A network security protection and assessment method based on automated penetration testing

By performing security scanning and automated penetration testing on the system, identifying and encrypting the source code of high-risk software, the invalid repair problems caused by unreasonable network security protection in the existing technology are solved, and the comprehensiveness and effectiveness of network security are improved.

CN119966719BActive Publication Date: 2025-08-26GUOTING INFORMATION TECHNOLOGY (BEIJING) CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510132566.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-06
Publication Date
2025-08-26
Estimated Expiration
2045-02-06

AI Technical Summary

Technical Problem

In the security detection and protection of existing vulnerabilities, the existing network security protection technology has problems such as unreasonable repairs, which leads to the ineffective repairs or encountering network security incidents during the repair.

Method used

By performing security scans on the system, identifying network vulnerabilities, performing automated penetration tests, detecting the effectiveness of different types of attacks, identifying high-risk software, turning on kernel isolation and encrypting the source code of high-risk software, and finally conducting security protection assessments.

Benefits of technology

It improves the effectiveness and pertinence of network security protection, ensures that vulnerabilities with low difficulty are directly repaired, and vulnerabilities with high difficulty are enhanced through kernel isolation and encryption protection, and the comprehensiveness and effectiveness of network security are enhanced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119966719B_ABST
    Figure CN119966719B_ABST
Patent Text Reader

Abstract

The present invention discloses a network security protection and evaluation method based on automated penetration testing, which relates to the technical field of network security protection and comprises the following steps: performing a security scan on a system to identify network vulnerabilities therein; performing automated penetration testing based on the network vulnerabilities; identifying high-risk software in the system based on the results of the automated penetration testing; performing security protection on the high-risk software based on the results of the automated penetration testing of the high-risk software; performing automated penetration testing again after performing the security protection to evaluate the effectiveness of the security protection; the present invention is used to solve the problem that the existing network security protection technology still has the problem of unreasonable processing of the vulnerability repair process in the security detection and protection for existing vulnerabilities, which easily leads to invalid repairs or encountering network security incidents during the repair period.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security protection technology, and in particular to a network security protection and evaluation method based on automated penetration testing. Background Art

[0002] Network security protection technology refers to a series of measures that use various technical means and methods to protect the security of computer network systems, network equipment, network data, and network communications. These technologies aim to prevent network systems from security threats such as malicious attacks, virus invasions, unauthorized access, and data leakage, ensuring the normal operation of network systems and the confidentiality, integrity, and availability of data. Network security protection technology covers firewalls, intrusion detection systems, encryption technology, access control, security auditing, vulnerability management, and security policy formulation, forming a multi-level and multi-dimensional network security protection system.

[0003] In the existing network security protection technology, in the security detection and protection of existing vulnerabilities, the vulnerabilities are usually repaired directly. However, the attack models corresponding to different vulnerabilities are different. If a vulnerability can only be breached by a single attack type, it is easier to repair it. However, a vulnerability that can be breached by multiple attack types is more difficult to repair and takes a longer time. Therefore, directly repairing it may result in invalid repair or encounter a network security incident during the repair period. For example, in the patent application with publication number CN111049827A, a network system security protection method, device and related equipment are disclosed. This solution is to repair the vulnerability after simulating an attack on the vulnerability. Different vulnerabilities have different repair difficulties and different threat levels to network security. Direct repair may result in invalid repair or encounter a network security incident during the repair period. The existing network security protection technology also has the problem of unreasonable handling of the vulnerability repair process in the security detection and protection of existing vulnerabilities, which makes it easy to have invalid repairs or encounter a network security incident during the repair period. Summary of the Invention

[0004] The present invention aims to solve one of the technical problems in the prior art to at least a certain extent, by performing a security scan on the system to identify the network vulnerabilities therein, and then performing automated penetration testing based on the network vulnerabilities to detect the effectiveness of different attack types on the network vulnerabilities, and then performing keyword extraction on the vulnerability name of the network vulnerability to identify the application software to which the network vulnerability belongs, and then identifying high-risk software based on the network vulnerabilities existing in the application software, for any high-risk software, enabling kernel isolation for the high-risk software, and then encrypting the source code of the software vulnerabilities contained in the high-risk software for protection, and performing automated penetration testing again after executing security protection to evaluate the effectiveness of security protection, so as to solve the problem that the existing network security protection technology still has the problem of unreasonable handling of the vulnerability repair process in security detection and protection for existing vulnerabilities, which leads to ineffective repairs or encountering network security incidents during the repair period.

[0005] To achieve the above objectives, this application provides a network security protection and assessment method based on automated penetration testing, comprising the following steps:

[0006] Perform security scans on the system to identify network vulnerabilities;

[0007] Perform automated penetration testing based on network vulnerabilities to detect the effectiveness of different attack types against network vulnerabilities;

[0008] Identify high-risk software in the system based on the results of automated penetration testing;

[0009] Implement security protection for high-risk software based on the results of automated penetration testing of high-risk software;

[0010] After implementing security protection, perform automated penetration testing again to evaluate the effectiveness of security protection.

[0011] Furthermore, the network vulnerabilities in the system are scanned by using OpenVAS technology, where the network vulnerabilities have vulnerability names.

[0012] Furthermore, performing automated penetration testing based on network vulnerabilities to detect the effectiveness of different attack types against network vulnerabilities includes the following sub-steps:

[0013] The attack types include vulnerability exploitation attacks, network layer simulation attacks, and social engineering simulation attacks;

[0014] Network vulnerabilities are numbered using the symbol NV i Represents, where i is a positive integer and i is the serial number of NV;

[0015] NV is attacked by vulnerability exploitation technology, network layer simulation attack and social engineering simulation attack in turn. iPerform a simulated attack. If NV i If it is not breached, it will output a regular vulnerability signal; if NV i If it is breached by one type of attack, it will output a single attack vulnerability signal; otherwise, it will output multiple attack vulnerability signals;

[0016] If a regular vulnerability signal is output, NV i Remove from the network vulnerability, if the output is a single attack vulnerability signal, then NV i Marked as a single attack vulnerability. If multiple attack vulnerability signals are output, NV i Marked as a multi-attack vulnerability.

[0017] Furthermore, identifying high-risk software in the system based on the results of automated penetration testing includes the following sub-steps:

[0018] Extract keywords from the names of network vulnerabilities to identify the application software to which the network vulnerabilities belong;

[0019] Identify high-risk software based on network vulnerabilities within the application software.

[0020] Furthermore, keyword extraction is performed on the vulnerability name of the network vulnerability to identify the application software to which the network vulnerability belongs, including the following sub-steps:

[0021] NV based on KeyBert keyword extraction technology i Perform keyword extraction on the vulnerability name to obtain name keywords, where the name keywords include a first number of name participles;

[0022] Get the name of the application process in the secondary directory of the application software running in the task manager and mark it as the process name;

[0023] Perform keyword extraction on the process name based on the KeyBert keyword extraction technology to obtain process keywords, wherein the process keywords include a first number of process participles;

[0024] NV i The name keywords are compared with the process keywords respectively. If any name segmentation word is the same as the process segmentation word, the number of the same name segmentation words and process segmentation words is counted and marked as the number of identical words, NV i For each application software, there is a number of identical words. Find the maximum value among them, mark it as the maximum identical word number, obtain the application software corresponding to the maximum identical word number, and set NV i Software vulnerabilities marked as application software.

[0025] Furthermore, identifying high-risk software based on network vulnerabilities in application software includes the following sub-steps:

[0026] For any application software, the attack types used when the software vulnerabilities contained in the application software are exploited are counted. If all the software vulnerabilities contained in the application software are exploited by the same attack type and no other attack types exist, a low-risk signal is output; if all the software vulnerabilities contained in the application software are exploited by two or more attack types, a high-risk signal is output;

[0027] If a low-risk signal is output, the application software is marked as low-risk software; if a high-risk signal is output, the application software is marked as high-risk software;

[0028] For any low-risk software, its corresponding attack type is marked as a software vulnerability type, and the network vulnerability of the low-risk software is repaired using the vulnerability repair technology corresponding to the software vulnerability type.

[0029] Furthermore, performing security protection on high-risk software based on the results of automated penetration testing of high-risk software includes the following sub-steps:

[0030] For any high-risk software, enable kernel isolation for the high-risk software;

[0031] Encrypt and protect the source code of software vulnerabilities contained in high-risk software.

[0032] Furthermore, encrypting the source code of software vulnerabilities contained in high-risk software includes the following sub-steps:

[0033] Obtain the source code of the software vulnerability contained in the high-risk software and name it as the vulnerability source code;

[0034] Convert the vulnerability source code into hexadecimal encoding based on ASCII encoding and name it source code encoding;

[0035] Get the number of characters in the source code, marked as Q, calculate the smallest factor of Q except 1 and 2, marked as M, calculate Q / M, marked as N;

[0036] Construct an N×M matrix, named encoding matrix, enter the characters in the source code into the encoding matrix from left to right and convert them into decimal numbers. Enter the characters from left to right and then from top to bottom, and number them H(n,m), where H(n,m) represents the character in the nth row and mth column of the encoding matrix, where n and m are both positive integers and 1≤n≤N, 1≤m≤M;

[0037] Encrypt and protect the vulnerable source code based on the coding matrix.

[0038] Furthermore, encrypting the vulnerable source code based on the encoding matrix includes the following sub-steps:

[0039] For H(n,m), calculate n+m and mark the result as the transformation number. Add H(n,m) and the transformation number to obtain F(n,m). A new matrix is ​​formed from F(n,m) based on the format of the encoding matrix and named the transformation matrix.

[0040] Convert F(n,m) to a hexadecimal number and complete it to four digits, marked as G(n,m);

[0041] Convert G(n,m) into Chinese based on Unicode encoding and mark it as C(n,m);

[0042] Combine C(n,m) in the order of n from small to large and m from small to large to obtain the encryption protection code;

[0043] After encryption protection is completed, the software vulnerabilities in high-risk software will be repaired. If they cannot be repaired, wait for the software author to update and repair them.

[0044] Furthermore, after executing the security protection, automated penetration testing is conducted again to evaluate the effectiveness of the security protection, which includes the following sub-steps:

[0045] After the network vulnerabilities are repaired and security protection is completed, the automated penetration test is performed again. If a network vulnerability is breached, a protection invalid signal is output; otherwise, a protection valid signal is output;

[0046] If the protection invalid signal is output, it marks that the network security protection is invalid. If the protection valid signal is output, it marks that the network security protection is valid.

[0047] The beneficial effects of the present invention are as follows: the present invention performs a security scan on the system to identify the network vulnerabilities therein, then performs an automated penetration test based on the network vulnerabilities to detect the effectiveness of different attack types against the network vulnerabilities, then extracts keywords from the vulnerability names of the network vulnerabilities to identify the application software to which the network vulnerabilities belong, and then identifies high-risk software based on the network vulnerabilities existing in the application software. The advantage is that different network vulnerabilities have different repair difficulties. For network vulnerabilities that are difficult to repair, the application software to which they belong is also prone to security risks. Therefore, it is necessary to identify such network vulnerabilities and application software in order to carry out targeted security protection, thereby improving the effectiveness and pertinence of network security protection.

[0048] The present invention enables kernel isolation for high-risk software, encrypts and protects the source code of software vulnerabilities contained in the high-risk software, and performs automated penetration testing again after executing security protection to evaluate the effectiveness of security protection. The present invention has the advantage that for network vulnerabilities that are easy to repair, a direct repair method is adopted, which has low repair difficulty and high repair efficiency. For network vulnerabilities that are more difficult to repair, kernel isolation is enabled for the software to which they belong first, increasing the difficulty for high-risk software to access and modify the operating system to prevent it from stealing information. The source code of the software vulnerabilities is then encrypted and protected to increase the difficulty of attacking by exploiting the vulnerabilities. The software is then repaired and protected during the repair period, thereby improving the comprehensiveness and effectiveness of network security protection. BRIEF DESCRIPTION OF THE DRAWINGS

[0049] Figure 1 is a flow chart of the steps of the method of the present invention;

[0050] Figure 2 A flowchart of the steps of the automated penetration test of the present invention;

[0051] Figure 3 Schematic diagram of the structure of the electronic device of the present invention. DETAILED DESCRIPTION

[0052] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0053] Example 1, please refer to Figure 1 As shown, the present application provides a network security protection and assessment method based on automated penetration testing, comprising the following steps:

[0054] Step S1, performing a security scan on the system to identify network vulnerabilities therein; scanning the network vulnerabilities in the system using OpenVAS technology, where the network vulnerabilities have vulnerability names;

[0055] In the specific implementation, when identifying network vulnerabilities, the existing OpenVAS technology is used for scanning and identification. All network vulnerabilities have vulnerability names. Network vulnerabilities are essentially defects in the specific implementation of hardware, software and protocols or in system security policies, that is, there are defects in the source code in the configuration file in the system or software, and the configuration file has a name, which is the vulnerability name. Since network vulnerabilities and vulnerability names involve privacy issues, it is not convenient to display them in detail in this embodiment. The vulnerability name in this embodiment is only referred to by "ASFNIOUAD", and the letters therein can be any numbers, letters or words.

[0056] See also Figure 2 As shown, step S2 performs automated penetration testing based on network vulnerabilities to detect the effectiveness of different attack types against network vulnerabilities; step S2 includes the following sub-steps:

[0057] Step S201: Attack types include vulnerability exploitation attacks, network layer simulation attacks, and social engineering simulation attacks.

[0058] Step S202: number the network vulnerabilities using the symbol NV. i Represents, where i is a positive integer and i is the serial number of NV;

[0059] Step S203: attack NV by vulnerability exploitation, network layer simulation and social engineering simulation. i Perform a simulated attack. If NV i If it is not breached, it will output a regular vulnerability signal; if NV i If it is breached by one type of attack, it will output a single attack vulnerability signal; otherwise, it will output multiple attack vulnerability signals;

[0060] Step S204: If a normal vulnerability signal is output, NV i Remove from the network vulnerability, if the output is a single attack vulnerability signal, then NV i Marked as a single attack vulnerability. If multiple attack vulnerability signals are output, NV i Marked as a multi-type attack vulnerability;

[0061] In the specific implementation, in this embodiment, a total of 7 network vulnerabilities are scanned and obtained, namely, NV i , 1≤i≤7, taking NV1 as an example, NV1 is simulated attacked in sequence through vulnerability exploitation technology attack, network layer simulation attack and social engineering simulation attack. If the effective attack type is 0, that is, the simulated attacks of the three attack types are not effective, a conventional vulnerability signal is output, and this network vulnerability poses basically no threat to network security. If the effective attack type is 1, that is, there is only one attack type that is effective in the simulated attack on NV1, a single attack vulnerability signal is output at this time, otherwise multiple attack vulnerability signals are output, indicating that NV1 can be exploited by multiple different attack types and the threat level is relatively high. In this embodiment, multiple attack vulnerability signals are output for NV1, and NV1 is marked as a multi-type attack vulnerability.

[0062] Step S3, identifying high-risk software in the system based on the results of the automated penetration test; Step S3 includes the following sub-steps:

[0063] Step S301, extracting keywords from the vulnerability name of the network vulnerability to identify the application software to which the network vulnerability belongs;

[0064] Step S301 includes the following sub-steps:

[0065] Step S3011, based on KeyBert keyword extraction technology, NV i Perform keyword extraction on the vulnerability name to obtain name keywords, where the name keywords include the first number of name participles;

[0066] Step S3012: Obtain the name of the application process in the secondary directory of the application software running in the task manager and mark it as the process name;

[0067] Step S3013: extract keywords from the process name based on the KeyBert keyword extraction technology to obtain process keywords, where the process keywords include a first number of process participles.

[0068] Step S3014, NV i The name keywords are compared with the process keywords respectively. If any name segmentation word is the same as the process segmentation word, the number of the same name segmentation words and process segmentation words is counted and marked as the number of identical words, NV i For each application software, there is a number of identical words. Find the maximum value among them, mark it as the maximum identical word number, obtain the application software corresponding to the maximum identical word number, and set NV i Software vulnerabilities marked as application software;

[0069] In the specific implementation, the existing KeyBert keyword extraction technology is used to perform name keyword extraction. Taking NV1 as an example, the vulnerability name of NV1 is "ASFNIOUAD", which does not contain quotation marks. Quotation marks are only used to limit the start and end of the vulnerability name or name segmentation. The name segmentations in the name keywords of NV1 extracted by the KeyBert keyword extraction technology include "ASF", "NIOU" and "AD". It should be noted that "ASF", "NIOU" and "AD" here are not real names. In this embodiment, they only represent aliases, indicating that three different name segmentations are extracted from the vulnerability name of NV1. The first number changes in real time according to the number of extracted name segmentations, rather than a fixed value. The process segmentations of application software A are extracted, including "ASF", "NIOU", "AD" and "SGHT". By comparison, it is found that the number of the same words between NV1 and application software A is 3, and the maximum number of the same words between NV1 and all application software is 3, and NV1 is marked as a software vulnerability of application software A.

[0070] Step S302, identifying high-risk software based on network vulnerabilities existing in the application software;

[0071] Step S302 includes the following sub-steps:

[0072] Step S3021: For any application software, count the attack types used when the software vulnerabilities contained in the application software are exploited. If all the software vulnerabilities contained in the application software are exploited by the same attack type and no other attack types exist, a low-risk signal is output; if all the software vulnerabilities contained in the application software are exploited by two or more attack types, a high-risk signal is output;

[0073] Step S3022: If a low-risk signal is output, the application software is marked as low-risk software; if a high-risk signal is output, the application software is marked as high-risk software;

[0074] Step S3023: For any low-risk software, the corresponding attack type is marked as a software vulnerability type, and the network vulnerability of the low-risk software is repaired using the vulnerability repair technology corresponding to the software vulnerability type;

[0075] In the specific implementation, taking application software A as an example, the software vulnerabilities contained in application software A include NV1, NV3 and NV4. If NV1, NV3 and NV4 are all single attack type vulnerabilities, and the effective attack types are all the same attack type, the application software will be marked as low-risk software. If NV1, NV3 and NV4 are all single attack type vulnerabilities, but there are multiple effective attack types, such as network layer simulation attacks are effective for NV3, and social engineering simulation attacks are effective for NV4, then the application software will be marked as high-risk software. If it includes multiple types of attack type vulnerabilities, the application software will be marked as high-risk software. In this embodiment, since NV1 is a multiple type of attack type vulnerability, application software A is marked as high-risk software; for low-risk software, since the vulnerability principles are the same, the complexity and difficulty of repair are low, and the repair speed is fast, it can be repaired directly.

[0076] Step S4, performing security protection on the high-risk software based on the results of the automated penetration test of the high-risk software; Step S4 includes the following sub-steps:

[0077] Step S401: For any high-risk software, enable kernel isolation for the high-risk software;

[0078] Step S402: Encrypt and protect the source code of the software vulnerabilities contained in the high-risk software;

[0079] Step S402 includes the following sub-steps:

[0080] Step S4021: Obtain the source code of the software vulnerability contained in the high-risk software and name it as vulnerability source code;

[0081] Step S4022: Convert the vulnerability source code into hexadecimal code based on ASCII code, and name it source code code.

[0082] Step S4023, obtaining the number of characters in the source code, marked as Q, calculating the smallest factor of Q excluding 1 and 2, marked as M, and calculating Q / M, marked as N;

[0083] Step S4024: Construct an N×M matrix, named encoding matrix. Enter the characters in the source code into the encoding matrix from left to right and convert them into decimal numbers. Enter the characters from left to right and then from top to bottom. The matrix is ​​numbered H(n,m), where H(n,m) represents the character in the nth row and mth column of the encoding matrix, where n and m are both positive integers and 1≤n≤N, 1≤m≤M.

[0084] In the specific implementation, since there are many vulnerable source codes, the encryption protection is carried out in units of behavior, that is, a line of code in the vulnerable source code is a vulnerable source code, and then it is encrypted and protected. Taking the vulnerable source code "data-domain-script" as an example, the converted source code is "646174612D646F6D61696E2D736372697074". There are 36 characters in the source code, so Q is 36. The factors of 36 are 1, 2, 3, 4, 6, 9, 12, 18 and 36. Except for 1 and 2, the smallest factor is 3, that is, M=3. Calculating 36 / 3 gives N=12; since all numbers contain 1 in the factors, and each character in the source code is a two-digit number when converted to hexadecimal code, Q must be divisible by 2. Only after eliminating them can the best N and M for constructing the matrix be obtained; a 12×3 encoding matrix is ​​constructed, and the source code code is entered into the encoding matrix as Convert to decimal numbers to get the encoding matrix:

[0085] Step S4025: Encrypt and protect the vulnerable source code based on the encoding matrix;

[0086] Step S4025 includes the following sub-steps:

[0087] Step S4025.1: Calculate n + m for H(n,m), mark the result as the transformation number, add H(n,m) to the transformation number to obtain F(n,m), and form a new matrix based on the encoding matrix format from F(n,m), named the transformation matrix.

[0088] Step S4025.2, convert F(n,m) into hexadecimal and complete it to a four-digit number, denoted as G(n,m);

[0089] Step S4025.3, convert G(n,m) into Chinese based on Unicode encoding and mark it as C(n,m);

[0090] Step S4025.4: Combine C(n,m) in the order of n from small to large and m from small to large to obtain an encryption protection code;

[0091] Step S4025.5: After encryption protection is complete, repair the software vulnerabilities in the high-risk software. If the vulnerabilities cannot be repaired, wait for the software author to update and repair them;

[0092] In the specific implementation, take H(5,2) as an example, n=5, m=2, H(5,2) is 15, the calculated transformation number is 7, and adding 15 and 7 to get F(5,2) is 22. Similarly, the remaining H(n,m) are transformed to get the transformation matrix: F(5,2) is 22, which is converted to hexadecimal as 16, and the four-digit complement is 0016. In the process of converting Unicode code to Chinese, every four hexadecimal digits constitute a Chinese character, so it needs to be completed to four digits. After converting F(n,m) to hexadecimal and completing it to four digits, the matrix composed of G(n,m) is obtained as follows: After converting to Chinese and combining, the encryption protection code is After encryption protection, the software vulnerabilities in high-risk software are repaired. If they cannot be repaired, wait for the software author to update and repair them.

[0093] Step S5: After executing the security protection, perform the automated penetration test again to evaluate the effectiveness of the security protection. Step S5 includes the following sub-steps:

[0094] Step S501: After the network vulnerability is repaired and the security protection is completed, the automated penetration test is performed again. If a network vulnerability is breached, a protection invalid signal is output; otherwise, a protection valid signal is output;

[0095] Step S502: If a protection invalid signal is output, the network security protection is marked invalid; if a protection valid signal is output, the network security protection is marked valid;

[0096] In the specific implementation, the software vulnerabilities in any application software are subjected to automated penetration testing again. If the software vulnerabilities are not successfully exploited, it means that the network security protection behavior is effective, otherwise the opposite is true.

[0097] Example 2, please refer to Figure 3As shown, the present application provides a structural diagram of an electronic device, which may include: a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other via the communication bus. The memory stores computer-readable instructions, and the processor can call the instructions in the memory. When the computer-readable instructions are executed by the processor, the steps in a network security protection and assessment method based on automated penetration testing are executed to achieve the following functions: perform a security scan on the system to identify network vulnerabilities therein; perform automated penetration testing based on network vulnerabilities; identify high-risk software in the system based on the results of the automated penetration testing; perform security protection on the high-risk software based on the results of the automated penetration testing of the high-risk software; and perform automated penetration testing again after performing security protection to evaluate the effectiveness of the security protection.

[0098] In addition, the logical instructions in the above-mentioned memory can be implemented in the form of a software functional unit and can be stored in a computer-readable storage medium when sold or used as an independent product. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product, which is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

[0099] Example 3. The present application also provides a computer-readable storage medium. The present application provides a storage medium on which a computer program is stored. When the computer program is executed by a processor, the steps in the above network security protection and assessment method based on automated penetration testing are executed to achieve the following functions: perform a security scan on the system to identify network vulnerabilities therein; perform automated penetration testing based on network vulnerabilities; identify high-risk software in the system based on the results of automated penetration testing; perform security protection on high-risk software based on the results of automated penetration testing of high-risk software; and perform automated penetration testing again after performing security protection to evaluate the effectiveness of security protection.

[0100] Through the description of the above embodiments, the embodiments of the present invention can be provided as methods, systems or computer program products. Based on this understanding, the above technical solutions, in essence or in other words, the part that contributes to the prior art, can be embodied in the form of a software product, which can be stored in a computer-readable storage medium, such as ROM / RAM, a magnetic disk, an optical disk, etc., and includes a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or certain parts of the embodiment.

[0101] In the embodiments provided in this application, it should be understood that the disclosed system or method can be implemented in other ways. The embodiments described above are merely illustrative. For example, the division of modules or units is only a logical function division. There may be other division methods in actual implementation. For example, multiple modules or units can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some communication interfaces, and the indirect coupling or communication connection of systems, modules and units can be electrical, mechanical or other forms.

[0102] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application.

Claims

1. A network security protection and assessment method based on automated penetration testing, characterized in that: The steps include: Perform security scans on the system to identify network vulnerabilities; Perform automated penetration testing based on network vulnerabilities to detect the effectiveness of different attack types against network vulnerabilities; Identify high-risk software in the system based on the results of automated penetration testing; Implement security protection for high-risk software based on the results of automated penetration testing of high-risk software; After implementing security protection, conduct automated penetration testing again to evaluate the effectiveness of security protection; Implementing security protection for high-risk software based on the results of automated penetration testing of high-risk software includes the following sub-steps: For any high-risk software, enable kernel isolation for the high-risk software; Encrypt and protect the source code of software vulnerabilities contained in high-risk software; Encrypting the source code of software vulnerabilities contained in high-risk software includes the following sub-steps: Obtain the source code of the software vulnerability contained in the high-risk software and name it as the vulnerability source code; Convert the vulnerability source code into hexadecimal encoding based on ASCII encoding and name it source code encoding; Get the number of characters in the source code, marked as Q, calculate the smallest factor of Q except 1 and 2, marked as M, calculate Q / M, marked as N; Construct an N×M matrix, named encoding matrix, enter the characters in the source code into the encoding matrix from left to right and convert them into decimal numbers. Enter the characters from left to right and then from top to bottom, and number them H(n,m), where H(n,m) represents the character in the nth row and mth column of the encoding matrix, where n and m are both positive integers and 1≤n≤N, 1≤m≤M; Encrypt and protect the vulnerable source code based on the coding matrix; Encrypting and protecting the vulnerable source code based on the coding matrix includes the following sub-steps: For H(n,m), calculate n+m and mark the result as the transformation number. Add H(n,m) and the transformation number to obtain F(n,m). A new matrix is ​​formed from F(n,m) based on the format of the encoding matrix and named the transformation matrix. Convert F(n,m) to a hexadecimal number and complete it to four digits, marked as G(n,m); Convert G(n,m) into Chinese based on Unicode encoding and mark it as C(n,m); Combine C(n,m) in the order of n from small to large and m from small to large to obtain the encryption protection code; After encryption protection is completed, the software vulnerabilities in high-risk software will be repaired. If they cannot be repaired, wait for the software author to update and repair them.

2. A network security protection and assessment method based on automated penetration testing according to claim 1, characterized in that: The system is scanned for network vulnerabilities using the OpenVAS technology, where the network vulnerabilities have vulnerability names.

3. A network security protection and assessment method based on automated penetration testing according to claim 2, characterized in that: Performing automated penetration testing based on network vulnerabilities to detect the effectiveness of different attack types against network vulnerabilities includes the following sub-steps: The attack types include vulnerability exploitation attacks, network layer simulation attacks, and social engineering simulation attacks; Network vulnerabilities are numbered using the symbol NV i Represents, where i is a positive integer and i is the serial number of NV; NV is attacked by vulnerability exploitation technology, network layer simulation attack and social engineering simulation attack in turn. i Perform a simulated attack. If NV i If it is not breached, it will output a regular vulnerability signal; if NV i If it is breached by one type of attack, it will output a single attack vulnerability signal; otherwise, it will output multiple attack vulnerability signals; If a regular vulnerability signal is output, NV i Remove from the network vulnerability, if the output is a single attack vulnerability signal, then NV i Marked as a single attack vulnerability. If multiple attack vulnerability signals are output, NV i Marked as a multi-attack vulnerability.

4. A network security protection and assessment method based on automated penetration testing according to claim 3, characterized in that: Identifying high-risk software in a system based on the results of automated penetration testing includes the following sub-steps: Extract keywords from the names of network vulnerabilities to identify the application software to which the network vulnerabilities belong; Identify high-risk software based on network vulnerabilities within the application software.

5. A network security protection and assessment method based on automated penetration testing according to claim 4, characterized in that: Extracting keywords from the vulnerability names of network vulnerabilities and identifying the application software to which the network vulnerabilities belong includes the following sub-steps: NV based on KeyBert keyword extraction technology i Perform keyword extraction on the vulnerability name to obtain name keywords, where the name keywords include a first number of name participles; Get the name of the application process in the secondary directory of the application software running in the task manager and mark it as the process name; Perform keyword extraction on the process name based on the KeyBert keyword extraction technology to obtain process keywords, wherein the process keywords include a first number of process participles; NV i The name keywords are compared with the process keywords respectively. If any name segmentation word is the same as the process segmentation word, the number of the same name segmentation words and process segmentation words is counted and marked as the number of identical words, NV i For each application software, there is a number of identical words. Find the maximum value among them, mark it as the maximum identical word number, obtain the application software corresponding to the maximum identical word number, and set NV i Software vulnerabilities marked as application software.

6. A network security protection and assessment method based on automated penetration testing according to claim 5, characterized in that: Identifying high-risk software based on network vulnerabilities within application software includes the following sub-steps: For any application software, the attack types used when the software vulnerabilities contained in the application software are exploited are counted. If all the software vulnerabilities contained in the application software are exploited by the same attack type and no other attack types exist, a low-risk signal is output; if all the software vulnerabilities contained in the application software are exploited by two or more attack types, a high-risk signal is output; If a low-risk signal is output, the application software is marked as low-risk software; if a high-risk signal is output, the application software is marked as high-risk software; For any low-risk software, its corresponding attack type is marked as a software vulnerability type, and the network vulnerability of the low-risk software is repaired using the vulnerability repair technology corresponding to the software vulnerability type.

7. A network security protection and assessment method based on automated penetration testing according to claim 6, characterized in that: After implementing security protection, automated penetration testing is conducted again to evaluate the effectiveness of security protection, which includes the following sub-steps: After the network vulnerabilities are repaired and security protection is completed, the automated penetration test is performed again. If a network vulnerability is breached, a protection invalid signal is output; otherwise, a protection valid signal is output; If the protection invalid signal is output, it marks that the network security protection is invalid. If the protection valid signal is output, it marks that the network security protection is valid.

Citation Information

Patent Citations

  • Network system safety protection method and device and related equipment thereof

    CN111049827A

  • Method and system for carrying out penetration test on network safety equipment

    CN102468985A

  • Internet of Things protection method, device and system

    CN110099041A