Network elasticity evaluation method and device for web application, product and equipment
By building a simulation environment for web applications, dynamic and static evaluation are carried out, and the network elasticity evaluation results are determined based on the results of the two, which solves the problem that the web application network elasticity evaluation cannot be conducted in the existing technology without affecting the user's use, and achieves a comprehensive and non-affecting evaluation effect.
Patent Information
- Application Number
- CN202510247020.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-03
- Publication Date
- 2025-05-27
AI Technical Summary
The existing technology is difficult to conduct network flexibility assessment of web applications without affecting user use, resulting in the inability to discover problems in a timely manner and improve the security of web applications.
By obtaining the network elasticity assessment data of web applications, a simulation and simulation environment corresponding to the existing network environment is constructed, and dynamic and static assessments are performed in this environment, and the results of the network elasticity assessment are determined based on the results of the two.
It realizes a comprehensive network elastic evaluation of web applications without affecting user usage, discovers problems and improves the security of web applications. Dynamic evaluation and static evaluation are combined to improve the comprehensiveness of evaluation.
Smart Images

Figure CN120050210A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of web application evaluation, and particularly to a network elasticity evaluation method, device, product, and equipment for web applications. Background Art
[0002] It is very common for web applications to be launched with vulnerabilities. Although the investment in security protection construction is increasing continuously, the intelligence and diversification of network attack means make it difficult for traditional security protection measures and security operation and maintenance personnel to accurately perceive in advance, effectively defend during the event, and recover in time after the event. The web application security protection has always been in a difficult situation of passive defense.
[0003] Currently, how to evaluate web applications, discover problems in a timely manner, and improve the security of web applications is an issue that needs to be solved. Summary of the Invention
[0004] In view of this, the purpose of this application is to provide a network elasticity evaluation method, device, product, and equipment for web applications, which can perform network elasticity evaluation on web applications without affecting user usage, thereby discovering problems and improving the security of web applications. The specific solutions are as follows:
[0005] In the first aspect, this application discloses a network elasticity evaluation method for web applications, including:
[0006] Obtain network elasticity evaluation data of the web application;
[0007] Based on the network elasticity evaluation data, construct a simulation environment corresponding to the live network environment of the web application, and simulate the running state of the web application in the live network environment in the simulation environment;
[0008] Perform dynamic evaluation on the web application in the simulation environment to obtain the dynamic evaluation result of the web application;
[0009] Perform static evaluation on the web application based on the network elasticity evaluation data to obtain the static evaluation result of the web application;
[0010] Determine the network elasticity evaluation result of the web application based on the static evaluation result and the dynamic evaluation result.
[0011] Optionally, the network elasticity evaluation data includes web application ontology domain evaluation data, running environment domain evaluation data, network security domain evaluation data, and operation and maintenance management domain evaluation data, where
[0012] The Web application ontology domain evaluation data are data information related to the development and implementation of the functions of the Web application itself. The operating environment domain evaluation data include software data information and hardware data information that support the operation of the Web application. The network security domain evaluation data include data information on various security software and hardware assets and policies adopted to ensure the network security of the Web application. The operation and maintenance management domain evaluation data include operation and maintenance management system data for ensuring the stable operation of the Web application and the implementation records of the operation and maintenance management system data.
[0013] Optionally, simulating the running state of the web application in the live network environment in the simulation environment includes:
[0014] Using the probes deployed in the live network environment to collect the running data of the web application in the live network environment and synchronize it to the simulation environment;
[0015] Copying the traffic of the web application in the live network environment to the simulation environment through a traffic mirroring plugin to keep the running states of the web application in the simulation environment and in the live network environment synchronized.
[0016] Optionally, dynamically evaluating the web application in the simulation environment to obtain the dynamic evaluation result of the web application includes:
[0017] Invoking threat samples in the Web application threat library and automated scripts in the elastic evaluation tool library to dynamically evaluate the web application in the simulation environment to obtain the dynamic evaluation result of the web application.
[0018] Optionally, the elastic evaluation tool library includes a preset tool set. The preset tool set includes evaluation tools corresponding to each stage of network attacks. The evaluation tools are automated scripts. Correspondingly, invoking the automated scripts in the elastic evaluation tool library to dynamically evaluate the web application in the simulation environment to obtain the dynamic evaluation result of the web application includes:
[0019] Invoking the evaluation tools corresponding to each stage in sequence according to the stages of network attacks to dynamically evaluate the web application in the simulation environment to obtain the dynamic evaluation result corresponding to the preset tool set of the web application. Optionally, statically evaluating the web application based on the network resilience evaluation data to obtain the static evaluation result of the web application includes:
[0020] Analyzing the network resilience evaluation data based on a deep learning model and using a preset network resilience knowledge base to obtain the static evaluation result of the web application, where the preset network resilience knowledge base includes a knowledge system of network security and network resilience.
[0021] In a second aspect, the present application discloses a network elasticity evaluation device for a web application, including:
[0022] A data acquisition module, configured to acquire network elasticity evaluation data of the web application;
[0023] An environment simulation module, configured to construct a simulation environment corresponding to the live network environment of the web application based on the network elasticity evaluation data, and simulate the running state of the web application in the live network environment in the simulation environment;
[0024] A dynamic evaluation module, configured to perform dynamic evaluation on the web application in the simulation environment to obtain a dynamic evaluation result of the web application;
[0025] A static evaluation module, configured to perform static evaluation on the web application based on the network elasticity evaluation data to obtain a static evaluation result of the web application;
[0026] A result determination module, configured to determine a network elasticity evaluation result of the web application based on the static evaluation result and the dynamic evaluation result.
[0027] In a third aspect, the present application discloses a computer program product, including computer programs / instructions, and when the computer programs / instructions are executed by a processor, the network elasticity evaluation method for the web application described above is implemented.
[0028] In a fourth aspect, the present application discloses an electronic device, including a memory and a processor, where:
[0029] The memory is used to store a computer program;
[0030] The processor is configured to execute the computer program to implement the network elasticity evaluation method for the web application described above.
[0031] In a fifth aspect, the present application discloses a computer-readable storage medium, used to store a computer program, where when the computer program is executed by a processor, the network elasticity evaluation method for the web application described above is implemented.
[0032] As can be seen from the above solution, the present application discloses a method for network elasticity evaluation of a web application, including: obtaining network elasticity evaluation data of the web application; constructing a simulation environment corresponding to the live network environment of the web application based on the network elasticity evaluation data, and simulating the running state of the web application in the live network environment in the simulation environment; performing dynamic evaluation on the web application in the simulation environment to obtain a dynamic evaluation result of the web application; performing static evaluation on the web application based on the network elasticity evaluation data to obtain a static evaluation result of the web application; and determining a network elasticity evaluation result of the web application based on the static evaluation result and the dynamic evaluation result.
[0033] It can be seen that the beneficial effects of the present application are as follows: Based on the network elasticity evaluation data of the web application, a simulation environment corresponding to the live network environment of the web application is constructed, and the running state in the live network environment is synchronized in the simulation environment, realizing the digital twin of the live network environment. Performing dynamic evaluation on the web application in the simulation environment avoids attack testing on the live network environment, and can perform network elasticity evaluation on the web application without affecting user use, so as to discover problems and improve the security of the web application. Moreover, the combination of dynamic evaluation and static evaluation improves the comprehensiveness of network elasticity evaluation.
[0034] Correspondingly, a network elasticity evaluation device, product, device, and readable storage medium for a web application provided by the present application also have the above technical effects. BRIEF DESCRIPTION OF THE DRAWINGS
[0035] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained according to the provided drawings without creative efforts.
[0036] Figure 1 It is a flowchart of a method for network elasticity evaluation of a web application provided by an embodiment of the present application;
[0037] Figure 2 It is a schematic diagram of dynamic evaluation based on digital twin provided by an embodiment of the present application;
[0038] Figure 3 It is a schematic diagram of network elasticity evaluation of a web application provided by an embodiment of the present application;
[0039] Figure 4 It is a schematic diagram of the structure of a network elasticity evaluation device for a web application provided by an embodiment of the present application;
[0040] Figure 5 A structural diagram of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0041] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.
[0042] The number of attacks on Web applications is on the rise. Moreover, in the process of digital construction of small and medium-sized enterprises, institutions, etc., there is a common phenomenon of focusing on applications and neglecting security. It is very common for Web applications to be launched with vulnerabilities. Although security compliance and policy review are becoming increasingly strict, and investment in traditional security protection construction is also increasing, the intelligent and diversified means of network attacks make it difficult for traditional security protection measures and security operation and maintenance personnel to accurately perceive before, effectively defend during, and recover in time after. Web application security protection is always in a difficult situation of passive defense. With the rise of the concept of network resilience, it has gradually become another important means to strengthen the security of digital infrastructure, and this is also true for Web applications. How to achieve Web applications with network resilience has become an important means to improve the current situation of Web application attack-stricken areas. However, research on network resilience is still in its infancy, especially for Web applications.
[0043] As the most common business form in digital transformation, web applications have a vital role in elastic design. However, most of the currently known network elasticity evaluation methods are relatively generalized, either for cloud computing resources, network control systems, etc., or only for individual objects under test. There is no universal network elasticity evaluation method for running web applications on existing networks. In addition, the key to network elasticity evaluation is to evaluate the ability of web applications to quickly restore functions when they are attacked by a network. Therefore, it is inevitable to implement a series of attack behaviors against web applications during the evaluation process. Most of the known network elasticity evaluation methods also mention the need to construct disturbances, attacks, etc. to attack the objects under test. However, from the user's perspective, web applications have basically been put into use on existing networks. In order to ensure the daily operation of the user's own business, direct attacks on existing web applications are not allowed. Therefore, the existing network elasticity evaluation methods have high practical limitations and lack a response mechanism. To this end, the present application provides a network elasticity evaluation scheme for web applications, which can perform network elasticity evaluation on web applications without affecting user use, thereby discovering problems and improving the security of web applications.
[0044] See Figure 1 As shown, an embodiment of the present application discloses a method for network elasticity evaluation of a web application, including:
[0045] Step S11: Obtain network elasticity evaluation data of the web application.
[0046] Among them, the network elasticity evaluation data can be data related to network elasticity evaluation of the web application uploaded by the user. The network elasticity evaluation data can be determined based on the network elasticity evaluation index system of the Web application. The network elasticity evaluation index system is a system including various evaluation indexes, and each evaluation index corresponds to several data in the network elasticity evaluation data. The data corresponding to the evaluation index can be extracted from the network elasticity evaluation data to complete the evaluation of the evaluation index.
[0047] In an embodiment of the present application, the network elasticity evaluation data includes Web application ontology domain evaluation data, operating environment domain evaluation data, network security domain evaluation data, and operation and maintenance management domain evaluation data. Among them, the Web application ontology domain evaluation data is data information related to the development and implementation of the Web application's own functions. The operating environment domain evaluation data includes software data information and hardware data information that support the operation of the Web application. The network security domain evaluation data includes data information of various security software and hardware assets and policies adopted to ensure the network security of the Web application. The operation and maintenance management domain evaluation data includes operation and maintenance management system data for ensuring the stable operation of the Web application and implementation records of the operation and maintenance management system data.
[0048] That is, an embodiment of the present application can perform a comprehensive network elasticity evaluation of the Web application according to four domains based on a preset network elasticity evaluation index system of the Web application. The four domains include the Web application ontology domain, the operating environment domain, the network security domain, and the operation and maintenance management domain.
[0049] Among them, the evaluation data of the Web application ontology domain refers to the data information closely related to the development and implementation of the Web application's own functions, which may include source code, development language and version, development framework and version, third-party libraries and versions. Among them, the third-party library is a library that assists in the development of the web application, such as JS (i.e., JavaScript, a dynamic programming language) library, CSS (i.e., Cascading Style Sheets) library, etc. The evaluation data of the operating environment domain refers to the software and hardware data information that supports the smooth operation of the Web application, which may include hardware architecture and model, operating system and version, virtualization layer software and version, web service software and version, database software and version, middleware and version, redundancy backup strategy. The evaluation data of the network security domain refers to the relevant data information of various security software and hardware assets and strategies adopted to ensure the network security of the Web application, which may include network security solutions, the list of network security assets involved and the quantity of each type of network security asset, manufacturer and model, configuration strategy. The evaluation data of the operation and maintenance management domain refers to the relevant management system data and other data information formulated by users to ensure the stable daily operation of the Web application, including the operation and maintenance management system data to ensure the stable operation of the Web application and the implementation records of the operation and maintenance management system data. For example, operation and maintenance management systems, risk warning plans and records, emergency plans and emergency drill records, threat intelligence library information, asset manufacturer qualification management systems, asset intellectual property rights, data backup strategies. Asset intellectual property rights may include information such as copyrights and patents.
[0050] It should be noted that the data forms of the above-listed four-domain data include but are not limited to various forms such as text, images, audio and video, and code, which need to be uploaded by the users of the target Web application to the evaluation system. The evaluation system conducts the evaluation. The above-listed four-domain data is only the minimum set to support the smooth implementation of the network resilience evaluation of the Web application, and other data that meet the definitions of the four-domain data are also within the protection scope of the present invention. Whether the Web application has business resilience under network attacks and what level the network resilience ability is at, relying solely on the results obtained from the network resilience evaluation of the Web application itself is incomplete and inaccurate. Through the comprehensive evaluation under the four domains in the embodiments of the present application, not only the Web application itself is considered, but also the actual deployment situation in the live network is combined for evaluation, and the goal of obtaining comprehensive and accurate evaluation results can be achieved to the greatest extent.
[0051] Step S12: Based on the network resilience evaluation data, construct a simulation environment corresponding to the live network environment of the web application, and simulate the running state of the web application in the live network environment in the simulation environment.
[0052] In an alternative embodiment, target data can be extracted from the network resilience evaluation data, and a simulation environment corresponding to the live network environment of the web application can be constructed based on the target data. The target data may include the Web application source code, middleware version, operating system version, etc. After building a website based on the target data and enabling it to run normally, a simulation environment is obtained. Further, a network security domain can be constructed by invoking network security virtualization resources based on the network security solution.
[0053] In the embodiment of the present application, probes deployed in the live network environment can be used to collect the operation data of the web application in the live network environment and synchronize it to the simulation environment; the traffic of the web application in the live network environment can be copied to the simulation environment through a traffic mirroring plugin to keep the running states of the web application in the simulation environment and in the live network environment synchronized.
[0054] Among them, the probes may include various probes in a probe library such as host probes, Web application probes, and log probes. By deploying various probes in the probe library such as host probes, Web application probes, and log probes to the live network environment of the Web application, the embodiment of the present application can collect past operation data and synchronize it to the simulation environment without affecting the actual operation of the Web application in the live network. In addition, the live network business traffic of the Web application can be copied and forwarded to the simulation environment through a traffic mirroring plugin, realizing the replication of real-time business traffic in the live network environment and keeping the running states of the simulation environment and the live network environment synchronized.
[0055] Step S13: Perform a dynamic evaluation on the web application in the simulation environment to obtain a dynamic evaluation result of the web application.
[0056] In the embodiment of the present application, threat samples in the Web application threat library and automated scripts in the resilience evaluation tool library can be invoked to perform a dynamic evaluation on the web application in the simulation environment to obtain a dynamic evaluation result of the web application.
[0057] In an alternative embodiment, the elastic evaluation tool library includes a preset tool set. The preset tool set includes evaluation tools corresponding to each stage of a cyber attack. The evaluation tools are automated scripts. Correspondingly, by invoking the automated scripts of the elastic evaluation tool library, the web application is dynamically evaluated in a simulation environment to obtain the dynamic evaluation result of the web application, including: invoking the evaluation tools corresponding to each stage in the order of each stage of the cyber attack, and dynamically evaluating the web application in the simulation environment to obtain the dynamic evaluation result corresponding to the preset tool set of the web application. In this way, by invoking the corresponding attacks in sequence according to the attack stages for evaluation, the evaluation efficiency can be improved, and moreover, each stage is taken into account to improve the evaluation accuracy of cyber attacks.
[0058] On the premise that the embodiments of the present application can run stably in a simulation environment, threat samples in the Web application threat library and automated scripts of the elastic evaluation tool library can be specifically invoked according to elastic metrics (i.e., evaluation metrics in the network resilience evaluation metric system), and then a series of dynamic evaluations of the Web application can be carried out in the simulation environment, including penetration testing, usability testing, fault simulation testing, etc.
[0059] Further, refer to Figure 2 as shown in Figure 2 a schematic diagram of dynamic evaluation based on digital twin provided by the embodiments of the present application. As Figure 2As shown in the figure, the dynamic assessment includes a digital twin platform, a probe library, a traffic mirroring plugin, a Web application threat library, and an elastic assessment tool library. Among them, the digital twin platform is mainly responsible for building a virtual assessment environment highly consistent with the live network environment, that is, a simulation environment, to support subsequent dynamic assessment tasks based on elastic metrics. First, based on the four-domain data uploaded by the target Web application user, the digital twin platform uses the scenario construction tool and builds a live network simulation environment of the target Web application with the help of the platform virtualization resources. The target Web application is the Web application to be subjected to network elasticity assessment. For example, build a website based on the source code of the target Web application, middleware version, operating system version, etc. and make it run normally, and build a network security domain by invoking network security virtualization resources based on the network security solution. Second, the digital twin platform can collect past operation data and synchronize it to the simulation environment without affecting the actual operation of the target Web application in the live network by deploying various probes in the probe library, such as host probes, Web application probes, and log probes, to the target Web application environment; by using the traffic mirroring plugin to copy and forward the live network service traffic of the target Web application to the simulation environment to keep its running state synchronized with the live network. Finally, on the premise that the simulation environment runs stably, the assessment execution module of the assessment system specifically invokes the threat samples in the Web application threat library and the automated scripts in the elastic assessment tool library according to the elastic metrics, and then conducts a series of dynamic assessments on the target Web application in the simulation environment, including penetration testing, usability testing, fault simulation testing, etc.
[0060] Among them, penetration testing is based on the Web application threat library and the elastic assessment tool library, uses attack scripts based on different vulnerabilities and tools in each attack stage to conduct network attacks on the target Web application, and records test data (including but not limited to running status, response time, business recovery time, etc.), checks whether the test data meets the requirements of the corresponding elastic metrics, which can be quantitative requirements. If it meets the requirements, the corresponding elastic metric score is given. For example, if it meets the requirements, the first metric score is given, and if it does not meet the requirements, the second metric score is given. The first metric score and the second metric score are different scores.
[0061] For the Web application threat library, vulnerability subsets are mainly extracted from CNVD (China National Vulnerability Database), CNNVD (China National Vulnerability Database of Information Security), CVE (Common Vulnerabilities & Exposures), CWE (Common Weakness Enumeration), etc., and automated attack samples that can be used for penetration testing are formed according to a unified format specification, and can be integrated into a systematic penetration script. The systemization involves all attack stages. This module supports retrieving vulnerability scripts by time because the vulnerability scripts are updated over time, so as to implement penetration testing. At the same time, it supports circularly executing all automated attack samples within a given evaluation period, automatically ending the penetration testing after the evaluation period ends, and visually outputting the penetration testing results.
[0062] For the elastic evaluation tool library, it includes Web application ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) tools, usability monitoring tools, fault simulation tools, etc. Among them, the Web application ATT&CK tools integrate tools for 7 typical stages of network attacks, such as initial access, execution, persistence, privilege escalation, defense evasion, data access, and lateral movement, and can perform penetration testing according to a standardized process that runs through all stages of ATT&CK, and visually output the penetration testing results. The usability monitoring tools are mainly used to evaluate whether the performance and functions of Web applications are at a normal level. The performance data monitored includes indicators such as response time, throughput, and concurrent connection count. The function content monitored includes static page services, dynamic page services, database access services, load balancing services, web cache management, virtual hosts and domain name resolution, redirection services, etc. The fault simulation tools mainly test Web applications by simulating common faults. The supported fault types include missing static resources, failed database access, unexpected host restart, unexpected modification of file permissions, etc.
[0063] The embodiment of this application provides a dynamic evaluation technology based on digital twins, aiming to solve the problems of rejection and difficulty in implementation of penetration testing by Web application users in the live network environment.
[0064] Step S14: Perform static evaluation on the web application based on the network elastic evaluation data to obtain the static evaluation result of the web application.
[0065] It should be noted that there is no order restriction between step S14 and steps S11 to S13. Dynamic evaluation can be performed first and then static evaluation, or static evaluation can be performed first and then dynamic evaluation, or dynamic evaluation and static evaluation can be carried out in parallel.
[0066] In an alternative embodiment, the static evaluation result of the web application can be obtained by analyzing the network elasticity evaluation data based on a deep learning model and using a preset network elasticity knowledge base. The preset network elasticity knowledge base includes a knowledge system of network security and network elasticity, that is, the knowledge architecture of network security and network elasticity, which organizes and integrates knowledge related to network security and network elasticity. Data corresponding to the elasticity index can be extracted from the network elasticity evaluation index. Based on the deep learning model, the extracted data is used as keywords to search in the preset network elasticity knowledge base. Whether the requirements corresponding to the elasticity index are met is judged based on the retrieved data. The score corresponding to the elasticity index is determined according to the judgment result, and the static evaluation result of the web application is determined based on the scores of each elasticity index.
[0067] Furthermore, there may be a situation where it is impossible to judge whether the requirements corresponding to the elasticity index are met based on the preset network elasticity knowledge base. In the embodiment of the present application, an expert can make a judgment and add the corresponding data to the preset network elasticity knowledge base to continuously improve the network elasticity knowledge base and continuously improve the analysis accuracy of the model.
[0068] In this way, the present application provides a static evaluation solution based on a network elasticity knowledge base + AI (Artificial Intelligence) judgment model. The static evaluation takes the knowledge system data in the network elasticity knowledge base as a reference, and the AI judgment model analyzes the evaluation data of four domains uploaded by the users of the target Web application. Finally, it is judged whether the requirements of the elasticity index are met according to the analysis result. The static evaluation solution based on the network elasticity knowledge base + AI judgment model can get rid of the form of completely relying on experts for manual evaluation, improve the efficiency of static evaluation, and rely on the AI judgment model to continuously learn and optimize the evaluation result.
[0069] Among them, the network resilience think tank covers the latest domestic and international research materials on network resilience, the parameters and functions of network security products, the network security construction plan for Web applications, the public vulnerability database / attack cases, and network security-related standards and other knowledge systems. The network resilience think tank is only the data support for static evaluation, and its content is constructed through industry collection and may not be limited to the form of a think tank. The AI judgment model is a deep learning model that uses the deep learning model to analyze and judge the data of the four domains uploaded by the target Web application. The input of the AI judgment model is the data of the four domains related to the target Web application. The main responsibility of the AI judgment model is to analyze and judge whether the target Web application itself, the current network operation environment, network security construction, and operation and maintenance management meet the strict requirements of the resilience indicators with the help of the knowledge system data in the network resilience think tank, and conduct a comprehensive evaluation. The output of the AI judgment model is the static evaluation score of the target Web application.
[0070] For example, for the Web application ontology domain, the development language and version, development framework and version, and third-party library and version used by the target Web application can be retrieved. The AI judgment model conducts automated analysis based on the data in the network resilience think tank, retrieves in the network resilience think tank with the submitted data as keywords, and checks whether there is supporting data indicating that the development language of the corresponding version used by the target Web application is an insecure language, that the corresponding version of the development framework has vulnerabilities, or that the corresponding version of the third-party library has vulnerabilities. If there is, it is considered not to meet the requirements of the corresponding resilience indicator; otherwise, it is considered to meet the requirements of the corresponding resilience indicator, and the corresponding score of the resilience indicator is given.
[0071] For the operating environment domain, the hardware architecture and model, operating system and version, virtualization layer software and version, web service software and version, database software and version, middleware and version, and redundancy backup strategy used by the current network operation environment of the target Web application can be retrieved. The AI judgment model conducts automated analysis based on the data in the network resilience think tank, retrieves in the network resilience think tank with the submitted data as keywords, and checks whether there is supporting data indicating that the hardware processor, operating system, virtualization software, web service software, database software, and middleware of the corresponding version used by the target Web application have vulnerabilities, and whether there is supporting material indicating that the redundancy backup strategy is unreasonable. If there is, it is considered not to meet the requirements of the corresponding resilience indicator; otherwise, it is considered to meet the requirements of the corresponding resilience indicator, and the corresponding score of the resilience indicator is given.
[0072] For the network security domain, the network security solutions implemented by the users of the target Web application to ensure application security, the list of network security assets involved, the quantity, manufacturer, and model of each type of network security asset, and the configuration policies can be retrieved. The AI judgment model conducts automated analysis based on the data in the network resilience knowledge base, and searches in the network resilience knowledge base using the submitted data as keywords to check whether there is any supporting material indicating that the network security solution of the target Web application does not meet the requirements of the classified protection standard, that the adopted network security assets have vulnerabilities, improper policy configurations, or lack redundant backups. If so, it is considered not to meet the corresponding resilience index requirements; otherwise, it is considered to meet the corresponding resilience index requirements, and the corresponding score of the resilience index is given.
[0073] For the operation and maintenance management domain, the operation and maintenance management system, risk warning plan and records, emergency plan and emergency drill records, threat intelligence library information, asset manufacturer qualification management system, asset intellectual property rights, and data backup strategy formulated by the users of the target Web application can be retrieved. The AI judgment model conducts automated analysis based on the data in the network resilience knowledge base, and searches in the network resilience knowledge base using the submitted data as keywords to check whether there is any supporting material indicating that the risk warning plan, emergency plan, emergency drill records, threat intelligence library, data backup strategy, etc. do not meet the requirements of the corresponding national standards. If so, it is considered not to meet the corresponding resilience index requirements; otherwise, it is considered to meet the corresponding resilience index requirements, and the corresponding score of the resilience index is given.
[0074] To illustrate the above examples, the evaluation data involved are all extracted from the data of the four domains and can be logically defined as the first evaluation data required for static evaluation; the evaluation processes listed are all implemented based on the network resilience evaluation index system of the Web application and are not limited to the above operations.
[0075] Step S15: Determine the network resilience evaluation result of the Web application based on the static evaluation result and the dynamic evaluation result. In the embodiments of the present application, the network resilience evaluation result of the Web application can be determined based on the static evaluation result and the dynamic evaluation result. For example, if the static evaluation result and the dynamic evaluation result are the static evaluation score and the dynamic evaluation score respectively, the embodiments of the present application give the final network resilience score of the Web application based on the static evaluation score and the dynamic evaluation score, such as adding the two, or weighting the two. That is, the embodiments of the present application can adopt an elastic evaluation method that combines static evaluation and dynamic evaluation.
[0076] See Figure 3 as shown Figure 3A schematic diagram of network elasticity evaluation for a web application provided by an embodiment of this application. During static evaluation, the evaluation execution module specifically retrieves evaluation data according to the elasticity index system (which can be defined as the first evaluation data), and automatically conducts evaluations in four domains with the help of a network elasticity knowledge base and an AI judgment model. On the one hand, the AI judgment model automatically analyzes the evaluation data corresponding to the four domains based on the data in the network elasticity knowledge base, judges whether it meets the requirements of the corresponding elasticity index according to the analysis results, and finally comprehensively gives the static evaluation score. On the other hand, the AI judgment model will continuously improve the network elasticity knowledge base according to the results of each web application network elasticity evaluation, and continuously improve the analysis accuracy of the AI judgment model. During dynamic evaluation, the evaluation system will retrieve the evaluation data uploaded by the users of the target web application (defined as the second evaluation data), simulate and construct a virtual evaluation environment highly consistent with the live network environment, and make the virtual evaluation environment simulate the actual operation state of the live network through the mirroring of the live network service traffic of the target web application. Then, the evaluation execution module will retrieve typical web application threats and complete attack chain implementation tools from the web application threat library and the elasticity evaluation tool library according to the elasticity index system, and conduct dynamic evaluations such as code auditing, penetration testing, performance testing, and fault simulation on the target web application. Finally, according to the compliance degree between the attack results and the elasticity index, the network elasticity evaluation result is obtained, and the dynamic evaluation score is given. The evaluation system will integrate the static evaluation score and the dynamic evaluation score, give the final network elasticity score of the target web application, and give relevant repair suggestions.
[0077] Furthermore, to explain the above content, the evaluation data involved are all extracted from the four-domain data, and can be logically defined as the second evaluation data required for dynamic evaluation; the listed evaluation processes are all implemented according to the web application network elasticity evaluation index system, not limited to the above operations. The first evaluation data and the second evaluation data are only logically classified. In the actual evaluation process, during the static evaluation and dynamic evaluation processes carried out by the evaluation system, the data elements corresponding to the four-domain data are extracted according to the web application network elasticity evaluation index system.
[0078] It should be noted that although the static evaluation proposed in this application can conduct a relatively comprehensive elasticity evaluation on the target web application, limited by the timeliness and authenticity of the data submitted by the users of the target web application, there may be certain errors in the results obtained from the static evaluation. Therefore, the embodiment of this application combines the data submitted by the users of the target web application to conduct dynamic evaluation on the basis of the static evaluation. Moreover, since most of the target web applications are in-use services already running in the live network, directly conducting dynamic evaluation in the live network environment will surely affect the normal functions of the services, and most users are not willing to adopt this method. Therefore, the above-mentioned dynamic evaluation technology based on digital twin is proposed in this application.
[0079] In this way, based on the four-domain evaluation data of web applications, a network resilience evaluation that combines static and dynamic methods is carried out, providing a static evaluation solution based on a network resilience think tank + AI judgment model and a dynamic evaluation solution based on digital twins. Without affecting user usage, it can comprehensively and accurately evaluate the network resilience of web applications.
[0080] See Figure 4 As shown, an embodiment of the present application provides a network resilience evaluation device for web applications, including:
[0081] A data acquisition module 11, configured to acquire network resilience evaluation data of a web application;
[0082] An environment simulation module 12, configured to construct a simulation environment corresponding to the live network environment of the web application based on the network resilience evaluation data, and simulate the running state of the web application in the live network environment in the simulation environment;
[0083] A dynamic evaluation module 13, configured to perform a dynamic evaluation on the web application in the simulation environment to obtain a dynamic evaluation result of the web application;
[0084] A static evaluation module 14, configured to perform a static evaluation on the web application based on the network resilience evaluation data to obtain a static evaluation result of the web application;
[0085] A result determination module 15, configured to determine a network resilience evaluation result of the web application based on the static evaluation result and the dynamic evaluation result.
[0086] Among them, the network resilience evaluation data includes Web application ontology domain evaluation data, running environment domain evaluation data, network security domain evaluation data, and operation and maintenance management domain evaluation data, where
[0087] The Web application ontology domain evaluation data is data information related to the development and implementation of the functions of the Web application itself. The running environment domain evaluation data includes software data information and hardware data information that support the running of the Web application. The network security domain evaluation data includes data information on various security software and hardware assets and policies adopted to ensure the network security of the Web application. The operation and maintenance management domain evaluation data includes operation and maintenance management system data for ensuring the stable operation of the Web application and implementation records of the operation and maintenance management system data.
[0088] In an optional implementation manner, the environment simulation module 12 is specifically configured to: use a probe deployed in the live network environment to collect the running data of the web application in the live network environment and synchronize it to the simulation environment;
[0089] Copy the traffic of the web application in the live network environment to the simulation environment through a traffic mirroring plugin, and keep the running states of the web application in the simulation environment and in the live network environment synchronized.
[0090] In an optional implementation manner, the dynamic evaluation module 13 is specifically configured to: call threat samples in the Web application threat library and automated scripts in the elastic evaluation tool library, and perform dynamic evaluation on the web application in the simulation environment to obtain the dynamic evaluation result of the web application.
[0091] In an optional implementation manner, the elastic evaluation tool library includes a preset tool set, and the preset tool set includes evaluation tools corresponding to each stage of network attack. The evaluation tools are automated scripts. Correspondingly, the dynamic evaluation module 13 is specifically configured to: call the evaluation tools corresponding to each stage in the order of each stage of network attack, perform dynamic evaluation on the web application in the simulation environment, and obtain the dynamic evaluation result corresponding to the preset tool set of the web application.
[0092] In an optional implementation manner, the static evaluation module 14 is specifically configured to:
[0093] Analyze the network elasticity evaluation data based on a deep learning model and using a preset network elasticity knowledge library to obtain the static evaluation result of the web application, where the preset network elasticity knowledge library includes a knowledge system of network security and network elasticity.
[0094] It can be seen that the embodiment of the present application constructs a simulation environment corresponding to the live network environment of the web application based on the network elasticity evaluation data of the web application, synchronizes the running state in the live network environment in the simulation environment, realizes the digital twin of the live network environment, performs dynamic evaluation on the web application in the simulation environment, avoids attack testing on the live network environment, can perform network elasticity evaluation on the web application without affecting user use, thereby discovering problems and improving the security of the Web application. Moreover, the combination of dynamic evaluation and static evaluation improves the comprehensiveness of network elasticity evaluation.
[0095] The embodiment of the present application discloses a computer program product, including a computer program / instructions, and the computer program / instructions are executed by a processor to implement the network elasticity evaluation method of the web application disclosed in the foregoing embodiment.
[0096] For the specific process of the foregoing network elasticity evaluation method of the web application, reference may be made to the corresponding content disclosed in the foregoing embodiment, and details are not described herein again.
[0097] See Figure 5As shown in the figure, an embodiment of the present application discloses an electronic device 20, including a processor 21 and a memory 22; wherein, the memory 22 is used to store a computer program; the processor 21 is used to execute the computer program, which is the network elasticity evaluation method of the web application disclosed in the foregoing embodiment.
[0098] For the specific process of the above-mentioned network elasticity evaluation method of the web application, reference can be made to the corresponding content disclosed in the foregoing embodiment, and details will not be repeated here.
[0099] Moreover, as a carrier for resource storage, the memory 22 can be a read-only memory, a random access memory, a magnetic disk or an optical disc, etc., and the storage method can be temporary storage or permanent storage.
[0100] In addition, the electronic device 20 further includes a power supply 23, a communication interface 24, an input / output interface 25 and a communication bus 26; wherein, the power supply 23 is used to provide operating voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and external devices, and the communication protocol it follows is any communication protocol applicable to the technical solution of the present application, and specific limitations are not imposed here; the input / output interface 25 is used to obtain external input data or output data to the outside, and its specific interface type can be selected according to specific application requirements, and specific limitations are not imposed here.
[0101] Furthermore, an embodiment of the present application also discloses a computer-readable storage medium for storing a computer program, wherein the computer program, when executed by a processor, implements the network elasticity evaluation method of the web application disclosed in the foregoing embodiment.
[0102] For the specific process of the above-mentioned network elasticity evaluation method of the web application, reference can be made to the corresponding content disclosed in the foregoing embodiment, and details will not be repeated here.
[0103] In this specification, each embodiment is described in a progressive manner. The key point of each embodiment is the difference from other embodiments. The same or similar parts between each embodiment can be referred to each other. For the device disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and the relevant parts can be referred to the description of the method part.
[0104] The steps of the methods or algorithms described in connection with the embodiments disclosed herein may be implemented directly in hardware, in software modules executed by a processor, or in a combination thereof. The software modules may be located in random access memory (RAM), internal memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium well known in the art.
[0105] The above has introduced in detail the network elasticity evaluation method, device, product and equipment of the web application provided by this application. Specific examples are used in this article to elaborate on the principle and implementation manner of this application. The description of the above embodiments is only used to help understand the method and its core idea of this application; at the same time, for those of ordinary skill in the art, according to the idea of this application, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to this application.
Claims
1. A network resilience evaluation method for a web application, characterized in that: include: Obtain network resilience evaluation data for web applications; Building a simulation environment corresponding to the live network environment of the web application based on the network elasticity evaluation data, and simulating the running state of the web application in the live network environment in the simulation environment; Performing dynamic evaluation on the web application in the simulation environment to obtain a dynamic evaluation result of the web application; Performing a static evaluation on the web application based on the network elasticity evaluation data to obtain a static evaluation result of the web application; A network elasticity evaluation result of the web application is determined based on the static evaluation result and the dynamic evaluation result.
2. The network resilience evaluation method for web applications according to claim 1, characterized in that: The network resilience evaluation data includes Web application ontology domain evaluation data, operating environment domain evaluation data, network security domain evaluation data and operation and maintenance management domain evaluation data, wherein: The Web application ontology domain evaluation data is data information related to the development and implementation of the Web application's own functions; the operating environment domain evaluation data includes software data information and hardware data information that support the operation of the Web application; the network security domain evaluation data includes data information on various types of security software and hardware assets and strategies used to ensure the network security of the Web application; the operation and maintenance management domain evaluation data includes operation and maintenance management system data that ensures the stable operation of the Web application and the implementation records of the operation and maintenance management system data.
3. The network resilience evaluation method for web applications according to claim 1, characterized in that: Simulating the running state of the web application in the existing network environment in the simulation environment includes: Using a probe deployed in the existing network environment, collecting the running data of the web application in the existing network environment and synchronizing it to the simulation environment; The traffic of the web application in the existing network environment is copied to the simulation environment through the traffic mirror plug-in, so as to keep the running status of the web application in the simulation environment and in the existing network environment synchronized.
4. The network resilience evaluation method for web applications according to claim 1, characterized in that: Dynamically evaluating the web application in the simulation environment to obtain a dynamic evaluation result of the web application includes: Threat samples in the Web application threat library and automated scripts in the elasticity assessment tool library are called to dynamically assess the web application in a simulation environment to obtain dynamic assessment results of the web application.
5. The network resilience evaluation method for web applications according to claim 4, characterized in that: The elasticity evaluation tool library includes a preset tool set, and the preset tool set includes evaluation tools corresponding to each stage of network attack. The evaluation tool is an automated script. Accordingly, the automated script of the elasticity evaluation tool library is called to dynamically evaluate the web application in a simulation environment to obtain a dynamic evaluation result of the web application, including: The evaluation tools corresponding to each stage are called in the order of each stage of the network attack, and the web application is dynamically evaluated in a simulation environment to obtain a dynamic evaluation result corresponding to the preset tool set of the web application.
6. The network resilience evaluation method for a web application according to any one of claims 1 to 5, characterized in that: Performing a static evaluation on the web application based on the network elasticity evaluation data to obtain a static evaluation result of the web application includes: The network resilience assessment data is analyzed based on a deep learning model and using a preset network resilience think tank to obtain a static assessment result of the web application, wherein the preset network resilience think tank includes a knowledge system of network security and network resilience.
7. A network resilience evaluation device for a web application, characterized in that: include: A data acquisition module is used to obtain network resilience evaluation data of web applications; An environment simulation module, used to construct a simulation environment corresponding to the existing network environment of the web application based on the network elasticity evaluation data, and simulate the running state of the web application in the existing network environment in the simulation environment; A dynamic evaluation module, used to dynamically evaluate the web application in the simulation environment to obtain a dynamic evaluation result of the web application; A static evaluation module, used to perform a static evaluation on the web application based on the network elasticity evaluation data to obtain a static evaluation result of the web application; The result determination module is used to determine the network elasticity evaluation result of the web application based on the static evaluation result and the dynamic evaluation result.
8. A computer program product, characterized in that The method comprises a computer program / instruction, wherein the computer program / instruction is executed by a processor to implement the network resilience assessment method of a web application as claimed in any one of claims 1 to 6.
9. An electronic device, characterized in that: comprising a memory and a processor, wherein: The memory is used to store the computer program; The processor is used to execute the computer program to implement the network resilience assessment method for a web application according to any one of claims 1 to 6.
10. A computer-readable storage medium, characterized in that: Used to store a computer program, wherein when the computer program is executed by a processor, the network resilience assessment method for a web application according to any one of claims 1 to 6 is implemented.