Network Security Intelligent Vulnerability Scanning Method and Its System

By selecting appropriate vulnerability scanning methods based on the security requirements data of network security and real-time detection requirements data, combined with automation and manual vulnerability scanning, the problem of vulnerabilities not being discovered in the existing technology is solved, and network security and business continuity are improved.

CN118432918BActive Publication Date: 2025-06-20GUANGDONG ZHONGDA TESTING & INSPECTION CENTER CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410652416.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-05-24
Publication Date
2025-06-20
Estimated Expiration
2044-05-24

AI Technical Summary

Technical Problem

The existing network security vulnerability scanning lacks the choice of vulnerability scanning methods in different environments, resulting in vulnerabilities not being discovered in time, falsely reported or misreported, affecting business continuity and increasing network security risks.

Method used

By determining the network security vulnerability scanning strategy based on the security requirements data of network security and real-time detection requirements data adjustments, selecting appropriate vulnerability scanning methods, including a combination of automated vulnerability scanning and manual vulnerability scanning, ensuring that the appropriate scanning method is selected in different environments.

Benefits of technology

It realizes the selection of appropriate vulnerability scanning methods in different environments, improves the timely detection rate of vulnerabilities, reduces false alarms and missed reports, enhances network security, and ensures business continuity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118432918B_ABST
    Figure CN118432918B_ABST
Patent Text Reader

Abstract

The present invention discloses a network security intelligent vulnerability scanning method and system, which relates to the technical field of security scanning and is used to solve the problem that the existing network security vulnerability scanning lacks the selection of vulnerability scanning methods in different environments, and the failure to select a suitable method for network security vulnerability scanning may lead to the failure to detect vulnerabilities in a timely manner. It includes collecting analysis data of security requirements for calculation to obtain security requirement data of network security; determining a vulnerability scanning method according to the security requirement data of network security and real-time detection requirement data, and starting to implement; combining automated vulnerability scanning and manual vulnerability scanning to perform intelligent vulnerability scanning on network security, providing a flexible and efficient selection method for vulnerability scanning. This decision-making mechanism ensures that while guaranteeing the selection accuracy rate, it more effectively improves the security of the organization.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of security scanning technology, and more specifically, to a network security intelligent vulnerability scanning method and system thereof. Background Art

[0002] Network security is the practice and technical field of protecting computer networks and their related devices, data, and communication traffic from unauthorized access, attacks, or damage. It covers multiple aspects, including protecting network infrastructure, preventing data leaks, blocking the spread of malware and viruses, and managing user permissions, etc.

[0003] Intelligent vulnerability scanning is a method that uses automated technology to discover security vulnerabilities existing in computer systems and applications. Such scanning tools can conduct extensive scans on the system and identify potential vulnerabilities, thereby helping organizations repair these problems in a timely manner and improve network security. Intelligent vulnerability scanning is closely related to network security and plays an important role in ensuring network security.

[0004] The existing technologies have the following deficiencies:

[0005] The existing network security vulnerability scanning lacks the selection of vulnerability scanning methods in different environments. Failure to select an appropriate method for network security vulnerability scanning may lead to the failure to discover vulnerabilities in a timely manner, false positives or missed reports of vulnerabilities, affecting business continuity, and lack of comprehensiveness, thereby increasing network security risks.

[0006] In view of the above problems, the present invention proposes a solution. Summary of the Invention

[0007] In order to overcome the above-mentioned defects of the existing technologies, embodiments of the present invention provide a network security intelligent vulnerability scanning method and system thereof to solve the problems raised in the above background art.

[0008] To achieve the above object, the present invention provides the following technical solutions:

[0009] A network security intelligent vulnerability scanning method and system thereof include the following steps:

[0010] Step 1: Adjust and determine a network security vulnerability scanning strategy according to the security requirement data and real-time detection requirement data of network security;

[0011] Step 2: Collect analysis data of security requirements and calculate to obtain the security requirement data of network security;

[0012] Step 3: Obtain a suitable vulnerability scanning method according to the security requirement data and real-time detection requirement data of network security, and start to implement it.

[0013] In a preferred embodiment, in step 1, the network security vulnerability scanning strategy includes first performing automated vulnerability scanning, then performing manual vulnerability scanning, and only performing manual vulnerability scanning to deeply analyze the network security system.

[0014] In a preferred embodiment, in step 2, the security requirement data for network security includes software security requirement data and hardware security requirement data;

[0015] The software security requirement data includes privilege management data, security audit data, and code security requirement data;

[0016] The hardware security requirement data for network security includes hardware encryption.

[0017] In a preferred embodiment, in step 3, the obtained security requirement data and real-time detection requirement data are defined as input variables, which are divided into different fuzzy sets, and the selected vulnerability scanning method is defined as the output variable. Performing automated vulnerability scanning first and then manual vulnerability scanning is calibrated as P1, and only performing automation is calibrated as P2;

[0018] Formulate fuzzy rules to describe the influence of different input variables on the output variable

[0019] Perform fuzzy inference according to the fuzzy rules to obtain a suitable vulnerability scanning method.

[0020] In a preferred embodiment, in step 3, the specific process of only performing automated vulnerability scanning for network security is as follows:

[0021] D1: Target determination, determine the target of vulnerability scanning;

[0022] D2: Scanning configuration, select a scanning tool and configure it;

[0023] D3: Scanning execution;

[0024] D4: Vulnerability identification, list the detected vulnerabilities and problems;

[0025] D5: Vulnerability assessment, for each identified vulnerability, conduct an assessment to determine its severity and impact level;

[0026] D6: Repair suggestions, for each identified vulnerability, provide repair suggestions;

[0027] D7: Vulnerability repair, according to the repair suggestions provided in the vulnerability scanning report, perform vulnerability repair work;

[0028] D8: Reporting and tracking, after generating the vulnerability scanning report, submit it to the relevant team or manager for review;

[0029] D9: Regular repetition, regularly perform vulnerability scans to ensure system security.

[0030] In a preferred embodiment, in step 3, first perform an automated vulnerability scan and then a manual vulnerability scan. Based on the automated vulnerability scan, the specific process of the manual vulnerability scan is as follows:

[0031] T1: Target identification and confirmation, first identify and confirm the target system or application;

[0032] T2: Information collection and reconnaissance, collect information related to the target system;

[0033] T3: Vulnerability detection and assessment, discover security vulnerabilities in the target system, and perform a comprehensive scan using a vulnerability scanning tool;

[0034] T4: Authentication and authorization testing, test the authentication and access control mechanisms of the target system to discover potential weaknesses and vulnerabilities;

[0035] T5: Vulnerability verification and exploitation, for the discovered vulnerabilities, perform in-depth manual verification to ensure the existence and exploitability of the vulnerabilities;

[0036] T6: Report writing and delivery, the process of organizing the vulnerability scan and test results into a detailed report and submitting it to the customer or the organization's security team;

[0037] T7: Vulnerability repair and tracking, assist system administrators and developers in repairing the discovered vulnerabilities and track the progress of vulnerability repair.

[0038] In a preferred embodiment, the software security requirement data calculation method is as follows:

[0039] Step S1: Data preparation, collect security-related data in the code, including security requirement information of code snippets, functions, or entire modules; for each code snippet, extract corresponding features, including input validation, output encoding, and permission control;

[0040] Step S2: Select appropriate features. If the code snippet contains input validation, the feature is 1, otherwise it is 0; the presence of input validation indicates that the code performs validation before accepting user input to ensure the security and effectiveness of the input;

[0041] Step S3: Preprocess these feature data to ensure that they are suitable for processing by the clustering algorithm;

[0042] Step S4: For the clustering analysis of the feature data, select the K-means clustering algorithm;

[0043] Step S5: Select an appropriate number of clusters according to specific requirements. When n code snippets are collected, select the number of clusters as n;

[0044] Step S6: Initialize the cluster centers. Select K samples from the feature data as the initial cluster centers, and then iteratively select the next cluster center until k cluster centers are selected and remain unchanged;

[0045] Step S6.1: For each sample point, calculate its distance to each cluster center. Use the Euclidean distance for calculation. The specific formula is where Xi is a sample point in the i-th feature dataset, representing the i-th code snippet, Cj is the j-th feature data point serving as the cluster center, Xik and Cjk represent the values of point Xi and Cj on the k-th feature, and N is the number of features;

[0046] For each data point, find the cluster center closest to it, and assign the data point to the cluster where the closest cluster center is located. That is, assign each sample point Xi to the cluster center Cj such that j = argmin j d(Xi, Cj); where argmin represents evaluating j to minimize the subsequent expression;

[0047] Step S6.2: Update the cluster centers. After all data points are assigned to the corresponding clusters, there will be multiple data points in each cluster. Next, update the center of the cluster according to all data points assigned to this cluster, that is, calculate the average value of all data points within the cluster, and use this average value as the new cluster center. The specific formula is where |uj| is the number of sample points in the j-th cluster;

[0048] Step S6.3: Repeat the processes of calculating distances, assigning data points, and updating cluster centers until the cluster centers no longer change or reach a pre-set number of iterations;

[0049] Step S7: When the algorithm converges, the cluster centers represent the central positions of each cluster, that is, the security features. Their features can reflect the common security features of the code snippets in this cluster. Statistically calculate the frequency of a specific security feature appearing in this cluster. Suppose there is a cluster containing t sample points, and the feature vector of the sample point yi is expressed as Yi = (yi1, yi2,..., yiN); the frequency of a specific security feature in this cluster is estimated by calculating the frequency of this feature appearing in all sample points. Specifically, there is a formula Where δ(yif, f) is an indicator function, which takes the value of 1 when the feature yif in the sample point yi is equal to the specific security feature f, and 0 otherwise; by calculating the frequency of the specific security feature in the clustering cluster, the prevalence of this feature in the clustering cluster can be understood; the feature frequency is a proportional value between 0 and 1, indicating the frequency of the specific security feature appearing in the clustering cluster; if the feature appears in all sample points in the clustering cluster, the frequency is 1; if the feature does not appear in all sample points in the clustering cluster, the frequency is 0.

[0050] In a preferred embodiment, in step 2, the time allocation for the two scanning methods is comprehensively analyzed according to the occurrence frequency of specific features in the software security requirement data and the scanning coverage rate of automated vulnerability scanning in the actual detection requirement data. The specific process is as follows:

[0051] First, obtain the occurrence frequency of specific features and the scanning coverage rate of automated vulnerability scanning. The occurrence frequency of specific features is Freq, and its value ranges from 0 to 1; the scanning coverage rate refers to the ratio between the number of vulnerabilities that can be detected by the scanning tool or method and the total number of vulnerabilities in the vulnerability scanning; the specific calculation formula is Among them, the "number of detected vulnerabilities" refers to the number of vulnerabilities actually discovered by the scanning tool or method, and the "total number of vulnerabilities" refers to all possible vulnerabilities in the target system or application, including known and unknown vulnerabilities;

[0052] Secondly, comprehensively analyze the occurrence frequency of specific features in the software security requirement data and the scanning coverage rate of automated vulnerability scanning in the actual detection requirement data; assume that the time of the entire scanning process is represented by Time, the scanning coverage rate is represented by R cov represents, and the occurrence frequency of specific features is represented by Freq. Then, a weighted average can be used to calculate the comprehensive score Q;

[0053] Finally, according to the comprehensive score and the time of the scanning process, the time allocation for automated vulnerability scanning and manual vulnerability scanning is obtained; specifically, there is a formula In the formula, Time 自动化 represents the time of automated vulnerability scanning, Time is the time of the entire scanning process, and Q is the comprehensive score; then Time - Time 自动化 is the time of manual vulnerability scanning.

[0054] A network security intelligent vulnerability scanning system for implementing the above network security intelligent vulnerability scanning method, including a data collection module, a data processing module, and a data storage module;

[0055] The data acquisition module is used to obtain the security requirement data and real-time detection requirement data of network security, and send them to the data processing module to ensure the operation of the subsequent data processing module;

[0056] The data processing module is used to determine and select a vulnerability scanning method based on the data collected by the data acquisition module, and start to implement it;

[0057] The data storage module is used to store all the data generated during the processing of the network security intelligent vulnerability scanning system.

[0058] The technical effects and advantages of the network security intelligent vulnerability scanning method and system of the present invention:

[0059] The present invention conducts intelligent vulnerability scanning for network security, and combines automated vulnerability scanning and manual vulnerability scanning to conduct intelligent vulnerability scanning for network security, providing a flexible and efficient selection method for vulnerability scanning. This decision-making mechanism ensures that while ensuring the selection accuracy rate, it more effectively improves the security of the organization. Description of the Drawings

[0060] Figure 1 It is a schematic flowchart of the network security intelligent vulnerability scanning method of the present invention. Detailed Embodiments

[0061] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0062] The present invention conducts intelligent vulnerability scanning for network security, and combines automated vulnerability scanning and manual vulnerability scanning to conduct intelligent vulnerability scanning for network security, providing a flexible and efficient selection method for vulnerability scanning. This decision-making mechanism ensures that while ensuring the selection accuracy rate, it more effectively improves the security of the organization.

[0063] Embodiment 1

[0064] Figure 1 A method flowchart of a network security intelligent vulnerability scanning of the present invention is given, and the specific steps are as follows:

[0065] Step 1: Adjust and determine the network security vulnerability scanning strategy according to the security requirement data and real-time detection requirement data of network security;

[0066] Step 2: Collect the analysis data of security requirements and calculate to obtain the security requirement data of network security.

[0067] Step 3: Obtain a suitable vulnerability scanning method based on the security requirement data and real-time detection requirement data of network security, and start implementation.

[0068] Specifically, in Step 1, it is mainly used to determine whether to perform automated vulnerability scanning followed by manual vulnerability scanning or only automated vulnerability scanning based on the security requirement data and real-time detection requirement data of network security. Obviously, if the security requirements of network security are high and the time and human resources for scanning are sufficient, there may be a large number of conventional vulnerabilities and some advanced vulnerabilities in network security. At this time, it is necessary to first perform automated vulnerability scanning to screen out conventional vulnerabilities, and then perform manual vulnerability scanning to ensure the discovery of more advanced vulnerabilities. Otherwise, only automated vulnerability scanning is required to quickly scan a large number of targets and discover conventional vulnerabilities, saving time and labor costs.

[0069] That is, the network security vulnerability scanning strategy includes first performing automated vulnerability scanning, then performing manual vulnerability scanning, and only performing manual vulnerability scanning to deeply analyze the network security system.

[0070] Specifically, in Step 2, the security requirement data of the network security of this application includes software security requirement data and hardware security requirement data.

[0071] Among them, the software security requirement data includes permission management data, security audit data, code security requirement data, etc. There may be some differences in the permission management data, security audit data, and code security requirement data between different software modules, and it is necessary to further analyze them to obtain representative security requirement data.

[0072] As mentioned above, the software security requirement data may include multiple types of security data, and the specific security data included is determined according to the actual situation. For example, the software security requirement data can only be code security requirement data. At this time, only the code of different software modules needs to be calculated. This application provides a code security requirement calculation method, which is specifically as follows:

[0073] S1: Data preparation. Collect security-related data in the code, which can be security requirement information of code snippets, functions, or entire modules. These can be obtained through information in code libraries, security documents, or security reviews. Here, code snippets are taken as an example. Suppose n code snippets are collected. For each code snippet, corresponding features need to be extracted, including input validation, output encoding, permission control, etc.

[0074] S2: Select appropriate features. In the security requirement data, each feature represents a security measure or requirement. Taking the input validation feature as an example, it can be represented as a binary variable. If the code snippet contains input validation, the feature is 1; otherwise, it is 0. The presence of input validation indicates that the code performs validation before accepting user input to ensure the security and effectiveness of the input.

[0075] S3: Preprocess these feature data to ensure that they are suitable for processing by the clustering algorithm and improve the clustering effect.

[0076] S4: For the clustering analysis of the feature data, select the K-means clustering algorithm. K-means clustering is a commonly used clustering algorithm suitable for processing large datasets.

[0077] S5: Select an appropriate number of clusters according to specific requirements. When n code snippets are collected, select the number of clusters as n.

[0078] S6: Initialize the cluster centers. K samples can be selected from the feature data as the initial cluster centers. Then iteratively select the next cluster center until k cluster centers are selected and do not change.

[0079] S6.1: For each sample point, calculate its distance to each cluster center. The Euclidean distance can be used for calculation. The specific formula is where Xi is a sample point in the feature dataset, representing the i-th code snippet, Cj is the j-th feature data point serving as a cluster center, Xik and Cjk represent the values of point Xi and Cj on the k-th feature, and N is the number of features.

[0080] For each data point, find the cluster center closest to it. Assign the data point to the cluster where the closest cluster center is located. That is, assign each sample point Xi to the cluster center Cj such that j = argmin j d(Xi, Cj); where argmin means evaluating j to minimize the subsequent expression.

[0081] S6.2: Update the cluster centers. After all data points are assigned to the corresponding clusters, there may be multiple data points in each cluster. Next, update the center of the cluster according to all the data points assigned to this cluster, that is, calculate the average value of all data points within the cluster and use this average value as the new cluster center. The specific formula is where |uj| is the number of sample points in the j-th cluster.

[0082] S6.3: Repeat the process of calculating distances, assigning data points, and updating cluster centers until the cluster centers no longer change or reach a pre-set number of iterations.

[0083] S7: When the algorithm converges, the clustering center represents the central position of each clustering cluster, i.e., the security feature, and its features can reflect the common security features of the code segments in that cluster. Statistically analyze the frequency of a specific security feature in this clustering cluster. Suppose a clustering cluster contains t sample points, and the feature vector of sample point yi is represented as Yi = (yi1, yi2,..., yiN); the frequency of a specific security feature in this clustering cluster can be estimated by calculating the frequency of this feature in all sample points. Specifically, there is a formula In the formula, δ(yif, f) is an indicator function, which takes the value of 1 when the feature yif in sample point yi is equal to the specific security feature f, and 0 otherwise. By calculating the frequency of a specific security feature in the clustering cluster, we can understand the prevalence of this feature in the clustering cluster. The feature frequency is a proportional value between 0 and 1, indicating the frequency of a specific security feature in the clustering cluster. The specific number depends on the ratio between the number of occurrences of this feature in all sample points and the total number of sample points. If the feature appears in all sample points in the clustering cluster, the frequency is 1; if the feature does not appear in all sample points in the clustering cluster, the frequency is 0.

[0084] If Freq(f) is larger, it means the frequency of this specific security feature is higher, indicating that the code segments in this clustering cluster generally have this security feature, the code security requirement is higher, and the software requirement is higher; conversely, it means the code security requirement is lower and the software requirement is lower.

[0085] It should be noted that the security requirement data for network security is only the code security requirement data in the software security requirement data, which is just an example in this embodiment. In fact, it can include other data, such as permission management data, security audit data, etc. in the software security requirement data, which will not be elaborated here.

[0086] The hardware security requirement data for network security includes hardware encryption. Obviously, if the encryption of the hardware is weak, it is more vulnerable to traditional attack methods. At this time, as long as an automated vulnerability scan is performed, it is easier to find weaknesses; conversely, if the encryption of the hardware is strong, an automated vulnerability scan needs to be performed first and then a manual vulnerability scan.

[0087] The real-time detection requirement data includes resources for vulnerability scanning, such as time, human resources, etc. Insufficient resources mean a shorter scanning time or fewer professional personnel. At this time, a large number of targets need to be scanned quickly, and only an automated vulnerability scan can be performed.

[0088] It should be noted that the hardware security requirement data and real-time detection requirement data of network security can also include more types of data according to actual situations. For example, the performance requirements during detection. The higher the performance requirements, the different vulnerability scanning methods will be selected. The specific data given in this application is only for illustrative purposes and will not be elaborated here.

[0089] Specifically, in step 3, the obtained security requirement data and real-time detection requirement data are defined as input variables and divided into different fuzzy sets. For example, "Low", "Medium", "High" for the security requirement data, and "Adequate", "Lack" for the real-time detection requirement data. The selected vulnerability scanning method is defined as the output variable. Automatically scanning for vulnerabilities first and then manually scanning is calibrated as P1, and only automatic scanning is calibrated as P2.

[0090] Formulate fuzzy rules to describe the influence of different input variables on the output variable. The definition of the rules can be based on the professional knowledge of this industry or obtained through data analysis and experiments. For example, mark the security requirement data of network security as A, the real-time detection requirement data as B, and the selected vulnerability scanning method as R_select. It can be defined as:

[0091] Rule 1: IF (A is High) AND (B is Adequate) THEN (R_select is P1)

[0092] Rule 1: IF (A is Low) AND (B is Lack) THEN (R_select is P2) ......

[0094] Perform fuzzy inference according to the fuzzy rules to obtain a suitable vulnerability scanning method.

[0095] It should be noted that the division of the fuzzy sets can be adjusted according to actual situations. For example, in this embodiment, three fuzzy sets are taken as an example. In fact, the security requirement data, real-time detection requirement data, and selected vulnerability scanning method can be divided into more than three sets, so as to more conveniently select the vulnerability scanning method.

[0096] Furthermore, for the judgment of high, medium, and low of the security requirement data and adequate and lack of the real-time detection requirement data, thresholds can be set for judgment according to actual situations. For example, when Freq(f)≥0.7 in the code security requirement data of the software security requirement data, it is calibrated as "High"; when the human resources in the real-time detection requirement data are more than 5 people, it is calibrated as "Adequate", etc., which will not be elaborated here.

[0097] During the implementation process, only automated vulnerability scanning for network security is carried out. The specific process is as follows:

[0098] D1: Target determination. When determining the target, network topology, asset inventory, and possible attack surfaces need to be considered. This may include determining the IP address range, specific domain names, or URLs to be scanned. For example, for an enterprise network, the target can be all internal hosts, servers, and network devices, which can be obtained through an asset management system or a network topology diagram.

[0099] D2: Scan configuration. When configuring the scan, an appropriate scan tool needs to be selected and configured to ensure that vulnerabilities can be effectively discovered. When setting scan parameters, factors such as scan depth, speed, and concurrent connection number need to be considered. For example, if OpenVAS is used as the scan tool, its scan policy can be configured, including selecting the port range to be scanned, enabling vulnerability detection plugins, etc.

[0100] D3: Scan execution. During scan execution, the scan tool sends various types of data packets to the target system and determines whether there are potential vulnerabilities based on the target's response. For example, the scan tool may send TCP SYN, TCPConnect, UDP, and other types of data packets to probe the open ports and services of the target system.

[0101] D4: Vulnerability identification. After the scan is completed, the scan tool generates a vulnerability scan report, which lists the detected vulnerabilities and problems. The report usually contains a detailed description of each vulnerability, CVE number, risk rating, impact scope, and possible solutions.

[0102] D5: Vulnerability assessment. For each identified vulnerability, an assessment needs to be carried out to determine its severity and impact. This can be determined based on the difficulty of exploiting the vulnerability, the possible impact, and the importance of the affected assets. For example, for an authentication bypass vulnerability, its severity depends on whether the attacker can obtain unauthorized access to the system and the permissions of the affected users.

[0103] D6: Repair suggestions. For each identified vulnerability, the report usually provides repair suggestions, including detailed repair steps and recommended security measures. Repair suggestions may include updating software versions, applying patches, modifying configurations, strengthening access control, etc.

[0104] D7: Vulnerability repair. According to the repair suggestions provided in the vulnerability scan report, carry out vulnerability repair work. This may require cross-team cooperation, including system administrators, network administrators, and developers, etc. Vulnerability repair may include operations such as installing patches, updating software, modifying configuration files, and fixing code.

[0105] D8: Reporting and Tracking. After generating a vulnerability scan report, it needs to be submitted to the relevant team or manager for review. The report should include detailed information about the vulnerabilities, repair suggestions, and repair progress. At the same time, it is necessary to track the progress of vulnerability repair to ensure that all vulnerabilities are repaired in a timely manner and update the report when necessary.

[0106] D9: Regular Repetition. Regularly performing vulnerability scans is an important step in ensuring system security. Regular scans can help discover new vulnerabilities and ensure that known vulnerabilities are repaired in a timely manner. The scan frequency may be adjusted according to the sensitivity and risk of the system and is usually performed after each vulnerability repair cycle.

[0107] Automated vulnerability scanning is performed first, followed by manual vulnerability scanning. Based on the automated vulnerability scanning, the specific process of manual vulnerability scanning is as follows:

[0108] T1: Target Identification and Confirmation. At the beginning stage of manual network security vulnerability scanning, it is first necessary to identify and confirm the target system or application. This includes scanning the target IP range using port scanning tools (such as Nmap or Masscan) to identify the IP addresses, open ports, and services of the target system. Subdomains of the target can also be discovered through subdomain collection tools (such as Amass or Sub l i st3r) and WHOIS queries. Further information collection may involve using intelligence collection tools (such as theHarvester or Ma ltego) to obtain more information about the target system, such as email addresses, IP addresses, etc. The goal of this stage is to obtain a preliminary understanding of the target system and determine the direction and method of subsequent attacks.

[0109] T2: Information Collection and Reconnaissance. The information collection and reconnaissance stage is a crucial step in manual network security vulnerability scanning. It involves collecting as much information as possible related to the target system from various sources. Using intelligence collection tools (such as Shodan or Censys) can obtain public information about the target system, such as open services, certificates, metadata, etc. In addition, searching for sensitive information related to the target, such as employee names, internal system architectures, etc., in search engines, social media, and public databases is also helpful. The goal of this stage is to collect as much information as possible to better understand the structure, technology stack, and potential weaknesses of the target system.

[0110] T3: Vulnerability Detection and Assessment. The vulnerability detection and assessment phase is the core part of manual network security vulnerability scanning. It involves using various techniques and tools to discover security vulnerabilities in the target system. Conduct a comprehensive scan using vulnerability scanning tools (such as Nessus or OpenVAS) to discover known vulnerabilities. At the same time, manually conduct vulnerability mining and use various techniques (such as code auditing, network sniffing, protocol analysis) to discover unknown vulnerabilities. Utilize penetration testing frameworks (such as Metasploit or BeEF) to verify the exploitability and impact level of the discovered vulnerabilities. The goal of this phase is to discover as many vulnerabilities as possible and evaluate the threat level to system security.

[0111] T4: Authentication and Authorization Testing. The authentication and authorization testing phase involves testing the authentication and access control mechanisms of the target system to discover potential weaknesses and vulnerabilities. Use password cracking tools (such as Hydra or John the Ripper) to conduct common username and password combination attacks on the target system. At the same time, use social engineering techniques to attempt to obtain credential information of the target system. In addition, utilize vulnerability exploitation tools to test the authentication and access control mechanisms of the target system and search for possible bypass methods. The goal of this phase is to determine whether the authentication and access control mechanisms of the target system are secure enough and to discover potential vulnerabilities and weaknesses.

[0112] T5: Vulnerability Verification and Exploitation. The vulnerability verification and exploitation phase is the process of conducting in-depth testing and exploitation of the discovered vulnerabilities. For the discovered vulnerabilities, in-depth manual verification is required to ensure the existence and exploitability of the vulnerabilities. Use various attack vectors (such as SQL injection, XSS, CSRF) to verify the exploitability of the vulnerabilities and attempt to obtain system access rights. Utilize the vulnerabilities for further penetration testing to explore the internal network and resources of the target system. The goal of this phase is to utilize the discovered vulnerabilities to obtain system access rights and explore deeper levels of the target system.

[0113] T6: Report Writing and Delivery. The report writing and delivery phase is the process of organizing the vulnerability scanning and testing results into a detailed report and submitting it to the customer or the security team of the organization. When writing the vulnerability report, it is necessary to include the technical details of the vulnerabilities, the verification process, the attack path, and the impact assessment. At the same time, provide the CVSS score of the vulnerabilities, repair suggestions, improvement suggestions, and possible subsequent actions that the attacker may take. Finally, deliver the report to the customer or the security team of the organization and provide necessary support and explanations. The goal of this phase is to provide the customer or the organization with comprehensive vulnerability scanning and testing results and help them understand and address the discovered security issues.

[0114] T7: Vulnerability Fixing and Tracking. The vulnerability fixing and tracking phase involves assisting system administrators and developers in fixing the discovered vulnerabilities and tracking the progress of vulnerability fixing. In this phase, it is necessary to assist system administrators and developers in fixing the discovered vulnerabilities, including applying security patches, modifying configurations, rewriting code, etc. Track the progress of vulnerability fixing, conduct necessary verification and testing to ensure that the vulnerabilities have been effectively fixed. Establish a vulnerability management system to continuously track the system.

[0115] Embodiment 2

[0116] In Embodiment 1 of the present invention, emphasis is placed on exemplifying how to select different vulnerability scanning methods according to the security requirement data and real-time detection requirement data of network security, and how to perform automated vulnerability scanning and manual vulnerability scanning is described in detail. However, in Embodiment 1, for network security, automated vulnerability scanning is performed first and then manual vulnerability scanning. Only the sequence of automated vulnerability scanning and manual vulnerability scanning is given, and the scanning time of the two methods is not explained, which may affect the progress and efficiency of the entire scanning process. Therefore, Embodiment 2 is further refined to provide a method for allocating scanning time for automated vulnerability scanning and manual vulnerability scanning.

[0117] In Step S7 of Embodiment 1, the occurrence frequency Freq of a specific feature is obtained. If Freq(f) is larger, the frequency of this specific security feature is higher, indicating that the code snippets in this cluster generally have this security feature, the higher the code security requirement, and the higher the software security requirement; otherwise, it indicates that the code security requirement is lower and the software security requirement is lower.

[0118] Taking the scanning coverage rate of automated vulnerability scanning as an example of the actual detection requirement data, the time allocation for the two scanning methods is comprehensively analyzed based on the occurrence frequency of specific features in the software security requirement data and the scanning coverage rate of automated vulnerability scanning in the actual detection requirement data. The following is the specific process:

[0119] First, obtain the occurrence frequency of specific features and the scanning coverage rate of automated vulnerability scanning. The occurrence frequency of specific features is Freq in Embodiment 1, and its value ranges from 0 to 1. The scanning coverage rate refers to the ratio between the number of vulnerabilities that can be detected by a scanning tool or method and the total number of vulnerabilities in vulnerability scanning. The specific calculation formula is Among them, the "number of detected vulnerabilities" refers to the number of vulnerabilities actually discovered by the scanning tool or method, which can be collected during real-time monitoring. The "total number of vulnerabilities", on the other hand, refers to all the vulnerabilities that may exist in the target system or application, including known and unknown vulnerabilities. Usually, the total number of vulnerabilities is an estimated value because it is impossible to accurately know all the vulnerabilities in a system. Therefore, it should be noted that this calculation is based on a known vulnerability library or vulnerability classification, ensuring that the vulnerability library and definitions during the vulnerability scanning process are complete and accurate. Also, the scanning results need to be reviewed and verified, and corresponding adjustments should be made according to the actual situation, which will not be elaborated here.

[0120] Secondly, a comprehensive analysis is conducted on the occurrence frequency of specific features in the software security requirement data and the scanning coverage rate of automated vulnerability scanning in the actual detection requirement data. Assume that the time for the entire scanning process is represented by Time, the scanning coverage rate is represented by R cov and the occurrence frequency of specific features is represented by Freq. Then, a weighted average can be used to calculate the comprehensive score. The specific formula is Q = w cov ×R cov +w freq ×Freq; where Q is the comprehensive score, w cov and w freq are the weighted coefficients corresponding to the scanning coverage rate and the occurrence frequency of specific features, and w cov +w freq = 1; the weighted coefficients can be determined according to the actual situation. For example, if the scanning coverage rate is crucial for this scanning process, a higher weighted coefficient can be assigned; if the occurrence frequency of specific features is more critical for the scanning process, a higher weighted coefficient can be given. This will not be limited here.

[0121] Finally, based on the comprehensive score and the time of the scanning process, the time allocation for automated vulnerability scanning and manual vulnerability scanning is obtained. Specifically, there is a formula where Time 自动化 represents the time for automated vulnerability scanning, Time is the time for the entire scanning process, and Q is the comprehensive score. Then Time - Time 自动化 is the time for manual vulnerability scanning. For example, if the occurrence frequency of specific features Freq is 0.7, the scanning coverage rate of automated vulnerability scanning is 0.9, w freq and w cov are 0.6 and 0.4 respectively, and the time for the scanning process Time is 50 minutes. Through formula calculation, Q = 0.78, Time 自动化 is 11 minutes, then the time for manual vulnerability scanning is 39 minutes.

[0122] By reasonably allocating the scanning time, it is possible to ensure the full utilization of the advantages of automated and manual vulnerability scanning, thereby maximizing the vulnerability discovery rate. Automated scanning can quickly detect common vulnerabilities, while manual scanning can discover more complex and customized vulnerabilities. The combination of the two can improve the overall vulnerability detection efficiency.

[0123] Embodiment 3

[0124] The present invention also provides a network security intelligent vulnerability scanning system for implementing the network security intelligent vulnerability scanning methods described in Embodiments 1 and 2, including a data acquisition module, a data processing module, and a data storage module;

[0125] The data acquisition module is used to obtain the security requirement data and real-time detection requirement data of network security, and send them to the data processing module to ensure the operation of the subsequent data processing module;

[0126] The data processing module is used to determine the selection of the vulnerability scanning method according to the data collected by the data acquisition module and start the implementation;

[0127] The data storage module is used to store all the data generated during the processing of the network security intelligent vulnerability scanning system.

[0128] The above formulas are all dimensionless and take their numerical values for calculation. The formulas are obtained by collecting a large amount of data for software simulation to get a formula closest to the real situation. The preset parameters in the formulas are set by those skilled in the art according to the actual situation.

[0129] The above embodiments can be implemented in whole or in part by software, hardware, firmware, or any other combination. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product.

[0130] Those of ordinary skill in the art can realize that the modules and algorithm steps of each example described in combination with the embodiments disclosed in this article can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in hardware or software depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.

[0131] In addition, in each embodiment of the present application, the functional modules can be integrated in a processing module, or each module can exist physically alone, or two or more modules can be integrated in one module.

[0132] As described above, it is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present application can easily think of changes or substitutions, which should all be covered within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the protection scope of the said claims.

[0133] Finally: The above description is only the preferred embodiment of the present invention and is not used to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.

Claims

1. A network security intelligent vulnerability scanning method, characterized in that: The steps include: Step 1: Adjust and determine the network security vulnerability scanning strategy based on network security demand data and real-time detection demand data; Step 2: Collect the security requirement analysis data and calculate the security requirement data of network security; Step 3: Determine the vulnerability scanning method based on the network security demand data and real-time detection demand data, and start implementation; In step 1, the network security vulnerability scanning strategy includes performing automated vulnerability scanning first, then performing manual vulnerability scanning, and only performing manual vulnerability scanning to deeply analyze the network security system; In step 2, the security requirement data of network security includes software security requirement data and hardware security requirement data; Software security requirement data includes permission management data, security audit data, and code security requirement data; Hardware security requirements for network security include hardware encryption; The calculation method of software safety requirement data is as follows: Step S1: Data preparation, collecting security-related data in the code, including security requirement information of code snippets, functions, or the entire module; for each code snippet, extracting corresponding features, including input verification, output encoding, and permission control; Step S2: Select a suitable feature. If the code snippet contains input validation, the feature is 1, otherwise it is 0. The presence of input validation indicates that the code performs validation before accepting user input to ensure the security and validity of the input. Step S3: pre-processing the feature data to ensure that the feature data is suitable for processing by the clustering algorithm; Step S4: For cluster analysis of feature data, select K-means clustering algorithm; Step S5: Select an appropriate number of clusters according to specific needs. When n code snippets are collected, the number of clusters is selected as n; Step S6: Initialize the cluster centers, select K samples from the feature data as the initial cluster centers, and then iteratively select the next cluster center until k cluster centers are selected so that they do not change; Step S6.1: For each sample point, calculate its distance to each cluster center using the Euclidean distance calculation. The specific formula is: Where Xi is a sample point in the feature data set, representing the i-th code snippet, Cj is the j-th feature data point as the cluster center, Xik and Cjk represent the values ​​of points Xi and Cj on the k-th feature, and N is the number of features; For each data point, find the cluster center closest to it and assign the data point to the cluster where the closest cluster center is located, that is, assign each sample point Xi to the cluster center Cj so that j = argmin j d(Xi, Cj); where arg min means evaluating j so that the following expression is minimized; Step S6.2: Update the cluster center. After all data points are assigned to the corresponding clusters, there will be multiple data points in each cluster. Next, the center of the cluster is updated according to all the data points assigned to the cluster, that is, the average value of all data points in the cluster is calculated, and this average value is used as the new cluster center. The specific formula is: Where |uj| is the number of sample points in the jth cluster; Step S6.3: Repeat the process of calculating distance, assigning data points and updating cluster centers until the cluster centers no longer change or a preset number of iterations is reached; Step S7: When the algorithm converges, the cluster center represents the central position of each cluster, i.e., the security feature. Its feature reflects the common security features of the code snippets in the cluster. The frequency of a specific security feature in the cluster is counted. Suppose a cluster contains t sample points, where the feature vector of the sample point yi is expressed as Yi = (yi1, yi2, ..., yiN); the frequency of a specific security feature in the cluster is estimated by calculating the frequency of the feature in all sample points; specifically, the formula Where δ(yif, f) is the indicator function, which takes the value of 1 when the feature yif in the sample point yi is equal to the specific security feature f, otherwise it takes the value of 0; by calculating the frequency of the specific security feature in the cluster, we can understand the prevalence of the feature in the cluster; the feature frequency is a proportional value between 0 and 1, indicating the frequency of the specific security feature in the cluster; if the feature appears in all sample points in the cluster, the frequency is 1; if the feature does not appear in all sample points in the cluster, the frequency is 0; In step 2, the time allocation for the two scanning methods is comprehensively analyzed based on the frequency of occurrence of specific features in the software security requirement data and the scanning coverage of the automated vulnerability scanning in the actual detection requirement data. The specific process is as follows: First, obtain the frequency of occurrence of specific features and the scan coverage of automated vulnerability scanning. The frequency of occurrence of specific features is Freq, and its value ranges from 0 to 1. Scan coverage refers to the ratio between the number of vulnerabilities that can be detected by the scanning tool or method and the total number of vulnerabilities in vulnerability scanning. The specific calculation formula is: Among them, "number of detected vulnerabilities" refers to the number of vulnerabilities actually found by the scanning tool or method, while "total number of vulnerabilities" refers to the number of all vulnerabilities that may exist in the target system or application, including known and unknown vulnerabilities; Secondly, a comprehensive analysis is conducted on the occurrence frequency of specific features in the software security demand data and the scan coverage of automated vulnerability scans in the actual detection demand data; assuming that the time of the entire scanning process is represented by Time and the scan coverage is represented by R cov Indicates that the frequency of occurrence of a specific feature is represented by Freq, and the weighted average is used to calculate the comprehensive score Q; Finally, the time allocation for automated vulnerability scanning and manual vulnerability scanning is obtained based on the comprehensive score and the time of the scanning process; the specific formula is Where Time 自动化 Indicates the time of automated vulnerability scanning, Time is the time of the entire scanning process, and Q is the comprehensive score; then Time-Time 自动化 The time for manual vulnerability scans.

2. The network security intelligent vulnerability scanning method according to claim 1 is characterized in that: In step 3, the acquired security requirement data and real-time detection requirement data are defined as input variables, divided into different fuzzy sets, and the selected vulnerability scanning method is defined as output variable. The automated vulnerability scanning followed by manual vulnerability scanning is calibrated as P1, and the automated scanning is calibrated as P2. Formulate fuzzy rules to describe the impact of different input variables on output variables Perform fuzzy reasoning based on fuzzy rules to obtain a suitable vulnerability scanning method.

3. The network security intelligent vulnerability scanning method according to claim 1 is characterized in that: In step 3, only the network security is automatically scanned for vulnerabilities. The specific process is as follows: D1: Target determination, determine the target of vulnerability scanning; D2: Scan configuration, select the scanning tool and configure it; D3: Scan execution; D4: Vulnerability identification, which lists the detected vulnerabilities and issues; D5: Vulnerability assessment: For each identified vulnerability, evaluate it to determine its severity and impact; D6: Repair suggestions: Provide repair suggestions for each identified vulnerability; D7: Vulnerability repair: perform vulnerability repair work according to the repair suggestions provided in the vulnerability scanning report; D8: Reporting and tracking, after generating the vulnerability scan report, submit it to the relevant team or manager for review; D9: Repeat regularly and perform vulnerability scans regularly to ensure system security.

4. The network security intelligent vulnerability scanning method according to claim 1, characterized in that: In step 3, perform automated vulnerability scanning first and then perform manual vulnerability scanning. Based on the automated vulnerability scanning, the specific process of manual vulnerability scanning is as follows: T1: Target identification and confirmation, first identify and confirm the target system or application; T2: Information gathering and reconnaissance, collecting information related to the target system; T3: Vulnerability detection and assessment, discovering security vulnerabilities in the target system and performing a comprehensive scan using vulnerability scanning tools; T4: Authentication and authorization testing: Testing the authentication and access control mechanisms of the target system to discover possible weaknesses and vulnerabilities; T5: Vulnerability verification and exploitation: For discovered vulnerabilities, in-depth manual verification is performed to ensure that the vulnerabilities exist and can be exploited; T6: Report writing and delivery, the process of compiling vulnerability scan and test results into detailed reports and submitting them to the customer or organization's security team; T7: Vulnerability fixing and tracking, assisting system administrators and developers to fix discovered vulnerabilities and track the progress of vulnerability fixing.

5. A network security intelligent vulnerability scanning system, used to implement the network security intelligent vulnerability scanning method according to any one of claims 1 to 4, characterized in that: It includes data acquisition module, data processing module and data storage module; The data acquisition module is used to obtain network security demand data and real-time detection demand data, and send it to the data processing module to ensure the operation of the subsequent data processing module; The data processing module is used to determine the vulnerability scanning method based on the data collected by the data collection module and start implementation; The data storage module is used to store all data generated during the processing of the network security intelligent vulnerability scanning system.

Citation Information

Patent Citations

  • Network protocol variation detection method and device, electronic equipment and storage medium

    CN111726264A

  • Vulnerability scanning mode scheduling method and device

    CN117171761A