Attack surface management method based on network assets and risk vulnerabilities

Through automated discovery and vulnerability assessment, and dynamically adjusting the protection strategy in combination with the attack surface scoring model, the problem that existing technology cannot fully identify and manage enterprise network assets and risk vulnerabilities is solved, and efficient and accurate network security protection is achieved.

CN119996042APending Publication Date: 2025-05-13BEIJING EASYNETWORKS TECHNOLOGY CO LTD

Patent Information

Application Number
CN202510270711.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-07
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

The existing attack surface management methods cannot identify and manage all assets and risk vulnerabilities in the enterprise network in a timely and comprehensive manner, and the existing risk assessment and attack surface scoring models are generally simple, making it difficult to adapt to complex enterprise network environments.

Method used

Through automation discovery of internal and external network assets of the enterprise, vulnerability scanning tools and preset vulnerabilities are used to identify security vulnerabilities, evaluate the risk level of vulnerabilities, calculate the attack surface score of each network asset, and dynamically adjust the network security protection strategy based on the score.

Benefits of technology

It realizes comprehensive and real-time discovery of enterprise network assets and accurate identification and evaluation of vulnerabilities, improves the comprehensiveness and accuracy of network security protection, can respond to network security threats in a timely manner, and reduces the possibility of successful attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119996042A_ABST
    Figure CN119996042A_ABST
Patent Text Reader

Abstract

The invention relates to the field of network security, and discloses an attack surface management method based on network assets and risk vulnerabilities, comprising the following steps: step 1, automatically discovering internal and external network assets of an enterprise, including collecting enterprise asset information through a public platform and scanning network resources through a crawler technology, integrating to obtain a complete network asset list of the enterprise; step 2, performing vulnerability detection on the network assets, scanning each asset by using a vulnerability scanning tool, and identifying various security vulnerabilities through a preset vulnerability feature library; and step 3, scanning a result according to the vulnerability of each network asset. According to the invention, comprehensive and real-time discovery and tracking are carried out on internal and external network assets of an enterprise through an automation technology, wide coverage and timely updating of the network assets are ensured, all assets of the enterprise can be actively identified and managed, the risk of missing key assets is avoided, and thus the comprehensiveness and accuracy of network security protection are remarkably improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to an attack surface management method based on network assets and risk vulnerabilities. Background Art

[0002] With the rapid development of information technology and the increasing complexity of enterprise network environments, network security threats are increasing, posing huge challenges to the security of enterprise assets and data. Traditional network security protection measures often rely on static firewall rules, anti-virus software, and manual vulnerability scanning, which have certain limitations in dealing with ever-changing network security threats. In particular, the management of enterprise network assets and risk vulnerabilities has become more difficult. Traditional protection measures cannot identify and repair vulnerabilities in a timely manner, and lack a dynamic adjustment mechanism, which easily exposes important assets to security threats.

[0003] At present, attack surface management, as a relatively new security management method, has gradually become an important means to deal with security threats in complex network environments. Attack surface management can timely discover vulnerabilities and risks and take effective protective measures by comprehensively understanding and managing network assets inside and outside the enterprise. However, existing attack surface management methods generally have certain limitations, mainly reflected in the lack of automated asset discovery capabilities, inaccurate vulnerability identification, lack of effective quantification of risk assessment, and imperfect attack surface scoring models. Existing technologies often rely on manual asset management and vulnerability repair, and lack efficient, accurate, and dynamic vulnerability scanning and protection capabilities.

[0004] The main problem with existing attack surface management methods is that they cannot timely and comprehensively identify and manage all assets and risk vulnerabilities in the enterprise network, and the existing risk assessment and attack surface scoring models are generally simple and difficult to adapt to complex enterprise network environments. Traditional security management methods lack the ability to accurately quantify the attack surface and cannot adjust protection strategies in real time according to changes in network assets and vulnerabilities. Therefore, when facing network security threats, it is difficult for enterprises to effectively prevent and control risks and respond quickly. Summary of the invention

[0005] In view of the shortcomings of the prior art, the present invention provides an attack surface management method based on network assets and risk vulnerabilities, which solves the problems that the existing management methods are unable to timely and comprehensively identify and manage all assets and risk vulnerabilities in the enterprise network, and the existing risk assessment and attack surface scoring models are generally simple and difficult to adapt to complex enterprise network environments.

[0006] To achieve the above objectives, the present invention is implemented through the following technical solutions: an attack surface management method based on network assets and risk vulnerabilities, comprising the following steps: Step 1: Automatically discover the internal and external network assets of the enterprise, including collecting enterprise asset information through public platforms and scanning network resources through crawler technology, and integrating to obtain a complete list of the enterprise's network assets; Step 2: Perform vulnerability detection on the network assets, use vulnerability scanning tools to scan each asset, and identify various security vulnerabilities through a preset vulnerability feature library; Step 3: Based on the vulnerability scan results of each network asset, assess the risk level of the vulnerability and quantify the risk based on asset exposure and vulnerability severity; Step 4: Calculate the attack surface score of each network asset based on the risk quantification result, and prioritize the network assets according to the attack surface score; Step 5. Based on the priority sorting results, formulate and dynamically adjust the company's network security protection strategy to ensure that the enterprise network is always in the best protection state in the ever-changing threat environment.

[0007] Preferably, in step one, the public platform collects enterprise asset information including obtaining the enterprise's organizational structure, domain name, IP address, and registered website information, and combines crawler technology to obtain enterprise equipment, ports, and service data.

[0008] Preferably, the vulnerability detection is performed by automatically scanning network assets using vulnerability scanning tools to identify and record possible security vulnerabilities in each asset. The vulnerability scanning tools include Nessus and OpenVAS.

[0009] Preferably, in step three, the risk level assessment of the vulnerability is scored based on a common vulnerability scoring system, and the assessment includes factors such as the severity, exploitability, and impact range of the vulnerability.

[0010] Preferably, in step 4, the attack surface score is calculated based on the following formula: in, For the The attack surface score of each asset, For the The risk score of an asset, For the The exposure score of an asset.

[0011] Preferably, the comprehensive calculation of the attack surface score is based on the following formula: in, Score the overall attack surface of the enterprise, For the The attack surface score of each asset, For the The weight of an asset.

[0012] Preferably, in step five, the dynamic adjustment of the protection strategy is based on the risk status of network assets and attack surface scores monitored in real time, and the protection strategy includes strengthening firewall rules, updating intrusion detection system rules, and adding security audit measures.

[0013] Preferably, in step five, the optimization of the protection strategy also includes regularly updating the vulnerability signature library and protection strategy according to changes in the internal network architecture of the enterprise and the external attack surface, so as to ensure that the security protection measures of the network assets are always in the latest state.

[0014] Preferably, the data collection and vulnerability scanning in step 1 and step 2 are performed automatically, and network assets are regularly scanned and tested comprehensively at preset time intervals or trigger conditions to ensure real-time updating of asset information and vulnerability information.

[0015] Preferably, the security protection system for enterprise network assets includes an asset discovery module, a vulnerability scanning module, a risk assessment module, an attack surface quantification module, a risk repair module and a protection strategy dynamic adjustment module, and the modules cooperate with each other to jointly ensure the security of the enterprise network.

[0016] The present invention provides an attack surface management method based on network assets and risk vulnerabilities. It has the following beneficial effects: 1. The present invention uses automation technology to conduct comprehensive and real-time discovery and tracking of internal and external network assets of an enterprise, ensuring that network assets are widely covered and updated in a timely manner. Compared with traditional static firewalls and anti-virus software, the present invention can actively identify and manage all assets of an enterprise, avoiding the risk of missing key assets, thereby significantly improving the comprehensiveness and accuracy of network security protection.

[0017] 2. The automatic vulnerability scanning and vulnerability signature library matching technology of the present invention can accurately and quickly identify potential risk vulnerabilities in network assets, and quantitatively evaluate the vulnerabilities in combination with the CVSS scoring model. Through efficient vulnerability identification and evaluation, enterprises can timely discover and respond to potential security threats in the network and prevent vulnerabilities from being exploited by hackers.

[0018] 3. The present invention uses an attack surface scoring model to accurately sort all network assets based on the risk level of vulnerabilities and the degree of exposure of assets. Enterprises can prioritize protection measures for high-risk assets based on the attack surface scores of assets, thereby effectively allocating resources and concentrating efforts on protecting the most important assets, avoiding the uneven resource allocation in traditional security protection methods.

[0019] 4. The present invention integrates dynamically adjusted security policies so that network protection can be adjusted in time with changes in asset risks. For example, if a certain asset exposes a new vulnerability or the attack surface score changes, the system will automatically adjust the configuration of security devices such as firewalls and intrusion detection systems (IDS) to block potential threats in a timely manner. This flexible adjustment mechanism improves the speed and accuracy of protection response and effectively reduces the possibility of successful attacks.

[0020] 5. The present invention integrates multiple functions such as asset management, vulnerability detection, risk assessment, and protection strategy adjustment into one system, avoiding the situation of decentralized security protection and complex management in traditional methods. Enterprise security managers only need to rely on the system for centralized management, thereby simplifying the overall security management process and improving management efficiency. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] Figure 1 The figure is a flow chart of the method of the present invention. DETAILED DESCRIPTION

[0022] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0023] Embodiment 1: Please see attached Figure 1 The embodiment of the present invention provides an attack surface management method based on network assets and risk vulnerabilities, comprising the following steps: Step 1: Automatically discover the internal and external network assets of the enterprise, including collecting enterprise asset information through public platforms and scanning network resources through crawler technology, and integrating to obtain a complete list of the enterprise's network assets; Step 2: Perform vulnerability detection on network assets, use vulnerability scanning tools to scan each asset, and identify various security vulnerabilities through a preset vulnerability signature library; Step 3: Based on the vulnerability scan results of each network asset, assess the risk level of the vulnerability and quantify the risk based on asset exposure and vulnerability severity; Step 4: Based on the risk quantification results, calculate the attack surface score of each network asset and prioritize the network assets according to the attack surface score; Step 5. Based on the priority sorting results, formulate and dynamically adjust the company's network security protection strategy to ensure that the enterprise network is always in the best protection state in the ever-changing threat environment.

[0024] In step one, the public platform collects enterprise asset information including the enterprise's organizational structure, domain name, IP address, and registered website information, and uses crawler technology to obtain enterprise equipment, ports, and service data.

[0025] Vulnerability detection uses vulnerability scanning tools to automatically scan network assets, identify and record possible security vulnerabilities in each asset. Vulnerability scanning tools include Nessus and OpenVAS.

[0026] In step three, the risk level of the vulnerability is assessed based on the Common Vulnerability Scoring System, which includes factors such as the severity, exploitability, and impact of the vulnerability.

[0027] In step 4, the attack surface score is calculated based on the following formula: in, For the The attack surface score of each asset, For the The risk score of an asset, For the The exposure score of an asset.

[0028] The composite calculation of the attack surface score is based on the following formula: in, Score the overall attack surface of the enterprise, For the The attack surface score of each asset, For the The weight of an asset.

[0029] In step five, the dynamic adjustment of the protection strategy is based on the real-time monitoring of the risk status of network assets and the attack surface score. The protection strategy includes strengthening firewall rules, updating intrusion detection system rules, and adding security audit measures.

[0030] In step five, the optimization of protection strategies also includes regularly updating the vulnerability signature library and protection strategies according to changes in the internal network architecture and external attack surface of the enterprise to ensure that the security protection measures of network assets are always up to date.

[0031] The data collection and vulnerability scanning in steps one and two are performed automatically. Through preset time intervals or trigger conditions, network assets are scanned and tested regularly to ensure real-time updating of asset information and vulnerability information.

[0032] The security protection system for enterprise network assets includes asset discovery module, vulnerability scanning module, risk assessment module, attack surface quantification module, risk repair module and protection strategy dynamic adjustment module. The modules work together to ensure the security of the enterprise network.

[0033] In one embodiment, this embodiment uses a security protection solution for an enterprise network to demonstrate how to implement attack surface management based on network assets and risk vulnerabilities. The enterprise has a multi-layered network architecture, including internal employee workstations, external network services (such as web servers, mail servers), and VPN connections accessed by external partners.

[0034] Step 1: Automated discovery of network assets Information collection on public platforms: Enterprises first obtain basic information about their network assets through public platforms (such as the company's official website, the Ministry of Industry and Information Technology's filing inquiry platform, etc.). This information includes but is not limited to the company's domain name, IP address, filing website, organizational structure, etc.

[0035] For example, after querying the MIIT filing platform, the system found that the company's main domain name was "example.com" and recorded all public subdomains and IP addresses (for example: 192.168.1.1, 192.168.2.2, etc.). This information is automatically organized and stored in the network asset database.

[0036] Crawling technology: Use crawler technology to scan public data sources on the Internet (such as GitHub, forums, blogs, etc.) to automatically identify other network asset information related to the enterprise.

[0037] For example, the crawler scans the enterprise's external interface API address (for example: api.example.com) and obtains its IP address and associated services (such as HTTP service, database port, etc.) through reverse lookup.

[0038] All this information (domain name, IP, port, service type, etc.) will be summarized into the network asset inventory.

[0039] Step 2: Vulnerability Detection and Identification Vulnerability Scanning: Use automated vulnerability scanning tools (such as Nessus and OpenVAS) to conduct a comprehensive scan of enterprise network assets to detect possible vulnerabilities in each asset. For example: Scanning the web server (such as 192.168.1.1) detected the vulnerability CVE-2023-12345, which is a SQL injection vulnerability.

[0040] A scan of the intranet database service (such as 192.168.2.2) revealed an unupdated version of Apache with a known remote code execution vulnerability.

[0041] Vulnerability signature library matching: The vulnerability of each asset is matched with the preset vulnerability signature library. The vulnerability signature library includes known common vulnerability information (such as CVE vulnerability number, vulnerability type, impact scope, vulnerability severity, etc.). For example, after the system matches the "CVE-2023-12345" vulnerability, it calculates the severity score of the vulnerability as 9.0 (high risk) based on CVSS (Common Vulnerability Scoring System).

[0042] Vulnerability information record: Record each vulnerability information scanned in the vulnerability management database, including a detailed description of the vulnerability, risk level, vulnerability repair suggestions, etc.

[0043] Step 3: Risk Assessment and Quantification Vulnerability Risk Assessment: For each vulnerability, its risk level is calculated. The risk assessment is quantified using the CVSS scoring model, including the following dimensions: Severity: Assess the potential harm of the vulnerability, such as remote code execution, denial of service, etc.

[0044] Exploitability: How easy it is for an attacker to exploit a vulnerability.

[0045] Impact: The scope of impact caused by the vulnerability, such as data leakage, system crash, etc.

[0046] For example, for the above-mentioned "SQL injection vulnerability (CVE-2023-12345)", the CVSS score is 9.0 (high risk), the impact range is enterprise database data leakage, and attackers can remotely execute SQL injection commands.

[0047] Attack Surface Score: The vulnerability of each asset is weighted and scored to obtain the attack surface score. The attack surface score calculation formula is: in, For the The attack surface score of each asset, For the Risk scores for each asset (based on severity and impact assessment of the vulnerability), For the The exposure score of each asset, such as whether the asset is publicly accessible, whether there are network port exposures, etc.)

[0048] For example, a web server has an attack surface score of 8.5 (high risk) and a database server has an attack surface score of 7.2 (medium risk).

[0049] Step 4: Dynamically adjust the protection strategy Protection strategy optimization: Based on the attack surface score, the enterprise network's protection strategy will be automatically optimized. Protection strategy optimization includes the following aspects: Strengthen firewall rules: For high-risk assets (such as Web servers), add access control rules for specific ports to prevent external SQL injection attacks.

[0050] Update Intrusion Detection System (IDS) rules: Update IDS rules based on identified vulnerabilities and add feature detection for SQL injection.

[0051] Strengthen identity authentication and permission management: For internal services with high exposure (such as database services), strengthen multi-factor authentication and limit administrator access rights.

[0052] Real-time monitoring and dynamic adjustment: The network security protection system will monitor the status of enterprise network assets in real time. If new vulnerabilities or threats are found, the protection strategy will be automatically adjusted. For example, if a new vulnerability is discovered, the system will trigger a vulnerability scan and re-evaluate the attack surface, automatically adjusting firewall rules and intrusion detection rules to prevent the attack from expanding.

[0053] Step 5: Regular scanning and report generation Regular asset scans: Enterprise network assets automatically conduct vulnerability scans once a week or month to ensure asset security. During the scan, the system will re-acquire new asset information from the public platform and crawler technology, and update the asset list in a timely manner.

[0054] Generate a security report: The system will automatically generate a security report based on the vulnerability scan results, attack surface score and protection strategy optimization for the company's security administrator to review. The report includes a vulnerability list, risk assessment results, attack surface score, optimized protection strategy and repair suggestions.

[0055] Experimental scenario In order to verify the effectiveness of the attack surface management method based on network assets and risk vulnerabilities proposed in this paper, we designed two experimental scenarios: one is the benchmark scenario of the traditional method, and the other is the experimental scenario of the application of the method of this invention. The experimental goal is to compare the effects of the two methods in network asset discovery, vulnerability detection, risk assessment, and protection strategy adjustment, and to evaluate their performance in dealing with complex attack surfaces.

[0056] Experimental environment and settings Enterprise network environment: The experiment selected a large enterprise network environment, covering internal core assets, external exposed assets and peripheral attack surfaces. The network environment includes multiple operating system platforms, database services, Web application servers and IoT devices.

[0057] Experimental Method: The experiment consists of three main parts: 1) network asset discovery; 2) vulnerability detection and identification; 3) risk assessment and protection strategy adjustment. Each part will be compared based on different processing methods.

[0058] Evaluation indicators: The main indicators of experimental evaluation include vulnerability discovery rate, false alarm rate, missed alarm rate, response time, risk assessment accuracy, and adjustment efficiency of protection strategies.

[0059] Comparative Example 1: Step 1: Automated discovery of network assets Experimental procedures Traditional method: Use static asset lists and manual scanning tools to discover assets on the network, relying on the company's existing resources and asset data for scanning. Assets include domain names, IP addresses, subnets, and service ports.

[0060] method Number of assets found Proportion of missing assets Time consumed (minutes) Comparative Example 1 520 5% 45 Embodiment 1 580 50% 30 Table 1 Comparative analysis: Traditional methods only use existing resources and manual scanning, which may result in certain assets being missed and the scanning process is time-consuming.

[0061] The method of the present invention not only discovers more assets, but also reduces the missed detection rate to 0 and greatly improves the scanning efficiency through automated network asset discovery and external data integration.

[0062] Comparative Example 2: Step 2: Vulnerability Detection and Identification Experimental procedures Traditional method: Use static vulnerability databases (such as CVEs) and traditional scanning tools (such as Nessus) to perform vulnerability scans and detect known vulnerabilities.

[0063] method Known vulnerability identification rate Unknown vulnerability identification rate False Positive Rate False negative rate Scan time (minutes) Comparative Example 2 95% 5% 8% 120% 120 Embodiment 1 98% 92% 2% 3% 80 Table 2 Comparative analysis: Traditional vulnerability identification methods mainly rely on known vulnerability libraries. Although the recognition rate of known vulnerabilities is high, the recognition ability of unknown vulnerabilities is weak and the false negative rate is high.

[0064] The method of the present invention significantly improves the recognition rate of unknown vulnerabilities and reduces the missed and false positive rates by combining dynamic vulnerability scanning with machine learning algorithms. In addition, the scanning time is also greatly shortened.

[0065] Comparative Example 3: Step 3: Risk Assessment and Quantification Experimental procedures Traditional method: Use a standard risk assessment system based on CVSS to assess vulnerability risk based on the vulnerability's CVSS score (such as severity, attack complexity, etc.).

[0066] method Risk assessment accuracy Response time (seconds) Bug fix prioritization accuracy Comparative Example 3 75% 5 80% Embodiment 1 92% 2 95% Table 3 Comparative analysis: Traditional methods only evaluate based on the CVSS score of the vulnerability, lacking a comprehensive assessment that considers the characteristics of the assets and the actual risks of the enterprise, so the accuracy of risk assessment is low.

[0067] The method of the present invention comprehensively considers the importance of enterprise assets and vulnerability characteristics, and uses a dynamic risk quantification model, which is not only highly accurate but also able to calculate risks in real time and quickly provide priority sorting for vulnerability repairs.

[0068] Comparative Example 4: Step 4: Dynamically adjust the protection strategy Experimental procedures Traditional approach: Protection based on static rules and firewall policies, which can only identify known attack patterns.

[0069] method Protection strategy update frequency Protection response time (seconds) Protective effect Comparative Example 4 Monthly 60 85% Embodiment 1 Real-time dynamic adjustment 5 98% Table 4 Comparative analysis: The protection strategies of traditional methods are updated slowly and cannot cope with new attack methods or vulnerabilities, so the protection effect is limited.

[0070] The method of the present invention can quickly respond to new security threats through real-time evaluation and dynamic adjustment of protection strategies, thereby greatly improving the protection effect.

[0071] Through the above comparative experiments, it can be clearly seen that the method of the present invention has significant advantages over the traditional method in multiple key indicators: More efficient asset discovery: Through automated asset discovery and external data integration, the comprehensiveness and efficiency of asset discovery are significantly improved.

[0072] Stronger vulnerability identification capabilities: Combining dynamic vulnerability detection and machine learning algorithms, it not only identifies known vulnerabilities, but also discovers unknown vulnerabilities in a timely manner, significantly improving the vulnerability identification rate.

[0073] Higher accuracy of risk assessment: The present invention comprehensively considers the importance of assets and vulnerability characteristics, assesses vulnerability risks in real time, and provides more accurate risk management.

[0074] Protection strategies respond more promptly: By dynamically adjusting protection strategies, the present invention can quickly respond to security threats and improve the protection effect of network security.

[0075] The present invention provides enterprises with a comprehensive, dynamic and intelligent attack surface management method, which can effectively deal with complex and changeable network security threats and enhance the overall security protection capabilities of enterprises.

[0076] Although embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions and variations may be made to the embodiments without departing from the principles and spirit of the present invention, and that the scope of the present invention is defined by the appended claims and their equivalents.

Claims

1. An attack surface management method based on network assets and risk vulnerabilities, characterized in that: The following steps are involved: Step 1: Automatically discover the internal and external network assets of the enterprise, including collecting enterprise asset information through public platforms and scanning network resources through crawler technology, and integrating to obtain a complete list of the enterprise's network assets; Step 2: Perform vulnerability detection on the network assets, use vulnerability scanning tools to scan each asset, and identify various security vulnerabilities through a preset vulnerability feature library; Step 3: Based on the vulnerability scan results of each network asset, assess the risk level of the vulnerability and quantify the risk based on asset exposure and vulnerability severity; Step 4: Calculate the attack surface score of each network asset based on the risk quantification result, and prioritize the network assets according to the attack surface score; Step 5. Based on the priority sorting results, formulate and dynamically adjust the company's network security protection strategy to ensure that the enterprise network is always in the best protection state in the ever-changing threat environment.

2. The attack surface management method based on network assets and risk vulnerabilities according to claim 1 is characterized in that: In the step one, the public platform collects enterprise asset information including obtaining the enterprise's organizational structure, domain name, IP address, and registered website information, and combines crawler technology to obtain enterprise equipment, ports, and service data.

3. The attack surface management method based on network assets and risk vulnerabilities according to claim 1 is characterized in that: The vulnerability detection automatically scans network assets using vulnerability scanning tools to identify and record possible security vulnerabilities in each asset. The vulnerability scanning tools include Nessus and OpenVAS.

4. The attack surface management method based on network assets and risk vulnerabilities according to claim 1 is characterized in that: In the step three, the risk level assessment of the vulnerability is scored based on a common vulnerability scoring system, and the assessment includes factors such as the severity, exploitability, and impact range of the vulnerability.

5. The attack surface management method based on network assets and risk vulnerabilities according to claim 1 is characterized in that: In step 4, the attack surface score is calculated based on the following formula: in, For the The attack surface score of each asset, For the The risk score of an asset, For the The exposure score of an asset.

6. The attack surface management method based on network assets and risk vulnerabilities according to claim 1 is characterized in that: The composite calculation of the attack surface score is based on the following formula: in, Score the overall attack surface of the enterprise, For the The attack surface score of each asset, For the The weight of an asset.

7. The attack surface management method based on network assets and risk vulnerabilities according to claim 1 is characterized in that: In step five, the dynamic adjustment of the protection strategy is based on the real-time monitored network asset risk status and attack surface score, and the protection strategy includes strengthening firewall rules, updating intrusion detection system rules, and adding security audit measures.

8. The attack surface management method based on network assets and risk vulnerabilities according to claim 1 is characterized in that: In step five, the optimization of the protection strategy also includes regularly updating the vulnerability signature library and protection strategy according to changes in the internal network architecture of the enterprise and the external attack surface to ensure that the security protection measures of network assets are always up to date.

9. The attack surface management method based on network assets and risk vulnerabilities according to claim 1 is characterized in that: The data collection and vulnerability scanning in step 1 and step 2 are performed automatically. Through preset time intervals or trigger conditions, network assets are regularly scanned and tested comprehensively to ensure real-time updating of asset information and vulnerability information.

10. The attack surface management method based on network assets and risk vulnerabilities according to claim 1 is characterized in that: The security protection system for enterprise network assets includes an asset discovery module, a vulnerability scanning module, a risk assessment module, an attack surface quantification module, a risk repair module and a protection strategy dynamic adjustment module. The modules cooperate with each other to jointly ensure the security of the enterprise network.

Citation Information

Patent Citations

  • Network asset and vulnerability information collection method, system, device and medium

    CN114168970A

  • Vulnerability management system based on network assets

    CN117544402A

  • Internet content risk analysis and early warning method

    CN118413385A

  • EPSS-based vulnerability accessibility rating method

    CN119484153A

Cited By

  • Digital security management system and method

    CN121030779A

  • Digital security management system and method

    CN121030779B

  • Asset vulnerability detection method and device, electronic equipment and storage medium

    CN121193547A