limited to these and any other suitable types of memory.

[0087] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from a website, computer, server, or data center to another website, computer, server, or data center in a wired manner (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wirelessly (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that can be accessed by a computer, or a data storage device such as a server or data center that includes one or more integrated available media. The available medium can be a magnetic medium (such as a floppy disk, hard disk, magnetic tape), an optical medium (such as a high-density digital video disc (DVD)), or a semiconductor medium (such as a solid state disc (SSD)), etc.

[0088] In the implementation process, the steps of the above method can be completed by the integrated logic circuit of the hardware in the processor or the instructions in the form of software. The steps of the method disclosed in combination with the embodiments of the present application can be directly embodied as being executed by the hardware processor, or executed by a combination of the hardware and software modules in the processor. The software module can be located in a mature storage medium in the art such as random access memory, flash memory, read-only memory, programmable read-only memory, or electrically erasable programmable memory, register, etc. This storage medium is located in the memory, and the processor reads the information in the memory and combines its hardware to complete the steps of the above method. To avoid repetition, it will not be described in detail here.

[0089] It should be noted that the processor in the embodiments of the present application may be an integrated circuit chip with signal processing capabilities. In the implementation process, the steps of the above method embodiments can be completed by the integrated logic circuit in the hardware of the processor or instructions in software form. The above processor may be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. It can implement or execute the various methods, steps and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The steps of the method disclosed in combination with the embodiments of the present application can be directly embodied as being executed and completed by the hardware decoding processor, or executed and completed by the combination of the hardware and software modules in the decoding processor. The software module may be located in a mature storage medium in the art such as random access memory, flash memory, read-only memory, programmable read-only memory or electrically erasable programmable memory, register, etc. This storage medium is located in the memory, and the processor reads the information in the memory and combines its hardware to complete the steps of the above method.

[0090] The above has introduced in detail an automated penetration testing method, system, device and storage medium based on an information flow asynchronous processing algorithm proposed by the present invention. Specific examples are used in this article to elaborate on the principle and implementation manner of the present invention. The description of the above embodiments is only used to help understand the method and its core idea of the present invention; at the same time, for those of ordinary skill in the art, according to the idea of the present invention, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to the present invention.

Claims

1. An automated penetration testing method based on an information flow asynchronous processing algorithm, characterized in that, It includes the following steps: Step S1: The hardware and system initialization module initializes the thread pools of each module according to the hardware configuration information. Each module registers its online status and thread pool parameters with the task scheduling module. The modules include the asynchronous asset rapid discovery module, the asynchronous service accurate discovery module, the asynchronous vulnerability detection module, and the asynchronous vulnerability verification module; Step S2, the task scheduling module receives the target address range input by the user. After disassembling it into unit target addresses in units of IP + ports, it is input to the bus module. If the unit target address contains high-risk ports, the priority of these unit target addresses is set to high; Step S3: The task scheduling module obtains the information of the unit target address to be processed from the bus module according to the unit target address priority and the workload of each module. According to the type of the unit target address, it is respectively allocated to each module, and the status of the unit target address is marked. Each module independently starts the corresponding thread to process the unit target address; Step S4: The asynchronous vulnerability verification module listens to the requests of the detected targets, decodes the ID information from the request data, and re-injects the ID information into the bus module. The asynchronous vulnerability detection module receives the ID information from the bus module, matches the specific vulnerability detection payload, determines the vulnerability information, and then re-injects the vulnerability information into the bus module; Step S5: The vulnerability warning module obtains the vulnerability information from the bus module in real time, generates a vulnerability information briefing, sends it to the user email address through the email system, and marks the warning status of the vulnerability information; The asynchronous asset rapid discovery module queries and obtains the targets to be rapidly discovered from the bus module according to its own number of idle threads, sends a SYN request to the target end to establish a connection. Within the waiting time, after receiving the ACK reply, it updates the online status of the target to the bus module; The asynchronous service accurate discovery module queries and obtains the service targets to be served from the bus module according to its own number of idle threads, attempts to establish a connection with the target end. Within the waiting time, it receives the Welcome Banner information sent by the target, compares it with the fingerprint database to determine the port service information, and updates the service information of the target to the bus module; The asynchronous vulnerability detection module queries and obtains the targets to be vulnerability detected from the bus module according to its own number of idle threads. According to the characteristic information of the target, it selects the targeted vulnerability detection scripts and general vulnerability scripts. Before each penetration of the detection script, it applies for a penetration batch ID from the bus module, binds the ID to the detection script, and then sends the detection payload to the penetrated target. At the same time, within the waiting time, it queries the bus module whether the batch ID has been successfully penetrated and writes the detection success result information into the bus module; 2. The automated penetration testing method based on the information flow asynchronous processing algorithm according to claim 1, characterized in that, The high-risk ports include 22, 80, 3306, and 3389.

3. An automated penetration testing system based on an information flow asynchronous processing algorithm, the system is implemented by using an automated penetration testing method based on an information flow asynchronous processing algorithm as described in any one of claims 1-2, characterized in that, The system includes a hardware and system initialization module, a task scheduling module, a bus module, an asynchronous asset rapid discovery module, an asynchronous service accurate discovery module, an asynchronous vulnerability detection module, an asynchronous vulnerability verification module, and a vulnerability warning module; The hardware and system initialization module reads the hardware information, initializes the thread pools of each module according to the hardware performance data, and starts each module. The hardware and system initialization module starts the bus module according to the IP and port configuration of the bus module, writes the thread pool parameters of each module into the bus module, and the hardware and system initialization module writes the detected target range address into the bus module; The task scheduling module reads the detected target range address from the bus module and disassembles it into the form of an IP + port. If the port is high-risk, it is marked as a priority. The task scheduling module obtains the working status of the bus module every 3 seconds and reads the thread pool and thread working status of each module. The task scheduling module adjusts the ratio of the number of running threads of each module every 60 seconds according to the degree of the unit target address queue to be processed in the bus module; The bus module is used to implement the query and persistence of the running status, thread count, unit target address queue to be processed, and vulnerability results of each module, and construct a bus interface service; The asynchronous asset rapid discovery module, according to its own number of idle threads, queries and obtains the targets to be rapidly discovered from the bus module, sends SYN requests to the target ends to establish connections. During the waiting time, after receiving ACK responses, it updates the online status of the targets to the bus module; The asynchronous service accurate discovery module, according to its own number of idle threads, queries and obtains the service targets from the bus module, attempts to establish connections with the target ends. During the waiting time, upon receiving the Welcome Banner information sent by the target, it compares with the fingerprint database to determine the port service information, and updates the service information of the target to the bus module; The asynchronous vulnerability detection module, according to its own number of idle threads, queries and obtains the targets to be vulnerability detected from the bus module. According to the characteristic information of the targets, it selects targeted vulnerability detection scripts and general vulnerability scripts. Before each penetration of the detection script, it applies for a penetration batch ID from the bus module. After binding the ID to the detection script, it sends detection payloads to the targets to be penetrated. At the same time, during the waiting time, it queries the bus module whether the batch ID has been successfully penetrated, and writes the successful detection result information into the bus module; The asynchronous vulnerability verification module, according to the configured listening information, starts the listening service. According to the length of the ID queue in the bus module, it generates IDs and writes them into the bus module ID queue. In the listening service, it listens for and decodes the ID information received from the detected target, and updates the penetration result of the ID to the bus module; The vulnerability warning module periodically obtains vulnerability result information from the bus module, embeds it into a preset report template, and sends the synthesized warning emails according to the warning email addresses.

4. An automated penetration testing system based on an information flow asynchronous processing algorithm according to claim 3, characterized in that, The hardware information includes the number of CPU cores, memory size, and network card performance.

5. An automated penetration testing system based on an information flow asynchronous processing algorithm according to claim 3, characterized in that, The task scheduling module adjusts the ratio of the running thread counts of each functional module, specifically: When the length of the target queue to be detected exceeds 50 each time, reduce the threads of the asynchronous service accurate discovery module by 10%; When the length of the target queue to be detected is 0, increase the threads of the asynchronous service accurate discovery module by 10%; When the length of the target queue discovered by the asynchronous service accurate discovery module exceeds 30 each time, reduce the threads of the asynchronous asset rapid discovery module by 10%; When the length of the target queue discovered by the asynchronous service accurate discovery module is 0, increase the threads of the asynchronous asset rapid discovery module by 10%; The threads of the asynchronous vulnerability verification module are fixed at 1.

6. An automated penetration testing system based on an information flow asynchronous processing algorithm according to claim 3, characterized in that, The listening service includes icmplog, tcplog, udplog, httplog, and dnslog.

7. An automated penetration testing system based on an information flow asynchronous processing algorithm according to claim 3, characterized in that, The bus module is based on redis to implement the query and persistence of the running status, thread pool, unit target address queue to be processed, and vulnerability results of each module; The bus module constructs the bus interface service based on TCP and RSA algorithms.

8. An electronic device, characterized in that, It includes a processor, a communication interface, a memory, and a communication bus. Among them, the processor, communication interface, and memory complete mutual communication through the communication bus; The memory is used to store computer programs; A processor, when executing a program stored in a memory, implements the method steps described in any one of claims 1-2.

9. A computer-readable storage medium, characterized in that, A computer program is stored in the computer-readable storage medium, and when the computer program is executed by a processor, the method steps described in any one of claims 1-2 are implemented.

Citation Information

Patent Citations

  • Web vulnerability scanning method and system based on Linux system

    CN109067789A

  • Multi-module penetration test system based on cooperative control

    CN111143852A