Method and device for starting vulnerability scanning instruction, electronic equipment and storage medium

By detecting abnormal forwarding through pre-detection commands and adding it to a whitelist, the problem of uncontrolled vulnerability scanning traffic is solved, improving scanning efficiency and accuracy, and preventing accidental traffic forwarding from interfering with the security operations of other organizations.

CN119544338BActive Publication Date: 2025-12-05AGRICULTURAL BANK OF CHINA
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411730570.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-28
Publication Date
2025-12-05
Estimated Expiration
2044-11-28

AI Technical Summary

Technical Problem

Uncontrolled vulnerability scanning traffic may be accidentally forwarded to other organizations via load balancers, reverse proxy servers, and other nodes, interfering with their security operations and even affecting the normal operation of related systems.

Method used

Abnormal forwarding is detected by pre-detection commands, nodes that are abnormally forwarded are added to a whitelist to prevent them from doing so, and once it is determined that the target system will not be affected, the focus is on scanning the target IP address range, and commands carrying specific identifiers are only forwarded within the whitelist.

Benefits of technology

Reduce business interruptions or security incidents caused by false alarms, improve scanning efficiency and accuracy, and achieve prevention and monitoring of vulnerability scanning traffic forwarding risks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119544338B_ABST
    Figure CN119544338B_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide a vulnerability scanning instruction starting method and device, electronic equipment and storage medium. The method comprises: if a starting instruction of vulnerability scanning is received, a pre-probing instruction is sent to an IP address range corresponding to a system, wherein the pre-probing instruction carries a first identifier; receiving probing information fed back by the pre-probing instruction, if the probing information indicates that the pre-probing instruction exists abnormal forwarding, determining a forwarding node corresponding to the abnormal forwarding, and adding the forwarding node to a white list, wherein the forwarding nodes in the white list are prohibited from forwarding instructions carrying the first identifier and instructions carrying a second identifier; determining a target IP address corresponding to each forwarding node in the white list, and sending a vulnerability scanning instruction to the remaining IP addresses in the IP address range except the target IP address to respond to the starting instruction, wherein the vulnerability scanning instruction carries the second identifier.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of network security, and in particular to a vulnerability scanning instruction starting method and device, electronic equipment and storage medium. BACKGROUND

[0002] With the wide application of Internet technology, the business system services of large enterprises are increasingly open, and the network security situation is increasingly severe. In order to avoid the existence of vulnerability risks in their own systems, enterprises usually conduct vulnerability scanning on internal assets on a regular basis. For large enterprises, the internal IT environment often interfaces with branch offices, subsidiaries, third-party cooperation units and other institutions. If the vulnerability scanning traffic is not effectively controlled, it may be accidentally forwarded to other institutions through load balancing devices, reverse proxy servers and other nodes, thereby interfering with the safe operation of other institutions, and even affecting the normal operation of related systems.

[0003] Therefore, there is an urgent need for a method that can prevent and monitor the risk of vulnerability scanning traffic forwarding and effectively control vulnerability scanning risks. SUMMARY

[0004] The embodiments of the present application provide a vulnerability scanning instruction starting method and device, electronic equipment and storage medium, which can achieve the effect of preventing and monitoring the risk of vulnerability scanning traffic forwarding and effectively controlling vulnerability scanning risks.

[0005] In a first aspect, the embodiments of the present application provide a vulnerability scanning instruction starting method, which includes: if a starting instruction of vulnerability scanning is received, a pre-probing instruction is sent to an IP address range corresponding to a system, wherein the pre-probing instruction carries a first identifier; receiving probing information fed back by the pre-probing instruction, if the probing information indicates that the pre-probing instruction exists abnormal forwarding, determining a forwarding node corresponding to the abnormal forwarding, and adding the forwarding node to a white list, wherein the forwarding nodes in the white list are prohibited from forwarding instructions carrying the first identifier and second identifier; determining a target IP address corresponding to each forwarding node in the white list, and sending a vulnerability scanning instruction to the remaining IP addresses in the IP address range except the target IP address to respond to the starting instruction, wherein the vulnerability scanning instruction carries a second identifier.

[0006] In a second aspect, an embodiment of the present application provides a starting device of a vulnerability scanning instruction, comprising: an issuing module, configured to issue a pre-probing instruction to a corresponding IP address range of a system if a starting instruction of vulnerability scanning is received, wherein the pre-probing instruction carries a first identifier; a receiving module, configured to receive probing information fed back by the pre-probing instruction, and if the probing information indicates that the pre-probing instruction exists abnormal forwarding, determine a forwarding node corresponding to the abnormal forwarding, and add the forwarding node to a white list, wherein the forwarding nodes in the white list are prohibited from forwarding instructions carrying the first identifier and / or a second identifier; and a determining module, configured to determine a target IP address corresponding to each forwarding node in the white list, and send a vulnerability scanning instruction to remaining IP addresses in the IP address range except the target IP address to respond to the starting instruction, wherein the vulnerability scanning instruction carries the second identifier.

[0007] In a third aspect, an embodiment of the present application provides a starting device of a vulnerability scanning instruction, comprising: a memory and a processor.

[0008] The memory stores computer execution instructions.

[0009] The processor executes the computer execution instructions stored in the memory, so that the processor executes the first aspect and / or various possible implementation manners of the first aspect.

[0010] In a fourth aspect, an embodiment of the present application provides a computer readable storage medium, wherein the computer readable storage medium stores computer execution instructions, and the computer execution instructions are executed by a processor to implement the first aspect and / or various possible implementation manners of the first aspect.

[0011] In a fifth aspect, an embodiment of the present application provides a computer program product, comprising a computer program, and the computer program is executed by a processor to implement the first aspect and / or various possible implementation manners of the first aspect. BRIEF DESCRIPTION OF DRAWINGS

[0012] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and serve to explain the principles of the present application together with the specification.

[0013] Figure 1 A scene schematic diagram of a starting method of a vulnerability scanning instruction provided by the present application;

[0014] Figure 2 A flowchart of a starting method of a vulnerability scanning instruction provided by the present application Figure 1 ;

[0015] Figure 3 A structure schematic diagram of a starting system of a vulnerability scanning instruction provided by the present application;

[0016] Figure 4 The structure diagram of the starting device of the vulnerability scanning instruction provided in the present application is shown in the following figure:

[0017] Figure 5 The structure diagram of the starting device of the vulnerability scanning instruction provided in the present application is shown in the following figure.

[0018] The specific embodiments of the present application have been shown in the above figures, and will be described in more detail hereinafter. These figures and the written description are not intended to limit the scope of the present application concept in any way, but to illustrate the present application concept to those skilled in the art by referring to specific embodiments. DETAILED DESCRIPTION

[0019] The exemplary embodiments will be described in detail herein with reference to the accompanying drawings. In the following description, same numbers refer to same or similar elements throughout the drawings. The embodiments described in the following exemplary embodiments are not representative of all embodiments consistent with the present application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of the present application as detailed in the appended claims.

[0020] First, the terms involved in the present application are explained:

[0021] Host field: The Host field is a key part of the HTTP request header, which is used to specify the server domain name or IP address and port number that the client wants to access. In the HTTP request, the Host field is used to specify the server domain name or IP address and port number that the client wants to access. When the enterprise internal system issues instructions, if these instructions need to be forwarded to the system of the cooperative unit for processing, the Host field is likely to be modified to the domain name or IP address of the system of the cooperative unit during the forwarding process.

[0022] IP: The full name is Internet Protocol, which means "Internet Interconnection Protocol". IP specifies the rules that computers should follow when communicating on the Internet. Any computer system produced by a manufacturer can be interconnected with the Internet as long as it follows the IP protocol. In addition, IP addresses are unique, and can be divided into public addresses and private addresses according to the nature of the user. Public addresses are used in the Internet and can be accessed freely in the Internet; private addresses can only be used in internal networks and can only communicate with the Internet through proxy servers.

[0023] Vulnerability scanning: refers to a security detection behavior based on vulnerability database, through scanning and other means to detect the security vulnerability of the specified remote or local computer system, and find exploitable vulnerabilities.

[0024] Load balancing: a technique that distributes network traffic, requests, or workloads across multiple servers or computing resources, with the goal of improving system performance, reliability, and scalability.

[0025] Reverse proxy: refers to a way of proxying requests from external users to a designated server inside the network. The client does not communicate directly with the server, but with the reverse proxy server.

[0026] Full-flow detection: full-flow mainly embodies three "fulls", namely full-flow collection and preservation, full-behavior analysis, and full-flow backtracking. Through the full-flow analysis device, network full-flow collection and preservation, full-behavior analysis and full-flow backtracking are realized, and network metadata is uploaded to the big data analysis platform to realize more rich functions.

[0027] Web Application Firewall (WAF): a specific form of application firewall that identifies and protects against malicious features through website or application traffic.

[0028] Packet: also known as packet, is a formatted data unit transmitted in a packet switching network. A packet (packet) is divided into two parts, including control information, that is, header data (header), and data itself, that is, payload (payload).

[0029] Configuration management database: CMDB for short, is a logical database that contains the information of the whole life cycle of configuration items and the relationship between configuration items (including physical relationship, real-time communication relationship, non-real-time communication relationship and dependency relationship).

[0030] Figure 1 The scene diagram of the starting method of the vulnerability scanning instruction provided in the present application is shown in FIG. Figure 1 The specific application scenario of the present application is that there is an enterprise A, a forwarding node for interaction between enterprise A and an associated institution, and an associated institution.

[0031] Vulnerability scanning is a security vulnerability detection based on vulnerability library. The request sent to the target system generally has a vulnerability exploitation feature. After the scanning traffic is accidentally forwarded to the associated institution, its security protection system will detect the attack behavior. At the same time, in recent years, network attack means are various and updated frequently, and the size of the vulnerability library has also increased substantially. Single vulnerability scanning will send a large number of vulnerability exploitation requests to the target system, triggering a large number of alarms in a short period of time, which may overwhelm the important alarms of the associated unit and affect its security monitoring.

[0032] The unexpected forwarding of vulnerability scanning traffic is generally caused by the fact that web application processing nodes such as load balancing devices and reverse proxy servers do not implement strict forwarding filtering control. The forwarding objects are often important business systems, and strong scanning traffic may affect the performance of associated business processing, interfere with normal business logic, and even trigger threat blocking mechanisms on the opposite end, causing serious consequences such as business connection interruption.

[0033] When vulnerability scanning traffic is unexpectedly forwarded to an important industry node, it may cause chaos in the industry network and seriously interfere with the operation of the entire industry.

[0034] In combination with the above scenarios, it can be seen that in the prior art, there is a technical problem that vulnerability scanning traffic is not effectively controlled and may be unexpectedly forwarded to other institutions via nodes such as load balancing devices and reverse proxy servers, thereby interfering with the safe operation of other institutions and even affecting the normal operation of related systems.

[0035] The vulnerability scanning instruction starting method provided by the present application can detect abnormal forwarding conditions through pre-detection instructions, avoid sending vulnerability scanning instructions to non-target systems by mistake, and thus reduce business interruption or security incidents caused by false positives. After adding abnormal forwarding nodes to the whitelist, these nodes are prohibited from forwarding instructions carrying specific identifiers, which can avoid the unexpected forwarding of vulnerability scanning traffic to non-target systems and protect them from unnecessary security threats. After determining that there is no impact on non-target systems, the vulnerability scanning system can focus more on scanning the target IP address range, thereby improving the efficiency and accuracy of scanning, preventing and monitoring the risk of vulnerability scanning traffic forwarding, and effectively controlling the vulnerability scanning risk effect. The problem of interfering with the safe operation of other institutions and even affecting the normal operation of related systems if vulnerability scanning traffic is not effectively controlled and is unexpectedly forwarded to other institutions via nodes such as load balancing devices and reverse proxy servers is solved.

[0036] The technical solutions of the present application and how the technical solutions of the present application solve the above technical problems will be described in detail below with specific embodiments. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of the present application will be described below with reference to the accompanying drawings.

[0037] Figure 2 Flowchart of the vulnerability scanning instruction starting method provided by the present application Figure 1 As shown in Figure 2 , the method comprises:

[0038] S201, if a vulnerability scanning starting instruction is received, a pre-detection instruction is sent to the IP address range corresponding to the system, wherein the pre-detection instruction carries a first identifier.

[0039] That is, in the case of receiving the start instruction of the vulnerability scan, instead of directly issuing the vulnerability scan instruction, a detection instruction is first issued. Optionally, the vulnerability scan instruction carries an attack feature, and if the vulnerability scan instruction is forwarded to the system of the cooperative unit connected to the enterprise system, it will cause damage to the system of the cooperative unit and affect the use of the normal business scenario. Therefore, before issuing the vulnerability scan instruction, a pre-detection instruction without an attack feature can be issued.

[0040] In the vulnerability scanning module, a harmless Web request detection task is pre-configured for subsequent scanning range checking tasks before formal scanning. Example: the IP address of the live host is 888.888.88.88, which opens a Web service at TCP 8088 port, and the request is http: / / 888.888.88.88:8088 / lousaozhuanfajiancha.

[0041] Optionally, the example code is as follows:

[0042] GET / lousaozhuanfajiancha HTTP / 1.1

[0043] Host:888.888.88.88:8088

[0044] Connection:keep-alive

[0045] Upgrade-Insecure-Requests:1

[0046] User-Agent:Mozilla / 5.0(Windows NT 10.0;Win64;x64)App

[0047] Among them, “lousaozhuanfajiancha” is equivalent to the first identifier.

[0048] S202, receive the detection information fed back by the pre-detection instruction, if the detection information indicates that the pre-detection instruction exists abnormal forwarding, determine the forwarding node corresponding to the abnormal forwarding, add the forwarding node to the white list, wherein the forwarding node in the white list is prohibited to forward the instruction carrying the first identifier and the instruction carrying the second identifier;

[0049] It should be noted that abnormal forwarding refers to forwarding to an address other than the expected address, for example, if the scanning traffic is accidentally forwarded to the associated agency, its security protection system will detect the attack behavior.

[0050] In order to avoid the forwarding node to continuously forward the pre-probing instruction or the vulnerability scanning instruction in the subsequent work, and to cause the trouble to the associated organization, the forwarding node is added to the white list. Then the vulnerability scanning system will not forward the vulnerability scanning instruction to the forwarding node.

[0051] S203, determine the target IP address corresponding to each forwarding node in the white list, and send a vulnerability scanning instruction to the remaining IP addresses in the IP address range except the target IP address, to respond to the start instruction, wherein the vulnerability scanning instruction carries a second identifier.

[0052] Optionally, the second identifier is configured in the vulnerability scanning module, a custom request header attribute is added to all HTTP requests (equivalent to vulnerability scanning instructions) in the vulnerability scanning, and the attribute content has uniqueness, such as Vendor-Scanner:saf87#K3o2l*13+mc8u (equivalent to the second identifier).

[0053] The code example is as follows:

[0054] GET / ** / ****** / *****.htm HTTP / 1.1

[0055] Host:www.****.com

[0056] Connection:keep-alive

[0057] Upgrade-Insecure-Requests:1

[0058] User-Agent:Mozilla / 5.0(Windows NT 10.0;Win64;x64)App

[0059] Vendor-Scanner:saf87#K3o2l*13+mc8u

[0060] Optionally, the execution subject of the above steps is the vulnerability scanning system, which is used to send the vulnerability scanning instruction and the probing instruction.

[0061] It should be noted that different forwarding nodes are responsible for forwarding to different associated organizations or forwarding to internal organizations. Then adding the forwarding node to the white list can effectively prevent the pre-probing instruction or the vulnerability scanning instruction from being forwarded to the associated organization.

[0062] Optionally, the load balancing, reverse proxy and other forwarding node IP information in the enterprise configuration management database (CMDB) is synchronized to the vulnerability scanning whitelist by the configuration and scheduling module, and each forwarding node IP is excluded from the scanning task.

[0063] The vulnerability scanning instruction starting method provided by the embodiments of the present application can detect abnormal forwarding through the pre-detection instruction, avoid sending the vulnerability scanning instruction to a non-target system by mistake, and thus reduce business interruption or security incidents caused by false positives. After the abnormal forwarding nodes are added to the whitelist, these nodes are prohibited from forwarding instructions carrying specific identifiers, which can avoid the accidental forwarding of vulnerability scanning traffic to non-target systems and protect them from unnecessary security threats. After it is determined that the non-target systems will not be affected, the vulnerability scanning system can focus more on scanning the target IP address range, thereby improving the scanning efficiency and accuracy and achieving the prevention and monitoring of vulnerability scanning traffic forwarding risks and effectively controlling the vulnerability scanning risk effect.

[0064] In one possible embodiment, the first address information corresponding to the pre-detection instruction when it is sent and the second address information corresponding to the pre-detection instruction in the forwarding process are determined; the first address information and the second address information are compared, and whether the pre-detection instruction has abnormal forwarding is determined according to the comparison result.

[0065] When the pre-detection instruction is sent, the source address information of the instruction is recorded. This usually refers to the IP address or network location of the system that initiates the scanning. During the forwarding of the pre-detection instruction, the address information of each node reached by the instruction is recorded. These information can be obtained through network monitoring tools or log analysis.

[0066] The recorded first address information and second address information are compared. If an unexpected address appears in the second address information, i.e., it is not within the predetermined scanning range, it can be considered that there is abnormal forwarding. According to the comparison result, if it is found that the pre-detection instruction is forwarded to an unauthorized address or a system unrelated to the business, it can be determined that there is abnormal forwarding. Once the existence of abnormal forwarding is determined, measures should be taken immediately to prevent further forwarding, and the related forwarding nodes should be added to the whitelist to prohibit them from forwarding instructions carrying specific identifiers.

[0067] In one possible embodiment, the first Host field carried by the first address information when the pre-probing instruction is issued and the second Host field carried by the second address information after the pre-probing instruction is issued are determined; if the first Host field and the second Host field are inconsistent, it is determined that the pre-probing instruction is abnormally forwarded; if the first Host field and the second Host field are consistent, it is determined that the pre-probing instruction is normally forwarded.

[0068] When the vulnerability scanning system issues a pre-probing instruction, the source address information of the instruction is recorded, and the first Host field carried therein is extracted. This field represents the intended target host. When the pre-probing instruction is transmitted on the network and forwarded, the nodes it reaches are monitored, and the Host field of the second address information is extracted from the responses of these nodes. This field represents the actual target host reached. If the two are inconsistent, it means that the pre-probing instruction has been incorrectly forwarded to a non-intended host, i.e., abnormal forwarding has occurred.

[0069] If the two are consistent, it means that the pre-probing instruction has been correctly forwarded as expected, and no abnormality has occurred.

[0070] If abnormal forwarding is found, measures should be taken immediately to prevent further forwarding, and the relevant forwarding nodes should be added to the whitelist to prohibit them from forwarding instructions carrying specific identifiers.

[0071] If it is normal forwarding, the subsequent forwarding process can be monitored to ensure the safety and accuracy of the entire scanning process. Through this method, the vulnerability scanning system can effectively identify and handle abnormal forwarding situations, protecting non-target systems from unnecessary interference or potential security threats. This Host field-based checking mechanism is simple and effective, allowing for quick problem localization and improving system stability and security.

[0072] In one possible embodiment, a shielding instruction is sent to the forwarding node, wherein the shielding instruction is used to shield instructions carrying the first identifier and / or the second identifier.

[0073] One or more shielding instructions are created, specifying the type of instructions to be shielded (i.e., instructions carrying the first identifier and / or the second identifier). These instructions will tell the forwarding node not to forward instructions carrying the first identifier and / or the second identifier to other network segments or systems.

[0074] That is, do not forward pre-probing instructions and vulnerability scanning instructions to other network segments or systems.

[0075] Optionally, by configuring HTTP request filtering rules in load balancing, reverse proxy, and other forwarding nodes, access requests with custom first identifier and / or second identifier are discarded.

[0076] Alternatively, a code example is shown below:

[0077] http{

[0078] upstream demo{

[0079] server xxx;

[0080] server xxx;

[0081] }

[0082] server{

[0083] listen xxx; # Listening port number

[0084] server_name xxx;

[0085] if($http_Vendor-Scanner='saf87#K3o2l*13+mc8u'){

[0086] rewrite^(.*)$ / 40x.html; # Redirects directly to a local custom 40x page.

[0087] }

[0088] location / xxx{

[0089] proxy_pass demo; # Proxy to the defined demo

[0090] }

[0091] }

[0092] }

[0093] Optionally, at the boundary between the enterprise and relevant organizations such as third-party partners, a bypass-type traffic security detection device can be deployed to identify the first identifier and / or the second identifier. When a custom request header or a specified directory is matched, logs containing source and destination addresses, HTTP request header information, etc. are sent to the monitoring and judgment module.

[0094] The code example is as follows:

[0095] TTP request path like " / lousaozhuanfajiancha" or Vendor-Scanner like "saf87#K3o2l*13+mc8u")

[0096] Response action:

[0097] Threat name = "vulnerability scan traffic" and send log to "monitoring and decision module"

[0098] In one possible embodiment, upon receiving an abnormal alert feedback from a forwarding node, determine the abnormal instruction that triggered the abnormal alert, wherein the abnormal alert is used to prompt that the forwarding node currently receives an instruction carrying a first identifier and / or a second identifier; determine whether to update the whitelist according to the IP address of the upstream forwarding node corresponding to the abnormal instruction.

[0099] The forwarding node triggers an abnormal alert when it receives an instruction carrying a first identifier and / or a second identifier. This alert is a signal that there are probing instructions and / or vulnerability scanning instructions passing through the node. The system first needs to identify the specific instruction that triggered the abnormal alert. Optionally, analyze network traffic logs or monitoring data to determine which instructions are abnormal. Once the abnormal instruction is determined, the next step is to trace the source of these instructions. This usually involves finding the IP address of the upstream forwarding node related to the abnormal instruction. According to the IP address of the upstream forwarding node, the system needs to decide whether to add these addresses to the whitelist. If it decides to update the whitelist, the system will perform the necessary operations to add new IP addresses. After updating the whitelist, the system should continue to monitor network activity to ensure that the new rules are effective and make adjustments as needed.

[0100] In one possible embodiment, determine the third address information of the upstream forwarding node corresponding to the abnormal instruction and the fourth address information of the current forwarding node; compare the third address information and the fourth address information, and determine whether to update the whitelist according to the comparison result.

[0101] When the abnormal instruction reaches the current forwarding node, record the source address information of the instruction in the upstream forwarding node, i.e. the third address information. At the same time, record the address information of the current forwarding node when it receives the abnormal instruction, i.e. the fourth address information. Compare the third address information with the fourth address information:

[0102] If they are inconsistent, it means that the abnormal instruction has passed through unexpected paths or nodes during transmission, which may pose a security risk or configuration error.

[0103] If they are consistent, it means that the transmission path of the abnormal instruction is as expected, i.e. within the enterprise that has installed the vulnerability scanning system.

[0104] If it is found that the third address information and the fourth address information are inconsistent, it indicates that there is abnormal forwarding or potential security problems, and the whitelist should be considered for updating.

[0105] Updating the whitelist may involve adding the IP addresses of the related upstream forwarding nodes to the whitelist to prevent future abnormal traffic.

[0106] Optionally, the third address information can be IP address information, and the fourth address information can be IP address information.

[0107] In one possible embodiment, the abnormal instruction is determined to correspond to a third Host field carried by third address information of an upstream forwarding node and a fourth Host field carried by fourth address information of a current forwarding node; if the third Host field is consistent with the fourth Host field, the upstream forwarding node is determined to be added to the whitelist; and if the third Host field is inconsistent with the fourth Host field, a forwarding node reporting the abnormal instruction is determined to be added to the whitelist.

[0108] Since the current forwarding node has issued an abnormality reminder, it is known that the Host field corresponding to the address forwarded by the current forwarding node has been forwarded to the system of the associated institution, and the upstream forwarding node corresponding to the Host field of the current forwarding node indicates that abnormal forwarding also occurs, but has not triggered an abnormality reminder. Therefore, the upstream forwarding node needs to be added to the whitelist.

[0109] Optionally, after the upstream forwarding node is added to the whitelist, the host field of the upstream forwarding node of the upstream forwarding node can be further determined to trace the source of the forwarding node that first appears abnormal.

[0110] Since the Host field corresponding to the current forwarding node is abnormal, the Host field corresponding to the current forwarding node is different, which can be considered as normal forwarding, that is, it belongs to the internal forwarding of the enterprise.

[0111] Optionally, a scanning traffic forwarding alarm strategy configuration is configured in the monitoring and judgment module: a correlation rule "vulnerability scanning exceeds the expected range" based on the above log is configured, when the network layer target IP of a certain access request is different from the IP of the Host field in the HTTP request header, it is indicated that the scanning request is forwarded, the Host IP of the HTTP request is the initial node IP of the forwarding, at this time, an alarm is generated, and intervention and confirmation are performed by the security operation personnel and the scanning execution personnel.

[0112] The code example is as follows: policy logic:

[0113] (data source="full flow detection device" or data source="Web application firewall") and (HTTP request path like " / lousaozhuanfajiancha" or threat name="leak scan forwarding check" or Vendor-Scanner like "saf87#K3o2l*13+mc8u") and not (destination address=HTTP_Host_IP)

[0114] Response action:

[0115] Alert Name = "Vulnerability scan out of expected range".

[0116] By adding a specific identifier in the vulnerability scan request content, and issuing rules to detect the identifier feature by the system's configuration and scheduling module to connect other agencies at the boundary of full-flow detection, WAF and other security devices, and at the same time, adding a harmless pre-scan task (i.e. including scanning identifier features and specific web request directory, but no attack request) task before actually carrying out vulnerability scan, through the monitoring and judgment module to realize real-time monitoring and analysis of the relevant flow situation during pre-scan and formal scan, when detecting the expected target address and the actual flow direction of the destination address in the scan flow are different, immediately generate vulnerability scan out of expected range alarm, and be disposed by enterprise security operation personnel in time. On the other hand, before carrying out pre-scan, configure forwarding filtering rules on load balancing, reverse proxy and other forwarding nodes to prevent forwarding of requests containing vulnerability scan features, and through the configuration and scheduling module, add the forwarding node IP information in CMDB to the whitelist exception in the scan module (i.e. not included in the scan), so as to reduce the possibility of forwarding behavior as much as possible, and effectively control the risk.

[0117] Figure 3 The structure diagram of the starting system of the vulnerability scan instruction provided in the present application is shown as Figure 3

[0118] (1) Vulnerability scan module. This module mainly includes vulnerability scan, configuration of scan request marker, configuration of vulnerability scan request path and addition of vulnerability scan whitelist function.

[0119] (2) Configuration and scheduling module, the main functions of this module include:

[0120] a) Synchronize the load balancing, reverse proxy and other forwarding node IP information in the enterprise CMDB to the vulnerability scan whitelist;

[0121] b) Synchronize the configuration information not included in (1) to CMDB.

[0122] (3) Monitoring and judgment module. The main function of this module is to collect and analyze the alarm logs sent by the flow or security device, and monitor the flow direction according to the source / destination address; at the same time, configure comprehensive detection rules, compare the corresponding fields of the parsed logs according to the logic in the rules and generate comparison results.

[0123] ​(4) Disposal module. The main function of this module is to respond to the contrast results generated in (3). When the detection rule in (3) is triggered, this module will generate an alarm and can be linked to (1) (2) to configure a response action, such as: adding a white list of missed scans, triggering a security device traffic blocking scenario.

[0124] The vulnerability scanning instruction starting method provided by the embodiment of the application can detect abnormal forwarding conditions through pre-detection instructions, avoid sending vulnerability scanning instructions to non-target systems by mistake, and thus reduce business interruption or security incidents caused by false positives. After adding abnormal forwarding nodes to the white list, these nodes are prohibited from forwarding instructions carrying specific identifiers, which can avoid vulnerability scanning traffic from being accidentally forwarded to non-target systems and protect them from unnecessary security threats. After determining that non-target systems will not be affected, the vulnerability scanning system can focus more on scanning target IP address ranges, thereby improving scanning efficiency and accuracy, preventing and monitoring vulnerability scanning traffic forwarding risks, and effectively controlling vulnerability scanning risks. The problem of interfering with the safe operation of other institutions or even affecting the normal operation of related systems if vulnerability scanning traffic is not effectively controlled and is accidentally forwarded to other institutions via load balancing devices, reverse proxy servers, etc. is solved.

[0125] Figure 4 The structure diagram of the vulnerability scanning instruction starting device provided by the application is shown in Figure 4 The vulnerability scanning instruction starting device 40 provided by the embodiment includes:

[0126] The sending module 401 is configured to send a pre-detection instruction to the IP address range corresponding to the system if a vulnerability scanning starting instruction is received, wherein the pre-detection instruction carries a first identifier.

[0127] The receiving module 402 is configured to receive detection information fed back by the pre-detection instruction. If the detection information indicates that the pre-detection instruction is abnormally forwarded, the receiving module 402 is configured to determine a forwarding node corresponding to the abnormal forwarding and add the forwarding node to a white list, wherein the forwarding nodes in the white list are prohibited from forwarding instructions carrying the first identifier and a second identifier.

[0128] The determining module 403 is configured to determine a target IP address corresponding to each forwarding node in the white list and send a vulnerability scanning instruction to the remaining IP addresses in the IP address range except the target IP address to respond to the starting instruction, wherein the vulnerability scanning instruction carries the second identifier.

[0129] In a possible implementation, the receiving module 402 is further configured to determine first address information corresponding to the pre-probing instruction when the pre-probing instruction is sent out and second address information corresponding to the pre-probing instruction in a forwarding process; and compare the first address information with the second address information, and determine whether the pre-probing instruction is abnormally forwarded according to a comparison result.

[0130] In a possible implementation, the receiving module 402 is further configured to determine a first Host field carried by a first address information of the pre-probing instruction when the pre-probing instruction is sent out and a second Host field carried by a second address information after the pre-probing instruction is sent out; and if the first Host field is inconsistent with the second Host field, it is determined that the pre-probing instruction is abnormally forwarded; if the first Host field is consistent with the second Host field, it is determined that the pre-probing instruction is normally forwarded.

[0131] In a possible implementation, the determining module 403 is further configured to send a shielding instruction to the forwarding node, where the shielding instruction is used to shield an instruction carrying the first identifier and the second identifier.

[0132] In a possible implementation, the apparatus further includes a reminding module (not shown in the figure) configured to, if an abnormality reminder fed back by the forwarding node is received, determine an abnormal instruction triggering the abnormality reminder, where the abnormality reminder is used to prompt that the forwarding node currently receives an instruction carrying the first identifier and the second identifier; and determine whether to update the white list according to an IP address corresponding to an upstream forwarding node of the abnormal instruction.

[0133] In a possible implementation, the reminding module is further configured to determine third address information corresponding to the upstream forwarding node of the abnormal instruction and fourth address information corresponding to the current forwarding node; compare the third address information with the fourth address information, and determine whether to update the white list according to a comparison result.

[0134] In a possible implementation, the reminding module is further configured to determine a third Host field carried by the third address information corresponding to the upstream forwarding node of the abnormal instruction and a fourth Host field carried by the fourth address information after the pre-probing instruction is sent out; if the third Host field is consistent with the fourth Host field, it is determined that the upstream forwarding node is added to the white list; if the third Host field is inconsistent with the fourth Host field, it is determined that a forwarding node reporting the abnormal instruction is added to the white list.

[0135] The starting apparatus of the vulnerability scanning instruction provided in this embodiment can execute the method provided in the method embodiment, and has similar implementation principles and technical effects, which will not be described here in detail.

[0136] Figure 5 A structural schematic diagram of a starting device of a vulnerability scanning instruction provided in the present application is shown. As shown in the figure, the electronic device 50 provided in the embodiment includes at least one processor 501 and a memory 502. Optionally, the device 50 further includes a communication component 503. The processor 501, the memory 502 and the communication component 503 are connected through a bus 504. Figure 5

[0137] In the implementation process, the at least one processor 501 executes the computer execution instruction stored in the memory 502, so that the at least one processor 501 executes the method described above.

[0138] The specific implementation process of the processor 501 can refer to the method embodiments described above, which has similar implementation principles and technical effects, and will not be described here in detail.

[0139] In the above embodiments, it should be understood that the processor can be a central processing unit (CPU), and can also be other general-purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC) and the like. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor and the like. The steps of the method disclosed in the application can be directly embodied as the execution of the hardware processor, or the execution of the combination of the hardware and software modules in the processor.

[0140] The memory can include a random access memory (RAM), and can also include a non-volatile memory (NVM), for example, at least one disk memory.

[0141] The bus can be an industry standard architecture (ISA) bus, a peripheral component (PCI) bus or an extended industry standard architecture (EISA) bus and the like. The bus can be divided into an address bus, a data bus, a control bus and the like. For the convenience of representation, the bus in the drawings of the present application does not limit to only one bus or one type of bus.

[0142] ​The application further provides a computer program product comprising a computer program which, when executed by a processor, implements the method described above.

[0143] The application further provides a computer readable storage medium, wherein computer execution instructions are stored in the computer readable storage medium, and when a processor executes the computer execution instructions, the method described above is implemented.

[0144] The readable storage medium described above can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk or optical disk. The readable storage medium can be any available medium that can be accessed by a general-purpose or special-purpose computer.

[0145] An exemplary readable storage medium is coupled to the processor, so that the processor can read information from the readable storage medium and write information to the readable storage medium. Of course, the readable storage medium can also be an integral part of the processor. The processor and the readable storage medium can be located in an application specific integrated circuit (ASIC). Of course, the processor and the readable storage medium can also exist as discrete components in the device.

[0146] The division of units is only a logical function division, and in actual implementation, there can be another division mode, for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the units shown or discussed can be indirect coupling or communication connection through some interfaces, devices or units, which can be electrical, mechanical or other forms.

[0147] The units described as separate components can or can not be physically separated, and the components shown as units can or can not be physical units, that is, they can be located in one place, or they can be distributed on a plurality of network units. According to actual needs, some or all of the units can be selected to achieve the purpose of the embodiment.

[0148] In addition, the functional units in each embodiment of the application can be integrated in one processing unit, or each unit can exist physically, or two or more units can be integrated in one unit.

[0149] If the functions are implemented in the form of software function units and sold or used as independent products, they can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the present application or the parts of the technical solutions that essentially contribute to the prior art can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes a number of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the embodiments of the method of the present application. The aforementioned storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a magnetic disk or an optical disk, and various media that can store program codes.

[0150] It can be understood by those skilled in the art that all or part of the steps of the above-mentioned method embodiments can be completed by program instruction related hardware. The aforementioned program can be stored in a computer readable storage medium. When the program is executed, the steps of the above-mentioned method embodiments are executed; and the aforementioned storage medium includes: ROM, RAM, magnetic disk or optical disk, and various media that can store program codes.

[0151] Finally, it should be noted that: those skilled in the art will easily think of other embodiments of the present application after considering the specification and practicing the application disclosed herein. The present application is intended to cover any variations, uses or adaptations of the present application that follow the general principles of the present application and include common knowledge or conventional technical means in the art that are not disclosed in the present application, and is not limited to the precise structure described above and shown in the drawings, and various modifications and changes can be made without departing from the scope thereof. The scope of the present application is only limited by the appended claims.

Claims

1. A method for initiating a vulnerability scanning command, characterized in that, include: If a vulnerability scan start command is received, a pre-probing command is sent to the corresponding IP address range of the system, wherein the pre-probing command carries a first identifier; If the detection information fed back by the pre-detection instruction indicates that the pre-detection instruction is abnormally forwarded, the forwarding node corresponding to the abnormal forwarding is determined and the forwarding node is added to the whitelist. The forwarding nodes in the whitelist are prohibited from forwarding instructions carrying the first identifier and the second identifier. The target IP address corresponding to each forwarding node in the whitelist is determined, and a vulnerability scanning command is sent to the remaining IP addresses in the IP address range other than the target IP address in response to the start command, wherein the vulnerability scanning command carries a second identifier.

2. The method according to claim 1, characterized in that, If the detection information indicates that the pre-detection command is being forwarded abnormally, before determining the forwarding node corresponding to the abnormal forwarding, the method further includes: Determine the first address information corresponding to the pre-detection command when it is issued and the second address information corresponding to the pre-detection command during the forwarding process; By comparing the first address information and the second address information, it is determined whether the pre-detection instruction is abnormally forwarded based on the comparison result.

3. The method according to claim 2, characterized in that, include: Determine the first Host field carried by the first address information when the pre-detection command is issued, and the second Host field carried by the second address information after the pre-detection command is issued; If the first Host field is inconsistent with the second Host field, it is determined that the pre-detection instruction has been abnormally forwarded; If the first Host field matches the second Host field, then the pre-detection instruction is determined to be forwarded normally.

4. The method according to claim 1, characterized in that, After sending vulnerability scanning commands to the remaining IP addresses in the IP address range other than the target IP address in response to the start command, the method further includes: A blocking instruction is sent to the forwarding node, wherein the blocking instruction is used to block instructions carrying the first identifier and / or the second identifier.

5. The method according to any one of claims 1-4, characterized in that, After sending vulnerability scanning commands to the remaining IP addresses in the IP address range other than the target IP address in response to the start command, the method further includes: If an abnormal alert is received from a forwarding node, an abnormal instruction that triggered the abnormal alert is determined, wherein the abnormal alert is used to indicate that the forwarding node has received an instruction carrying a first identifier and / or a second identifier; Whether to update the whitelist is determined based on the IP address of the upstream forwarding node corresponding to the abnormal instruction.

6. The method according to claim 5, characterized in that, The method further includes determining whether to update the whitelist based on the IP address of the upstream forwarding node corresponding to the abnormal instruction, and the method also includes: Determine the third address information corresponding to the abnormal instruction at the upstream forwarding node and the fourth address information corresponding to the current forwarding node; The third address information and the fourth address information are compared, and a decision is made on whether to update the whitelist based on the comparison result.

7. The method according to claim 6, characterized in that, The method further includes comparing the third address information and the fourth address information, and determining whether to update the whitelist based on the comparison result. Determine the third Host field carried by the third address information corresponding to the upstream forwarding node and the fourth Host field carried by the fourth address information corresponding to the current forwarding node for the abnormal instruction; If the third Host field is consistent with the fourth Host field, then the upstream forwarding node will be added to the whitelist. If the third Host field is inconsistent with the fourth Host field, then the forwarding node that reported the abnormal instruction will be added to the whitelist.

8. A vulnerability scanning command initiation device, characterized in that, include: The issuing module is used to issue a pre-probing instruction to the corresponding IP address range of the system if a vulnerability scanning start instruction is received, wherein the pre-probing instruction carries a first identifier; The receiving module is used to receive the detection information fed back by the pre-detection instruction. If the detection information indicates that the pre-detection instruction has abnormal forwarding, the module determines the forwarding node corresponding to the abnormal forwarding and adds the forwarding node to the whitelist. The forwarding nodes in the whitelist are prohibited from forwarding instructions carrying the first identifier and / or the second identifier. The determination module is used to determine the target IP address corresponding to each forwarding node in the whitelist, and send vulnerability scanning instructions to the remaining IP addresses in the IP address range other than the target IP address in response to the start instruction, wherein the vulnerability scanning instructions carry a second identifier.

9. A device for launching vulnerability scanning instructions, characterized in that, include: Memory, processor; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory, causing the processor to perform the method as described in any one of claims 1-7.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the method as described in any one of claims 1-7.

Citation Information

Patent Citations

  • Vulnerability detection method and device

    CN109711166A

  • Vulnerability hot repair method and server

    CN117220933A