Asset Risk Assessment Method and Device Based on Simulated Penetration Attack and White-Box Testing
Through simulated penetration attacks and white box testing, combined with deep learning technology, continuous risk monitoring and analysis of power system assets is achieved, solving the problem of difficulty in discovering and responding to new outbreaks in the existing technology in a timely manner, and improving the security and stability of the system.
Patent Information
- Application Number
- CN202410300275.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-03-15
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2044-03-15
AI Technical Summary
It is difficult for the existing technology to realize continuous risk monitoring and analysis of power system assets, making it difficult for the system to detect and deal with new outbreaks when hacker attack methods are updated.
The asset risk assessment method based on simulated penetration attacks and white box testing is adopted to carry out penetration attacks on the target through the simulated attacker's perspective, collect attack link information, conduct continuous white box testing, and use deep learning technology to identify new attack modes to achieve the quantification and evaluation of assets' risks.
It realizes continuous risk monitoring and analysis of power system assets, raises the attack threshold, shortens the repair window period, and enhances the security and stability of the system.
Smart Images

Figure CN118233166B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular, to an asset risk assessment method and device based on simulated penetration attacks and white box testing. Background Art
[0002] In recent years, the ways of hacker attacks have been constantly changing and evolving. It is difficult to obtain accurate answers in the security operation and maintenance mode mainly in the form of audit reports regarding the security defense effect of the power system, whether the latest security defense program has been loaded and upgraded in a timely manner. When facing the increasingly updated attack means, turning passive into active and launching attacks on one's own system in the posture of an attacker can effectively verify the security and stability of one's own system when encountering attacks.
[0003] After comprehensively mastering the power asset information, it is necessary to further clarify the vulnerability situation of all assets, converge known risks such as weak passwords, high-risk vulnerabilities, and unpatched patches in advance, narrow the risk exposure surface, and prevent problems before they occur. When users use traditional black box vulnerability scanning tools, they can only perform scans periodically. During the period when no detection is carried out, newly emerged vulnerabilities are extremely likely to be exploited by hackers to invade. Therefore, it is necessary to achieve continuous monitoring and analysis of risks, change the convergence of known threats from passive to active, deeply discover internal exposure problems and risks, continuously and effectively handle risks, so as to increase the attack threshold and shorten the repair window period. Therefore, the problems and defects existing in the prior art are that the ways of hacker attacks are constantly updated, and it is necessary to continuously monitor and analyze the system and continuously and effectively respond to risks. Summary of the Invention
[0004] The purpose of the present invention is to overcome the defects and problems of poor asset risk assessment effect existing in the prior art, and provide an asset risk assessment method and device based on simulated penetration attacks and white box testing with good asset risk assessment effect.
[0005] To achieve the above purpose, the technical solution of the present invention is: An asset risk assessment method based on simulated penetration attacks and white box testing, comprising:
[0006] Performing simulated penetration attacks on the agreed scope and target from the perspective of an attacker;
[0007] Collecting associated asset information on the attack link and restoring the attacker's attack link;
[0008] Performing continuous white box testing on each node of the attack link and visualizing the full-link attack process;
[0009] Constructing a security analysis view to quantify and evaluate risks for multiple types of assets.
[0010] Using deep learning technology, perform pattern recognition on a large amount of historical attack data to identify new, unknown, or variant attack patterns, and use the attack patterns to simulate penetration attacks on the agreed scope and targets.
[0011] Use the attack patterns to perform automated penetration on the agreed scope and targets to complete asset collection of IP addresses, domain names, hosts, services, credentials, operating systems, application programs, plugins, and network devices;
[0012] The attack patterns include full-scenario penetration attacks, website penetration attacks, intranet environment penetration attacks, and WAF simulation attacks.
[0013] The visualized full-link attack process includes:
[0014] Proactively detect and analyze target risks from multiple perspectives to form multi-dimensional analysis views and attack link diagrams;
[0015] Show specific risks or vulnerabilities in the complete link from target discovery to attack success to present the hacker attack path;
[0016] Generate a topology diagram for the key information collected during the task execution process, identify the risks found in each node, and show the attack relationships between nodes.
[0017] The visualized full-link attack process is achieved through the following methods:
[0018] Collect text information of attack logs and security events;
[0019] Use natural language processing technology to analyze the text information and extract the key entities, events, and relationships;
[0020] Based on the extracted key entity, event, and relationship information, construct a knowledge graph;
[0021] Use the knowledge graph to construct a visualized threat intelligence analysis platform;
[0022] Use the threat intelligence analysis platform to visualize the full-link attack process.
[0023] The construction of the security analysis view quantifies and evaluates the risks of multiple types of assets, including:
[0024] Adopt quantifiable indicators to construct security analysis views in different dimensions;
[0025] Adopt unsupervised learning technology to automatically classify assets;
[0026] Use real-time data stream processing technology, combined with pre-trained machine learning models, to continuously and real-time evaluate the security risks of assets.
[0027] The quantifiable indicators include the length, complexity, number of vulnerabilities, and threat level of the attack chain.
[0028] An asset risk assessment device based on simulated penetration attacks and white box testing, which is applied to the above-mentioned asset risk assessment method based on simulated penetration attacks and white box testing. The device includes:
[0029] A simulated penetration attack module, configured to perform simulated penetration attacks on the agreed scope and target from the perspective of an attacker;
[0030] An attack link restoration module, configured to collect associated asset information on the attack link and restore the attacker's attack link;
[0031] A white box testing module, configured to perform continuous white box testing on each node on the attack link and visualize the full-link attack process;
[0032] An asset risk assessment module, configured to construct a security analysis view and perform risk quantification and assessment on multiple types of assets.
[0033] An asset risk assessment device based on simulated penetration attacks and white box testing, including a memory and a processor;
[0034] The memory is configured to store computer program code and transmit the computer program code to the processor;
[0035] The processor is configured to execute the above-mentioned asset risk assessment method based on simulated penetration attacks and white box testing according to the instructions in the computer program code.
[0036] A computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the above-mentioned asset risk assessment method based on simulated penetration attacks and white box testing is implemented.
[0037] Compared with the prior art, the beneficial effects of the present invention are:
[0038] In the asset risk assessment method and device based on simulated penetration attacks and white box testing of the present invention, the method uses continuous white box testing for monitoring and analysis, converges known threats from passive to active, and continuously and effectively responds to risks, thereby increasing the attack threshold and shortening the repair window period. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] Figure 1 is a flowchart of an asset risk assessment method based on simulated penetration attacks and white box testing of the present invention.
[0040] Figure 2It is a structural block diagram of an asset risk assessment device based on simulated penetration attacks and white box testing according to the present invention.
[0041] Figure 3 It is a structural block diagram of an asset risk assessment device based on simulated penetration attacks and white box testing according to the present invention. Specific implementation manners
[0042] The present invention will be further described in detail below in conjunction with the accompanying drawings and specific implementation manners.
[0043] See Figure 1 , an asset risk assessment method based on simulated penetration attacks and white box testing, including:
[0044] S1. Conduct simulated penetration attacks on the agreed scope and targets from the perspective of an attacker.
[0045] Adopt deep learning technology to perform pattern recognition on a large amount of historical attack data to identify new, unknown or variant attack patterns, and use this attack pattern to conduct simulated penetration attacks on the agreed scope and targets.
[0046] Use the attack pattern to conduct automated penetration on the agreed scope and targets to complete the asset collection of IP addresses, domain names, hosts, services, credentials, operating systems, application programs, plugins, and network devices;
[0047] The attack pattern includes full-scenario penetration attacks, website penetration attacks, intranet environment penetration attacks, and WAF simulation attacks.
[0048] The entire attack process does not require manual access and is completed by the automatic attack script itself.
[0049] S2. Collect the associated asset information on the attack link and restore the attacker's attack link.
[0050] S3. Conduct continuous white box testing on each node on the attack link and visualize the full-link attack process.
[0051] Through the white box testing method, compare the attack structure in ATT&CK, display the detailed information of the attack source, attack link, and weak points in the full link, and provide solutions.
[0052] The visualization of the full-link attack process includes:
[0053] Proactively detect and analyze the target risk from multiple perspectives to form a multi-dimensional analysis view and an attack link diagram;
[0054] Display specific risks or vulnerabilities in the complete link from target discovery to successful attack to present the hacker attack path;
[0055] Generate a topology graph for the key information collected during the task execution, identify the risks found in each node, and display the attack relationships between nodes.
[0056] The visualization of the full - link attack process is achieved through the following steps:
[0057] Collect the text information of attack logs and security events;
[0058] Use natural language processing technology to analyze the text information and extract the key entities, events, and relationships;
[0059] Based on the extracted key entity, event, and relationship information, construct a knowledge graph;
[0060] Use the knowledge graph to construct a visual threat intelligence analysis platform;
[0061] Use the threat intelligence analysis platform to visualize the full - link attack process.
[0062] S4. Construct a security analysis view to quantify and evaluate the risks of multiple types of assets, including:
[0063] Adopt quantifiable metrics to construct security analysis views in different dimensions;
[0064] Adopt unsupervised learning technology to automatically classify assets;
[0065] Use real - time data stream processing technology, combined with pre - trained machine learning models, to continuously and real - time evaluate the security risks of assets.
[0066] The quantifiable metrics include the length, complexity, number of vulnerabilities, and threat level of the attack link.
[0067] The present invention relies on intelligent crawler technology and fingerprint recognition algorithm to continuously comb assets in a loop, discover existing or exposed risks, and record classification identifiers.
[0068] The working principle of the method provided by the present invention can be divided into the following four main steps, which help to identify and respond to potential security threats:
[0069] (1) Simulate penetration attacks:
[0070] Simulate penetration attacks from the attacker's perspective. This is a method of evaluating a system or network from the attacker's thinking mode. The system simulates penetration attacks from the attacker's perspective, attempts to enter the system and obtain unauthorized access rights. Specifically, the system can use various known attack techniques and strategies to attempt to attack the target system. This scope includes networks, servers, applications, databases, etc. The purpose of this simulated attack is to understand the strategies and methods used by attackers, and at the same time, it can also discover security vulnerabilities existing in the target system. It can cover multiple attack vectors, such as vulnerability exploitation, social engineering, malware, etc.
[0071] (2) Collection of associated asset information:
[0072] During the attack simulation, the system collects information on associated assets on the attack chain. This includes various assets accessed, affected, or manipulated by the attacker during the attack process, such as servers, databases, network devices, etc. This information is used to reconstruct the attacker's attack chain, that is, the steps and paths of the attack.
[0073] (3) Continuous white-box testing:
[0074] White-box testing is a testing method that assumes the tester has a comprehensive understanding of the system being tested and can view its internal working mechanism. In this case, white-box testing can help the system construct a detailed attack chain diagram, enabling security experts to clearly see each step of the attack process. Continuous white-box testing means that the system conducts white-box testing on each component of the attack chain to evaluate its security. This includes a detailed review and testing of application code, network configuration, system settings, etc. Through visualization tools, the system can monitor each node on the attack chain in real time, identify potential vulnerabilities and weaknesses, and provide a visual display for the security team to better understand the attack process and potential risks.
[0075] (4) Construction of a security analysis view:
[0076] Use quantifiable metrics to construct different dimensions of the security analysis view and conduct risk quantification and assessment of multiple types of assets. These metrics can include the length, complexity, number of vulnerabilities, threat level, etc. of the attack chain. Through risk quantification and assessment of multiple types of assets, the system generates a security analysis view to help the security team understand the overall security status of the system.
[0077] The method provided by the present invention simulates penetration attacks by attackers, collects relevant asset information, conducts continuous white-box testing, and constructs a security analysis view, providing a comprehensive security assessment and threat visualization analysis framework. This helps the security team better understand and identify potential threats and take corresponding measures to improve the security of the system.
[0078] To improve the above technical solution intelligently, the present invention introduces artificial intelligence and machine learning technologies to achieve adaptive attack chain analysis, more accurate risk assessment, and real-time security event response. The following are the improved technical solution and the detailed signal and data processing procedures.
[0079] 1. Adaptive Attack Chain Analysis Based on Deep Learning
[0080] (1) Data collection: Collect attack logs, traffic data, and other relevant information from different network entry points and endpoints.
[0081] (2) Data preprocessing: Clean the collected data above, filter out noise, and convert it into a format suitable for deep learning models. Extract meaningful features from the preprocessed data, such as attack sources, attack types, attack targets, etc., which will be used to train machine learning models.
[0082] (3) Model training: Use the collected historical attack data to train an adaptive attack chain analysis model based on a deep learning framework (such as TensorFlow or PyTorch).
[0083] (4) Real-time analysis and response: Deploy the trained model to the actual environment to analyze real-time network traffic. Once the model detects known or unknown attack patterns, immediately trigger preset response measures.
[0084] (5) Continuous learning and model update: As the network environment and attack techniques continue to change, the model needs to continuously learn and update to maintain its effectiveness in the face of new threats.
[0085] 2. Knowledge Graph Construction and Threat Intelligence Analysis Combining NLP
[0086] (1) Log collection: Collect attack logs and relevant text information from different sources (such as firewalls, intrusion detection systems, application servers, etc.).
[0087] (2) NLP processing: Use NLP tools (such as BERT, Spacy, or OpenNLP) to analyze the collected text data to identify key entities (such as attackers, attack tools, target systems, etc.) and events (such as the time and method of attacks).
[0088] (3) Knowledge graph construction: Use NLP techniques to perform text analysis on attack logs, extract key entities and relationships, and construct a knowledge graph. Over time, the knowledge graph will become richer and can provide more in-depth threat intelligence analysis for the security team.
[0089] (4) Threat intelligence analysis: Based on the constructed knowledge graph, use graph analysis techniques for in-depth threat intelligence analysis to identify potential security risks and threat patterns.
[0090] (5) Automated response: Combine the analysis results of the knowledge graph to design automated response strategies. For example, when a certain critical system is frequently targeted by attacks, automatically increase the security protection measures of the system or change its network location.
[0091] The intelligent improvement solution provided by the present invention uses deep learning technology to learn previous attack patterns, thereby automatically identifying new or variant attack patterns, which can help security teams identify and respond to new security threats more quickly. Use unsupervised learning techniques, such as clustering analysis, to automatically classify assets, thereby more accurately determining the importance of assets and potential security risks. Combine real-time data stream processing technology, use machine learning models to evaluate the security risks of the system in real time, and automatically trigger corresponding response measures according to the risk level. Analyze text data such as attack logs and security events through NLP technology, extract useful information, and build a knowledge graph to achieve in-depth threat intelligence analysis. Through this intelligent improvement solution, not only can the recognition and response speed of security teams to attacks be greatly improved, but also more in-depth threat intelligence analysis can be provided for them, thereby achieving more comprehensive and efficient network security protection.
[0092] Adopt deep learning technology to perform pattern recognition and analysis on a large amount of historical attack data, which can identify new, unknown or variant attack patterns; furthermore, in a real-time environment, quickly identify these new security threats, reduce false positives and false negatives, and achieve immediate security responses.
[0093] Combine unsupervised learning technology for automatic asset classification, which can automatically determine the importance and potential risks of assets according to the attributes, behaviors and relationships of assets; use real-time data stream processing technology, combined with pre-trained machine learning models, to continuously and real-time evaluate the security risks of the system; according to preset strategies, when the risk reaches a certain threshold, the system can automatically trigger corresponding security response measures, including isolating attacks, notifying administrators or starting backup systems. Specifically, it can be divided into the following key steps:
[0094] (1) Pattern recognition and analysis of historical attack data:
[0095] Use deep learning technology to perform pattern recognition and analysis on a large amount of historical attack data. This includes learning the behaviors, characteristics and patterns of attacks to establish a benchmark for attack patterns.
[0096] (2) Identification of new, unknown or variant attack patterns:
[0097] Based on the established attack pattern benchmarks, the system can identify new, unknown, or variant attack patterns. This helps to detect unrecognized security threats in a timely manner.
[0098] (3) Quick identification in a real-time environment:
[0099] In a real-time environment, the system continuously monitors network traffic and system activities. Once it detects behavior that matches known or unknown attack patterns, the system can quickly identify potential security threats.
[0100] (4) Reduction of false positives and false negatives:
[0101] Through deep learning techniques and accurate attack pattern matching, the system endeavors to reduce false positives and false negatives, ensuring that only genuine security threats are alerted and logged.
[0102] (5) Automatic asset classification:
[0103] Unsupervised learning techniques are employed to automatically classify assets. This means that the system can automatically determine their importance and potential risks based on the attributes, behaviors, and relationships of the assets.
[0104] (6) Real-time security risk assessment:
[0105] Utilizing real-time data stream processing technology, the system continuously monitors assets and network traffic, and combines pre-trained machine learning models to conduct continuous real-time assessments of the system's security risks.
[0106] (7) Automatic security response:
[0107] According to the preset policies, when potential security risks are detected and reach a certain threshold, the system can automatically trigger corresponding security response measures. These measures include isolating the affected systems, notifying the administrator, or activating the backup system to mitigate potential threats.
[0108] Combining natural language processing technology and knowledge graph technology, it deeply analyzes attack logs, security events, and related text information, automatically extracts key entities, events, and relationships therein; constructs a knowledge graph based on this data to provide a visual and structured threat intelligence analysis platform for the security team; at the same time, through continuous online learning, the system ensures that the model can adapt to the continuous changes in the network environment and attack strategies, guaranteeing its high level of vigilance and response ability when facing new threats and challenges. Combining natural language processing technology and knowledge graph technology to provide more in-depth security analysis and intelligence processing. The following is its detailed working principle:
[0109] (1) In-depth analysis of text information:
[0110] The system collects data from attack logs, security events, and relevant text information. This text information includes log records, reports, threat intelligence, etc.
[0111] (2) Application of natural language processing (NLP) technology:
[0112] Using natural language processing technology, the system analyzes and processes text information. This includes text parsing, lexical analysis, syntactic analysis, etc. NLP technology helps the system understand the text content and extract key entities, events, and relationships from it.
[0113] (3) Construction of a knowledge graph:
[0114] Based on the extracted entity, event, and relationship information, the system constructs a knowledge graph. A knowledge graph is a graphical representation that contains various entities (such as IP addresses, malware, attackers, etc.), events (such as intrusion, data leakage, etc.), and the relationships between them.
[0115] (4) Visual threat intelligence analysis platform:
[0116] The knowledge graph is used to construct a visual threat intelligence analysis platform. This platform can help security teams view and analyze security data in a structured and graphical way. It provides an interactive interface that allows users to explore and understand threat intelligence.
[0117] (5) Continuous online learning:
[0118] The system adopts a continuous online learning method to continuously update and improve its model. This includes monitoring changes in the network environment and attack strategies and automatically adjusting the model to adapt to these changes. This ensures that the system can maintain a high level of vigilance and response ability when facing new threats and challenges.
[0119] The present invention combines NLP technology, knowledge graph construction, and continuous online learning to deeply analyze text information, construct a structured knowledge graph, and provide a powerful threat intelligence analysis platform for security teams. This helps to better understand and respond to complex security threats.
[0120] Based on the above intelligent improvements, the advantages of the present invention are:
[0121] (1) Adaptive ability: Traditional attack information analysis is usually based on fixed rules or known attack patterns. After introducing deep learning technology, the system can adaptively identify and learn new attack patterns, enhancing the detection and response capabilities against unknown threats.
[0122] (2) Real-time risk assessment: Through real-time data stream processing and machine learning technologies, the system can assess and respond to various threats in real time, greatly reducing the time from threat detection to response and lowering security risks.
[0123] (3) Precise asset classification and risk grading: Using unsupervised learning technologies to classify assets ensures the rational allocation of resources and the deployment of targeted security policies, improving the efficiency of security management.
[0124] (4) In-depth threat intelligence analysis: Combining natural language processing and knowledge graphs, the system can provide more in-depth and comprehensive threat intelligence analysis, helping security teams better understand and respond to complex threat environments.
[0125] (5) Continuous learning and self-optimization: The system can continuously learn and optimize models based on new threat data, ensuring its effectiveness in a constantly changing network environment.
[0126] (6) Integration and automation: All of these technological advancements are not just independent; they work together in the entire system, enabling the entire security management process from threat detection, risk assessment to response and repair to achieve a high degree of automation and intelligence.
[0127] In summary, the method provided by the present invention utilizes deep learning, unsupervised learning, real-time data stream processing, and automated response technologies. By learning from historical attack data and monitoring the real-time environment, it can quickly identify and respond to various security threats, improving the security of networks and systems. This intelligent improvement not only enhances the efficiency and accuracy of security protection but also provides a more comprehensive and in-depth perspective for security teams, making the entire network security management process more advanced, efficient, and systematic, which is undoubtedly a significant technological advancement.
[0128] The terms used in the present invention are common nouns in the fields of computer science and artificial intelligence, which describe technologies and methods in different fields:
[0129] (1) Deep learning: Deep learning is a branch of machine learning that focuses on building and training deep neural networks to simulate and solve complex problems. These neural networks consist of multiple layers of neurons and can be used for tasks such as image recognition, natural language processing, and speech recognition. Deep learning technologies have achieved significant breakthroughs in many fields, such as face recognition, autonomous driving, and medical image analysis.
[0130] (2) Unsupervised learning: Unsupervised learning is a machine learning method that does not rely on labeled training data. In unsupervised learning, the algorithm attempts to discover patterns, structures, or associations from the data without prior knowledge of the expected output. Common unsupervised learning tasks include clustering (grouping data into similar categories) and dimensionality reduction (reducing the data dimensions to simplify analysis).
[0131] (3) Real-time data stream processing: Real-time data stream processing is a computational method for processing real-time data streams. It involves processing and analyzing data immediately when it is generated, rather than waiting for data to accumulate for batch processing. This technology is typically used in applications that require real-time responses, such as real-time monitoring, fraud detection, and online advertising.
[0132] (4) Automated response technology: Automated response technology involves developing and implementing automated programs or systems to automatically take predefined response measures when specific events or conditions are detected. These responses can include alert notifications, isolating threats, starting backup systems, etc. Automated response technology helps to speed up the processing of security incidents and reduce the need for manual intervention.
[0133] See Figure 2 , the present invention also provides an asset risk assessment device based on simulated penetration attacks and white box testing. This device is applied to the above-mentioned asset risk assessment method based on simulated penetration attacks and white box testing. The device includes:
[0134] A simulated penetration attack module for performing simulated penetration attacks on the agreed scope and target from the perspective of an attacker;
[0135] An attack link restoration module for collecting associated asset information on the attack link and restoring the attacker's attack link;
[0136] A white box testing module for continuously performing white box testing on each node on the attack link and visualizing the full-link attack process;
[0137] An asset risk assessment module for constructing a security analysis view and quantifying and assessing the risks of multiple types of assets.
[0138] See Figure 3 , the present invention also provides an asset risk assessment device based on simulated penetration attacks and white box testing, including a memory and a processor;
[0139] The memory is used to store computer program code and transmit the computer program code to the processor;
[0140] The processor is used to execute the above-mentioned asset risk assessment method based on simulated penetration attacks and white box testing according to the instructions in the computer program code.
[0141] A computer-readable storage medium has a computer program stored thereon, and when the computer program is executed by a processor, it implements the above-mentioned asset risk assessment method based on simulated penetration attacks and white box testing.
[0142] Generally speaking, the computer instructions for implementing the method of the present invention can be carried by any combination of one or more computer-readable storage media. A non-transitory computer-readable storage medium may include any computer-readable medium except for the signal itself in transient propagation.
[0143] The computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples (non-exhaustive list) of the computer-readable storage medium include: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EKROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present invention, the computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.
[0144] The computer program code for performing the operations of the present invention can be written in one or more programming languages or combinations thereof. The programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. In particular, the Python language suitable for neural network computing and platform frameworks based on TensorFlow, PyTorch, etc. can be used. The program code can be executed entirely on the user's computer, partially on the user's computer, executed as an independent software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or connected to an external computer (for example, by using an Internet service provider to connect through the Internet).
[0145] For the above-mentioned device and non-transitory computer-readable storage medium, reference can be made to the specific description of an asset risk assessment method and beneficial effects based on simulated penetration attacks and white box testing, which will not be elaborated here.
[0146] Although the embodiments of the present invention have been shown and described above, it should be understood that the above embodiments are exemplary and should not be construed as limiting the present invention. Those of ordinary skill in the art can make changes, modifications, substitutions, and variations to the above embodiments within the scope of the present invention.
Claims
1. An asset risk assessment method based on simulated penetration attacks and white box testing, characterized in that: include: Conduct simulated penetration attacks on the agreed scope and target from the attacker's perspective; Use attack patterns to automatically penetrate the agreed scope and target to complete the asset collection of IP addresses, domain names, hosts, services, credentials, operating systems, applications, plug-ins, and network devices; the attack patterns include full-scenario penetration attacks, website penetration attacks, intranet environment penetration attacks, and WAF simulation attacks; Collect the associated asset information on the attack chain and restore the attacker's attack chain; Conduct continuous white-box testing on each node in the attack chain and visualize the entire attack chain process; The visualized full-link attack process is implemented in the following ways: collecting text information of attack logs and security events; using natural language processing technology to analyze the text information and extract key entities, events and relationships therein, wherein the key entities include attackers, attack tools, and target systems; constructing a knowledge graph based on the extracted key entities, events and relationship information; and using the knowledge graph to construct a visualized threat intelligence analysis platform; Use the threat intelligence analysis platform to visualize the entire attack process; Construct security analysis views to quantify and assess risks of multiple types of assets; specifically: Use quantifiable indicators to construct security analysis views in different dimensions; use unsupervised learning technology to automatically classify assets; use real-time data stream processing technology, combined with pre-trained machine learning models, to conduct continuous real-time assessment of asset security risks.
2. The asset risk assessment method based on simulated penetration attack and white box testing according to claim 1 is characterized in that: Deep learning technology is used to perform pattern recognition on a large amount of historical attack data to identify new, unknown or variant attack patterns, and use the attack patterns to simulate penetration attacks on agreed scopes and targets.
3. The asset risk assessment method based on simulated penetration attack and white box testing according to claim 1 is characterized in that: The quantifiable indicators include the length, complexity, number of vulnerabilities and threat level of the attack chain.
4. An asset risk assessment device based on simulated penetration attack and white box testing, characterized in that: The device is applied to the method described in any one of claims 1 to 3, and the device comprises: The simulated penetration attack module is used to simulate penetration attacks on the agreed scope and target from the attacker's perspective; The attack link restoration module is used to collect the associated asset information on the attack link and restore the attacker's attack link; White-box testing module, used to perform continuous white-box testing on each node in the attack link and visualize the full-link attack process; The asset risk assessment module is used to build a security analysis view and quantify and assess the risks of multiple types of assets.
5. An asset risk assessment device based on simulated penetration attacks and white box testing, characterized in that: including memory and processor; The memory is used to store computer program code and transmit the computer program code to the processor; The processor is configured to execute the method according to any one of claims 1 to 3 according to instructions in the computer program code.
6. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 3 is implemented.
Citation Information
Patent Citations
Automatic network simulation attack framework based on attack tree and deep reinforcement learning
CN116545687A
Penetration testing method and system based on high-value asset data flow and storage medium
CN116723028A
Intelligent report generation method and system based on automatic countermeasure simulation attack
CN116800548A
Network asset attack surface management method, system and device based on knowledge graph and storage medium
CN117318978A