Method and apparatus for determining network resource exposure surface

By determining the asset attributes and policy rules of the target assets, quantifying the exposure of network resources, solving the problem of inaccurate management of network resources in the existing technology, and achieving an effective assessment of network security risks.

CN119496662BActive Publication Date: 2025-07-11BEIJING QIANGWEI SMART TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411708964.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-26
Publication Date
2025-07-11
Estimated Expiration
2044-11-26

AI Technical Summary

Technical Problem

The existing technology is difficult to effectively manage and quantify the exposure of network resources, resulting in inaccurate assessment of network security risks.

Method used

By determining the asset attributes of the target asset, determining the collection of network visitors based on the asset attributes and policy rules, the exposure of the target asset in the target network area is quantified.

Benefits of technology

The quantification of network resource exposure has been achieved, which facilitates subsequent network management and security risk assessment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119496662B_ABST
    Figure CN119496662B_ABST
Patent Text Reader

Abstract

The embodiments of this specification provide a method and apparatus for determining the exposed surface of network resources. The method for determining the exposed surface of network resources includes: determining a target asset and obtaining the asset attributes of the target asset; determining a set of network visitors based on the asset attributes and policy rules; and determining the exposed surface of the target asset in the target network area based on the set of network visitors. By determining the target asset, obtaining the asset attributes of the target asset, determining the set of network visitors based on the asset attributes and policy rules, and determining the exposed surface of the target asset in the target network area, the quantification of the exposed surface can be achieved, which facilitates subsequent network management.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of this specification relate to the field of network security technology, and particularly to a method for determining the exposed surface of network resources. Background Art

[0002] With the rapid development of information technology, network security issues have become increasingly prominent, posing a major challenge that enterprises and organizations urgently need to address. When dealing with increasingly complex network attack threats, it is crucial to deeply understand the core concepts of network security. The exposed surface, attack surface, and vulnerable surface are three key elements for evaluating network security risks.

[0003] The exposed surface refers to the parts in the network that can be accessed externally. These parts are usually resources opened by an organization to the outside, such as public IP addresses, network services, and API interfaces. The exposed surface is the primary target of attackers, and any resource that can be directly accessed through the Internet belongs to this category. The more resources are exposed, the more potential attack opportunities there are. Exposed resources are often the first choice of attackers because they provide direct attack entrances. Therefore, managing the exposed surface is an important part of improving network security. Thus, there is an urgent need for a solution for exposed surface assessment. Summary of the Invention

[0004] In view of this, the embodiments of this specification provide a method for determining the exposed surface of network resources. One or more embodiments of this specification also relate to a device for determining the exposed surface of network resources, a computing device, a computer-readable storage medium, and a computer program to solve the technical defects existing in the prior art.

[0005] According to the first aspect of the embodiments of this specification, a method for determining the exposed surface of network resources is provided, including:

[0006] Determine the target assets and obtain the asset attributes of the target assets;

[0007] Determine the set of network visitors based on the asset attributes and policy rules;

[0008] Determine the exposed surface of the target assets in the target network area based on the set of network visitors.

[0009] In a possible implementation, obtaining the asset attributes of the target assets includes:

[0010] Obtain the workload attributes, role attributes, workgroup attributes, protocol port attributes, and policy status attributes of the target assets.

[0011] In a possible implementation, determining the set of network visitors based on the asset attributes and policy rules includes:

[0012] Determine the target attribute based on the asset attribute, and determine the sub-rule corresponding to the target attribute from the policy rules;

[0013] Determine the visitor set based on the target attribute and the sub-rule.

[0014] In a possible implementation, determining the exposure surface of the target asset in the target network area based on the network visitor set includes:

[0015] Determine the address information of the network visitor set;

[0016] Determine the network area relationship information based on the address information and the address definition table;

[0017] Determine the exposure surface of the target asset in the target network area based on the network area relationship information; where the target network area includes the intranet and the extranet.

[0018] In a possible implementation, determining the network area relationship information based on the address information and the address definition table includes:

[0019] Determine the address definition table; where the address definition table includes the intranet address and the extranet address;

[0020] Match the address information with the address definition table to determine the network area;

[0021] Determine the network area relationship information based on the network area.

[0022] In a possible implementation, determining the exposure surface of the target asset in the target network area based on the network visitor set includes:

[0023] Determine the workgroup attribute of the network visitor set;

[0024] Determine the group area relationship information based on the workgroup attribute;

[0025] Determine the exposure surface of the target asset in the target network area based on the group area relationship information; where the target network area includes between groups and within groups.

[0026] In a possible implementation, determining the group area relationship information based on the workgroup attribute includes:

[0027] Match the workgroup attribute with the workgroup attribute of the target asset to determine the group area;

[0028] Determine the network area relationship information based on the group area.

[0029] According to the second aspect of the embodiments of the present specification, there is provided a network resource exposure surface determination device, including:

[0030] An asset attribute determination module, configured to determine a target asset and obtain the asset attributes of the target asset;

[0031] An access set determination module, configured to determine a network visitor set based on the asset attributes and policy rules;

[0032] An exposure surface determination module, configured to determine the exposure surface of the target asset in the target network area based on the network visitor set.

[0033] According to a third aspect of the embodiments of the present specification, a computing device is provided, including:

[0034] A memory and a processor;

[0035] The memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions. When the computer-executable instructions are executed by the processor, the steps of the above-mentioned network resource exposure surface determination method are implemented.

[0036] According to a fourth aspect of the embodiments of the present specification, a computer-readable storage medium is provided, which stores computer-executable instructions. When the instructions are executed by a processor, the steps of the above-mentioned network resource exposure surface determination method are implemented.

[0037] According to a fifth aspect of the embodiments of the present specification, a computer program is provided. When the computer program is executed on a computer, the computer is made to execute the steps of the above-mentioned network resource exposure surface determination method.

[0038] The embodiments of the present specification provide a network resource exposure surface determination method and device. The network resource exposure surface determination method includes: determining a target asset and obtaining the asset attributes of the target asset; determining a network visitor set based on the asset attributes and policy rules; determining the exposure surface of the target asset in the target network area based on the network visitor set. By determining the target asset, obtaining the asset attributes of the target asset, determining the network visitor set based on the asset attributes and policy rules, and determining the exposure surface of the target asset in the target network area, the quantification of the exposure surface can be achieved, thus facilitating subsequent network management. Description of the Drawings

[0039] Figure 1 is a flowchart of a network resource exposure surface determination method provided by an embodiment of the present specification;

[0040] Figure 2 is a schematic diagram of a network resource exposure surface determination method provided by an embodiment of the present specification;

[0041] Figure 3 is a structural schematic diagram of a network resource exposure surface determination device provided by an embodiment of the present specification;

[0042] Figure 4 It is a structural block diagram of a computing device provided by an embodiment of this specification. Detailed implementation manners

[0043] In the following description, many specific details are set forth in order to provide a thorough understanding of this specification. However, this specification can be implemented in many other ways different from those described herein, and those skilled in the art can make similar generalizations without departing from the connotation of this specification. Therefore, this specification is not limited by the specific implementations disclosed below.

[0044] The terms used in one or more embodiments of this specification are for the purpose of describing specific embodiments only and are not intended to limit one or more embodiments of this specification. The singular forms "a" and "the" used in one or more embodiments of this specification and the appended claims are also intended to include the plural forms unless the context clearly dictates otherwise. It should also be understood that the term "and / or" used in one or more embodiments of this specification refers to and encompasses any or all possible combinations of one or more of the associated listed items.

[0045] It should be understood that although the terms first, second, etc. may be used in one or more embodiments of this specification to describe various information, such information should not be limited to these terms. These terms are only used to distinguish the same type of information from each other. For example, without departing from the scope of one or more embodiments of this specification, the first may also be referred to as the second, and similarly, the second may also be referred to as the first. Depending on the context, the word "if" as used herein may be interpreted as "when" or "while" or "in response to determining".

[0046] In this specification, a method for determining the exposed surface of network resources is provided. This specification also relates to a device for determining the exposed surface of network resources, a computing device, and a computer-readable storage medium, which will be described in detail one by one in the following embodiments.

[0047] See Figure 1 , Figure 1 which shows a flowchart of a method for determining the exposed surface of network resources provided by an embodiment of this specification, specifically including the following steps.

[0048] Step 101: Determine the target asset and obtain the asset attributes of the target asset.

[0049] Among them, the assets can be information technology assets, which are any information or data, software or hardware used by an organization during its business operations. Hardware assets include physical computing devices, such as physical servers in a data center, desktop computers, mobile devices, laptops, keyboards, and printers. On the other hand, software assets include applications that are usually licensed by user or machine, as well as software systems and databases built using open-source resources. Software assets also include cloud-based assets and cloud services, such as software as a service (SaaS) applications.

[0050] In a possible implementation, obtaining the asset attributes of the target asset includes: obtaining the workload attribute, role attribute, workgroup attribute, protocol port attribute, and policy status attribute of the target asset.

[0051] In practical applications, referring to Table 1, the asset attributes can include workload id, protocol port, affiliated workgroup, role, and policy status attribute. Among them, the policy status attribute can include being accessed by the office network address and being accessed by the external address.

[0052] Table 1

[0053]

[0054] There are three assets in the above table, w1, w2, and w3. The ports opened by w1 include tcp / 80 and tcp / 8080, belonging to the workgroup g1, and the role is r1. The ports opened by w2 include tcp / 80, belonging to the workgroup g1, and the role is r2. The ports opened by W3 include tcp / 22, belonging to the workgroup g2, and the role is r3.

[0055] Step 102: Determine the network visitor set based on the asset attributes and policy rules.

[0056] In a possible implementation, determining the network visitor set based on the asset attributes and policy rules includes: determining the target attribute based on the asset attributes, and determining the sub-rule corresponding to the target attribute from the policy rules; determining the visitor set based on the target attribute and the sub-rule.

[0057] In practical applications, referring to Table 2, the policy rules can include the policy rules of the server and the visitor in the dimensions of workgroup, role, address, and port.

[0058] Table 2

[0059]

[0060] For example, the r2 role in the working group g1 can access the tcp / 8080 port of the r1 role in the working group g1. The r3 role in the working group g2 or the network segment located at 123.186.0.0 / 16 can access the tcp / 80 port of the r2 role in the working group g1.

[0061] In the above manner, the set of all network visitors can be determined. For example, for w1, the open ports of w1 include tcp / 80 and tcp / 8080, belonging to the working group g1 with the role of r1. Then the visitor set of w1 includes all assets in the network segment 123.186.0.0 / 16 or the assets corresponding to the r2 role in the working group g1.

[0062] It should be noted that the determination of visitors can be made from the overall dimension of the assets or from other dimensions. For example, see Figure 2 , and the set of visitors to the asset ports can be obtained by matching the port dimension of the assets with the policy rules. The embodiments of this specification do not limit this.

[0063] Step 103: Determine the exposure surface of the target asset in the target network area based on the network visitor set.

[0064] In a possible implementation manner, determining the exposure surface of the target asset in the target network area based on the network visitor set includes: determining the address information of the network visitor set; determining the network area relationship information based on the address information and the address definition table; determining the exposure surface of the target asset in the target network area based on the network area relationship information; where the target network area includes the intranet and the extranet.

[0065] In practical applications, see Figure 2 , if the intranet is the office network, the number of exposure surfaces can be judged by the IP addresses of all visitors in the visitor set.

[0066] Table III

[0067]

[0068] See Table III. Table III is the address definition table, and the intranet network segment is 192.168.0.0 / 16;

[0069] The extranet network segment is 0.0.0.0 / 0,!192.168.0.0 / 16,!10.0.0.0 / 8,!172.16.0.0 / 12; where! represents the logical NOT, that is, excluding the address segments 192.168.0.0 / 16, 10.0.0.0 / 8, and 172.16.0.0 / 12.

[0070] Specifically, determining the network area relationship information based on the address information and the address definition table includes: determining the address definition table; where the address definition table includes the internal network address and the external network address; matching the address information with the address definition table to determine the network area; and determining the network area relationship information based on the network area.

[0071] Continuing with the above example, from the perspective of the IP address, the visitor set of w1 includes all assets in the 123.186.0.0 / 16 network segment. Querying from the "IP address definition table", it can be seen that 123.186.0.0 / 16 belongs to the external address, and the number of its IP addresses is 2 to the power of (32 - 24), that is, 2 to the 16th power: 65536. In the IP address definition table, the upper limit of the number of external addresses is defined as 60000. As shown in Table 4, the value here is 60000, that is, the exposure surface is quantified as 60000.

[0072] For example, from the perspective of the IP address, the visitor set of w3 includes all assets in the 192.168.10.0 / 24 network segment. Querying from the "IP address definition table", it can be seen that 192.168.10.0 / 24 belongs to the office network address, and the number of its IP addresses is 2 to the power of (32 - 24), that is, 2 to the 8th power: 256. Since the number of office network assets in the IP address definition table is 400 and 256 is less than 400, the value here is 256.

[0073] Table 4

[0074]

[0075] In a possible implementation manner, determining the exposure surface of the target asset in the target network area based on the network visitor set includes: determining the workgroup attribute of the network visitor set; determining the group area relationship information based on the workgroup attribute; and determining the exposure surface of the target asset in the target network area based on the group area relationship information; where the target network area includes between groups and within groups.

[0076] In practical applications, referring to Figure 2 , it is also possible to judge the number of exposure surfaces through the workgroups of all visitors in the visitor set.

[0077] Specifically, determining the group area relationship information based on the workgroup attribute includes: matching the workgroup attribute with the workgroup attribute of the target asset to determine the group area; and determining the network area relationship information based on the group area.

[0078] For example, from the perspective of the workgroup, the visitor set of w1 includes the assets corresponding to the r2 role in the workgroup g1, and the assets corresponding to the r2 role in the workgroup g1 are w2, so the in-group exposure surface is 1.

[0079] Further, the set of visitors to w2 includes the assets corresponding to the role r3 in the work group g2, and the exposure surface between groups is 1.

[0080] The embodiments of this specification provide a method and apparatus for determining the exposure surface of network resources. The method for determining the exposure surface of network resources includes: determining a target asset and obtaining the asset attributes of the target asset; determining a set of network visitors based on the asset attributes and policy rules; and determining the exposure surface of the target asset in the target network area based on the set of network visitors. By determining the target asset, obtaining the asset attributes of the target asset, determining the set of network visitors based on the asset attributes and policy rules, and determining the exposure surface of the target asset in the target network area, the quantification of the exposure surface can be achieved, which is convenient for subsequent network management.

[0081] Corresponding to the above method embodiments, this specification also provides embodiments of an apparatus for determining the exposure surface of network resources. Figure 3 The structural schematic diagram of an apparatus for determining the exposure surface of network resources provided by an embodiment of this specification is shown. As Figure 3 shown, the apparatus includes:

[0082] An asset attribute determination module 301, configured to determine a target asset and obtain the asset attributes of the target asset;

[0083] An access set determination module 302, configured to determine a set of network visitors based on the asset attributes and policy rules;

[0084] An exposure surface determination module 303, configured to determine the exposure surface of the target asset in the target network area based on the set of network visitors.

[0085] In a possible implementation, obtaining the asset attributes of the target asset includes:

[0086] Obtaining the workload attributes, role attributes, work group attributes, protocol port attributes, and policy status attributes of the target asset.

[0087] In a possible implementation, determining a set of network visitors based on the asset attributes and policy rules includes:

[0088] Determining target attributes based on the asset attributes, and determining sub-rules corresponding to the target attributes from the policy rules;

[0089] Determining a set of visitors based on the target attributes and sub-rules.

[0090] In a possible implementation, determining the exposure surface of the target asset in the target network area based on the set of network visitors includes:

[0091] Determining the address information of the set of network visitors;

[0092] Determine network area relationship information based on address information and an address definition table;

[0093] Determine the exposure surface of a target asset in a target network area based on the network area relationship information; where the target network area includes an internal network and an external network.

[0094] In a possible implementation, determining network area relationship information based on address information and an address definition table includes:

[0095] Determine the address definition table; where the address definition table includes internal network addresses and external network addresses;

[0096] Match the address information with the address definition table to determine the network area;

[0097] Determine network area relationship information based on the network area.

[0098] In a possible implementation, determining the exposure surface of a target asset in a target network area based on a network visitor set includes:

[0099] Determine the workgroup attribute of the network visitor set;

[0100] Determine group area relationship information based on the workgroup attribute;

[0101] Determine the exposure surface of the target asset in the target network area based on the group area relationship information; where the target network area includes between groups and within groups.

[0102] In a possible implementation, determining group area relationship information based on the workgroup attribute includes:

[0103] Match the workgroup attribute with the workgroup attribute of the target asset to determine the group area;

[0104] Determine network area relationship information based on the group area.

[0105] The embodiments of this specification provide a method and apparatus for determining the exposure surface of network resources. The apparatus for determining the exposure surface of network resources includes: determining a target asset, and obtaining the asset attributes of the target asset; determining a network visitor set based on the asset attributes and policy rules; determining the exposure surface of the target asset in a target network area based on the network visitor set. By determining the target asset, obtaining the asset attributes of the target asset; determining a network visitor set based on the asset attributes and policy rules; determining the exposure surface of the target asset in a target network area based on the network visitor set, the quantification of the exposure surface can be achieved, thereby facilitating subsequent network management.

[0106] The above is a schematic solution of a network resource exposure surface determination device according to this embodiment. It should be noted that the technical solution of this network resource exposure surface determination device and the technical solution of the above network resource exposure surface determination method belong to the same concept. For the details not described in the technical solution of the network resource exposure surface determination device, reference can be made to the description of the technical solution of the above network resource exposure surface determination method.

[0107] Figure 4 The structural block diagram of a computing device 400 provided according to an embodiment of this specification is shown. The components of the computing device 400 include, but are not limited to, a memory 410 and a processor 420. The processor 420 is connected to the memory 410 through a bus 430, and a database 450 is used to store data.

[0108] The computing device 400 further includes an access device 440, which enables the computing device 400 to communicate via one or more networks 460. Examples of these networks include the Public Switched Telephone Network (PSTN), Local Area Network (LAN), Wide Area Network (WAN), Personal Area Network (PAN), or a combination of communication networks such as the Internet. The access device 440 can include one or more of any type of wired or wireless network interfaces (for example, a network interface card (NIC)), such as an IEEE802.11 Wireless Local Area Network (WLAN) wireless interface, a Worldwide Interoperability for Microwave Access (Wi-MAX) interface, an Ethernet interface, a Universal Serial Bus (USB) interface, a cellular network interface, a Bluetooth interface, a Near Field Communication (NFC).

[0109] In an embodiment of this specification, the above components of the computing device 400 and Figure 4 other components not shown in Figure 4 can also be connected to each other, for example, through a bus. It should be understood that

[0110] The computing device 400 can be any type of stationary or mobile computing device, including mobile computers or mobile computing devices (e.g., tablet computers, personal digital assistants, laptop computers, notebook computers, netbooks, etc.), mobile phones (e.g., smartphones), wearable computing devices (e.g., smartwatches, smart glasses, etc.) or other types of mobile devices, or stationary computing devices such as desktop computers or personal computers (PCs). The computing device 400 can also be a mobile or stationary server.

[0111] Among them, the processor 420 is used to execute the following computer-executable instructions, and when the computer-executable instructions are executed by the processor, the steps of the above network resource exposure surface determination method are implemented. The above is a schematic solution of a computing device in this embodiment. It should be noted that the technical solution of this computing device and the technical solution of the above network resource exposure surface determination method belong to the same concept. For the details not described in detail in the technical solution of the computing device, reference can be made to the description of the technical solution of the above network resource exposure surface determination method.

[0112] An embodiment of this specification also provides a computer-readable storage medium, which stores computer-executable instructions, and when the computer-executable instructions are executed by the processor, the steps of the above network resource exposure surface determination method are implemented.

[0113] The above is a schematic solution of a computer-readable storage medium in this embodiment. It should be noted that the technical solution of this storage medium and the technical solution of the above network resource exposure surface determination method belong to the same concept. For the details not described in detail in the technical solution of the storage medium, reference can be made to the description of the technical solution of the above network resource exposure surface determination method.

[0114] An embodiment of this specification also provides a computer program, and when the computer program is executed on a computer, the computer is made to execute the steps of the above network resource exposure surface determination method.

[0115] The above is a schematic solution of a computer program in this embodiment. It should be noted that the technical solution of this computer program and the technical solution of the above network resource exposure surface determination method belong to the same concept. For the details not described in detail in the technical solution of the computer program, reference can be made to the description of the technical solution of the above network resource exposure surface determination method.

[0116] The above describes specific embodiments of this specification. Other embodiments are within the scope of the appended claims. In some cases, the acts or steps recited in the claims may be performed in a different order than in the embodiments and still achieve the desired result. Additionally, the processes depicted in the drawings do not necessarily require the particular order or sequential order shown to achieve the desired result. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0117] The computer instructions include computer program code, which may be in the form of source code, object code, an executable file, or some intermediate form, etc. The computer-readable medium may include: any entity or device capable of carrying the computer program code, a recording medium, a USB flash drive, a removable hard disk, a magnetic disk, an optical disk, a computer memory, a read-only memory (ROM), a random access memory (RAM), an electrical carrier signal, a telecommunication signal, and a software distribution medium, etc. It should be noted that the content included in the computer-readable medium may be appropriately increased or decreased according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, the computer-readable medium does not include electrical carrier signals and telecommunication signals.

[0118] It should be noted that for the foregoing method embodiments, for the sake of simplicity of description, they are all expressed as a series of action combinations. However, those skilled in the art should be aware that the embodiments of this specification are not limited by the described order of actions, because according to the embodiments of this specification, certain steps may be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to the embodiments of this specification.

[0119] In the above embodiments, the descriptions of the various embodiments have their own focuses. For the parts not detailed in a certain embodiment, reference may be made to the relevant descriptions of other embodiments.

[0120] The preferred embodiments of this specification disclosed above are only used to help explain this specification. The alternative embodiments do not exhaust all the details and do not limit the invention to the specific embodiments described. Obviously, many modifications and variations can be made according to the content of the embodiments of this specification. This specification selects and specifically describes these embodiments to better explain the principles and practical applications of the embodiments of this specification, so that those skilled in the art can well understand and utilize this specification. This specification is only limited by the claims and their full scope and equivalents.

Claims

1. A method for determining the exposed surface of network resources, characterized in that, Including: Determine the target asset and obtain the asset attributes of the target asset; Determine the network visitor set based on the asset attributes and policy rules; Determine the exposure surface of the target asset in the target network area based on the network visitor set; wherein, the exposure surface is represented by a numerical value; The obtaining the asset attributes of the target asset includes: Obtain the workload attributes, role attributes, workgroup attributes, protocol port attributes, and policy status attributes of the target asset; The determining the exposure surface of the target asset in the target network area based on the network visitor set includes: Determine the address information of the network visitor set; Determine the network area relationship information based on the address information and the address definition table; Determine the exposure surface of the target asset in the target network area based on the network area relationship information; wherein, the target network area includes the internal network and the external network; The determining the exposure surface of the target asset in the target network area based on the network visitor set includes: Determine the workgroup attributes of the network visitor set; Determine the group area relationship information based on the workgroup attributes; Determine the exposure surface of the target asset in the target network area based on the group area relationship information; wherein, the target network area includes between groups and within groups.

2. The method according to claim 1, characterized in that, The determining the network visitor set based on the asset attributes and policy rules includes: Determine the target attributes based on the asset attributes, and determine the sub-rules corresponding to the target attributes from the policy rules; Determine the visitor set based on the target attributes and the sub-rules.

3. The method according to claim 1, wherein The determining the network area relationship information based on the address information and the address definition table includes: Determine the address definition table; wherein, the address definition table includes internal network addresses and external network addresses; Match the address information and the address definition table to determine the network area; Determine the network area relationship information based on the network area.

4. The method according to claim 1, characterized in that, The determining the group area relationship information based on the workgroup attributes includes: Match the workgroup attributes with the workgroup attributes of the target asset to determine the group area; Determine the network area relationship information based on the group area.

5. A network resource exposure surface determination device, characterized in that The steps for implementing the network resource exposure surface determination method according to any one of claims 1 to 4 include: An asset attribute determination module configured to determine a target asset and obtain the asset attributes of the target asset; An access set determination module configured to determine a network visitor set based on the asset attributes and policy rules; An exposure surface determination module configured to determine the exposure surface of the target asset in the target network area based on the network visitor set.

6. A computing device, characterized in that, Including: A memory and a processor; The memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions. When the computer-executable instructions are executed by the processor, the steps of the network resource exposure surface determination method according to any one of claims 1 to 4 are implemented.

7. A computer-readable storage medium storing computer-executable instructions, which when executed by a processor implement the steps of the network resource exposure surface determination method according to any one of claims 1 to 4.

Citation Information

Patent Citations

  • Exposed surface determination method and system and storage medium

    CN113472775A

  • Internet asset exposure surface determination method

    CN117294525A