Active Internet exposed surface detection method and system
Through the active Internet exposure detection method, combined with crawler programs and AI recognition models, the problem of passive management of enterprises in Internet exposure management is solved, and more efficient and accurate Internet exposure detection and risk management is achieved.
Patent Information
- Application Number
- CN202411885623.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-19
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2044-12-19
AI Technical Summary
Enterprises have passive management methods in Internet exposure management, which leads to the inability to effectively manage and reduce Internet exposure, which increases network security risks, and it is difficult for existing technologies to achieve full inspection and traceability.
Active Internet exposure detection method is adopted to obtain local asset management information, network configuration information and security control information of enterprises, and combine crawling programs and AI identification models to crawl and risk assessment of Internet data sources to generate trusted Internet exposure information.
It significantly improves the efficiency, accuracy and security of enterprise Internet exposure detection, can more effectively identify and manage Internet exposure, and reduce network security risks.
Smart Images

Figure CN119945715A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the fields of network technology and security technology, and in particular to a method and system for actively detecting Internet exposure surfaces. Background Art
[0002] With the continuous development of the Internet and the application of digital technologies such as 5G and cloud computing, the access of corporate assets to the network will show a rapid growth trend, which also means that the risk exposure of enterprises will increase accordingly and become more complicated. At the same time, the continuous evolution of network attack technology and the professionalization, organization and tool-based attack methods of network attack teams have put enterprises' network security management under more serious pressure. At present, the management of Internet exposure within most enterprises is still in a passive management mode of using internal asset ledger records and regular manual review, which has the following problems:
[0003] 1. Asset exposure management: With the rapid growth of enterprise assets connected to the Internet, how to effectively manage and reduce the enterprise's exposure to the Internet to reduce potential network security risks.
[0004] 2. Complexity of network security risks: The continuous evolution of network attack technology and the specialization, organization and toolization of attack teams have increased the network security management pressure faced by enterprises, and some fake shell websites and information leaks caused by factors not caused by the enterprises themselves.
[0005] 3. Limitations of internal management methods: Most companies still rely on traditional internal asset ledger records and manual review methods, which have problems such as untimely updates, omissions in review, and inability to fully investigate and trace.
[0006] 4. Passivity of security protection: Enterprises often adopt a passive defense strategy in network security protection and lack the ability to actively discover and respond to security threats. Small-scale leaks of platform physical accounts, high-risk ports, sensitive information, etc. cannot be fully investigated and traced manually with a lot of resources. Due to the low attention paid to some test systems and edge systems, administrators fail to promptly learn about the exposure of such systems, resulting in a lack of corresponding monitoring methods. Moreover, due to the particularity of such systems, their own security reinforcement is generally low, and they are prone to various vulnerability risks. The Internet exposure investigation service provided by security vendors is effective, but the price is generally expensive. Enterprises generally only use this type of solution as a one-time full-scale investigation solution for Internet exposure in the short term, which is difficult to solve the company's long-term Internet exposure problem.
[0007] 5. Combination of technology and management: Enterprises need to find a balance between technical means and management measures to achieve more effective network security management. Asset ledgers are not updated and summarized in a timely manner, and there are omissions in the administrator's review.
[0008] In response to the above problems, enterprises need to take a series of measures, including but not limited to automated asset discovery and management, strengthening security monitoring and response, improving security protection capabilities, strengthening compliance and best practices, improving security awareness and training, using professional security services, establishing emergency response mechanisms, implementing risk management, and using threat intelligence, etc., to build a more comprehensive and effective network security management system. Therefore, a technical solution is urgently needed to proactively detect Internet exposure surfaces. Summary of the invention
[0009] The present application shows an active Internet exposure surface detection method and system.
[0010] In a first aspect, the present application provides an active Internet exposure surface detection method, comprising:
[0011] Obtain the enterprise's local asset management information, network configuration information, and security control information, and perform cleaning and sorting operations to generate an internal asset data set including asset management information and network configuration information and an unknown exposure keyword data set including security control information;
[0012] Based on the internal asset data set and the unknown exposure keyword data set, crawlers are used to crawl Internet data sources and extract Internet exposure information;
[0013] Effectively verify the Internet exposure information, input the verified Internet exposure information into the local AI recognition model, combine the internal asset data set and the unknown exposure keyword data set to perform data cleaning and risk assessment, calculate and sort the risk level and correlation of the Internet exposure information through the local AI recognition model, and generate credible Internet exposure information.
[0014] Furthermore, the crawler program uses Selenium tools to render web pages, and according to the type of web pages visited, it captures Internet data sources by locating static page elements and simulating automatic clicks on web pages.
[0015] Furthermore, the crawler program crawls data by using a proxy IP pool and a browser header address pool.
[0016] Furthermore, the extracting of Internet exposure surface information includes: interfacing with a spatial mapping engine to collect vulnerability data and threat intelligence information of Internet exposure surfaces.
[0017] Furthermore, the local AI is obtained by training with an internal asset dataset and an unknown exposure keyword dataset.
[0018] Furthermore, the local AI recognition model is trained through reinforcement learning and reward modeling, and the local AI recognition model is optimized through the PPO algorithm.
[0019] Furthermore, the risk level and relevance of Internet exposure surface information are calculated and sorted by the local AI recognition model, including: the local AI recognition model assigns weights and sorts the risk level and relevance of the Internet exposure surface information according to the vulnerability data and threat intelligence information of the Internet exposure surface information, and generates a risk report on the Internet exposure surface information.
[0020] In a second aspect, the present application provides an active Internet exposure detection system, characterized in that the system comprises:
[0021] The information acquisition module is used to obtain the enterprise's local asset management information, network configuration information and security control information, and perform cleaning and sorting operations to generate an internal asset data set including asset management information and network configuration information and an unknown exposure surface keyword data set including security control information;
[0022] The crawling module is used to crawl Internet data sources through crawlers based on the internal asset data set and the unknown exposure keyword data set to extract Internet exposure information;
[0023] The detection module is used to effectively verify the Internet exposure information through the cyberspace mapping engine, input the verified Internet exposure information into the local AI recognition model, combine the internal asset data set and the unknown exposure keyword data set to perform data cleaning and risk assessment, calculate and sort the risk level and correlation of the Internet exposure information through the local AI recognition model, and generate credible Internet exposure information.
[0024] The technical solution provided by this application may have the following beneficial effects:
[0025] The technical solution of the present application effectively verifies Internet exposure information through a cyberspace mapping engine, and inputs the verified Internet exposure information into a local AI recognition model; and combines automated data collection, advanced crawler technology, AI recognition models and risk assessment methods to significantly improve the efficiency, accuracy and security of enterprise Internet exposure detection. BRIEF DESCRIPTION OF THE DRAWINGS
[0026] Figure 1 is a flowchart of the steps of the application method;
[0027] Figure 2 is a method flow chart of Embodiment 1 of the present application;
[0028] Figure 3This is a schematic diagram of an example flow chart of the second embodiment of the present application;
[0029] Figure 4 It is a structural block diagram of an active Internet exposure surface detection system of the present application;
[0030] Figure 5 is a block diagram of an electronic device of the present application;
[0031] Figure 6 It is a block diagram of a computer-readable storage medium of the present application. DETAILED DESCRIPTION
[0032] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.
[0033] Glossary:
[0034] Web crawler: refers to a program that is written by humans and can automatically collect and crawl information from specific web pages on the Internet according to certain rules.
[0035] Internet exposure: refers to domain names, IP addresses, websites, physical accounts, application systems, high-risk ports, source codes, file data, etc. owned or controlled by the operating unit that are exposed to the Internet and can be exploited or invaded by attackers.
[0036] Cyberspace mapping engine: a site or application that detects, collects, analyzes, and processes global network assets in real time, obtains various attributes of assets in cyberspace, and maps the status of these attributes.
[0037] AI recognition model: refers to the use of open source AI models that can automatically obtain Internet exposure information and make judgments after fine-tuning training on local data sets and function development.
[0038] Selenium: Selenium is a tool for automated testing of web applications. It can simulate user operations in the browser, such as clicks and inputs, to detect the functions and performance of the application. Selenium originated in 2004 and was originally a JavaScript-based testing tool called Selenium Core. Later, with the development of technology, Selenium has undergone many iterations and improvements, and finally formed the current Selenium WebDriver, also known as Selenium.
[0039] Headless Chrome: Headless Chrome is a headless running mode of the Chrome browser, that is, running Chrome without a graphical user interface. This mode allows users to run programs with all the features supported by Chrome without opening the browser GUI. It is particularly suitable for scenarios such as automated testing, web crawling, and server-side tasks.
[0040] PPO algorithm: PPO algorithm (Proximal Policy Optimization) is a reinforcement learning algorithm proposed by OpenAI in 2017. PPO algorithm aims to solve the problem of unstable training caused by excessive policy updates in traditional policy gradient methods. By introducing a mechanism to limit the scope of policy updates, it ensures convergence while improving the stability and efficiency of the algorithm.
[0041] Request library: The request library is a very popular Python HTTP third-party library, mainly used to send various HTTP requests, handle cookies, sessions, connection pools, redirects, multiple authentication methods, etc. It makes processing HTTP requests very convenient and is a commonly used tool in crawlers and network requests.
[0042] Session: In the database, session refers to an interaction process between a user and a database server, starting from when the user successfully connects to the database server and ending when the user disconnects. Session is mainly used to identify and manage the interaction process between the user and the database. The user can perform various database operations in the session, such as query, insert, update, and delete. The database server will record all operations in the session and use them to restore data when necessary.
[0043] JavaScript: JavaScript (JS) is a lightweight interpreted or just-in-time compiled programming language, mainly used in web development to enhance the interactivity and dynamism of web pages.
[0044] RabbitMQ: is an open source message middleware developed in Erlang language and implemented based on AMQP (Advanced Message Queuing Protocol). It is mainly used for asynchronous communication between applications, especially in distributed systems and microservice architectures. RabbitMQ can help solve message delivery problems and improve the scalability, reliability and response speed of the system.
[0045] SHAP: SHAP (SHapley Additive exPlanations) is a tool for explaining the output of machine learning models. It quantifies the contribution of features to model predictions based on the Shapley value in game theory. The core idea of SHAP is to calculate the marginal contribution of each feature to the model output, thereby explaining the "black box model" from both the global and local levels.
[0046] URL: Uniform Resource Locator, URL (Uniform Resource Locator) is a string used to identify and locate resources on the Internet. Each information resource has a unique address on the Internet, which is the URL. It not only indicates the location of the resource, but also provides the information needed to access the resource, such as the protocol type, server address, port number, and the specific location of the resource on the server.
[0047] fake_useragent: is a Python library that is specifically used to generate fake User-Agent strings. User-Agent is part of the HTTP request and is used to help the server identify the type, version, and operating system of the client browser that made the request. In some cases, such as crawler development, forging User-Agent can simulate different browser environments to avoid being identified and blocked by the website.
[0048] SSL: SSL (Secure Sockets Layer) is a security protocol designed to protect the security of data transmission in Internet communications, providing encryption, authentication and data integrity. The SSL protocol establishes an encrypted link between the client and the server to ensure that the transmitted data cannot be intercepted or tampered with by unauthorized third parties. It establishes a session between the client and the server through a handshake process, completes the identity verification of both parties, and negotiates keys and encryption suites, thereby ensuring the security of communication.
[0049] json: (JavaScript Object Notation) is a lightweight data exchange format, widely used in data interfaces, serialization, token generation and configuration files in Web development. It is designed based on a subset of ECMAScript, is language independent, and supports multiple programming languages. etree: is a library written in Python for parsing tree element files.
[0050] Embodiment 1:
[0051] Reference Figure 1, shows an active Internet exposure surface detection method of the present application, which can be applied to electronic devices, and the method includes the following steps:
[0052] Step 101, obtaining the local asset management information, network configuration information and security control information of the enterprise, and performing cleaning and sorting operations to generate an internal asset data set including the asset management information and network configuration information and an unknown exposure surface keyword data set including the security control information;
[0053] Step 102: crawling Internet data sources through a crawler program to extract Internet exposure information based on the internal asset data set and the unknown exposure keyword data set. For example, a corresponding web crawler program can be generated for conventional search engines, network disk searches, file resource searches, public accounts, applets and other network information sources to extract Internet exposure information;
[0054] Specifically, web crawler programs should be classified according to desktop and mobile terminals. They can be written by static page element positioning, simulating automatic web page clicks, etc. The page elements positioned by the crawler should try to use text characters or dual-element positioning methods to ensure the uniqueness of the elements. For web pages with login verification or requiring page operations, use headless browser settings and simulate web page clicks to submit data and operate the page to reduce the number of times the verification code is triggered. For simpler verification code types such as numbers, letters, sliding, and clicking, optical character recognition can be used to process the verification code image to identify the verification code, or intercept the returned data packet to obtain the verification code, or connect to a third-party verification code recognition platform to identify the verification code. The crawler program includes combining Selenium with Headless Chrome and supports JavaScript rendering to ensure the integrity and accuracy of the Internet data source. Crawl the proxy IP pool provided by cloud vendors and platforms according to demand, use the session sub-library of the request library to write a test function to test the survival and quality of the IP pool, collect IPs with higher survival quality to build the crawler's proxy address pool, and randomly use the proxy address pool and browsing header address pool to crawl data when crawling data to reduce the frequency of the anti-crawling mechanism triggered when the website visits a single IP too many times.
[0055] The key code blocks of the web crawler program, such as element positioning, login verification, data acquisition, and data submission, should be modularized. According to the different types of web pages visited, redundant pools should be established for items that change, such as positioning elements, unknown exposure keyword data, and submission data types. Different modules of the web crawler program should be compiled in categories to ensure the stability and reliability of the web crawler program. By adding message sorting queue middleware such as rabbitMQ, or implementing asynchronous message queues in the code, multi-threading and thread locking technology can be used to implement multi-threaded crawlers from the time the crawler sends a request to the data analysis stage, crawling data from multiple websites at the same time, and asynchronously receiving data crawling and processing stages through message queues, which can greatly reduce the network socket requirements when the crawler is running. When encountering errors caused by anti-crawling mechanisms and other reasons, the data obtained by the crawler before the exception can be effectively retained.
[0056] Step 103, using network programming technology, effectively verify the Internet exposure information through the cyberspace mapping engines of major security vendors, input the verified Internet exposure information into the local AI recognition model, combine the internal asset data set and the unknown exposure keyword data set, perform data cleaning and risk assessment, calculate and sort the risk level and correlation of the Internet exposure information through the local AI recognition model, generate credible Internet exposure information, and complete Internet exposure detection.
[0057] Specifically, use programming technology to establish an active security scanning program, perform security scans on unknown Internet exposures to collect vulnerability data and threat intelligence information such as Web applications and frameworks, middleware, subdomains, API information, SSL / TLS certificates, ports, C segments, vulnerabilities, CDNs, etc., and connect with the cyberspace mapping engine through an interface to obtain vulnerability data and threat intelligence information.
[0058] The cyberspace mapping engine is called to collect information such as keywords, icons, return data, domain name certificates, and filing nature that may appear in assets, and at the same time, it is connected to the enterprise information search engine to obtain possible enterprise information data.
[0059] Specifically, the local AI recognition model is trained through internal asset data sets and unknown exposure keyword data sets to improve the accuracy of Internet exposure information identification. The local AI recognition model is trained through reinforcement learning and reward modeling, and optimized through the PPO algorithm to improve the accuracy of risk assessment of Internet exposure information. The risk level and relevance of Internet exposure information are calculated and sorted through the local AI recognition model, including: the local AI recognition model assigns weights and sorts the risk level and relevance of Internet exposure information according to the vulnerability data and threat intelligence information of Internet exposure information, and generates a risk report on Internet exposure information.
[0060] Specifically, the AI recognition module is developed with function calls and external connections to realize the calling of web crawler programs and spatial mapping calling programs. The main process is that the program provides a set of calling functions to the AI recognition model. The AI recognition model chooses to use or not use, or is forced to use the function according to the administrator's selection. The application obtains the result according to the function and provides it to the AI recognition model. The AI recognition model can continuously use function calls and new data as training data sets. After supervised and regulated training, and manually setting preferences and weights, it can realize online learning and continuous updating of AI to ensure the stability and availability of AI.
[0061] Specifically, the SHAP model interpretation technology is used to analyze the decision-making process of the AI recognition model, track and illustrate the feature points of the Internet exposure surface data set, and reduce the impact of feature points with low correlation with the exposure surface on the average prediction value. For example, some system keywords have a greater impact on the predicted average value, but their actual importance is relatively low. After multiple feature accumulations, this seriously affects the discrimination of the data.
[0062] The present application can be applied to network and system security system analysis scenarios, especially Internet exposure risk assessment and security protection scenarios, where Internet exposure refers to domain names, IP addresses, websites, entity accounts, application systems, high-risk ports, source codes, file data quality and other data that are exposed and run or retained on the Internet and can be detected, as well as systems, devices, information, etc. that can be exploited or invaded by attackers.
[0063] The method and system of the present application are suitable for the Internet asset exposure management of medium and large enterprises. Based on web crawler and network programming technology, combined with a variety of detection technologies, they automatically, multi-angle, and long-term detect unknown exposure surfaces on the Internet that may be related to the enterprise, and use algorithms to perform data analysis on unknown exposure surfaces to sort out exposure asset information related to the enterprise. It has a low error rate and high real-time performance, and can greatly reduce the time for manual sorting and verification.
[0064] The following is a detailed description of the present application example with reference to the accompanying drawings:
[0065] Embodiment 2:
[0066] The method of the present application is solidified in a physical product such as a computer in the form of software. Figure 2 This is a flow chart of the method of Example 1 of this application.
[0067] Step 1, obtain internal asset source data and unknown exposure keyword data. As described in step 1, the internal asset source data may include: asset name, hardware information, IP address, port, domain name, service name, service type, software identification, software process, framework fingerprint, certificate file, file name, file type, entity account and other asset data. The unknown exposure keyword data is to enumerate and collect the keywords that may appear in the above internal asset source data in combination with data characteristics, which may include: asset keywords, IP address C segment, asset high-frequency port, subdomain dictionary, directory dictionary, high-frequency service interface, common framework fingerprint, ICP filing name, file name keyword, entity account keyword and other data. The detail and availability of unknown exposure keyword data determine the effectiveness of the Internet exposure detection method. Due to the differences in the internal asset operating environment and main business, the collected source data will be diversified and scattered. It is necessary to classify and solidify the data collection process and rules to improve the detail and availability of unknown exposure keyword data.
[0068] Step 2: Generate unknown exposure keyword data based on internal asset data sets and asset exposure keywords; build crawlers for search engines, file searches, network disk searches, public accounts and other network information sources to collect unknown Internet exposure information. As described in step 2, due to the different types of websites to be crawled, the code should be modularized as much as possible when writing the crawler program, and the element positioning should be encapsulated into a configuration file to reduce the workload of the crawler program when it is replicated later.
[0069] The crawler should be implemented according to the following steps:
[0070] 1) The crawler is split into modules, including URL management module, access module, parsing module, data storage module, scheduler module, anti-crawling mechanism processing module, exception handling module, and configuration management module.
[0071] 2) The URL management module should classify different types of web pages, use fake_useragent and headless browser to set up disguised browsing headers, improve the URL connection success rate, and reduce the chance of encountering SSL errors and anti-crawling measures.
[0072] 3) When building the access module, when the web page is a static page, use request+bs4 to obtain data. When the web page is a dynamic page, use selenium+request+bs4 to dynamically capture content after rendering the web page. When the web page is in a heterogeneous data format (such as JSON, XML, etc.), use json and etree to extract data. When the web page is an application, xray+selenium should be used to capture HTML (HyperText Markup Language) after rendering the web page, and analyze the API (Application Programming Interface, a set of rules and protocols that define how software components interact) endpoints to obtain data.
[0073] 4) Use bs4 (Beautiful Soup 4, a Python library for parsing HTML and XML documents, mainly used to extract data from web pages) and lxml (a high-performance Python library) to parse the collected pages, define extraction tags according to collection requirements, perform extraction tests based on different web pages to generate corresponding extraction strategies and logic, and label and format the data to ensure data availability and consistency.
[0074] 5) The data storage module should try to use a relational database such as MySQL (an open source relational database management system (RDBMS)) to associate and store the extracted exposure surface data.
[0075] 6) The scheduler module should control the crawling order and frequency of the crawler. The scheduling modules work together to realize multi-threading and asynchronous crawling to increase the crawling rate. When writing multi-threading, attention should be paid to thread lock and thread apoptosis design to avoid thread preemption and thread deadlock.
[0076] 7) The anti-crawling mechanism processing module mainly realizes user agent randomization, random waiting interval, Captcha (Completely Automated Public Turing test to tell Computers and Humans Apart) bypass, session access. Some websites will limit user_agent and IP, and establish a proxy IP address pool and random agent to bypass. Some websites will detect the access frequency. When there are a large number of visits in a short period of time, anti-crawling measures will pop up, and random waiting intervals will be used to bypass. Some websites will use verification codes for anti-crawling, which can be bypassed by disabling javascript, simulating clicks and Huadong, optical character recognition and connecting to third-party verification code recognition.
[0077] 8) The exception handling module should include crawler log collection, performance monitoring and exception handling. Log collection records the crawler's running status and collects crawler error information. Performance monitoring monitors the crawler's crawling speed, success rate, occupancy rate, etc. When an exception occurs in the crawler, the exception handling module can adjust and alert the crawler according to the exception type to reduce abnormal interruptions of the crawler.
[0078] 9) The configuration management module should use formats such as YAML (YAML Ain't a Markup Language, a format for expressing data serialization) to store crawler settings and parameters to reduce direct modifications to the crawler source code and achieve dynamic updates of the crawler.
[0079] Step 3, build a web crawler program, use the unknown exposure keyword data to actively conduct network detection, and obtain the unknown exposure information; build a spatial mapping call program that operates the spatial mapping engine and reads data to collect more relevant vulnerability data and threat intelligence information of unknown Internet exposures; as described in step 3, the spatial mapping call program should be able to call and query but not limited to the vulnerability data of the port opening history, subdomains, domain name registration subject information, sensitive directories, framework fingerprints, enterprise information, etc. of the unknown exposure. When building this program, attention should be paid to the active security scanning program in the above options, and building a program that can actively scan the Internet exposure surface to obtain real-time exposure vulnerability data can greatly improve the real-time and effectiveness of Internet exposure detection.
[0080] Step 4: Use the unknown exposure surface information and unknown exposure surface keyword data to call the spatial mapping engine to effectively verify the data and obtain more relevant vulnerable data;
[0081] Build an exposure surface AI identification program to clean and identify the acquired unknown Internet exposure surface information and related vulnerability data to obtain the associated Internet exposure surface information; Step 5: Use an active security scanning program to perform a security scan on the unknown exposure surface information and verify and supplement the related vulnerability data;
[0082] The Internet exposure AI identification program should be implemented by the following steps:
[0083] 1) Pre-training stage: The AI model uses qwen2 (a large language model developed by the Alibaba Cloud Tongyi Qianwen team) and LLaMA-Factory (Large Language Model Factory) to process internal asset datasets and unknown exposure keyword datasets. The stage is set to pt to comply with the pre-training dataset format.
[0084] 2) Post-training stage: After the pre-training stage, supervised fine-tuning is used, the stage is set to SFT, and the fine-tuning method is configured to Lora+. In this stage, a single data is trained according to the task requirements to improve the recognition quality of AI. At the same time, RLHF (Reinforcement Learning from Human Feedback) technology is introduced, and the output of pre-training is manually evaluated and ranked to optimize the behavior of the model.
[0085] 3) Reward modeling stage: Set the stage to rm, set the data set to: input, good answers, bad answers, observe the output results and training loss rate, and modify the data set preference so that its output is more in line with the required preference.
[0086] 4) Reinforcement learning stage: Use the score of the reward model as the reward signal, and optimize the model through the PPO algorithm. The AI model accepts the output of the pre-trained model as input, and its output is used as the input of the reward model. The model parameters are continuously adjusted so that the model does not lose too much of its original problem-solving ability while learning to approach human preferences.
[0087] 5) Evaluation and tuning: Provide a test dataset in an independent test environment, evaluate its output results, adjust parameters such as learning ability, learning depth, and exploration rate, optimize model performance, ensure stable convergence of strategies and value functions, combine model interpretation, fine-tune and update unstable parameters, and iterate and improve multiple times.
[0088] When building an AI recognition program, you should write a call function that adapts to the crawler program and the spatial mapping call program. When AI is reasoning, you can call the function to obtain the required information. When building an AI recognition program, you should perform data analysis on the type of exposure information data set obtained, build corresponding regular expressions and scoring rewards, score and grade vulnerability data and Internet exposure keywords, and establish first, second, and third risk levels. For example, the first risk level should include options that are directly related to the internal asset data source, such as file certificates, ICP filing names, asset keywords, IP addresses, file name keywords, ports, etc.; the second risk level should include options that are weakly related to the internal asset data source, such as IP address C segment, entity account management detection, fingerprint framework, etc., and so on.
[0089] Step 6: AI identifies unknown Internet exposure data and determines the relevance and risk level of the unknown Internet exposure.
[0090] Among them, an exposure surface AI recognition program can be optionally constructed to clean and distinguish the acquired unknown Internet exposure surface information and related vulnerability data to obtain related Internet exposure surface information; specifically, the SHAP model interpretation technology can be used to analyze the decision-making process of the AI recognition model, track and illustrate the feature points of the Internet exposure surface data set, and reduce the impact of feature points with low correlation with the exposure surface on the average prediction value. For example, some system keywords have a greater impact on the predicted average value, but their actual importance is low. After multiple feature accumulations, they seriously affect the discrimination of the data. For example, the more "telecommunication" keywords appear, the higher the exposure surface is ranked in the model after multiple feature accumulations. In fact, except for this keyword, the shap values of other feature points are actually negatively affected, resulting in reduced model consistency.
[0091] In summary, the technical solution of this application significantly improves the efficiency, accuracy and security of enterprise Internet exposure detection by combining automated data collection, advanced crawler technology, AI recognition model and risk assessment method, as follows:
[0092] Improve detection efficiency and accuracy: By automatically acquiring enterprise asset management information, network configuration information, and security control information, and generating internal asset data sets and unknown exposure keyword data sets, enterprises can more efficiently manage and identify Internet exposure.
[0093] Enhanced data integrity and accuracy: The crawler combines Selenium and Headless Chrome and supports JavaScript rendering to ensure the integrity and accuracy of Internet data sources.
[0094] Improve data crawling efficiency: The crawler program crawls data according to the type of web page, by locating static page elements and simulating automatic clicks on web pages. At the same time, it uses proxy IP pools and browser header address pools to reduce the triggering of anti-crawling mechanisms, thereby improving the efficient crawling of Internet data sources.
[0095] Strengthen the acquisition of vulnerability data and threat intelligence: Through the interface with the cyberspace mapping engine, vulnerability data and threat intelligence information are obtained, which enhances the risk assessment of Internet exposure information.
[0096] Improve the discrimination accuracy of AI recognition models: Train local AI recognition models by using internal asset data sets and unknown exposure keyword data sets to improve the discrimination accuracy of Internet exposure information.
[0097] Improve risk assessment accuracy: The local AI recognition model is trained through reinforcement learning and reward modeling, and optimized using the PPO algorithm to improve the risk assessment accuracy of Internet exposure information.
[0098] Risk level and relevance assessment: The local AI recognition model can weight and rank the risk level and relevance of Internet exposure information based on vulnerability data and threat intelligence information, generate risk reports, and provide enterprises with more accurate risk management basis.
[0099] Reduce false positives and improve threat detection efficiency: The application of AI technology in network security can reduce false positives and improve the efficiency of threat detection, allowing security teams to focus more on real threats.
[0100] Save resources and improve test stability: Tests in Selenium Headless mode will not pop up a visible browser window and can run silently in the background, saving resources and improving test stability.
[0101] Improve network security protection capabilities: Through active Internet exposure detection, enterprises can more effectively identify and defend against network attacks, reduce security risks, and improve network security protection capabilities.
[0102] Embodiment 3:
[0103] This embodiment is applicable to multi-system, multi-asset important environments. The system is composed of multiple servers, databases, network devices and related application software. It is one of the important assets of the enterprise and is directly related to the normal operation of the business and the security of the data. Since the system involves a large amount of sensitive data and is exposed to the Internet environment, it is vulnerable to hacker attacks and vulnerability exploits. Therefore, it is very necessary to integrate assets, monitor exposure surfaces, monitor vulnerabilities and strengthen the system for the system. Figure 3 This is a schematic diagram of an example flow chart of the second embodiment.
[0104] As in step 1, internal asset types and information are obtained to generate internal resource data; specifically, internal asset data and special exposure keywords are obtained through internal resource data sorting, including: obtaining local asset management information, network configuration information and security control information of the enterprise, and automated scanning tools can be used to scan the entire network environment for information collection. Using the natural language processing capabilities in AI technology, asset information (such as servers, databases, network devices, applications) is automatically parsed and detailed information is extracted, including: IP address, port number, operating system and its version, installed software and its version, network topology relationship and connection method of the device. This not only improves the speed of data collection, but also reduces errors caused by manual operations. Data integration and cleaning include cleaning and sorting operations on the collected information. Specifically, after the information is entered into the asset management system, data association analysis technology (such as a graph database or a relational database) is applied to logically classify and associate assets. Automatic data classification is based not only on static features, but also on dynamic information such as business traffic and access rights to achieve intelligent classification of assets. Asset classification uses Scikit-learn's classification algorithm to classify assets according to their importance, such as "critical assets", "secondary assets", and "auxiliary assets", and mark assets that require special protection so that they can be prioritized in subsequent processes.
[0105] Generate an internal asset data set including asset management information and network configuration information and an unknown exposure keyword data set including security control information; specifically, exposure keyword setting includes setting keywords related to the enterprise asset system, using spaCy natural language processing (NLP) technology to set keywords related to the enterprise asset system, such as asset name, IP address, domain name, port number, service name, etc., and generate related keywords for exposure monitoring. In order to conduct more accurate Internet exposure monitoring to ensure that all possible security risks are covered.
[0106] As in step 2, unknown exposure keyword data is generated based on internal asset source data and asset exposure keywords; the security team monitors the Internet exposure through asset exposure keywords and configures monitoring tools (web crawler technology, search engine), uses web crawler technology, module programming and distributed crawler technology to support large-scale and efficient data capture, and conducts Internet exposure search. Specifically: Real-time monitoring uses AI-driven web crawler technology to monitor Internet exposure in real time and search for assets exposed on the Internet. Pay special attention to port exposure, disclosure of application version information, and the status of open services. Exposure analysis uses ElasticSearch to compare with the company's internal asset ledger to analyze whether the exposed assets are actually used by the company. Combined with the exposure monitoring results and asset classification, ElasticSearch is used to conduct risk assessment on the confirmed exposure and determine the security threats it may bring. Finally, the "Internet Exposure Monitoring Report" is generated and displayed using visual analysis tools (such as Grafana or Tableau) to make the report more intuitive and easy to understand, and propose targeted risk response strategies, including a list of exposed assets, exposed services, possible risk points, and recommended response measures.
[0107] As in step 3, a network monitoring program is built to connect to the vulnerability disclosure platform and intelligence threat platform data interface of security vendors to obtain the latest vulnerability information and threat intelligence information; specifically, daily vulnerability information vulnerability disclosure monitoring and analysis, interface connection with the vulnerability disclosure platform and intelligence threat platform of major security vendors on the network, realize data call and reading, and obtain relevant vulnerability information and threat intelligence information; vulnerability monitoring includes real-time monitoring of vulnerability databases (such as CVE, CNVD) and 0day vulnerability disclosure platforms to obtain industry-related vulnerability information, with special attention to high-risk vulnerabilities involving operating systems, databases, and applications used by core systems. The AI model automatically screens and classifies vulnerability information to quickly identify potential impacts on corporate assets. Vulnerability analysis uses the VulnWhisperer tool to compare the obtained vulnerability information with the data in the enterprise asset management system, evaluate the impact of newly disclosed vulnerabilities on existing systems, and mark the affected assets. Vulnerability marking uses the Scikit-learn classification model to mark vulnerabilities based on vulnerability information and generate a vulnerability priority list. Vulnerabilities are divided into three priorities: high, medium, and low based on factors such as the harmfulness, exploitability, and existence time of the vulnerability. Impact assessment is to analyze the potential impact of each vulnerability, including data leakage, system downtime, unauthorized access, etc. Generate a "Vulnerability Impact Analysis Report" including a detailed description of the vulnerability, a list of affected assets, potential business impacts, and recommended repair strategies. As in step 4, analyze the obtained vulnerability information and compare it with the asset management system data, evaluate the impact of the newly disclosed vulnerability on the existing system, mark the affected assets, and classify them into high, medium, and low priorities.
[0108] Among them, system administrators and security operation and maintenance teams enter the repair period to carry out vulnerability repair and reinforcement based on the vulnerability analysis report.
[0109] As in step 5, perform vulnerability repair and reinforcement, formulate a repair plan, arrange a system maintenance window, allocate repair resources, and perform repair verification to ensure that the vulnerability has been repaired and the system is running stably; specifically, it includes:
[0110] 1. Preparation of repair plans: According to the Vulnerability Impact Analysis Report, use automated patch management tools (such as Ansible and Chef) to prepare repair plans for vulnerabilities of different priorities and arrange system maintenance windows to ensure that the repair process does not affect business continuity.
[0111] 2. Repair implementation: For high-priority vulnerabilities, take repair measures immediately, such as patching, updating system versions, disabling or removing high-risk services. For medium and low priority vulnerabilities, repair them in combination with daily system maintenance. In addition to repairing known vulnerabilities, we also implement system reinforcement measures, such as multi-factor authentication, updating firewall policies, and deploying Web Application Firewall (WAF), to further enhance the overall protection capabilities of the system.
[0112] 3. Reinforcement measures: While fixing vulnerabilities, implement system reinforcement measures, such as deploying WAF (Web Application Firewall) to prevent common attacks. Add multi-factor authentication and strengthen user access control. Update and reinforce firewall policies and close unnecessary ports and services. Implement regular security audits and penetration tests to discover new vulnerabilities in a timely manner. Use AI to monitor system behavior after implementation and identify abnormal activities through user behavior analysis.
[0113] 4. Repair verification: After the repair and reinforcement measures are implemented, the system is tested to ensure that the vulnerability has been completely repaired and the system is running stably. The repair process and results are recorded and a "Repair and Reinforcement Verification Report" is generated.
[0114] As in step 6, the repaired and reinforced system asset information is updated to the asset management system, and the keywords and policies for Internet exposure monitoring are updated.
[0115] Specifically, it includes updating assets and monitoring data: updating the repaired and reinforced system asset information to the asset management system. Updating the keywords and policies for Internet exposure monitoring to reflect the current system security status.
[0116] Embodiment 4:
[0117] like Figure 4 , showing an active Internet exposure surface detection system of the present application, the system comprising:
[0118] The information acquisition module is used to obtain the enterprise's local asset management information, network configuration information and security control information, and perform cleaning and sorting operations to generate an internal asset data set including asset management information and network configuration information and an unknown exposure surface keyword data set including security control information;
[0119] The crawling module is used to crawl Internet data sources through crawlers based on the internal asset data set and the unknown exposure keyword data set to extract Internet exposure information;
[0120] The detection module is used to effectively verify the Internet exposure information through the cyberspace mapping engine, input the verified Internet exposure information into the local AI recognition model, combine the internal asset data set and the unknown exposure keyword data set to perform data cleaning and risk assessment, calculate and sort the risk level and correlation of the Internet exposure information through the local AI recognition model, generate credible Internet exposure information, and complete Internet exposure detection.
[0121] As for the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.
[0122] Optionally, an embodiment of the present application further provides an electronic device, comprising: a processor, a memory, and a computer program stored in the memory and executable on the processor. When the computer program is executed by the processor, the various processes of the above-mentioned method embodiment are implemented, and the same technical effect can be achieved. To avoid repetition, it will not be described here.
[0123] The embodiment of the present application also provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, each process of the above method embodiment is implemented, and the same technical effect can be achieved. To avoid repetition, it is not repeated here. The computer-readable storage medium is, for example, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
[0124] FIG5 is a block diagram of an electronic device 800 shown in the present application. For example, the electronic device 800 may be a mobile phone, a computer, a digital broadcast terminal, a messaging device, a game console, a tablet device, a medical device, a fitness device, a personal digital assistant, etc.
[0125] Reference Figure 5 , the electronic device 800 may include one or more of the following components: a processing component 802 , a memory 804 , a power component 806 , a multimedia component 808 , an audio component 810 , an input / output (I / O) interface 812 , a sensor component 814 , and a communication component 816 .
[0126] The processing component 802 generally controls the overall operation of the electronic device 800, such as operations associated with display, phone calls, data communications, camera operations, and recording operations. The processing component 802 may include one or more processors 820 to execute instructions to complete all or part of the steps of the above method. In addition, the processing component 802 may include one or more modules to facilitate the interaction between the processing component 802 and other components. For example, the processing component 802 may include a multimedia module to facilitate the interaction between the multimedia component 808 and the processing component 802.
[0127] The memory 804 is configured to store various types of data to support operations on the device 800. Examples of such data include instructions for any application or method operating on the electronic device 800, contact data, phone book data, messages, images, videos, etc. The memory 804 can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk or optical disk.
[0128] The power supply component 806 provides power to the various components of the electronic device 800. The power supply component 806 may include a power management system, one or more power supplies, and other components associated with generating, managing, and distributing power to the electronic device 800.
[0129] The multimedia component 808 includes a screen that provides an output interface between the electronic device 800 and the user. In some embodiments, the screen may include a liquid crystal display (LCD) and a touch panel (TP). If the screen includes a touch panel, the screen may be implemented as a touch screen to receive input signals from the user. The touch panel includes one or more touch sensors to sense touch, slide, and gestures on the touch panel. The touch sensor may not only sense the boundaries of the touch or slide action, but also detect the duration and pressure associated with the touch or slide operation. In some embodiments, the multimedia component 808 includes a front camera and / or a rear camera. When the device 800 is in an operating mode, such as a shooting mode or a video mode, the front camera and / or the rear camera may receive external multimedia data. Each front camera and the rear camera may be a fixed optical lens system or have a focal length and optical zoom capability.
[0130] The audio component 810 is configured to output and / or input audio signals. For example, the audio component 810 includes a microphone (MIC), and when the electronic device 800 is in an operating mode, such as a call mode, a recording mode, and a voice recognition mode, the microphone is configured to receive an external audio signal. The received audio signal can be further stored in the memory 804 or sent via the communication component 816. In some embodiments, the audio component 810 also includes a speaker for outputting audio signals.
[0131] I / O interface 812 provides an interface between processing component 802 and peripheral interface modules, such as keyboards, click wheels, buttons, etc. These buttons may include but are not limited to: home button, volume button, start button, and lock button.
[0132] The sensor assembly 814 includes one or more sensors for providing various aspects of status assessment for the electronic device 800. For example, the sensor assembly 814 can detect the open / closed state of the device 800, the relative positioning of components, such as the display and keypad of the electronic device 800, and the sensor assembly 814 can also detect the position change of the electronic device 800 or a component of the electronic device 800, the presence or absence of contact between the user and the electronic device 800, the orientation or acceleration / deceleration of the electronic device 800, and the temperature change of the electronic device 800. The sensor assembly 814 may include a proximity sensor configured to detect the presence of nearby objects without any physical contact. The sensor assembly 814 may also include an optical sensor, such as a CMOS or CCD image sensor, for use in imaging applications. In some embodiments, the sensor assembly 814 may also include an accelerometer, a gyroscope sensor, a magnetic sensor, a pressure sensor, or a temperature sensor.
[0133] The communication component 816 is configured to facilitate wired or wireless communication between the electronic device 800 and other devices. The electronic device 800 can access a wireless network based on a communication standard, such as WiFi, a carrier network (such as 2G, 3G, 4G or 5G), or a combination thereof. In an exemplary embodiment, the communication component 816 receives a broadcast signal or broadcast operation information from an external broadcast management system via a broadcast channel. In an exemplary embodiment, the communication component 816 also includes a near field communication (NFC) module to facilitate short-range communication. For example, the NFC module can be implemented based on radio frequency identification (RFID) technology, infrared data association (IrDA) technology, ultra-wideband (UWB) technology, Bluetooth (BT) technology and other technologies.
[0134] In an exemplary embodiment, the electronic device 800 may be implemented by one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors, or other electronic components to perform the above methods.
[0135] In an exemplary embodiment, a non-transitory computer-readable storage medium including instructions is also provided, such as a memory 804 including instructions, and the instructions can be executed by a processor 820 of an electronic device 800 to perform the above method. For example, the non-transitory computer-readable storage medium can be a ROM, a random access memory (RAM), a CD-ROM, a magnetic tape, a floppy disk, an optical data storage device, etc.
[0136] Figure 619 is a block diagram of a computer-readable storage medium 1900 shown in the present application. For example, the computer-readable storage medium 1900 may be provided as a server.
[0137] Reference Figure 6 , the computer-readable storage medium 1900 includes a processing component 1922, which further includes one or more processors, and a memory resource represented by a memory 1932 for storing instructions, such as an application, that can be executed by the processing component 1922. The application stored in the memory 1932 may include one or more modules, each corresponding to a set of instructions. In addition, the processing component 1922 is configured to execute instructions to perform the above method.
[0138] The computer readable storage medium 1900 may also include a power supply component 1926 configured to perform power management of the computer readable storage medium 1900, a wired or wireless network interface 1950 configured to connect the computer readable storage medium 1900 to a network, and an input / output (I / O) interface 1958. The computer readable storage medium 1900 may operate based on an operating system stored in the memory 1932, such as Windows Server™, Mac OS X™, Unix™, Linux™, FreeBSD™ or the like.
[0139] It should be noted that, in this article, the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, an element defined by the sentence "comprises a ..." does not exclude the existence of other identical elements in the process, method, article or device including the element.
[0140] Through the description of the above implementation methods, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus a necessary general hardware platform, and of course by hardware, but in many cases the former is a better implementation method. Based on such an understanding, the technical solution of the present application, or the part that contributes to the prior art, can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, a magnetic disk, or an optical disk), and includes a number of instructions for a terminal (which can be a mobile phone, a computer, a server, an air conditioner, or a network device, etc.) to execute the methods described in each embodiment of the present application.
[0141] The embodiments of the present application are described above in conjunction with the accompanying drawings, but the present application is not limited to the above-mentioned specific implementation methods. The above-mentioned specific implementation methods are merely illustrative and not restrictive. Under the guidance of the present application, ordinary technicians in this field can also make many forms without departing from the purpose of the present application and the scope of protection of the claims, all of which are within the protection of the present application.
[0142] Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed in the present application can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0143] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0144] In the embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0145] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0146] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
[0147] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art or the part of the technical solution, can be embodied in the form of a software product, which is stored in a storage medium and includes several instructions for a computer device (which can be a personal computer, server, or network device, etc.) to perform all or part of the steps of the methods described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard drives, ROM, RAM, magnetic disks, or optical disks.
[0148] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art who is familiar with the present technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.
Claims
1. An active Internet exposure surface detection method, characterized in that: The method comprises: Obtain the enterprise's local asset management information, network configuration information, and security control information, and perform cleaning and sorting operations to generate an internal asset data set including asset management information and network configuration information and an unknown exposure keyword data set including security control information; Based on the internal asset data set and the unknown exposure keyword data set, crawlers are used to crawl Internet data sources and extract Internet exposure information; Effectively verify the Internet exposure information, input the verified Internet exposure information into the local AI recognition model, combine the internal asset data set and the unknown exposure keyword data set to perform data cleaning and risk assessment, calculate and sort the risk level and correlation of the Internet exposure information through the local AI recognition model, and generate credible Internet exposure information.
2. The active Internet exposure surface detection method according to claim 1, characterized in that: The crawler program uses the Selenium tool to render web pages, and according to the type of web pages visited, it captures Internet data sources by locating static page elements and simulating automatic clicks on web pages.
3. The active Internet exposure surface detection method according to claim 1, characterized in that: The crawler program crawls data by using a proxy IP pool and a browser header address pool.
4. The active Internet exposure surface detection method according to claim 1, characterized in that: The extracting of Internet exposure surface information includes: interfacing with a spatial mapping engine to collect vulnerability data and threat intelligence information of Internet exposure surfaces.
5. The active Internet exposure surface detection method according to claim 1, characterized in that: The local AI is obtained by training the internal asset dataset and the unknown exposure keyword dataset.
6. The active Internet exposure surface detection method according to claim 5, characterized in that: The local AI recognition model is trained through reinforcement learning and reward modeling, and is optimized through the PPO algorithm.
7. The active Internet exposure surface detection method according to claim 6, characterized in that: The method of calculating and sorting the risk level and relevance of Internet exposure surface information by the local AI recognition model includes: the local AI recognition model assigns weights and sorts the risk level and relevance of the Internet exposure surface information according to the vulnerability data and threat intelligence information of the Internet exposure surface information, and generates a risk report for the Internet exposure surface information.
8. An active Internet exposure detection system, characterized in that: The system comprises: The information acquisition module is used to obtain the enterprise's local asset management information, network configuration information and security control information, and perform cleaning and sorting operations to generate an internal asset data set including asset management information and network configuration information and an unknown exposure surface keyword data set including security control information; The crawling module is used to crawl Internet data sources through crawlers based on the internal asset data set and the unknown exposure keyword data set to extract Internet exposure information; The detection module is used to effectively verify the Internet exposure information through the cyberspace mapping engine, input the verified Internet exposure information into the local AI recognition model, combine the internal asset data set and the unknown exposure keyword data set to perform data cleaning and risk assessment, calculate and sort the risk level and correlation of the Internet exposure information through the local AI recognition model, and generate credible Internet exposure information.
9. An electronic device, characterized in that: include: A processor, a memory, and a computer program stored in the memory and executable on the processor, wherein the computer program implements the method according to any one of claims 1 to 7 when executed by the processor.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.
Citation Information
Patent Citations
Enterprise internet asset attack surface detection model based on hidden trace query algorithm
CN117857126A
System and method for cyber exploitation path analysis and response using federated networks
US20230370491A1
Cited By
Visual financial data dynamic analysis method and system
CN120910481A