A vulnerability risk assessment and monitoring system for network security

By designing a vulnerability risk assessment and monitoring system for network security, using multiple vulnerability scanning channels and encrypted transmission models, the security risk problems during network page jumps and APP jumps are solved, and efficient vulnerability interception and jump security improvement is achieved.

CN119603082BActive Publication Date: 2025-06-24BEIJING CHENG MING NETWORK TECH HLDG LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510142834.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-10
Publication Date
2025-06-24
Estimated Expiration
2045-02-10

AI Technical Summary

Technical Problem

Vulnerabilities in network security cause security risks such as information leakage, property fraud and account theft when redirecting to network pages and APPs. It is difficult for existing technology to effectively solve these problems.

Method used

Design a vulnerability risk assessment and monitoring system for network security, including vulnerability filtering module, jump monitoring module, encrypted transmission module and management module. By setting up multi-channel vulnerability scanning channels and encrypted transmission models, multi-level vulnerability scanning and permission restrictions for jump sources are realized, ensuring the security of the jump process.

Benefits of technology

Quickly intercept vulnerability target URLs through multiple vulnerability scanning channels to improve interception speed and jump security; evaluate potential vulnerabilities through weighting coefficients to further eliminate potential risks and prevent information and property loss.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119603082B_ABST
    Figure CN119603082B_ABST
Patent Text Reader

Abstract

The present invention provides a vulnerability risk assessment and monitoring system for network security, which relates to the field of network security. The present invention obtains the first vulnerability scanning channel, sets up an abnormal feature coding training mechanism, and then obtains a precise abnormal coding feature data set. According to the precise abnormal coding feature data set, the target URL is filtered for vulnerabilities to obtain a jumpable source. A second vulnerability scanning model is set up, and the target weighting coefficient corresponding to the jumpable source is obtained, and then a potential target URL is obtained. A permission database is pre-stored, and the jumpable source is restricted according to the permission database to obtain an authorized jump source. A third transmission encryption model is set up, and a confirmation log is obtained according to the authorized jump source, and a user confirmation mechanism is set up. According to the user confirmation mechanism, the confirmation log is confirmed to obtain an encrypted jump user. The encrypted jump user is monitored to obtain abnormal jump data. Furthermore, the abnormal jump data is managed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security, and in particular, to a vulnerability risk assessment and monitoring system for network security. Background Art

[0002] A vulnerability in network security refers to a defect or error in the design, implementation of system software and hardware, or the use of system security policies, which enables an attacker to access or damage the system without authorization; vulnerabilities can exist in multiple aspects such as hardware, software, and protocols, including but not limited to operating system vulnerabilities, application program vulnerabilities, network protocol vulnerabilities, etc.; these vulnerabilities may be caused by defects in design, coding errors, improper configuration, or human factors in specific implementations, thus threatening the security of the system;

[0003] In real life, due to vulnerabilities in network security, there are information leakage, property fraud, account theft, or other security risks during network page jumps and jumps before APPs. Therefore, in order to solve network security during jumps before APPs in network page jumps, a vulnerability risk assessment and monitoring system for network security is provided. Summary of the Invention

[0004] In order to solve the above technical problems, the present invention provides a vulnerability risk assessment and monitoring system for network security;

[0005] The object of the present invention can be achieved by the following technical solutions: A vulnerability risk assessment and monitoring system for network security, including a monitoring center, which is wirelessly communicatively connected to a vulnerability filtering module, a jump monitoring module, an encrypted transmission module, and a management module;

[0006] The vulnerability filtering module is provided with a scanning channel unit and a target scanning unit; the scanning channel unit is used to obtain the first vulnerability scanning channel, set an abnormal feature coding training mechanism, and then obtain an accurate abnormal coding feature data set; the target scanning unit is used to obtain the source to be jumped, and filter the target URL corresponding to the source to be jumped according to the accurate abnormal coding feature data set to obtain the source that can be jumped;

[0007] The jump monitoring module is provided with a potential abnormality unit and a jump permission unit. The potential abnormality unit is used to set a second vulnerability scanning model, obtain the target weighting coefficient corresponding to the source that can be jumped, and then obtain the potential target URL; the jump permission unit is used to pre-store a permission database, and perform permission restriction on the source that can be jumped according to the permission database to obtain the authorized jump source;

[0008] The encryption transmission module is used to set the third transmission encryption model, obtain the confirmation log according to the authorized jump source, and set up a user confirmation mechanism. According to the user confirmation mechanism, the confirmation log is confirmed to obtain the encrypted jump user;

[0009] The management module is provided with a target monitoring unit and an exception management unit. The target monitoring unit is used to monitor the encrypted jump user and obtain abnormal jump data; the exception management unit is used to manage the abnormal jump data.

[0010] Further, the process of the scanning channel unit obtaining the first vulnerability scanning channel includes:

[0011] Set a number of jump transmission channels, obtain the jump request and the corresponding source to be jumped, connect the jump request, the source to be jumped and the target scanning unit through the number of jump transmission channels, and then obtain the target URL corresponding to the source to be jumped;

[0012] Obtain the structure data to be monitored corresponding to the target URL and the corresponding feature identifier, obtain a number of structure data anomaly types and the corresponding anomaly feature identifiers according to the structure data to be monitored, set a number of vulnerability scanning nodes in the jump transmission channel connecting the source to be jumped and the target scanning unit, disperse and store the structure data anomaly types and the corresponding anomaly feature identifiers in the vulnerability scanning nodes to generate a structure data anomaly type data node set, and connect the vulnerability scanning nodes in sequence to generate the first vulnerability scanning channel.

[0013] Further, the process of obtaining the accurate anomaly coding feature data set includes:

[0014] Set an anomaly feature coding converter in the first vulnerability scanning channel to convert the feature identifier into a feature code; then obtain the anomaly feature code corresponding to the anomaly feature identifier and store it in the corresponding structure data anomaly type data node set to generate an anomaly feature coding data set;

[0015] The anomaly feature coding training mechanism is used to perform data training on the anomaly feature coding data set; set a number of anomaly target URLs corresponding to the anomaly feature identifiers and transmit them to the first vulnerability scanning channel for conversion through the anomaly feature coding converter to generate the corresponding anomaly feature codes, and match them with the anomaly feature coding data set. If the match is unsuccessful, obtain the anomaly feature identifier corresponding to the anomaly feature code, and add the anomaly feature code to the anomaly feature coding data set corresponding to the corresponding anomaly feature identifier to generate an accurate anomaly coding feature data set; otherwise, do nothing;

[0016] The structure data to be monitored includes communication protocol, IP address, server listening port, resource path, query parameter, and fragment identifier;

[0017] The types of abnormal structure data include, but are not limited to, binary anomalies, abnormal IP addresses, nested addresses, abnormal resource paths, symbol anomalies, etc.

[0018] Furthermore, the process by which the target scanning unit obtains the source for jumping includes:

[0019] Transmit the target URL to the first vulnerability scanning channel, obtain the feature identifier corresponding to the target URL based on the abnormal feature encoding converter and convert it into a feature code, match the feature code with the accurate abnormal code feature data set. If the match is successful, intercept the corresponding target URL, generate a vulnerable target URL and send it to the management module; otherwise, generate a source for jumping from the source to be jumped and send it to the jump monitoring module.

[0020] Furthermore, the process by which the potential anomaly unit obtains the potential target URL includes:

[0021] The second vulnerability scanning model is wirelessly connected to the first vulnerability scanning channel. Based on the abnormal feature encoding converter, obtain the feature code corresponding to the target URL of the source for jumping and denote it as the target feature code. Fragment the target feature code to obtain several sub-feature codes; match the several sub-feature codes with several accurate abnormal code feature data sets. If the match is successful, denote the sub-feature code as a potential sub-feature code; otherwise, denote the sub-feature code as a normal sub-feature code, and obtain the corresponding abnormal feature identifier and feature identifier;

[0022] Set the weighting coefficients corresponding to the potential sub-feature code and the normal sub-feature code according to the feature identifier, and mark them as α q λ and β z λ , where λ represents the corresponding feature identifier. Furthermore, obtain the target weighting coefficient K corresponding to the target feature code according to the weighting coefficient, that is, the acquisition formula is;

[0023] K = ∑β z λ -∑α q λ ;

[0024] Set the target weighting coefficient threshold K′, and compare it with the target weighting coefficient:

[0025] If K < K′, then mark the feature code corresponding to the source for jumping as a potential feature code, intercept the corresponding target URL, generate a potential target URL and send it to the management module;

[0026] If K ≥ K′, then send the source for jumping to the jump permission unit.

[0027] Further, the process by which the jump permission unit obtains the authorized jump source includes:

[0028] Determine whether the target URL corresponding to the jumpable source exists in the permission database. If it exists, generate the authorized jump source from the jumpable source and send it to the encryption transmission module;

[0029] Otherwise, send an authorization request to the management module.

[0030] Further, the process by which the encryption transmission module obtains the encrypted jump user includes:

[0031] Obtain the jump request corresponding to the authorized jump source, click on the jump request to obtain the jump user, and then obtain the jump user authorization function corresponding to the jump user and send it to the third transmission encryption model;

[0032] The third transmission encryption model is provided with an automatic shutdown mechanism and is wirelessly communicatively connected to a function database. Obtain the jump user authorization function and compare it with the function database. If it exists in the function database, automatically shut down the corresponding jump user authorization function; otherwise, send the jump user authorization function to the jump user interface to generate a confirmation log;

[0033] A user confirmation mechanism is set on the jump user interface for receiving and confirming the confirmation log;

[0034] The jump user receives the confirmation log according to the user confirmation mechanism and manually judges the jump user authorization function. Manually select the jump user authorization function to be closed and confirm. If the confirmation is successful, obtain the encrypted jump user and perform the jump.

[0035] Further, the process by which the target monitoring unit obtains the abnormal jump data includes:

[0036] Send the jump user authorization function manually closed by the jump user through the user confirmation mechanism to the function database for storage;

[0037] Obtain the jump user authorization function during the jump process of the encrypted jump user, and obtain the abnormal jump data according to the function database and send it to the abnormal management unit.

[0038] Further, the process by which the abnormal management unit manages the abnormal jump data includes:

[0039] The abnormal management unit is wirelessly communicatively connected to the management terminal and the encrypted jump user terminal;

[0040] The anomaly management unit receives the vulnerable target URL, obtains the corresponding source to be redirected and sends it to the management terminal. After receiving the source to be redirected, it prohibits the corresponding redirection request and sends "Anomaly request, automatically closed" to the encrypted redirection user terminal for display;

[0041] The anomaly management unit receives the potential target URL, obtains the corresponding redirectable source and sends it to the management terminal. After receiving the redirectable source, it reminds the corresponding redirection request and sends "Anomaly request, recommended to close" to the encrypted redirection user terminal for display;

[0042] The anomaly management unit receives the vulnerable target URL, obtains the corresponding source to be redirected and sends it to the management terminal. After receiving the source to be redirected, it prohibits the corresponding redirection request and sends "Anomaly request, automatically closed" to the encrypted redirection user terminal for display;

[0043] The anomaly management unit receives the abnormal redirection data and sends it to the encrypted redirection user terminal for reminder, and asks whether to close the redirection immediately.

[0044] Compared with the prior art, the beneficial effects of the present invention are:

[0045] 1. By obtaining the first vulnerability scanning channel, the target URL corresponding to the source to be redirected is scanned for the first time through the first vulnerability scanning channel, quickly intercepting the vulnerable target URL, improving the interception speed and the security of redirection;

[0046] 2. Set up the second vulnerability scanning model, obtain the feature code of the target URL corresponding to the redirectable source, and perform sharding processing to obtain the corresponding target weighting coefficient. Scan the potential vulnerabilities of the redirectable source according to the target weighting coefficient, and then obtain the potential target URL and intercept it, which can better perform further vulnerability scanning on the redirectable, eliminate potential vulnerabilities, and prevent property loss and information loss caused by omission of the first vulnerability scanning channel. BRIEF DESCRIPTION OF THE DRAWINGS

[0047] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required in the embodiments. Obviously, the drawings in the following description are only some embodiments recorded in the present invention. For those of ordinary skill in the art, other drawings can also be obtained according to these drawings.

[0048] Figure 1 It is the schematic diagram of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0049] To more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the accompanying drawings required in the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments recorded in the present invention. For those of ordinary skill in the art, other accompanying drawings can also be obtained based on these drawings.

[0050] As Figure 1 shown, a vulnerability risk assessment and monitoring system for network security includes a monitoring center, and the monitoring center is wirelessly communicatively connected to a vulnerability filtering module, a jump monitoring module, an encrypted transmission module, and a management module;

[0051] The vulnerability filtering module is provided with a scanning channel unit and a target scanning unit; the scanning channel unit is used to obtain the first vulnerability scanning channel, set an abnormal feature coding training mechanism, and then obtain an accurate abnormal coding feature data set; the target scanning unit is used to obtain the source to be jumped, and filter the target URL corresponding to the source to be jumped according to the accurate abnormal coding feature data set to obtain the source that can be jumped;

[0052] The jump monitoring module is provided with a potential abnormality unit and a jump permission unit. The potential abnormality unit is used to set a second vulnerability scanning model, obtain the target weighting coefficient corresponding to the source that can be jumped, and then obtain the potential target URL; the jump permission unit is used to pre-store a permission database, and perform permission restriction on the source that can be jumped according to the permission database to obtain an authorized jump source;

[0053] The encrypted transmission module is used to set a third transmission encryption model, obtain the jump user corresponding to the authorized jump source, and then obtain a confirmation log, and set a user confirmation mechanism to confirm the confirmation log according to the user confirmation mechanism to obtain an encrypted jump user;

[0054] The management module is provided with a target monitoring unit and an abnormality management unit. The target monitoring unit is used to monitor the encrypted jump user to obtain abnormal jump data; the abnormality management unit is used to manage the abnormal jump data;

[0055] The process by which the scanning channel unit obtains the first vulnerability scanning channel includes:

[0056] Set a number of jump transmission channels, obtain a jump request and the corresponding source to be jumped, connect the jump request, the source to be jumped, and the target scanning unit through the number of jump transmission channels, receive the jump request, obtain the corresponding source to be jumped through the jump transmission channel, and then obtain the target URL corresponding to the source to be jumped;

[0057] Obtain the structure data to be monitored corresponding to the target URL and the corresponding feature identifier. According to the structure data to be monitored, obtain several structure data anomaly types and the corresponding anomaly feature identifiers. Set several vulnerability scanning nodes in the jump transmission channel of the target scanning unit of the source to be jumped. Disperse and store the structure data anomaly types and the corresponding anomaly feature identifiers in the vulnerability scanning nodes to generate a structure data anomaly type data node set, and connect the vulnerability scanning nodes in sequence to generate the first vulnerability scanning channel;

[0058] The process of obtaining the accurate anomaly coding feature data set includes:

[0059] Set an anomaly feature coding converter in the first vulnerability scanning channel to convert the feature identifier into a feature code; further obtain the anomaly feature code corresponding to the anomaly feature identifier and store it in the corresponding structure data anomaly type data node set to generate an anomaly feature code data set;

[0060] The anomaly feature coding training mechanism is used to perform data training on the anomaly feature code data set to obtain an accurate anomaly coding feature data set;

[0061] Set the anomaly target URLs corresponding to several anomaly feature identifiers and transmit them to the first vulnerability scanning channel for conversion through the anomaly feature coding converter to generate the corresponding anomaly feature codes, and match them with the anomaly feature code data set. If the match is unsuccessful, obtain the anomaly feature identifier corresponding to the anomaly feature code, and add the anomaly feature code to the anomaly feature code data set corresponding to the corresponding anomaly feature identifier to generate an accurate anomaly coding feature data set; otherwise, do nothing;

[0062] It should be further noted that in the specific implementation process, the jump request includes an active request and a passive request, including but not limited to QR code scanning, advertisement jump, link, etc.; the source to be jumped includes but not limited to web page browsing, file download, video playback, etc.; the target URL corresponding to the source to be jumped is a uniform resource locator, which is an address identifier used to locate resources (such as web pages, pictures, videos, etc.) on the Internet. The main function of the URL is to identify and locate resources on the Internet. Through a browser or other application programs, resources can be accessed and obtained according to the URL; it is the portal and access entrance of information resources on the Internet and the basis for operations such as web page browsing, file download, and video playback; therefore, converting the source to be jumped corresponding to the jump request into a unified target URL can better perform vulnerability scanning on the source to be jumped;

[0063] The structure data to be monitored includes communication protocol, IP address, server listening port, resource path, query parameter, and fragment identifier;

[0064] The types of abnormal structure data include, but are not limited to, binary anomalies, abnormal IP addresses, nested addresses, abnormal resource paths, symbol anomalies, etc.;

[0065] It should be further noted that in the specific implementation process, usually the target URL is expressed as scheme: / / host:port / path?query#fragment; where, scheme represents the communication protocol; host represents the IP address; port represents the server listening port, path represents the resource path; query represents the query parameter; fragment represents the fragment identifier;

[0066] The process by which the target scanning unit obtains the jumpable source includes:

[0067] Transmit the target URL to the first vulnerability scanning channel, obtain the feature identifier corresponding to the target URL based on the abnormal feature encoding converter and convert it into a feature code, match the feature code with the accurate abnormal code feature data set. If the match is successful, intercept the corresponding target URL, generate a vulnerable target URL and send it to the management module; otherwise, generate a jumpable source from the source to be jumped and send it to the jump monitoring module;

[0068] It should be further noted that in the specific implementation process, by obtaining the first vulnerability scanning channel, the target URL corresponding to the source to be jumped is scanned for the first time through the first vulnerability scanning channel, quickly intercepting the vulnerable target URL, improving the interception speed and the security of the jump;

[0069] The process by which the potential anomaly unit obtains the target weighting coefficient includes:

[0070] The second vulnerability scanning model is wirelessly connected to the first vulnerability scanning channel. Based on the abnormal feature encoding converter, obtain the feature code of the target URL corresponding to the jumpable source and record it as the target feature code. Fragment the target feature code to obtain several sub-feature codes. Match the several sub-feature codes with several accurate abnormal code feature data sets. If the match is successful, record the sub-feature code as the potential sub-feature code; otherwise, record the sub-feature code as the normal sub-feature code; and obtain the corresponding abnormal feature identifier and feature identifier;

[0071] Set the weighting coefficients corresponding to the potential sub-feature code and the normal sub-feature code according to the feature identifier, and mark them as α q λ and β z λ , where λ represents the corresponding feature identifier, and then obtain the target weighting coefficient K corresponding to the target feature code according to the weighting coefficient, that is, the acquisition formula is;

[0072] K = ∑β z λ - ∑α q λ ;

[0073] Set a target weighted coefficient threshold K' and compare it with the target weighted coefficient:

[0074] If K < K', then mark the feature code corresponding to the jumpable source as a potential feature code, intercept the corresponding target URL, generate a potential target URL and send it to the management module;

[0075] If K ≥ K', then send the jumpable source to the jump permission unit;

[0076] It should be further noted that in the specific implementation process, set a second vulnerability scanning model, obtain the feature code of the target URL corresponding to the jumpable source, and perform sharding processing to obtain the corresponding target weighted coefficient. Scan the potential vulnerabilities of the jumpable source according to the target weighted coefficient, and then obtain and intercept the potential target URL, which can better perform further vulnerability scanning on the jumpable, cut off potential vulnerabilities, and prevent property loss and information loss caused by vulnerabilities;

[0077] The process by which the jump permission unit obtains the authorized jump source includes:

[0078] Judge whether the target URL corresponding to the jumpable source exists in the permission database. If it exists, generate an authorized jump source from the jumpable source and send it to the encryption transmission module;

[0079] Otherwise, send an authorization request to the management module.

[0080] The process by which the encryption transmission module obtains the encrypted jump user includes:

[0081] Obtain the jump request corresponding to the authorized jump source, obtain the jump user by accepting the jump request, and then obtain the jump user authorization function corresponding to the jump user and send it to the third transmission encryption model;

[0082] The third transmission encryption model is provided with an automatic shutdown mechanism and is wirelessly communicatively connected to a function database. Obtain the jump user authorization function and compare it with the function database. If it exists in the function database, automatically shut down the corresponding jump user authorization function; otherwise, send the jump user authorization function to the jump user interface to generate a confirmation log;

[0083] A user confirmation mechanism is set on the jump user interface for receiving and confirming the confirmation log;

[0084] The jumping user receives the confirmation log according to the user confirmation mechanism and manually judges the jumping user authorization function. Manually select the jumping user authorization function to be closed and confirm. If the confirmation is successful, obtain the encrypted jumping user and perform the jump;

[0085] It should be further noted that in the specific implementation process, in the prior art, when a user jumps between web pages or before an APP, the user usually directly accepts the jump request and enters the jump source. Only when entering the jump source will it be informed whether there is an abnormality, but usually by this time, privacy information and finances have been lost. Therefore, through the first vulnerability scan, the second vulnerability scan, and the third vulnerability scan, the jump source is scanned for vulnerabilities. Only when it is judged as an authorized jump source can the jump request be accepted, and the privacy information needs to be automatically and actively encrypted, improving the security of information;

[0086] The process by which the target monitoring unit obtains abnormal jump data includes:

[0087] Send the jumping user authorization function manually closed by the jumping user through the user confirmation mechanism to the function database for storage;

[0088] Obtain the jumping user authorization function of the encrypted jumping user during the jumping process, and judge whether there is a function database. If so, generate the corresponding jumping user authorization function into abnormal jump data and send it to the abnormal management unit;

[0089] The process by which the abnormal management unit manages the abnormal jump data includes:

[0090] The abnormal management unit is wirelessly communicatively connected to the management terminal and the encrypted jumping user terminal;

[0091] When the abnormal management unit receives the vulnerable target URL, obtain the corresponding source to be jumped and send it to the management terminal. After receiving the source to be jumped, prohibit the corresponding jump request and send "Abnormal request, automatically closed" to the encrypted jumping user terminal for display;

[0092] When the abnormal management unit receives the potential target URL, obtain the corresponding source that can be jumped and send it to the management terminal. After receiving the source that can be jumped, remind the corresponding jump request and send "Abnormal request, it is recommended to close" to the encrypted jumping user terminal for display;

[0093] When the abnormal management unit receives the vulnerable target URL, obtain the corresponding source to be jumped and send it to the management terminal. After receiving the source to be jumped, prohibit the corresponding jump request and send "Abnormal request, automatically closed" to the encrypted jumping user terminal for display;

[0094] The exception management unit receives the exception jump data and sends it to the encrypted jump user terminal for reminder, and asks whether to close the jump immediately.

[0095] The features and exemplary embodiments of various aspects of the present application will be described in detail below. For the purpose, technical solutions and advantages of the present application to be more clear, the present application will be further described in detail with reference to the accompanying drawings and specific embodiments; it should be understood that the specific embodiments described herein are only intended to explain the present application, rather than limiting the present application; for those skilled in the art, the present application can be implemented without some of these specific details; the above description of the embodiments is only to provide a better understanding of the present application by showing examples of the present application.

[0096] The above embodiments are only used to illustrate the technical method of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical method of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical method of the present invention.

Claims

1. A vulnerability risk assessment and monitoring system for network security, comprising a monitoring center, characterized in that: The monitoring center is wirelessly connected to a vulnerability filtering module, a jump monitoring module, an encrypted transmission module, and a management module; The vulnerability filtering module is provided with a scanning channel unit and a target scanning unit; the scanning channel unit is used to obtain the first vulnerability scanning channel, set an abnormal feature coding training mechanism, and then obtain an accurate abnormal coding feature data set; the target scanning unit is used to obtain the source to be jumped, and filter the target URL corresponding to the source to be jumped according to the accurate abnormal coding feature data set to obtain the source that can be jumped; The jump monitoring module is provided with a potential anomaly unit and a jump permission unit. The potential anomaly unit is used to set a second vulnerability scanning model, obtain the target weighting coefficient corresponding to the source that can be jumped, and then obtain the potential target URL; The jump permission unit is used to pre-store a permission database, restrict the permission of the source that can be jumped according to the permission database, and obtain the authorized jump source; The encrypted transmission module is used to set a third transmission encryption model, obtain a confirmation log according to the authorized jump source, and set a user confirmation mechanism to confirm the confirmation log according to the user confirmation mechanism to obtain the encrypted jump user; The management module is provided with a target monitoring unit and an anomaly management unit. The target monitoring unit is used to monitor the encrypted jump user and obtain abnormal jump data; The anomaly management unit is used to manage the abnormal jump data; The process by which the scanning channel unit obtains the first vulnerability scanning channel includes: Set a number of jump transmission channels, obtain a jump request and the corresponding source to be jumped, connect the jump request, the source to be jumped, and the target scanning unit through the number of jump transmission channels, and then obtain the target URL corresponding to the source to be jumped; Obtain the structure data to be monitored corresponding to the target URL and the corresponding feature identifier, obtain a number of structure data anomaly types and the corresponding abnormal feature identifiers according to the structure data to be monitored, set a number of vulnerability scanning nodes in the jump transmission channel connecting the source to be jumped and the target scanning unit, disperse and store the structure data anomaly types and the corresponding abnormal feature identifiers in the vulnerability scanning nodes to generate a structure data anomaly type data node set, and connect the vulnerability scanning nodes in sequence to generate the first vulnerability scanning channel; The process by which the potential anomaly unit obtains the potential target URL includes: The second vulnerability scanning model is wirelessly connected to the first vulnerability scanning channel, obtains the feature coding of the target URL corresponding to the source that can be jumped based on the abnormal feature coding converter and records it as the target feature coding, slices the target feature coding to obtain a number of sub-feature codings; matches the number of sub-feature codings with a number of accurate abnormal coding feature data sets to obtain the potential sub-feature coding and the normal sub-feature coding corresponding to the number of sub-feature codings, and obtains the corresponding feature identifier; According to the feature identifier, the weight coefficients corresponding to the potential sub-feature encoding and the normal sub-feature encoding are set and marked as α respectively. q λ and β z λ , where λ represents the corresponding feature identifier, and then the target weighting coefficient K corresponding to the target feature code is obtained according to the weighting coefficient, that is, the acquisition formula is; K=∑β z λ -∑α q λ ; Set a target weighting coefficient threshold K', and compare it with the target weighting coefficient: If K < K', then mark the feature coding corresponding to the source that can be jumped as the potential feature coding, intercept the corresponding target URL, generate the potential target URL and send it to the management module; If K≥K', the jumpable source is sent to the jump permission unit.

2. A vulnerability risk assessment and monitoring system for network security according to claim 1, characterized in that: The process of obtaining the precise abnormal coding feature data set includes: An abnormal feature code converter is set in the first vulnerability scanning channel to convert the feature identifier to generate a feature code; then the abnormal feature code corresponding to the abnormal feature identifier is obtained and stored in the corresponding structure data abnormal type data node set to generate an abnormal feature code data set; The abnormal feature coding training mechanism is used to perform data training on the abnormal feature coding data set; set a number of abnormal target URLs corresponding to abnormal feature identifiers, and transmit them to the first vulnerability scanning channel for conversion through the abnormal feature coding converter, generate corresponding abnormal feature codes, and match them with the abnormal feature coding data set, obtain the abnormal feature identifier corresponding to the abnormal feature code, and add the abnormal feature code to the abnormal feature coding data set corresponding to the corresponding abnormal feature identifier to generate an accurate abnormal feature coding feature data set.

3. A vulnerability risk assessment and monitoring system for network security according to claim 2, characterized in that: The process of the target scanning unit acquiring the jumpable source includes: The target URL is transmitted to the first vulnerability scanning channel. Based on the abnormal feature encoding converter, the feature identifier corresponding to the target URL is obtained and converted into a feature code. The feature code is matched with the precise abnormal encoding feature data set. If the match is successful, the corresponding target URL is intercepted, and the vulnerability target URL is generated and sent to the management module; otherwise, the source to be jumped is generated into a jumpable source and sent to the jump monitoring module.

4. A vulnerability risk assessment and monitoring system for network security according to claim 3, characterized in that: The process of the jump permission unit for obtaining the authorized jump source includes: Determine whether the target URL corresponding to the redirectable source exists in the authority database. If so, generate the redirectable source as an authorized redirect source and send it to the encrypted transmission module; Otherwise, an authorization request is sent to the management module.

5. A vulnerability risk assessment and monitoring system for network security according to claim 4, characterized in that: The process of the encrypted transmission module acquiring the encrypted jump user includes: Get the jump request corresponding to the authorized jump source, click the jump request to get the jump user, and then get the jump user authorization function corresponding to the jump user and send it to the third transmission encryption model; The third transmission encryption model is provided with an automatic closing mechanism and is wirelessly connected to a function database, and obtains a jump user authorization function and compares it with the function database. If it exists in the function database, the corresponding jump user authorization function is automatically closed; otherwise, the jump user authorization function is sent to the jump user interface to generate a confirmation log; A user confirmation mechanism is provided in the jump user interface for receiving and confirming the confirmation log; The jump user receives the confirmation log according to the user confirmation mechanism and manually judges the jump user authorization function, manually selects the jump user authorization function that needs to be closed and confirms it. If the confirmation is successful, the encrypted jump user is obtained and the jump is performed.

6. A vulnerability risk assessment and monitoring system for network security according to claim 5, characterized in that: The process of the target monitoring unit acquiring abnormal jump data includes: Send the jump user authorization function manually closed by the jump user through the user confirmation mechanism to the function database for storage; The jump user authorization function of the encrypted jump user during the jump process is obtained, and the abnormal jump data is obtained according to the function database and sent to the abnormal management unit.

7. A vulnerability risk assessment and monitoring system for network security according to claim 6, characterized in that: The process of managing abnormal jump data by the abnormal management unit includes: The exception management unit is used to receive and manage vulnerability target URLs, potential target URLs and abnormal jump data.

Citation Information

Patent Citations

  • Detection method and detection device for webpage redirection skip loophole

    CN102592089A

  • Method and system for acquiring downloading link of resources

    CN103530365A

  • Method and apparatus for detecting webpage redirection vulnerabilities

    CN104881603A