Method and system for generating network security penetration test report

By establishing a vulnerability relationship model and generating attack paths, the problem that existing technology is difficult to identify complex relationships between vulnerabilities is solved, and the accurate identification and evaluation of key vulnerabilities and vulnerability chains is achieved, which improves the efficiency of network security protection.

CN120017397AActive Publication Date: 2025-05-16HUBEI XINGYE TECHNOLOGY DEVELOPMENT CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510222740.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-27
Publication Date
2025-05-16
Estimated Expiration
2045-02-27

AI Technical Summary

Technical Problem

Existing methods for generating cybersecurity penetration test reports are difficult to comprehensively and systematically identify and describe the complex relationships between vulnerabilities, resulting in security personnel who may only focus on the resolution of individual vulnerabilities when formulating repair strategies.

Method used

By collecting vulnerability information during penetration testing, a vulnerability relationship model is established, and weight assignments are made to nodes and edges based on vulnerability characteristics, the correlation between vulnerabilities is calculated to identify key vulnerabilities and vulnerability chains. Based on these models and historical attack data, the attack paths are generated, which simulates the routes of action that an attacker may take, and evaluates the success rate of each attack path.

Benefits of technology

It realizes in-depth analysis and identification of complex relationships between vulnerabilities, can accurately identify key vulnerabilities and vulnerability chains, provides more accurate security assessment and repair strategies, and improves the ability and efficiency of network security protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120017397A_ABST
    Figure CN120017397A_ABST
Patent Text Reader

Abstract

The invention relates to a network security penetration test report generation method and system, and relates to the technical field of network security, and the method comprises the steps: collecting vulnerability information in a penetration test process; taking each vulnerability as a node, and establishing an edge connected with the node based on a mutual relationship between the vulnerabilities to obtain a vulnerability relationship model; performing weight assignment on the nodes and the edges according to vulnerability features; the correlation degree between the vulnerabilities is calculated to identify key vulnerabilities and vulnerability chains; generating an attack path based on the established vulnerability relation model and historical attack data; and generating a penetration test report based on the vulnerability relation model and the attack path.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of network security, and in particular to a method and system for generating a network security penetration test report. Background Art

[0002] In today's digital age, network security is of vital importance. With the rapid development of information technology, various network systems are widely used in many key fields such as finance, medical care, and government affairs. However, the means of network attacks are becoming increasingly complex and diverse.

[0003] As an important means of ensuring network security, network security penetration testing can simulate hacker attacks to discover potential security vulnerabilities in the system. The current report generation method often focuses on the surface description and analysis of known vulnerabilities, lacking in-depth exploration of the potential correlations and combined impacts between different vulnerabilities. With the increasing complexity of the network environment, a single vulnerability may be just the tip of the iceberg, and the combination of multiple vulnerabilities may cause more serious security threats. However, when generating reports, existing technologies have difficulty in comprehensively and systematically identifying and explaining the complex relationships between these vulnerabilities, resulting in security personnel only focusing on solving a single vulnerability when formulating repair strategies.

[0004] Therefore, there is an urgent need for a method that can deeply analyze vulnerability relationships and accurately identify key vulnerabilities and vulnerability chains to meet the needs of network security assessment in the current complex and changing network security environment. Summary of the invention

[0005] In order to at least partially solve the above technical problems, the present application provides a method and system for generating a network security penetration test report.

[0006] In a first aspect, a method for generating a network security penetration test report provided in the present application adopts the following technical solution.

[0007] A method for generating a network security penetration test report, comprising: Collect vulnerability information during penetration testing; Treat each vulnerability as a node and build edges connecting the nodes based on the relationships between the vulnerabilities to obtain a vulnerability relationship model; assign weights to the nodes and edges based on the vulnerability characteristics; calculate the correlation between the vulnerabilities to identify key vulnerabilities and vulnerability chains; Generate an attack path based on the established vulnerability relationship model and historical attack data; Generate penetration test reports based on vulnerability relationship models and attack paths.

[0008] By adopting the above technical solution, by collecting vulnerability information during the penetration test, each vulnerability is taken as a node and edges are established based on their mutual relationships to obtain a vulnerability relationship model. Weights are assigned to nodes and edges according to vulnerability characteristics. Based on the importance of each vulnerability and its relationship, key vulnerabilities and vulnerability chains can be identified through correlation calculation. Based on the vulnerability relationship model and historical attack data, attack paths are generated to simulate the possible routes of action taken by attackers. The success rate of each attack path is evaluated in combination with vulnerability correlation and system business logic, so that security personnel can know the actual probability of different attack paths.

[0009] Optionally, each vulnerability is taken as a node and edges connecting the nodes are built based on the relationships between the vulnerabilities to obtain a vulnerability relationship model, including: Identify each vulnerability found during the penetration test and treat each vulnerability as a separate node; Determine for each vulnerability whether there is a relationship between it and other vulnerabilities; the relationship includes: precondition relationship, concurrency relationship and subsequent impact relationship; According to the determined mutual relations between the vulnerabilities, edges are established between the nodes having the mutual relations to form a vulnerability relation model; Assign weights to nodes and edges based on vulnerability characteristics, including: The nodes corresponding to each vulnerability are weighted based on the severity, exploitability, impact scope and business importance of the vulnerability; Each edge connecting nodes is weighted based on the closeness of the relationship, the availability of the relationship, and the impact on the system.

[0010] Optionally, identify vulnerability chains, including: Add each key vulnerability node to the search queue; Initialize an empty vulnerability chain list to store the discovered vulnerability chains; When the search queue is not empty, a vulnerability node is taken out of the queue; all outgoing edge connection relationships of the current vulnerability node are found; for each outgoing edge connection relationship, it is determined whether the comprehensive weight of the outgoing edge connection relationship and the comprehensive weight of the vulnerability node pointed to by the outgoing edge connection relationship meet the priority condition; if so, the vulnerability node pointed to by the outgoing edge connection relationship is added to the search queue, and the path from the current vulnerability node to the vulnerability node pointed to by the outgoing edge connection relationship is added to the current vulnerability chain; when the length of the current vulnerability chain reaches the termination condition, the vulnerability chain is stored in the vulnerability chain list.

[0011] Optionally, generating an attack path based on the established vulnerability relationship model and historical attack data includes: Initialize a stack data structure, and push all key vulnerabilities and their initial paths into the stack in sequence; the stack data structure is used to store the nodes to be visited and the current access path; initialize an empty attack path set, and the attack path set is used to store the generated attack paths; When the stack is not empty, do the following: Pop an element from the stack, where the popped element contains a vulnerable node and the current access path; For all outgoing edges of the vulnerability node contained in the element, determine the next vulnerability node pointed to by the outgoing edge and check whether the next vulnerability node meets the condition for continuing the search, where the condition for continuing the search is based on historical attack data considerations, business logic and weights; If the conditions for continuing the search are met, the next vulnerability node and the updated access path are pushed into the stack; When the current vulnerability node has no outgoing edges, the current access path is added to the attack path set; If the next vulnerable node pointed to by all outgoing edges of the vulnerable node represented by the element popped from the stack does not meet the conditions for continuing the search, the corresponding element is marked as visited.

[0012] Optionally, before generating a penetration test report based on the vulnerability relationship model and the attack path, the method further includes: Before generating a penetration test report, first identify the user who requested the report; Define different report access permissions and information visibility levels for users with different identities; Determine what is presented in the penetration test report based on report access permissions and information visibility levels.

[0013] Optionally, create a pruning mark set; the pruning mark set is used to store known pruning path information; based on historical attack data, find low-risk node combinations that have never been successfully exploited in history. It is added to the set of pruning marks; When an element is popped from the stack, a node combination identifier is generated starting from the current node and passing through the outgoing edge to reach the next vulnerable node; the node combination identifier is compared with the information in the pruning mark set; If the current node combination identifier exists in the pruning mark set, it means that the node combination has never been successfully exploited in historical data, and the subsequent search operation for the next vulnerable node pointed to by the outgoing edge is directly skipped.

[0014] In a second aspect, a network security penetration test report generation system provided in the present application adopts the following technical solution.

[0015] A system for generating a network security penetration test report, comprising: The first processing module is used to: collect vulnerability information during the penetration test; The second processing module is used to: take each vulnerability as a node and build edges connecting the nodes based on the mutual relationship between the vulnerabilities to obtain a vulnerability relationship model; assign weights to the nodes and edges according to the vulnerability characteristics; calculate the correlation between the vulnerabilities to identify key vulnerabilities and vulnerability chains; A third processing module is used to: generate an attack path based on the established vulnerability relationship model and historical attack data; The fourth processing module is used to generate a penetration test report based on the vulnerability relationship model and the attack path. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] Figure 1 It is a flow chart of a method for generating a network security penetration test report according to an embodiment of the present application; Figure 2 It is a system block diagram of a method for generating a network security penetration test report according to an embodiment of the present application; In the figure, 201 is a first processing module; 202 is a second processing module; 203 is a third processing module; 204 is a fourth processing module. DETAILED DESCRIPTION

[0017] The following is combined with Figure 1-2 The present application is further described with specific embodiments: The present application embodiment discloses a method for generating a network security penetration test report, comprising the following steps: Step 101: Collect vulnerability information found during the penetration test. Vulnerability information is data related to system security vulnerabilities found during the penetration test. Vulnerability information includes descriptions of vulnerability types such as SQL injection, cross-site scripting attacks, discovery locations, severity of vulnerabilities, and impacts on system functions.

[0018] Step 102: Take each vulnerability as a node and build edges connecting the nodes based on the relationship between the vulnerabilities to obtain a vulnerability relationship model; assign weights to the nodes and edges according to the vulnerability characteristics; and calculate the correlation between the vulnerabilities to identify key vulnerabilities and vulnerability chains. The vulnerability relationship model is formed by treating each vulnerability as a node and building edges connecting these nodes based on the relationship between the vulnerabilities. A numerical value is assigned to each vulnerability node according to the vulnerability characteristics, and the numerical value reflects the relative importance of the vulnerability in the overall system security. Vulnerability characteristics may include the severity of the vulnerability, the ease of exploitation, and the scope of impact. The higher the weight, the greater the potential threat of the vulnerability to system security. The edge weight is the numerical value assigned to the edge connecting the vulnerability nodes based on the vulnerability characteristics, indicating the closeness of the relationship between the two vulnerabilities. For example, if the existence of one vulnerability is a prerequisite for the exploitation of another vulnerability, then the edge weight connecting the two vulnerabilities may be high, which means that the relationship between them has a greater impact on the overall security situation.

[0019] Step 103: Generate an attack path based on the established vulnerability relationship model and historical attack data; and evaluate the success rate of each attack path based on vulnerability correlation and system business logic.

[0020] Step 104: Generate a penetration test report based on the vulnerability relationship model and attack path.

[0021] Specifically, by collecting vulnerability information during the penetration test, each vulnerability is taken as a node and edges are established based on their mutual relationships to obtain a vulnerability relationship model. Weights are assigned to nodes and edges based on vulnerability characteristics. Based on the importance of each vulnerability and its relationship, key vulnerabilities and vulnerability chains can be identified through correlation calculation. Based on the vulnerability relationship model and historical attack data, an attack path is generated to simulate the possible action routes taken by the attacker. The success rate of each attack path is evaluated by combining the vulnerability correlation and system business logic, so that security personnel can know the actual probability of different attack paths, so that those risks with high success rates and great harm can be dealt with in a targeted and prioritized manner. The penetration test report is generated based on the vulnerability relationship model and attack path, which improves the ability and efficiency of network security protection.

[0022] As a specific implementation method of a network security penetration test report generation method, each vulnerability is taken as a node and edges connecting the nodes are built based on the mutual relationship between the vulnerabilities to obtain a vulnerability relationship model, including: Identify each vulnerability found during the penetration test and treat each vulnerability as a separate node; Determine for each vulnerability whether there is a relationship between it and other vulnerabilities; the relationship includes: precondition relationship, concurrency relationship and subsequent impact relationship; According to the determined mutual relations between the vulnerabilities, edges are established between the nodes having the mutual relations to form a vulnerability relation model; Assign weights to nodes and edges based on vulnerability characteristics, including: The nodes corresponding to each vulnerability are weighted based on the severity, exploitability, impact scope and business importance of the vulnerability; Each edge connecting nodes is weighted based on the closeness of the relationship, the availability of the relationship, and the impact on the system.

[0023] Specifically, each vulnerability is identified as an independent node, the relationships between vulnerabilities are determined, and edges are established based on these relationships to form a vulnerability relationship model. The precondition relationship is used to identify key vulnerabilities that must be exploited before triggering other vulnerabilities. Once the precondition vulnerability is breached by the attacker, it may lay the foundation for subsequent attacks; the concurrency relationship is used to identify multiple vulnerabilities that can be exploited at the same time. The attacker may use a multi-pronged approach to attack multiple vulnerabilities at the same time, posing a greater threat to the system; the subsequent impact relationship is used to identify the chain reaction of other vulnerabilities that will be triggered after a vulnerability is exploited, which may cause more serious damage to the system. Weights are assigned to nodes and edges based on vulnerability characteristics. For nodes, weights are assigned based on the severity, exploitability, impact range, and business importance of the vulnerability. The weight size is used to determine which vulnerabilities may cause more serious damage to the system, which vulnerabilities are more likely to be exploited by attackers, and which vulnerabilities will affect the key business of the system. For the weight assignment of edges, the closeness of the relationship, the exploitability of the relationship, and the system impact are considered, so as to know the closeness of the association between different vulnerabilities, the possibility of such association being exploited during the attack process, and the impact on the system. Based on the vulnerability relationship model, the most likely attack route from one vulnerability to another can be found, and then the possible attack steps of the attacker can be inferred. By comprehensively considering the node and edge weights, the potential risks of different attack paths can be calculated, which helps to evaluate the security status of the entire system. Vulnerabilities can be sorted according to weights, and resources can be allocated to the repair of vulnerabilities with high weights first, avoiding blindly handling vulnerabilities during defense, and improving the efficiency and pertinence of vulnerability repair.

[0024] As a specific implementation of a method for generating a network security penetration test report, calculating the correlation between vulnerabilities to identify key vulnerabilities includes: The total number of vulnerability nodes is counted based on the vulnerability relationship network in the vulnerability relationship model, and recorded as the total number of vulnerability nodes; For each vulnerable node, assign the same initial page rank value; Iteratively calculate the relevance and update the page ranking value of each vulnerability node; Mark vulnerabilities whose page ranking values ​​are greater than the ranking threshold as critical vulnerability nodes; The iterative calculation of the correlation degree and updating of the page ranking value of each vulnerability node include: Initialize a temporary representation value; Find all the connection relationships pointing to the current vulnerability node; perform the following steps for each connection relationship pointing to the current vulnerability node: determine the source vulnerability node, count the number of outgoing edge connection relationships of the source vulnerability node, obtain the comprehensive weight of the source vulnerability node, obtain the comprehensive weight of the current connection relationship, and obtain the current page ranking value of the source vulnerability node; calculate the increment of the new page ranking value; update the new temporary representation value of the current vulnerability node based on the increment; where the calculation formula of the increment is ;Wherein, a is the increment; b is the comprehensive weight of the source vulnerability node; c is the comprehensive weight of the current connection relationship; d is the page ranking value of the source vulnerability node; e is the number of outgoing edge connection relationships of the source vulnerability node; repeat the iteration until the difference between the new temporary representation value and the previous temporary representation value is less than the difference threshold; Update the page ranking value of each vulnerability node based on the final temporary representation value.

[0025] Specifically, during the iteration process, the connection relationship pointing to the current vulnerability node is found, and each connection relationship is analyzed, including determining the source vulnerability node, counting the number of outgoing connection relationships of the source vulnerability node, obtaining the comprehensive weight of the source vulnerability node, obtaining the comprehensive weight of the current connection relationship, and the current page ranking value of the source vulnerability node. The increment combines the comprehensive weight of the source vulnerability node, the comprehensive weight of the current connection relationship, the page ranking value of the source vulnerability node, and the number of outgoing connection relationships of the source vulnerability node. Through multiple iterations, the temporary representation value of each vulnerability node can reflect its importance and influence in the entire vulnerability relationship network. When the difference between the new temporary representation value and the previous temporary representation value is less than the difference threshold, it means that the page ranking value of the vulnerability node tends to be stable, and its final page ranking value comprehensively reflects its relevance in the entire network. Vulnerabilities with page ranking values ​​greater than the ranking threshold are marked as key vulnerability nodes, and those vulnerability nodes that are at the core of the vulnerability relationship network, have important connections with many vulnerability nodes and have high weights are screened out. This avoids judging only from the characteristics of a single vulnerability, but instead from the perspective of the entire network, based on the relationships and weights between vulnerabilities, finds out those key vulnerabilities that, once exploited, may trigger a chain reaction and pose a major threat to system security.

[0026] As a specific implementation of a method for generating a network security penetration test report, identifying a vulnerability chain includes: Add each key vulnerability node to the search queue; Initialize an empty vulnerability chain list to store the discovered vulnerability chains; When the search queue is not empty, a vulnerability node is taken out of the queue; all outgoing edge connection relationships of the current vulnerability node are found; for each outgoing edge connection relationship, it is determined whether the comprehensive weight of the outgoing edge connection relationship and the comprehensive weight of the vulnerability node pointed to by the outgoing edge connection relationship meet the priority condition; if so, the vulnerability node pointed to by the outgoing edge connection relationship is added to the search queue, and the path from the current vulnerability node to the vulnerability node pointed to by the outgoing edge connection relationship is added to the current vulnerability chain; when the length of the current vulnerability chain reaches the termination condition, the vulnerability chain is stored in the vulnerability chain list.

[0027] Specifically, suppose there is a vulnerable node A, which may have some association with several other vulnerable nodes (such as B, C, D). The edge from node A to node B is an outgoing edge of node A.

[0028] Start by adding key vulnerability nodes to the search queue and gradually build a vulnerability chain. Initialize an empty vulnerability chain list for the system to store discovered vulnerability chains. When the search queue is not empty, take out the vulnerability nodes in order and find their outgoing edge connections. For each outgoing edge connection, determine whether it meets the priority conditions based on the comprehensive weight. Only when the conditions are met will the vulnerability chain be further expanded, effectively avoiding meaningless path exploration and improving the accuracy of vulnerability chain construction. Once the current vulnerability chain length reaches the termination condition, it is stored in the vulnerability chain list. Identifying vulnerability chains in this way can more clearly and accurately present potential security threat paths in the system.

[0029] As one implementation of a method for generating a network security penetration test report, generating an attack path based on the established vulnerability relationship model and historical attack data includes: Initialize a stack data structure, and push all key vulnerabilities and their initial paths into the stack in sequence; the stack data structure is used to store the nodes to be visited and the current access path; initialize an empty attack path set, and the attack path set is used to store the generated attack paths; When the stack is not empty, do the following: Pop an element from the stack, where the popped element contains a vulnerable node and the current access path; For all outgoing edges of the vulnerability node contained in the element, determine the next vulnerability node pointed to by the outgoing edge and check whether the next vulnerability node meets the condition for continuing the search, where the condition for continuing the search is based on historical attack data considerations, business logic and weights; If the conditions for continuing the search are met, the next vulnerability node and the updated access path are pushed into the stack; When the current vulnerability node has no outgoing edges, the current access path is added to the attack path set; If the next vulnerable node pointed to by all outgoing edges of the vulnerable node represented by the element popped from the stack does not meet the conditions for continuing the search, the corresponding element is marked as visited.

[0030] Specifically, the initialization stack data structure pushes all key vulnerabilities and their own initial paths in sequence, and the initialized empty attack path set is used to store the final generated attack path to ensure the orderly storage of the results. When the stack is not empty, elements are continuously popped from the stack, and the vulnerability nodes and access paths contained in it will become the objects of further operations. By checking the next vulnerability node pointed to by all outgoing edges of the vulnerability node contained in the element, whether the conditions for continued search are met are considered according to historical attack data, business logic and weight, and nodes with actual attack possibilities are screened out to avoid blind search. The next vulnerability node and the updated access path that meet the conditions for continued search will be pushed into the stack, realizing the dynamic expansion of the search path. When the current vulnerability node has no outgoing edges, the current access path is added to the attack path set, so that the complete attack path can be completely saved. For the case where the outgoing edges of the vulnerability node of the popped element in the stack do not meet the conditions for continued search, it is marked as visited to avoid repeated operations. Using the storage and operation mechanism of the stack, attack paths that meet the actual attack scenarios can be accurately and efficiently generated, which helps to discover potential security vulnerabilities in the system.

[0031] As one implementation of a method for generating a network security penetration test report, before generating a penetration test report based on a vulnerability relationship model and an attack path, the method further includes: Before generating a penetration test report, first identify the user who requested the report; Define different report access permissions and information visibility levels for users with different identities; Determine what is presented in the penetration test report based on report access permissions and information visibility levels.

[0032] As one implementation of a method for generating a network security penetration test report, the method further includes: Creating a pruning mark set; the pruning mark set is used to store known pruning path information; based on historical attack data, finding low-risk node combinations that have never been successfully exploited in history and adding them to the pruning mark set; When an element is popped from the stack, a node combination identifier is generated starting from the current node and passing through the outgoing edge to reach the next vulnerable node; the node combination identifier is compared with the information in the pruning mark set; If the current node combination identifier exists in the pruning mark set, it means that the node combination has never been successfully exploited in historical data, and the subsequent search operation for the next vulnerable node pointed to by the outgoing edge is directly skipped.

[0033] Specifically, a pruning mark set is created to store known pruning path information; based on historical attack data, low-risk node combinations that have never been successfully exploited in history are found and added to the pruning mark set, so that the system can identify those node combinations that are low-risk and non-threatening in attack scenarios in advance based on past experience; when an element is popped from the stack, a node combination identifier is generated from the current node through the outgoing edge to the next vulnerable node, and it is compared with the information in the pruning mark set. If the node combination identifier exists in the pruning mark set, it indicates that it belongs to a low-risk node combination that has never been successfully exploited in historical data, and the subsequent search operation for the next vulnerable node pointed to by the outgoing edge is directly skipped, avoiding the invalid exploration of these low-value nodes and saving system resources and time.

[0034] The present application also provides a system for generating a network security penetration test report, including: The first processing module 201 is used to collect vulnerability information during the penetration test; The second processing module 202 is used to: take each vulnerability as a node and build edges connecting the nodes based on the mutual relationship between the vulnerabilities to obtain a vulnerability relationship model; assign weights to the nodes and edges according to the vulnerability characteristics; calculate the correlation between the vulnerabilities to identify key vulnerabilities and vulnerability chains; The third processing module 203 is used to: generate an attack path based on the established vulnerability relationship model and historical attack data; The fourth processing module 204 is used to generate a penetration test report based on the vulnerability relationship model and the attack path.

[0035] It should be noted that the above embodiments are only used to illustrate the present application and are not intended to limit the technical solutions described in the present application. Although the present application has been described in detail in this specification with reference to the above embodiments, a person of ordinary skill in the art should understand that a person of ordinary skill in the art can still modify or make equivalent substitutions to the present application, and all technical solutions and improvements thereof that do not depart from the spirit and scope of the present application should be included in the scope of the claims of the present application.

Claims

1. A method for generating a network security penetration test report, characterized in that: include: Collect vulnerability information during penetration testing; Each vulnerability is taken as a node and edges connecting the nodes are built based on the mutual relationship between the vulnerabilities to obtain a vulnerability relationship model; weights are assigned to the nodes and edges according to the vulnerability characteristics; Calculate the correlation between vulnerabilities to identify key vulnerabilities and vulnerability chains; Generate an attack path based on the established vulnerability relationship model and historical attack data; Generate penetration test reports based on vulnerability relationship models and attack paths.

2. The method for generating a network security penetration test report according to claim 1, characterized in that: Each vulnerability is taken as a node and edges connecting the nodes are built based on the relationships between the vulnerabilities to obtain a vulnerability relationship model, including: Identify each vulnerability found during the penetration test and treat each vulnerability as a separate node; Determine for each vulnerability whether there is a relationship between it and other vulnerabilities; the relationship includes: precondition relationship, concurrency relationship and subsequent impact relationship; According to the determined mutual relations between the vulnerabilities, edges are established between the nodes having the mutual relations to form a vulnerability relation model; Assign weights to nodes and edges based on vulnerability characteristics, including: The nodes corresponding to each vulnerability are weighted based on the severity, exploitability, impact scope and business importance of the vulnerability; Each edge connecting nodes is weighted based on the closeness of the relationship, the availability of the relationship, and the impact on the system.

3. The method for generating a network security penetration test report according to claim 2, characterized in that: Calculate correlations between vulnerabilities to identify critical vulnerabilities, including: The total number of vulnerability nodes is counted based on the vulnerability relationship network in the vulnerability relationship model, and recorded as the total number of vulnerability nodes; For each vulnerable node, assign the same initial page rank value; Iteratively calculate the relevance and update the page ranking value of each vulnerability node; Mark vulnerabilities whose page ranking values ​​are greater than the ranking threshold as critical vulnerability nodes; The iterative calculation of the correlation degree and updating of the page ranking value of each vulnerability node include: Initialize a temporary representation value; Find all the connection relationships pointing to the current vulnerability node; perform the following steps for each connection relationship pointing to the current vulnerability node: determine the source vulnerability node, count the number of outgoing edge connection relationships of the source vulnerability node, obtain the comprehensive weight of the source vulnerability node, obtain the comprehensive weight of the current connection relationship, and obtain the current page ranking value of the source vulnerability node; calculate the increment of the new page ranking value; update the new temporary representation value of the current vulnerability node based on the increment; where the calculation formula of the increment is ;Wherein, a is the increment; b is the comprehensive weight of the source vulnerability node; c is the comprehensive weight of the current connection relationship; d is the page ranking value of the source vulnerability node; e is the number of outgoing edge connection relationships of the source vulnerability node; repeat the iteration until the difference between the new temporary representation value and the previous temporary representation value is less than the difference threshold; Update the page ranking value of each vulnerability node based on the final temporary representation value.

4. A method for generating a network security penetration test report according to claim 3, characterized in that: Identify vulnerability chains, including: Add each key vulnerability node to the search queue; Initialize an empty vulnerability chain list to store the discovered vulnerability chains; When the search queue is not empty, a vulnerability node is taken out of the queue; all outgoing edge connection relationships of the current vulnerability node are found; for each outgoing edge connection relationship, it is determined whether the comprehensive weight of the outgoing edge connection relationship and the comprehensive weight of the vulnerability node pointed to by the outgoing edge connection relationship meet the priority condition; if so, the vulnerability node pointed to by the outgoing edge connection relationship is added to the search queue, and the path from the current vulnerability node to the vulnerability node pointed to by the outgoing edge connection relationship is added to the current vulnerability chain; when the length of the current vulnerability chain reaches the termination condition, the vulnerability chain is stored in the vulnerability chain list.

5. A method for generating a network security penetration test report according to claim 4, characterized in that: Generate an attack path based on the established vulnerability relationship model and historical attack data, including: Initialize a stack data structure, and push all key vulnerabilities and their initial paths into the stack in sequence; the stack data structure is used to store the nodes to be visited and the current access path; initialize an empty attack path set, and the attack path set is used to store the generated attack paths; When the stack is not empty, do the following: Pop an element from the stack, where the popped element contains a vulnerable node and the current access path; For all outgoing edges of the vulnerability node contained in the element, determine the next vulnerability node pointed to by the outgoing edge and check whether the next vulnerability node meets the condition for continuing the search, where the condition for continuing the search is based on historical attack data considerations, business logic and weights; If the conditions for continuing the search are met, the next vulnerability node and the updated access path are pushed into the stack; When the current vulnerability node has no outgoing edges, the current access path is added to the attack path set; If the next vulnerable node pointed to by all outgoing edges of the vulnerable node represented by the element popped from the stack does not meet the conditions for continuing the search, the corresponding element is marked as visited.

6. A method for generating a network security penetration test report according to claim 5, characterized in that: Before generating a penetration test report based on the vulnerability relationship model and the attack path, the method further includes: Before generating a penetration test report, first identify the user who requested the report; Define different report access permissions and information visibility levels for users with different identities; Determine what is presented in the penetration test report based on report access permissions and information visibility levels.

7. A method for generating a network security penetration test report according to claim 6, characterized in that: The method further comprises: Create a pruning mark set; the pruning mark set is used to store known pruning path information; find low-risk node combinations that have never been successfully exploited in history based on historical attack data It is added to the set of pruning marks; When an element is popped from the stack, a node combination identifier is generated starting from the current node and passing through the outgoing edge to reach the next vulnerable node; the node combination identifier is compared with the information in the pruning mark set; If the current node combination identifier exists in the pruning mark set, it means that the node combination has never been successfully exploited in historical data, and the subsequent search operation for the next vulnerable node pointed to by the outgoing edge is directly skipped.

8. A system for generating a network security penetration test report, characterized in that: include: The first processing module is used to: collect vulnerability information during the penetration test; The second processing module is used to: take each vulnerability as a node and build edges connecting the nodes based on the mutual relationship between the vulnerabilities to obtain a vulnerability relationship model; assign weights to the nodes and edges according to the vulnerability characteristics; Calculate the correlation between vulnerabilities to identify key vulnerabilities and vulnerability chains; A third processing module is used to: generate an attack path based on the established vulnerability relationship model and historical attack data; The fourth processing module is used to generate a penetration test report based on the vulnerability relationship model and the attack path.

Citation Information

Patent Citations

  • Automated safety penetration test method

    CN107426227A

  • Loophole finding method based on loophole correlation distribution model

    CN107526971A

  • Automatic penetration testing method and system, electronic equipment and storage medium

    CN116566674A

  • Working method of automatic penetration test

    CN119420533A

  • Security finding categories-based prioritization

    US20240267400A1