Method and system for performing security test according to enterprise name
By crawling enterprise investment information and forming new enterprise secondary domain names for security testing, the problem that existing technology cannot effectively detect enterprise domain name vulnerabilities is solved, and a comprehensive security assessment and vulnerability discovery of enterprise information systems is achieved.
Patent Information
- Application Number
- CN202411910766.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-24
- Publication Date
- 2025-05-13
Smart Images

Figure CN119995925A_ABST
Abstract
Description
Technical Field
[0001] The invention relates to a method and a system for performing security testing according to enterprise names, belonging to the technical field of network security. Background Art
[0002] With the rapid development of Internet technology, the degree of informatization of enterprises has been continuously improved, and various network systems and domain names have become an important support for enterprise operations.
[0003] In the tide of digital transformation, enterprise information systems have become the core infrastructure to support business operations. As the scale of enterprises expands and business needs continue to evolve, various information systems are constantly built and superimposed, gradually forming a complex system architecture. These systems cover various business areas from human resources, financial management, supply chain to customer service, and the number often reaches dozens or even hundreds. However, enterprises face severe management challenges in the process of information system construction: potential vulnerabilities may lead to serious consequences such as enterprise information leakage and system paralysis.
[0004] Existing security detection methods are often not comprehensive and in-depth enough to effectively conduct comprehensive vulnerability detection and security assessment of enterprise domain names and related systems. Therefore, in this context, comprehensive identification and management of enterprise informationization vulnerabilities has become an important issue that needs to be solved urgently. Summary of the invention
[0005] In order to solve the above problems, the present invention proposes a method and system for performing security testing based on enterprise names, which can perform security vulnerability testing based on the characteristics of the enterprise's second-level domain name and provide support for discovering hidden vulnerabilities.
[0006] The technical solution adopted by the present invention to solve the technical problem is:
[0007] In a first aspect, an embodiment of the present invention provides a method for performing a security test based on an enterprise name, comprising the following steps:
[0008] Step S1, obtaining relevant information of the enterprise to be tested and crawling its investment enterprise information, wherein the relevant information includes the full Chinese name and enterprise domain name of the enterprise to be tested;
[0009] Step S2, performing domain name analysis on the crawled investment enterprise information to obtain the enterprise domain name, agreement and main domain name of the investment enterprise;
[0010] Step S3, based on obtaining the enterprise domain name of the invested enterprise, the agreement of the invested enterprise and the primary domain name, a new enterprise secondary domain name is formed and tested;
[0011] Step S4, performing security tests on enterprise domain names at all levels and secondary domain names at all levels and recording the test results;
[0012] Step S5, generating a safety test report based on the test results.
[0013] As a possible implementation of this embodiment, the step S1, obtaining relevant information of the enterprise to be tested and crawling its investment enterprise information, includes:
[0014] Get the full Chinese name and domain name of the enterprise to be tested;
[0015] Use crawler technology to crawl investment companies that hold more than 50% of the shares of the company to be tested, and record the names and domain names of the investment companies;
[0016] According to the names and domain names of the crawled investment enterprises, the secondary investment enterprises in which the investment enterprises hold more than 50% of the shares are further crawled, and this process is repeated recursively until no new investment enterprises can be crawled.
[0017] As a possible implementation of this embodiment, step S2, performing domain name analysis on the crawled investment enterprise information to obtain the enterprise domain name, the agreement and the main domain name of the investment enterprise, includes:
[0018] Analyze all crawled enterprise domain names and divide them into protocol names, host names, and primary domain names using regular expressions;
[0019] The protocol of the target domain name is determined based on the protocol name. If it is http or https, the domain name is further analyzed. If there is no protocol name, https is used by default.
[0020] As a possible implementation of this embodiment, step S3, based on obtaining the enterprise domain name of the invested enterprise, the agreement of the invested enterprise and the primary domain name, forms a new enterprise secondary domain name and performs a test, including:
[0021] Combine the enterprise domain name, agreement and primary domain name of the invested enterprise with the enterprise's commonly used system name dictionary to form a new enterprise secondary domain name;
[0022] The new enterprise secondary domain name is queried through DNS query and TCP connection. If the query has a response, it proves that the generated domain name exists.
[0023] As a possible implementation method of this embodiment, the names of the commonly used enterprise systems include EMAIL system (mail system), OA system (office automation system), CRM system (customer relationship management system), ERP system (enterprise resource planning system), MES system (manufacturing execution system), HRM system (human resource management system), SCM system (supply chain management system), WMS system (warehouse management system), OMS system (order management system), CMS system (content management system) and BI system (enterprise decision-making system).
[0024] As a possible implementation of this embodiment, the step S4, performing security tests on enterprise domain names at all levels and enterprise secondary domain names at all levels and recording the test results, includes:
[0025] Conduct N-day vulnerability tests on all enterprise domain names and sub-domain names at all levels. The N-day vulnerability tests include Apache vulnerability tests, IIS vulnerability tests, Nginx vulnerability tests, and various database vulnerability tests.
[0026] Conduct targeted vulnerability testing on the secondary domain name and host name characteristics of enterprises at all levels;
[0027] Use crawler technology to crawl URLs (Uniform Resource Locator) of enterprise domain names at all levels, and perform general vulnerability tests on the crawled URLs;
[0028] Generate dynamic URLs based on crawled URLs and perform general vulnerability tests on the generated dynamic URLs.
[0029] As a possible implementation method of this embodiment, the general vulnerability test includes SQL injection test, session management test, HTTP method test, user enumeration test, cross-site scripting attack test, unauthorized access test, cross-site request forgery test, user password brute force test, authentication mode bypass test, logout and browser cache management test, path traversal test and system command execution test.
[0030] As a possible implementation of this embodiment, the generating of a dynamic URL based on the crawled URL includes:
[0031] Mark the paths and parameters in the crawled URLs;
[0032] Modify the marked path and store the modified path;
[0033] The crawled URL and the marked parameter values are modified sequentially and randomly to form a dynamic URL.
[0034] As a possible implementation of this embodiment, the step S5, forming a safety test report according to the test results, includes:
[0035] Sort out the collected enterprise domain names, generated enterprise domain names, and vulnerabilities discovered during security testing, and classify and grade the discovered vulnerabilities;
[0036] Formulate a security test rectification plan based on the causes of the vulnerabilities and the results of classification and grading;
[0037] All results are summarized into a final safety test report.
[0038] In a second aspect, an embodiment of the present invention provides a system for performing security testing based on an enterprise name, including:
[0039] An enterprise information acquisition module is used to obtain relevant information of the enterprise to be tested and crawl its investment enterprise information, wherein the relevant information includes the full Chinese name and enterprise domain name of the enterprise to be tested;
[0040] The domain name analysis module is used to perform domain name analysis on the crawled investment enterprise information to obtain the enterprise domain name, agreement and main domain name of the investment enterprise;
[0041] A secondary domain name generation module is used to generate a new secondary domain name of an enterprise and conduct testing based on the enterprise domain name, agreement and primary domain name of the invested enterprise;
[0042] Security testing module, used to conduct security tests on enterprise domain names at all levels and secondary domain names at all levels and record the test results;
[0043] The test report generation module is used to generate a safety test report based on the test results.
[0044] The beneficial effects of the technical solution of the embodiment of the present invention are as follows:
[0045] A method for performing security testing based on the name of an enterprise in the technical solution of an embodiment of the present invention comprises the following steps: step S1, obtaining relevant information of the enterprise to be tested and crawling its investment enterprise information, wherein the relevant information includes the full Chinese name and enterprise domain name of the enterprise to be tested; step S2, performing domain name analysis on the crawled investment enterprise information, obtaining the enterprise domain name, the agreement and the main domain name of the investment enterprise; step S3, based on obtaining the enterprise domain name, the agreement and the main domain name of the investment enterprise, forming a new enterprise secondary domain name and performing a test; step S4, performing security testing on the enterprise domain names and the secondary domain names of enterprises at all levels and recording the test results; step S5, forming a security test report according to the test results. The present invention automatically identifies and searches for companies at all levels controlled by the enterprise by enterprise name, thereby ensuring the breadth and comprehensiveness of the test scope; by detecting and discovering the enterprise secondary domain name, and performing security vulnerability testing according to the characteristics of the enterprise secondary domain name, thereby ensuring the accuracy of the test; by randomly generating and orderly generating URL parameters and paths and testing, the depth of the security test is ensured, and the possibility of discovering hidden vulnerabilities is provided. BRIEF DESCRIPTION OF THE DRAWINGS
[0046] Figure 1 is a flow chart of a method for performing security testing according to an enterprise name according to an exemplary embodiment;
[0047] Figure 2 The diagram is a structural diagram of a system for performing security testing based on enterprise names according to an exemplary embodiment. DETAILED DESCRIPTION
[0048] In order to more clearly illustrate the technical features of the solution of the present invention, the present invention is described in detail below through specific implementation methods and in conjunction with the accompanying drawings.
[0049] like Figure 1 As shown, a method for performing security testing according to an enterprise name provided by an embodiment of the present invention includes the following steps:
[0050] Step S1, obtaining relevant information of the enterprise to be tested and crawling its investment enterprise information, wherein the relevant information includes the full Chinese name and enterprise domain name of the enterprise to be tested;
[0051] Step S2, performing domain name analysis on the crawled investment enterprise information to obtain the enterprise domain name, agreement and main domain name of the investment enterprise;
[0052] Step S3, based on obtaining the enterprise domain name of the invested enterprise, the agreement of the invested enterprise and the primary domain name, a new enterprise secondary domain name is formed and tested;
[0053] Step S4, performing security tests on enterprise domain names at all levels and secondary domain names at all levels and recording the test results;
[0054] Step S5, generating a safety test report based on the test results.
[0055] As a possible implementation of this embodiment, the step S1, obtaining relevant information of the enterprise to be tested and crawling its investment enterprise information, includes:
[0056] Get the full Chinese name and domain name of the enterprise to be tested;
[0057] Use crawler technology to crawl investment companies that hold more than 50% of the shares of the company to be tested, and record the names and domain names of the investment companies;
[0058] According to the names and domain names of the crawled investment enterprises, the secondary investment enterprises in which the investment enterprises hold more than 50% of the shares are further crawled, and this process is repeated recursively until no new investment enterprises can be crawled.
[0059] As a possible implementation of this embodiment, step S2, performing domain name analysis on the crawled investment enterprise information to obtain the enterprise domain name, the agreement and the main domain name of the investment enterprise, includes:
[0060] Analyze all crawled enterprise domain names and divide them into protocol names, host names, and primary domain names using regular expressions;
[0061] The protocol of the target domain name is determined based on the protocol name. If it is http or https, the domain name is further analyzed. If there is no protocol name, https is used by default.
[0062] As a possible implementation of this embodiment, step S3, based on obtaining the enterprise domain name of the invested enterprise, the agreement of the invested enterprise and the primary domain name, forms a new enterprise secondary domain name and performs a test, including:
[0063] Combine the enterprise domain name, agreement and primary domain name of the invested enterprise with the enterprise's commonly used system name dictionary to form a new enterprise secondary domain name;
[0064] The new enterprise secondary domain name is queried through DNS query and TCP connection. If the query has a response, it proves that the generated domain name exists.
[0065] As a possible implementation method of this embodiment, the names of the commonly used enterprise systems include EMAIL system (mail system), OA system (office automation system), CRM system (customer relationship management system), ERP system (enterprise resource planning system), MES system (manufacturing execution system), HRM system (human resource management system), SCM system (supply chain management system), WMS system (warehouse management system), OMS system (order management system), CMS system (content management system) and BI system (enterprise decision-making system).
[0066] As a possible implementation of this embodiment, the step S4, performing security tests on enterprise domain names at all levels and enterprise secondary domain names at all levels and recording the test results, includes:
[0067] Conduct N-day vulnerability tests on all enterprise domain names and sub-domain names at all levels. The N-day vulnerability tests include Apache vulnerability tests, IIS vulnerability tests, Nginx vulnerability tests, and various database vulnerability tests.
[0068] Conduct targeted vulnerability testing on the secondary domain name and host name characteristics of enterprises at all levels;
[0069] Use crawler technology to crawl URLs (Uniform Resource Locator) of enterprise domain names at all levels, and perform general vulnerability tests on the crawled URLs;
[0070] Generate dynamic URLs based on crawled URLs and perform general vulnerability tests on the generated dynamic URLs.
[0071] As a possible implementation method of this embodiment, the general vulnerability test includes SQL injection test, session management test, HTTP method test, user enumeration test, cross-site scripting attack test, unauthorized access test, cross-site request forgery test, user password brute force test, authentication mode bypass test, logout and browser cache management test, path traversal test and system command execution test.
[0072] As a possible implementation of this embodiment, the generating of a dynamic URL based on the crawled URL includes:
[0073] Mark the paths and parameters in the crawled URLs;
[0074] Modify the marked path and store the modified path;
[0075] The crawled URL and the marked parameter values are modified sequentially and randomly to form a dynamic URL.
[0076] As a possible implementation of this embodiment, the step S5, forming a safety test report according to the test results, includes:
[0077] Sort out the collected enterprise domain names, generated enterprise domain names, and vulnerabilities discovered during security testing, and classify and grade the discovered vulnerabilities;
[0078] Formulate a security test rectification plan based on the causes of the vulnerabilities and the results of classification and grading;
[0079] All results are summarized into a final safety test report.
[0080] like Figure 2 As shown, a system for performing security testing based on enterprise names provided by an embodiment of the present invention includes:
[0081] An enterprise information acquisition module is used to obtain relevant information of the enterprise to be tested and crawl its investment enterprise information, wherein the relevant information includes the full Chinese name and enterprise domain name of the enterprise to be tested;
[0082] The domain name analysis module is used to perform domain name analysis on the crawled investment enterprise information to obtain the enterprise domain name, agreement and main domain name of the investment enterprise;
[0083] A secondary domain name generation module is used to generate a new secondary domain name of an enterprise and conduct testing based on the enterprise domain name, agreement and primary domain name of the invested enterprise;
[0084] Security testing module, used to conduct security tests on enterprise domain names at all levels and secondary domain names at all levels and record the test results;
[0085] The test report generation module is used to generate a safety test report based on the test results.
[0086] The specific process of security testing for this application based on the company name is as follows.
[0087] 1. Analysis of company name.
[0088] Based on the full Chinese name and corporate domain name of the enterprise to be tested, crawl the investment enterprises in which the test enterprise holds more than 50% of the shares, and record the name and domain name of the investment enterprise.
[0089] Using the obtained investment enterprise names and domain names, continue to use crawler technology to crawl secondary investment enterprises in which the investment enterprise holds more than 50% of the shares, and do this recursively until no new enterprises and domain names can be analyzed and crawled.
[0090] 2. Target domain name analysis.
[0091] All crawled enterprise names and enterprise domain names are segmented by regular expressions. First, the enterprise domain name is divided into three parts. The first part is the protocol name. The protocol of the target domain name is determined. If it is determined to be http or https, the domain name is further analyzed. If the protocol name is not entered, such as www.example.com, the https protocol is used by default. The second part is the host name. The host name of the enterprise domain name is extracted by regular expressions, such as www in https: / / www.example.com. The third part is the main domain name of the enterprise. The main domain name of the target domain name is extracted by regular expressions, such as example.com in https: / / www.example.com.
[0092] 3. Domain name generation test.
[0093] Combine the generated enterprise domain name, the protocol and primary domain name of the investment enterprise with the stored dictionary of commonly used enterprise system names (as host names) to form a new enterprise secondary domain name. Common information system names include EMAIL (mail system), OA (office automation system), CRM (customer relationship management system), ERP (enterprise resource planning system), MES (manufacturing execution system), HRM (human resource management system), SCM (supply chain management system), WMS (warehouse management system), OMS (order management system), CMS (content management system) and BI (enterprise decision-making system). New secondary domain names are formed, such as "https: / / oa.example.com", "https: / / erp.example.com", "https: / / mes.example.com", "https: / / hrm.example.com", etc.
[0094] Test each generated enterprise domain name, and test whether the generated domain name responds to the query through DNS query and TCP link. If the query responds, it proves that the generated domain name exists and is recorded.
[0095] 4. Safety assessment.
[0096] Conduct security tests on enterprise domain names and sub-domain names at all levels.
[0097] N-day vulnerability testing is performed on all enterprise domain names and sub-domain names at all levels, such as Apache vulnerabilities, IIS vulnerabilities, Nginx vulnerabilities, and various database vulnerabilities to discover vulnerabilities and record vulnerability information.
[0098] Conduct targeted vulnerability testing on the host name characteristics of the second-level domain names of enterprises at all levels. For example, if the host name is OA, use the existing OA system vulnerabilities for testing. If the host name is CSM, use the existing CSM system vulnerabilities for testing. Discover vulnerabilities and record vulnerability information.
[0099] The URLs of enterprise domain names at all levels are crawled by crawler technology, and the crawled URLs are used for general vulnerability testing. The security tests for URLs mainly include SQL injection test, session management test, HTTP method test, user enumeration test, cross-site scripting attack test, unauthorized access test, cross-site request forgery test, user password brute force cracking test, authentication mode bypass test, logout and browser cache management test, path traversal test, system command execution test, etc., and the URLs with problems are recorded.
[0100] Generate dynamic URLs based on crawled URs, and perform general vulnerability tests on dynamic URLs. General vulnerability tests on dynamic URLs mainly include SQL injection tests, session management tests, HTTP method tests, user enumeration tests, cross-site scripting attack tests, unauthorized access tests, cross-site request forgery tests, user password brute force cracking tests, authentication mode bypass tests, logout and browser cache management tests, path traversal tests, system command execution tests, etc. URLs with problems are recorded, and URLs without problems are discarded.
[0101] The specific process of generating dynamic URLs based on crawled UR is as follows:
[0102] Mark the paths and parameters in the crawled URLs, such as the paths "code", "index.php", and parameters "id=1", "page=2" in https: / / www.example.com / code / index.php?id=1&page=2.
[0103] Modify the marked path, such as modifying the "code" and "index.php" marked in the first step to generate the following URL:
[0104] https: / / www.example.com / admin / index.php?id=1&page=2;
[0105] https: / / www.example.com / www / index.php?id=1&page=2;
[0106] https: / / www.example.com / code / test.php?id=1&page=2;
[0107] https: / / www.example.com / code / index1.php?id=1&page=2;
[0108] https: / / www.example.com / code / aammm.php?id=1&page=2;
[0109] https: / / www.example.com / mumu / pheq.php?id=1&page=2;
[0110] And store the modified path.
[0111] The URL generated by the path of the modification mark and the parameter value of the mark are modified sequentially and randomly to form a dynamic URL, and all the generated dynamic URLs are stored.
[0112] The URL after sequential modification is:
[0113] https: / / www.example.com / code / index.php?id=2&page=3;
[0114] https: / / www.example.com / code / index.php?id=3&page=4;
[0115] https: / / www.example.com / code / index.php?id=4&page=5;
[0116] https: / / www.example.com / code / index.php?id=5&page=6;
[0117] https: / / www.example.com / code / index.php?id=6&page=7;
[0118] The randomly modified URL is:
[0119] https: / / www.example.com / code / index.php?id=131&page=431;
[0120] https: / / www.example.com / code / index.php?id=axz&page=2198;
[0121] https: / / www.example.com / code / index.php?cv=ZS3&a=UI1;
[0122] https: / / www.example.com / code / index.php?uu=ew&pyn=7&isj=120a1;
[0123] https: / / www.example.com / code / index.php?sid=3&ds=7&tk=RX;
[0124] After all dynamic URLs are generated, security testing is performed and URLs with problems are recorded.
[0125] 6. Record the results.
[0126] Sort out the collected enterprise domain names, generated enterprise domain names, and discovered vulnerabilities, and classify and grade the discovered vulnerabilities according to the National Information Security Vulnerability Database (CVVND);
[0127] Formulate a rectification plan based on the causes of the vulnerabilities and the results of classification and grading;
[0128] All results are summarized into a final safety test report.
[0129] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the above embodiments, ordinary technicians in the relevant field should understand that the specific implementation methods of the present invention can still be modified or replaced by equivalents. Any modification or equivalent replacement that does not depart from the spirit and scope of the present invention should be covered within the scope of protection of the claims of the present invention.
Claims
1. A method for performing security testing based on an enterprise name, characterized in that: The steps include: Step S1, obtaining relevant information of the enterprise to be tested and crawling its investment enterprise information, wherein the relevant information includes the full Chinese name and enterprise domain name of the enterprise to be tested; Step S2, performing domain name analysis on the crawled investment enterprise information to obtain the enterprise domain name, agreement and main domain name of the investment enterprise; Step S3, based on obtaining the enterprise domain name of the invested enterprise, the agreement of the invested enterprise and the primary domain name, a new enterprise secondary domain name is formed and tested; Step S4, performing security tests on enterprise domain names at all levels and secondary domain names at all levels and recording the test results; Step S5, generating a safety test report based on the test results.
2. A method for performing security testing based on enterprise names according to claim 1, characterized in that: The step S1, obtaining relevant information of the enterprise to be tested and crawling its investment enterprise information, includes: Get the full Chinese name and domain name of the enterprise to be tested; Use crawler technology to crawl investment companies that hold more than 50% of the shares of the company to be tested, and record the names and domain names of the investment companies; According to the names and domain names of the crawled investment enterprises, the secondary investment enterprises in which the investment enterprises hold more than 50% of the shares are further crawled, and this process is repeated recursively until no new investment enterprises can be crawled.
3. A method for performing security testing based on enterprise names according to claim 1, characterized in that: The step S2, performing domain name analysis on the crawled investment enterprise information to obtain the enterprise domain name, the agreement and the main domain name of the investment enterprise, includes: Analyze all crawled enterprise domain names and divide them into protocol names, host names, and primary domain names using regular expressions; The protocol of the target domain name is determined based on the protocol name. If it is http or https, the domain name is further analyzed. If there is no protocol name, https is used by default.
4. A method for performing security testing based on enterprise names according to claim 1, characterized in that: The step S3, based on obtaining the enterprise domain name of the invested enterprise, the agreement of the invested enterprise and the primary domain name, forms a new enterprise secondary domain name and performs a test, including: Combine the enterprise domain name, agreement and primary domain name of the invested enterprise with the enterprise's commonly used system name dictionary to form a new enterprise secondary domain name; The new enterprise secondary domain name is queried through DNS query and TCP connection. If the query has a response, it proves that the generated domain name exists.
5. A method for performing security testing based on enterprise names according to claim 4, characterized in that: The names of the commonly used enterprise systems include EMAIL system, OA system, CRM system, ERP system, MES system, HRM system, SCM system, WMS system, OMS system, CMS system and BI system.
6. A method for performing security testing based on a company name according to any one of claims 1 to 5, characterized in that: Step S4, performing security tests on enterprise domain names at all levels and enterprise secondary domain names at all levels and recording the test results; Conduct N-day vulnerability tests on all enterprise domain names and sub-domain names at all levels. The N-day vulnerability tests include Apache vulnerability tests, IIS vulnerability tests, Nginx vulnerability tests, and various database vulnerability tests. Conduct targeted vulnerability testing on the secondary domain name and host name characteristics of enterprises at all levels; Use crawler technology to crawl URLs of enterprise domain names at all levels, and perform general vulnerability tests on the crawled URLs; Generate dynamic URLs based on crawled URLs and perform general vulnerability tests on the generated dynamic URLs.
7. A method for performing security testing based on enterprise names according to claim 6, characterized in that: The general vulnerability tests include SQL injection test, session management test, HTTP method test, user enumeration test, cross-site scripting attack test, unauthorized access test, cross-site request forgery test, user password brute force test, authentication mode bypass test, logout and browser cache management test, path traversal test and system command execution test.
8. A method for performing security testing based on enterprise names according to claim 6, characterized in that: The method of generating a dynamic URL based on the crawled URL includes: Mark the paths and parameters in the crawled URLs; Modify the marked path and store the modified path; The crawled URL and the marked parameter values are modified sequentially and randomly to form a dynamic URL.
9. A method for performing security testing based on enterprise names according to claim 6, characterized in that: The step S5, forming a safety test report according to the test results, includes: Sort out the collected enterprise domain names, generated enterprise domain names, and vulnerabilities discovered during security testing, and classify and grade the discovered vulnerabilities; Formulate a security testing rectification plan based on the causes of the vulnerabilities and the results of classification and grading; All results are summarized into a final safety test report.
10. A system for performing security testing based on enterprise names, characterized in that: include: An enterprise information acquisition module is used to obtain relevant information of the enterprise to be tested and crawl its investment enterprise information, wherein the relevant information includes the full Chinese name and enterprise domain name of the enterprise to be tested; The domain name analysis module is used to perform domain name analysis on the crawled investment enterprise information to obtain the enterprise domain name, agreement and main domain name of the investment enterprise; A secondary domain name generation module is used to generate a new secondary domain name of an enterprise and conduct testing based on the enterprise domain name, agreement and primary domain name of the invested enterprise; Security testing module, used to conduct security tests on enterprise domain names at all levels and secondary domain names at all levels and record the test results; The test report generation module is used to generate a safety test report based on the test results.