Network vulnerability scanning system, method, electronic device and storage medium

By building a dedicated vulnerability scanning tunnel between the local CPE and the cloud-based CPE, remote and secure network vulnerability scanning is achieved, solving the problems of high cost and poor detection effect in existing technologies, and improving the efficiency and security of enterprise network vulnerability scanning.

CN116232640BActive Publication Date: 2025-12-12CHINA TELECOM CORP LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211573448.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-08
Publication Date
2025-12-12
Estimated Expiration
2042-12-08

AI Technical Summary

Technical Problem

Existing network vulnerability scanning technologies suffer from high costs, environmental limitations, and poor vulnerability detection results. In particular, in enterprise internal networks, relying on manual offline scanning can easily lead to security crises and there is a shortage of professional personnel.

Method used

By building a dedicated vulnerability scanning tunnel between the user's local CPE on the intranet and the cloud-based CPE in the cloud, the cloud-based CPE obtains scanning tasks and assigns target IP addresses to the scanner for vulnerability detection. After generating the results, the local CPE transmits them to the user's management terminal, thus achieving remote and secure network vulnerability scanning.

Benefits of technology

It effectively reduces the cost of network vulnerability scanning, improves scanning efficiency and accuracy, ensures data security, and expands the application scenarios of scanning.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116232640B_ABST
    Figure CN116232640B_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide a network vulnerability scanning system, method, electronic device and storage medium, the scanning system at least includes at least one local CPE located in the user intranet, cloud CPE located in the cloud and at least two scanners in communication connection with the cloud CPE, the cloud CPE is configured with a virtual network interface for network vulnerability scanning, the local CPE is configured with a network identifier for accessing the virtual network interface, and the vulnerability scanning tunnel for network vulnerability scanning is constructed between the local CPE and the cloud CPE through the cooperation between the network identifier and the virtual network interface.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of network communication, in particular to a network vulnerability scanning system, a network vulnerability scanning method, an electronic device and a computer readable storage medium. BACKGROUND

[0002] In recent years, network attacks are increasingly severe, and advanced network countermeasure security incidents frequently occur; hackers sell personal and enterprise data information on the network, and data leakage risks are increasing, continuously affecting various industries. Many security problems are discovered after the fact, and it is impossible to provide early warning before the threat period to minimize security risks. However, in the related network vulnerability scanning process, at least the following problems exist: 1. For enterprises and related application scenarios with high security coefficient requirements, if a non-enterprise internal scanning tool is used, it is easy to induce an information security crisis; 2. The professional requirements threshold of security scanning service personnel is high, and the enterprise investment cost is higher than expected: security service personnel need to have professional security qualification certification and rich work experience, and there is a lack of professional talents and means; 3. Due to actual conditions, the offline processing of security scanning service personnel is limited; 4. There are problems such as high false positives, high false negatives, high costs, and low efficiency in vulnerability scanning. SUMMARY

[0003] The embodiments of the present application provide a network vulnerability scanning system, method, electronic device and computer readable storage medium to solve or partially solve the problems of high cost, environmental limitations and poor vulnerability detection effect in the network vulnerability scanning process.

[0004] The embodiments of the present application disclose a network vulnerability scanning system, which comprises at least one local CPE located in a user intranet, a cloud CPE located in the cloud, and at least two scanners in communication connection with the cloud CPE. The cloud CPE is configured with a virtual network interface for network vulnerability scanning. The local CPE is configured with a network identifier for accessing the virtual network interface. A vulnerability scanning tunnel for network vulnerability scanning is constructed between the local CPE and the cloud CPE through cooperation between the network identifier and the virtual network interface. Wherein,

[0005] The cloud CPE is configured to obtain a network vulnerability scanning task, extract a target IP address corresponding to a target object to be scanned from the network vulnerability scanning task, and send the target IP address to at least two scanners.

[0006] The scanner is configured to perform network vulnerability detection on the target object according to the target IP address, generate a vulnerability detection result corresponding to the target object, and return the vulnerability detection result to a target local CPE corresponding to the target IP address.

[0007] The target local CPE is configured to transmit the vulnerability detection result to a corresponding user management terminal, so as to display the vulnerability detection result through the user management terminal.

[0008] Optionally, the cloud CPE is further configured to, if there are at least two network vulnerability scanning tasks, acquire a request time corresponding to each of the network vulnerability scanning tasks respectively, and send a target IP address corresponding to each of the at least two network vulnerability scanning tasks to at least two scanners in a sequence of the request times.

[0009] Optionally, the cloud CPE is further configured to, if the request times corresponding to the at least two network vulnerability scanning tasks are same, acquire an importance value corresponding to a user to which each of the network vulnerability scanning tasks belongs respectively, and send the target IP address corresponding to each of the at least two network vulnerability scanning tasks to the at least two scanners in a sequence of the importance values.

[0010] Optionally, the cloud CPE is further configured to, if the request times corresponding to the at least two network vulnerability scanning tasks are same and the importance values are equal, acquire a task amount corresponding to each of the network vulnerability scanning tasks respectively, and send the target IP address corresponding to each of the at least two network vulnerability scanning tasks to the at least two scanners in a sequence of the task amounts.

[0011] Optionally, the local CPE is in communication connection with a user terminal located in the same user intranet.

[0012] The local CPE is configured to acquire an IP address and gateway information of the user intranet from the user terminal.

[0013] Optionally, the system further comprises a cloud switch in communication connection with the cloud CPE and the at least two scanners.

[0014] Optionally, the target object at least includes one of a business system and an office network.

[0015] The embodiment of the present application also discloses a network vulnerability scanning method, which is applied to a scanning system, wherein the scanning system comprises at least one local CPE located in a user intranet, a cloud CPE located in a cloud, and at least two scanners in communication connection with the cloud CPE, the cloud CPE is configured with a virtual network interface for network vulnerability scanning, the local CPE is configured with a network identifier for accessing the virtual network interface, a vulnerability scanning tunnel for network vulnerability scanning is constructed between the local CPE and the cloud CPE through cooperation between the network identifier and the virtual network interface, and the method comprises the following steps of:

[0016] acquiring a network vulnerability scanning task through the cloud CPE, extracting a target IP address corresponding to a target object to be scanned from the network vulnerability scanning task, and sending the target IP address to the at least two scanners;

[0017] performing network vulnerability detection on the target object by the scanner according to the target IP address, generating a vulnerability detection result corresponding to the target object, and returning the vulnerability detection result to a target local CPE corresponding to the target IP address;

[0018] transmitting the vulnerability detection result to a corresponding user management terminal through the target local CPE, and displaying the vulnerability detection result through the user management terminal.

[0019] Optionally, the method further comprises the following steps of:

[0020] if the cloud CPE detects that there are at least two network vulnerability scanning tasks, acquiring a request time corresponding to each network vulnerability scanning task, and sending target IP addresses corresponding to the at least two network vulnerability scanning tasks to the at least two scanners in the order of the request times.

[0021] Optionally, if the cloud CPE detects that the request times corresponding to the at least two network vulnerability scanning tasks are the same, acquiring an importance value corresponding to a user to which each network vulnerability scanning task belongs, and sending target IP addresses corresponding to the at least two network vulnerability scanning tasks to the at least two scanners in the order of the importance values.

[0022] Optionally, if the cloud CPE detects that the request times corresponding to the at least two network vulnerability scanning tasks are the same and the importance values are equal, acquiring a task amount corresponding to each network vulnerability scanning task, and sending target IP addresses corresponding to the at least two network vulnerability scanning tasks to the at least two scanners in the order of the task amounts.

[0023] Optionally, the local CPE is in communication connection with a user terminal located in the same user intranet.

[0024] The local CPE acquires the IP address and gateway information of the user intranet from the user terminal.

[0025] Optionally, the scanning system further comprises a cloud switch located in the cloud and in communication connection with the cloud CPE, and the cloud switch is in communication connection with the at least two scanners respectively.

[0026] Optionally, the target object at least includes one of a business method and an office network.

[0027] The embodiment of the present application further discloses an electronic device, including a processor, a communication interface, a memory and a communication bus, wherein the processor, the communication interface and the memory complete mutual communication through the communication bus;

[0028] The memory is used for storing a computer program.

[0029] The processor is used for executing the program stored on the memory, and realizes the method as described in the embodiment of the present application.

[0030] The embodiment of the present application further discloses a computer readable storage medium, which stores instructions, and when executed by one or more processors, makes the processor execute the method as described in the embodiment of the present application.

[0031] The embodiment of the present application has the following advantages:

[0032] In the embodiment of the present application, the network vulnerability can be scanned by a scanning system, which can include at least one local CPE located in the user's intranet, a cloud CPE located in the cloud, and at least two scanners in communication connection with the cloud CPE, the cloud CPE being configured with a virtual network interface for network vulnerability scanning, the local CPE being configured with a network identifier for accessing the virtual network interface, a vulnerability scanning tunnel for network vulnerability scanning being built between the local CPE and the cloud CPE through cooperation between the network identifier and the virtual network interface, in the process of scanning the network vulnerability, the network vulnerability scanning task can be obtained through the cloud CPE, and the target IP address corresponding to the target object to be scanned for network vulnerability is extracted from the network vulnerability scanning task, the target IP address is sent to the at least two scanners, then the network vulnerability detection of the target object is performed by the scanner according to the target IP address, and the vulnerability detection result corresponding to the target object is generated, the vulnerability detection result is returned to the target local CPE corresponding to the target IP address, for the target local CPE, the vulnerability detection result can be transmitted to the corresponding user management terminal to display the vulnerability detection result through the user management terminal, so that the vulnerability scanning tunnel dedicated to network vulnerability scanning is built between the local CPE and the cloud CPE, the remote and secure vulnerability scanning can be realized based on the private channel while realizing the network vulnerability scanning, the data security is effectively guaranteed, at the same time, based on the distributed arrangement between the local CPE and the cloud CPE and between the cloud CPE and the scanner, different user private networks can be scanned synchronously, the efficiency of network vulnerability scanning is effectively improved, the cost is reduced, and the application scenario of network vulnerability scanning is improved based on the remote network vulnerability scanning in the cloud. BRIEF DESCRIPTION OF DRAWINGS

[0033] Figure 1 is a structural block diagram of a network vulnerability scanning system provided in the embodiment of the present application;

[0034] Figure 2 is a schematic diagram of a network communication architecture provided in the embodiment of the present application;

[0035] Figure 3 is a system architecture of a scanning system provided in the embodiment of the present application;

[0036] Figure 4 is a network architecture schematic diagram of a scanning system provided in the embodiment of the present application;

[0037] Figure 5 is a schematic diagram of an application scenario provided in the embodiment of the present application;

[0038] Figure 6 is a flowchart of task scanning provided in the embodiment of the present application;

[0039] Figure 7 is a step flow chart of a network vulnerability scanning method provided in an embodiment of the present application;

[0040] Figure 8 is a block diagram of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0041] In order to make the above-mentioned objects, features and advantages of the present application more apparent and easy to understand, the present application will be further described in detail below with reference to the drawings and specific embodiments.

[0042] As an example, in recent years, network attacks have become increasingly severe, and advanced network confrontation security incidents have frequently occurred; hackers sell personal and enterprise data information on the dark web, and data leakage risks are increasing, continuously affecting various industries. Many security problems are discovered after the fact, and it is impossible to provide early warning before the threat period to minimize security risks. The high-quality development of digital economy cannot be achieved without network security as the foundation, providing basic and universal protection. Security has become a necessity, and the overall security operation and maintenance capability of current small and medium-sized enterprise users is inefficient, and the market generally lacks a security scanning method that is isolated from the public network and end-to-end.

[0043] To this end, one of the core points of the application is to build a private channel for network vulnerability scanning of a private network between a physical CPE and a virtual CPE, to remotely scan the network vulnerability of the user's private network while ensuring data security, so that the network vulnerability scanning no longer relies too much on manual offline scanning, greatly reducing the cost. Specifically, for the scanning system, it can include at least one local CPE located in the user's intranet, a cloud CPE located in the cloud, and at least two scanners in communication connection with the cloud CPE, the cloud CPE is configured with a virtual network interface for network vulnerability scanning, the local CPE is configured with a network identifier for accessing the virtual network interface, and a vulnerability scanning tunnel for network vulnerability scanning is built between the local CPE and the cloud CPE through the cooperation between the network identifier and the virtual network interface. In the process of scanning the network vulnerability, the network vulnerability scanning task can be obtained through the cloud CPE, and the target IP address corresponding to the target object to be scanned for network vulnerability is extracted from the network vulnerability scanning task, and the target IP address is sent to at least two scanners. Then, the scanner performs network vulnerability detection on the target object according to the target IP address, and generates a vulnerability detection result corresponding to the target object. The vulnerability detection result is returned to the target local CPE corresponding to the target IP address. For the target local CPE, the vulnerability detection result can be transmitted to the corresponding user management terminal to display the vulnerability detection result through the user management terminal. Thus, by building a vulnerability scanning tunnel between the local CPE and the cloud CPE, which is exclusively used for network vulnerability scanning, remote and secure vulnerability scanning can be realized based on the private channel while implementing network vulnerability scanning, effectively ensuring the security of the data. At the same time, based on the distributed arrangement between the local CPE and the cloud CPE, and between the cloud CPE and the scanner, different user private networks can be scanned synchronously, effectively improving the efficiency of network vulnerability scanning, reducing the cost, and based on the remote network vulnerability scanning of the cloud, the application scenario of network vulnerability scanning is improved.

[0044] Reference Figure 1 , a structure block diagram of a network vulnerability scanning device provided in an embodiment of the application is shown, the scanning system at least includes at least one local CPE located in the user's intranet, a cloud CPE located in the cloud, and at least two scanners in communication connection with the cloud CPE, the cloud CPE is configured with a virtual network interface for network vulnerability scanning, the local CPE is configured with a network identifier for accessing the virtual network interface, and a vulnerability scanning tunnel for network vulnerability scanning is built between the local CPE and the cloud CPE through the cooperation between the network identifier and the virtual network interface; wherein,

[0045] The cloud CPE is configured to acquire a network vulnerability scanning task, extract a target IP address corresponding to a target object to be scanned from the network vulnerability scanning task, and send the target IP address to at least two scanners.

[0046] The scanner is configured to perform network vulnerability detection on the target object according to the target IP address, generate a vulnerability detection result corresponding to the target object, and return the vulnerability detection result to a target local CPE corresponding to the target IP address.

[0047] The target local CPE is configured to transmit the vulnerability detection result to a corresponding user management terminal, and display the vulnerability detection result through the user management terminal.

[0048] In the embodiment of the present application, for a user intranet, which can be a private network in an enterprise, an enterprise user can access enterprise internal data in a fixed local area network. For such a private network, when network vulnerability scanning is required, in the related art, a security scanning service personnel is usually offline to the corresponding enterprise, and a corresponding external device is used to scan the network vulnerability of the enterprise network and system to determine whether there is a corresponding network vulnerability. In this process, since the external device needs to be connected, it may induce information and security crisis, and excessive dependence on experienced and qualified security scanning service personnel greatly limits the application scenario of network vulnerability scanning.

[0049] Therefore, in the scanning system in the embodiment of the present application, a corresponding local CPE (Customer Premise Equipment) can be configured in the user intranet, and the local CPE can be communicatively connected with a user terminal in the same user intranet, so as to acquire an idle IP address and gateway information of the user intranet from the user terminal through the local CPE. In addition, the local CPE can access a corresponding virtual network through a preconfigured corresponding network identifier, so as to access a dedicated line network through the network identifier.

[0050] In a specific implementation, for the scanning system, it can include, in one aspect, a local CPE located in the user private network, and further include a cloud CPE located in the cloud and at least two scanners in communication connection with the cloud CPE. Wherein, for the cloud CPE, it can be a virtual terminal device (for example, in the form of a software application), and correspondingly, for the local CPE, it can be a physical virtual terminal device, while for the cloud CPE, it can be configured with a virtual network interface for network vulnerability scanning, and the local CPE can be configured with a network identifier for accessing the virtual network interface, and a vulnerability scanning tunnel for network vulnerability scanning is built between the local CPE and the cloud CPE through cooperation between the network identifier and the virtual network interface, so that through building the vulnerability scanning tunnel between the local CPE and the cloud CPE which is exclusively used for network vulnerability scanning, remote and secure vulnerability scanning can be realized based on the private channel while realizing network vulnerability scanning, effectively ensuring the security of data.

[0051] Optionally, isolation can be made with the Internet through a 5G slice private line channel, and direct access to the user intranet through a private line ensures network security. Specifically, a security scanning service personnel can configure a 5G CPE in a user intranet that needs to be scanned for network vulnerability, and use a wired connection user intranet port to collect an intranet idle IP and corresponding gateway information, so as to realize positioning of the user intranet through the IP and gateway information when scanning the user intranet for network vulnerability in the future. At the same time, after configuring the corresponding physical 5G CPE, a special network identifier DNN (Data Network Name) can be configured on the physical 5G CPE, through which network layer tunnel intercommunication with the cloud CPE in the cloud can be realized. Correspondingly, after configuring the corresponding physical 5G CPE in the user intranet, a background administrator can configure a pre-set VNI (Virtual Network Interface) on the cloud CPE of the scanning system, through which a VxLAN (Virtual Extensible Local Area Network) layer two tunnel with the physical 5G CPE in the user intranet can be realized, and through the VxLAN layer two tunnel, network vulnerability can be scanned in a private line private network, effectively ensuring the data security of the user intranet.

[0052] In addition, at least two heterogeneous scanners can be configured in the cloud, and when it is necessary to scan the user intranet for network vulnerability, the cloud CPE can send corresponding client IP addresses to each heterogeneous scanner, so as to start remote scanning. In one example, referring to Figure 2Fig. 1 shows a schematic diagram of a network communication architecture provided in an embodiment of the present application, wherein the customer intranet can be an object requiring network vulnerability scanning, and the customer intranet can be configured with a business system, a corresponding office network, and a local switch in communication connection with the business system and the office network, and a 5G CPE for constructing a network vulnerability scanning tunnel, and in the cloud, a corresponding cloudified 5G CPE, a cloud switch in communication connection with the cloudified 5G CPE, and at least two heterogeneous scanners (scanner 1, scanner 2, etc. shown in the figure) in communication connection with the cloud switch, and by customizing a dedicated DNN and a layer 2 VLAN ID isolation between the local 5G CPE and the cloudified 5G CPE to punch through a VxLAN layer 2 tunnel between the local 5G CPE and the cloudified 5G CPE, a dedicated network vulnerability scanning is realized, and the data security of the user intranet is effectively guaranteed. Figure 2 As shown in Fig. 1, based on the VxLAN layer 2 tunnel between the local 5G CPE and the cloudified 5G CPE, a dedicated communication channel is directly constructed between the local switch and the cloud switch, and is used for network vulnerability scanning of the user intranet.

[0053] Optionally, for the cloudified CPE and the scanner, the scanner can be deployed by cloudified CPE networking, specifically, the cloudified CPE is deployed on the cloud, and the scanner is also deployed on the cloud, and the deployment and issuance of the scanning task is realized on the cloud, by cloudified CPE networking, not only the number of concurrent tasks is determined by the number of virtual network cards supported by the cloud host, but also the administrator remotely configures the tunnel and starts the scanning task on the cloudified CPE, and the cloudified CPE and the UPF (User Plane Function) are connected through the cloud private line, which can effectively guarantee the network bandwidth and stability. In addition, by deploying at least two heterogeneous scanners on the cloud for network vulnerability scanning, the accuracy of network vulnerability scanning can be effectively improved.

[0054] In a specific implementation, when the cloud CPE receives a network vulnerability scanning task, the target IP address corresponding to the target object to be scanned can be extracted from the network vulnerability scanning task, and the target IP address is sent to the scanner. For the target IP address, the IP address of the user's internal network corresponding to the target object can be obtained. When each scanner receives the target IP address, it can access the target IP address and perform network vulnerability scanning on the target object. Then, based on the scanning result, the corresponding vulnerability detection result is generated and transmitted to the cloud CPE. The cloud CPE sends the vulnerability detection result to the target local CPE corresponding to the target IP address, and then the target local CPE transmits the vulnerability detection result to the corresponding user management terminal to display the vulnerability detection result through the user management terminal. By constructing a vulnerability scanning tunnel between the local CPE and the cloud CPE, which is dedicated to network vulnerability scanning, the network vulnerability scanning is realized, and the remote and secure vulnerability scanning is realized based on the private channel, effectively ensuring the security of the data. At the same time, based on the distributed arrangement between the local CPE and the cloud CPE, and between the cloud CPE and the scanner, different user private networks can be scanned synchronously, effectively improving the efficiency of network vulnerability scanning, reducing costs, and improving the application scenarios of network vulnerability scanning based on the cloud.

[0055] It should be noted that the scanning method, process, etc. of network vulnerability scanning can be related to the prior art. The core invention in the embodiment of the present application is to construct a scanning system for network vulnerability scanning. The present application does not limit the implementation of network vulnerability scanning.

[0056] In addition, since the cloud CPE can concurrently process multiple network vulnerability scanning tasks, when the cloud CPE detects that there are at least two network vulnerability scanning tasks, the request time corresponding to each network vulnerability scanning task can be obtained in sequence, and the target IP address corresponding to the at least two network vulnerability scanning tasks is sent to at least two scanners in sequence according to the request time. Further, if the request time corresponding to the at least two network vulnerability scanning tasks is the same, the importance value corresponding to the user to which each network vulnerability scanning task belongs is obtained, and the target IP address corresponding to the at least two network vulnerability scanning tasks is sent to at least two scanners in sequence according to the importance value. Furthermore, if the request time corresponding to the at least two network vulnerability scanning tasks is the same and the importance value is equal, the task amount corresponding to each network vulnerability scanning task is obtained, and the target IP address corresponding to the at least two network vulnerability scanning tasks is sent to at least two scanners in sequence according to the task amount.

[0057] The request time can be the initiation time point of the user terminal side request for network vulnerability scanning. The cloud CPE can arrange the network vulnerability scanning of the scanner according to the order of the initiation time point. The importance value can be used to represent the priority of network vulnerability scanning of different users. The higher the importance value, the higher the priority of network vulnerability scanning. If the request time is the same, the cloud CPE can perform the corresponding network vulnerability scanning. If the request time is different, the cloud CPE needs to perform the corresponding network vulnerability scanning according to the priority order. The task amount can be the workload of one network vulnerability scanning. Different network vulnerability tasks can correspond to different workloads. If the request time and the importance value are the same, the cloud CPE can perform the corresponding network vulnerability scanning according to the workload.

[0058] In an example, assuming that the user intranet A, the user intranet B, the user intranet C and the user intranet D need to perform network vulnerability scanning, the corresponding request time is T1, T2, T3 and T4 respectively, wherein T1 is earlier than T2, T3 and T4, T2, T3 and T4 are the same time point, and the importance value of the user intranet B, the user intranet C and the user intranet D is the same, and the task amount of the network vulnerability task corresponding to the user intranet C is higher than that of the network vulnerability task corresponding to the user intranet D. Based on the above process information, the cloud CPE can perform network vulnerability scanning on each user intranet through at least two scanners in the order of the user intranet A, the user intranet B, the user intranet C and the user intranet D, so as to construct a vulnerability scanning tunnel between the local CPE and the cloud CPE, which is dedicated to network vulnerability scanning, so as to realize remote and secure vulnerability scanning based on the private channel while realizing network vulnerability scanning, effectively ensuring the security of data, and based on the distributed arrangement between the local CPE and the cloud CPE and between the cloud CPE and the scanner, different user private networks can be scanned synchronously, effectively improving the efficiency of network vulnerability scanning, reducing the cost, and based on the remote network vulnerability scanning of the cloud, the application scene of network vulnerability scanning is improved.

[0059] In the embodiment of the present application, the network vulnerability can be scanned by a scanning system, which can include at least one local CPE located in the user's intranet, a cloud CPE located in the cloud, and at least two scanners in communication connection with the cloud CPE, the cloud CPE being configured with a virtual network interface for network vulnerability scanning, the local CPE being configured with a network identifier for accessing the virtual network interface, a vulnerability scanning tunnel for network vulnerability scanning being built between the local CPE and the cloud CPE through cooperation between the network identifier and the virtual network interface, in the process of scanning the network vulnerability, the network vulnerability scanning task can be obtained by the cloud CPE, and the target IP address corresponding to the target object to be scanned for network vulnerability is extracted from the network vulnerability scanning task, the target IP address is sent to the at least two scanners, then the network vulnerability detection of the target object is performed by the scanners according to the target IP address, and the vulnerability detection result corresponding to the target object is generated, the vulnerability detection result is returned to the target local CPE corresponding to the target IP address, for the target local CPE, the vulnerability detection result can be transmitted to the corresponding user management terminal to display the vulnerability detection result through the user management terminal, thereby building the vulnerability scanning tunnel between the local CPE and the cloud CPE which is exclusively used for network vulnerability scanning, realizing network vulnerability scanning, and based on the private channel, remote and secure vulnerability scanning can be realized, effectively ensuring the security of data, at the same time, based on the distributed arrangement between the local CPE and the cloud CPE, and between the cloud CPE and the scanners, different user private networks can be scanned synchronously, effectively improving the efficiency of network vulnerability scanning, reducing the cost, and based on the remote network vulnerability scanning in the cloud, the application scenario of network vulnerability scanning is improved.

[0060] In order for those skilled in the art to better understand the technical solutions in the embodiments of the present application, the following will be exemplarily described by an example:

[0061] Reference Figure 3, the system architecture of the scanning system provided in the embodiment of the application is shown, for the scanning system, core modules such as portal function, task scheduling, service scheduling, and auxiliary log recording, file storage and cache mechanism modules can be designed in a secure channel isolated from the public network, specifically, the front-end application can be a portal web application; for the application service, modules such as portal function, task scheduling and service calling can be included, the portal function module can include function modules such as homepage management, customer management, asset management, task management, report management, scanner management, risk intelligence library, solution, log audit, permission management and the like, the task scheduling module can be a scheduling center, the service calling module can include function modules such as xx scanner, automatic penetration test, Github scanning, yy base and 5G attack and defense target range, in addition, the application service can further include modules such as log recording, permission control and access control; for the persistent storage, it can be composed of corresponding cache mechanism, relational database: MySQL and file storage Minio. Correspondingly, for the infrastructure involved in the scanning system, it can include 5G slice network, server and operating system and the like.

[0062] Referring to Figure 4 , the network architecture diagram of the scanning system provided in the embodiment of the application is shown, for the CPE networking management platform, corresponding local CPEs (such as CPE1, CPE2, CPE n and the like) can be respectively configured on different branch organizations, one branch organization is configured with one local CPE, each local CPE is in communication connection with the 5G UPF, and is in communication connection with the cloud PE (i.e. cloud server) in the cloud through the ASBR (Autonomous System Boundary Router) to realize data communication with the business cloud, the cloudization CPE corresponding to the local CPE and the heterogeneous scanner in communication connection with the cloudization CPE can be configured in the business cloud, in the process of network vulnerability scanning, private channel network vulnerability scanning can be realized based on the 5G slice cloud entry private line, and the safety of branch organization data is ensured.

[0063] Referring to Figure 5FIG. 1 shows a schematic diagram of an application scenario provided in an embodiment of the present application, assuming that network vulnerability scanning is performed on different enterprises in different cities, including in Qingyuan, Guangzhou and other cities, and each city can include a plurality of enterprises that need to be subjected to network vulnerability scanning, and each enterprise can be configured with a corresponding physical CPE, the physical CPE accesses the intranet of the enterprise through a LAN port, and at the same time, the physical CPE builds a corresponding VxLAN tunnel between the 5G UPF and the cloud CPE, and correspondingly, the cloud CPE can be connected to the scanner through a corresponding LAN. When network vulnerability scanning is performed on the corresponding enterprise, the enterprise portal can place an order online, and the scheduling center of the scanning system can queue, time-multiplex and weight the priority of the order, and when the network vulnerability scanning task corresponding to the order is executed, the corresponding scanner (such as scanner 1) is called to achieve remote layer 2 connection through Vxlan, and the scanner directly reaches the customer intranet to perform network vulnerability scanning.

[0064] Referring to Figure 6 , a flowchart of task scanning provided in an embodiment of the present application is shown, which can specifically include:

[0065] 1. The scheduling center acquires a task.

[0066] 2. The task queue receives the task issued by the scheduling center and transmits the task to the task asset to calculate the corresponding route by the task asset, and returns the calculation result to the scheduling center.

[0067] 3. The scheduling center acquires an idle network card and a scanner address from the scanner network card pool.

[0068] 4. The scheduling center sets the corresponding network card IP on the scanner.

[0069] 5. The scheduling center sets the corresponding network card route on the scanner.

[0070] 6. The scheduling center triggers the scanner to execute the task.

[0071] 7. The report center queries the corresponding scanning result from the scanner.

[0072] 8. The scanner generates a corresponding report based on the scanning result and transmits it to the report center.

[0073] Processes 7 and 8 can be executed in a loop.

[0074] Through the above examples, in the embodiment of the application, by constructing the vulnerability scanning tunnel which is special for network vulnerability scanning between the local CPE and the cloud CPE, the network vulnerability scanning is realized, and the remote and safe vulnerability scanning can be realized based on the private channel, which effectively ensures the security of the data, and based on the distributed arrangement between the local CPE and the cloud CPE and between the cloud CPE and the scanner, different user private networks can be scanned synchronously, which effectively improves the efficiency of network vulnerability scanning, reduces the cost, and based on the remote network vulnerability scanning of the cloud, the application scene of network vulnerability scanning is improved.

[0075] Referring to Figure 7 , a step flow chart of a network vulnerability scanning system provided in the embodiment of the application is shown, which is applied to a scanning system, and the scanning system at least includes at least one local CPE located in a user intranet, a cloud CPE located in a cloud, and at least two scanners in communication connection with the cloud CPE, the cloud CPE is configured with a virtual network interface for network vulnerability scanning, the local CPE is configured with a network identifier for accessing the virtual network interface, and a vulnerability scanning tunnel for network vulnerability scanning is constructed between the local CPE and the cloud CPE through cooperation between the network identifier and the virtual network interface, and the specific steps can include the following steps:

[0076] Step 701, the cloud CPE acquires a network vulnerability scanning task, extracts a target IP address corresponding to a target object to be scanned for network vulnerability from the network vulnerability scanning task, and sends the target IP address to at least two scanners;

[0077] Step 701, the scanner performs network vulnerability detection on the target object according to the target IP address, generates a vulnerability detection result corresponding to the target object, and returns the vulnerability detection result to a target local CPE corresponding to the target IP address;

[0078] Step 701, the target local CPE transmits the vulnerability detection result to a corresponding user management terminal, so as to display the vulnerability detection result through the user management terminal.

[0079] In an optional embodiment, it further includes:

[0080] If the cloud CPE detects that there are at least two network vulnerability scanning tasks, the request time corresponding to each network vulnerability scanning task is acquired, and the target IP address corresponding to the at least two network vulnerability scanning tasks is sent to at least two scanners in the order of the request time.

[0081] In an alternative embodiment, if the cloud CPE detects that the request time corresponding to the at least two network vulnerability scanning tasks is the same, the importance value corresponding to the user to which each of the network vulnerability scanning tasks belongs is obtained respectively, and the target IP addresses corresponding to the at least two network vulnerability scanning tasks are sent to the at least two scanners in the order of the importance values.

[0082] In an alternative embodiment, if the cloud CPE detects that the request time corresponding to the at least two network vulnerability scanning tasks is the same and the importance values are equal, the task amount corresponding to each of the network vulnerability scanning tasks is obtained respectively, and the target IP addresses corresponding to the at least two network vulnerability scanning tasks are sent to the at least two scanners in the order of the task amounts.

[0083] In an alternative embodiment, the local CPE is in communication connection with a user terminal located in the same user intranet.

[0084] The IP address and gateway information of the user intranet are obtained from the user terminal by the local CPE.

[0085] In an alternative embodiment, the scanning system further comprises a cloud switch in the cloud and in communication connection with the cloud CPE, and the cloud switch is in communication connection with the at least two scanners respectively.

[0086] In an alternative embodiment, the target object at least includes one of a business method and an office network.

[0087] In the embodiment of the present application, the network vulnerability can be scanned by a scanning system, which can include at least one local CPE located in the user's intranet, a cloud CPE located in the cloud, and at least two scanners in communication connection with the cloud CPE, the cloud CPE being configured with a virtual network interface for network vulnerability scanning, the local CPE being configured with a network identifier for accessing the virtual network interface, a vulnerability scanning tunnel for network vulnerability scanning being built between the local CPE and the cloud CPE through cooperation between the network identifier and the virtual network interface, in the process of scanning the network vulnerability, the cloud CPE can obtain a network vulnerability scanning task, and extract a target IP address corresponding to a target object to be scanned for network vulnerability from the network vulnerability scanning task, and send the target IP address to the at least two scanners, then the scanners perform network vulnerability detection on the target object according to the target IP address, and generate a vulnerability detection result corresponding to the target object, and return the vulnerability detection result to a target local CPE corresponding to the target IP address, for the target local CPE, the vulnerability detection result can be transmitted to a corresponding user management terminal to display the vulnerability detection result through the user management terminal, so that the vulnerability scanning tunnel between the local CPE and the cloud CPE is built for network vulnerability scanning, the remote and secure vulnerability scanning can be realized based on the private channel while realizing network vulnerability scanning, the data security is effectively ensured, the different user private networks can be scanned synchronously based on the distributed arrangement between the local CPE and the cloud CPE and between the cloud CPE and the scanners, the efficiency of network vulnerability scanning is effectively improved, the cost is reduced, and the application scenarios of network vulnerability scanning are improved based on the remote network vulnerability scanning in the cloud.

[0088] It should be noted that, for the method embodiments, in order to simply describe, they are all described as a series of action combinations, but those skilled in the art should know that the embodiments of the present application are not limited to the order of the described actions, because according to the embodiments of the present application, certain steps can be performed in other order or at the same time. Secondly, those skilled in the art should know that the embodiments described in the specification all belong to preferred embodiments, and the actions involved are not necessarily necessary for the embodiments of the present application.

[0089] In addition, the present application also provides an electronic device, which includes a processor, a memory, a computer program stored in the memory and executable on the processor, which, when executed by the processor, implements each process of the above-mentioned network vulnerability scanning method embodiment and achieves the same technical effect. To avoid repetition, it will not be repeated here.

[0090] The embodiment of the present application further provides a computer readable storage medium, and the computer readable storage medium stores a computer program. The computer program is executed by a processor to realize each process of the network vulnerability scanning method embodiment and achieve the same technical effects. To avoid repetition, details are not described herein. The computer readable storage medium includes a read-only memory (ROM), a random access memory (RAM), a magnetic disk, an optical disk, and the like.

[0091] Figure 8 A hardware structure schematic diagram of an electronic device for implementing various embodiments of the present application.

[0092] The electronic device 800 includes, but is not limited to, a radio frequency unit 801, a network module 802, an audio output unit 803, an input unit 804, a sensor 805, a display unit 806, a user input unit 807, an interface unit 808, a memory 809, a processor 810, and a power supply 811, and the like. Those skilled in the art can understand that the electronic device structure involved in the embodiments of the present application does not constitute a limitation on the electronic device, and the electronic device can include more or fewer components than the illustration, or combine certain components, or different component arrangements. In the embodiments of the present application, the electronic device includes, but is not limited to, a mobile phone, a tablet computer, a notebook computer, a palm computer, a vehicle terminal, a wearable device, and a pedometer, and the like.

[0093] It should be understood that in the embodiments of the present application, the radio frequency unit 801 can be used for receiving and sending signals in the process of information or call. Specifically, after receiving the downlink data from the base station, the processor 810 processes it. In addition, the uplink data is sent to the base station. Generally, the radio frequency unit 801 includes, but is not limited to, an antenna, at least one amplifier, a transceiver, a coupler, a low noise amplifier, a duplexer, and the like. In addition, the radio frequency unit 801 can also communicate with the network and other devices through a wireless communication system.

[0094] The electronic device provides wireless broadband Internet access for users through the network module 802, such as helping users to send and receive emails, browse web pages, and access streaming media, and the like.

[0095] The audio output unit 803 can convert audio data received by the radio frequency unit 801 or the network module 802 or stored in the memory 809 into an audio signal and output as a sound. Moreover, the audio output unit 803 can also provide audio output related to a specific function performed by the electronic device 800 (for example, a call signal receiving sound, a message receiving sound, and the like). The audio output unit 803 includes a speaker, a buzzer, a receiver, and the like.

[0096] The input unit 804 is configured to receive audio or video signals. The input unit 804 can include a graphic processing unit (GPU) 8041 and a microphone 8042. The graphic processing unit 8041 processes image data of a still picture or a video obtained by an image capture apparatus (e.g., a camera) in a video capture mode or an image capture mode. Processed image frames can be displayed on the display unit 806. Processed image frames can be stored in the memory 809 (or other storage medium) or transmitted via the radio frequency unit 801 or the network module 802. The microphone 8042 can receive sound and is capable of processing such sound as audio data. Processed audio data can be converted into a format that can be transmitted to a mobile communication base station via the radio frequency unit 801 in a telephone call mode.

[0097] The electronic device 800 further includes at least one sensor 805, such as a light sensor, a motion sensor, and other sensors. Specifically, the light sensor includes an ambient light sensor and a proximity sensor, wherein the ambient light sensor can adjust the brightness of the display panel 8061 according to the brightness of ambient light, and the proximity sensor can turn off the display panel 8061 and / or the backlight when the electronic device 800 is moved to the ear. As one of the motion sensors, the accelerometer sensor can detect the magnitude of acceleration in each direction (generally three axes), and when at rest, can detect the magnitude and direction of gravity, and can be used to identify the electronic device posture (such as screen switching, related games, magnetometer posture calibration), vibration recognition related functions (such as pedometer, knock), and the like. The sensor 805 can also include a fingerprint sensor, a pressure sensor, an iris sensor, a molecular sensor, a gyroscope, a barometer, a hygrometer, a thermometer, an infrared sensor, and the like, which will not be described here.

[0098] The display unit 806 is configured to display information input by a user or information provided to the user. The display unit 806 can include a display panel 8061, which can be configured in the form of a liquid crystal display (LCD), an organic light-emitting diode (OLED), or the like.

[0099] The user input unit 807 can be used to receive inputted digital or character information and to generate key signal input with respect to user settings of the electronic device and control of functions. Specifically, the user input unit 807 includes a touch panel 8081 and other input devices 8072. The touch panel 8081, also called a touch screen, can collect a touch operation of a user thereon or adjacent thereto, such as an operation of the user using a finger, a stylus, or any suitable object or accessory on or adjacent to the touch panel 8081. The touch panel 8081 can include two parts of a touch detecting device and a touch controller. The touch detecting device detects a user's touch position and detects a signal resulting from the touch operation and transmits the signal to the touch controller. The touch controller receives the touch information from the touch detecting device and converts it into touch coordinates, which are then transmitted to the processor 810, which receives commands from the processor 810 and executes them. In addition, the touch panel 8081 can be implemented in various types such as a resistive type, a capacitive type, an infrared type, and a surface acoustic wave type. In addition to the touch panel 8081, the user input unit 807 can include other input devices 8072. Specifically, the other input devices 8072 can include, but are not limited to, a physical keyboard, function keys (such as volume control keys, switch keys, etc.), a trackball, a mouse, a joystick, etc., without being limited thereto.

[0100] Further, the touch panel 8081 can be overlaid on the display panel 8061, and when the touch panel 8081 detects a touch operation thereon or adjacent thereto, it transmits the same to the processor 810 to determine the type of the touch event, and then the processor 810 provides a corresponding visual output on the display panel 8061 according to the type of the touch event. It can be understood that, in one embodiment, the touch panel 8081 and the display panel 8061 are implemented as two independent components to realize the input and output functions of the electronic device, but in some embodiments, the touch panel 8081 and the display panel 8061 can be integrated to realize the input and output functions of the electronic device, without being limited thereto.

[0101] The interface unit 808 is an interface for connecting an external device to the electronic device 800. For example, the external device can include a wired or wireless headset port, an external power supply (or battery charger) port, a wired or wireless data port, a memory card port, a port for connecting a device having an identification module, an audio input / output (I / O) port, a video I / O port, an earphone port, etc. The interface unit 808 can be used to receive input (e.g., data information, power, etc.) from an external device and transmit the received input to one or more elements within the electronic device 800 or can be used to transmit data between the electronic device 800 and the external device.

[0102] The memory 809 is operable to store software programs as well as various data. The memory 809 can mainly include a program storage area and a data storage area, wherein the program storage area can store an operating system, application programs required by at least one function (such as a sound playing function, an image playing function, etc.), and the like; and the data storage area can store data created based on the use of the mobile phone (such as audio data, a phone book, etc.), and the like. In addition, the memory 809 can include a high-speed random access memory, and can further include a nonvolatile memory such as at least one magnetic disk storage device, a flash memory device, or other volatile solid-state memory device.

[0103] The processor 810 is a control center of the electronic device, which connects each part of the entire electronic device through various interfaces and lines, performs various functions of the electronic device and processes data by running or executing software programs and / or modules stored in the memory 809 and calling data stored in the memory 809, and thus performs overall monitoring of the electronic device. The processor 810 can include one or more processing units; preferably, the processor 810 can integrate an application processor and a modem processor, wherein the application processor mainly processes an operating system, a user interface, and application programs, and the modem processor mainly processes wireless communication. It can be understood that the above-mentioned modem processor can also not be integrated into the processor 810.

[0104] The electronic device 800 can further include a power supply 811 (such as a battery) for supplying power to each component; preferably, the power supply 811 can be logically connected to the processor 810 through a power management system, so as to realize functions such as management of charging, discharging, and power consumption management through the power management system.

[0105] In addition, the electronic device 800 includes some functional modules which are not shown and will not be described herein.

[0106] It should be noted that, in this document, the term "comprising" or "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article, or apparatus including a series of elements not only includes those elements, but also includes other elements not explicitly listed, or further includes elements inherent to such a process, method, article, or apparatus. Without more limitations, the element defined by the statement "including a" does not exclude the presence of additional identical elements in the process, method, article, or apparatus including the element.

[0107] Those skilled in the art can clearly understand that the above-mentioned embodiment method can be realized by means of software and necessary general hardware platform, of course, it can also be realized by hardware, but in many cases, the former is a better embodiment. Based on such understanding, the technical solutions of the present application can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes a plurality of instructions for making a terminal (which can be a mobile phone, computer, server, air conditioner, or network device) execute the method described in each embodiment of the present application.

[0108] The embodiments of the present application are described above with reference to the accompanying drawings, but the present application is not limited to the above-mentioned specific embodiments, and the above-mentioned specific embodiments are only illustrative, not restrictive. Those skilled in the art can make many forms without departing from the purpose of the present application and the scope protected by the claims under the inspiration of the present application, which all belong to the protection of the present application.

[0109] Those skilled in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed in the embodiments of the present application can be realized by electronic hardware or a combination of computer software and electronic hardware. Whether the functions are realized in hardware or software depends on the specific application and design constraints of the technical solutions. Those skilled in the art can use different methods to realize the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.

[0110] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process of the above-mentioned system, device and unit can refer to the corresponding process in the foregoing method embodiments, which will not be repeated here.

[0111] In the embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are only illustrative, for example, the division of the units is only a logical function division, and actual implementation can have another division manner, for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the displayed or discussed units can be indirect coupling or communication connection through some interfaces, devices or units, which can be electrical, mechanical or other forms.

[0112] The units described as separate components may or may not be physically separate, and the components displayed as units may or may not be physical units, that is, may be located in one place, or may be distributed on multiple network units. Part or all of the units can be selected according to actual needs to achieve the purpose of the embodiment scheme.

[0113] In addition, each functional unit in each embodiment of the application can be integrated in one processing unit, or each unit can be physically present alone, or two or more units can be integrated in one unit.

[0114] If the functions are realized in the form of software functional units and sold or used as independent products, they can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the application or the part of the prior art that contributes essentially or the part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes a plurality of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the application. The foregoing storage medium includes various storage media that can store program codes, such as a U disk, a mobile hard disk, a ROM, a RAM, a magnetic disk or an optical disk.

[0115] The above is only a specific embodiment of the application, but the protection scope of the application is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical range disclosed by the application, which should be covered within the protection scope of the application. Therefore, the protection scope of the application should be subject to the protection scope of the claims.

Claims

1. A network vulnerability scanning system, characterized in that, The scanning system includes at least one local CPE located on the user's intranet, a cloud-based CPE located in the cloud, and at least two scanners communicatively connected to the cloud-based CPE. The cloud-based CPE is configured with a virtual network interface for network vulnerability scanning. The local CPE is configured with a network identifier for accessing the virtual network interface. Through the cooperation between the network identifier and the virtual network interface, a vulnerability scanning tunnel is constructed between the local CPE and the cloud-based CPE for network vulnerability scanning. The vulnerability scanning tunnel is a virtual extended LAN Layer 2 tunnel built based on a 5G slice leased line, used to achieve Layer 2 network isolation and interconnection between the local CPE and the cloud-based CPE. The at least two scanners are heterogeneous scanners. The cloud-based CPE is used to acquire network vulnerability scanning tasks, extract the target IP address corresponding to the target object to be scanned from the network vulnerability scanning tasks, and send the target IP address to at least two scanners. The scanner is configured to perform network vulnerability detection on the target object based on the target IP address, generate vulnerability detection results corresponding to the target object, and return the vulnerability detection results to the target local CPE corresponding to the target IP address; The target local CPE is used to transmit the vulnerability detection results to the corresponding user management terminal, so that the vulnerability detection results can be displayed through the user management terminal.

2. The scanning system according to claim 1, characterized in that, The cloud-based CPE is also configured to, if there are at least two network vulnerability scanning tasks, obtain the request time corresponding to each of the network vulnerability scanning tasks, and send the target IP addresses corresponding to the at least two network vulnerability scanning tasks to at least two scanners in the order of the request times.

3. The scanning system according to claim 2, characterized in that, The cloud-based CPE is further configured to, if the request times corresponding to the at least two network vulnerability scanning tasks are the same, obtain the importance value corresponding to the user to which each network vulnerability scanning task belongs, and send the target IP address corresponding to the at least two network vulnerability scanning tasks to the at least two scanners in descending order of the importance value.

4. The scanning system according to claim 3, characterized in that, The cloud-based CPE is further configured to, if the request times corresponding to the at least two network vulnerability scanning tasks are the same and the importance values ​​are equal, obtain the task volume corresponding to each of the network vulnerability scanning tasks respectively, and send the target IP addresses corresponding to the at least two network vulnerability scanning tasks to the at least two scanners respectively in order of the size of the task volume.

5. The scanning system according to claim 1, characterized in that, The local CPE is communicatively connected to user terminals located on the same user intranet; wherein... The local CPE is used to obtain the user's intranet IP address and gateway information from the user terminal.

6. The scanning system according to claim 1, characterized in that, It also includes a cloud switch located in the cloud and communicating with the cloud-based CPE, the cloud switch communicating with the at least two scanners respectively.

7. The scanning system according to claim 1, characterized in that, The target objects include at least one of the following: business systems and office networks.

8. A method for scanning network vulnerabilities, characterized in that, The scanning system includes at least one local CPE located on the user's intranet, a cloud-based CPE located in the cloud, and at least two scanners communicatively connected to the cloud-based CPE. The cloud-based CPE is configured with a virtual network interface for network vulnerability scanning, and the local CPE is configured with a network identifier for accessing the virtual network interface. Through the cooperation between the network identifier and the virtual network interface, a vulnerability scanning tunnel for network vulnerability scanning is constructed between the local CPE and the cloud-based CPE. The vulnerability scanning tunnel is a virtual extended LAN Layer 2 tunnel built based on 5G slice leased lines, used to achieve Layer 2 network isolation and interconnection between the local CPE and the cloud-based CPE. The at least two scanners are heterogeneous scanners; the method includes: The network vulnerability scanning task is obtained through the cloud-based CPE, and the target IP address corresponding to the target object to be scanned is extracted from the network vulnerability scanning task. The target IP address is then sent to at least two of the scanners. The scanner performs network vulnerability detection on the target object based on the target IP address, generates vulnerability detection results corresponding to the target object, and returns the vulnerability detection results to the target local CPE corresponding to the target IP address. The vulnerability detection results are transmitted to the corresponding user management terminal via the target local CPE, so that the vulnerability detection results can be displayed on the user management terminal.

9. An electronic device, characterized in that, It includes a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other through the communication bus; The memory is used to store computer programs; When the processor executes a program stored in the memory, it implements the method as described in claim 8.

10. A computer-readable storage medium having instructions stored thereon that, when executed by one or more processors, cause the processors to perform the method of claim 8.

Citation Information

Patent Citations

  • Host security scanning method, device, electronic equipment and system

    CN114866327A

  • Network scanning system

    WO2018007917A1