Methods, devices, equipment, storage media and products for identifying network threats

By obtaining Internet Protocol address information associated with the target domain name, network asset exploration and risk assessment are conducted, solving the problem of incomplete identification of network exposure surfaces in existing technologies, achieving accurate threat information identification, and improving network security detection and response capabilities.

CN118827188BActive Publication Date: 2026-01-30CHINA MOBILE INFORMATION TECHNOLOGY CO LTD +1
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202410888971.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-07-03
Publication Date
2026-01-30
Estimated Expiration
2044-07-03

AI Technical Summary

Technical Problem

Existing network exposure surface management technologies cannot achieve comprehensive and complete network exposure surface identification, resulting in scattered information and easy omissions.

Method used

By obtaining Internet Protocol address information associated with target domain names, network asset probing is conducted, digital asset information is acquired, network risk assessment and availability verification are performed, and threat information is identified.

Benefits of technology

It enables comprehensive identification of network exposure surfaces, accurately determines threat information, and improves network security detection and response capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118827188B_ABST
    Figure CN118827188B_ABST
Patent Text Reader

Abstract

This application provides a method, apparatus, device, storage medium, and product for determining network threats. The method includes: acquiring Internet Protocol (IP) address information associated with target domain name information; performing network asset probing on the IP address information to obtain digital asset information corresponding to the IP address information; conducting network risk assessment on the digital asset information to obtain potential risk information; verifying the exploitability of the potential risk information; and using potential risk information that is exploitable based on the exploitability verification result as threat information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technology, and in particular to a method, apparatus, device, storage medium and product for determining network threats. Background Technology

[0002] With the digital transformation of various industries and the development of cloud computing, information systems are becoming increasingly complex, greatly increasing the pressure on network exposure surface management. At the same time, new attack surfaces may emerge within these systems. For increasingly complex systems, there is an urgent need to change the current state of attack surfaces being "unknowable and uncontrollable." The cybersecurity field needs to shift from simple prevention methods to more mature, strategically enhanced prevention and control measures with detection and response capabilities.

[0003] Current exposure surface management (APS) technologies identify assets from various angles, including external asset management, threat intelligence related to assets, port scanning, and fingerprint matching, to achieve attack surface management. However, existing technologies lack a unified approach to acquiring digital asset information, resulting in the acquisition of independent information. This fragmented information makes comprehensive and complete network exposure surface identification impossible, easily leading to omissions in the discovery of exposure surfaces. Summary of the Invention

[0004] This application provides a method, apparatus, device, storage medium, and product for determining network threats, which can perform comprehensive network exposure surface identification.

[0005] Firstly, this application provides a method for determining network threats, the method comprising:

[0006] Obtain the Internet Protocol address information associated with the target domain name;

[0007] Network asset probing is performed on the Internet Protocol address information to obtain the digital asset information corresponding to the Internet Protocol address information;

[0008] A network risk assessment is performed on the digital asset information to obtain potential risk information;

[0009] The availability of the potential risk information is verified;

[0010] The availability verification results are considered as potential risk information that can be exploited, and are thus treated as threat information.

[0011] In some possible implementations, the availability verification of the potential risk information includes:

[0012] Obtain the Internet Protocol address information corresponding to the potential risk information;

[0013] Vulnerability scanning was performed based on the Internet Protocol address information to obtain vulnerability information;

[0014] Input the relevant data of each vulnerability in the vulnerability information into a preset vulnerability verification model to obtain the success probability of exploitation for each vulnerability.

[0015] The vulnerabilities are sorted according to their probability of successful exploitation.

[0016] The exploitability of each vulnerability is verified by testing each vulnerability in the order of the pre-defined verification process script corresponding to each vulnerability.

[0017] In some possible implementations, the step of performing vulnerability scanning based on the Internet Protocol address information to obtain vulnerability information includes:

[0018] Obtain the device information corresponding to the Internet Protocol address information, wherein the device information includes network port and / or software version information;

[0019] Query the potential vulnerability information corresponding to the device information;

[0020] If a network service vulnerability exists in the potential vulnerability information, detailed information about the network service vulnerability can be obtained by crawling.

[0021] By combining the device information, the potential vulnerability information, and the detailed information of the network service vulnerability, vulnerability information is obtained.

[0022] In some possible implementations, querying the potential vulnerability information corresponding to the device information includes:

[0023] The target device is scanned based on the device information to obtain the corresponding detailed software information;

[0024] Based on the detailed software information, a heuristic search is performed in the vulnerability database to obtain the corresponding potential vulnerability information.

[0025] In some possible implementations, after determining the potential risk information that is exploitable as network threat information based on the exploitability verification result, the method further includes:

[0026] Obtain the current session list from the default vulnerability monitoring tool;

[0027] Match each session in the current session list with preset threat characteristics;

[0028] The detailed information of sessions in the current session list that match the preset threat characteristics is taken as network threat information.

[0029] In some possible implementations, after obtaining the current session list from the preset vulnerability monitoring tool, the method further includes:

[0030] Extract the unique session identifier of each session in the current session list;

[0031] Based on the unique session identifier, send a verification command to the corresponding session;

[0032] Receive the return information corresponding to the verification command;

[0033] If the returned information is not empty and does not contain command execution failure information, the corresponding session will be marked as a real session;

[0034] The step of matching each session in the current session list with preset threat characteristics includes:

[0035] Each session marked as a real session in the current session list is matched with a preset threat feature.

[0036] In some possible implementations, the step of performing network asset probing on the Internet Protocol address information to obtain the digital asset information corresponding to the Internet Protocol address information includes:

[0037] Based on the Internet Protocol address information, a port scan is performed to obtain the target port;

[0038] The Uniform Resource Locator and Network Service Information corresponding to the target port are crawled using a web crawler.

[0039] The target domain name information, the Internet Protocol address information, the Uniform Resource Locator (URL), and the network service information are integrated into a network asset set;

[0040] Based on the Internet Protocol address information, obtain the corresponding application programming interface information, which includes the interface name, interface address, or request method.

[0041] The obtained application programming interface (API) information is integrated into an API asset set;

[0042] The network asset set and the application programming interface asset set are merged to obtain digital asset information.

[0043] In some possible implementations, the network risk assessment of the digital asset information to obtain potential risk information includes:

[0044] Based on a pre-defined vulnerability database, the network asset set is analyzed for security risks to obtain network security risk information;

[0045] The application programming interface asset set is compared with the data in the preset application programming interface baseline library;

[0046] Based on the data in the application programming interface asset set that differs from the preset application programming interface baseline library, application programming interface security risk information is obtained;

[0047] By combining the network security risk information and the application programming interface security risk information, potential risk information is obtained.

[0048] In some possible implementations, the step of performing security vulnerability analysis on the network asset set based on a preset vulnerability database to obtain network security risk information includes:

[0049] Obtain compromise intelligence from a preset vulnerability database, wherein the compromise intelligence is information on network assets that have already suffered network security risks;

[0050] The compromised intelligence is matched with the Internet Protocol address information and the Uniform Resource Locator in the network asset set to obtain the asset compromise risk;

[0051] On a pre-defined network platform, sensitive data is searched based on target domain name information in the network asset set to determine the risk of data leakage.

[0052] Based on the Internet Protocol address information and the Uniform Resource Locator in the network asset set, vulnerability scanning is performed on the corresponding ports to obtain security configuration risks;

[0053] The network service information in the network asset set is compared with a preset security baseline database to identify unnecessary open ports and / or services, which are then identified as asset exposure risks.

[0054] By combining the risks of asset loss, data leakage, security configuration, and asset exposure, we obtain cybersecurity risk information.

[0055] In some possible implementations, after determining the potential risk information that is usable as a network threat information based on the availability verification result, the method further includes:

[0056] Extract the network nodes connected to the preset attack start node and preset attack end node from the Internet Protocol address information to obtain attack-related node information;

[0057] Find the vulnerability information related to each network node in the attack-related node information from the network threat information, and obtain the vulnerability weight of each network node in the attack-related node information;

[0058] Find the asset information related to each network node in the attack-related node information from the digital asset information, and obtain the asset weight of each network node in the attack-related node information;

[0059] Based on the vulnerability weight and the asset weight, the threat weight of each network node in the attack-related node information is obtained;

[0060] An attack path graph is formed based on the connectivity between the network nodes and the threat weights corresponding to the network nodes. The attack path graph represents the possible paths from the preset attack start node to the preset attack end node.

[0061] The shortest path in the attack path graph is obtained through the Q-learning algorithm.

[0062] In some possible implementations, obtaining the shortest path in the attack path graph using the Q-learning algorithm includes:

[0063] The preset attack starting node in the attack path graph is taken as the current node;

[0064] Based on the current node, determine the target node according to the current Q value;

[0065] The Q value is updated based on the threat weight corresponding to the target node;

[0066] Record the path from the current node to the target node, and update the target node to the current node;

[0067] Determine whether the current node is the preset attack endpoint node. If not, redetermine the target node and the current node based on the Q value and record the corresponding path until the current node is the preset attack endpoint node. Then, use the path as the shortest path in the attack path graph.

[0068] Secondly, this application also provides a network threat determination device, the device comprising:

[0069] The acquisition module is used to acquire Internet Protocol address information associated with the target domain name information;

[0070] The exploration module is used to explore network assets using the Internet Protocol address information to obtain digital asset information corresponding to the Internet Protocol address information;

[0071] The assessment module is used to conduct a network risk assessment on the digital asset information to obtain potential risk information;

[0072] A verification module is used to verify the availability of the potential risk information.

[0073] The determination module is used to identify potential risks that can be exploited based on the availability verification results, and treat them as threat information.

[0074] Thirdly, this application provides a network threat determination device, the device comprising: a processor, and a memory storing computer program instructions; the processor reads and executes the computer program instructions to implement the network threat determination method described above.

[0075] Fourthly, this application provides a computer-readable storage medium storing computer program instructions that, when executed by a processor, implement the network threat determination method described above.

[0076] Fifthly, this application provides a computer program product in which instructions, when executed by a processor of an electronic device, cause the electronic device to perform the network threat determination method described above.

[0077] The network threat determination method, apparatus, device, storage medium, and product provided in this application, after obtaining Internet Protocol address information associated with target domain name information, performs network asset probing to obtain corresponding digital asset information, and then conducts network risk assessment on the digital asset information to obtain potential risk information. Subsequently, the exploitability of the potential risk information is verified to determine threat information. The above-described embodiments of this application comprehensively obtain all digital asset information associated with the target domain name information and perform an overall risk assessment. After the assessment, the exploitability of each possible potential risk is verified to accurately determine the actual risk that can pose a threat. The network threat determination method, apparatus, device, storage medium, and product provided in this application can perform comprehensive network exposure surface identification and accurately determine threat information. Attached Figure Description

[0078] This application can be better understood from the following description of specific embodiments in conjunction with the accompanying drawings, wherein:

[0079] Other features, objects, and advantages of this application will become more apparent from the following detailed description of non-limiting embodiments with reference to the accompanying drawings, wherein the same or similar reference numerals denote the same or similar features.

[0080] Figure 1 This is a flowchart of a network threat determination method provided in one embodiment of this application;

[0081] Figure 2 This is a flowchart of a network threat determination method provided in another embodiment of this application;

[0082] Figure 3This is a schematic diagram illustrating the attack path evaluation principle of a network threat determination method provided in one embodiment of this application;

[0083] Figure 4 This is a schematic diagram of the structure of a network threat determination device provided in one embodiment of this application;

[0084] Figure 5 This is a schematic diagram of the hardware structure of the network threat determination device provided in the embodiments of this application. Detailed Implementation

[0085] The features and exemplary embodiments of various aspects of this application will now be described in detail. Numerous specific details are set forth in the following detailed description to provide a comprehensive understanding of this application. However, it will be apparent to those skilled in the art that this application can be implemented without requiring some of these specific details. The following description of embodiments is merely intended to provide a better understanding of this application by illustrating examples. This application is by no means limited to any specific configurations and algorithms presented below, but covers any modifications, substitutions, and improvements to elements, components, and algorithms without departing from the spirit of this application. Well-known structures and techniques are not shown in the accompanying drawings and the following description in order to avoid unnecessary obfuscation of this application.

[0086] Continuous Threat Exposure Management (CTEM) refers to the process of continuously managing and responding to threat exposures. It is an integrated, iterative approach that prioritizes potential solutions and continuously improves the security posture.

[0087] A proof-of-concept (PoC) script is a practical script used to demonstrate the feasibility and effectiveness of an idea, concept, or technology. It is a preliminary implementation designed to validate a theory or hypothesis and determine whether it can be successfully applied in real-world scenarios.

[0088] With the development of digital transformation and cloud computing, user information systems are becoming increasingly complex. This complexity significantly increases the pressure on exposure surface management. For increasingly complex systems, users urgently need to change the "unknowable and uncontrollable" state of the attack surface. The cybersecurity field requires a new security technology framework that transforms simple prevention methods into more mature, strategically enhanced prevention and control with detection and response capabilities. The CTEM framework is precisely the realization of this idea.

[0089] A complete CTEM cycle comprises five steps: scope definition, discovery and identification, prioritization, verification, and action. CTEM uses tools to inventory and classify assets and vulnerabilities, conducts simulated or semi-automated test attacks and other forms of situational assessment, analyzes current risk priorities, verifies threats, and provides effective and actionable risk mitigation recommendations to infrastructure teams, system and project owners to enable action on identified issues. However, current technologies struggle to implement all five steps of CTEM. The lack of implementation technologies and methods for crucial aspects of the CTEM management process, such as "priority assessment, threat exposure surface verification, and threat closed-loop mitigation," leads to a disconnect between existing discovery methods and technologies during application, resulting in fragmented information and an inability to comprehensively and completely identify network exposure surfaces, making it prone to omissions in exposure surface discovery.

[0090] The inventors, through their research addressing the aforementioned problems, discovered that solving the issues of determining the scope of the exposure surface and identifying threat exposure surfaces using a combination of methods can improve the ability to discover exposure surfaces. Simultaneously, solving the problem of threat exposure surface verification methods, and eliminating the severe interference caused by a large number of false threats in threat exposure surface handling operations through threat exposure surface verification, can solve the problem of continuous monitoring and identification of threat exposure surfaces.

[0091] To address the problems of the prior art, embodiments of this application provide a method, apparatus, device, storage medium, and product for determining network threats. The method for determining network threats provided in this application embodiment is described first. In this embodiment, the method can be executed by computer software, which can run on the aforementioned network threat determination apparatus and device.

[0092] Figure 1 A flowchart illustrating a network threat determination method according to an embodiment of this application is shown. Figure 1 As shown, the method includes the following steps S101 to S105.

[0093] Step S101: The software obtains the Internet Protocol address information associated with the target domain name information.

[0094] In its implementation, the software can use the Domain Name System (DNS) to query the Internet Protocol (IP) address of a target domain name. For example, it sends a query request to a DNS server to obtain the IP address corresponding to the target domain name. Once the IP address of the target domain name is obtained, it can use that IP address to send a network request to the target server. After establishing a connection with the target server and sending the request, it receives detailed information related to that IP address, namely the Internet Protocol address information.

[0095] Step S102: The software performs network asset exploration based on the above Internet Protocol address information to obtain the digital asset information corresponding to the above Internet Protocol address information.

[0096] In its implementation, the software uses the provided IP address information to perform an IP address scan to determine if the target IP address is reachable. Once the target IP address is determined to be reachable, a port scan can be performed to identify the open ports and services on the target host. By analyzing the port scan results, the software can attempt to identify the specific services and applications running on the target host. Further feature recognition is then performed to obtain more information about digital assets, such as website information, database version information, and application frameworks for web servers.

[0097] As another example, software can perform IP address scanning by sending network requests or using specialized scanning tools. Scanning can include detecting open ports, response times, and other network metrics to determine whether the target host is online and accessible.

[0098] As another example, port scanning can be done by sending specific network requests or by using port scanning tools.

[0099] Step S103: The software base performs a network risk assessment on the above-mentioned digital asset information to obtain potential risk information.

[0100] In its implementation, a pre-defined vulnerability database is used to scan the target digital asset for vulnerabilities. During the scan, the software analyzes the results and matches them against the vulnerability information in the database to determine if the target asset is affected by known vulnerabilities. Based on the vulnerability matching results, a network risk assessment is performed. Finally, a potential risk information report is generated, containing potential risk information related to vulnerabilities in the digital asset. This report may include detailed information such as vulnerability descriptions, scope of impact, and remediation recommendations.

[0101] As another example, cyber risk assessment specifically involves calculating the risk level of each vulnerability based on its severity, public disclosure, and potential impact. This can be achieved using pre-defined assessment rules, weighted algorithms, or other risk assessment models.

[0102] Step S104: The software verifies the availability of the aforementioned potential risk information.

[0103] In its implementation, the software, based on previously obtained potential risk information reports and following a verification process script, executes a series of operations to verify the exploitability of the potential risk information. The pre-defined verification process script defines the specific steps and procedures for verifying potential risks. The script may include operations such as using vulnerability exploitation tools, sending specific requests, and code auditing. The results of the verification process are analyzed to determine whether the potential risk can be successfully exploited.

[0104] As another example, the software can attempt to exploit known vulnerabilities, simulate malicious behavior, or send specific requests to trigger vulnerabilities based on the verification process script.

[0105] Step S105: The software interprets the availability verification results as potential risk information that can be exploited, and treats this as threat information.

[0106] In its implementation, the software first analyzes the results of the exploitability verification. Based on the verification results and analysis, it assesses potential risk information. For example, it recalculates the risk level of the vulnerability and, combined with the verification results, determines the severity and scope of the potential risk. If the verification results indicate that the potential risk information has a high degree of exploitability and may pose a substantial threat to the system or data, the software will classify this information as threat information.

[0107] As another example, the software analyzes the results of exploitability verification, specifically by checking whether the vulnerabilities discovered during the verification process are real, whether the vulnerabilities can be successfully exploited, and the actual impact of potential risks.

[0108] As another example, once information is identified as a threat, it can be flagged and categorized for further processing and notification. This might include assigning threat levels, marking threats as requiring immediate action, and so on.

[0109] The method described in this application involves obtaining Internet Protocol (IP) address information associated with the target domain name, then probing for network assets and corresponding digital asset information. Based on a pre-defined vulnerability database, a network risk assessment is performed on this digital asset information to obtain potential risk information. Subsequently, the exploitability of this potential risk information is verified to confirm the threat information. This approach enables comprehensive network exposure surface identification and accurate threat identification.

[0110] To improve the efficiency of verification, in some embodiments, the above-mentioned S104 may include steps A1 to E1:

[0111] Step A1: The software obtains the Internet Protocol address information corresponding to the above potential risk information.

[0112] In its implementation, the software obtains the previously acquired potential risk information report, analyzes and processes the potential risk information to determine the Internet Protocol address information involved, and further collects detailed information about these addresses, including hostname, port information, service information, etc.

[0113] Step B1: The software performs a vulnerability scan based on the above Internet Protocol address information to obtain vulnerability information.

[0114] In its implementation, the software determines the targets to be scanned for vulnerabilities based on the obtained Internet Protocol (IP) address information and performs the vulnerability scan. After the scan is complete, the software analyzes the scan results to obtain vulnerability information.

[0115] As another example, software vulnerability scanning can be performed using automated vulnerability scanning tools or scripts to check for security vulnerabilities in a target system. The scanning tool may send specific test packets or requests to probe for vulnerabilities in the target system.

[0116] Step C1: The software inputs the relevant data of each vulnerability in the above vulnerability information into the preset vulnerability verification model to obtain the success probability of exploitation for each of the above vulnerabilities.

[0117] In its implementation, the software integrates vulnerability information obtained from previous vulnerability scans and transforms it into an easily processed data format. This may include a vulnerability description, affected software or system, vulnerability type, vulnerability severity, and sample vulnerability code. For each vulnerability, the software selects an appropriate vulnerability verification model and uses this model to verify whether the vulnerability can be exploited. Then, based on the vulnerability description and the requirements of the verification model, the corresponding model parameters are set. The model is then used to calculate the probability of successful exploitation.

[0118] As another example, specific model parameters may be set, including parameters such as attack vector, attacker capabilities, and target environment.

[0119] Step D1: The software sorts the above vulnerabilities according to the probability of successful exploitation of each vulnerability.

[0120] In its implementation, the software calculates the probability of successful exploitation for each vulnerability based on the previous steps and normalizes these probabilities. Then, it sorts these normalized success probabilities.

[0121] As another example, software normalization can be achieved by mapping the probability of success to a uniform range, such as a score between 0 and 100, or in percentage form.

[0122] As another example, sorting algorithms can be bubble sort, insertion sort, selection sort, quick sort, and merge sort, etc.

[0123] Step E1: The software tests each of the above-mentioned vulnerabilities according to the preset verification process scripts corresponding to each of the above-mentioned vulnerabilities, based on the sorted order, in order to verify the exploitability of each of the above-mentioned vulnerabilities.

[0124] In its implementation, the software utilizes a corresponding verification process script based on the characteristics and exploitation conditions of each vulnerability. According to the verification process script for each vulnerability, appropriate verification parameters are set, which may include attack vectors, exploit code, and target system configurations. Based on the sorting results, vulnerabilities are tested sequentially according to their verification process scripts. During testing, the results for each vulnerability are recorded, including whether exploitation was successful, error messages, and any anomalies encountered during the attack. The test results are then analyzed to determine the exploitability of each vulnerability.

[0125] As another example, the software can provide feedback based on the test results, such as whether the vulnerability was successfully exploited, or specific problems encountered during the attack phase.

[0126] The method described in this application involves performing vulnerability scanning based on the aforementioned Internet Protocol (IP) address information to obtain vulnerability information and the probability of successful exploitation for each vulnerability. Then, the vulnerabilities are sorted according to their probability of successful exploitation, and tested sequentially to verify their exploitability. This sorting process before verifying exploitability improves the efficiency of the verification process.

[0127] To obtain comprehensive vulnerability information, in some implementations, the vulnerability scanning based on the aforementioned Internet Protocol address information to obtain vulnerability information may include steps A2 to D2:

[0128] Step A2: The software obtains the device information corresponding to the Internet Protocol address information mentioned above. The device information includes network port and / or software version information.

[0129] In practice, the software can use IP address scanning techniques, such as ICMP Echo requests or TCP SYN scans, to discover hosts and open ports on the network. Once a specific IP address and open port are discovered, a port scan can be performed to obtain more information. By simulating communication with the target port, the software can determine whether the port is open and obtain information about the services and software versions associated with that port.

[0130] As another example, IP address scanning technology can determine which IP addresses are active and identify open network ports by sending probe packets and listening to the responses.

[0131] As another example, port scanning can include TCP-based full connection scanning, half-open (SYN) scanning, and UDP scanning.

[0132] Step B2: The software queries for potential vulnerability information corresponding to the above device information.

[0133] In practice, the software can connect to known vulnerability databases, such as the CVE (Common Vulnerability and Exposure) database, NVD (National Vulnerability Database), or vendor-provided vulnerability information databases, to query known vulnerabilities related to device information. The obtained device information can be matched with records in the vulnerability database to obtain corresponding potential vulnerability information. By comparing the correlation between device information and known vulnerabilities, it can be determined whether the device is affected by known vulnerabilities.

[0134] As another example, software can use automated vulnerability scanning tools to scan the acquired device information and automatically query vulnerability databases.

[0135] Step C2: If the software finds that a network service exists in the aforementioned potential vulnerability information, it will use a web crawler to obtain detailed information about that network service.

[0136] In practical implementation, the software identifies the network services running on the device. Once the network services on the device are determined, service fingerprinting technology can be used to obtain more detailed information. For network services identified as web servers, web crawling technology can be used to obtain even more detailed information.

[0137] As another example, software can identify the network services running on a device by using open port information obtained through port scanning technology. For instance, through techniques such as TCP SYN scanning or UDP scanning, software can identify common network services running on the device, such as HTTP (port 80), FTP (port 21), SSH (port 22), SMTP (port 25), etc.

[0138] Step D2: The software merges the above-mentioned device information, the above-mentioned potential vulnerability information, and the above-mentioned network service details to obtain vulnerability information.

[0139] In its implementation, the software needs to integrate the acquired device information, potential vulnerability information, and detailed network service information. Appropriate methods are used to correlate and match this information. Once the correlation and matching are complete, vulnerability information can be generated based on the device's potential vulnerability information and the network service's detailed information.

[0140] As another example, the software correlates and matches device information, potential vulnerability information, and network service details using common identifiers, device names, IP addresses, and other key information. For instance, a device's unique identifier (such as its MAC address) can be used to associate device information with potential vulnerability information and network service details.

[0141] The method described in this application obtains device information corresponding to Internet Protocol (IP) address information, then queries for potential vulnerability information corresponding to that device information. If network services are present in the vulnerability information, detailed information about those network services is obtained through web scraping. Finally, the device information, potential vulnerability information, and detailed information about the network services are combined to obtain the vulnerability information. By collecting device information, potential vulnerability information, and detailed information about network services, comprehensive vulnerability information can be obtained.

[0142] To save time and resources in the automated vulnerability verification process, in some implementations, the above-mentioned query for potential vulnerability information corresponding to the above-mentioned device information may include steps A3 to B3:

[0143] Step A3: The software scans the target device based on the above device information to obtain the corresponding detailed software information.

[0144] In practice, the software needs to use appropriate scanning technology to scan the target device. Based on the information obtained from the device scan, the software can be identified to determine the specific software and its version running on the target device, and obtain the corresponding detailed software information.

[0145] As another example, scanning can include port scanning, service fingerprinting, operating system identification, and so on. By sending network requests and parsing the device's responses, software can determine the open ports on the device, the services running, and basic device information (such as IP address, operating system, etc.).

[0146] Step B3: Based on the above detailed software information, the software performs a heuristic search in the vulnerability database to obtain the corresponding potential vulnerability information.

[0147] In practical implementation, once the software running on the target device and its version are determined, a heuristic search can be performed using a vulnerability database to obtain potential vulnerability information related to these software versions. The matched potential vulnerability information can then be extracted from the database. The extracted information may include the vulnerability description, severity, scope of impact, possible attack methods, and suggested solutions.

[0148] As another example, heuristic search refers to a search method that uses fuzzy matching or rule matching based on detailed software information to find relevant vulnerability information. Vulnerability databases can be queried based on software name, version number, specific characteristics, or other relevant information to obtain potential vulnerability information matching the software version of the target device.

[0149] The method described in this application scans the target device based on device information to obtain detailed software information, and then performs a heuristic search in a vulnerability database to obtain corresponding potential vulnerability information. By excluding vulnerability exploitation information that is clearly irrelevant to the product, noise in vulnerability exploitation information is reduced, improving the accuracy of vulnerability identification, thereby saving time and resources in the automated vulnerability verification process.

[0150] To enhance overall security capabilities, in some implementations, after identifying the potential risk information as network threat information based on the availability verification results, the method may further include steps A4 to C4:

[0151] Step A4: The software retrieves the current session list from the preset vulnerability monitoring tool.

[0152] In its implementation, the software monitors network traffic and identifies and records information about the current session to obtain a list of current sessions.

[0153] As another example, software can define sessions based on different protocols (such as TCP, UDP, etc.) and application layer protocols (such as HTTP, SMTP, etc.). Pre-defined vulnerability monitoring tools need to capture and record information related to these sessions, such as source IP address, target IP address, communication protocol, and port.

[0154] Step B4: The software matches each session in the current session list with preset threat characteristics.

[0155] Predefined threat signatures refer to predefined rules, patterns, signatures, or other characteristics associated with threats. These signatures may include fingerprints of known malware, patterns of attack behavior, and unusual network traffic.

[0156] In its implementation, the software matches preset threat characteristics with each session in the current session list. The matching process can be implemented using regular expressions and pattern matching algorithms.

[0157] Step C4: The software uses the detailed information of sessions that match the preset threat characteristics in the current session list as network threat information.

[0158] In its implementation, when a current session is detected to match a preset threat signature, the software marks the session's detailed information as network threat information. This detailed information can include all data related to the session, such as source IP address, destination IP address, communication protocol, port, and packet content. The marked network threat information can be stored in a centralized threat database for subsequent analysis and processing.

[0159] The method described in this application obtains a list of current sessions from a preset vulnerability monitoring tool, matches each session in the current session list with preset threat characteristics, and uses the detailed information of sessions in the session list that match the preset threat characteristics as network threat information. This can improve the ability to detect sessions that have already been exploited, reduce false negatives, and improve overall security protection capabilities.

[0160] To improve the speed and effectiveness of response to potential threats, in some implementations, after obtaining the current session list from the preset vulnerability monitoring tool, the method may further include steps A5 to D5:

[0161] Step A5: The software extracts the unique session identifier for each session in the current session list above.

[0162] In practical implementation, the software can use network protocol headers or other relevant information as a unique identifier for a session. For example, in the TCP protocol, a unique identifier can be composed of the source IP address, destination IP address, source port number, and destination port number. Upon receiving the current session list, the unique identifier for each session is extracted.

[0163] Step B5: The software sends a verification command to the corresponding session based on the unique session identifier mentioned above.

[0164] In its implementation, the software assigns a unique identifier to each session and sends a verification command to confirm whether the session is genuine.

[0165] Step C5: The software receives the return information corresponding to the above verification command.

[0166] In the actual implementation, the software needs to wait for the corresponding return information for each sent verification command. The return information may include the command execution result, session state information, etc.

[0167] Step D5: If the returned information is not empty and does not contain command execution failure information, the software marks the corresponding session as a real session.

[0168] In its implementation, the software determines the session based on the returned information. If the returned information is not empty and does not contain command execution failure information, the corresponding session can be marked as a real session. Real sessions can be added to the list of known sessions for subsequent matching and analysis.

[0169] The above method matches each session in the current session list with preset threat characteristics, including:

[0170] The software matches each session marked as a real session in the current session list with preset threat characteristics.

[0171] In its implementation, the software can perform threat signature matching on sessions marked as real sessions.

[0172] As another example, when a session that matches a preset threat profile is detected, the software can generate a threat report that includes information such as the threat type, threat level, and session details.

[0173] The method described in this application extracts the unique session identifier of each session in the current session list, sends a verification command to the corresponding session, and then receives the return information corresponding to the verification command. If the return information is not empty and does not contain command execution failure information, the corresponding session is marked as a real session. Then, each session marked as a real session in the current session list is matched against preset threat characteristics. This ensures that the identified sessions are real and valid, accurately identifies and responds to real security events, optimizes resource allocation, and improves the speed and effectiveness of response to potential threats.

[0174] To obtain complete digital asset information, some implementation methods may refer to... Figure 2 The above S102 may include:

[0175] Step 201: Based on the above Internet Protocol address information, the software performs a port scan to obtain the target port.

[0176] In its implementation, the software extracts the target IP address from the session information, determines the range of ports to be scanned, and iterates through the port numbers in the set range to obtain the target port.

[0177] As another example, the software determines the range of ports to scan, allowing you to choose to scan common ports, such as those in the range of 1 to 65535. You can also customize the port range according to your needs.

[0178] As another example, the scanning process could involve creating a socket using Socket programming and attempting to establish a connection with a specified port on the target host. The port's status is then determined based on the connection's outcome. If the connection succeeds, the port is open and can be processed accordingly. If the connection fails, the port is closed or filtered by a firewall.

[0179] Step 202: The software crawls the Uniform Resource Locator and network service information corresponding to the target port mentioned above.

[0180] In its implementation, the software obtains the target IP address and open port number from the port scan results. A URL is constructed based on the target IP address and port number, and the content of the target URL is retrieved by sending an HTTP request. For the returned HTML content, the target URL and network service information are extracted. The extracted URL and service information are recorded to obtain the Uniform Resource Locator (URL) and network service information corresponding to the target port.

[0181] Step 203: The software integrates the above target domain name information, the above Internet Protocol address information, the above Uniform Resource Locator (URL), and the above network service information into a network asset set.

[0182] In its implementation, the software can define a suitable data structure to represent the network asset set. The software adds target domain name information, Internet Protocol address information, Uniform Resource Locator (URL), and network service information to the network asset set.

[0183] As another example, a collection of network assets can use data structures such as dictionaries or custom classes to store target domain names, Internet Protocol addresses, URLs, and network service information as key-value pairs.

[0184] Step 204: Based on the above Internet Protocol address information, the software obtains the corresponding application programming interface information, which includes the interface name, interface address, or request method.

[0185] In its implementation, the software retrieves Internet Protocol (IP) addresses from the previously integrated set of network assets, uses relevant network programming APIs to send HTTP requests to obtain the page content corresponding to those IP addresses, and then obtains the corresponding application programming interface (API) information.

[0186] Step 205: The software integrates the obtained application programming interface (API) information into an API asset set.

[0187] In practice, the software adds the obtained API information to the application programming interface asset collection.

[0188] Step 206: The software merges the above-mentioned network asset set and the above-mentioned application programming interface asset set to obtain digital asset information.

[0189] The method described in this application involves port scanning to obtain target ports, then using a web crawler to extract the corresponding Uniform Resource Locator (URI) and network service information. The target domain name information, Internet Protocol (IP) address information, URI, and network service information are then integrated into a network asset set. Next, the obtained Application Programming Interface (API) information is integrated into an API asset set. Finally, the network asset set and the API asset set are merged to obtain digital asset information. By merging these two sets, complete digital asset information can be obtained.

[0190] In order to accurately obtain potential risk information, in some implementations, the above-mentioned S103 may include steps A6 to D6:

[0191] Step A6: Based on a preset vulnerability database, the software performs security vulnerability analysis on the above-mentioned set of network assets to obtain network security risk information.

[0192] In its implementation, the software obtains a pre-defined vulnerability database containing known cybersecurity vulnerabilities and risk information. Using this database, it performs a security risk analysis on a set of network assets. Each asset in the set is iterated over, compared with the vulnerability information in the database, and checked for the presence of any known cybersecurity vulnerabilities. If a matching vulnerability is found, it is recorded as a cybersecurity risk.

[0193] Step B6: The software compares the above set of application programming interface assets with the data in the preset application programming interface baseline library.

[0194] In its implementation, the software acquires a pre-defined application programming interface (API) baseline library, which contains basic information and security requirements for known APIs. The baseline library may include basic information such as API names, addresses, and request methods. The API asset set is then compared with the pre-defined API baseline library.

[0195] Step C6: The software obtains application programming interface (API) security risk information based on the data in the above API asset set that differs from the preset API baseline library.

[0196] In its implementation, the software compares the name, address, request method, and other information of each application programming interface (API) to check if they are consistent with the information in the baseline library. If any inconsistencies are found, they are recorded as API security risk information.

[0197] Step D6: The software merges the above network security risk information and the above application programming interface security risk information to obtain potential risk information.

[0198] In its implementation, the software merges the cybersecurity risk information and application programming interface (API) security risk information obtained in the above steps. Based on the merged cybersecurity risk information and API security risk information, potential risk information is derived.

[0199] The method described in this application analyzes the security risks of the aforementioned network asset set based on a preset vulnerability database to obtain network security risk information. Then, it compares the aforementioned application programming interface (API) asset set with a preset API baseline database. Based on data in the API asset set that differs from the preset API baseline database, it obtains API security risk information. Finally, it merges the network security risk information and the API security risk information to obtain potential risk information. Based on the network security risk information and the API security risk information, it accurately obtains potential risk information.

[0200] To accurately obtain cybersecurity risk information, in some implementations, the aforementioned analysis of the network asset set based on a preset vulnerability database to obtain cybersecurity risk information may include steps A7 to F7:

[0201] Step A7: The software obtains vulnerability information from a preset vulnerability database. The aforementioned vulnerability information refers to information about network assets that have already suffered network security risks.

[0202] In its implementation, the software needs to retrieve known cybersecurity vulnerabilities and risks from a pre-defined vulnerability database. This can be achieved by reading the database file or accessing its database. The database may contain various common vulnerability information, such as weak passwords and unpatched software vulnerabilities. The software needs to parse and extract this information and store it in memory or a database for later use.

[0203] Step B7: The software matches the above-mentioned compromise information with the above-mentioned Internet Protocol address information and the above-mentioned Uniform Resource Locator in the above-mentioned network asset set to obtain the asset compromise risk.

[0204] In its implementation, the software matches the compromise intelligence obtained in step A7 with the Internet Protocol address information and Uniform Resource Locators (URLs) in the network asset set. Based on the vulnerability or risk information described in the compromise intelligence, the software can iterate through each asset in the network asset set and compare its Internet Protocol address and URL with the information in the compromise intelligence. If a match is found, indicating that the asset is subject to the corresponding cybersecurity risk, the software needs to record the compromise risk of these assets.

[0205] Step C7: On a preset network platform, the software performs a sensitive data search based on the target domain name information in the aforementioned network asset set to determine the risk of data leakage.

[0206] In its implementation, the software performs sensitive data searches on a pre-defined network platform based on target domain name information in a set of network assets.

[0207] As another approach, the software can use web crawling techniques or specific search algorithms to search for sensitive data related to the target domain on online platforms, such as personal information and passwords. If sensitive data is found, the software needs to log it as a data breach risk.

[0208] Step D7: Based on the Internet Protocol address information and Uniform Resource Locator (URL) in the above-mentioned network asset set, the software performs vulnerability scanning on the corresponding ports to obtain security configuration risks.

[0209] In its implementation, the software performs vulnerability scans on corresponding ports based on Internet Protocol (IP) address information and Uniform Resource Locators (URLs) from the network asset set. Vulnerability scanning can be implemented using existing vulnerability scanning tools or custom scanning modules. During the scan, the software attempts to connect to various ports of the network assets and performs vulnerability checks. If security configuration issues related to known vulnerabilities are found, they need to be recorded as security configuration risks.

[0210] Step E7: The software compares the network service information in the above network asset set with the preset security baseline library to identify unnecessary open ports and / or services, and identifies them as asset exposure risks.

[0211] In its implementation, the software compares the network service information in the network asset set with a pre-defined security baseline database. This database contains the security requirements and best practices for each network service. The software compares the name, port number, and other information of each network service to determine if it meets the security baseline requirements. If any unnecessary open ports and / or services are found, the software records them as asset exposure risks.

[0212] Step F7: The software combines the above-mentioned risks of asset loss, data leakage, security configuration, and asset exposure to obtain cybersecurity risk information.

[0213] In its implementation, the software merges the risk information obtained from steps B7, C7, D7, and E7. This risk information can be stored and organized using lists, dictionaries, or custom data structures to form cybersecurity risk information.

[0214] The method described in this application involves obtaining vulnerability intelligence from a pre-defined vulnerability database, matching this vulnerability intelligence with the Internet Protocol address information and Uniform Resource Locators (URLs) in the network asset set to identify asset vulnerability risks. Then, on a pre-defined network platform, sensitive data is searched based on target domain name information in the network asset set to determine data leakage risks. Based on the Internet Protocol address information and URLs in the network asset set, vulnerability scanning is performed on corresponding ports to identify security configuration risks. The network service information in the network asset set is compared with a pre-defined security baseline database to identify unnecessary open ports and / or services, which are then considered as asset exposure risks. Finally, the asset vulnerability risks, data leakage risks, security configuration risks, and asset exposure risks are combined to obtain network security risk information. This method can accurately obtain network security risk information.

[0215] In order to accurately obtain cybersecurity risk information, in some implementations, after S105, the method may further include steps A8 to F8:

[0216] Step A8: The software extracts network nodes connected to the preset attack start node and preset attack end node from the above Internet Protocol address information to obtain attack-related node information.

[0217] In its implementation, the software extracts information about network nodes connected to preset attack start and end nodes. First, the software uses network scanning techniques (such as Ping or port scanning) to obtain information about all active nodes in the network. Then, by analyzing network topology or network traffic data, it identifies nodes connected to the preset attack start and end nodes. This process may involve techniques such as routing tables, network topology diagrams, and network traffic analysis. Finally, the software extracts and records the network node information related to the attack.

[0218] Step B8: The software searches for vulnerability information related to each network node in the above network threat information and attack-related node information, and obtains the vulnerability weight of each network node in the above attack-related node information.

[0219] In its implementation, the software searches for relevant vulnerability information for each network node in the aforementioned attack-related node information and obtains a vulnerability weight. Specifically, it can access vulnerability databases or online vulnerability databases to obtain vulnerability information for each network node. Based on factors such as the severity, public awareness, and scope of impact of the vulnerability, the software assigns a vulnerability weight to each vulnerability. The vulnerability weight can be a numerical value or a classification label used to represent the severity of the vulnerability.

[0220] Step C8: The software searches for asset information related to each network node in the above-mentioned digital asset information and attack-related node information, and obtains the asset weight of each network node in the above-mentioned attack-related node information.

[0221] In its implementation, the software searches for related asset information for each network node in the aforementioned attack-related node information and obtains its asset weight. Asset information may include digital assets such as servers, databases, and applications. The software can obtain asset information corresponding to each network node by accessing an asset management system, network topology map, or other resource discovery tools. Based on factors such as the asset's value, importance, and sensitivity, the software assigns an asset weight to each asset. The asset weight can be a numerical value or a classification label used to represent the asset's importance.

[0222] Step D8: Based on the above vulnerability weights and asset weights, the software obtains the threat weight of each network node in the above attack-related node information.

[0223] In its implementation, the software calculates the threat weight of each attack-related node based on the aforementioned vulnerability and asset weights. The threat weight is obtained by weighting the vulnerability and asset weights. The specific method of weighting can be determined according to the actual situation, such as a simple weighted sum or a more complex weighted average. The threat weight represents the overall threat level of each attack-related node and is used to assess the severity of security risks.

[0224] Step E8: The software generates an attack path graph based on the connectivity between the network nodes and the threat weights of the network nodes. The attack path graph represents the possible paths from the preset attack start node to the preset attack end node.

[0225] In its implementation, the software constructs an attack path graph based on the connectivity and threat weights between network nodes. The attack path graph represents the possible paths from a preset attack start node to a preset attack end node. The software analyzes the connectivity between each network node, determines possible paths, and plots the connectivity and threat weight information of the nodes into a graphical structure. The attack path graph can be constructed using graph theory algorithms or network analysis algorithms, such as shortest path algorithms, depth-first search, or breadth-first search.

[0226] Step F8: The software uses the Q-learning algorithm to obtain the shortest path in the attack path graph above.

[0227] In its implementation, the software uses the Q-learning algorithm to calculate the shortest path in the attack path graph. Q-learning is a reinforcement learning algorithm used to learn the optimal strategy in a given environment. Based on the information of nodes and edges in the attack path graph, as well as the threat weights between nodes, the software uses Q-learning to find the shortest path from a preset attack start node to a preset attack end node. Q-learning considers factors such as distance between nodes, threat weights, and connectivity to select the optimal path. Finally, the software outputs the shortest path as the result in the attack path graph.

[0228] The method described in this application extracts network nodes connected to preset attack start and end nodes from the Internet Protocol address information to obtain attack-related node information. Then, it searches for vulnerability information related to each network node in the attack-related node information from the network threat information to obtain the vulnerability weight of each network node in the attack-related node information. Based on the vulnerability weight and asset weight, the threat weight of each network node in the attack-related node information is obtained. An attack path graph is formed according to the connectivity between the network nodes and the corresponding threat weights. Based on the attack path graph, the shortest path in the attack path graph is obtained using the Q-learning algorithm. The shortest path in the attack path graph is obtained using the Q-learning algorithm to obtain possible attack paths.

[0229] To accurately obtain the shortest path in the attack path graph, in some implementations, the Q-learning algorithm used to obtain the shortest path in the attack path graph may include steps A8 to E9:

[0230] Step A9: The software uses the preset attack starting node in the attack path diagram as the current node.

[0231] In its implementation, the software uses the preset attack starting node as the current node in the first iteration.

[0232] Step B9: Based on the current node, the software determines the target node according to the current Q value.

[0233] In the actual implementation, for the current node, the software looks up the corresponding maximum Q value in the Q table and selects the corresponding target node.

[0234] Step C9: The software updates the Q value based on the threat weight corresponding to the target node.

[0235] In its implementation, the software updates the Q value of the corresponding state in the Q table based on the threat weight of the target node and the Q value of the current node.

[0236] Step D9: The software records the path from the current node to the target node and updates the target node to the current node.

[0237] In its implementation, the software updates the current node to the target node and records the path from the current node to the target node.

[0238] Step E9: The software determines whether the current node is the preset attack endpoint node. If not, it redetermines the target node and the current node based on the Q value and records the corresponding path until the current node is the preset attack endpoint node. The path is then used as the shortest path in the attack path graph.

[0239] In the actual implementation, if the current node is not the preset attack endpoint node, the software returns to step B9, selects the next target node based on the Q value of the current node, and jumps to steps C9 and D9. This continues until the current node becomes the preset attack endpoint node, at which point the software outputs the marked path as the shortest path.

[0240] In summary, the software needs to define the structure of the Q-table and initialize the Q-values. The Q-table is a two-dimensional array, where the first dimension represents network nodes and the second dimension represents target nodes. Each Q-value represents the expected reward of the optimal path from the current node to the target node. The initialization of Q-values ​​can be done according to the actual situation, such as using random values ​​or setting fixed initial values. In each iteration, the software needs to calculate the shortest path and the corresponding Q-value based on the current node and the target node, and update the Q-value of the corresponding state in the Q-table according to the Q-learning algorithm. Finally, the software outputs the shortest path as the result in the attack path graph.

[0241] The method described in this application uses the preset attack starting node in the attack path graph as the current node. Based on the current node, the target node is determined according to the current Q value. Then, the Q value is updated according to the threat weight corresponding to the target node. Through iteration, the shortest path in the attack path graph is accurately obtained.

[0242] In one embodiment of this application, based on the obtained domain name information, a network space mapping platform is connected to obtain IP addresses and other digital asset information associated with the domain name on the Internet. Distributed port scanning technology and intelligent crawling technology are used to discover more detailed information such as ports and services of IT assets existing on the internal and external networks using the IP address data obtained by the asset mapping engine or the internal network IP address data provided by the user.

[0243] Based on the acquired digital asset data, and using technologies such as product fingerprint information query, vulnerability scanning, weak password brute-force attack, comparison with security baselines established by customers, external vulnerability intelligence, and threat intelligence correlation analysis, potential threats on the exposure surface are discovered.

[0244] Based on automated vulnerability testing processes, vulnerability detection and exploitability verification are performed on the discovered threat exposure surfaces, and asset threat details are generated.

[0245] Using IP address data as input, and based on the A3C algorithm and automated penetration testing techniques, this system automatically performs penetration tests on assets. The process includes two main steps: training mode execution and test mode execution. In the training mode execution phase, the system primarily identifies port services and product information, generating potential vulnerability exploit information Exp1. Then, the host, port, product, and Exp1 are used as input to the A3C penetration testing model for training. During a set number of training iterations, based on the number of successful exploit executions in each Exp1, a ranking model M1 is established to rank the probability of successful execution for each exploit in Exp1. In the Exp1 generation business logic, optimizing the product-related vulnerability exploit discovery business process P3 significantly improves the accuracy of Exp1 information. In the vulnerability exploit success / failure judgment business logic, optimizing the vulnerability identification session detection business process P4 and the vulnerability exploit session authenticity judgment business process P5 effectively improves the accuracy of vulnerability exploit success. In A3C model training, mismatches are eliminated by matching the target operating system and service product information to the potential exploit set of the A3C model input parameters. This significantly reduces the size of the exploit set, thereby significantly reducing the computational load of A3C model training. In the testing phase, the main tasks are to load model M1, generate an exploit availability ranking for exploits in Exp1, execute reverse shell tests based on the order, and perform lateral penetration tests by downloading a proxy to the target.

[0246] For example, a manual process retrieves a list of hosts to be tested from the Continuous Threat Exposure Surface Management Center platform and saves it as a comma-separated text file containing IP addresses. Then, the targets are identified by port, service, and version to obtain their port, service, and version information.

[0247] Then, the penetration testing engine module retrieves potential vulnerability exploitation information for the service, including the PoC script name, PoC parameters, vulnerability description, vulnerability solution, and other exploitation information, along with port and service information. It determines if the port is a web service; if so, it starts a crawler to obtain the web service's service and version number information. The intelligent vulnerability verification model is initialized, and the model's operating mode is determined. The model training mode is used to build an A3C vulnerability exploitability probability ranking model; the model testing mode uses the vulnerability exploitability probability ranking model obtained during model training to rank exploitable vulnerabilities in the target based on their probability of exploitation, from highest to lowest, for deep penetration testing attacks. The automated penetration testing process first trains the model, then loads the trained model and executes model testing.

[0248] In training mode, A3C model training is performed. The host, port, product name, and exploit name (extracted from Exp1) are used as input to the A3C model. An exploit evaluation score is assigned based on success or failure: 1 point for successful exploit execution and -1 point for failure. After all input data has been processed, one model training cycle is complete. Training ends after 1000 cycles. In testing mode, the attack model is initialized, the probability of successful exploit execution for each port, service, and exploit is calculated, and exploits are sorted by probability. Automatic threat exposure surface verification is performed based on probability. After all verifications are completed, a threat verification report is generated for successfully executed threats.

[0249] An excessive number of product-irrelevant exploits in the potential exploit list can severely impact model execution efficiency, leading to prolonged A3C model training and vulnerability identification times. Conversely, missing product-related exploits can result in false negatives. The P3 process improves exploit efficiency and reduces false positives by optimizing port matching logic and heuristic exploit knowledge base search logic. This is achieved by comprehensively extracting service- and product-related exploits and eliminating obviously product-irrelevant ones. Specifically, this involves scanning target ports to obtain port product and version information, and then performing a heuristic search based on this information to retrieve exploit information. For example, for the scanned product information ApacheHTTPD, the information is first segmented into individual words, and then words other than service process names are selected as search terms.

[0250] Within the local exploit file, a heuristic search is performed using ports to obtain exploit information. This exploit information is then combined to generate potential exploit information for host IP addresses and ports. Next, the session list is retrieved, and each session is matched against its payload, port, exploit, and host IP address. If a matching session is found, the session's JSON data is returned; otherwise, an empty object is returned.

[0251] refer to Figure 3 Through a maximum risk assessment process on the exposure surface, the system generates the maximum risk attack path and visualizes the attack path results. It also provides a centralized display of vulnerabilities within the maximum risk attack path. The core principle of the maximum risk attack path assessment is to assign specific weights to threat nodes (primarily focusing on vulnerabilities). Threat node weight = 100 / (asset importance * vulnerability score). The more important the asset, the higher the vulnerability score, and the lower the threat node weight. All threat nodes and internal network host nodes n form a weighted directed graph. The maximum risk attack path assessment is transformed into a shortest path planning problem for this weighted directed graph, which is essentially solving for the minimum weighted path.

[0252] Specifically, from the target network, select all network node IPs that are connected to the source IP (the initial target IP on the attack path, generally the attacker's initial target IP) and the destination IP (the ending target IP on the attack path, generally the core business asset IP) to form Tar1 data. For the IPs in Tar1, query the automatically verified vulnerability information V1 from T1. For IPs not in T1, manually execute vulnerability detection tasks, and manually review the vulnerability detection response to confirm the authenticity and exploitability of the vulnerability. For confirmed vulnerabilities, form vulnerability information V2. Based on the V1 and V2 information and the corresponding IP address information, form exploitable vulnerability information Vuln. Vuln includes: vulnerability number, vulnerability name, severity level, vulnerability score, and host. Query the asset database using the IP addresses in Tar1 to obtain the asset importance level and IP connectivity information. Calculate the threat node weight using the asset importance level and the vulnerability score in Vuln according to the formula. Using IP connectivity and the Vuln information obtained in step 2, a directed graph from the threat node to the internal network host node n is constructed, forming the directed attack path graph G. The directed attack path graph G is a matrix file that records the weights and connectivity of threat nodes.

[0253] Using the directed graph G of attack paths as input, reinforcement learning Q-Learning is used to identify the shortest path, ultimately yielding a shortest directed path. This identified shortest path is the maximum risk attack path MaxG.

[0254] Based on the results of continuous asset exposure identification, threat exposure verification, and priority assessment, statistical analysis of all asset threat exposures is generated. Newly added threat exposures, the current maximum risk attack paths, and asset threat exposure statistics are displayed in real time on a large screen, with email alerts sent for newly added threat exposures and the maximum risk attack paths.

[0255] Based on the network threat determination method provided in the above embodiments, this application also provides specific implementations of the network threat determination device. Please refer to the following embodiments.

[0256] First see Figure 4 The network threat determination device 400 provided in this application embodiment includes the following modules:

[0257] The acquisition module 401 is used to acquire Internet Protocol address information associated with the target domain name information.

[0258] The exploration module 402 is used to explore network assets based on the above Internet Protocol address information and obtain the digital asset information corresponding to the above Internet Protocol address information.

[0259] The assessment module 403 is used to conduct a network risk assessment on the aforementioned digital asset information based on a preset vulnerability database to obtain potential risk information.

[0260] Verification module 404 is used to verify the availability of the aforementioned potential risk information.

[0261] The determination module 405 is used to identify potential risk information that is exploitable based on the exploitability verification results, as threat information.

[0262] The method described in this application involves obtaining Internet Protocol (IP) address information associated with the target domain name, then probing for network assets and corresponding digital asset information. Based on a pre-defined vulnerability database, a network risk assessment is performed on this digital asset information to obtain potential risk information. Subsequently, a pre-defined verification process script verifies the exploitability of this potential risk information to confirm the threat information. This approach enables comprehensive network exposure surface identification and accurate threat identification.

[0263] As one implementation of this application, the network threat determination device 400 may further include:

[0264] The acquisition module is used to acquire the Internet Protocol address information corresponding to the aforementioned potential risk information.

[0265] The scanning module is used to perform vulnerability scanning based on the aforementioned Internet Protocol address information to obtain vulnerability information.

[0266] The scanning module is used to input the relevant data of each vulnerability in the above vulnerability information into a preset vulnerability verification model to obtain the probability of successful exploitation of each of the above vulnerabilities.

[0267] The sorting module is used to sort the above vulnerabilities according to the probability of successful exploitation of each vulnerability.

[0268] The verification module is used to test each of the above-mentioned vulnerabilities in the order listed above, based on the preset verification process scripts corresponding to each of the above-mentioned vulnerabilities, in order to verify the exploitability of each of the above-mentioned vulnerabilities.

[0269] The method described in this application involves performing vulnerability scanning based on the aforementioned Internet Protocol (IP) address information to obtain vulnerability information and the probability of successful exploitation for each vulnerability. Then, the vulnerabilities are sorted according to their probability of successful exploitation, and tested sequentially to verify their exploitability. This sorting process before verifying exploitability improves the efficiency of the verification process.

[0270] As one implementation of this application, the network threat determination device 400 may further include:

[0271] The acquisition module is used to acquire the device information corresponding to the Internet Protocol address information mentioned above, including network port and / or software version information.

[0272] The query module is used to query potential vulnerability information corresponding to the above device information.

[0273] The acquisition module is also used to obtain detailed information about the network services mentioned above by crawling, if the network services are present in the potential vulnerability information.

[0274] The merging module is used to merge the aforementioned device information, potential vulnerability information, and detailed information of the aforementioned network services to obtain vulnerability information.

[0275] The method described in this application obtains device information corresponding to Internet Protocol (IP) address information, then queries for potential vulnerability information corresponding to that device information. If network services are present in the vulnerability information, detailed information about those network services is obtained through web scraping. Finally, the device information, potential vulnerability information, and detailed information about the network services are combined to obtain the vulnerability information. By collecting device information, potential vulnerability information, and detailed information about network services, comprehensive vulnerability information can be obtained.

[0276] As one implementation of this application, the network threat determination device 400 may further include:

[0277] The scanning module is used to scan the target device based on the above device information to obtain the corresponding detailed software information.

[0278] The search module is used to perform heuristic searches in the vulnerability database based on the above software details to obtain corresponding potential vulnerability information.

[0279] The method described in this application scans the target device based on device information to obtain detailed software information, and then performs a heuristic search in a vulnerability database to obtain corresponding potential vulnerability information. By excluding vulnerability exploitation information that is clearly irrelevant to the product, noise in vulnerability exploitation information is reduced, improving the accuracy of vulnerability identification, thereby saving time and resources in the automated vulnerability verification process.

[0280] As one implementation of this application, the network threat determination device 400 may further include:

[0281] The acquisition module is used to obtain the current session list from the preset vulnerability monitoring tool.

[0282] The matching module is used to match each session in the current session list with preset threat characteristics.

[0283] The determination module is used to identify network threat information by taking the detailed information of sessions that match the preset threat characteristics from the current session list.

[0284] The method described in this application obtains a list of current sessions from a preset vulnerability monitoring tool, matches each session in the current session list with preset threat characteristics, and uses the detailed information of sessions in the session list that match the preset threat characteristics as network threat information. This can improve the ability to detect sessions that have already been exploited, reduce false negatives, and improve overall security protection capabilities.

[0285] As one implementation of this application, the network threat determination device 400 may further include:

[0286] The extraction module is used to extract the unique session identifier of each session in the current session list.

[0287] The sending module is used to send a verification command to the corresponding session based on the unique session identifier mentioned above.

[0288] The receiving module is used to receive the return information corresponding to the above verification command.

[0289] The marking module is used to mark the corresponding session as a real session if the returned information is not empty and does not contain command execution failure information.

[0290] The tagging module is also used to match each session marked as a real session in the current session list with preset threat characteristics.

[0291] The method described in this application extracts the unique session identifier of each session in the current session list, sends a verification command to the corresponding session, and then receives the return information corresponding to the verification command. If the return information is not empty and does not contain command execution failure information, the corresponding session is marked as a real session. Then, each session marked as a real session in the current session list is matched against preset threat characteristics. This ensures that the identified sessions are real and valid, accurately identifies and responds to real security events, optimizes resource allocation, and improves the speed and effectiveness of response to potential threats.

[0292] As one implementation of this application, the network threat determination device 400 may further include:

[0293] The scanning module is used to perform port scanning based on the aforementioned Internet Protocol address information to obtain the target port.

[0294] The crawling module is used to crawl the Uniform Resource Locator and network service information corresponding to the target ports mentioned above.

[0295] The integration module is used to integrate the aforementioned target domain name information, Internet Protocol address information, Uniform Resource Locator (URL), and network service information into a network asset set.

[0296] The acquisition module is used to obtain the corresponding application programming interface information based on the Internet Protocol address information mentioned above. The application programming interface information includes the interface name, interface address, or request method.

[0297] The integration module is used to integrate the obtained application programming interface (API) information into an API asset set.

[0298] The merging module is used to merge the aforementioned network asset set and the aforementioned application programming interface asset set to obtain digital asset information.

[0299] The method described in this application involves port scanning to obtain target ports, then using a web crawler to extract the corresponding Uniform Resource Locator (URI) and network service information. The target domain name information, Internet Protocol (IP) address information, URI, and network service information are then integrated into a network asset set. Next, the obtained Application Programming Interface (API) information is integrated into an API asset set. Finally, the network asset set and the API asset set are merged to obtain digital asset information. By merging these two sets, complete digital asset information can be obtained.

[0300] As one implementation of this application, the network threat determination device 400 may further include:

[0301] The analysis module is used to perform security vulnerability analysis on the above-mentioned set of network assets based on a preset vulnerability database, and obtain network security risk information.

[0302] The comparison module is used to compare the above-mentioned set of application programming interface assets with the data in the preset application programming interface baseline library.

[0303] The determination module is used to obtain application programming interface (API) security risk information based on data in the aforementioned API asset set that differs from the preset API baseline library.

[0304] The merging module is used to merge the aforementioned network security risk information and the aforementioned application programming interface security risk information to obtain potential risk information.

[0305] The method described in this application analyzes the security risks of the aforementioned network asset set based on a preset vulnerability database to obtain network security risk information. Then, it compares the aforementioned application programming interface (API) asset set with a preset API baseline database. Based on data in the API asset set that differs from the preset API baseline database, it obtains API security risk information. Finally, it merges the network security risk information and the API security risk information to obtain potential risk information. Based on the network security risk information and the API security risk information, it accurately obtains potential risk information.

[0306] As one implementation of this application, the network threat determination device 400 may further include:

[0307] The acquisition module is used to acquire vulnerability intelligence from a preset vulnerability database. The vulnerability intelligence refers to information about network assets that have already suffered network security risks.

[0308] The matching module is used to match the aforementioned compromised intelligence with the aforementioned Internet Protocol address information and the aforementioned Uniform Resource Locator in the aforementioned set of network assets to obtain the asset compromise risk.

[0309] The search module is used to perform sensitive data searches on a preset network platform based on target domain name information in the aforementioned network asset set, in order to determine the risk of data leakage.

[0310] The scanning module is used to perform vulnerability scanning on the corresponding ports based on the Internet Protocol address information and the Uniform Resource Locator (URL) in the aforementioned network asset set, thereby identifying security configuration risks.

[0311] The comparison module is used to compare the network service information in the above-mentioned network asset set with the preset security baseline library to identify unnecessary open ports and / or services, and to identify asset exposure risks.

[0312] The merging module is used to merge the aforementioned risks of asset loss, data leakage, security configuration, and asset exposure to obtain cybersecurity risk information.

[0313] The method described in this application involves obtaining vulnerability intelligence from a pre-defined vulnerability database, matching this vulnerability intelligence with the Internet Protocol address information and Uniform Resource Locators (URLs) in the network asset set to identify asset vulnerability risks. Then, on a pre-defined network platform, sensitive data is searched based on target domain name information in the network asset set to determine data leakage risks. Based on the Internet Protocol address information and URLs in the network asset set, vulnerability scanning is performed on corresponding ports to identify security configuration risks. The network service information in the network asset set is compared with a pre-defined security baseline database to identify unnecessary open ports and / or services, which are then considered as asset exposure risks. Finally, the asset vulnerability risks, data leakage risks, security configuration risks, and asset exposure risks are combined to obtain network security risk information. This method can accurately obtain network security risk information.

[0314] As one implementation of this application, the network threat determination device 400 may further include:

[0315] The acquisition module is used to extract network nodes connected to the preset attack start node and preset attack end node from the above Internet Protocol address information to obtain attack-related node information.

[0316] The determination module is used to find vulnerability information related to each network node in the above network threat information and attack-related node information, and to obtain the vulnerability weight of each network node in the above attack-related node information.

[0317] The determination module is also used to find asset information related to each network node in the above-mentioned digital asset information and attack-related node information, and to obtain the asset weight of each network node in the above-mentioned attack-related node information.

[0318] The determination module is also used to obtain the threat weight of each network node in the attack-related node information based on the aforementioned vulnerability weight and asset weight.

[0319] The connectivity module is used to form an attack path graph based on the connectivity between the network nodes and the threat weights corresponding to the network nodes. The attack path graph represents the possible paths from the preset attack start node to the preset attack end node.

[0320] The determination module is also used to obtain the shortest path in the attack path graph mentioned above through the Q-learning algorithm.

[0321] The method described in this application extracts network nodes connected to preset attack start and end nodes from the Internet Protocol address information to obtain attack-related node information. Then, it searches for vulnerability information related to each network node in the attack-related node information from the network threat information to obtain the vulnerability weight of each network node in the attack-related node information. Based on the vulnerability weight and asset weight, the threat weight of each network node in the attack-related node information is obtained. An attack path graph is formed according to the connectivity between the network nodes and the corresponding threat weights. Based on the attack path graph, the shortest path in the attack path graph is obtained using the Q-learning algorithm. The shortest path in the attack path graph is obtained using the Q-learning algorithm to obtain possible attack paths.

[0322] As one implementation of this application, the network threat determination device 400 may further include:

[0323] The determination module is used to take the aforementioned preset attack starting node in the attack path graph as the current node.

[0324] The determination module is also used to determine the target node based on the current Q value of the current node.

[0325] The update module is used to update the Q value based on the threat weight corresponding to the target node.

[0326] The update module is also used to record the path from the current node to the target node and update the target node to the current node.

[0327] The judgment module is used to determine whether the current node is the preset attack endpoint node. If not, the target node and the current node are re-determined based on the Q value, and the corresponding path is recorded until the current node is the preset attack endpoint node. The path is then used as the shortest path in the attack path graph.

[0328] The method described in this application uses the preset attack starting node in the attack path graph as the current node. Based on the current node, the target node is determined according to the current Q value. Then, the Q value is updated according to the threat weight corresponding to the target node. Through iteration, the shortest path in the attack path graph is accurately obtained.

[0329] Each module in the network threat determination device provided in this application embodiment can implement each step in the above-described network threat determination method and achieve the corresponding effect. For the sake of brevity, it will not be described in detail here.

[0330] Figure 5 A schematic diagram of the network threat determination hardware provided in an embodiment of this application is shown.

[0331] The network threat identification device may include a processor 501 and a memory 502 storing computer program instructions.

[0332] Specifically, the processor 501 may include a central processing unit (CPU), an application-specific integrated circuit (ASIC), or one or more integrated circuits that can be configured to implement the embodiments of this application.

[0333] Memory 502 may include mass storage for data or instructions. For example, and not limitingly, memory 502 may include a hard disk drive (HDD), floppy disk drive, flash memory, optical disk, magneto-optical disk, magnetic tape, or Universal Serial Bus (USB) drive, or a combination of two or more of these. Where appropriate, memory 502 may include removable or non-removable (or fixed) media. Where appropriate, memory 502 may be internal or external to the integrated gateway disaster recovery device. In a particular embodiment, memory 502 is non-volatile solid-state memory.

[0334] Memory may include read-only memory (ROM), random access memory (RAM), disk storage media devices, optical storage media devices, flash memory devices, and electrical, optical, or other physical / tangible memory storage devices. Therefore, typically, memory includes one or more tangible (non-transitory) computer-readable storage media (e.g., memory devices) encoded with software including computer-executable instructions, and when the software is executed (e.g., by one or more processors), it is operable to perform the operations described with reference to the network threat determination method according to any embodiment of this disclosure.

[0335] The processor 501 implements any of the network threat determination methods described in the above embodiments by reading and executing computer program instructions stored in the memory 502.

[0336] In one example, the network threat determination device may also include a communication interface 503 and a bus 510. For example, Figure 5 As shown, the processor 501, memory 502, and communication interface 503 are connected through bus 510 and complete communication with each other.

[0337] The communication interface 503 is mainly used to realize communication between various modules, devices, units and / or equipment in the embodiments of this application.

[0338] Bus 510 includes hardware, software, or both, that couples components of an online data traffic metering device together. For example, and not limitingly, the bus may include an Accelerated Graphics Port (AGP) or other graphics bus, an Enhanced Industry Standard Architecture (EISA) bus, a Front Side Bus (FSB), HyperTransport (HT) interconnect, an Industry Standard Architecture (ISA) bus, an Infinite Bandwidth Interconnect, a Low Pin Count (LPC) bus, a memory bus, a Microchannel Architecture (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (PCI-X) bus, a Serial Advanced Technology Attachment (SATA) bus, a Video Electronics Standards Association Local (VLB) bus, or other suitable buses, or combinations of two or more of these. Where appropriate, bus 510 may include one or more buses. Although specific buses are described and illustrated in embodiments of this application, any suitable bus or interconnect is contemplated herein.

[0339] Furthermore, in conjunction with the network threat determination methods described in the above embodiments, this application embodiment can provide a computer storage medium for implementation. The computer storage medium stores computer program instructions; when these computer program instructions are executed by a processor, they implement any of the network threat determination methods described in the above embodiments.

[0340] This application also provides a computer program product, including a computer program, which, when executed, implements any of the network threat determination methods described in the above embodiments.

[0341] It should be clarified that this application is not limited to the specific configurations and processes described above and shown in the figures. For the sake of brevity, detailed descriptions of known methods are omitted here. In the above embodiments, several specific steps are described and shown as examples. However, the method process of this application is not limited to the specific steps described and shown. Those skilled in the art can make various changes, modifications, and additions, or change the order of steps, after understanding the spirit of this application.

[0342] The functional blocks shown in the above-described structural diagram can be implemented as hardware, software, firmware, or a combination thereof. When implemented in hardware, they can be, for example, electronic circuits, application-specific integrated circuits (ASICs), appropriate firmware, plug-ins, function cards, etc. When implemented in software, the elements of this application are programs or code segments used to perform the required tasks. Programs or code segments can be stored on a machine-readable medium or transmitted over a transmission medium or communication link via data signals carried on a carrier wave. "Machine-readable medium" can include any medium capable of storing or transmitting information. Examples of machine-readable media include electronic circuits, semiconductor memory devices, ROM, flash memory, erasable ROM (EROM), floppy disks, CD-ROMs, optical disks, hard disks, fiber optic media, radio frequency (RF) links, etc. Code segments can be downloaded via computer networks such as the Internet, intranets, etc.

[0343] It should also be noted that the exemplary embodiments mentioned in this application describe methods or systems based on a series of steps or apparatus. However, this application is not limited to the order of the above steps; that is, the steps can be performed in the order mentioned in the embodiments, or in a different order, or several steps can be performed simultaneously.

[0344] The aspects of this disclosure have been described above with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this disclosure. It should be understood that each block in the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce a machine such that these instructions, executable via the processor of the computer or other programmable data processing apparatus, enable the implementation of the functions / actions specified in one or more blocks of the flowchart illustrations and / or block diagrams. Such a processor can be, but is not limited to, a general-purpose processor, a special-purpose processor, a special application processor, or a field-programmable logic circuit. It is also understood that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can also be implemented by special-purpose hardware performing the specified functions or actions, or can be implemented by a combination of special-purpose hardware and computer instructions.

[0345] The above description is merely a specific implementation of this application. Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, modules, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here. It should be understood that the protection scope of this application is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in this application, and these modifications or substitutions should all be covered within the protection scope of this application.

Claims

1. A network threat determination method, characterized by, The method comprises: obtaining internet protocol address information associated with target domain name information; performing network asset exploration on the internet protocol address information to obtain digital asset information corresponding to the internet protocol address information; performing network risk assessment on the digital asset information to obtain potential risk information; verifying the potential risk information for exploitability; potential risk information with a result of exploitability verification is taken as threat information; The exploitability verification of the potential risk information comprises: obtaining internet protocol address information corresponding to the potential risk information; performing vulnerability scanning according to the internet protocol address information to obtain vulnerability information; inputting the related data of each vulnerability in the vulnerability information into a preset vulnerability verification model to obtain the exploit success probability of each vulnerability; sorting each vulnerability according to the exploit success probability of each vulnerability; testing each vulnerability based on the order of the sorting through a preset verification process script corresponding to each vulnerability to verify the exploitability of each vulnerability; After the potential risk information with a result of exploitability verification is taken as threat information, the method further comprises: obtaining a current session list from a preset vulnerability monitoring tool; matching each session in the current session list with a preset threat feature; taking the detailed information of the session in the current session list that matches the preset threat feature as network threat information; After the current session list is obtained from the preset vulnerability monitoring tool, the method further comprises: extracting the unique session identifier of each session in the current session list; sending a verification command to the corresponding session according to the unique session identifier; receiving return information corresponding to the verification command; in the case that the return information is not empty and does not contain command execution failure information, marking the corresponding session as a real session; The matching of each session in the current session list with a preset threat feature comprises: matching each session in the current session list that is marked as a real session with a preset threat feature; The network asset exploration on the internet protocol address information to obtain digital asset information corresponding to the internet protocol address information comprises: performing port scanning based on the internet protocol address information to obtain target ports; scraping uniform resource locators and network service information corresponding to the target ports through a crawler; integrating the target domain name information, the internet protocol address information, the uniform resource locators and the network service information into a network asset set; obtaining corresponding application programming interface information based on the internet protocol address information, the application programming interface information including interface name, interface address or request method; integrating the obtained application programming interface information into an application programming interface asset set; merging the network asset set and the application programming interface asset set to obtain digital asset information; The network risk assessment on the digital asset information to obtain potential risk information comprises: Based on the preset vulnerability library, the network asset set is analyzed for security risks to obtain network security risk information; The application programming interface asset set is compared with data in a preset application programming interface baseline library; According to the data in the application programming interface asset set that is different from the preset application programming interface baseline library, application programming interface security risk information is obtained; The network security risk information and the application programming interface security risk information are merged to obtain potential risk information.

2. The network threat determination method of claim 1, wherein, The vulnerability scanning according to the Internet protocol address information to obtain vulnerability information includes: Obtaining device information corresponding to the Internet protocol address information, the device information including network port and / or software version information; Querying potential vulnerability information corresponding to the device information; In the case that there is a network service vulnerability in the potential vulnerability information, the detailed information of the network service vulnerability is obtained through crawling; Merging the device information, the potential vulnerability information, and the detailed information of the network service vulnerability to obtain vulnerability information.

3. The network threat determination method of claim 2, wherein, The querying of the potential vulnerability information corresponding to the device information includes: Scanning a target device according to the device information to obtain corresponding software detailed information; According to the software detailed information, performing heuristic search in a vulnerability database to obtain corresponding potential vulnerability information.

4. The network threat determination method of claim 1, wherein, The security risk analysis of the network asset set based on the preset vulnerability library to obtain network security risk information includes: Obtaining compromised intelligence in the preset vulnerability library, the compromised intelligence being network asset information that has suffered network security risks; Matching the compromised intelligence with the Internet protocol address information and the uniform resource locator in the network asset set to obtain asset compromise risk; Based on target domain name information in the network asset set, searching for sensitive data on a preset network platform to determine data leakage risk; Based on the Internet protocol address information and the uniform resource locator in the network asset set, performing vulnerability scanning on corresponding ports to obtain security configuration risk; Comparing the network service information in the network asset set with a preset security baseline library to determine unnecessary open ports and / or services, and taking them as asset exposure risk; Merging the asset compromise risk, the data leakage risk, the security configuration risk, and the asset exposure risk to obtain network security risk information.

5. The method of any of claims 1 to 4, wherein, After the exploitability verification result of the potential risk information is available as threat information, the method further includes: Extracting network nodes in the Internet protocol address information that are connected with a preset attack starting node and a preset attack ending node to obtain attack-related node information; Finding vulnerability information related to each network node in the attack-related node information in the network threat information to obtain a vulnerability weight of each network node in the attack-related node information; Finding asset information related to each network node in the attack-related node information in the digital asset information to obtain an asset weight of each network node in the attack-related node information; Obtain threat weights of each network node in the attack-related node information based on the vulnerability weights and the asset weights; Form an attack path graph based on the connectivity between the network nodes and the threat weights corresponding to the network nodes, the attack path graph representing possible paths from the preset attack starting node to the preset attack ending node; Obtain the shortest path in the attack path graph through a Q-learning algorithm.

6. The network threat determination method of claim 5, wherein, The obtaining of the shortest path in the attack path graph through the Q-learning algorithm comprises Taking the preset attack starting node in the attack path graph as a current node; Determining a target node based on a current Q value of the current node; Updating the Q value based on a threat weight corresponding to the target node; Recording a path from the current node to the target node, and updating the target node as the current node; Determining whether the current node is the preset attack ending node, and if not, re-determining the target node and the current node based on the Q value and recording a corresponding path, until the current node is the preset attack ending node, and taking the path as the shortest path in the attack path graph.

7. A network threat determination apparatus, characterized by, The device comprises: An acquisition module configured to acquire Internet protocol address information associated with target domain name information; An exploration module configured to perform network asset exploration on the Internet protocol address information to obtain digital asset information corresponding to the Internet protocol address information; An evaluation module configured to perform network risk evaluation on the digital asset information to obtain potential risk information; A verification module configured to verify the potential risk information for availability; A determination module configured to take potential risk information that is verified as available as threat information; The acquisition module is further configured to acquire Internet protocol address information corresponding to the potential risk information; A scanning module configured to perform vulnerability scanning based on the Internet protocol address information to obtain vulnerability information; The scanning module is further configured to input related data of each vulnerability in the vulnerability information into a preset vulnerability verification model to obtain a probability of successful exploitation of each vulnerability; An ordering module configured to order each vulnerability according to the probability of successful exploitation of each vulnerability; The verification module is further configured to test each vulnerability based on the order to verify the availability of each vulnerability through a preset verification process script corresponding to each vulnerability; The acquisition module is further configured to acquire a current session list from a preset vulnerability monitoring tool; A matching module configured to match each session in the current session list with a preset threat feature; The determination module is further configured to take detailed information of a session that matches the preset threat feature in the current session list as network threat information; An extraction module configured to extract a unique session identifier of each session in the current session list; A sending module configured to send a verification command to a corresponding session according to the unique session identifier; A receiving module configured to receive return information corresponding to the verification command. The marking module is configured to mark the corresponding session as a real session when the return information is not empty and does not contain command execution failure information. The marking module is further configured to match each session in the current session list that is marked as a real session with a preset threat feature. The scanning module is further configured to perform port scanning based on the Internet protocol address information to obtain a target port. The crawling module is configured to crawl a uniform resource locator and network service information corresponding to the target port by using a crawler. The integration module is configured to integrate the target domain name information, the Internet protocol address information, the uniform resource locator and the network service information into a network asset set. The obtaining module is further configured to obtain application programming interface information based on the Internet protocol address information, the application programming interface information including an interface name, an interface address or a request method. The integration module is further configured to integrate the obtained application programming interface information into an application programming interface asset set. The merging module is configured to merge the network asset set and the application programming interface asset set to obtain digital asset information. The analysis module is configured to perform security risk analysis on the network asset set based on a preset vulnerability library to obtain network security risk information. The comparison module is configured to compare the application programming interface asset set with data in a preset application programming interface baseline library. The determination module is further configured to obtain application programming interface security risk information according to data in the application programming interface asset set that is different from the preset application programming interface baseline library. The merging module is further configured to merge the network security risk information and the application programming interface security risk information to obtain potential risk information.

8. A network threat determination device, comprising: The device comprises a processor and a memory storing computer program instructions; the processor reads and executes the computer program instructions to implement the network threat determination method of any one of claims 1-6.

9. A computer-readable storage medium, characterized in that, The computer readable storage medium stores computer program instructions, and the computer program instructions are executed by the processor to implement the network threat determination method of any one of claims 1-6.

10. A computer program product, characterised in that, The instructions in the computer program product are executed by the processor of the electronic device, so that the electronic device performs the network threat determination method of any one of claims 1-6.

Citation Information

Patent Citations

  • Automatic penetration test system and method based on artificial intelligence

    CN110968873A

  • Fingerprint-based asset discovery, identification and detection method and system

    CN112468360A

  • Exposed surface asset risk assessment method, device, equipment and medium

    CN113468542A

  • Dynamic attack path generation method based on reinforcement learning

    CN116743468A