Intranet asset vulnerability scanning method, electronic equipment, storage medium and program product

By establishing a communication channel between the intranet and the cloud service platform, and using lightweight access terminals and the MQTT protocol to encrypt and forward traffic, the problem of the cloud service platform being unable to perform vulnerability scanning on intranet assets was solved, achieving secure and stable intranet asset scanning and reducing user costs.

CN119728215BActive Publication Date: 2025-10-24BEIJING TOPSEC NETWORK SECURITY TECH +2
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411849574.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-16
Publication Date
2025-10-24
Estimated Expiration
2044-12-16

AI Technical Summary

Technical Problem

In existing technologies, cloud service platforms cannot perform vulnerability scanning on intranet assets, and pure cloud solutions are limited by the network environment and cannot provide effective vulnerability scanning services.

Method used

A communication channel is established between the intranet and the cloud service platform through the access terminal. A lightweight access terminal is used to implement Socks 5 proxy, encrypt and forward traffic, and use the MQTT protocol to standardize communication. Online access terminals are selected for vulnerability scanning, and vulnerability scanners are pre-bound to enable scanning of intranet assets.

Benefits of technology

It enables cloud service platforms to perform vulnerability scanning on internal network assets, improving the security and stability of the scanning process, reducing user costs, and enhancing the service experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119728215B_ABST
    Figure CN119728215B_ABST
Patent Text Reader

Abstract

The application provides an internal network asset vulnerability scanning method, an electronic device, a storage medium and a program product. The method comprises the following steps: receiving a vulnerability scanning request; the vulnerability scanning request comprises to-be-scanned asset information, and the asset corresponding to the to-be-scanned asset information is an internal network asset; determining an access terminal based on the to-be-scanned asset information; the access terminal is used to realize the communication connection between a cloud service platform and the internal network; determining a vulnerability scanner on the cloud service platform according to the access terminal; sending vulnerability scanning traffic to the access terminal through the vulnerability scanner, so that the access terminal forwards the vulnerability scanning traffic to the asset corresponding to the to-be-scanned asset information, to realize the vulnerability scanning of the asset. Through the access terminal, the communication channel between the cloud service platform and the internal network asset is opened, so that the purpose of using the vulnerability scanner on the cloud service platform to perform the vulnerability scanning on the internal network asset is realized.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of computer security, in particular to an intranet asset vulnerability scanning method, an electronic device, a storage medium and a program product. BACKGROUND

[0002] With the increasing demand for digital transformation of enterprises, cloud services meet the needs of enterprises for efficient and convenient services with their flexibility, scalability and cost-effectiveness. Based on the development of the cloud service industry, the cloud service business model is becoming the mainstream trend of the security service industry.

[0003] However, due to the particularity of the security industry, such as the vulnerability scanning business of the intranet, the pure cloud solution is limited by the network environment and cannot provide vulnerability scanning services. SUMMARY

[0004] The purpose of the embodiments of the present application is to provide an intranet asset vulnerability scanning method, an electronic device, a storage medium and a program product, which can realize the scanning of the vulnerabilities of the intranet assets by the vulnerability scanner on the cloud service platform.

[0005] In a first aspect, the embodiments of the present application provide an intranet asset vulnerability scanning method applied to a cloud service platform, which comprises:

[0006] receiving a vulnerability scanning request; the vulnerability scanning request comprises asset information to be scanned, and the asset corresponding to the asset information to be scanned is an intranet asset;

[0007] determining an access terminal based on the asset information to be scanned; the access terminal is used to realize the communication connection between the cloud service platform and the intranet;

[0008] determining a vulnerability scanner on the cloud service platform according to the access terminal;

[0009] sending vulnerability scanning traffic to the access terminal through the vulnerability scanner, so as to realize the vulnerability scanning of the asset by forwarding the vulnerability scanning traffic to the asset corresponding to the asset information to be scanned by the access terminal.

[0010] The embodiments of the present application pass through the communication channel between the cloud service platform and the intranet asset through the access terminal, thereby realizing the purpose of scanning the vulnerabilities of the intranet assets by the vulnerability scanner on the cloud service platform.

[0011] In any embodiment, the method further comprises:

[0012] receiving a registration request sent by the access terminal, and the registration request comprises an access code;

[0013] Verify the access code, and if the verification is passed, open the socks 5 proxy channel, and open the access terminal's permission to the MQTT publish / subscribe topic of the server socks 5 proxy in the cloud service platform, to realize the communication between the server socks 5 proxy and the access terminal through the MQTT protocol;

[0014] Receive the registration completion information of the access terminal, and the registration completion information includes the basic information of the access terminal and the address information of the server socks 5 proxy corresponding to the access terminal;

[0015] Store the registration completion information.

[0016] The embodiment of the application specifies the communication protocol between the access terminal and the cloud service platform through the MQTT protocol, and uses the socks5 proxy to encrypt and forward the traffic between the access terminal and the cloud service platform, thereby improving the security in the vulnerability scanning process.

[0017] In any embodiment, the vulnerability scanner sends vulnerability scanning traffic to the access terminal, so that the access terminal forwards the vulnerability scanning traffic to the asset corresponding to the to-be-scanned asset information, including:

[0018] The vulnerability scanner sends the vulnerability scanning traffic to the access terminal based on the MQTT protocol through the server socks5 proxy, so that the access terminal forwards the vulnerability scanning traffic to the client socks 5 proxy through MQTT subscription, and the client socks 5 proxy forwards the vulnerability scanning traffic to the asset corresponding to the to-be-scanned asset information.

[0019] The embodiment of the application specifies the communication protocol between the access terminal and the cloud service platform through the MQTT protocol, and uses the socks5 proxy to encrypt and forward the traffic between the access terminal and the cloud service platform, thereby improving the security in the vulnerability scanning process.

[0020] In any embodiment, the method further includes:

[0021] Receive the heartbeat information sent by the access terminal that has successfully registered.

[0022] The embodiment of the application sends heartbeat information to the cloud service platform through the access terminal, so that the cloud service platform knows which access terminals are in a normal working state, and when performing vulnerability scanning, the access terminal in the normal working state can be selected, thereby improving the stability of vulnerability scanning.

[0023] In any embodiment, the access terminal is determined based on the to-be-scanned asset information, including:

[0024] Based on the received heartbeat information, one terminal in an online state is selected as the access terminal.

[0025] The embodiment of the application determines the online access terminal through the heartbeat information, and when performing the vulnerability scanning, the access terminal in the normal working state can be selected, thereby improving the stability of the vulnerability scanning.

[0026] In any embodiment, the method further comprises:

[0027] obtaining the terminal information of the vulnerability scanner resource on the cloud service platform and the terminal to be bound;

[0028] receiving a target vulnerability scanner selected from the vulnerability scanner resource;

[0029] associating and storing the target vulnerability scanner with the terminal information.

[0030] The embodiment of the application binds the terminal and the vulnerability scanner in advance, and when the access terminal is determined, the vulnerability scanner for performing the vulnerability scanning on the intranet asset can be quickly determined.

[0031] In any embodiment, the vulnerability scanner on the cloud service platform is determined according to the access terminal, comprising:

[0032] determining the vulnerability scanner having the binding relationship with the access terminal from the pre-stored binding relationship table.

[0033] The embodiment of the application can conveniently and quickly determine the vulnerability scanner through the pre-stored binding relationship table.

[0034] In a second aspect, the embodiment of the application provides an intranet asset vulnerability scanning method applied to an access terminal, the access terminal and the intranet asset to be scanned are in the same local area network; the method comprises:

[0035] receiving the vulnerability scanning traffic sent by the vulnerability scanner on the cloud service platform; the access terminal is determined by the cloud service platform based on the received vulnerability scanning request; the vulnerability scanner has the binding relationship with the access terminal;

[0036] sending the vulnerability scanning traffic to the intranet asset to be scanned, so as to perform the vulnerability scanning on the intranet asset to be scanned;

[0037] receiving the response information returned by the intranet asset to be scanned, and sending the response information to the vulnerability scanner.

[0038] The embodiment of the application passes through the access terminal to open the communication channel between the cloud service platform and the intranet asset, thereby achieving the purpose of performing the vulnerability scanning on the intranet asset by using the vulnerability scanner on the cloud service platform.

[0039] In any embodiment, the method further comprises:

[0040] sending a registration request to the cloud service platform, the registration request including an access code, so that the cloud service platform opens a socks 5 proxy channel and the right of the terminal to be accessed to publish / subscribe to a topic of a service end socks 5 proxy in the cloud service platform after verification based on the access code, to realize communication between the service end socks 5 proxy and the terminal to be accessed through the MQTT protocol;

[0041] after completing the registration, sending registration completion information to the cloud service platform, the registration completion information including basic information of the terminal to be accessed and address information of the service end socks 5 proxy corresponding to the terminal to be accessed, so that the cloud service platform stores the registration completion information;

[0042] receiving information of successful access sent by the cloud service platform.

[0043] The application embodiment specifies the communication protocol between the access terminal and the cloud service platform through the MQTT protocol, adopts the socks5 proxy to encrypt and forward the traffic between the access terminal and the cloud service platform, and improves the security in the vulnerability scanning process.

[0044] In any embodiment, the access terminal receives vulnerability scanning traffic sent by the cloud service platform through the vulnerability scanner, including:

[0045] The vulnerability scanning traffic sent by the service end socks 5 proxy based on the MQTT protocol is received through the client end socks 5 proxy;

[0046] The vulnerability scanning traffic is sent to the internal network asset to be scanned, including:

[0047] The vulnerability scanning traffic is sent to the internal network asset to be scanned through the client end socks 5 proxy.

[0048] The application embodiment specifies the communication protocol between the access terminal and the cloud service platform through the MQTT protocol, adopts the socks5 proxy to encrypt and forward the traffic between the access terminal and the cloud service platform, and improves the security in the vulnerability scanning process.

[0049] In any embodiment, the access terminal is a lightweight access terminal.

[0050] The application embodiment opens the communication channel between the cloud service platform and the internal network asset through the lightweight access terminal, reduces the cost of the user, and improves the service experience.

[0051] In a third aspect, the application embodiment provides an internal network asset vulnerability scanning device applied to a cloud service platform, and the device includes:

[0052] The request receiving module is configured to receive a vulnerability scanning request; the vulnerability scanning request comprises asset information to be scanned, and the asset corresponding to the asset information to be scanned is an intranet asset;

[0053] The terminal determining module is configured to determine an access terminal based on the asset information to be scanned; the access terminal is configured to realize communication connection between the cloud service platform and the intranet;

[0054] The scanner determining module is configured to determine a vulnerability scanner on the cloud service platform according to the access terminal.

[0055] The flow sending module is configured to send, to the access terminal, vulnerability scanning flow through the vulnerability scanner, so that the access terminal forwards the vulnerability scanning flow to the asset corresponding to the asset information to be scanned, to realize vulnerability scanning on the asset.

[0056] In a fourth aspect, an embodiment of the present application provides another intranet asset vulnerability scanning device, which is applied to an access terminal, the access terminal and an intranet asset to be scanned are in the same local area network; the device comprises:

[0057] The flow receiving module is configured to receive vulnerability scanning flow sent by the cloud service platform through the vulnerability scanner; the access terminal is determined by the cloud service platform based on the received vulnerability scanning request; the vulnerability scanner has a binding relationship with the access terminal.

[0058] The flow forwarding module is configured to send the vulnerability scanning flow to the intranet asset to be scanned, to realize vulnerability scanning on the intranet asset to be scanned.

[0059] The response information receiving module is configured to receive response information returned by the intranet asset to be scanned, and send the response information to the vulnerability scanner.

[0060] In a fifth aspect, an embodiment of the present application provides an electronic device, comprising a processor, a memory and a bus, wherein,

[0061] The processor and the memory complete mutual communication through the bus;

[0062] The memory stores program instructions executable by the processor, and the processor calling the program instructions can execute the method of the first aspect or the second aspect.

[0063] In a sixth aspect, an embodiment of the present application provides a non-transitory computer readable storage medium, comprising:

[0064] The non-transitory computer readable storage medium stores computer instructions, and the computer instructions make the computer execute the method of the first aspect or the second aspect.

[0065] In a seventh aspect, an embodiment of the present application provides a computer program product, comprising computer program instructions, which, when read and executed by a processor, perform the method of the first aspect or the second aspect.

[0066] In an eighth aspect, an embodiment of the present application provides an internal network asset vulnerability scanning system, comprising a cloud service platform and an access terminal; the cloud service platform and the access terminal are in communication connection; the access terminal and the internal network asset to be scanned are in the same local area network;

[0067] The cloud service platform is configured to perform the method of the first aspect;

[0068] The access terminal is configured to perform the method of the second aspect.

[0069] Other features and advantages of the present application will be described in the following description, and some will become apparent from the description, or will be learned through practice of the application. The purpose and other advantages of the present application can be achieved and obtained by the structure specifically pointed out in the written description, claims, and drawings. BRIEF DESCRIPTION OF DRAWINGS

[0070] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings needed to be used in the embodiments of the present application. It should be understood that the following drawings only show some embodiments of the present application, and therefore should not be regarded as limiting the scope. For those skilled in the art, other related drawings can also be obtained without creative labor on the basis of these drawings.

[0071] Figure 1 A flowchart of an internal network asset vulnerability scanning method provided by an embodiment of the present application is shown in the figure;

[0072] Figure 2 A flowchart of an access terminal accessing a cloud service platform provided by an embodiment of the present application is shown in the figure;

[0073] Figure 3 A flowchart of a vulnerability scanning traffic forwarding provided by an embodiment of the present application is shown in the figure;

[0074] Figure 4 A flowchart of an access terminal and a vulnerability scanner binding method provided by an embodiment of the present application is shown in the figure;

[0075] Figure 5 A flowchart of another internal network asset vulnerability scanning method provided by an embodiment of the present application is shown in the figure;

[0076] Figure 6 A flowchart of another internal network asset vulnerability scanning method provided by an embodiment of the present application is shown in the figure;

[0077] Figure 7A flowchart of a method for scanning vulnerabilities of internal network assets in a specific scenario according to an embodiment of the present application is provided.

[0078] Figure 8 A structural diagram of a device for scanning vulnerabilities of internal network assets according to an embodiment of the present application is provided.

[0079] Figure 9 A structural diagram of another device for scanning vulnerabilities of internal network assets according to an embodiment of the present application is provided.

[0080] Figure 10 A structural diagram of an electronic device according to an embodiment of the present application is provided. DETAILED DESCRIPTION

[0081] The embodiments of the technical solutions of the present application will be described in detail below with reference to the drawings. The following embodiments are only used to more clearly illustrate the technical solutions of the present application, and therefore only serve as examples, and cannot limit the protection scope of the present application.

[0082] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs; the terms used herein are only for the purpose of describing specific embodiments and are not intended to limit the present application; the terms "include" and "have" and any variations thereof in the specification and claims of the present application and the above description of drawings are intended to cover non-exclusive inclusion.

[0083] In the description of the embodiments of the present application, the technical terms "first", "second", etc. are only used to distinguish different objects, and cannot be understood as indicating or implying relative importance or implicitly indicating the number, specific order or primary and secondary relationship of the indicated technical features. In the description of the embodiments of the present application, the meaning of "a plurality of" is two or more, unless otherwise explicitly and specifically limited.

[0084] In this document, the term "embodiment" means that the specific features, structures or characteristics described in connection with the embodiment can be included in at least one embodiment of the present application. The appearance of this phrase in various places in the specification does not necessarily mean the same embodiment, nor is it independent or alternative to other embodiments. The skilled person in the art explicitly and implicitly understands that the embodiments described herein can be combined with other embodiments.

[0085] In the description of the embodiments of the present application, the term "and / or" is only a description of the association relationship between the associated objects, which means that there can be three relationships, for example, A and / or B, which can represent the three cases of A alone, A and B together, and B alone. In addition, the character " / " in this document generally represents a "or" relationship between the front and rear associated objects.

[0086] In the description of the embodiments of the present application, the term "a plurality of" refers to two or more (including two), and similarly, "a plurality of groups" refers to two or more groups (including two groups), and "a plurality of pieces" refers to two or more pieces (including two pieces).

[0087] In the description of the embodiments of the present application, unless otherwise explicitly specified and limited, the technical terms "mounting", "connection", "connecting", "fixing" and the like should be understood in a broad sense, for example, can be fixedly connected, or can be detachably connected, or can be integrated; can be mechanically connected, or can be electrically connected; can be directly connected, or can be indirectly connected through an intermediate medium; can be the internal communication of two elements or the interaction relationship between two elements. For those skilled in the art, the specific meanings of the above terms in the embodiments of the present application can be understood according to the specific circumstances.

[0088] In order to facilitate the understanding of the scheme of the present application, the related terms involved will now be explained:

[0089] MQTT protocol (Message Queuing Telemetry Transport): a "lightweight" message protocol based on the publish / subscribe paradigm, which is built on the TCP / IP protocol.

[0090] The working principle of the MQTT protocol is based on the publish / subscribe model, and devices (clients) publish data to specific Topics (topics), and other devices (servers) can subscribe to these Topics to receive data. The three key roles in the MQTT protocol include:

[0091] Publisher: responsible for publishing messages to specific Topics.

[0092] Subscriber: receives messages by subscribing to specific Topics.

[0093] Broker: located between the publisher and the subscriber, responsible for receiving the publisher's messages and forwarding them to the corresponding subscriber according to the subscriber's subscription information.

[0094] Access specification: a specification for terminal device access to the cloud based on the MQTT protocol, describing the transmission data format, MQTT Topic specification, etc.

[0095] Broker specification: a Socks 5 proxy specification based on the MQTT protocol, describing the transmission data format, MQTT Topic specification, etc.

[0096] Cloud service platform: an online service platform that provides secure business capabilities, with characteristics such as super large scale, high reliability and universality. A vulnerability scanning resource pool is set up in the cloud service platform.

[0097] Vulnerability scanning resource pool: a resource pool composed of multiple vulnerability scanners, located in the cloud, capable of providing comprehensive scanning capabilities, covering different types of security vulnerability detection, to improve the overall security protection level.

[0098] Vulnerability scanning resource group: composed of multiple vulnerability scanners selected from the vulnerability scanning resource pool.

[0099] Vulnerability scanner: a security tool used to automatically detect security vulnerabilities in computer systems, networks or web applications, helping users identify and fix potential security threats. The scanner needs to support Socks 5 proxy.

[0100] Lightweight vulnerability scanning terminal: a lightweight vulnerability scanning terminal, its main function is to establish a secure communication channel between the cloud and the internal network assets, and through the Socks 5 proxy function to realize the encrypted transmission of data, to ensure the security of communication, but not directly with scanning capabilities.

[0101] Socks 5 (Socket Secure version 5) proxy: a protocol for proxy server handling data traffic, routing Internet traffic through a proxy server. The proxy server generates a random IP address before reaching the destination, acting as an intermediary between the client and the server, forwarding the client's request to the server on the Internet, thereby achieving relay transmission of data. In this process, the user's real IP address is hidden, enhancing privacy protection.

[0102] Due to the security of internal network assets, the cloud service platform can usually only perform vulnerability scanning on assets on the public network, and cannot perform vulnerability scanning on internal network assets. To solve this problem, the embodiments of the present application provide a method for scanning vulnerabilities of internal network assets, which uses an access terminal in the same local area network as the internal network to open up the communication channel between the cloud service platform and the internal network assets, thereby realizing vulnerability scanning of internal network assets using the cloud service platform.

[0103] Figure 1 A flowchart of a method for scanning vulnerabilities of internal network assets provided by the embodiments of the present application is shown in Figure 1As shown, the method is applied to a cloud service platform. The cloud service platform is an Internet-based computing service that helps enterprises and individuals quickly build, deploy, and manage applications and data by providing computing, storage, network, and other infrastructure and services. The embodiments of the present application can provide network resources, storage resources, computing resources, vulnerability scanning resources, etc. to customers in the manner of SaaS cloud services. Customers only need to access the application through the network, without the need to install and maintain software locally. It should be noted that the embodiments of the present application can also be applied to other types of cloud service platforms, such as IaaS, PaaS, etc.

[0104] The method comprises:

[0105] Step 101: receiving a vulnerability scanning request.

[0106] The vulnerability scanning request comprises to-be-scanned asset information, the asset corresponding to the to-be-scanned asset information is an intranet asset, and the to-be-scanned asset information is used to indicate which intranet asset the cloud service platform is to scan, for example, it can be a web address, or an IP address or MAC address of a certain host, etc. A user can log in to the cloud service platform, enter the to-be-scanned asset information in the vulnerability scanning task management of the cloud service platform, and then the cloud service platform generates a vulnerability scanning request for the user.

[0107] Step 102: determining an access terminal based on the to-be-scanned asset information; the access terminal is used to realize the communication connection between the cloud service platform and the intranet.

[0108] The access terminal is accessed to the intranet and is in the same local area network as the to-be-scanned asset. The access terminal can be a normal terminal, for example, a PC, a notebook computer, a tablet computer, a wearable device, etc.; or a lightweight terminal, for example, a USB flash disk, or even an executable file. If it is a USB flash disk, it can be plugged into one of the servers or hosts in the intranet, and if it is an executable file, it can be run on one of the servers or hosts in the intranet. The lightweight terminal implements Socks 5 proxy according to the communication access specification of the cloud service platform, and the specific protocol specification will be introduced in the terminal access sub-process. The lightweight terminal form can be a pluggable USB flash disk or an executable file, and the terminal size is controlled as much as possible, which can be implemented by python, go, etc. The terminal itself does not have scanning capability, but only maintains a safe and reliable Socks 5 proxy channel based on the MQTT protocol, which is used to proxy and forward the vulnerability scanning request of the cloud scanner, breaking the separation between the cloud and the intranet.

[0109] Since there can be multiple access terminals connected to the intranet, and the access terminal can be removed from the intranet at any time, the cloud service platform determines the intranet corresponding to the asset to be scanned after receiving the vulnerability scanning request, and obtains the access terminal in the online state in the intranet. If there are multiple access terminals in the online state, any one of them can be selected.

[0110] It should be noted that the access terminal is pre-verified by the cloud service platform for security, and the registration is completed. The access terminal that passes the security verification and completes the registration can communicate with the cloud service platform, receive data from the cloud service platform, and forward it to the intranet, and also can forward the data of the intranet to the cloud service platform.

[0111] Step 103: Determine the vulnerability scanner on the cloud service platform according to the access terminal.

[0112] In the specific implementation process, the vulnerability scanner resource pool is a collection of vulnerability scanners built in the cloud, which provides vulnerability scanning services for users using the resource pool. The main features are sufficient computing power, cloud centralized management, and distributed vulnerability scanning capability, which avoids using local computing resources and reduces the user's own operation and maintenance cost.

[0113] The vulnerability scanner can be a single vulnerability scanner in the vulnerability scanning resource pool, or one of the vulnerability scanners in the vulnerability scanning resource group in the vulnerability scanning resource pool. Each access terminal can be pre-bound to a vulnerability scanner or a vulnerability scanning resource group in the cloud service platform. After the access terminal is determined, the vulnerability scanner used for vulnerability scanning of the intranet asset can be located according to the binding relationship.

[0114] The cloud service platform can also temporarily allocate a vulnerability scanner for the access terminal after receiving the vulnerability scanning request and determining the access terminal. The allocated vulnerability scanner is bound to the access terminal. When allocating the vulnerability scanner, the type of vulnerability to be scanned, the scanning load of the vulnerability scanner, etc. can be selected. After completing the scanning of the intranet asset, the binding relationship between the access terminal and the vulnerability scanner can be released.

[0115] Step 104: Send the vulnerability scanning traffic to the access terminal through the vulnerability scanner, so that the access terminal forwards the vulnerability scanning traffic to the asset corresponding to the asset information to be scanned, to realize the vulnerability scanning of the asset.

[0116] After the vulnerability scanner is determined, the vulnerability scanner sends the vulnerability scanning traffic to the access terminal. After receiving the vulnerability scanning traffic, the access terminal forwards the vulnerability scanning traffic to the corresponding intranet asset to realize the vulnerability scanning of the intranet asset.

[0117] The embodiment of the present application opens a communication channel between the cloud service platform and the intranet assets through the access terminal, thereby achieving the purpose of using the vulnerability scanner on the cloud service platform to scan the intranet assets for vulnerabilities. In addition, since the access terminal and the intranet assets are in the same local area network, the access terminal is considered to be trustworthy, thereby meeting the security requirements of the intranet assets.

[0118] Based on the above embodiment, the method further includes:

[0119] Receive a registration request sent by a waiting terminal, the registration request including an access code;

[0120] Verify the access code and, if the verification is successful, open the socks 5 proxy channel and enable the permission for the MQTT publish / subscribe topic between the terminal to be connected and the server-side socks 5 proxy in the cloud service platform, so as to achieve communication between the server-side socks 5 proxy and the terminal to be connected through the MQTT protocol;

[0121] Receive registration completion information of the waiting terminal, which includes basic information of the waiting terminal and address information of the server-side socks 5 proxy corresponding to the waiting terminal;

[0122] The registration completion information is stored.

[0123] Among them, the MQTT protocol constraints are as follows:

[0124] 1. MQTT needs to use TLS / SSL security protocol encryption, which protects network communications from eavesdropping and tampering by using encryption algorithms to ensure the security of data transmission;

[0125] 2. Use certificates to implement bidirectional authentication between the client and server, ensuring the trustworthiness of the terminals. Both parties possess a pair of public and private keys. When establishing a connection, both parties exchange certificates and verify each other's certificates to ensure that both communicating parties are authenticated and trusted entities.

[0126] 3. The data transmission service quality must be QoS 2 to ensure the reliability of data transmission. QoS 2 is the service quality specified by the MQTT protocol, and 2 is the best level to ensure successful data release.

[0127] 4. MQTT channel transmission data adopts Protocol Buffers (v3) data format, which effectively reduces the transmission volume (after serialization, it saves 90% of space compared to JSON and binary), and the structure is platform-independent and applicable.

[0128] Figure 2 A schematic diagram of a process of accessing a cloud service platform provided by an access terminal in an embodiment of the present application is shown as follows: Figure 2 Shown, including:

[0129] Step 201: terminal initialization, start socks5 proxy service;

[0130] Step 202: terminal initiates a registration request; after the terminal completes initialization, a lightweight executable program implemented in Python or Go language can be used. The user applies for a terminal access code (i.e. authentication information) on the cloud service platform. The terminal access code has a valid period and is bound to the user information (using the user's employee number, etc.). The terminal carries the authentication information and the collected basic information of the server where the terminal is located (terminal type, MAC address, server type, terminal unique code, etc., the terminal unique code is used to distinguish the terminal without repetition) and initiates a registration request to the cloud service platform through the MQTT protocol, and starts the local Socks 5 proxy service.

[0131] Step 203: cloud service platform access authentication; after the registration request reaches the cloud service platform, the cloud service terminal authentication module verifies whether the access code is legal. The verification includes checking the access code format, whether the access code is within the valid period, whether the terminal type is compliant, etc. to ensure that the terminal is legal and effective. If not, the registration fails. If it is legal, it enters the Socks 5 proxy dedicated channel opening process.

[0132] Step 204: open socks5 proxy dedicated channel; after successful access verification, the cloud service platform opens the MQTT Topic publishing / subscription permission required by the terminal and the server Socks 5 proxy; the terminal and the server Socks 5 proxy are allowed to access the corresponding Topic for data publishing and subscribing. The Topic naming specification carries the terminal unique code to distinguish the Topic of different terminals and realize Topic isolation for data transmission.

[0133] Step 205: start socks5 service; after the MQTT Socks 5 Topic permission is opened, the server will start a Socks 5 proxy, the port is random, and the Socks 5 service is exposed to the outside. Since the number of ports is limited, K8s and other technical solutions can be used to realize multiple IP methods.

[0134] Step 206: server starts listening to socks5 MQTT Topic; after the Socks 5 is started, the cloud needs to open the MQTT Topic publishing / subscription required by the Socks 5 proxy, which is used to forward the traffic of the server Socks 5 service interface to the terminal through MQTT, and return the response traffic sent by the terminal to the server Socks 5 service. In this way, Socks 5 over MQTT protocol is realized. The user of Socks 5 cannot perceive the existence of MQTT.

[0135] Step 207: Terminal registration: The waiting terminal records basic terminal information and exclusive channel information, and sends a registration completion message to the cloud service platform.

[0136] Step 208: The cloud service platform notifies the terminal to open an MQTT socks5 channel. The cloud service platform notifies the waiting terminal via the MQTT protocol that access has been successful and can enable the MQTT topic publish / subscribe required by the client-side Socks 5 proxy. At this point, the waiting terminal can be referred to as an access terminal. In this way, the client-side socks5 on the access terminal can subscribe to the socks 5 traffic sent by the cloud service platform to the client-side socks5 proxy service, and send the client-side socks5 proxy service's response to the server-side socks5 proxy service via MQTT.

[0137] Step 209: Continuously maintain the terminal online status; the access terminal regularly sends heartbeat information to the cloud service platform to determine whether the access terminal is online. If the cloud service platform does not receive the heartbeat information sent by the access terminal within a preset time, the access terminal is considered offline.

[0138] The embodiment of the present application standardizes the communication protocol between the access terminal and the cloud service platform through the MQTT protocol, and adopts the socks5 proxy to encrypt and forward the traffic between the access terminal and the cloud service platform, thereby improving the security during the vulnerability scanning process.

[0139] Based on the above embodiment, the vulnerability scanner sends vulnerability scanning traffic to the access terminal, so that the access terminal forwards the vulnerability scanning traffic to the asset corresponding to the asset information to be scanned, including:

[0140] The vulnerability scanner sends vulnerability scanning traffic to the access terminal through the server-side sock5 proxy based on the MQTT protocol, so that the access terminal subscribes to the vulnerability scanning traffic through MQTT and forwards the vulnerability scanning traffic to the client-side socks 5 proxy, so that the client-side socks 5 proxy forwards the vulnerability scanning traffic to the asset corresponding to the asset information to be scanned.

[0141] In the specific implementation process, Figure 3 A schematic diagram of vulnerability scanning traffic forwarding provided in an embodiment of the present application is shown as follows: Figure 3After the access terminal completes registration, the client-side socks5 proxy service is started on the intranet side, the server-side socks5 proxy service is started on the cloud service platform side, and the vulnerability scanner forwards the vulnerability scanning traffic to the access terminal through the server-side socks5 proxy. In the forwarding process, the MQTT protocol specification is followed. The access terminal sends the vulnerability scanning traffic to the client-side socks5 proxy service through MQTT subscription, and the client-side socks5 proxy service sends the vulnerability scanning traffic to the intranet resource, and the intranet resource is scanned for vulnerabilities. It can be understood that the scanning result data is also forwarded to the server-side socks5 proxy service through the client-side socks5 proxy, and then the server-side socks5 proxy sends the scanning result data to the vulnerability scanner.

[0142] The embodiment of the application regulates the communication protocol between the access terminal and the cloud service platform through the MQTT protocol, uses the socks5 proxy to encrypt and forward the traffic between the access terminal and the cloud service platform, improves the security in the vulnerability scanning process, and uses the cloud service mode of heavy cloud and light client to realize vulnerability scanning of intranet assets, reduces user cost, and improves cloud service experience.

[0143] On the basis of the above embodiment, the method further comprises:

[0144] Obtaining vulnerability scanner resources on the cloud service platform and terminal information of a terminal to be bound;

[0145] Receiving a target vulnerability scanner selected from the vulnerability scanner resources;

[0146] Associating and storing the target vulnerability scanner with the terminal information.

[0147] In the specific implementation process, the binding of the access terminal and the vulnerability scanner is to associate and bind the lightweight terminal with a resource group or a specific scanner in the resource pool of the cloud vulnerability scanner, and the bound scanner can realize intranet vulnerability scanning through the Socket5 channel of the terminal. Figure 4 The access terminal and vulnerability scanner binding method provided by the embodiment of the application is shown in Figure 4 .

[0148] Comprise:

[0149] Step 401: Obtain scanner resources; obtain cloud vulnerability scanning resource groups, vulnerability scanners, and terminal information, wherein the vulnerability scanning resource groups and the vulnerability scanners are both distinguished by types, some of the vulnerability scanning resource groups and the vulnerability scanners are used for scanning web assets, some of the vulnerability scanning resource groups and the vulnerability scanners are used for scanning host assets, and the like. The vulnerability scanning resource group is composed of multiple independent vulnerability scanners, and can exert parallel capability and improve the efficiency of vulnerability scanning.

[0150] Step 402: Obtain terminal information; obtain basic information of the access terminal and a corresponding server socks 5 address, the server socks 5 address is one-to-one with the access terminal. The basic information of the access terminal can include terminal type, MAC address, terminal unique code, and the like.

[0151] Step 403: Determine whether the terminal is online; the cloud service platform determines whether the access terminal is online according to the received heartbeat information, if the access terminal to be bound is in an online state, step 404 can be executed; otherwise, the binding process is ended.

[0152] Step 404: Bind the terminal and the scanner relationship; the user logs in the cloud service platform, selects the vulnerability scanner to be bound with the access terminal, and binds the two, specifically, the binding method can be to associate the primary keys through a relationship table. The binding relationship of the two can also be stored in a binding relationship table.

[0153] Step 405: Monitor the terminal state and determine whether the binding relationship is available; if the terminal is offline, it indicates that the binding relationship cannot be used, and the vulnerability scanner cannot forward the vulnerability scanning traffic to the intranet asset through the access terminal.

[0154] The embodiment of the application binds the terminal and the vulnerability scanner in advance, and when the access terminal is determined, the vulnerability scanner for scanning the intranet asset can be quickly determined.

[0155] After the binding of the access terminal and the vulnerability scanner is completed, when the access terminal is determined, the vulnerability scanner having the binding relationship with the access terminal can be determined from the pre-stored binding relationship table. The embodiment of the application can conveniently and quickly determine the vulnerability scanner through the pre-stored binding relationship table.

[0156] Figure 5 Another intranet asset vulnerability scanning method provided by the embodiment of the application is shown in a flowchart as shown in Figure 5 The method is applied to an access terminal, the access terminal and the intranet asset to be scanned are in the same local area network, and the access terminal is pre-registered in a cloud service platform. It can be understood that the access terminal can be a normal terminal or a lightweight terminal. The method comprises the following steps.

[0157] Step 501: receiving the vulnerability scanning traffic sent by the cloud service platform through the vulnerability scanner; the access terminal being determined by the cloud service platform based on the received vulnerability scanning request; the vulnerability scanner having a binding relationship with the access terminal;

[0158] Step 502: sending the vulnerability scanning traffic to the internal network asset to be scanned, so as to implement vulnerability scanning on the internal network asset to be scanned;

[0159] Step 503: receiving the response information returned by the internal network asset to be scanned, and sending the response information to the vulnerability scanner.

[0160] In the specific implementation process, the user enters the asset information to be scanned in the vulnerability scanning task management of the cloud service platform, and then the cloud service platform generates a vulnerability scanning request for it. The cloud service platform filters the available access terminals based on the vulnerability scanning request, and determines the access terminal, and then determines the vulnerability scanner having a binding relationship with the access terminal according to the access terminal. The cloud service platform sends a vulnerability scanning task to the vulnerability scanner, and the vulnerability scanner sends vulnerability scanning traffic to the internal network asset to be scanned, which is used for vulnerability scanning on the internal network asset. When sending the vulnerability scanning traffic, the vulnerability scanner first sends the vulnerability scanning traffic to the access terminal, and the access terminal forwards the vulnerability scanning traffic to the internal network asset. In addition, the access terminal can also forward the response information of the internal network asset to the vulnerability scanner.

[0161] The embodiment of the application passes through the access terminal to open the communication channel between the cloud service platform and the internal network asset, thereby achieving the purpose of using the vulnerability scanner on the cloud service platform to scan the vulnerability of the internal network asset.

[0162] On the basis of the above embodiment, a registration request is sent to the cloud service platform, the registration request including an access code, so that the cloud service platform opens the socks 5 proxy channel after passing the access code verification, and opens the permission of the topic of the MQTT publish / subscribe of the access terminal and the server socks 5 proxy in the cloud service platform, so as to realize the communication between the server socks 5 proxy and the access terminal through the MQTT protocol;

[0163] After completing the registration, registration completion information is sent to the cloud service platform, the registration completion information including the basic information of the access terminal and the address information of the server socks 5 proxy corresponding to the access terminal, so that the cloud service platform stores the registration completion information;

[0164] Receiving information sent by the cloud service platform that the access is successful.

[0165] It should be noted that the specific process of terminal access to the cloud service platform can be referred to the above embodiment, which will not be described here.

[0166] The embodiment of the application regulates the communication protocol between the access terminal and the cloud service platform through the MQTT protocol, adopts the socks5 proxy to encrypt and forward the traffic between the access terminal and the cloud service platform, and improves the security in the vulnerability scanning process.

[0167] On the basis of the above embodiment, the receiving cloud service platform sends the vulnerability scanning traffic of the vulnerability scanner, including:

[0168] The vulnerability scanning traffic sent by the vulnerability scanner based on the MQTT protocol through the server socks 5 proxy is received through the client socks 5 proxy;

[0169] The vulnerability scanning traffic is sent to the internal network asset to be scanned, including:

[0170] The vulnerability scanning traffic is sent to the internal network asset to be scanned through the client socks 5 proxy.

[0171] It should be noted that the specific process of the access terminal receiving the vulnerability scanning traffic can be referred to the above embodiment, which will not be repeated here.

[0172] The embodiment of the application regulates the communication protocol between the access terminal and the cloud service platform through the MQTT protocol, adopts the socks5 proxy to encrypt and forward the traffic between the access terminal and the cloud service platform, and improves the security in the vulnerability scanning process.

[0173] Figure 6 Another internal network asset vulnerability scanning method process provided by the embodiment of the application is shown in FIG. 6, which includes: Figure 6

[0174] Step 601: Create a scanning task; the user logs in to the cloud service platform, enters the asset information to be scanned in the cloud service platform, which can be the web address of the internal network. The scanning task is created based on the entered asset information to be scanned.

[0175] Step 602: Select a vulnerability scanning terminal; obtain the registered terminal data, verify whether the terminal device is online, whether the vulnerability scanner is bound, and whether the server socks 5 service is available, select an access terminal that is online, has bound the vulnerability scanner, and has available server socks 5 service.

[0176] ​Step 603: issue a scanning task to the vulnerability scanner and specify the proxy egress address; the cloud service platform will match the selected terminal device to the bound vulnerability scanner or scanner resource group for task issuance, and specify the scanner to use the terminal-associated server Socks5 proxy for scanning when issuing the task. The scanner resource group can use a distributed method to select the specific vulnerability scanner, implement task load balancing, and improve scanning performance.

[0177] Step 604: perform vulnerability scanning through the terminal proxy channel; the vulnerability scanning traffic will be forwarded to the access terminal through the server Socks5 based on the MQTT protocol, the access terminal will forward the traffic to the client Socks5 service through MQTT subscription, so as to realize vulnerability scanning of the cloud vulnerability scanner on the user's internal network.

[0178] Step 605: scan result management; the scan result is forwarded to the server Socks5 service through the client Socks5 response traffic via MQTT, and finally returned to the vulnerability scanning server and stored in the cloud service platform.

[0179] Figure 7 A specific scenario-based internal network asset vulnerability scanning method flowchart provided by the embodiment of the present application is shown in FIG. 1, and the embodiment of the present application can be applied to provide a cloud service version vulnerability scanning business, and SaaS cloud service is used to reduce local computing resources and realize user internal network vulnerability scanning service. Figure 7

[0180] In the cloud service vulnerability scanning business, the user can install a lightweight access terminal A in the internal network environment, which can be a small executable program. The access terminal can obtain an access code through cloud service terminal management, register and access the access terminal based on the access code, and after successful registration, the user can view the terminal A in the terminal management. At this time, the terminal A is built-in with a client Socks5 service that only itself can access, and the corresponding server Socks5 service corresponding to the access terminal A is provided on the server.

[0181] The user binds the access terminal A and the vulnerability scanner resource in the terminal management, and binds the access terminal A and the vulnerability scanner B (or the vulnerability scanner resource group) through logical association. The specific vulnerability scanner can be quickly determined through the access terminal, and if it is a resource group, a vulnerability scanner can be determined by using load balancing or polling strategy.

[0182] ​The user enters the internal network asset to be scanned and creates a scanning task in the vulnerability scanning task management, selects the access terminal A when issuing the task, at this time, the platform quickly locates to the vulnerability scanner B according to the selected terminal, and simultaneously acquires the server Socks 5 address corresponding to the terminal A, and carries the above parameters to issue to the vulnerability scanner (the vulnerability scanner needs to support Socks5 proxy).

[0183] The vulnerability scanner scanning task flow passes through the server Socks 5->MQTT->client Socks5, and is finally forwarded to the internal network, so as to realize the scanning of the internal network asset by using the cloud vulnerability scanning resource, and the scanning result is summarized to the cloud service platform, and the user can view the scanning result through the cloud service platform.

[0184] The embodiment of the application has the following beneficial effects:

[0185] Unified communication protocol: the network channel required by the vulnerability scanning can be constructed on the basis of the cloud service Internet of Things MQTT communication protocol, and the protocol is unchanged;

[0186] Lightweight access terminal: the lightweight access terminal is adopted to facilitate and quickly open the network channel of the cloud service and the internal network, and the cost of use of the user is reduced by using this way;

[0187] Small local resource consumption: the cloud is used to construct the vulnerability scanning server resource pool to provide the computing resource, the use and resource cost of the user side are reduced, and the real cloud service experience is brought to the user;

[0188] The vulnerability scanning service of the internal network based on the cloud service: the barrier between the internal network and the Internet is broken, and the vulnerability scanning service of the internal network can be provided for the cloud service platform.

[0189] Figure 8 A structure diagram of an internal network asset vulnerability scanning device provided by the embodiment of the application, the device can be a module, a program segment or code on an electronic device. It should be understood that the device corresponds to the method embodiment described above, can execute each step involved in the method embodiment, and the specific functions of the device can be referred to the description in the above, and the detailed description is appropriately omitted here to avoid repetition. The device includes a request receiving module 801, a terminal determining module 802, a scanner determining module 803 and a flow sending module 804, wherein: Figure 1 Figure 1 The request receiving module 801 is configured to receive a vulnerability scanning request; the vulnerability scanning request includes to-be-scanned asset information, and the asset corresponding to the to-be-scanned asset information is an internal network asset;

[0190] The request receiving module 801 is configured to receive a vulnerability scanning request; the vulnerability scanning request includes to-be-scanned asset information, and the asset corresponding to the to-be-scanned asset information is an internal network asset;

[0191] ​The terminal determination module 802 is configured to determine an access terminal based on the asset information to be scanned; and the access terminal is configured to realize the communication connection between the cloud service platform and the intranet.

[0192] The scanner determination module 803 is configured to determine a vulnerability scanner on the cloud service platform according to the access terminal.

[0193] The flow sending module 804 is configured to send the vulnerability scanning flow to the access terminal through the vulnerability scanner, so that the access terminal forwards the vulnerability scanning flow to the asset corresponding to the asset information to be scanned, to realize the vulnerability scanning on the asset.

[0194] On the basis of the above-mentioned embodiments, the device further comprises a first registration module configured to:

[0195] receive a registration request sent by the access terminal, wherein the registration request comprises an access code;

[0196] verify the access code, and in the case of passing the verification, open a socks 5 proxy channel, and open the permission of the topic of the MQTT publishing / subscription of the access terminal and a server socks 5 proxy in the cloud service platform, to realize the communication between the server socks 5 proxy and the access terminal through the MQTT protocol;

[0197] receive registration completion information of the access terminal, wherein the registration completion information comprises basic information of the access terminal and address information of the server socks 5 proxy corresponding to the access terminal;

[0198] store the registration completion information.

[0199] On the basis of the above-mentioned embodiments, the flow sending module 804 is specifically configured to:

[0200] The vulnerability scanner sends the vulnerability scanning flow to the access terminal based on the MQTT protocol through the server socks 5 proxy, so that the access terminal subscribes to the vulnerability scanning flow through the MQTT, forwards the vulnerability scanning flow to a client socks 5 proxy, and makes the client socks 5 proxy forward the vulnerability scanning flow to the asset corresponding to the asset information to be scanned.

[0201] On the basis of the above-mentioned embodiments, the device further comprises a heartbeat information receiving module configured to:

[0202] receive heartbeat information sent by the access terminal which has successfully registered.

[0203] On the basis of the above-mentioned embodiments, the terminal determination module 802 is specifically configured to:

[0204] Based on the received heartbeat information, one terminal in the online state is selected as the access terminal.

[0205] On the basis of the above-mentioned embodiments, the device further comprises a binding module for:

[0206] Obtaining vulnerability scanner resources on the cloud service platform and terminal information of the terminal to be bound;

[0207] Receiving a target vulnerability scanner selected from the vulnerability scanner resources;

[0208] Associating the target vulnerability scanner with the terminal information and storing.

[0209] On the basis of the above-mentioned embodiments, the scanner determination module 803 is specifically configured to:

[0210] Determine the vulnerability scanner having a binding relationship with the access terminal from a pre-stored binding relationship table.

[0211] Figure 9 Another internal network asset vulnerability scanning device structure diagram is provided for the embodiments of the present application. The device can be a module, program segment or code on an electronic device. It should be understood that the device corresponds to the above-mentioned Figure 5 method embodiments, and can perform each step involved in the Figure 5 method embodiments. The specific functions of the device can be referred to the description in the above text. To avoid repetition, the detailed description is appropriately omitted here. The device comprises a traffic receiving module 901, a traffic forwarding module 902 and a response information receiving module 903, wherein:

[0212] The traffic receiving module 901 is configured to receive vulnerability scanning traffic sent by a vulnerability scanner on a cloud service platform; the access terminal is determined by the cloud service platform based on the received vulnerability scanning request; the vulnerability scanner has a binding relationship with the access terminal;

[0213] The traffic forwarding module 902 is configured to send vulnerability scanning traffic to an internal network asset to be scanned, so as to implement vulnerability scanning on the internal network asset to be scanned;

[0214] The response information receiving module 903 is configured to receive response information returned by the internal network asset to be scanned, and send the response information to the vulnerability scanner.

[0215] On the basis of the above-mentioned embodiments, the device further comprises a second registration module for:

[0216] sending a registration request to the cloud service platform, the registration request including an access code, so that the cloud service platform opens a socks 5 proxy channel after verification based on the access code passes, and opens the authority of the terminal to be accessed and a service end socks 5 proxy in the cloud service platform to publish / subscribe a topic, so as to realize the communication between the service end socks 5 proxy and the terminal to be accessed through the MQTT protocol;

[0217] After completing the registration, sending registration completion information to the cloud service platform, the registration completion information including the basic information of the terminal to be accessed and the address information of the service end socks 5 proxy corresponding to the terminal to be accessed, so that the cloud service platform stores the registration completion information;

[0218] Receiving information of successful access sent by the cloud service platform.

[0219] On the basis of the above-mentioned embodiments, the traffic receiving module 901 is specifically configured to:

[0220] Receiving the vulnerability scanning traffic sent by the vulnerability scanner based on the MQTT protocol through the service end socks 5 proxy through the client end socks 5 proxy;

[0221] Sending the vulnerability scanning traffic to the internal network asset to be scanned, including:

[0222] Sending the vulnerability scanning traffic to the internal network asset to be scanned through the client end socks 5 proxy.

[0223] On the basis of the above-mentioned embodiments, the access terminal is a lightweight access terminal.

[0224] Figure 10 The electronic device provided in the embodiments of the present application provides an electronic device entity structure diagram as shown in Figure 10 The electronic device includes a processor 1001, a memory 1002 and a bus 1003; wherein,

[0225] The processor 1001 and the memory 1002 complete mutual communication through the bus 1003;

[0226] The processor 1001 is configured to invoke program instructions in the memory 1002 to perform the method provided by the above method embodiments, for example, including: receiving a vulnerability scanning request; the vulnerability scanning request includes to-be-scanned asset information, and the to-be-scanned asset information corresponds to an asset that is an intranet asset; determining an access terminal based on the to-be-scanned asset information; the access terminal is configured to realize communication connection between the cloud service platform and the intranet; determining a vulnerability scanner on the cloud service platform according to the access terminal; sending vulnerability scanning traffic to the access terminal through the vulnerability scanner, so that the access terminal forwards the vulnerability scanning traffic to the asset corresponding to the to-be-scanned asset information, to realize vulnerability scanning on the asset. Or,

[0227] receiving vulnerability scanning traffic sent by a cloud service platform through a vulnerability scanner; the access terminal is determined by the cloud service platform based on the received vulnerability scanning request; the vulnerability scanner has a binding relationship with the access terminal; sending the vulnerability scanning traffic to the to-be-scanned intranet asset to realize vulnerability scanning on the to-be-scanned intranet asset; receiving response information returned by the to-be-scanned intranet asset, and sending the response information to the vulnerability scanner.

[0228] The processor 1001 can be an integrated circuit chip having a signal processing capability. The processor 1001 can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), and the like; and can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. It can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor can be a microprocessor, or the processor can also be any conventional processor.

[0229] The memory 1002 can include, but is not limited to, a random access memory (RAM), a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), and the like.

[0230] The embodiment discloses a computer program product, which comprises a computer program stored on a non-transitory computer-readable storage medium, and the computer program comprises program instructions, and when the program instructions are executed by a computer, the computer can execute the method provided by each method embodiment, for example, comprising: receiving a vulnerability scanning request; the vulnerability scanning request comprises to-be-scanned asset information, and an asset corresponding to the to-be-scanned asset information is an intranet asset; determining an access terminal based on the to-be-scanned asset information; the access terminal is used to realize communication connection between the cloud service platform and the intranet; determining a vulnerability scanner on the cloud service platform according to the access terminal; sending vulnerability scanning traffic to the access terminal through the vulnerability scanner, so that the access terminal forwards the vulnerability scanning traffic to an asset corresponding to the to-be-scanned asset information, to realize vulnerability scanning on the asset. Or,

[0231] receiving vulnerability scanning traffic sent by a vulnerability scanner of a cloud service platform; the access terminal is determined by the cloud service platform based on a received vulnerability scanning request; the vulnerability scanner has a binding relationship with the access terminal; sending the vulnerability scanning traffic to the to-be-scanned intranet asset, to realize vulnerability scanning on the to-be-scanned intranet asset; receiving response information returned by the to-be-scanned intranet asset, and sending the response information to the vulnerability scanner.

[0232] The embodiment provides a non-transitory computer-readable storage medium, which stores computer instructions, and the computer instructions enable the computer to execute the method provided by each method embodiment, for example, comprising: receiving a vulnerability scanning request; the vulnerability scanning request comprises to-be-scanned asset information, and an asset corresponding to the to-be-scanned asset information is an intranet asset; determining an access terminal based on the to-be-scanned asset information; the access terminal is used to realize communication connection between the cloud service platform and the intranet; determining a vulnerability scanner on the cloud service platform according to the access terminal; sending vulnerability scanning traffic to the access terminal through the vulnerability scanner, so that the access terminal forwards the vulnerability scanning traffic to an asset corresponding to the to-be-scanned asset information, to realize vulnerability scanning on the asset. Or,

[0233] receiving vulnerability scanning traffic sent by a vulnerability scanner of a cloud service platform; the access terminal is determined by the cloud service platform based on a received vulnerability scanning request; the vulnerability scanner has a binding relationship with the access terminal; sending the vulnerability scanning traffic to the to-be-scanned intranet asset, to realize vulnerability scanning on the to-be-scanned intranet asset; receiving response information returned by the to-be-scanned intranet asset, and sending the response information to the vulnerability scanner.

[0234] In the embodiments of the present application, it should be understood that the disclosed apparatus and method can be implemented in other manners. The embodiments described above are merely exemplary, for example, the division of the units is only a logical function division, and there can be another division manner in actual implementation; for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed mutual couplings or direct couplings or communication connections can be indirect couplings or communication connections through some interfaces, devices or units, and can be in electrical, mechanical or other forms.

[0235] In addition, the units described as separate components can or can not be physically separate, and the components displayed as units can or can not be physical units, i.e., can be located in one place, or can be distributed on a plurality of network units. Some or all of the units can be selected according to actual needs to achieve the purposes of the embodiments of the present application.

[0236] In addition, the functional modules in each of the embodiments of the present application can be integrated together to form an independent part, or each module can exist independently, or two or more modules can be integrated to form an independent part.

[0237] In this document, the terms such as first and second are used only to distinguish one entity or operation from another, and do not necessarily require or imply that there is any such actual relationship or order between these entities or operations.

[0238] The above only describes the embodiments of the present application, and is not used to limit the protection scope of the present application. For those skilled in the art, the present application can have various modifications and changes. Any modification, equivalent replacement, improvement, etc. made within the spirit and principles of the present application shall be included in the protection scope of the present application.

Claims

1. An internal network asset vulnerability scanning method, characterized in that, The method is applied to a cloud service platform, and the method comprises the following steps: receiving a vulnerability scanning request; the vulnerability scanning request comprises asset information to be scanned, and an asset corresponding to the asset information to be scanned is an intranet asset; determining an access terminal based on the asset information to be scanned; the access terminal is used to realize a communication connection between the cloud service platform and the intranet; the access terminal comprises a pluggable USB flash disk and an executable file; the access terminal itself does not have scanning capability and is used to maintain a safe and reliable socks 5 proxy channel based on an MQTT protocol, the channel being used to proxy and forward a vulnerability scanning request of a cloud scanner to the intranet; when the access terminal establishes a connection with the cloud service platform, the two parties exchange certificates and verify the certificates of each other, and the connection is established after the verification is passed; determining, according to the access terminal, a vulnerability scanner on the cloud service platform which has a binding relationship with the access terminal; sending, by the vulnerability scanner, vulnerability scanning traffic to the access terminal, so that the access terminal forwards the vulnerability scanning traffic to an asset corresponding to the asset information to be scanned, to realize vulnerability scanning on the asset; the sending, by the vulnerability scanner, of the vulnerability scanning traffic to the access terminal, so that the access terminal forwards the vulnerability scanning traffic to the asset corresponding to the asset information to be scanned, comprises the following steps: the vulnerability scanner sends, based on the MQTT protocol, the vulnerability scanning traffic encrypted by using a TLS / SSL security protocol to the access terminal through a server-side socks 5 proxy, so that the access terminal subscribes to the vulnerability scanning traffic through MQTT, forwards the vulnerability scanning traffic to a client-side socks 5 proxy, and makes the client-side socks 5 proxy forward the vulnerability scanning traffic to the asset corresponding to the asset information to be scanned.

2. The method of claim 1, wherein, The method further comprises the following steps: receiving a registration request sent by the access terminal, the registration request comprising an access code; verifying the access code, and in the case that the verification is passed, starting a socks 5 proxy channel, and starting the right of the access terminal to the topic of MQTT publishing / subscription of a server-side socks 5 proxy in the cloud service platform, to realize the communication between the server-side socks 5 proxy and the access terminal through the MQTT protocol; receiving registration completion information of the access terminal, the registration completion information comprising basic information of the access terminal and address information of a server-side socks 5 proxy corresponding to the access terminal; storing the registration completion information.

3. The method of claim 2, wherein, The method further comprises the following steps: receiving heartbeat information sent by the access terminal which has registered successfully.

4. The method of claim 3, wherein, The determination of the access terminal based on the asset information to be scanned comprises the following steps: selecting one terminal in an online state as the access terminal based on the received heartbeat information.

5. The method according to any one of claims 1 to 4, characterized in that, The method further comprises the following steps: obtaining vulnerability scanner resources on the cloud service platform and terminal information of a terminal to be bound; receiving a target vulnerability scanner selected from the vulnerability scanner resources; associating the target vulnerability scanner with the terminal information and storing the same.

6. The method of claim 5, wherein, The vulnerability scanner on the cloud service platform is determined according to the access terminal, and the method comprises the steps that: The vulnerability scanner having a binding relationship with the access terminal is determined from a pre-stored binding relationship table.

7. An internal network asset vulnerability scanning method, characterized by, The access terminal is applied to, and the access terminal and the internal network asset to be scanned are in the same local area network; the access terminal comprises a plug-in USB flash disk and an executable file; the access terminal itself does not have scanning capability, and is used for maintaining a socks 5 proxy channel based on a MQTT protocol, which is used for proxy forwarding of a vulnerability scanning request of a cloud scanner to an internal network; when the access terminal establishes a connection with a cloud service platform, both sides exchange certificates and verify the certificates of each other, and the connection is established after the verification is passed; the method comprises the steps that: Receiving vulnerability scanning traffic sent by a vulnerability scanner of a cloud service platform; the access terminal is determined by the cloud service platform based on a received vulnerability scanning request; the vulnerability scanner has a binding relationship with the access terminal; Sending the vulnerability scanning traffic to the internal network asset to be scanned, so as to realize vulnerability scanning on the internal network asset to be scanned; Receiving response information returned by the internal network asset to be scanned, and sending the response information to the vulnerability scanner; The access terminal receives vulnerability scanning traffic sent by a vulnerability scanner of a cloud service platform, and the method comprises the steps that: Receiving the vulnerability scanning traffic sent by the vulnerability scanner based on the MQTT protocol through the server-side socks 5 proxy by using the TLS / SSL security protocol for encryption through the client-side socks 5 proxy; The access terminal sends the vulnerability scanning traffic to the internal network asset to be scanned, and the method comprises the steps that: The access terminal sends the vulnerability scanning traffic to the internal network asset to be scanned through the client-side socks 5 proxy.

8. The method of claim 7, wherein, The method further comprises the steps that: Sending a registration request to the cloud service platform, the registration request comprising an access code, so that the cloud service platform opens a socks 5 proxy channel and opens the permission of the MQTT publish / subscribe topic of the server-side socks 5 proxy of the access terminal and the cloud service platform after passing the verification based on the access code, so as to realize the communication between the server-side socks 5 proxy and the access terminal through the MQTT protocol; After completing the registration, sending registration completion information to the cloud service platform, the registration completion information comprising basic information of the access terminal and address information of the server-side socks 5 proxy corresponding to the access terminal, so that the cloud service platform stores the registration completion information; Receiving information of successful access sent by the cloud service platform.

9. The method according to any of claims 7-8, characterized in that, The access terminal is a lightweight access terminal.

10. An electronic device, comprising: Comprise: A processor, a memory and a bus, wherein, The processor and the memory complete mutual communication through the bus; The memory stores program instructions capable of being executed by the processor, and the processor calling the program instructions can execute the method of any one of claims 1-9.

11. A non-transitory computer-readable storage medium, comprising: The non-transitory computer readable storage medium stores computer instructions, which, when executed by a computer, cause the computer to perform the method of any one of claims 1-9.

12. A computer program product, characterised in that, The computer program instructions, when read and executed by a processor, perform the method of any one of claims 1-9.

13. An internal web asset vulnerability scanning system, comprising: The cloud service platform and the access terminal are in communication connection; the access terminal is in the same local area network as the internal network asset to be scanned; The cloud service platform is configured to perform the method of any one of claims 1-6; The access terminal is configured to perform the method of any one of claims 7-9.

Citation Information

Patent Citations

  • Method for dynamically distributing channels to penetrate intranet to access local system

    CN113259372A

  • Vulnerability scanning method, system and device for intranet assets and storage medium

    CN117061175A