POC plug-in dynamic loading method and device based on concurrent scanning

Through the dynamic loading method of POC plug-in based on concurrent scanning, the problem that vulnerability scanning in the existing technology cannot adapt to the rapidly changing needs is solved, efficient and flexible vulnerability scanning is achieved, and scanning quality and efficiency are improved.

CN119987886APending Publication Date: 2025-05-13CHINA NUCLEAR POWER OPERATION TECH CORP +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411769240.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-04
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

The existing technology cannot effectively adapt to the rapidly changing vulnerability scanning needs and diversified network environments, resulting in difficulty in improving the quality and efficiency of vulnerability scanning.

Method used

The dynamic loading method of POC plug-in based on concurrent scanning is adopted. By setting goals and vulnerability types, multiple POC plug-ins are dynamically loaded and called for vulnerability verification, and the scanning efficiency is improved by using coroutine technology and preset plug-in interfaces.

Benefits of technology

It realizes dynamic loading of POC plug-ins to adapt to different scanning needs, improves the quality and efficiency of vulnerability scanning, supports high concurrency scanning tasks, and simplifies plug-in maintenance and updates.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119987886A_ABST
    Figure CN119987886A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of nuclear power, and particularly relates to a POC plug-in dynamic loading method and device based on concurrent scanning. According to the POC plug-in dynamic loading method based on concurrent scanning, the POC plug-in can be dynamically loaded according to the setting of actual vulnerability scanning, a system can flexibly adapt to different scanning requirements, and main scanning engine codes do not need to be modified. According to the method, the scanning function is modularized into the POC plug-ins, so that maintenance and updating can be carried out more easily, and only implementation details of each plug-in need to be concerned without worrying about influences on other parts of the system. The new vulnerability can be realized by writing and adding a new POC plug-in, and an existing system does not need to be greatly changed, so that the dynamic expansibility of vulnerability scanning is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of network security, and in particular relates to a POC plug-in dynamic loading method and device based on concurrent scanning. Background Art

[0002] In the field of network security, POC (Proof of Concept) usually refers to a code snippet that can verify the existence of a certain vulnerability or a certain type of vulnerability. As a core extension of vulnerability scanning tools, POC plug-ins can help scanning tools detect more types of vulnerabilities. For example, many network security tools (such as Burp Suite, pocsuite3, etc.) support POC plug-ins, which greatly enhances their detection capabilities. Users can write POC plug-ins according to actual needs to scan specific vulnerabilities.

[0003] However, with the rapid development of network technology, new vulnerabilities emerge in an endless stream. The above methods cannot adapt to the rapidly changing and growing vulnerability scanning needs and diversified network environments. Therefore, there is an urgent need to improve the quality and efficiency of vulnerability scanning. Summary of the invention

[0004] In order to overcome the problems existing in the related art, a POC plug-in dynamic loading method and device based on concurrent scanning are provided.

[0005] According to one aspect of an embodiment of the present disclosure, a POC plug-in dynamic loading method based on concurrent scanning is provided, the method comprising:

[0006] Step 11, setting a target to be scanned and multiple vulnerability types that need to be verified for the target;

[0007] Step 12, determining a POC plug-in corresponding to each vulnerability type according to multiple vulnerability types contained in the target to be scanned and a first mapping relationship between the pre-stored vulnerability type and the POC plug-in;

[0008] Step 13, calling multiple POC plug-ins at the same time to verify the vulnerability of the target, and generating a verification result after the verification is completed. Each POC plug-in is used to verify the corresponding type of vulnerability, and the verification result is used to describe whether the set vulnerability types exist.

[0009] In one possible implementation, in step 13, coroutine technology is used to control the CPU to execute other codes when I / O blocking is detected, and the transmission data is switched between switch threads, registers, and stacks to reduce the operating system switching overhead.

[0010] In one possible implementation, in step 13, the terminal device simultaneously sends a POC plug-in corresponding to each target to multiple targets; or simultaneously sends different types of POC to the same target; or cyclically sends a POC plug-in to verify vulnerabilities to multiple targets until a corresponding vulnerability is verified from one of the multiple targets.

[0011] In a possible implementation, the preset plug-in interface is a standard interface, which is used to perform initialization, execution, and result return operations of the plug-in.

[0012] In a possible implementation, the pre-stored mapping relationship can add, modify or delete the associated entry between the vulnerability type and the POC plug-in.

[0013] In a possible implementation, the method further includes:

[0014] Step 14, when a newly released vulnerability is detected on the target website, the newly added vulnerability information is obtained from the target website, thereby obtaining the vulnerability type, triggering conditions, sent payload, and expected response data;

[0015] Step 15, obtaining a POC plug-in template corresponding to the vulnerability type according to the acquired vulnerability type and a second mapping relationship between the pre-stored vulnerability type and the POC plug-in module;

[0016] Step 16, automatically fill the analyzed trigger conditions, sent payload and expected response data into the POC plug-in template, obtain the POC plug-in corresponding to the newly added vulnerability type, and store it in the first mapping relationship.

[0017] In a possible implementation, before the POC plug-in needs to send packets to the target host, the POC plug-in determines the packet size and frequency according to the current CPU usage of the host and the maximum CPU tolerance threshold corresponding to the host type.

[0018] In one possible implementation, before the POC plug-in executes packet sending, the terminal device obtains the current usage rate of the host, and determines the estimated CPU usage rate corresponding to each combination of POC plug-in packet sending size and packet sending frequency, and the CPU maximum tolerance threshold corresponding to the host type based on the current usage rate of the host, and uses the POC plug-in packet sending size and packet sending frequency with an estimated usage rate that is less than and closest to the CPU maximum tolerance threshold as the packet sending size and packet sending frequency of the actual POC packet sending execution.

[0019] According to another aspect of an embodiment of the present disclosure, a POC plug-in dynamic loading device based on concurrent scanning is provided, the device comprising:

[0020] A setting module, used to set a target to be scanned and multiple vulnerability types that need to be verified for the target;

[0021] A determination module, used to determine the POC plug-in corresponding to each vulnerability type according to multiple vulnerability types contained in the target to be scanned and a first mapping relationship between the pre-stored vulnerability type and the POC plug-in;

[0022] The scanning module is used to call multiple POC plug-ins at the same time to verify the vulnerability of the target and generate verification results after the verification. Each POC plug-in is used to verify the corresponding type of vulnerability, and the verification result is used to describe whether the set vulnerability types exist.

[0023] According to another aspect of an embodiment of the present disclosure, a POC plug-in dynamic loading device based on concurrent scanning is provided, the device comprising:

[0024] processor;

[0025] a memory for storing processor-executable instructions;

[0026] Wherein, the processor is configured to execute the above method.

[0027] According to another aspect of an embodiment of the present disclosure, a non-volatile computer-readable storage medium is provided, on which computer program instructions are stored, and the computer program instructions implement the above method when executed by a processor.

[0028] The beneficial effect of the present disclosure is that the present disclosure provides a POC plug-in dynamic loading method based on concurrent scanning, which can dynamically load the POC plug-in according to the actual vulnerability scanning settings, and the system can flexibly adapt to different scanning requirements without modifying the main scanning engine code.

[0029] The present disclosure modularizes the scanning function into POC plug-ins, which can be maintained and updated more easily, because only the implementation details of each plug-in need to be paid attention to, without worrying about the impact on other parts of the system. New vulnerabilities can be implemented by writing and adding new POC plug-ins without making major changes to the existing system, thereby achieving dynamic scalability of vulnerability scanning.

[0030] Since the POC plug-in is executed as an independent process or thread, the method disclosed in the present invention can execute multiple scanning tasks at the same time, thereby improving scanning efficiency and throughput and achieving high concurrency. In addition, users can select and configure the fixed-value POC plug-in according to their needs to achieve a customized scanning solution to better meet their needs. BRIEF DESCRIPTION OF THE DRAWINGS

[0031] Figure 1It is a flowchart of a POC plug-in dynamic loading method based on concurrent scanning shown in an embodiment of the present disclosure.

[0032] Figure 2 It is a block diagram of a POC plug-in dynamic loading device based on concurrent scanning shown in an embodiment of the present disclosure. DETAILED DESCRIPTION

[0033] The present disclosure is further described in detail below with reference to the accompanying drawings and specific embodiments.

[0034] Unless otherwise defined, the technical and scientific terms used in the present disclosure have the same meanings as those generally understood by those skilled in the art to which the present disclosure belongs; the terms used in the present disclosure are only for the purpose of describing specific embodiments and are not intended to limit the present disclosure; the term "including" and any variations thereof in the present disclosure are intended to cover non-exclusive inclusions. Obviously, the embodiments described in the present disclosure are only part of the embodiments of the present disclosure, not all of the embodiments. Based on the embodiments in the present disclosure, all other embodiments obtained by ordinary technicians in the field without making creative efforts are within the scope of protection of the present disclosure.

[0035] Reference to "embodiments" in this disclosure means that a particular feature, structure, or characteristic described in conjunction with the embodiments may be included in at least one embodiment of the disclosure. The appearance of the phrase in various places in the specification does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment that is mutually exclusive with other embodiments. It is explicitly and implicitly understood by those skilled in the art that the embodiments described herein may be combined with other embodiments.

[0036] Figure 1 1 is a flowchart of a method for dynamically loading a POC plug-in based on concurrent scanning shown in an embodiment of the present disclosure. The method can be executed by a terminal device, wherein the terminal device can be a server, a desktop computer, a laptop computer, etc. The embodiment of the present disclosure does not limit the type of the terminal device. Figure 1 As shown, the method includes:

[0037] Step 11, the terminal device sets the target to be scanned and multiple vulnerability types that need to be verified for the target according to the user's needs. The target can be, for example, a network, an application, or an interface, etc. The present disclosure does not limit the type of the target and the type of vulnerability.

[0038] Step 12: The terminal device determines a POC plug-in corresponding to each vulnerability type according to multiple vulnerability types contained in the target to be scanned and a first mapping relationship between the pre-stored vulnerability type and the POC plug-in.

[0039] In step 13, the terminal device uses a preset plug-in interface to simultaneously call multiple POC plug-ins to verify the vulnerability of the target, and generates a verification result after the verification is completed. Each POC plug-in is used to verify the corresponding type of vulnerability, and the verification result is used to describe whether the set vulnerability types exist.

[0040] As an example of this embodiment, in step 13, the terminal device can meet the high concurrency requirements of the POC plug-in by combining a single thread with coroutine technology. In traditional multi-threaded tasks, task switching is controlled by the operating system, and automatically switches to other threads when I / O blocking occurs; and coroutines are a lightweight thread technology controlled by the program itself. When I / O blocking is detected, the coroutine can actively switch the CPU to other tasks without the need for thread switching management by the operating system, thereby reducing the system overhead caused by context switching.

[0041] In I / O-intensive tasks, coroutines allow the CPU to execute other tasks while waiting for I / O, keeping the CPU as busy as possible and improving program execution efficiency. In socket-based TCP communication, coroutines enable single threads to achieve high concurrency processing. Compared with multithreading, they avoid frequent thread context switching and further improve concurrency efficiency.

[0042] In a possible implementation, the preset plug-in interface can be a standard interface for performing operations such as plug-in initialization, execution, and result return. For example, the dynamic loading of plug-ins can be achieved by using Python's built-in function __import_(). This system function is used to dynamically load classes and functions to solve the problem of frequent module changes.

[0043] In one possible implementation, the pre-stored mapping relationship can add, modify or delete the associated entries between the vulnerability type and the POC plug-in. For example, network security personnel can write a corresponding POC plug-in for a certain type of vulnerability and store it in the first mapping relationship;

[0044] For another example, the terminal device may also obtain newly released vulnerability information and automatically generate a corresponding POC plug-in to supplement the first mapping relationship. The method further includes:

[0045] Step 14, when the terminal device detects a newly released vulnerability on the target website, it obtains the newly added vulnerability information from the target website. For example, it can use targeted crawler technology to obtain vulnerability update content through HTML structure parsing or API data interface, thereby obtaining the vulnerability type, trigger conditions, sent payload, and expected response data.

[0046] Step 15, according to the acquired vulnerability type and the second mapping relationship between the pre-stored vulnerability type and the POC plug-in module (network security personnel can set the POC plug-in template pre-stored in the second mapping relationship according to each vulnerability type), obtain the POC plug-in template corresponding to the vulnerability type.

[0047] Step 16, automatically fill the analyzed trigger conditions, sent payload and expected response data into the POC plug-in template, obtain the POC plug-in corresponding to the newly added vulnerability type, and store it in the first mapping relationship.

[0048] In this way, the present disclosure can add POC plug-ins corresponding to the vulnerabilities according to the new vulnerabilities of major websites, thereby dynamically adapting to the changes in the vulnerabilities and meeting the vulnerability scanning needs.

[0049] In a possible implementation, before the POC plug-in needs to send packets to the target host, the POC plug-in determines the packet size and frequency according to the current CPU usage of the host and the maximum CPU tolerance threshold corresponding to the host type.

[0050] For example, the normal range of host CPU usage depends on the task load, which is 10%-30% for light use and 30%-70% for moderate use. Before the POC plug-in executes the packet, the terminal device first collects the current usage of the host. Based on the current usage of the host, it determines the estimated CPU usage corresponding to each combination of POC plug-in packet size and packet frequency, as well as the CPU maximum tolerance threshold corresponding to the host type, and uses the POC plug-in packet size and packet frequency with an estimated usage less than and closest to the CPU maximum tolerance threshold as the packet size and packet frequency of the actual POC execution packet. The CPU maximum tolerance threshold corresponding to the host type can be statistically analyzed based on the empirical values ​​executed on different types of hosts.

[0051] In the related art, the POC plug-in usually uses uncontrolled packet sending to the host (i.e., sending a payload to the host), which may cause the target host to have a blue screen, freeze, or consume too much machine performance. It may also be prohibited by the host due to excessive packet sending frequency. In view of this situation, before the POC plug-in sends a packet, the present invention first evaluates the performance of the object under test, estimates the tolerable packet size, frequency, and executable operations, and then controls the size and frequency of the packet through flexible parameter settings, thereby improving the security and concealment of the POC plug-in's packet sending operation.

[0052] According to another aspect of an embodiment of the present disclosure, a POC plug-in dynamic loading device based on concurrent scanning is provided, the device comprising:

[0053] A setting module, used to set a target to be scanned and multiple vulnerability types that need to be verified for the target;

[0054] A determination module, used to determine the POC plug-in corresponding to each vulnerability type according to multiple vulnerability types contained in the target to be scanned and a first mapping relationship between the pre-stored vulnerability type and the POC plug-in;

[0055] The scanning module is used to call multiple POC plug-ins at the same time to verify the vulnerability of the target and generate verification results after the verification. Each POC plug-in is used to verify the corresponding type of vulnerability, and the verification result is used to describe whether the set vulnerability types exist.

[0056] The description of the above-mentioned device has been explained in detail in the description of the above-mentioned method, and will not be repeated here.

[0057] Figure 2 1900 is a block diagram of a POC plug-in dynamic loading device based on concurrent scanning according to an embodiment of the present disclosure. For example, the device 1900 may be provided as a server. Figure 2 , the apparatus 1900 includes a processing component 1922, which further includes one or more processors, and a memory resource represented by a memory 1932 for storing instructions, such as an application, that can be executed by the processing component 1922. The application stored in the memory 1932 may include one or more modules, each corresponding to a set of instructions. In addition, the processing component 1922 is configured to execute instructions to perform the above method.

[0058] The device 1900 may also include a power supply component 1926 configured to perform power management of the device 1900, a wired or wireless network interface 1950 configured to connect the device 1900 to a network, and an input / output (I / O) interface 1958. The device 1900 may operate based on an operating system stored in the memory 1932, such as Windows Server™, MacOS X™, Unix™, Linux™, FreeBSD™, or the like.

[0059] In an exemplary embodiment, a non-volatile computer-readable storage medium is also provided, such as a memory 1932 including computer program instructions, which can be executed by the processing component 1922 of the device 1900 to perform the above method.

[0060] The present disclosure may be a system, a method and / or a computer program product. The computer program product may include a computer-readable storage medium carrying computer-readable program instructions for causing a processor to implement various aspects of the present disclosure.

[0061] A computer-readable storage medium may be a tangible device that can hold and store instructions used by an instruction execution device. A computer-readable storage medium may be, for example, but not limited to, an electrical storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination of the foregoing. More specific examples of computer-readable storage media (a non-exhaustive list) include: a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a static random access memory (SRAM), a portable compact disk read-only memory (CD-ROM), a digital versatile disk (DVD), a memory stick, a floppy disk, a mechanical encoding device, such as a punch card or a raised structure in a groove on which instructions are stored, and any suitable combination of the foregoing. As used herein, a computer-readable storage medium is not to be interpreted as a transient signal per se, such as a radio wave or other freely propagating electromagnetic wave, an electromagnetic wave propagating through a waveguide or other transmission medium (e.g., a light pulse through a fiber optic cable), or an electrical signal transmitted through a wire.

[0062] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to each computing / processing device, or downloaded to an external computer or external storage device via a network, such as the Internet, a local area network, a wide area network, and / or a wireless network. The network can include copper transmission cables, optical fiber transmissions, wireless transmissions, routers, firewalls, switches, gateway computers, and / or edge servers. The network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards the computer-readable program instructions for storage in the computer-readable storage medium in each computing / processing device.

[0063] The computer program instructions for performing the operation of the present disclosure may be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-related instructions, microcode, firmware instructions, state setting data, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages, such as Smalltalk, C++, etc., and conventional procedural programming languages, such as "C" language or similar programming languages. Computer-readable program instructions may be executed completely on a user's computer, partially on a user's computer, as an independent software package, partially on a user's computer, partially on a remote computer, or completely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., using an Internet service provider to connect via the Internet). In some embodiments, an electronic circuit, such as a programmable logic circuit, a field programmable gate array (FPGA), or a programmable logic array (PLA), may be customized by utilizing the state information of the computer-readable program instructions, and the electronic circuit may execute the computer-readable program instructions, thereby realizing various aspects of the present disclosure.

[0064] Various aspects of the present disclosure are described herein with reference to the flowcharts and / or block diagrams of the methods, devices (systems) and computer program products according to the embodiments of the present disclosure. It should be understood that each box in the flowchart and / or block diagram and the combination of each box in the flowchart and / or block diagram can be implemented by computer-readable program instructions.

[0065] These computer-readable program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, thereby producing a machine, so that when these instructions are executed by the processor of the computer or other programmable data processing device, a device that implements the functions / actions specified in one or more boxes in the flowchart and / or block diagram is generated. These computer-readable program instructions can also be stored in a computer-readable storage medium, and these instructions cause the computer, programmable data processing device, and / or other equipment to work in a specific manner, so that the computer-readable medium storing the instructions includes a manufactured product, which includes instructions for implementing various aspects of the functions / actions specified in one or more boxes in the flowchart and / or block diagram.

[0066] Computer-readable program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other device so that a series of operating steps are performed on the computer, other programmable data processing apparatus, or other device to produce a computer-implemented process, thereby causing the instructions executed on the computer, other programmable data processing apparatus, or other device to implement the functions / actions specified in one or more boxes in the flowchart and / or block diagram.

[0067] The flow chart and block diagram in the accompanying drawings show the possible architecture, function and operation of the system, method and computer program product according to multiple embodiments of the present disclosure. In this regard, each square box in the flow chart or block diagram can represent a part of a module, program segment or instruction, and a part of the module, program segment or instruction includes one or more executable instructions for realizing the specified logical function. In some alternative implementations, the function marked in the square box can also occur in a sequence different from that marked in the accompanying drawings. For example, two continuous square boxes can actually be executed substantially in parallel, and they can sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each square box in the block diagram and / or flow chart, and the combination of the square boxes in the block diagram and / or flow chart can be implemented with a dedicated hardware-based system that performs the specified function or action, or can be implemented with a combination of special hardware and computer instructions.

[0068] The embodiments of the present disclosure have been described above, and the above description is exemplary, not exhaustive, and is not limited to the disclosed embodiments. Many modifications and changes will be apparent to those of ordinary skill in the art without departing from the scope and spirit of the described embodiments. The selection of terms used herein is intended to best explain the principles of the embodiments, practical applications, or improvements to the technology in the market, or to enable other persons of ordinary skill in the art to understand the embodiments disclosed herein.

Claims

1. A POC plug-in dynamic loading method based on concurrent scanning, characterized in that: The method comprises: Step 11, setting a target to be scanned and multiple vulnerability types that need to be verified for the target; Step 12, determining a POC plug-in corresponding to each vulnerability type according to multiple vulnerability types contained in the target to be scanned and a first mapping relationship between the pre-stored vulnerability type and the POC plug-in; Step 13, calling multiple POC plug-ins at the same time to verify the vulnerability of the target, and generating a verification result after the verification is completed. Each POC plug-in is used to verify the corresponding type of vulnerability, and the verification result is used to describe whether the set vulnerability types exist.

2. The method according to claim 1, characterized in that In step 13, the coroutine technology is used to control the CPU to execute other codes when I / O blocking is detected, and the transmission data is switched between the switch threads, registers, and stacks to reduce the operating system switching overhead.

3. The method according to claim 1, characterized in that In step 13, the terminal device sends the POC plug-in corresponding to each target to multiple targets at the same time; or sends different types of POC to the same target at the same time; or sends the POC plug-in to verify the vulnerability to multiple targets in a loop until the corresponding vulnerability is verified from one of the multiple targets.

4. The method according to claim 1, characterized in that The default plug-in interface is a standard interface used to perform plug-in initialization, execution, and result return operations.

5. The method according to claim 1, characterized in that The pre-existing mapping relationship can add, modify or delete the associated entries between the vulnerability type and the POC plug-in.

6. The method according to claim 1, characterized in that The method further comprises: Step 14, when a newly released vulnerability is detected on the target website, the newly added vulnerability information is obtained from the target website, thereby obtaining the vulnerability type, triggering conditions, sent payload, and expected response data; Step 15, obtaining a POC plug-in template corresponding to the vulnerability type according to the acquired vulnerability type and a second mapping relationship between the pre-stored vulnerability type and the POC plug-in module; Step 16, automatically fill the analyzed trigger conditions, sent payload and expected response data into the POC plug-in template, obtain the POC plug-in corresponding to the newly added vulnerability type, and store it in the first mapping relationship.

7. The method according to claim 1, characterized in that Before the POC plug-in needs to send a packet to the target host, the POC plug-in determines the packet size and frequency according to the current CPU usage of the host and the maximum CPU tolerance threshold corresponding to the host type.

8. The method according to claim 7, characterized in that Before the POC plug-in executes the packet sending, the terminal device obtains the current usage rate of the host, and determines the estimated CPU usage rate corresponding to each combination of the POC plug-in packet size and packet sending frequency, as well as the CPU maximum tolerance threshold corresponding to the host type based on the current usage rate of the host. The POC plug-in packet sending size and packet sending frequency with an estimated usage rate less than and closest to the CPU maximum tolerance threshold are used as the packet sending size and packet sending frequency of the actual POC execution packet sending.

9. A POC plug-in dynamic loading device based on concurrent scanning, characterized in that: The device comprises: A setting module, used to set a target to be scanned and multiple vulnerability types that need to be verified for the target; A determination module, used to determine the POC plug-in corresponding to each vulnerability type according to multiple vulnerability types contained in the target to be scanned and a first mapping relationship between the pre-stored vulnerability type and the POC plug-in; The scanning module is used to call multiple POC plug-ins at the same time to verify the vulnerability of the target and generate verification results after the verification. Each POC plug-in is used to verify the corresponding type of vulnerability, and the verification result is used to describe whether the set vulnerability types exist.

10. A POC plug-in dynamic loading device based on concurrent scanning, characterized in that: The device comprises: processor; a memory for storing processor-executable instructions; The processor is configured to execute the method according to any one of claims 1 to 8.

11. A non-volatile computer-readable storage medium having computer program instructions stored thereon, characterized in that: When the computer program instructions are executed by a processor, the method according to any one of claims 1 to 8 is implemented.