A network security assessment method, device, equipment and storage medium

CN116582360BActive Publication Date: 2025-10-03GUANGDONG POWER GRID CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310802100.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-06-30
Publication Date
2025-10-03
Estimated Expiration
2043-06-30

AI Technical Summary

Technical Problem

[0003]然而,目前现有的有线通信方式和公网4G、WIFI(Wireless Fidelity,WIFI)等传统的无线通信技术存在信号覆盖弱、流量费用高等问题,已无法满足需求,此外,现有技术还存在安全缺陷,没有信息安全保护措施,容易受到攻击

Benefits of technology

[0024]The technical solution of this embodiment obtains resource data of three devices associated with the network under test: the terminal device, the wireless access point device, and the authentication server, and constructs a corresponding device model based on the resource data. The device anomaly judgment result is determined based on the first resource data and the second resource data. Then, the data exchange transmission between the terminal device, the wireless access point device, and the authentication server is simulated through a data transmission link to obtain an interactive authentication result. Finally, a network security assessment is performed on the network under test by determining the device anomaly judgment result and the interactive authentication result between the device models. The above technical solution performs an initial judgment on the network under test based on the device anomaly judgment result; based on the data transmission link, the data exchange transmission between the terminal device, the wireless access point device, and the authentication server is obtained to obtain an interactive authentication result, and a secondary judgment is performed on the network under test to obtain a network security assessment result, thereby improving the accuracy of the network security assessment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116582360B_ABST
    Figure CN116582360B_ABST
Patent Text Reader

Abstract

The present invention discloses a network security assessment method, apparatus, device, and storage medium. The method includes: obtaining first resource data of a terminal device associated with a network under test, second resource data of an associated wireless access point device, and third resource data of an associated authentication server; constructing a first device model based on the first resource data, a second device model based on the second resource data, and a third device model based on the third resource data; determining a device anomaly determination result based on the first resource data and the second resource data; establishing a data transmission link between the first device model, the second device model, and the third device model; simulating data exchange between the terminal device, the wireless access point device, and the authentication server to obtain an interactive authentication result; and performing a network security assessment on the network under test to obtain a network security assessment result. The technical solution of the present invention improves the accuracy of network security assessments.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a network security assessment method, apparatus, device and storage medium. Background Art

[0002] With the development of digital transformation and digital power grids, new intelligent services such as robot inspection, smart safety monitoring, and mobile office have emerged in substations, which are of great significance to the construction of smart grids. Therefore, whether the terminal equipment of substations can be securely connected to the network has become crucial.

[0003] However, existing wired communication methods and traditional wireless communication technologies such as public 4G and WIFI (Wireless Fidelity, WIFI) have problems such as weak signal coverage and high traffic costs, and can no longer meet the needs. In addition, existing technologies also have security flaws and lack information security protection measures, making them vulnerable to attacks. Summary of the Invention

[0004] The present invention provides a network security assessment method, apparatus, device and storage medium to improve the accuracy of network security assessment.

[0005] According to one aspect of the present invention, a network security assessment method is provided, the method comprising:

[0006] Acquire first resource data of a terminal device associated with the network to be tested, second resource data of an associated wireless access point device, and third resource data of an associated authentication server;

[0007] constructing a first device model according to the first resource data, constructing a second device model according to the second resource data, and constructing a third device model according to the third resource data;

[0008] determining a device abnormality judgment result based on the first resource data and the second resource data;

[0009] establishing a data transmission link between the first device model, the second device model, and the third device model;

[0010] Based on the data transmission link, simulating data interactive transmission between the terminal device, the wireless access point device and the authentication server to obtain an interactive authentication result;

[0011] A network security assessment is performed on the network to be tested according to the device abnormality judgment result and the interactive authentication result to obtain a network security assessment result.

[0012] According to another aspect of the present invention, there is provided a network security assessment device, comprising:

[0013] A resource data acquisition module, configured to acquire first resource data of a terminal device associated with the network to be tested, second resource data of an associated wireless access point device, and third resource data of an associated authentication server;

[0014] a device model construction module, configured to construct a first device model according to the first resource data, a second device model according to the second resource data, and a third device model according to the third resource data;

[0015] an equipment abnormality judgment module, configured to determine an equipment abnormality judgment result based on the first resource data and the second resource data;

[0016] a transmission link establishing module, configured to establish a data transmission link between the first device model, the second device model, and the third device model;

[0017] an interactive authentication result module, configured to simulate data interactive transmission between the terminal device, the wireless access point device, and the authentication server based on the data transmission link to obtain an interactive authentication result;

[0018] The network security evaluation module is used to perform a network security evaluation on the network to be tested according to the device abnormality judgment result and the interactive authentication result to obtain a network security evaluation result.

[0019] According to another aspect of the present invention, an electronic device is provided, comprising:

[0020] at least one processor; and

[0021] a memory communicatively connected to the at least one processor; wherein,

[0022] The memory stores a computer program that can be executed by the at least one processor. The computer program is executed by the at least one processor to enable the at least one processor to perform any network security assessment method described in the embodiments of the present invention.

[0023] According to another aspect of the present invention, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement any network security assessment method described in the embodiments of the present invention when executed.

[0024] The technical solution of this embodiment obtains resource data of three devices associated with the network under test: the terminal device, the wireless access point device, and the authentication server, and constructs a corresponding device model based on the resource data. The device anomaly judgment result is determined based on the first resource data and the second resource data. Then, the data exchange transmission between the terminal device, the wireless access point device, and the authentication server is simulated through a data transmission link to obtain an interactive authentication result. Finally, a network security assessment is performed on the network under test by determining the device anomaly judgment result and the interactive authentication result between the device models. The above technical solution performs an initial judgment on the network under test based on the device anomaly judgment result; based on the data transmission link, the data exchange transmission between the terminal device, the wireless access point device, and the authentication server is obtained to obtain an interactive authentication result, and a secondary judgment is performed on the network under test to obtain a network security assessment result, thereby improving the accuracy of the network security assessment.

[0025] It should be understood that the content described in this section is not intended to identify the key or important features of the embodiments of the present invention, nor is it intended to limit the scope of the present invention. Other features of the present invention will become readily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0026] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0027] Figure 1 This is a flowchart of a network security assessment method provided according to the first embodiment of the present invention;

[0028] Figure 2 This is a flowchart of a network security assessment method provided according to the second embodiment of the present invention;

[0029] Figure 3 This is a schematic diagram of the structure of a network security assessment device provided according to a third embodiment of the present invention;

[0030] Figure 4 It is a structural diagram of an electronic device for implementing the network security assessment method according to an embodiment of the present invention. DETAILED DESCRIPTION

[0031] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of the present invention.

[0032] It should be noted that the terms "first", "second", "third", etc. in the description and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the numbers used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0033] In addition, it should be noted that in the technical solution of the present invention, the collection, storage, use, processing, transmission, provision and disclosure of the first resource data, second resource data and third resource data involved are in compliance with the provisions of relevant laws and regulations and do not violate public order and good morals.

[0034] Example 1

[0035] Figure 1 This is a flowchart of a network security assessment method provided in Example 1 of the present invention. This embodiment is applicable to situations where integrity and interoperability testing and network security assessment are performed on power grid networks. The method can be performed by a network security assessment device, which can be implemented in the form of hardware and / or software. The network security assessment device can be configured in an electronic device, such as a server.

[0036] like Figure 1 As shown, the method includes:

[0037] S110: Acquire first resource data of a terminal device associated with the network to be tested, second resource data of an associated wireless access point device, and third resource data of an associated authentication server.

[0038] The network to be tested refers to a network to be subjected to security assessment. Exemplarily, the network to be tested may be a Wireless LAN Authentication and Privacy Infrastructure (WAPI) network. WAPI is a wireless transmission protocol and a computer network that uses wireless transmission media. A terminal device (Station, STA) is a wireless network terminal entity with input and output functions, such as a laptop computer, a smart phone, or an Internet of Things terminal device that includes WAPI. A wireless access point device (Access Point, AP) is a device that accesses a wireless network, such as a wireless switch. An authentication server (Application Server, AS) is a third-party device that authenticates, identifies, and manages the identities of terminal devices and wireless access point devices.

[0039] The first resource data is the resource data of the terminal device, and the first resource data may include first typed resource data and first intention resource data. The first typed resource data may include basic information, certificates, access duration, system time, and browsing history of the terminal device. The first intention resource may be the terminal device's Internet search history and historically accessed wireless access points as intents, and resources are obtained based on the intents. The second resource data may include second typed resource data and second intention resource data, wherein the second typed resource data may include basic information, certificates, the number of accessed terminal devices, and tag information of the wireless access point device. The second intention resource data may be the wireless access point device's IP (Internet Protocol, IP) address change information and historically allowed access terminals as intents, and second intention resource data is obtained based on the intents. The third resource data may include third typed resource data, and the third typed resource data may include managed certificates, historical authentication records, and digital signature algorithms.

[0040] Specifically, the terminal device, wireless access point device, and authentication server are three devices associated with the network under test. Bidirectional identity authentication and key management can be performed between the terminal device and the wireless access point device, and this operation can be performed by the authentication server. The wireless access point device initiates an authentication request to the authentication server, and the authentication server returns the authentication result to the wireless access point device, thereby establishing a bidirectional trust relationship between the terminal device and the wireless access point device. Furthermore, first resource data of the device, second resource data of the wireless access point device, and third resource data of the associated authentication server are obtained.

[0041] S120: Construct a first device model according to the first resource data, construct a second device model according to the second resource data, and construct a third device model according to the third resource data.

[0042] Among them, the first device model is a model constructed based on the first resource data, and the second device model and the third device model are similar to the first device model. Exemplarily, the first device model, the second device model and the third device model can be the first DIKWP (Date Information Knowledge Wisdom Purpose, DIKWP) model, the second DIKWP model and the DIKW (Date Information Knowledge Wisdom, DIKW) model, respectively. The first DIKWP model, the second DIKWP model and the DIKW model can be knowledge graph models. For example, the DIKWP model includes data graphs, information graphs, knowledge graphs, wisdom graphs and intent graphs, and realizes the interaction and transformation of data, information, knowledge and wisdom through the drive of intent; the first DIKWP model, the second DIKWP model and the DIKW model can also be database models used to store typed resource data and intent resource data, which is not limited in this embodiment.

[0043] Specifically, the first resource data, the second resource data, and the third resource data are used as the data basis for constructing the first device model, the second device model, and the third device model. The specific construction method is: based on the first typed resource data and the first intention resource data, the first device model of the terminal device is constructed; based on the second typed resource data and the second intention resource data, the second device model of the wireless access point device is constructed; based on the third typed resource data, the third device model of the authentication server is constructed.

[0044] Exemplarily, basic information, certificates, access time, system time and browsing history of the terminal device are obtained, wherein the basic information includes the type of terminal device, usage time, specific address, etc., and the basic information of the terminal device and the certificate, access time on the Internet, current system time and browsing history are composed into typed resource data, and the Internet search history of the terminal device and the historically accessed wireless access point devices are obtained as intentions, and intention resources are obtained according to the intentions. For the Internet search history of the terminal device, some potential intentions of the terminal device can be obtained through keyword recognition and judgment, and the obvious intentions of the terminal device itself can be judged through the compliance of its historically accessed wireless access point devices. The intention resource data consists of potential intentions and obvious intentions; a first device model is constructed based on the typed resource data and the intention resource data.

[0045] For another example, basic information, certificates, the number of connected terminal devices, and tag information of a wireless access point device are obtained and formed into second-type resource data. Information on changes in the wireless access point device's IP address and the terminal devices historically permitted to access the device are obtained as intent, and second-intention resource data is obtained based on the intent. For wireless access point devices, their IP addresses generally remain consistent under normal use, while the IP addresses of some illegal or illegitimate wireless access point devices often change. This can be used to determine possible illegal intent of the wireless access point device. Furthermore, the status of the wireless access point device can be determined by determining whether the terminal devices historically permitted to access the wireless access point device are compliant. The above content constitutes the second-intention resource data of the wireless access point device; a second device model is constructed based on the second-type resource data and the second-intention resource data.

[0046] For another example, since the authentication server itself is a trustworthy third party, there is no so-called latent intention or obvious intention. It is only necessary to obtain its basic information and then build a third device model.

[0047] It should be noted that by utilizing typed resource data and intent resource data to construct a device model, the data richness of the device model is increased, and the use of a multivariate database reduces the amount of computation to improve evaluation efficiency.

[0048] S130. Determine a device abnormality judgment result based on the first resource data and the second resource data.

[0049] The device abnormality judgment result refers to whether the terminal device and the wireless access point device are legal.

[0050] Specifically, the legality of the terminal device is determined according to the first device model, thereby determining whether the terminal device is a normal device. If the terminal device is legal, the terminal device is a normal device; otherwise, the terminal device is an abnormal device. The legality of the wireless access point device is determined according to the second device model, that is, whether the wireless access point device is a normal device. If the wireless access point device is legal, the wireless access point device is a normal device; otherwise, the wireless access point device is an abnormal device.

[0051] Optionally, a device abnormality judgment result is determined based on the first resource data and the second resource data, including: determining whether the terminal device is an abnormal device based on the first typed resource data and the first intention resource data, and obtaining a first abnormality judgment result; determining whether the wireless access point device is an abnormal device based on the second typed resource data and the second intention resource data, and obtaining a second abnormality judgment result; generating a device abnormality judgment result including the first abnormality judgment result and the second abnormality judgment result.

[0052] Specifically, the judgment result of whether the terminal device is an abnormal device is used as the first abnormal judgment result. If the terminal device is an abnormal device, the first abnormal judgment result is that the terminal device is an abnormal device. Similarly, if the wireless access point device is an abnormal device, the second abnormal judgment result is that the wireless access point device is an abnormal device. The device abnormal judgment result is determined based on the first abnormal judgment result and the second abnormal judgment result. If at least one of the first abnormal judgment result or the second abnormal judgment result is an abnormal device, the device abnormal judgment result is that the device is abnormal.

[0053] For example, if the terminal device is a smart phone that can access a wireless network, the first type of resource data of the terminal device, such as the basic information of the terminal device, certificate, access time, system time and browsing history, as well as the search history of the smart phone on the Internet, such as searching on the Internet for how to crack a firewall, how to bypass the firewall, etc., is used as the first intention resource data. The first type of resource data and the first intention resource data are used to determine whether the terminal device is an abnormal device. For example, it is possible to determine whether the terminal device is an abnormal device by determining whether there is abnormal basic information, abnormal certificate, abnormal access time, abnormal system time and abnormal browsing history. If one of them is abnormal, the terminal device is considered to be an abnormal device. Alternatively, it is possible to determine whether the terminal device is an abnormal device by determining whether the search history of the smart phone on the Internet is abnormal. If the search history of the smart phone is abnormal, the terminal device is considered to be an abnormal device. At the same time, when the wireless access point that the terminal device has accessed is listed as an unsafe access point, the terminal can also be determined to be an abnormal device. For another example, if a wireless access point device's IP address changes frequently and the span is large, it can be judged as a fake wireless access point, that is, the wireless access point device is an abnormal device. At the same time, if the terminal device it once allowed access to is also listed as an unsafe terminal, it can be judged that the wireless access point device is an abnormal device.

[0054] The above technical solution lays the foundation for subsequent network security assessment by determining whether the terminal device and wireless access point device are abnormal devices, making the network security assessment more accurate.

[0055] S140: Establish a data transmission link among the first device model, the second device model, and the third device model.

[0056] The data transmission link is a data exchange communication link between the first device model, the second device model, and the third device model. Optionally, the data transmission link includes a first data transmission link and a second data transmission link, wherein the first data transmission link is a data transmission link between the first device model and the second device model, and the second data transmission link is a data transmission link between the second device model and the third device model.

[0057] Specifically, a data transmission link is established between the first device model, the second device model, and the third device model via wired or wireless communication. The data transmission link includes a request link and a response link. Data is transmitted between the first device model and the second device model via the request link and the response link, and data is transmitted between the second device model and the third device model via the request link and the response link.

[0058] S150: Based on the data transmission link, simulate the data interactive transmission between the terminal device, the wireless access point device and the authentication server to obtain an interactive authentication result.

[0059] The interactive authentication result is a simulated authentication result between the first device model, the second device model, and the third device model. Specifically, when the two-way identity recognition between the terminal device and the wireless access point device is passed, the wireless access point device allows the terminal device to access the network.

[0060] Specifically, based on the data transmission link, an interactive authentication result between the terminal device and the wireless access point device is simulated, and an interactive authentication result between the wireless access point device and the authentication server is simulated.

[0061] S160: Perform a network security assessment on the network to be tested based on the device abnormality judgment result and the interactive authentication result to obtain a network security assessment result.

[0062] The network security assessment result refers to whether the network under test is secure or unsecure.

[0063] Specifically, the security assessment result of the network to be tested is jointly determined by the device abnormality judgment result and the interactive authentication result. The specific assessment method is: if the first abnormality judgment result and the second abnormality judgment result in the device abnormality judgment result are both that the device is normal, and the interactive authentication result is that the authentication is passed, then the network security assessment result is that the security assessment is passed; if the first abnormality judgment result or the second abnormality judgment result in the device abnormality judgment result is that the device is abnormal, and the interactive authentication result is that the authentication is passed, then the network security assessment result is that the security assessment fails; if the first abnormality judgment result or the second abnormality judgment result in the device abnormality judgment result is that the device is abnormal, and the interactive authentication result is that the authentication is failed, then the network security assessment result is that the security assessment fails.

[0064] The technical solution of this embodiment obtains resource data of three devices associated with the network under test: the terminal device, the wireless access point device, and the authentication server, and constructs a corresponding device model based on the resource data. The device anomaly judgment result is determined based on the first resource data and the second resource data. Then, the data exchange transmission between the terminal device, the wireless access point device, and the authentication server is simulated through a data transmission link to obtain an interactive authentication result. Finally, a network security assessment is performed on the network under test by determining the device anomaly judgment result and the interactive authentication result between the device models. The above technical solution performs an initial judgment on the network under test based on the device anomaly judgment result; based on the data transmission link, the data exchange transmission between the terminal device, the wireless access point device, and the authentication server is obtained to obtain an interactive authentication result, and a secondary judgment is performed on the network under test to obtain a network security assessment result, thereby improving the accuracy of the network security assessment.

[0065] Example 2

[0066] Figure 2 This is a flowchart of a network security assessment method provided in Example 2 of the present invention. This embodiment further refines the above-mentioned embodiments. Specifically, the process of "based on the data transmission link, simulating the data interaction transmission between the terminal device, the wireless access point device, and the authentication server to obtain an interactive authentication result" is refined into "based on the first data transmission link, simulating the data interaction transmission between the terminal device and the wireless access point to obtain a first interactive result; based on the second data transmission link, simulating the data interaction transmission between the wireless access point and the authentication server to obtain a second interactive result; and determining an interactive authentication result based on the first and second interactive results" to improve the network security assessment mechanism. It should be noted that for portions not detailed in this embodiment of the present invention, reference can be made to the relevant descriptions of other embodiments and will not be repeated here.

[0067] like Figure 2 As shown, the method includes:

[0068] S110: Acquire first resource data of a terminal device associated with the network to be tested, second resource data of an associated wireless access point device, and third resource data of an associated authentication server.

[0069] S220: Construct a first device model according to the first resource data, construct a second device model according to the second resource data, and construct a third device model according to the third resource data.

[0070] S230: Determine a device abnormality judgment result based on the first resource data and the second resource data.

[0071] S240: Establish a data transmission link among the first device model, the second device model, and the third device model.

[0072] S250: Based on the first data transmission link, simulate data interaction transmission between the terminal device and the wireless access point device to obtain a first interaction result.

[0073] S260: Based on the second data transmission link, simulate the data interaction transmission between the wireless access point device and the authentication server to obtain a second interaction result.

[0074] S270: Determine an interactive authentication result according to the first interaction result and the second interaction result.

[0075] Specifically, the first device model and the second device model exchange data via the request link and the response link. Simultaneously, the second device model also exchanges data with the third device model via the request link and the response link, enabling simulated authentication access and interactive data transmission. Specifically, based on the first data transmission link, the first device model initiates an access request to the second device model via the request link, and the second device model sends an access authentication response to the first device model via the response link. The second device model sends a key negotiation request to the first device model via the request link, and the first device model sends a key negotiation response to the second device model via the response link. The second device model sends a multicast key announcement to the first device model via the request link, and the first device model sends a multicast key response to the second device model via the response link. If the access request, access authentication response, key negotiation request, key negotiation response, multicast key announcement, and multicast key response between the first and second device models all operate normally, the first interaction result is passed. The second device model initiates a certificate authentication request to the third device model via the request link, and the third device model sends a certificate authentication response to the second device model via the response link. If both the certificate authentication request and certificate authentication response operate normally, the second interaction result is passed. A key agreement request is a negotiation between two or more entities to jointly establish a session key. Any participant can influence the outcome, without requiring a trusted third party. Multicast key announcement is a communication method in which one or more senders transmit data to multiple listeners. If both the first and second interaction results pass, the interactive authentication result is considered passed. If at least one of the first and second interaction results fails, the interactive authentication result is considered failed.

[0076] The technical solution of this embodiment simulates data exchange between a terminal device and a wireless access point device to obtain a first interaction result; simulates data exchange between the wireless access point device and an authentication server to obtain a second interaction result; and then determines an interaction authentication result based on the first and second interaction results. This technical solution, through the issuance of a certificate by a third-party authentication server, ensures that when a terminal device accesses the wireless access point device, both parties must authenticate their identities through the authentication server, thus ensuring the legitimacy of both the terminal device and the wireless access point device and providing comprehensive security for the network.

[0077] Example 3

[0078] Figure 3 This is a structural diagram of a network security assessment device provided in Example 3 of the present invention. This embodiment is applicable to situations where integrity and interoperability testing and network security assessment of power grid networks are performed. The network security assessment device can be implemented in the form of hardware and / or software. The network security assessment device can be configured in an electronic device, such as a server.

[0079] like Figure 3 As shown, the apparatus includes a resource data acquisition module 310 , a device model construction module 320 , a device anomaly judgment module 330 , a transmission link establishment module 340 , an interactive authentication result module 350 and a network security assessment module 360 ​​.

[0080] The resource data acquisition module 310 is configured to acquire first resource data of a terminal device associated with the network to be tested, second resource data of an associated wireless access point device, and third resource data of an associated authentication server;

[0081] The device model construction module 320 is configured to construct a first device model based on the first resource data, a second device model based on the second resource data, and a third device model based on the third resource data;

[0082] The device abnormality judgment module 330 is used to determine a device abnormality judgment result based on the first resource data and the second resource data;

[0083] The transmission link establishing module 340 is used to establish a data transmission link between the first device model, the second device model and the third device model;

[0084] An interactive authentication result module 350 is configured to simulate data interaction between the terminal device, the wireless access point device, and the authentication server based on the data transmission link to obtain an interactive authentication result;

[0085] The network security assessment module 360 ​​is used to perform a network security assessment on the network to be tested based on the device anomaly judgment result and the interactive authentication result to obtain a network security assessment result.

[0086] The technical solution of this embodiment obtains resource data of three devices associated with the network under test: the terminal device, the wireless access point device, and the authentication server, and constructs a corresponding device model based on the resource data. The device anomaly judgment result is determined based on the first resource data and the second resource data. Then, the data exchange transmission between the terminal device, the wireless access point device, and the authentication server is simulated through a data transmission link to obtain an interactive authentication result. Finally, a network security assessment is performed on the network under test by determining the device anomaly judgment result and the interactive authentication result between the device models. The above technical solution performs an initial judgment on the network under test based on the device anomaly judgment result; based on the data transmission link, the data exchange transmission between the terminal device, the wireless access point device, and the authentication server is obtained to obtain an interactive authentication result, and a secondary judgment is performed on the network under test to obtain a network security assessment result, thereby improving the accuracy of the network security assessment.

[0087] Optionally, the first resource data includes first typed resource data and first intended resource data; the second resource data includes second typed resource data and second intended resource data; and the third resource data includes third typed resource data.

[0088] Accordingly, a first device model is constructed according to the first resource data, a second device model is constructed according to the second resource data, and a third device model is constructed according to the third resource data. The device model construction module 320 includes:

[0089] A first model building unit, configured to build a first device model of the terminal device according to the first typed resource data and the first intention resource data;

[0090] A second model building unit, configured to build a second device model of the wireless access point device according to the second typed resource data and the second intention resource data;

[0091] The third model building unit is configured to build a third device model of the authentication server according to the third typed resource data.

[0092] Optionally, the device abnormality determination result is determined based on the first resource data and the second resource data. The device abnormality determination module 330 includes:

[0093] A first abnormality subunit is configured to determine whether the terminal device is an abnormal device according to the first typed resource data and the first intended resource data, and obtain a first abnormality judgment result;

[0094] A second abnormality subunit is configured to determine whether the wireless access point device is an abnormal device according to the second typed resource data and the second intended resource data, and obtain a second abnormality judgment result;

[0095] The device abnormality subunit is used to generate a device abnormality judgment result including a first abnormality judgment result and a second abnormality judgment result.

[0096] Optionally, the data transmission link includes a first data transmission link between the first device model and the second device model and a second data transmission link between the second device model and the third device model; based on the data transmission link, data interactive transmission between the terminal device, the wireless access point device, and the authentication server is simulated to obtain an interactive authentication result, and the interactive authentication result module 350 is specifically configured to:

[0097] Based on the first data transmission link, simulate the data interaction transmission between the terminal device and the wireless access point to obtain a first interaction result;

[0098] Based on the second data transmission link, simulate the data interaction transmission between the wireless access point and the authentication server to obtain a second interaction result;

[0099] The interactive authentication result unit is used to determine the interactive authentication result according to the first interaction result and the second interaction result.

[0100] Optionally, the device abnormality judgment result includes whether the device is normal or abnormal. Accordingly, based on the device abnormality judgment result and the interactive authentication result, a network security assessment is performed on the network to be tested to obtain a network security assessment result. The network security assessment module 360 ​​is specifically configured to:

[0101] If both the first abnormality judgment result and the second abnormality judgment result in the device abnormality judgment result indicate that the device is normal, and the interactive authentication result indicates that the authentication is passed, then the network security assessment result is security assessment passed.

[0102] If the first abnormality judgment result or the second abnormality judgment result in the device abnormality judgment result is both device abnormality, and the interactive authentication result is authentication failure, then the network security assessment result is security assessment passed;

[0103] If the first abnormality judgment result or the second abnormality judgment result in the device abnormality judgment result is both device abnormality, and the interactive authentication result is authentication passed, the network security assessment result is security assessment failed.

[0104] The network security assessment device provided in the embodiment of the present invention can execute the network security assessment method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the execution method.

[0105] Example 4

[0106] Figure 4 Schematic diagram of the structure of an electronic device that implements the network security assessment method of an embodiment of the present invention. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital assistants, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or claimed herein.

[0107] like Figure 4 As shown, the electronic device 10 includes at least one processor 11, and a memory connected to the at least one processor 11, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc., wherein the memory stores a computer program that can be executed by the at least one processor, and the processor 11 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 to the random access memory (RAM) 13. Various programs and data required for the operation of the electronic device 10 can also be stored in the RAM 13. The processor 11, ROM 12 and RAM 13 are connected to each other via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.

[0108] Multiple components in the electronic device 10 are connected to the I / O interface 15, including an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a magnetic disk, an optical disk, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.

[0109] The processor 11 can be any general-purpose and / or specialized processing component with processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various specialized artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any other suitable processor, controller, microcontroller, etc. The processor 11 executes the various methods and processes described above, such as the network security assessment method.

[0110] In some embodiments, the network security assessment method can be implemented as a computer program that is tangibly contained in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program can be loaded and / or installed on electronic device 10 via ROM 12 and / or communication unit 19. When the computer program is loaded into RAM 13 and executed by processor 11, one or more steps of the network security assessment method described above can be performed. Alternatively, in other embodiments, processor 11 can be configured to perform the network security assessment method in any other appropriate manner (e.g., by means of firmware).

[0111] Various embodiments of the systems and techniques described herein can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), system-on-chip systems (SOCs), programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include being implemented in one or more computer programs that are executable and / or interpreted on a programmable system that includes at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.

[0112] Computer programs for implementing the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the computer program is executed by the processor, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The computer program may be executed entirely on the machine, partially on the machine, as a stand-alone software package, partially on the machine and partially on a remote machine, or entirely on a remote machine or server.

[0113] In the context of the present invention, computer-readable storage media can be tangible media that can contain or store a computer program for use with an instruction execution system, device or equipment or used in combination with an instruction execution system, device or equipment. Computer-readable storage media can include but are not limited to electronic, magnetic, optical, electromagnetic, infrared or semiconductor systems, devices or equipment, or any suitable combination of the foregoing. Alternatively, computer-readable storage media can be machine-readable signal media. More specific examples of machine-readable storage media can include electrical connections based on one or more lines, portable computer disks, hard disks, random access memories (RAM), read-only memories (ROM), erasable programmable read-only memories (EPROM or flash memory), optical fibers, portable compact disk read-only memories (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.

[0114] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user can provide input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).

[0115] The systems and techniques described herein can be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer with a graphical user interface or web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.

[0116] A computing system may include clients and servers. The clients and servers are typically remote from each other and typically interact via a communication network. This client-server relationship arises through computer programs running on the respective computers, creating a client-server relationship. The server may be a cloud server, also known as a cloud computing server or cloud host. This server is a hosting product within the cloud computing service ecosystem that addresses the management difficulties and limited scalability of traditional physical hosting and VPS services.

[0117] It should be understood that the various forms of the processes shown above can be used to reorder, add, or delete steps. For example, the steps described in the present invention can be performed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of the present invention can be achieved. This is not limited herein.

[0118] The above specific embodiments do not limit the scope of protection of the present invention. Those skilled in the art will appreciate that various modifications, combinations, sub-combinations, and substitutions may be made based on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention are intended to be included within the scope of protection of the present invention.

Claims

1. A network security assessment method, characterized in that: include: Obtain first resource data of a terminal device associated with the network to be tested, second resource data of an associated wireless access point device, and third resource data of an associated authentication server; wherein the first resource data includes first typed resource data and first intended resource data; the second resource data includes second typed resource data and second intended resource data; the third resource data includes third typed resource data; the first typed resource data includes basic information, certificates, Internet access duration, current system time, and browsing history of the terminal device; the first intended resource data includes Internet search records and historically accessed wireless access point devices of the terminal device; the second typed resource data includes basic information, certificates, number of accessed terminal devices, and tag information of the wireless access point device; the second intended resource data includes IP address change information of the wireless access point device and historically allowed access terminal devices; the third typed resource data includes basic information of the authentication server; constructing a first device model according to the first resource data, constructing a second device model according to the second resource data, and constructing a third device model according to the third resource data; determining a device abnormality judgment result based on the first resource data and the second resource data; establishing a data transmission link between the first device model, the second device model, and the third device model; Based on the data transmission link, simulating data interactive transmission between the terminal device, the wireless access point device and the authentication server to obtain an interactive authentication result; Performing a network security assessment on the network to be tested according to the device abnormality determination result and the interactive authentication result to obtain a network security assessment result; The step of constructing a first device model according to the first resource data, constructing a second device model according to the second resource data, and constructing a third device model according to the third resource data includes: Constructing a first device model of the terminal device according to the first typed resource data and the first intention resource data; Constructing a second device model of the wireless access point device according to the second typed resource data and the second intended resource data; A third device model of the authentication server is constructed according to the third typed resource data.

2. The method according to claim 1, characterized in that The determining, based on the first resource data and the second resource data, a device abnormality judgment result, includes: determining, based on the first typed resource data and the first intended resource data, whether the terminal device is an abnormal device, and obtaining a first abnormality judgment result; determining, based on the second typed resource data and the second intended resource data, whether the wireless access point device is an abnormal device, and obtaining a second abnormality determination result; An equipment abnormality judgment result including the first abnormality judgment result and the second abnormality judgment result is generated.

3. The method according to claim 1, characterized in that The data transmission link includes a first data transmission link between the first device model and the second device model and a second data transmission link between the second device model and the third device model; Based on the data transmission link, simulating data interaction transmission between the terminal device, the wireless access point device, and the authentication server to obtain an interactive authentication result, including: Based on the first data transmission link, simulate the data interaction transmission between the terminal device and the wireless access point device to obtain a first interaction result; simulating data interaction transmission between the wireless access point device and the authentication server based on the second data transmission link to obtain a second interaction result; An interactive authentication result is determined according to the first interaction result and the second interaction result.

4. The method according to claim 2, characterized in that The device abnormality judgment result includes whether the device is normal or abnormal. Accordingly, the network security assessment is performed on the network to be tested based on the device abnormality judgment result and the interactive authentication result to obtain a network security assessment result, including: If both the first abnormality judgment result and the second abnormality judgment result in the device abnormality judgment result indicate that the device is normal, and the interactive authentication result indicates that the authentication is passed, then the network security assessment result indicates that the security assessment is passed. If the first abnormality judgment result or the second abnormality judgment result in the device abnormality judgment result is a device abnormality, and the interactive authentication result is authentication failure, then the network security assessment result is security assessment failure; If the first abnormality judgment result or the second abnormality judgment result in the device abnormality judgment result is device abnormality, and the interactive authentication result is authentication passed, then the network security assessment result is security assessment failed.

5. A network security assessment device, characterized in that: include: A resource data acquisition module, configured to acquire first resource data of a terminal device associated with the network to be tested, second resource data of an associated wireless access point device, and third resource data of an associated authentication server; wherein the first resource data includes first typed resource data and first intended resource data; the second resource data includes second typed resource data and second intended resource data; the third resource data includes third typed resource data; the first typed resource data includes basic information, certificates, Internet access duration, current system time, and browsing history of the terminal device; the first intended resource data includes Internet search history and historically accessed wireless access point devices of the terminal device; the second typed resource data includes basic information, certificates, number of accessed terminal devices, and tag information of the wireless access point device; the second intended resource data includes IP address change information of the wireless access point device and historically allowed access terminal devices; the third typed resource data includes basic information of the authentication server; a device model construction module, configured to construct a first device model according to the first resource data, a second device model according to the second resource data, and a third device model according to the third resource data; an equipment abnormality judgment module, configured to determine an equipment abnormality judgment result based on the first resource data and the second resource data; a transmission link establishing module, configured to establish a data transmission link between the first device model, the second device model, and the third device model; an interactive authentication result module, configured to simulate data interactive transmission between the terminal device, the wireless access point device, and the authentication server based on the data transmission link to obtain an interactive authentication result; A network security assessment module, configured to perform a network security assessment on the network to be tested based on the device abnormality judgment result and the interactive authentication result, and obtain a network security assessment result; Wherein, the device model construction module includes: A first model building unit, configured to build a first device model of the terminal device according to the first typed resource data and the first intention resource data; A second model building unit, configured to build a second device model of the wireless access point device according to the second typed resource data and the second intention resource data; The third model building unit is configured to build a third device model of the authentication server according to the third typed resource data.

6. The apparatus according to claim 5, wherein the data transmission link comprises a first data transmission link between the first device model and the second device model and a second data transmission link between the second device model and the third device model; Based on the data transmission link, simulating data interaction transmission between the terminal device, the wireless access point device, and the authentication server to obtain an interactive authentication result, including: A first interaction result unit is configured to simulate data interaction transmission between the terminal device and the wireless access point based on the first data transmission link to obtain a first interaction result; a second interaction result unit, configured to simulate data interaction transmission between the wireless access point and the authentication server based on the second data transmission link to obtain a second interaction result; The interaction result authentication unit is used to determine an interaction authentication result according to the first interaction result and the second interaction result.

7. An electronic device, characterized in that: The electronic device comprises: at least one processor; and a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor. The computer program is executed by the at least one processor to enable the at least one processor to perform the network security assessment method according to any one of claims 1 to 4.

8. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the network security assessment method according to any one of claims 1 to 4 when executed.

Citation Information

Patent Citations

  • NB-IOT network problem positioning method and device

    CN110896547A

  • Modeling cyber-physical attack paths in the internet-of-things

    US20200162500A1