Network Security Risk Identification Method, Device, Medium, Electronic Device and Program Product
By obtaining and analyzing the network topology diagram of the target object and combining business attributes and security characteristics for attack link analysis, the problem of security risks identification and repair in the cloud environment is solved, and accurate identification and rapid response to key risks is achieved.
Patent Information
- Application Number
- CN202410870283.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-06-28
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2044-06-28
AI Technical Summary
In the cloud environment, the assets, permissions, and security policies provided by cloud manufacturers are heterogeneous, resulting in continued increase in risks, configuration, and permissions, making it difficult for existing technologies to accurately identify and repair serious security risks.
By obtaining the network topology diagram of the target object, combining the business attributes and security characteristics of the asset, attack link analysis is carried out to identify security risks in the network.
It realizes accurate identification of security risks in cloud environments, reduces the time for repairing non-essential risks, ensures the continuity of key business processes, and reduces business interruptions caused by security issues.
Smart Images

Figure CN118555128B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of network security technologies, and in particular, to a network security risk identification method, device, medium, electronic device, and program product. Background Art
[0002] With the migration of services to the cloud, the popularity of multi-cloud and hybrid cloud environments has brought new security challenges. In the cloud environment, the assets, permissions heterogeneity, and inconsistent security policies provided by each cloud provider have continuously increased risks such as load, configuration, and permissions. A large number of risks and vulnerabilities make it impossible for the business team to repair them manually, and it is difficult to reconcile business development and security convergence. At present, cloud providers usually determine the severity of risks according to the classification and destructiveness of risks. For example, vulnerabilities are divided into high-risk, medium-risk, and low-risk. However, for the business, some high-risk vulnerabilities are in an isolated environment, or some serious configuration anomalies are in a test environment, and the severity of the risk does not really reflect the urgency of risk repair. Moreover, the risk magnitude is large, resulting in unnecessary risks taking up more time for repair and affecting business development. Summary of the Invention
[0003] This Summary of the Invention section is provided to introduce concepts in a brief form, which will be described in detail in the subsequent Detailed Implementation section. This Summary of the Invention section is not intended to identify key features or essential features of the claimed technical solution, nor is it intended to be used to limit the scope of the claimed technical solution.
[0004] In a first aspect, the present disclosure provides a network security risk identification method, including: obtaining a target network topology map based on a target object, where the target network topology map is used to represent the relationship between the target object and its related assets; and performing an attack link analysis on the target network topology map based on the business attributes and security characteristics of the assets in the target network topology map to identify security risks in the target network topology map.
[0005] In a second aspect, the present disclosure provides a network security risk identification device, including: a first acquisition module, configured to obtain a target network topology map based on a target object, where the target network topology map is used to represent the relationship between the target object and its related assets; and a link analysis module, configured to perform an attack link analysis on the target network topology map based on the business attributes and security characteristics of the assets in the target network topology map to identify security risks in the target network topology map.
[0006] In a third aspect, the present disclosure provides a computer-readable medium, on which a computer program is stored, and when the computer program is executed by a processing device, the steps of the network security risk identification method provided in the first aspect of the present disclosure are implemented.
[0007] Fourthly, the present disclosure provides an electronic device, including: a storage device storing a computer program thereon; a processing device configured to execute the computer program in the storage device to implement the steps of the network security risk identification method provided in the first aspect of the present disclosure.
[0008] Fifthly, the present disclosure provides a computer program product, including a computer program which, when executed by a processor, implements the steps of the network security risk identification method provided in the first aspect of the present disclosure.
[0009] In the above technical solution, a target network topology graph based on a target object is obtained; then, based on the business attributes and security characteristics of the assets in the target network topology graph, an attack link analysis is performed on the target network topology graph to identify security risks in the target network topology graph. In this way, the network topology graph can be utilized to combine risks with the business attributes and security characteristics of the assets in the network topology graph, and an attack link analysis is performed from the perspective of an attacker, so as to more accurately identify key risks, reduce the number of business repair risks, focus on the risks that can most cause asset losses, ensure the continuity of key business processes, and reduce business interruptions caused by security issues. Additionally, through automated attack link analysis, potential security threats can be quickly identified, enabling rapid response and repair, and reducing the impact of security incidents on the business. Furthermore, only the target network topology graph related to the target object is generated, rather than the network topology graph of the entire business system. In this way, a multi-layer topology effect can be achieved with less storage space, so that key risk identification can be carried out targeted. Moreover, through the target network topology graph, risk repair personnel can clearly see the asset losses caused by not repairing, increasing the motivation of risk repair personnel for repair.
[0010] Other features and advantages of the present disclosure will be described in detail in the subsequent specific implementation section. BRIEF DESCRIPTION OF THE DRAWINGS
[0011] In combination with the drawings and with reference to the following specific implementation, the above and other features, advantages and aspects of the embodiments of the present disclosure will become more obvious. Throughout the drawings, the same or similar reference numerals represent the same or similar elements. It should be understood that the drawings are schematic, and the original components and elements are not necessarily drawn to scale. In the drawings:
[0012] Figure 1 is a core principle diagram of a network security risk identification method shown according to an exemplary embodiment.
[0013] Figure 2 is a flowchart of a network security risk identification method shown according to an exemplary embodiment.
[0014] Figure 3It is a flowchart of a method for generating a target network topology diagram according to the connection relationship between assets and the mapping relationship between elastic public network IPs and assets, as shown in an exemplary embodiment.
[0015] Figure 4 It is a flowchart of a method for adding assets and elastic public network IPs related to the current node to the first network topology diagram according to the connection relationship between assets and the mapping relationship between elastic public network IPs and assets, as shown in an exemplary embodiment.
[0016] Figures 5A to 5D It is a schematic diagram of the process for generating a target network topology diagram according to the connection relationship between assets and the mapping relationship between elastic public network IPs and assets, as shown in an exemplary embodiment.
[0017] Figure 6 It is a flowchart of a network security risk identification method, as shown in another exemplary embodiment.
[0018] Figure 7 It is a flowchart of a network security risk identification method, as shown in yet another exemplary embodiment.
[0019] Figure 8 It is a block diagram of a network security risk identification device, as shown in an exemplary embodiment.
[0020] Figure 9 It is a schematic diagram of the structure of an electronic device, as shown in another exemplary embodiment. Detailed implementation manners
[0021] Before introducing the specific embodiments of the present disclosure, the terms related to the present disclosure and the core principles of security risk identification are first introduced and explained.
[0022] Elastic Compute Service (ECS) is a cloud computing service that allows users to rent virtual servers in the cloud to run applications and process data.
[0023] In the fields of information security and risk management, assets usually refer to an organization's information assets, including hardware, software, data, documents, services, etc. These assets are crucial for the organization's operations, decision-making, and competitiveness, and thus need to be properly protected and managed. Exemplarily, assets can be ECS, Virtual Private Cloud (VPC), subnet, network interface card, Server Load Balancer (SLB), Network Address Translation (NAT), virtual IP, container, Elastic IP (EIP), etc.
[0024] Assets can be classified into core assets and non-core assets according to their business attributes. Among them, core assets are a set of assets that run core businesses and need to be protected with emphasis. They are the assets that attackers ultimately want to obtain or destroy. Core assets are assets that meet preset conditions. The preset conditions can be assets with core tags, and core assets and non-core assets can be classified manually. Core assets include but are not limited to data assets, equipment assets, and operating systems that need to be protected with emphasis. Non-core assets refer to assets with relatively low importance to the organization. They may have a certain impact on daily operations, but even if they are damaged or lost, they will not cause serious or long-term impacts on the organization.
[0025] Internet exposure usually means that on the public network, some devices, services, or data are not properly protected or hidden, making them vulnerable to unauthorized access or attacks. In the field of network security, this is usually a serious problem because it may lead to risks such as the leakage of sensitive information, system intrusion, or data tampering.
[0026] In the field of network security, lateral movement is the process by which an attacker uses vulnerabilities or improper configurations to move from an infected system or network node to another, in order to expand the scope of the attack or obtain more sensitive information. This movement can be achieved through trust relationships in the internal network, using known credentials, or exploiting other system vulnerabilities. Once an attacker successfully makes a lateral movement, it may pose a greater threat to the entire network, including data leakage, system paralysis, or business interruption.
[0027] A Web Shell is a script or program that executes commands through a scripting language on a Web server and is usually used for remote management of the Web server. It allows users to execute system commands through a Web interface, just like operating directly on the command line of the server.
[0028] Cloud Security Posture Management (CSPM) is a strategy and technology focused on improving security performance in cloud environments. The goal of CSPM is to ensure that cloud resource configurations comply with security standards, detect and fix security vulnerabilities in a timely manner, and continuously monitor the security status of cloud resources.
[0029] Cloud Identity and Event Management (CIEM) is a cloud security solution that focuses on managing identities and cloud permissions through the principle of least privilege.
[0030] Distributed Denial of Service (DDoS) is a common network attack method. Attackers control or utilize a large number of computers or network devices to send a large number of useless requests or data packets to the target server, consuming its bandwidth, CPU, and memory resources, thereby making it unable to process normal requests or provide normal services.
[0031] A bastion host, also known as an operation and maintenance security audit system, in a specific network environment, is used to protect the network and data from intrusion and damage by external and internal users. It uses various technical means to monitor and record the operation behaviors of operation and maintenance personnel on devices such as servers, network devices, security devices, and databases within the network, facilitating centralized alarm, timely processing, and audit liability determination.
[0032] Log4j is an open-source project of the Apache Software Foundation, providing a powerful logging management tool for Java. It aims to set logging behaviors at runtime through configuration files, enabling flexible control over the output format of logs, output destinations (such as consoles, files, GUI components, etc.), and log levels.
[0033] Git is an open-source distributed version control system used to track changes in project files. It allows developers to record every update and modification of file content and manage the project history of multiple versions.
[0034] One-Liner Shell usually refers to a very short script code that can be embedded in a web page or uploaded to a server in other ways. Although this code is short, it is powerful and allows attackers to execute remote commands or gain control of the server. It is usually contained in one line of code, so it is called "one-liner".
[0035] A prefix list is a set of rules used to match the destination network segment address or the next-hop address in routing information. A prefix list typically includes prefixes (i.e., IP addresses) and mask length ranges, and these rules are used to filter the routing information advertised and received by routing protocols. Specifically, a prefix list can be used to specify which networks are reachable and which are not, thereby controlling the propagation of routing information. A prefix list has two main parameters: the prefix and the prefix length (or subnet mask). The prefix is the specified routing prefix (network segment), and the prefix length specifies the length of the subnet mask.
[0036] The core principle of security risk identification is elaborated below. As Figure 1 shown, there are usually two entry points for an attacker to break into core assets: one entry point is public network exposure, which belongs to the network layer entry point. Through public network exposure, the core assets can be reached on the network path. For example, an attacker can move laterally from a compromised non-core asset to a core asset; the other entry point is secret leakage.
[0037] As Figure 1 shown, an attacker can attack core assets through public network exposure. If non-core assets (such as Figure 1 the cloud resources shown in
[0038] (a1) Network vulnerabilities can be exploited: Attack through exploitable network vulnerabilities, such as the log4j vulnerability;
[0039] (a2) Web Shell / malware can be exploited: An attacker uploads a Web Shell through a Web application or deploys malware through a malicious image, etc., causing users to deploy it;
[0040] (a3) An attacker breaks into non-core assets through attacks, such as a one-line shell;
[0041] (a4) An attacker breaks into non-core assets through brute force cracking or weak passwords (i.e., weak passwords).
[0042] When resource codes such as plaintext access keys (Access Key, AK), secret keys (SecretKey, SK), and database passwords are deployed on non-core assets, an attacker can further expand the attack to obtain access rights to core assets, that is, reach core assets through unreasonable network configurations, namely Figure 1Reaching core assets through CSPM as shown. When non-core assets can access database resources such as Relational Database Service (RDS), MongoDB, etc., attackers can further conduct brute force attacks to amplify permissions in order to obtain core data (i.e., reach core assets), that is Figure 1 Reaching core assets through CIEM as shown. After breaking non-core assets, the compromised non-core assets can also move laterally to core assets.
[0043] Such as Figure 1 shown, attackers can also attack core assets from identity permissions, that is, break core assets through secret leakage. There are the following specific ways:
[0044] (b1) If some core assets are not set with authorized access (i.e., anonymous access), attackers can easily obtain core data, that is, reach core assets;
[0045] (b2) If the AK is leaked, such as developers embedding the AK plaintext or SK plaintext in the code and uploading it to Git, the core assets can be easily broken by attackers;
[0046] (b3) When internal users steal core confidential data with their own permissions, resulting in data leakage (i.e., Figure 1 the abnormal users shown);
[0047] (b4) If attackers obtain a certain cloud identity, due to CSPM anomalies resulting in identity permission amplification, attackers can obtain more cloud resources, that is, through the secret leakage entry, reach core assets through permission amplification (i.e., Figure 1 reaching core assets through CSPM as shown).
[0048] Embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although some embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. On the contrary, these embodiments are provided to more thoroughly and completely understand the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are only for exemplary purposes and are not used to limit the protection scope of the present disclosure.
[0049] It should be understood that the various steps recorded in the method embodiments of the present disclosure can be executed in different orders and / or executed in parallel. In addition, the method embodiments may include additional steps and / or omit the steps shown. The scope of the present disclosure is not limited in this regard.
[0050] As used herein, the term "including" and its variations are open-ended, i.e., "including but not limited to". The term "based on" means "at least partially based on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". Relevant definitions of other terms will be given in the following description.
[0051] It should be noted that the concepts such as "first", "second", etc. mentioned in this disclosure are only used to distinguish different devices, modules or units, and are not used to limit the order or interdependence of the functions performed by these devices, modules or units.
[0052] It should be noted that the modifications of "one" and "multiple" mentioned in this disclosure are illustrative rather than restrictive. Those skilled in the art should understand that unless otherwise clearly specified in the context, it should be understood as "one or more".
[0053] The names of the messages or information exchanged between multiple devices in the embodiments of this disclosure are only for illustrative purposes and are not used to limit the scope of these messages or information.
[0054] It can be understood that before using the technical solutions disclosed in the embodiments of this disclosure, the types, usage scopes, usage scenarios, etc. of the personal information involved in this disclosure should be informed to the user and the user's authorization should be obtained in an appropriate manner in accordance with relevant laws and regulations.
[0055] For example, when responding to receiving an active request from the user, a prompt message is sent to the user to clearly prompt the user that the operation requested by the user will require obtaining and using the user's personal information. Thus, the user can autonomously choose whether to provide personal information to software or hardware such as an electronic device, an application program, a server, or a storage medium that performs the operations of the technical solutions of this disclosure according to the prompt message.
[0056] As an optional but non-limiting implementation manner, when responding to receiving an active request from the user, the manner of sending a prompt message to the user can be, for example, in the form of a pop-up window, and the prompt message can be presented in text in the pop-up window. In addition, the pop-up window can also carry a selection control for the user to choose "agree" or "disagree" to provide personal information to the electronic device.
[0057] It can be understood that the above process of notifying and obtaining the user's authorization is only illustrative and does not limit the implementation manners of this disclosure. Other manners that meet relevant laws and regulations can also be applied to the implementation manners of this disclosure.
[0058] Meanwhile, it can be understood that the data involved in this technical solution (including but not limited to the data itself, the acquisition or use of the data) should comply with the requirements of the corresponding laws, regulations and related provisions.
[0059] Figure 2 is a flowchart of a network security risk identification method shown according to an exemplary embodiment. As Figure 2 shown, the above network security risk identification method may include the following S101 and S102.
[0060] In S101, a target network topology map based on a target object is obtained.
[0061] In the present disclosure, the target object may be an object preset by a user or determined based on a security risk identification request initiated by the user. Among them, the security risk identification request is used to indicate the identification of security risks related to the target object, and the security risk identification request may include the target object. The target network topology map is used to characterize the relationship between the target object and its related assets. Among them, the target object may include one of assets, identities, and resources. Among them, identity entities can be divided into five types, namely users, user groups, roles, services, and identity providers (Identity Provider, IDP); resources include databases, and assets may include at least one of virtual private cloud VPC, subnet, network card, elastic computing service, and container.
[0062] In S102, based on the business attributes and security characteristics of the assets in the target network topology map, an attack link analysis is performed on the target network topology map to identify security risks in the target network topology map.
[0063] In the present disclosure, the business attributes of the assets are used to characterize whether the corresponding assets are core assets, and the security characteristics of the assets may include characteristics such as lateral movement and public network exposure of the assets. Using the network topology map, the risks are combined with the business attributes and security characteristics of the assets in the network topology map, and an attack link analysis is performed from the perspective of an attacker.
[0064] In the above technical solution, a target network topology diagram based on a target object is obtained; then, based on the business attributes and security characteristics of the assets in the target network topology diagram, an attack link analysis is performed on the target network topology diagram to identify security risks in the target network topology diagram. In this way, the network topology diagram can be used to combine risks with the business attributes and security characteristics of the assets in the network topology diagram, and an attack link analysis can be performed from the perspective of an attacker, so as to more accurately identify key risks, reduce the number of business repair risks, focus on the risks that can most cause asset losses, ensure the continuity of key business processes, and reduce business interruptions caused by security issues. In addition, through automated attack link analysis, potential security threats can be quickly identified, so that a rapid response and repair can be made, reducing the impact of security incidents on the business. Furthermore, only the target network topology diagram related to the target object can be generated, rather than the network topology diagram of the entire business system. In this way, a multi-layer topology effect can be achieved with less storage space, so that key risk identification can be carried out targeted. And through the target network topology diagram, risk repair personnel can clearly see the asset losses caused by not repairing, increasing the motivation of risk repair personnel to repair.
[0065] The following will detail the specific implementation of obtaining the target network topology diagram based on the target object in S101 above.
[0066] Specifically, when obtaining the target network topology diagram based on the target object, it can first be detected whether a network topology diagram based on the target object has been generated within a preset time period before the current moment. If a network topology diagram based on the target object has been generated within the preset time period before the current moment, the generated network topology diagram is directly used as the target network topology diagram; if a network topology diagram based on the target object has not been generated within the preset time period before the current moment, different topology diagram generation methods can be used according to different types of target objects to generate the target network topology diagram.
[0067] In one implementation, the target object is an asset, which can specifically include target assets. At this time, a target network topology diagram representing the relationship between the target assets and other related assets can be generated by according to the connection relationship between assets and the mapping relationship between elastic public network IPs and assets.
[0068] In the present disclosure, the connection relationships between assets may include relationships between different VPCs, relationships between subnets, relationships between a subnet and the assets or IPs within its affiliated VPC, relationships between bastion hosts and ECSs, relationships between EIPs and cloud walls, relationships between a Web Application Firewall (WAF) and service groups, restrictive relationships between the WAF and the Internet, etc. Among them, the restrictive relationship between the WAF and the Internet is mainly reflected in the prevention of Web application attacks by the WAF and the restriction of access ports.
[0069] In another implementation, the target object is a resource or an identity, specifically including a target resource or a target identity. At this time, the target network topology diagram based on the target object can be generated through the following steps (c1) to (c4):
[0070] Step (c1): Obtain a permission topology diagram based on the target object, where the permission topology diagram is used to represent the relationship between identities and resources.
[0071] In one implementation, the target object is a target resource. At this time, according to the pre-established correspondence between identities and resources (used to represent the resources that different identities can access), the identities corresponding to the target resource can be obtained. Then, a topology diagram is used to represent the connection relationship between the target resource and its corresponding identities, that is, the permission topology diagram based on the target resource is obtained.
[0072] In another implementation, the target object is a target identity. At this time, according to the pre-established correspondence between identities and resources, the resources corresponding to the target identity can be obtained. Then, a topology diagram is used to represent the connection relationship between the target identity and its corresponding resources, that is, the permission topology diagram based on the target identity is obtained.
[0073] Among them, the attributes of the connection relationship between resources and identities may include read-only, read-write, management, privilege (for example, including all permissions such as read-write, management, etc.).
[0074] Step (c2): Based on the pre-established correspondence between assets and resources, determine the assets related to the resources in the permission topology diagram.
[0075] In the present disclosure, each resource is usually configured with a whitelist, and only the assets in the whitelist can access the corresponding resources. The correspondence between assets and resources can be constructed according to the whitelist corresponding to each resource.
[0076] Step (c3): Obtain a tenth network topology diagram based on the related assets.
[0077] In the present disclosure, if a network topology diagram based on relevant assets has been generated within a preset time period before the current moment, the generated network topology is directly used as the tenth network topology diagram; if a network topology diagram based on relevant assets has not been generated within the preset time period before the current moment, a tenth network topology diagram based on relevant assets can be generated according to the connection relationship between assets and the mapping relationship between elastic public network IPs and assets.
[0078] Step (c4): Add the tenth network topology diagram to the permission topology diagram to obtain a target network topology diagram based on the target object.
[0079] The target network topology diagram based on the target identity or target resource not only includes the relationship between the identity and the resource, but also includes the relationship between the resource and the asset. In this way, an association relationship can be established between the identity and the asset, so that more security risks can be mined starting from the secret leakage as the attack entry point.
[0080] The following will elaborate on the construction method of the connection relationship between the above-mentioned assets. Specifically, it can be achieved through the following steps (d1) to (d3):
[0081] Step (d1): Collect assets in the business system.
[0082] In the present disclosure, assets in the business system can be queried based on asset identifiers (such as IDs), and an association relationship between the assets and the asset identifiers is established.
[0083] Step (d2): Process the relationships of the collected assets.
[0084] In the present disclosure, the relationship processing can specifically include: for each VPC in the business system, constructing the corresponding relationship between the VPC identifier, the asset identifier, and the IP segment of the asset; constructing the mapping relationship between the EIP and the asset; constructing the corresponding relationship between the NAT and the ECS, and constructing the corresponding relationship between the SLB and the ECS; associating the access control list (ACL) with the subnet and abstracting the ACL into a unified structure permission; associating the policies of the cloud wall (i.e., the permission list of the cloud wall) with the assets bound by the cloud wall and abstracting the policies of the cloud wall into a unified structure permission; abstracting the policies of the security group (i.e., the permission list of the security group) into a unified structure permission.
[0085] Among them, permission usually refers to a data structure or object model that encapsulates the rules and attributes of access control. This structure can contain various elements, such as operations (allow / deny), protocol types (such as TCP, UDP, ICMP), port ranges, address information (including any one of the source IP address, destination IP address, network segment), etc. The policies of the cloud firewall are divided into two categories, one is the cloud firewall policy based on EIP, and the other is the cloud firewall policy across VPCs.
[0086] Step (d3): Based on the processing results of the assets, construct the connection relationships between the above-mentioned assets.
[0087] In the disclosure, the relationships between different VPCs, between subnets, and between a subnet and the assets or IPs within its affiliated VPC can be constructed by traversing the routing tables in the business system. Specifically, it can be achieved through the following methods:
[0088] First, for each routing table in the business system, find the VPC and subnet to which the routing table belongs according to the identifier of the VPC and the identifier of the subnet to which the routing table belongs; then, associate the routing table with its affiliated VPC and subnet. At the same time, obtain the routing entries in the routing table and traverse them. Among them, the routing entries are classified and processed according to the next-hop type, and the routing entry consists of (destination IP address, next-hop type, next-hop identifier).
[0089] Specifically, if the destination IP address in the current routing entry is 100.64.0.0 / 10, it is ignored, that is, no relationship association operation is performed; if the destination IP address in the current routing entry is the default gateway (for example, 0.0.0.0 / 0), obtain the next-hop asset according to the next-hop identifier in the routing entry, establish a one-way connection relationship between the VPC to which the routing table belongs and the next-hop asset, and mark the next-hop asset as "gateway"; if the destination IP address in the current routing entry is neither 100.64.0.0 / 10 nor the default gateway, construct the relationship according to the next-hop type in the current routing entry.
[0090] Among them, the relationship can be constructed through the following methods according to the next-hop type in the current routing entry:
[0091] If the next-hop type in the current routing entry is InnerSubnet, then according to the correspondence relationship between the VPC identifier, asset identifier, and IP segment of the asset constructed in step (d2) above, determine the first target asset identifier corresponding to the destination IP address in the current routing entry, and according to the association relationship between the asset and the asset identifier constructed in step (d1) above, determine the first target asset (specifically, the target subnet) corresponding to the first target asset identifier; then, establish a one-way connection relationship between the subnet to which the routing table belongs and the target subnet, and mark this connection relationship as "Intra-VPC connection".
[0092] If the next-hop type in the current routing entry is a prefix list, then according to the next-hop identifier (i.e., the prefix list identifier), obtain the IP prefix object (i.e., the target prefix list) corresponding to the next-hop identifier; then, according to the correspondence relationship between the VPC identifier, asset identifier, and IP segment of the asset constructed in step (d2) above, determine the first target IP segment that matches the IP prefix object and the second target asset identifier corresponding to this first target IP segment; next, according to the association relationship between the asset and the asset identifier constructed in step (d1) above, determine the second target asset corresponding to the second target asset identifier, and establish a connection relationship between the subnet to which the routing table belongs and the second target asset.
[0093] If the next-hop type in the current routing entry is any one of a cloud server, auxiliary network card, NAT gateway, highly available virtual IP, and IPv6 gateway, then according to the correspondence relationship between the VPC identifier, asset identifier, and IP segment of the asset constructed in step (d2) above, determine the second target IP segment that is consistent with the destination IP address in the current routing entry and the third target asset identifier corresponding to this second target IP segment, and according to the association relationship between the asset and the asset identifier constructed in step (d1) above, determine the third target asset corresponding to the third target asset identifier; then, establish a one-way connection relationship between the subnet to which the routing table belongs and the third target asset, and mark the connection relationship as "Intra-VPC connection". If there is no IP segment in the correspondence relationship between the VPC identifier, asset identifier, and IP segment of the asset that is consistent with the destination IP address, and the destination IP address is a subset of a certain IP segment (hereinafter referred to as the third target IP segment) in this correspondence relationship, then according to this correspondence relationship, determine the fourth target asset identifier corresponding to the third target IP segment, and according to the association relationship between the asset and the asset identifier constructed in step (d1) above, determine the fourth target asset corresponding to the fourth target asset identifier; then, establish a one-way connection relationship between the subnet to which the routing table belongs and the fourth target asset, and mark the connection relationship as "Limited connection", and attach the destination IP address to the relationship.
[0094] If the next-hop type in the current routing entry is any one of Cloud Enterprise Network, VPN Gateway, Transit Router, and Dedicated Line, obtain the connection asset corresponding to the next-hop identifier in the current routing entry, and find the peer asset based on the connection asset; then, establish a one-way relationship between the VPC to which the routing table belongs and the peer asset, and mark the connection relationship as "connection between VPCs".
[0095] To facilitate users to correct the relationship in a timely manner when there are problems with the relationship, after establishing the above relationship, the routing table identifier and the current routing entry identifier can be attached to the relationship as the source of establishing the relationship.
[0096] The following details the specific construction methods for the above relationships between WAF and service groups, and the restrictive relationships between WAF and the Internet. Specifically, when the user enables WAF: If WAF is SLB WAF, establish the relationship between SLB and WAF; if WAF is Canonical Name (CNAME) WAF, obtain the public network provided by WAF, establish the relationship between the EIP of this public network and WAF, obtain the list of backend server IPs bound to WAF, convert this IP list into assets, and establish the relationship between WAF and the assets obtained after conversion.
[0097] In addition, the asset instance with the cloud wall enabled can be obtained, and then, a two-way relationship between the asset instance and the cloud wall can be established, so as to realize the construction of the relationship between the EIP and the cloud wall. And when the ECS enables the bastion host, establish the relationship between this ECS and the bastion host.
[0098] The following details the specific implementation methods for generating a target network topology diagram that represents the relationship between the target asset and other related assets based on the connection relationship between assets and the mapping relationship between the Elastic Public IP and assets. Specifically, the target asset can include at least one VPC. Among them, when generating the topology diagram between VPCs, the target asset can include one or more VPCs; when generating the topology diagram between subnets in a VPC, the target asset includes one VPC, and the target network topology diagram is used to represent the connection relationship between subnets in this one VPC. At this time, the target network topology diagram can be generated through Figure 3 Steps 1 to 6 shown below:
[0099] Step 1, use the first node in the target sequence as the current node.
[0100] Among them, when generating the topology diagram between VPCs, the target sequence is composed of the above at least one VPC; when generating the topology diagram between subnets in a VPC, the target asset includes one VPC, and the target sequence is composed of the subnets in this one VPC.
[0101] Step 2: Determine whether the current node exists in the first network topology diagram.
[0102] In the present disclosure, the first network topology diagram is initially empty. If the current node exists in the first network topology diagram, it indicates that the assets directly related to the current node have been added to the first network topology diagram. At this time, the current node can be ignored, and the next node of the current node in the target sequence can be considered, that is, directly execute the following Step 3; if the current node does not exist in the first network topology diagram, consider adding the assets directly related to the current node to the first network topology diagram, that is, execute the following Step 4, and then execute Step 3.
[0103] Step 3: Determine whether the current node has a next node.
[0104] If the current node has a next node, execute the following Step 5; if the current node does not have a next node, it indicates that all relevant relationships have been added to the first network topology diagram. At this time, the construction of the first network topology diagram is completed, and the latest first network topology diagram is determined as the target network topology diagram, that is, execute the following Step 6.
[0105] Step 4: Add the assets and elastic public network IPs related to the current node to the first network topology diagram according to the connection relationship between assets and the mapping relationship between elastic public network IPs and assets.
[0106] Step 5: Take the next node of the current node in the target sequence as the current node, and return to the above Step 2.
[0107] Step 6: Determine the first network topology diagram as the target network topology diagram.
[0108] The following details the specific implementation of adding the assets and elastic public network IPs related to the current node to the first network topology diagram in Step 4 above according to the connection relationship between assets and the mapping relationship between elastic public network IPs and assets. Specifically, it can be achieved through Figure 4 Steps 21 to 28 therein:
[0109] Step 21: Add the current node to the target node set.
[0110] Among them, the target node set is initially empty.
[0111] In Step 22, determine the target connection relationship related to the current node according to the connection relationship between assets.
[0112] In the present disclosure, the target connection relationship is used to characterize the relationship between the current node and its same-type assets.
[0113] In one implementation, the current node is a VPC, and the assets of the same type as the current node are also VPCs. At this time, the target connection relationship is used to represent the relationship between the current VPC and the VPCs associated with it.
[0114] In another implementation, the current node is a subnet, and the assets of the same type as the current node are also subnets. At this time, the target connection relationship is used to represent the relationship between the current subnet and the subnets associated with it, where the current subnet and the subnets associated with it belong to the same VPC.
[0115] Step 23: Add the target connection relationship to the first network topology diagram.
[0116] Step 24: If there is an elastic public network IP corresponding to the current node in the mapping relationship between the elastic public network IP and the assets, add the corresponding relationship between the corresponding elastic public network IP and the current node to the first network topology diagram.
[0117] To facilitate directly knowing whether an asset has a public network exposure when identifying security risks, the elastic public network IP corresponding to the current node can be added to the first network topology diagram.
[0118] Step 27: Determine whether the newly added nodes based on the current node in the first network topology diagram are empty.
[0119] In the present disclosure, the newly added nodes based on the current node refer to the nodes added after adding the target connection relationship associated with the current node to the first network topology diagram, where the newly added nodes do not include elastic public network IPs.
[0120] If the newly added nodes based on the current node in the first network topology diagram are not empty, perform the following Step 25; if the newly added nodes based on the current node in the first network topology diagram are empty, perform the following Step 28.
[0121] Step 26: For each newly added node in the target node set, use this newly added node as the current node.
[0122] Step 25: Remove the current node from the target node set and add the newly added nodes to the target node set.
[0123] After removing the current node from the target node set and adding the newly added nodes to the target node set, the above Step 26 can be executed, and then return to the above Step 22 to add the connection relationships related to the newly added nodes to the first network topology diagram.
[0124] In Step 28, determine whether the newly added nodes of each node in the target node set are all empty.
[0125] When the newly added nodes based on the current node in the first network topology diagram are not empty, there can be one or more newly added nodes based on the current node. At this time, the association relationships related to each newly added node can be added to the first network topology diagram respectively, that is, each newly added node is used as the current node, and the association relationships related to each current node are added to the first network topology diagram respectively; then, for each newly added node, if the newly added nodes based on this newly added node are not empty, the association relationships related to the newly added nodes based on the newly added node are added to the first network topology diagram, and so on in a loop until the newly added nodes based on the last batch of newly added nodes (that is, one or more current nodes) are all empty, that is, until the newly added nodes based on each node in the target node set are all empty. At this time, it indicates that the association relationships directly related and indirectly related to the current node have been added to the first network topology diagram, and the next node of the current node in the target sequence can be considered, that is, step 3 above is executed; if the newly added nodes based on each node in the target node set are not all empty, continue to monitor whether the newly added nodes based on each node in the target node set are all empty, that is, return to step 28 and continue to execute.
[0126] Exemplarily, the target sequence is VPC1, VPC3, VPC6. At this time, the target network topology diagram can be constructed through steps (e1) to (e6):
[0127] Step (e1): Use VPC1 as the current node. At this time, the first network topology diagram is empty, that is, VPC1 does not exist in the first network topology diagram.
[0128] Step (e2): Add the current node VPC1 to the target node set. At this time, the target node set is {VPC1}.
[0129] Step (e3): According to the connection relationship between assets, the target connection relationships related to VPC1 determined include the connection relationship between VPC1 and VPC2, and the connection relationship between VPC1 and VPC3; add this target connection relationship to the first network topology diagram to obtain Figure 5A the first network topology diagram shown.
[0130] Step (e4): The elastic public network IP corresponding to VPC1 in the above mapping relationship is EIP1. Add the corresponding relationship between EIP1 and VPC1 to Figure 5A the first network topology diagram shown to obtain Figure 5B the first network topology diagram shown in.
[0131] Step (e5): At this time, the newly added nodes based on VPC1 include VPC2 and VPC3. Remove the current node VPC1 from the target node set "{VPC1}", and add VPC2 and VPC3 to the target node set. At this time, the target node set is {VPC2, VPC3}. Then, take VPC2 and VPC3 as the current nodes respectively to add the target connection relationships related to them to Figure 5B the first network topology diagram shown in; where: for VPC2, the target connection relationship related to VPC2 determined according to the connection relationship between assets includes the connection relationship between VPC1 and VPC2, and add it to Figure 5B the first network topology diagram shown in, the obtained topology diagram does not change, that is, the newly added nodes based on VPC2 are empty. At this time, the condition that the newly added nodes for each node in the target node set are all empty is not satisfied, and continue to detect whether the condition that the newly added nodes for each node in the target node set are all empty is satisfied; for VPC3, the target connection relationships related to VPC3 determined according to the connection relationship between assets include the connection relationship between VPC3 and VPC1, and the connection relationship between VPC3 and VPC4, and add them to Figure 5B the first network topology diagram shown in, and get Figure 5C the first network topology diagram shown in. There is no EIP corresponding to VPC3 in the above mapping relationship, and no EIP addition operation is required.
[0132] Step (e6): At this time, the newly added nodes based on VPC3 include VPC4. Remove the current node VPC3 from the target node set "{VPC2, VPC3}", and add VPC4 to the target node set. At this time, the target node set is {VPC2, VPC4}. Then, VPC4 can be taken as the current node, and the target connection relationship related to VPC4 determined according to the connection relationship between assets includes the connection relationship between VPC4 and VPC3, and add it to Figure 5C the first network topology diagram shown in, the obtained topology diagram does not change, that is, the newly added nodes based on VPC4 are empty; at this time, the condition that the newly added nodes for each node in the target node set are all empty is satisfied. The VPC3 in the target sequence can be taken as the current node, Figure 5C VPC3 is already included in the first network topology diagram shown in. Therefore, VPC6 in the target sequence can be taken as the current node. For VPC6 as the current node, add the current node VPC6 to the target node set. At this time, the target node set is {VPC2, VPC4, VPC6}. The target connection relationship related to VPC6 determined according to the connection relationship between assets includes the connection relationship between VPC6 and VPC7, and add it to Figure 5C the first network topology diagram shown in, and getFigure 5D The first network topology diagram shown
[0133] Step (e7): There is no EIP corresponding to VPC6 in the above mapping relationship, so there is no need to perform the EIP addition operation. At this time, the new nodes based on VPC6 include VPC7. After that, remove the current node VPC6 from the target node set "{VPC2, VPC4, VPC6}" and add VPC7 to the target node set. At this time, the target node set is {VPC2, VPC4, VPC6}. VPC7 can be used as the current node. The target connection relationships related to VPC7 determined according to the connection relationships between assets include the connection relationship between VPC7 and VPC6. After adding it to Figure 5D the first network topology diagram shown in, the obtained topology diagram does not change, that is, the new nodes based on VPC7 are empty. At this time, the condition that the new nodes based on each node in the target node set are all empty is satisfied. After that, it is determined that the next node of VPC6 in the target sequence is empty. Therefore, Figure 5D the first network topology diagram shown in can be determined as the target network topology diagram.
[0134] To ensure the real-time accuracy of the above target network topology diagram, when there is a cloud wall between the above target connection relationships, use the strategy of the cloud wall to correct the network topology diagram after adding the target connection relationships. Specifically, before the above step 24, the above-mentioned addition of assets and elastic public network IPs related to the current node to the first network topology diagram according to the connection relationships between assets and the mapping relationships between elastic public network IPs and assets further includes:
[0135] If the target connection relationship is a cross-VPC relationship and there is a cloud wall between the target connection relationships, correct the first network topology diagram based on the permission list of the cloud wall.
[0136] At this time, the above step 24 may include: If there is an elastic public network IP corresponding to the current node in the mapping relationship between the elastic public network IP and the asset, add the corresponding relationship between the corresponding elastic public network IP and the current node to the first network topology diagram obtained after correction.
[0137] Among them, the cloud wall may include Figure 1 the firewall (Firewall, abbreviated as FW) shown in, and at the same time, the first network topology diagram can also be corrected based on the Secure Sockets Layer (SSL), Network Traffic Analysis (NTA), etc.
[0138] The following is a detailed description of the specific implementation for correcting the first network topology diagram for the above-mentioned permission list based on the cloud wall. Specifically, it can be achieved through the following steps (f1) to (f5):
[0139] Step (f1): Sort the permission list of the cloud wall from the lowest to the highest priority to obtain the first permission list.
[0140] Step (f2): Arrange the permission rules with the same priority in the first permission list in the order of the operation being deny first and then allow to obtain the second permission list.
[0141] In the present disclosure, the policy of the cloud wall is a permission list composed of permission rules. Among them, the permission rule is abstracted into a permission structure, which includes elements such as an operation (allow / deny) and address information (IP address or IP segment).
[0142] Step (f3): Traverse the second permission list, and determine the first target node to be processed according to the type of the address information in the current permission rule.
[0143] In the present disclosure, the current permission rule is the permission rule currently traversed in the second permission list. Specifically, if the address information in the current permission rule is the default gateway, the VPC to which the cloud wall belongs existing between the target connection relationships is determined as the first target node; if the address information in the current permission rule is a security group, the address information is determined as the first target node, that is, the security group is determined as the first target node; if the address information in the current permission rule is an IP address or an IP prefix, the first target node is determined according to this address information and the corresponding relationship between the pre-constructed VPC identifier, asset identifier, and the IP segment of the asset.
[0144] Step (f4): When the operation in the current permission rule is accept, add the connection relationship between the current node and the first target node to the first network topology diagram according to the direction information in the current permission rule.
[0145] In the present disclosure, the direction information is in or out. Among them, when the direction information is in, the connection relationship between the current node and the first target node is from the first target node to the current node, indicating that the first target node can access the current node; when the direction information is out, the connection relationship between the current node and the first target node is from the current node to the first target node, indicating that the current node can access the first target node.
[0146] Step (f5): When the operation in the current permission rule is rejection, determine and execute a target processing policy for the first target node at least according to the type of the address information in the current permission rule, where the target processing policy is one of the following: removing the first target node from the first network topology diagram, and modifying the relationship between the current node and the first target node to a limited connection.
[0147] The following is a detailed description of the specific implementation manner of determining the first target node according to the above address information and the corresponding relationship between the pre-constructed VPC identifier, asset identifier, and IP segment of the asset.
[0148] Specifically, if there is a fourth target IP segment in the corresponding relationship between the VPC identifier, asset identifier, and IP segment of the asset that is consistent with the address information, then determine the asset represented by the asset identifier corresponding to the fourth target IP segment in the corresponding relationship as the first target node; if there is no fourth target IP segment in the corresponding relationship between the VPC identifier, asset identifier, and IP segment of the asset that is consistent with the address information, and the address information is a subset of a certain IP segment (hereinafter referred to as the fifth target IP segment) in the corresponding relationship, then determine the asset represented by the asset identifier corresponding to the fifth target IP segment in the corresponding relationship as the first target node. At this time, the connection relationship between the current node and the first target node is a limited connection; if there is no fourth target IP segment in the corresponding relationship between the VPC identifier, asset identifier, and IP segment of the asset that is consistent with the address information, and a certain IP segment (hereinafter referred to as the sixth target IP segment) in the corresponding relationship is a subset of the address information, then split the address information to obtain the sixth target IP segment and other IP segments. At this time, the asset represented by the asset identifier corresponding to the sixth target IP segment in the corresponding relationship can be determined as the first target node, and at the same time, the asset corresponding to the other IP segment (if no corresponding asset can be found, use the IP segment to represent) is also determined as the first target node; if none of the above situations are met, then determine the address information as the first target node.
[0149] The following is a detailed description of the specific implementation manner of determining the target processing policy for the first target node at least according to the type of the address information in the above step (f5).
[0150] Specifically, when the address information in the current permission rule is a default gateway or a security group, determine the target processing policy as removing the first target node from the first network topology diagram.
[0151] When the address information in the current permission rule is an IP address or an IP prefix: If there is a fourth target IP segment in the correspondence between the VPC identifier, the asset identifier, and the IP segment of the asset that is consistent with the address information, or if there is no fourth target IP segment in the correspondence that is consistent with the address information, and the address information is a subset of an IP segment in the correspondence, then determine that the target processing policy is to remove the first target node from the first network topology diagram; if there is no fourth target IP segment in the correspondence between the VPC identifier, the asset identifier, and the IP segment of the asset that is consistent with the address information, and an IP segment in the correspondence is a subset of the address information, then modify the relationship between the current node and the first target node to a limited connection.
[0152] To ensure the real-time accuracy of the above-mentioned target network topology diagram, after adding the elastic public IP corresponding to the current node to the first network topology diagram, if the elastic public IP corresponding to the current node enables the cloud wall, then use the policy of the cloud wall to correct the network topology diagram after adding the elastic public IP corresponding to the current node. Specifically, in the case of generating the topology diagram between subnets in the VPC, before the above-mentioned step 27, the above-mentioned generation of the target network topology diagram according to the connection relationship between assets and the mapping relationship between the elastic public IP and assets further includes:
[0153] If the elastic public IP corresponding to the current node enables the cloud wall, then correct the first network topology diagram according to the permission list of the cloud wall enabled by the elastic public IP corresponding to the current node.
[0154] At this time, the above-mentioned step 27 includes: determining whether the newly added nodes based on the current node in the first network topology diagram obtained after correction are empty. That is, if the newly added nodes based on the current node in the first network topology diagram obtained after correction are not empty, then remove the current node from the target node set and add the newly added nodes to the target node set.
[0155] Among them, the first network topology diagram can be corrected according to the permission list of the cloud wall enabled by the elastic public IP corresponding to the current node in a manner similar to the above-mentioned steps (f1) to (f5), and the only difference is that: if the address information in the current permission rule is the default gateway, then determine the Internet node (abstract node) as the first target node, rather than determining the VPC to which the cloud wall belongs among the target connection relationships as the first target node.
[0156] In addition, a tenth network topology diagram based on relevant assets can be generated according to the connection relationship between assets and the mapping relationship between the elastic public IP and assets in a manner similar to the above-mentioned generation of the target network topology diagram according to the connection relationship between assets and the mapping relationship between the elastic public IP and assets, and the present disclosure will not elaborate further.
[0157] To improve the accuracy of the target network topology diagram, when generating the topology diagram between subnets in a VPC, the access control lists bound to each subnet in the target network topology diagram can be used to correct the target network topology diagram. Specifically, as Figure 6 shown, before the above S102, the above network security risk identification method may further include S103 and S104.
[0158] In S103, the target network topology diagram is corrected according to the access control lists bound to each subnet in the target network topology diagram to obtain a second network topology diagram.
[0159] In S104, if there is an Elastic IP (EIP) that is simultaneously connected to a subnet and the VPC to which the subnet belongs in the second network topology diagram, the connection relationship between the simultaneously connected EIP and the VPC to which the subnet belongs is removed to obtain a third network topology diagram.
[0160] In the present disclosure, if there is an EIP that is simultaneously connected to a subnet and the VPC to which the subnet belongs in the second network topology diagram, in order to avoid redundant relationships, only the connection relationship between the EIP and the subnet may be retained, that is, the connection relationship between the EIP and the VPC to which the subnet belongs needs to be deleted.
[0161] At this time, the above S102 may perform an attack link analysis on the third network topology diagram based on the service attributes and security characteristics of the assets in the third network topology diagram.
[0162] The following details the specific implementation manner of correcting the target network topology diagram according to the access control lists bound to each subnet in the above S103 to obtain a second network topology diagram. Specifically, it can be implemented through the following steps (g1) to (g5):
[0163] Step (g1): For each subnet in the target network topology diagram, sort the access control list of the subnet from low to high priority to obtain a first access control list.
[0164] Step (g2): Arrange the permission rules with the same priority in the first access control list in the order of the operation being denied first and then allowed to obtain a second access control list.
[0165] Step (g3): Traverse the second access control list, and determine the second target node to be processed according to the type of address information in the current access control rule.
[0166] In the present disclosure, the current access control rule is the access control rule currently traversed in the second access control list. Additionally, in a manner similar to that of determining the first target node to be processed according to the type of address information in the current permission rule in step (f3) above, the second target node to be processed can be determined according to the type of address information in the current access control rule. The only difference is that if the address information in the current access control rule is the default gateway, other subnets in the VPC to which this subnet belongs except this subnet, and the VPC to which this subnet belongs are determined as the second target nodes.
[0167] Step (g4): When the operation in the current access control rule is acceptance, according to the direction information in the current access control rule, add the connection relationship between the current node and the second target node to the target network topology graph.
[0168] In the present disclosure, the direction information is in or out. Among them, when the direction information is in, the connection relationship between the current node and the second target node is from the second target node to the current node, indicating that the second target node can access the current node; when the direction information is out, the connection relationship between the current node and the second target node is from the current node to the second target node, indicating that the current node can access the second target node.
[0169] Step (g5): When the operation in the current access control rule is rejection, determine and execute the target processing policy for the second target node at least according to the type of address information in the current access control rule.
[0170] In the present disclosure, the target processing policy for the second target node is one of the following: remove the second target node from the target network topology graph, and modify the relationship between the current node and the second target node to a limited connection.
[0171] Additionally, in a manner similar to that of determining the target processing policy for the first target node at least according to the type of address information in the current permission rule in step (f5) above, the target processing policy for the second target node can be determined at least according to the type of address information in the current access control rule, which is not elaborated in the present disclosure.
[0172] To be able to more accurately identify key risks, after constructing the topology graph between subnets in the VPC, it can be associated with the upper-layer topology of the VPC. Specifically, when generating the topology graph between subnets in the VPC, the target object includes a VPC. As Figure 7 shown, before the above S102, the above method may further include the following S105 and S106.
[0173] In S105, obtain the fourth network topology graph based on this one VPC.
[0174] In the present disclosure, the fourth network topology diagram is used to characterize the topological relationship between VPCs. Among them, a fourth network topology diagram based on this one VPC can be obtained in a manner similar to that of obtaining the target network topology diagram based on the target object in S101 above, which will not be elaborated in the present disclosure.
[0175] In S106, the fourth network topology diagram is added to the target network topology diagram to obtain the fifth network topology diagram.
[0176] At this time, in S102 above, an attack link analysis can be performed on the fifth network topology diagram based on the service attributes and security characteristics of the assets in the fifth network topology diagram.
[0177] In addition to constructing the topology diagram between VPCs or the topology diagram between subnets in a VPC, a topology diagram based on network cards can also be constructed. Specifically, when the target asset includes a network card, at this time, according to the connection relationship between assets and the mapping relationship between the elastic public network IP and the assets, the target network topology diagram characterizing the relationship between the target asset and other related assets can be generated through the following steps (h1) to (h3).
[0178] Step (h1): Determine the elastic public network IP corresponding to the network card according to the mapping relationship between the elastic public network IP and the assets.
[0179] Step (h2): Generate a sixth network topology diagram based on the network card and its corresponding elastic public network IP.
[0180] Step (h3): Modify the sixth network topology diagram according to the permission list of the security group associated with the network card to obtain the target network topology diagram characterizing the relationship between the target asset and other related assets.
[0181] Specifically, the permission list of the security group associated with the network card can be sorted from low to high in priority to obtain the third permission list; then, the permission rules with the same priority in the third permission list are arranged in the order of the operation being deny and the operation being allow to obtain the fourth permission list; next, traverse the fourth permission list, and determine the third target node to be processed according to the type of the address information in the current permission rule; when the operation in the current permission rule is accept, according to the direction information in the current permission rule, add the connection relationship between the current node and the third target node to the sixth network topology diagram to obtain the seventh network topology diagram; when the operation in the current permission rule is deny, at least according to the type of the address information in the current permission rule, determine and execute the target processing strategy for the third target node, where the target processing strategy for the third target node is one of the following: remove the third target node from the sixth network topology diagram, and modify the relationship between the current node and the third target node to a limited connection.
[0182] Among them, a third target node to be processed can be determined according to the type of address information in the current permission rule in a similar manner to that for determining the first target node to be processed according to the type of address information in the current permission rule in step (f3) above. The only difference is that if the address information in the current permission rule is the default gateway, the security group associated with the network card and the subnet where the network card is located are determined as the third target node.
[0183] In addition, a target processing policy for the third target node can be determined at least according to the type of address information in the current permission rule in a similar manner to that for determining the target processing policy for the first target node at least according to the type of address information in the current permission rule in step (f5) above, which will not be elaborated in this disclosure.
[0184] In order to more accurately identify key risks, after constructing the topology graph based on the network card, it can be associated with the subnets in the VPC where the network card is located. Specifically, when generating the topology graph based on the network card, the target object includes the network card. Before the above S102, the above network security risk identification method may further include the following two steps:
[0185] Obtain a seventh network topology graph based on the VPC where the network card is located, where the seventh network topology graph is used to represent the topological relationship between subnets in the VPC;
[0186] If there is an elastic public network IP that is simultaneously connected to the network card and the subnet to which the network card belongs in the seventh network topology graph, then remove the connection relationship between the simultaneously connected elastic public network IP and the subnet to which the network card belongs to obtain an eighth network topology graph;
[0187] At this time, the above S102 can perform an attack link analysis on the eighth network topology graph based on the service attributes and security characteristics of the assets in the eighth network topology graph.
[0188] In this disclosure, when there is an elastic public network IP that is simultaneously connected to the network card and the subnet to which the network card belongs in the seventh network topology graph, in order to avoid redundant relationships, only the connection relationship between the EIP and the network card can be retained, that is, the connection relationship between the EIP and the subnet to which the network card belongs needs to be deleted.
[0189] Not only can a topology graph between VPCs, a topology graph between subnets in a VPC, and a topology graph based on a network card be constructed, but also a topology graph based on an ECS or a container can be constructed. At this time, according to the connection relationship between assets and the mapping relationship between the elastic public network IP and the assets, a target network topology graph representing the relationship between the target assets and other related assets can be generated through the following two steps:
[0190] First, determine the target network card bound by the elastic computing service or the container;
[0191] Then, obtain the ninth network topology diagram based on the target network card as the target network topology diagram.
[0192] In the present disclosure, a method similar to the above-mentioned method for obtaining the target network topology diagram based on the network card can be adopted to obtain the ninth network topology diagram based on the target network card, and details are not described herein again.
[0193] The following will describe in detail a specific implementation manner of performing an attack link analysis on the target network topology diagram based on the service attributes and security features of the assets in the target network topology diagram in S102 above to identify security risks in the target network topology diagram.
[0194] In one implementation manner, the target object includes target assets. At this time, risk assets with public network exposure in the target network topology diagram can be identified first. Among them, assets directly connected to the EIP in the target network topology diagram can be determined as risk assets with public network exposure; if the risk asset does not belong to the core asset and the risk asset meets any one of the first preset conditions, then determine whether the risk asset can move laterally to the core asset; if the risk asset can move laterally to the core asset, then determine the risk asset as a security risk; if the risk asset cannot move laterally to the core asset, it indicates that the risk asset does not belong to a security risk.
[0195] If the risk asset does not belong to the core asset and the risk asset meets any one of the second preset conditions, then determine the risk asset as a security risk.
[0196] If the risk asset belongs to the core asset and the risk asset meets any one of the third preset conditions, then determine the risk asset as a security risk.
[0197] In the present disclosure, the first preset condition may include: having any one of high-risk exploitable vulnerabilities, having malicious files / WebShells, having weak passwords, brute-force cracking, credential stuffing attacks, off-site logins, and having suspicious port listening.
[0198] For example, if there are publicly exposed VMs / containers in the target network topology diagram, and at the same time, the publicly exposed virtual machine (VM) / container has highly exploitable vulnerabilities and can laterally move to core assets, then the publicly exposed VM / container is determined as a security risk; if there are publicly exposed VMs / containers in the target network topology diagram, and at the same time, the publicly exposed VM / container has malicious files / Web Shells and can laterally move to core assets, then the publicly exposed VM / container is determined as a security risk; if there are publicly exposed VMs / containers in the target network topology diagram, and at the same time, the publicly exposed VM / container has weak passwords, brute-force cracking, credential stuffing attacks, off-site logins, etc. and can laterally move to core assets, then the publicly exposed VM / container is determined as a security risk; if there are publicly exposed VMs / containers in the target network topology diagram, and at the same time, the publicly exposed VM / container has suspicious port listening and can laterally move to core assets, then the publicly exposed VM / container is determined as a security risk;
[0199] The second preset condition may include: the resource code of the risk asset contains access credentials, and the access permissions corresponding to the access credentials can access core assets; there is an access key call for the risk asset, and the access key involves core assets.
[0200] For example, if there are publicly exposed VMs / containers in the target network topology diagram, and at the same time, the resource code of the publicly exposed VM / container contains the plaintext of AK or the plaintext of SK, and the access permissions corresponding to the plaintext of AK or the plaintext of SK can access core assets, then the publicly exposed VM / container is determined as a security risk; if there are publicly exposed VMs / containers in the target network topology diagram, and at the same time, there is an access key call and the access key involves core assets, then the publicly exposed VM / container is determined as a security risk.
[0201] In addition, if the VM / container has an alarm on the host and can move horizontally to core assets, then the VM / container is determined as a security risk.
[0202] The third preset condition may include: having highly exploitable vulnerabilities or high-risk vulnerabilities, having malicious files / WebShells, having any one of weak passwords, brute-force cracking, credential stuffing attacks, off-site logins, and having suspicious port listening.
[0203] In another implementation, the target object includes a target resource or a target identity. At this time, based on the business attributes and security characteristics of the assets in the target network topology diagram, and the secret leakage of the identity in the target network topology diagram, an attack link analysis can be performed on the target network topology diagram to identify security risks in the target network topology diagram.
[0204] Specifically, a similar approach as in the above embodiments can be adopted to perform an attack link analysis on the target network topology map based on the business attributes and security features of the assets in the target network topology map to identify the key risks in the target network topology map; meanwhile, based on the secret leakage, the security risks in the target network topology map can be further identified.
[0205] Among them, based on the secret leakage, the security risks in the target network topology map can be identified through the following methods:
[0206] If the core asset has a public network opening (the CSPM impact surface is public network access and the asset is a core asset), and there is a CSPM risk with an overly large permission impact surface, then the core asset is determined as a security risk;
[0207] If the leaked AK can access the core asset, then the leaked AK is determined as a security risk;
[0208] If an account with a secret leakage risk (for example, all CSPM risk impact surfaces such as anonymous access, weak password, unauthorized access, etc. are secret leakage) can access the core asset, then the account with abnormal behavior is determined as a security risk;
[0209] If an account with abnormal behavior can access the core asset, then the account with abnormal behavior is determined as a security risk;
[0210] If there is an identity entity that can access the core asset, then the identity entity is determined as a security risk.
[0211] In addition, the above method may further include the following steps:
[0212] In response to receiving a security risk identification request, determine a target object based on the security risk identification request, where the security risk identification request includes the target object.
[0213] Figure 8 It is a block diagram of a network security risk identification device shown according to an exemplary embodiment. As Figure 8 shown, the device 700 includes:
[0214] A first acquisition module 701, configured to acquire a target network topology map based on a target object, where the target network topology map is used to characterize the relationship between the target object and its related assets;
[0215] A link analysis module 702, configured to perform an attack link analysis on the target network topology map based on the business attributes and security features of the assets in the target network topology map to identify the security risks in the target network topology map.
[0216] In the above technical solution, a target network topology map based on a target object is obtained; then, based on the business attributes and security characteristics of the assets in the target network topology map, an attack link analysis is performed on the target network topology map to identify security risks in the target network topology map. In this way, the network topology map can be used to combine risks with the business attributes and security characteristics of the assets in the network topology map, and an attack link analysis is performed from the perspective of an attacker, so that key risks can be identified more accurately, the number of business repair risks can be reduced, the risks that can most cause asset losses can be focused on, the continuity of critical business processes can be ensured, and business interruptions caused by security problems can be reduced. In addition, through automated attack link analysis, potential security threats can be quickly identified, so that rapid response and repair can be achieved, and the impact of security incidents on the business can be reduced. Furthermore, only the target network topology map related to the target object can be generated instead of generating the network topology map of the entire business system. In this way, a multi-layer topology effect can be achieved with less storage space, so that key risk identification can be carried out targeted. And through the target network topology map, risk repair personnel can clearly see the asset losses caused by not repairing, increasing the repair motivation of risk repair personnel.
[0217] Optionally, the target object includes one of an asset, an identity, and a resource;
[0218] Among them, the resource includes a database;
[0219] The asset includes at least one of a virtual private cloud VPC, a subnet, a network card, an elastic computing service, and a container.
[0220] Optionally, the business attribute is used to characterize whether the corresponding asset belongs to a core asset, and the security characteristics include public network exposure and lateral movement, where the core asset is an asset that meets a preset condition.
[0221] Optionally, the target object includes a target asset;
[0222] The first acquisition module 701 is used to generate the target network topology map characterizing the relationship between the target asset and other related assets according to the connection relationship between assets and the mapping relationship between the elastic public network IP and the assets.
[0223] Optionally, the target asset includes at least one virtual private cloud VPC;
[0224] The first acquisition module 701 includes:
[0225] The first determination sub-module is used to take the first node in the target sequence as the current node. When generating the topology graph between VPCs, the target sequence is composed of the at least one VPC. When generating the topology graph between subnets in a VPC, the target asset includes one VPC, and the target sequence is composed of subnets in this one VPC;
[0226] The first addition sub-module is used to determine whether the current node exists in the first network topology graph. If not, according to the connection relationship between assets and the mapping relationship between elastic public network IPs and assets, add the assets and elastic public network IPs related to the current node to the first network topology graph, and then trigger the operation of the second determination sub-module. If so, directly trigger the operation of the second determination sub-module, where the first network topology graph is initially empty;
[0227] The second determination sub-module is used to determine whether there is a next node for the current node. If so, take the next node of the current node in the target sequence as the current node and trigger the operation of the first addition sub-module. If not, determine the first network topology graph as the target network topology graph.
[0228] Optionally, the first addition sub-module includes:
[0229] The second addition sub-module is used to add the current node to the target node set, where the target node set is initially empty;
[0230] The third determination sub-module is used to determine the target connection relationship related to the current node according to the connection relationship between assets, where the target connection relationship is used to characterize the relationship between the current node and its same-type assets;
[0231] The third addition sub-module is used to add the target connection relationship to the first network topology graph;
[0232] The fourth addition sub-module is used to, if there is an elastic public network IP corresponding to the current node in the mapping relationship between elastic public network IPs and assets, add the corresponding relationship between the corresponding elastic public network IP and the current node to the first network topology graph;
[0233] The fifth addition sub-module is used to, if the new nodes based on the current node in the first network topology graph are not empty, remove the current node from the target node set and add the new nodes to the target node set, where the new nodes do not include elastic public network IPs;
[0234] A trigger sub-module, for each new node in the target node set, taking the new node as the current node and triggering the third determination sub-module until the new node of each node in the target node set is empty.
[0235] Optionally, the first addition sub-module further includes:
[0236] A first correction sub-module, before the fourth addition sub-module executes the step of adding the corresponding relationship between the corresponding elastic public network IP and the current node to the first network topology map if there is an elastic public network IP corresponding to the current node in the mapping relationship between the elastic public network IP and the asset, if the target connection relationship is a cross-VPC relationship and there is a cloud wall between the target connection relationships, correcting the first network topology map based on the permission list of the cloud wall;
[0237] The fourth addition sub-module is used to add the corresponding relationship between the corresponding elastic public network IP and the current node to the corrected first network topology map if there is an elastic public network IP corresponding to the current node in the mapping relationship between the elastic public network IP and the asset.
[0238] Optionally, the first correction sub-module includes:
[0239] A first sorting sub-module, for sorting the permission list of the cloud wall from low to high according to the priority to obtain a first permission list;
[0240] A second sorting sub-module, for arranging the permission rules with the same priority in the first permission list in the order of operation being rejection first and then acceptance to obtain a second permission list;
[0241] A traversal sub-module, for traversing the second permission list and determining the first target node to be processed according to the type of the address information in the current permission rule, where the current permission rule is the permission rule currently traversed in the second permission list;
[0242] A sixth addition sub-module, when the operation in the current permission rule is acceptance, adding the connection relationship between the current node and the first target node to the first network topology map according to the direction information in the current permission rule;
[0243] An execution sub-module, configured to, when the operation in the current permission rule is a rejection, determine and execute a target processing policy for the first target node at least according to the type of the address information, where the target processing policy is one of the following: removing the first target node from the first network topology diagram, and modifying the relationship between the current node and the first target node to a limited connection.
[0244] Optionally, the traversal sub-module includes:
[0245] A fourth determination sub-module, configured to, if the address information in the current permission rule is a default gateway, determine the VPC to which the cloud wall belongs as the first target node;
[0246] A fifth determination sub-module, configured to, if the address information is a security group, determine the address information as the first target node;
[0247] A sixth determination sub-module, configured to, if the address information is an IP address or an IP prefix, determine the first target node according to the address information and the corresponding relationship between the pre-constructed VPC identifier, asset identifier, and IP segment of the asset.
[0248] Optionally, in the case of generating a topology diagram between subnets in a VPC, the first addition sub-module further includes:
[0249] A second correction sub-module, configured to, before the fifth addition sub-module executes the step of, if the new node based on the current node in the first network topology diagram is not empty, removing the current node from the target node set and adding the new node to the target node set, if the elastic public network IP corresponding to the current node enables the cloud wall, correct the first network topology diagram according to the permission list of the cloud wall enabled by the corresponding elastic public network IP;
[0250] The fifth addition sub-module is configured to, if the new node based on the current node in the corrected first network topology diagram is not empty, remove the current node from the target node set and add the new node to the target node set.
[0251] Optionally, when generating a topology diagram between subnets in a VPC, the apparatus 700 further includes:
[0252] A correction module, configured to, before the link analysis module 702 performs an attack link analysis on the target network topology diagram based on the service attributes and security characteristics of the assets in the target network topology diagram, correct the target network topology diagram according to the access control lists bound to the subnets in the target network topology diagram to obtain a second network topology diagram;
[0253] A first removal module, configured to, if there is an Elastic Public IP (EIP) that is connected to both a subnet and the VPC to which the subnet belongs in the second network topology diagram, remove the connection relationship between the simultaneously connected EIP and the VPC to which the subnet belongs, so as to obtain a third network topology diagram;
[0254] The link analysis module 702 is configured to perform attack link analysis on the third network topology diagram based on the service attributes and security characteristics of the assets in the third network topology diagram.
[0255] Optionally, when generating the topology diagram between subnets in a VPC, the target object includes one VPC;
[0256] The device 700 further includes:
[0257] A second acquisition module, configured to acquire a fourth network topology diagram based on the one VPC before the link analysis module 702 performs attack link analysis on the target network topology diagram based on the service attributes and security characteristics of the assets in the target network topology diagram, where the fourth network topology diagram is used to characterize the topology relationship between VPCs;
[0258] An addition module, configured to add the fourth network topology diagram to the target network topology diagram to obtain a fifth network topology diagram;
[0259] The link analysis module 702 is configured to perform attack link analysis on the fifth network topology diagram based on the service attributes and security characteristics of the assets in the fifth network topology diagram.
[0260] Optionally, the target asset includes a network card;
[0261] The first acquisition module 701 includes:
[0262] A seventh determination sub-module, configured to determine the EIP corresponding to the network card according to the mapping relationship between the EIP and the asset;
[0263] A generation sub-module, configured to generate a sixth network topology diagram based on the network card and its corresponding EIP;
[0264] A third correction sub-module, configured to correct the sixth network topology diagram according to the permission list of the security group associated with the network card, so as to obtain the target network topology diagram characterizing the relationship between the target asset and other related assets.
[0265] Optionally, the target object includes a network card;
[0266] The device 700 further includes:
[0267] A third acquisition module, configured to acquire a seventh network topology graph based on the VPC where the network card is located before the link analysis module 702 performs attack link analysis on the target network topology graph based on the service attributes and security characteristics of the assets in the target network topology graph, where the seventh network topology graph is used to represent the topological relationship between subnets in the VPC;
[0268] A second removal module, configured to, if there is an elastic public network IP that is simultaneously connected to the network card and the subnet to which the network card belongs in the seventh network topology graph, remove the connection relationship between the simultaneously connected elastic public network IP and the subnet to which the network card belongs, to obtain an eighth network topology graph;
[0269] The link analysis module 702 is configured to perform attack link analysis on the eighth network topology graph based on the service attributes and security characteristics of the assets in the eighth network topology graph.
[0270] Optionally, the target asset includes an elastic computing service or a container;
[0271] The first acquisition module 701 includes:
[0272] An eighth determination sub-module, configured to determine the target network card bound by the elastic computing service or the container;
[0273] A first acquisition sub-module, configured to acquire a ninth network topology graph based on the target network card as the target network topology graph.
[0274] Optionally, the target object includes a target asset;
[0275] The service attribute is used to represent whether the corresponding asset belongs to a core asset, and the security characteristics include public network exposure and lateral movement;
[0276] The link analysis module 702 includes:
[0277] An identification sub-module, configured to identify risk assets with public network exposure in the target network topology graph;
[0278] A ninth determination sub-module, configured to determine whether the risk asset can move laterally to the core asset if the risk asset does not belong to the core asset and the risk asset meets any one of the first preset conditions;
[0279] A tenth determination sub-module, configured to, if the risk asset can move laterally to the core asset, determine the risk asset as a security risk.
[0280] Optionally, the link analysis module 702 further includes:
[0281] An eleventh determination sub-module, configured to determine the risk asset as a security risk if the risk asset does not belong to the core asset and the risk asset meets any one of the second preset conditions;
[0282] Wherein, the second preset condition includes:
[0283] The resource code of the risk asset contains an access credential, and the access permission corresponding to the access credential can access the core asset;
[0284] The risk asset has an access key call, and the access key involves the core asset.
[0285] Optionally, the link analysis module 702 further includes:
[0286] If the risk asset belongs to the core asset and the risk asset meets any one of the third preset conditions, then determine the risk asset as a security risk.
[0287] Optionally, the target object includes a target resource or a target identity;
[0288] The first acquisition module 701 includes:
[0289] A second acquisition sub-module, configured to acquire a permission topology graph based on the target object, where the permission topology graph is used to represent the relationship between identities and resources;
[0290] A twelfth determination sub-module, configured to determine related assets of the resources in the permission topology graph based on a pre-constructed correspondence between assets and resources;
[0291] A third acquisition sub-module, configured to acquire a tenth network topology graph based on the related assets;
[0292] A sixth addition sub-module, configured to add the tenth network topology graph to the permission topology graph to obtain the target network topology graph.
[0293] Optionally, the link analysis module 702 is configured to perform attack link analysis on the target network topology graph based on the service attributes and security characteristics of the assets in the target network topology graph, and the secret leakage of the identities in the target network topology graph.
[0294] In addition, the present disclosure also provides a computer-readable medium, on which a computer program is stored, and when the computer program is executed by a processing device, the steps of the above-mentioned network security risk identification method provided by the present disclosure are implemented.
[0295] Furthermore, the present disclosure provides a computer program product, including a computer program, and when the computer program is executed by a processor, the steps of the above-mentioned network security risk identification method provided by the present disclosure are implemented.
[0296] Refer to the following Figure 9 , which shows a schematic structural diagram of an electronic device (terminal device or server) 600 suitable for implementing the embodiments of the present disclosure. The terminal devices in the embodiments of the present disclosure may include, but are not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Tablet Computers), PMPs (Portable Multimedia Players), in-vehicle terminals (such as in-vehicle navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc. Figure 9 The electronic device shown is only an example and should not impose any limitations on the functions and usage scope of the embodiments of the present disclosure.
[0297] As Figure 9 shown, the electronic device 600 may include a processing device (such as a central processing unit, a graphics processing unit, etc.) 601, which may perform various appropriate actions and processes according to the programs stored in the read-only memory (ROM) 602 or the programs loaded from the storage device 608 into the random access memory (RAM) 603. In the RAM 603, various programs and data required for the operation of the electronic device 600 are also stored. The processing device 601, the ROM 602, and the RAM 603 are connected to each other through a bus 604. The input / output (I / O) interface 605 is also connected to the bus 604.
[0298] Generally, the following devices may be connected to the I / O interface 605: an input device 606 including, for example, a touch screen, a touch pad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; an output device 607 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 608 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 609. The communication device 609 may allow the electronic device 600 to communicate with other devices wirelessly or wiredly to exchange data. Although Figure 9 the electronic device 600 with various devices is shown, it should be understood that it is not required to implement or have all the shown devices. Instead, more or fewer devices may be implemented or had.
[0299] In particular, according to an embodiment of the present disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, an embodiment of the present disclosure includes a computer program product, which includes a computer program carried on a non-transitory computer-readable medium, and the computer program includes program codes for performing the methods shown in the flowcharts. In such an embodiment, the computer program can be downloaded and installed from the network through the communication device 609, or installed from the storage device 608, or installed from the ROM 602. When the computer program is executed by the processing device 601, the above-mentioned functions defined in the method of the embodiment of the present disclosure are performed.
[0300] It should be noted that the above-mentioned computer-readable medium in the present disclosure can be a computer-readable signal medium or a computer-readable storage medium or any combination of the two. A computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of the computer-readable storage medium can include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present disclosure, the computer-readable storage medium can be any tangible medium that contains or stores a program, and the program can be used by or in combination with an instruction execution system, apparatus, or device. And in the present disclosure, a computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, which carries computer-readable program codes. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The computer-readable signal medium can also be any computer-readable medium other than the computer-readable storage medium, and the computer-readable signal medium can send, propagate, or transmit a program for use by or in combination with an instruction execution system, apparatus, or device. The program codes contained on the computer-readable medium can be transmitted by any appropriate medium, including but not limited to: wires, optical cables, RF (radio frequency), etc., or any suitable combination of the above.
[0301] In some embodiments, the client and the server can communicate using any currently known or future-developed network protocol such as HTTP (HyperText Transfer Protocol), and can be interconnected with digital data communication in any form or medium (e.g., a communication network). Examples of communication networks include local area networks ("LAN"), wide area networks ("WAN"), the Internet (e.g., the Internet), and end-to-end networks (e.g., ad hoc end-to-end networks), as well as any currently known or future-developed network.
[0302] The above computer-readable medium can be included in the above electronic device; it can also exist separately without being assembled into the electronic device.
[0303] The above computer-readable medium carries one or more programs, which, when executed by the electronic device, cause the electronic device to: obtain a target network topology map based on a target object, where the target network topology map is used to characterize the relationship between the target object and its related assets; perform attack link analysis on the target network topology map based on the business attributes and security characteristics of the assets in the target network topology map to identify security risks in the target network topology map.
[0304] Computer program code for performing the operations of the present disclosure can be written in one or more programming languages or combinations thereof. The above programming languages include, but are not limited to, object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, executed as an independent software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computer (e.g., by using an Internet service provider to connect through the Internet).
[0305] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flowchart or block diagram may represent a module, a segment of a program, or a portion of code that contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions noted in the blocks may occur in a different order than noted in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, or they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented by a dedicated hardware-based system that performs the specified functions or operations, or by a combination of dedicated hardware and computer instructions.
[0306] The modules described in the embodiments of the present disclosure can be implemented in software or in hardware. Among them, the name of the module does not constitute a limitation on the module itself in some cases. For example, the first acquisition module can also be described as "the module for acquiring the target network topology map based on the target object".
[0307] The functions described above in this document can be performed, at least in part, by one or more hardware logic components. For example, without limitation, exemplary types of hardware logic components that can be used include: Field Programmable Gate Arrays (FPGA), Application Specific Integrated Circuits (ASIC), Application Specific Standard Products (ASSP), System on a Chip (SOC), Complex Programmable Logic Devices (CPLD), and so on.
[0308] In the context of the present disclosure, a machine-readable medium can be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of a machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a Random Access Memory (RAM), a Read-Only Memory (ROM), an Erasable Programmable Read-Only Memory (EPROM or Flash memory), an optical fiber, a portable Compact Disc Read-Only Memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0309] According to one or more embodiments of the present disclosure, Example 1 provides a method for identifying network security risks, including: obtaining a target network topology map based on a target object, where the target network topology map is used to characterize the relationship between the target object and its related assets; and performing an attack link analysis on the target network topology map based on the business attributes and security characteristics of the assets in the target network topology map to identify security risks in the target network topology map.
[0310] According to one or more embodiments of the present disclosure, Example 2 provides the method of Example 1, where the target object includes one of an asset, an identity, and a resource; where the resource includes a database; and the asset includes at least one of a virtual private cloud (VPC), a subnet, a network card, an elastic compute service, and a container.
[0311] According to one or more embodiments of the present disclosure, Example 3 provides the method of Example 1, where the business attribute is used to characterize whether the corresponding asset belongs to a core asset, and the security characteristics include public network exposure and lateral movement, where the core asset is an asset that meets a preset condition.
[0312] According to one or more embodiments of the present disclosure, Example 4 provides the method of Example 1, where the target object includes a target asset; and the obtaining of the target network topology map based on the target object includes: generating the target network topology map that characterizes the relationship between the target asset and other related assets according to the connection relationship between assets and the mapping relationship between elastic public IPs and assets.
[0313] According to one or more embodiments of the present disclosure, Example 5 provides the method of Example 4, where the target asset includes at least one virtual private cloud (VPC); generating the target network topology diagram according to the connection relationship between assets and the mapping relationship between elastic public IPs and assets includes: generating the target network topology diagram representing the relationship between the target asset and other related assets according to the connection relationship between assets and the mapping relationship between elastic public IPs and assets, including: Step 1, taking the first node in the target sequence as the current node, where when generating the topology diagram between VPCs, the target sequence is composed of the at least one VPC, and when generating the topology diagram between subnets in a VPC, the target asset includes one VPC, and the target sequence is composed of the subnets in this one VPC; Step 2, determining whether the current node exists in the first network topology diagram. If not, adding the assets and elastic public IPs related to the current node to the first network topology diagram according to the connection relationship between assets and the mapping relationship between elastic public IPs and assets, and then performing Step 3. If so, directly performing Step 3, where the first network topology diagram is initially empty; Step 3, determining whether there is a next node for the current node. If so, taking the next node of the current node in the target sequence as the current node and returning to Step 2. If not, determining the first network topology diagram as the target network topology diagram.
[0314] According to one or more embodiments of the present disclosure, Example 6 provides the method of Example 5. Adding the assets and elastic public network IPs related to the current node to the first network topology diagram according to the connection relationship between assets and the mapping relationship between the elastic public network IP and the assets includes: Step 21, adding the current node to the target node set, where the target node set is initially empty; Step 22, determining the target connection relationship related to the current node according to the connection relationship between assets, where the target connection relationship is used to characterize the relationship between the current node and its same-type assets; Step 23, adding the target connection relationship to the first network topology diagram; Step 24, if there is an elastic public network IP corresponding to the current node in the mapping relationship between the elastic public network IP and the assets, adding the corresponding relationship between the corresponding elastic public network IP and the current node to the first network topology diagram; Step 25, if the new nodes based on the current node in the first network topology diagram are not empty, removing the current node from the target node set and adding the new nodes to the target node set, where the new nodes do not include elastic public network IPs; Step 26, for each new node in the target node set, taking the new node as the current node and repeating Steps 22 to 26 until the new nodes of each node in the target node set are all empty.
[0315] According to one or more embodiments of the present disclosure, Example 7 provides the method of Example 6. Before the step of if there is an elastic public network IP corresponding to the current node in the mapping relationship between the elastic public network IP and the assets, adding the corresponding relationship between the corresponding elastic public network IP and the current node to the first network topology diagram, adding the assets and elastic public network IPs related to the current node to the first network topology diagram according to the connection relationship between assets and the mapping relationship between the elastic public network IP and the assets further includes: if the target connection relationship is a cross-VPC relationship and there is a cloud wall between the target connection relationships, correcting the first network topology diagram based on the permission list of the cloud wall; the step of if there is an elastic public network IP corresponding to the current node in the mapping relationship between the elastic public network IP and the assets, adding the corresponding relationship between the corresponding elastic public network IP and the current node to the first network topology diagram includes: if there is an elastic public network IP corresponding to the current node in the mapping relationship between the elastic public network IP and the assets, adding the corresponding relationship between the corresponding elastic public network IP and the current node to the corrected first network topology diagram.
[0316] According to one or more embodiments of the present disclosure, Example 8 provides the method of Example 7. Modifying the first network topology diagram based on the permission list of the cloud wall includes: sorting the permission list of the cloud wall from low to high according to the priority to obtain a first permission list; arranging the permission rules with the same priority in the first permission list in the order of the operation being deny and then allow to obtain a second permission list; traversing the second permission list, and determining a first target node to be processed according to the type of the address information in the current permission rule, where the current permission rule is the permission rule currently traversed in the second permission list; when the operation in the current permission rule is accept, adding the connection relationship between the current node and the first target node to the first network topology diagram according to the direction information in the current permission rule; when the operation in the current permission rule is deny, determining and executing a target processing strategy for the first target node at least according to the type of the address information, where the target processing strategy is one of the following: removing the first target node from the first network topology diagram, and modifying the relationship between the current node and the first target node to a limited connection.
[0317] According to one or more embodiments of the present disclosure, Example 9 provides the method of Example 8. Determining the first target node to be processed according to the type of the address information in the current permission rule includes: if the address information in the current permission rule is the default gateway, determining the VPC to which the cloud wall belongs as the first target node; if the address information is the security group, determining the address information as the first target node; if the address information is an IP address or an IP prefix, determining the first target node according to the address information and the corresponding relationship between the pre-constructed VPC identifier, asset identifier, and the IP segment of the asset.
[0318] According to one or more embodiments of the present disclosure, Example 10 provides the method of Example 6. In the case of generating a topology graph between subnets in a VPC, before the step of removing the current node from the target node set and adding the newly added nodes to the target node set if the newly added nodes based on the current node in the first network topology graph are not empty, the method of adding the assets and elastic public network IPs related to the current node to the first network topology graph according to the connection relationship between assets and the mapping relationship between elastic public network IPs and assets further includes: if the cloud wall is enabled for the elastic public network IP corresponding to the current node, correcting the first network topology graph according to the permission list of the cloud wall enabled for the corresponding elastic public network IP; the step of removing the current node from the target node set and adding the newly added nodes to the target node set if the newly added nodes based on the current node in the first network topology graph are not empty includes: if the newly added nodes based on the current node in the first network topology graph obtained after correction are not empty, removing the current node from the target node set and adding the newly added nodes to the target node set.
[0319] According to one or more embodiments of the present disclosure, Example 11 provides the method of Example 1. In the case of generating a topology graph between subnets in a VPC, before the step of performing an attack link analysis on the target network topology graph based on the service attributes and security characteristics of the assets in the target network topology graph, the method further includes: correcting the target network topology graph according to the access control lists bound to each subnet in the target network topology graph to obtain a second network topology graph; if there is an elastic public network IP that is simultaneously connected to a subnet and the VPC to which the subnet belongs in the second network topology graph, removing the connection relationship between the simultaneously connected elastic public network IP and the VPC to which the subnet belongs to obtain a third network topology graph; the step of performing an attack link analysis on the target network topology graph based on the service attributes and security characteristics of the assets in the target network topology graph includes: performing an attack link analysis on the third network topology graph based on the service attributes and security characteristics of the assets in the third network topology graph.
[0320] According to one or more embodiments of the present disclosure, Example 12 provides the method of Example 1. When generating a topology map between subnets in a VPC, the target object includes a VPC. Before the step of performing an attack link analysis on the target network topology map based on the service attributes and security characteristics of the assets in the target network topology map, the method further includes: obtaining a fourth network topology map based on the one VPC, where the fourth network topology map is used to characterize the topology relationship between VPCs; adding the fourth network topology map to the target network topology map to obtain a fifth network topology map; the performing an attack link analysis on the target network topology map based on the service attributes and security characteristics of the assets in the target network topology map includes: performing an attack link analysis on the fifth network topology map based on the service attributes and security characteristics of the assets in the fifth network topology map.
[0321] According to one or more embodiments of the present disclosure, Example 13 provides the method of Example 4. The target asset includes a network card. The generating the target network topology map that characterizes the relationship between the target asset and other related assets according to the connection relationship between assets and the mapping relationship between an elastic public network IP and an asset includes: determining the elastic public network IP corresponding to the network card according to the mapping relationship between the elastic public network IP and the asset; generating a sixth network topology map based on the network card and its corresponding elastic public network IP; and correcting the sixth network topology map according to the permission list of the security group associated with the network card to obtain the target network topology map that characterizes the relationship between the target asset and other related assets.
[0322] According to one or more embodiments of the present disclosure, Example 14 provides the method of Example 1. The target object includes a network card. Before the step of performing an attack link analysis on the target network topology map based on the service attributes and security characteristics of the assets in the target network topology map, the method further includes: obtaining a seventh network topology map based on the VPC where the network card is located, where the seventh network topology map is used to characterize the topology relationship between subnets in the VPC; if there is an elastic public network IP that is simultaneously connected to the network card and the subnet to which the network card belongs in the seventh network topology map, removing the connection relationship between the simultaneously connected elastic public network IP and the subnet to which the network card belongs to obtain an eighth network topology map; the performing an attack link analysis on the target network topology map based on the service attributes and security characteristics of the assets in the target network topology map includes: performing an attack link analysis on the eighth network topology map based on the service attributes and security characteristics of the assets in the eighth network topology map.
[0323] According to one or more embodiments of the present disclosure, Example 15 provides the method of Example 4, where the target asset includes an elastic computing service or a container; generating the target network topology diagram characterizing the relationship between the target asset and other related assets according to the connection relationship between assets and the mapping relationship between the elastic public network IP and the assets includes: determining the target network card bound to the elastic computing service or the container; obtaining the ninth network topology diagram based on the target network card as the target network topology diagram. According to one or more embodiments of the present disclosure, Example 16 provides the method of Example 1, where the target object includes a target asset; the business attribute is used to characterize whether the corresponding asset belongs to a core asset, and the security features include public network exposure and lateral movement; performing an attack link analysis on the target network topology diagram based on the business attributes and security features of the assets in the target network topology diagram to identify security risks in the target network topology diagram includes: identifying risk assets with public network exposure in the target network topology diagram; if the risk asset does not belong to the core asset and the risk asset meets any one of the first preset conditions, determining whether the risk asset can move laterally to the core asset; if the risk asset can move laterally to the core asset, determining the risk asset as a security risk.
[0324] According to one or more embodiments of the present disclosure, Example 17 provides the method of Example 16, where performing an attack link analysis on the target network topology diagram based on the business attributes and security features of the assets in the target network topology diagram to identify security risks in the target network topology diagram further includes: if the risk asset does not belong to the core asset and the risk asset meets any one of the second preset conditions, determining the risk asset as a security risk; where the second preset conditions include: the resource code of the risk asset contains an access credential, and the access permission corresponding to the access credential can access the core asset; the risk asset has an access key call, and the access key involves the core asset.
[0325] According to one or more embodiments of the present disclosure, Example 18 provides the method of Example 16. The method of performing attack link analysis on the target network topology graph based on the business attributes and security characteristics of the assets in the target network topology graph to identify security risks in the target network topology graph further includes: if the risk asset belongs to a core asset and the risk asset meets any one of the third preset conditions, determining the risk asset as a security risk. According to one or more embodiments of the present disclosure, Example 19 provides the method of Example 1. The target object includes a target resource or a target identity. The obtaining of the target network topology graph based on the target object includes: obtaining a permission topology graph based on the target object, where the permission topology graph is used to represent the relationship between an identity and a resource; determining, based on a pre-constructed correspondence between assets and resources, the assets related to the resources in the permission topology graph; obtaining a tenth network topology graph based on the related assets; and adding the tenth network topology graph to the permission topology graph to obtain the target network topology graph.
[0326] According to one or more embodiments of the present disclosure, Example 20 provides the method of Example 19. The performing of attack link analysis on the target network topology graph based on the business attributes and security characteristics of the assets in the target network topology graph includes: performing attack link analysis on the target network topology graph based on the business attributes and security characteristics of the assets in the target network topology graph and the secret leakage of identities in the target network topology graph.
[0327] According to one or more embodiments of the present disclosure, Example 21 provides the method of Example 1. In response to receiving a security risk identification request, determining the target object based on the security risk identification request, where the security risk identification request includes the target object.
[0328] According to one or more embodiments of the present disclosure, Example 22 provides a network security risk identification device, including: a first obtaining module, configured to obtain a target network topology graph based on a target object, where the target network topology graph is used to represent the relationship between the target object and its related assets; and a link analysis module, configured to perform attack link analysis on the target network topology graph based on the business attributes and security characteristics of the assets in the target network topology graph to identify security risks in the target network topology graph.
[0329] According to one or more embodiments of the present disclosure, Example 23 provides a computer-readable medium, on which a computer program is stored, and when the computer program is executed by a processing device, the steps of the method according to any one of Examples 1-21 are implemented.
[0330] According to one or more embodiments of the present disclosure, Example 24 provides an electronic device, including:
[0331] A storage device on which a computer program is stored; a processing device for executing the computer program in the storage device to implement the steps of the method according to any one of Examples 1-21.
[0332] According to one or more embodiments of the present disclosure, Example 25 provides a computer program product including a computer program, which when executed by a processor implements the steps of the method according to any one of Examples 1-21.
[0333] The above description is only a preferred embodiment of the present disclosure and an explanation of the applied technical principles. Those skilled in the art should understand that the scope of the disclosure involved in the present disclosure is not limited to the technical solutions formed by the specific combination of the above technical features, and should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the above disclosure concept. For example, the technical solutions formed by mutually replacing the above features with the (but not limited to) technical features having similar functions disclosed in the present disclosure.
[0334] In addition, although the operations are depicted in a particular order, this should not be construed as requiring that the operations be performed in the particular order shown or in sequential order. In certain environments, multitasking and parallel processing may be advantageous. Similarly, although a number of specific implementation details are included in the above discussion, these should not be construed as limiting the scope of the present disclosure. Certain features described in the context of separate embodiments may also be implemented combinatorially in a single embodiment. Conversely, the various features described in the context of a single embodiment may also be implemented separately or in any suitable sub-combination in multiple embodiments.
[0335] Although the subject matter has been described in language specific to structural features and / or methodological acts, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or acts described above. On the contrary, the specific features and acts described above are merely example forms for implementing the claims. Regarding the device in the above embodiments, the specific manner in which each module performs operations has been described in detail in the embodiments related to the method, and will not be elaborated here.
Claims
1. A network security risk identification method, characterized in that: include: Acquire a target network topology map based on the target object, wherein the target network topology map is used to characterize the relationship between the target object and its related assets, wherein the target object includes one of an asset, an identity, and a resource, wherein the asset includes at least one of a virtual private cloud VPC, a subnet, a network card, an elastic computing service, and a container, the resource includes a database, and the identity includes a user; Based on the business attributes and security characteristics of the assets in the target network topology map, performing attack link analysis on the target network topology map to identify security risks in the target network topology map; The business attributes are used to characterize whether the corresponding assets belong to core assets, the security characteristics include public network exposure and lateral movement, and the core assets are assets that meet the preset conditions; When the target object includes a target asset, performing attack link analysis on the target network topology map based on the business attributes and security characteristics of the asset in the target network topology map to identify security risks in the target network topology map includes: Identify risky assets exposed to the public network in the target network topology diagram; If the risk asset does not belong to the core asset and the risk asset meets any one of the first preset conditions, determine whether the risk asset can be moved horizontally to the core asset, wherein the first preset condition includes: high-risk exploitable vulnerabilities, malicious files, web backdoors, weak passwords, brute force cracking, database collision attacks, remote logins, and suspicious port monitoring; If the risk asset can be moved horizontally to the core asset, the risk asset is determined to be a security risk.
2. The method according to claim 1, characterized in that When the target object includes the target asset, the acquiring of the target network topology map based on the target object includes: The target network topology diagram representing the relationship between the target asset and other related assets is generated according to the connection relationship between assets and the mapping relationship between the elastic public network IP and assets.
3. The method according to claim 2, characterized in that The target assets include at least one virtual private cloud VPC; The generating of the target network topology diagram representing the relationship between the target asset and other related assets according to the connection relationship between assets and the mapping relationship between the elastic public network IP and assets includes: Step 1: taking the first node in the target sequence as the current node, wherein when generating a topology diagram between VPCs, the target sequence is composed of the at least one VPC, and when generating a topology diagram between subnets in a VPC, the target asset includes one VPC, and the target sequence is composed of the subnets in the one VPC; Step 2, determine whether the current node exists in the first network topology map. If not, add the assets and elastic public IPs related to the current node to the first network topology map according to the connection relationship between assets and the mapping relationship between elastic public IPs and assets, and then execute step 3. If yes, directly execute step 3, wherein the first network topology map is initially empty. Step 3, determine whether there is a next node for the current node. If so, take the next node of the current node in the target sequence as the current node and return to step 2. If not, determine the first network topology map as the target network topology map.
4. The method according to claim 3, characterized in that The adding the assets and the elastic public IP related to the current node to the first network topology map according to the connection relationship between the assets and the mapping relationship between the elastic public IP and the assets includes: Step 21, adding the current node to a target node set, wherein the target node set is initially empty; Step 22, determining a target connection relationship related to the current node according to the connection relationship between the assets, wherein the target connection relationship is used to characterize the relationship between the current node and its assets of the same type; Step 23, adding the target connection relationship to the first network topology graph; Step 24: If there is an elastic public IP corresponding to the current node in the mapping relationship between the elastic public IP and the asset, add the corresponding relationship between the corresponding elastic public IP and the current node to the first network topology diagram; Step 25: If the newly added node based on the current node in the first network topology graph is not empty, the current node is removed from the target node set, and the newly added node is added to the target node set, wherein the newly added node does not include an elastic public network IP; Step 26: for each newly added node in the target node set, use the newly added node as the current node, and repeat steps 22 to 26 until the newly added nodes of each node in the target node set are empty.
5. The method according to claim 4, characterized in that Before the step of adding the corresponding relationship between the corresponding elastic public IP and the current node to the first network topology map if there is an elastic public IP corresponding to the current node in the mapping relationship between the elastic public IP and the asset, the step of adding the assets and elastic public IP related to the current node to the first network topology map according to the connection relationship between assets and the mapping relationship between the elastic public IP and the asset further includes: If the target connection relationship is a cross-VPC relationship and a cloud wall exists between the target connection relationships, the first network topology diagram is modified based on the permission list of the cloud wall; If there is an elastic public IP corresponding to the current node in the mapping relationship between the elastic public IP and the asset, adding the corresponding relationship between the corresponding elastic public IP and the current node to the first network topology diagram, including: If there is an elastic public IP corresponding to the current node in the mapping relationship between the elastic public IP and the asset, the corresponding relationship between the corresponding elastic public IP and the current node is added to the corrected first network topology map.
6. The method according to claim 5, characterized in that The modifying of the first network topology diagram based on the permission list of the cloud wall includes: Sort the permission list of the cloud wall from low to high priority to obtain a first permission list; Arrange the permission rules with the same priority in the first permission list in the order of denying the operation and allowing the operation to obtain a second permission list; Traversing the second permission list, and determining a first target node to be processed according to a type of address information in a current permission rule, wherein the current permission rule is a permission rule currently traversed in the second permission list; When the operation in the current permission rule is acceptance, adding the connection relationship between the current node and the first target node to the first network topology graph according to the direction information in the current permission rule; When the operation in the current authority rule is rejection, a target processing strategy for the first target node is determined and executed at least based on the type of the address information, wherein the target processing strategy is one of the following: removing the first target node from the first network topology map, and modifying the relationship between the current node and the first target node to a limited connection.
7. The method according to claim 6, characterized in that The determining, according to the type of address information in the current permission rule, the first target node to be processed includes: If the address information in the current permission rule is the default gateway, the VPC to which the cloud wall belongs is determined as the first target node; If the address information is a security group, determining the address information as the first target node; If the address information is an IP address or an IP prefix, the first target node is determined according to the address information and a pre-built correspondence between a VPC identifier, an asset identifier, and an IP segment of the asset.
8. The method according to claim 4, characterized in that In the case of generating a topology map between subnets in a VPC, before the step of removing the current node from the target node set and adding the newly added node to the target node set if the newly added node based on the current node in the first network topology map is not empty, the step of adding the assets and elastic public IP related to the current node to the first network topology map according to the connection relationship between assets and the mapping relationship between the elastic public IP and the assets further includes: If the elastic public network IP corresponding to the current node has a cloud wall enabled, the first network topology diagram is modified according to the permission list of the cloud wall enabled by the corresponding elastic public network IP; If the newly added node based on the current node in the first network topology graph is not empty, the current node is removed from the target node set, and the newly added node is added to the target node set, including: If the newly added node based on the current node in the corrected first network topology graph is not empty, the current node is removed from the target node set, and the newly added node is added to the target node set.
9. The method according to claim 1, characterized in that: In the case of generating a topology diagram between subnets in a VPC, before the step of performing attack link analysis on the target network topology diagram based on the business attributes and security characteristics of the assets in the target network topology diagram, the method further includes: According to the access control list bound to each subnet in the target network topology map, the target network topology map is modified to obtain a second network topology map; If there is an elastic public IP connected to both the subnet and the VPC to which the subnet belongs in the second network topology, remove the connection relationship between the elastic public IP connected at the same time and the VPC to which the subnet belongs, and obtain a third network topology; The performing attack link analysis on the target network topology map based on the business attributes and security characteristics of the assets in the target network topology map includes: Based on the business attributes and security characteristics of the assets in the third network topology map, an attack link analysis is performed on the third network topology map.
10. The method according to claim 1, characterized in that When generating a topology diagram between subnets in a VPC, the target object includes a VPC; Before the step of performing attack link analysis on the target network topology map based on the business attributes and security characteristics of the assets in the target network topology map, the method further includes: Obtaining a fourth network topology map based on the one VPC, wherein the fourth network topology map is used to characterize a topological relationship between VPCs; Adding the fourth network topology map to the target network topology map to obtain a fifth network topology map; The performing attack link analysis on the target network topology map based on the business attributes and security characteristics of the assets in the target network topology map includes: Based on the business attributes and security characteristics of the assets in the fifth network topology map, an attack link analysis is performed on the fifth network topology map.
11. The method according to claim 2, characterized in that The target asset includes the network card; The generating of the target network topology diagram representing the relationship between the target asset and other related assets according to the connection relationship between assets and the mapping relationship between the elastic public network IP and assets includes: Determine the elastic public network IP corresponding to the network card according to the mapping relationship between the elastic public network IP and the asset; Generate a sixth network topology diagram based on the network card and its corresponding elastic public network IP; The sixth network topology map is modified according to the permission list of the security group associated with the network card to obtain the target network topology map representing the relationship between the target asset and other related assets.
12. The method according to claim 1, characterized in that In the case where the target object includes the network card, before the step of performing attack link analysis on the target network topology map based on the business attributes and security characteristics of the assets in the target network topology map, the method further includes: Obtain a seventh network topology map based on the VPC where the network card is located, wherein the seventh network topology map is used to characterize the topological relationship between subnets in the VPC; If there is an elastic public IP connected to both the network card and the subnet to which the network card belongs in the seventh network topology diagram, remove the connection relationship between the elastic public IP connected at the same time and the subnet to which the network card belongs, and obtain an eighth network topology diagram; The performing attack link analysis on the target network topology map based on the business attributes and security characteristics of the assets in the target network topology map includes: Based on the business attributes and security characteristics of the assets in the eighth network topology map, an attack link analysis is performed on the eighth network topology map.
13. The method according to claim 2, characterized in that The target asset includes the elastic computing service or the container; The generating of the target network topology diagram representing the relationship between the target asset and other related assets according to the connection relationship between assets and the mapping relationship between the elastic public network IP and assets includes: Determine a target network card to which the elastic computing service or the container is bound; A ninth network topology map based on the target network card is obtained as the target network topology map.
14. The method according to claim 1, characterized in that The performing attack link analysis on the target network topology map based on the business attributes and security characteristics of the assets in the target network topology map to identify security risks in the target network topology map also includes: If the risk asset does not belong to the core asset and the risk asset meets any one of the second preset conditions, the risk asset is determined as a security risk; Wherein, the second preset condition includes: The resource code of the risk asset contains access credentials, and the access rights corresponding to the access credentials can access the core assets; The risk asset has an access key call, and the access key involves the core asset.
15. The method according to claim 1, characterized in that The performing attack link analysis on the target network topology map based on the business attributes and security characteristics of the assets in the target network topology map to identify security risks in the target network topology map also includes: If the risk asset belongs to a core asset and the risk asset satisfies any one of the third preset conditions, the risk asset is determined to be a security risk.
16. The method according to claim 1, characterized in that When the target object includes a target resource or a target identity, the acquiring of a target network topology map based on the target object includes: Acquire a permission topology map based on the target object, wherein the permission topology map is used to represent the relationship between identity and resources; Determine the assets related to the resources in the permission topology diagram based on the pre-built correspondence between assets and resources; Obtaining a tenth network topology map based on the relevant assets; The tenth network topology map is added to the authority topology map to obtain the target network topology map.
17. The method according to claim 16, characterized in that The performing attack link analysis on the target network topology map based on the business attributes and security characteristics of the assets in the target network topology map includes: Based on the business attributes and security characteristics of the assets in the target network topology map, and the secret leakage of the identity in the target network topology map, the target network topology map is subjected to attack link analysis.
18. The method according to claim 1, characterized in that The method further comprises: In response to receiving a security risk identification request, the target object is determined based on the security risk identification request, wherein the security risk identification request includes the target object.
19. A network security risk identification device, characterized in that: include: A first acquisition module is used to acquire a target network topology map based on a target object, wherein the target network topology map is used to characterize the relationship between the target object and its related assets, wherein the target object includes one of an asset, an identity, and a resource, wherein the asset includes at least one of a virtual private cloud VPC, a subnet, a network card, an elastic computing service, and a container, the resource includes a database, and the identity includes a user; A link analysis module, configured to perform attack link analysis on the target network topology map based on the business attributes and security characteristics of the assets in the target network topology map, so as to identify security risks in the target network topology map; The business attributes are used to characterize whether the corresponding assets belong to core assets, the security characteristics include public network exposure and lateral movement, and the core assets are assets that meet the preset conditions; When the target object includes a target asset, the link analysis module includes: An identification submodule, used to identify risky assets exposed to the public network in the target network topology diagram; A ninth determination submodule, for determining whether the risk asset can be laterally moved to the core asset if the risk asset does not belong to the core asset and the risk asset meets any one of the first preset conditions, wherein the first preset condition includes: a high-risk exploitable vulnerability, a malicious file, a web backdoor, a weak password, a brute force crack, a database collision attack, a remote login, and a suspicious port monitoring; The tenth determination submodule is used to determine the risk asset as a security risk if the risk asset can be moved horizontally to the core asset.
20. A computer readable medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processing device, the steps of the method according to any one of claims 1 to 18 are implemented.
21. An electronic device, characterized in that: include: a storage device having a computer program stored thereon; A processing device, configured to execute the computer program in the storage device to implement the steps of the method according to any one of claims 1 to 18.
22. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 18 are implemented.
Citation Information
Patent Citations
Asset vulnerability assessment method, device and equipment, medium and product
CN116049832A