Network configuration benchmark checking method based on depth features

Through the network configuration benchmark verification method based on deep features, the problem of low management efficiency of traditional methods is solved, more efficient management and stronger security protection is achieved, and it is suitable for the construction and operation and maintenance of the full life cycle management and control system.

CN120110693APending Publication Date: 2025-06-06CHINA TOBACCO GUIZHOU IND
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202311659647.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-04
Publication Date
2025-06-06

AI Technical Summary

Technical Problem

The traditional process management method based on network configuration benchmark verification method has low management efficiency.

Method used

The network configuration benchmark verification method based on deep features is adopted. By obtaining the operating system type of the device to be inspected, the target operating system type is established, the backend of the device to be inspected, the description rules and feature weights of the deep features are obtained, the general and specific version script inspection folders are established, the script security assessment is performed, the security assessment report is generated, the verification log is established, and the security risks are judged.

Benefits of technology

It improves management efficiency, enhances security protection for general and specific versions of scripts, and realizes effective docking and full life cycle control of network configuration benchmark verification systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120110693A_ABST
    Figure CN120110693A_ABST
Patent Text Reader

Abstract

The invention discloses a network configuration benchmark checking method based on depth features, which comprises the following steps: acquiring an operating system type of to-be-checked equipment, and configuring a target operating system type according to the operating system type of the to-be-checked equipment; entering a background of the to-be-detected equipment based on an identifier in the target operating system type, a command prefix and a command parameter when a baseline is executed in the target operating system type; obtaining description rules about the depth features of the inspection item types and the weight of each feature; establishing a general script management check folder and a specific version script check folder; aiming at each script in the general script management check folder and the specific version script check folder, carrying out check and security assessment, and generating a security assessment report of the to-be-checked equipment; and establishing a check log by using the security assessment report of the to-be-checked device, and judging the security risk of the check log. The management efficiency can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of software engineering, and in particular to a network configuration benchmark verification method based on deep features. Background Art

[0002] At present, the business systems of some enterprises are managed in local servers, involving many different versions of operating systems, middleware, databases, etc. With the continuous development and widespread application of Internet technology, the openness and sharing of the network make them vulnerable to external attacks and destruction.

[0003] As an effective means to resist external attacks and destruction, the network configuration benchmark verification method has been used to prevent external attacks and destruction. However, the process management method based on the network configuration benchmark verification method has low management efficiency. Summary of the invention

[0004] The purpose of the present invention is to solve the problem of low management efficiency of the traditional process management method based on the network configuration benchmark verification method. The present invention provides a network configuration benchmark verification method based on deep features, which can improve management efficiency.

[0005] To solve the above technical problems, an embodiment of the present invention provides a network configuration benchmark verification method based on deep features, comprising:

[0006] Obtain the operating system type of the device to be tested, and configure the target operating system type according to the operating system type of the device to be tested;

[0007] Entering the backend of the device to be inspected based on the identifier in the target operating system type, the command prefix, and the command parameters when executing the baseline in the target operating system type;

[0008] Obtaining description rules for deep features of the inspection item type and weights of each feature, where the deep features of the inspection item type include an identifier of a target operating system type, a command prefix, and command parameters;

[0009] Establish a general script management inspection folder and a specific version script inspection folder. According to the description rules of the deep features of the inspection item type and the weights of each feature, the general script of the background of the device to be inspected is included in the general script management inspection folder, and the specific version script of the background of the device to be inspected is included in the specific version script inspection folder;

[0010] For each script in the general script management check folder and the specific version script check folder, each feature of the script is checked based on the description rules of the deep features of the inspection item type, and the script is security evaluated using the weight of each feature until all scripts in the general script management check folder and the specific version script check folder have completed security evaluation, and a security evaluation report for the device to be inspected is generated;

[0011] Use the security assessment report of the equipment to be inspected to establish a verification log and determine the security risks of the verification log.

[0012] According to another specific embodiment of the present invention, the method further includes: determining the priority of the special script according to the weight of the special script, and the special script verification probe screening the special script according to the priority of the special script.

[0013] According to another specific embodiment of the present invention, obtaining the operating system type of the device to be inspected, and configuring the target operating system type according to the operating system type of the device to be inspected, includes:

[0014] Establish work order scripts for baseline checks;

[0015] Get the operating system type of the device to be tested;

[0016] When the operating system type of the device to be inspected is a Windows operating system, the work order script of the baseline inspection is modified based on the Windows operating system to form a first inspection component to adapt to the Windows operating system;

[0017] When the operating system type of the device to be inspected is a Linux operating system, the work order script of the baseline inspection is modified based on the Linux operating system to form a second inspection component to adapt to the Linux operating system;

[0018] When the operating system type of the device to be inspected is a Unix operating system, the work order script of the baseline inspection is modified based on the Unix operating system to form a third inspection component to adapt to the Unix operating system.

[0019] According to another specific embodiment of the present invention, obtaining the operating system type of the device to be inspected, and configuring the target operating system type according to the operating system type of the device to be inspected, further includes:

[0020] Establishing a network configuration baseline verification framework, and incorporating the first inspection component, the second inspection component, and the third inspection component into the network configuration baseline verification framework;

[0021] generating a selection catalog based on the first inspection component, the second inspection component, and the third inspection component;

[0022] Receive various versions of Windows operating system, various versions of Linux operating system and various versions of Unix operating system;

[0023] The first inspection component is adapted to each version of the Windows operating system, the second inspection component is adapted to each version of the Linux operating system, and the third inspection component is adapted to each version of the Unix operating system;

[0024] A mapping relationship is formed between the selection directory and the first inspection component, the second inspection component, and the third inspection component.

[0025] According to another specific embodiment of the present invention, entering the background of the device to be inspected based on the identifier in the target operating system type, the command prefix, and the command parameters when executing the baseline in the target operating system type includes:

[0026] Establish communication with the background of the device to be inspected;

[0027] Analyze the operating system type of the background of the device to be tested;

[0028] Select the operating system that matches the operating system type of the background of the device to be inspected in the selection catalog;

[0029] Based on the matched operating system, a background identifier, command prefix and command parameter screening program of the device to be inspected is executed to obtain the background identifier, command prefix and command parameter.

[0030] According to another specific embodiment of the present invention, obtaining description rules for deep features of inspection item types and weights of each feature includes:

[0031] Based on the identifier, a first identification rule is established regarding the network device, host, storage device and database of the background of the device to be inspected;

[0032] Based on the command prefix, a second identification rule is established regarding the background intermediate device, service object and World Wide Web service system of the device to be inspected;

[0033] Based on the command parameters, a third identification rule of the backend probe system of the device to be inspected is established;

[0034] The first recognition rule, the second recognition rule and the third recognition rule are used to obtain description rules of the background deep features of the device to be inspected and the weights of each feature.

[0035] According to another specific embodiment of the present invention, a general script management inspection folder and a specific version script inspection folder are established, and according to the description rules of the deep features of the inspection item type and the weights of each feature, the general script of the background of the device to be inspected is included in the general script management inspection folder, and the specific version script of the background of the device to be inspected is included in the specific version script inspection folder. Before, the method further includes:

[0036] Using the description rule of the deep feature based on the first recognition rule, the script of the background network device, host, storage device and database of the device to be inspected performs the first scanning task;

[0037] Using the description rule of the deep feature based on the second recognition rule, the script of the background intermediate device, service object and World Wide Web service system of the device to be inspected performs the second scanning task;

[0038] Using the description rule of the deep feature based on the third recognition rule, the script of the background probe system of the device to be inspected executes the third scanning task;

[0039] A database of scripts is obtained through the first scanning task, the second scanning task and the third scanning task.

[0040] According to another specific embodiment of the present invention, a general script management inspection folder and a specific version script inspection folder are established, and according to the description rules of the deep features of the inspection item type and the weights of each feature, the general script of the background of the device to be inspected is included in the general script management inspection folder, and the specific version script of the background of the device to be inspected is included in the specific version script inspection folder. Before, the method further includes:

[0041] Select a script from the script database, the script including the command script;

[0042] Using an operating system that matches the operating system type of the background of the device to be inspected, determine whether the script matches the current operating system;

[0043] If the script matches the current operating system, the script is determined to be a generic script;

[0044] If the script does not match the current operating system, the script is determined to be a specific version script;

[0045] Returns a script in the selected script database until all scripts in the script database are selected.

[0046] According to another specific embodiment of the present invention, a general script management inspection folder and a specific version script inspection folder are established, and according to the description rules of the deep features of the inspection item type and the weights of each feature, the general script of the background of the device to be inspected is included in the general script management inspection folder, and the specific version script of the background of the device to be inspected is included in the specific version script inspection folder. Before, the method further includes:

[0047] Call select directory;

[0048] Select a specific version of the script;

[0049] Select an operating system version from the selection list;

[0050] Based on the selected operating system version, parse the specific version script to determine whether the parsing passes;

[0051] If the parsing is successful, a mapping relationship is formed between the selected operating system version and the specific version script;

[0052] If the parsing fails, it returns to selecting an operating system version in the selection directory until all operating system versions are selected;

[0053] Return to selecting a specific version script until all specific version scripts are selected.

[0054] According to another specific implementation of the present invention, a security assessment report of the device to be inspected is used to establish a verification log, and the security risk of the verification log is determined, including:

[0055] Establish daily statistics about the network devices, hosts, storage devices, databases, intermediate devices, service objects, World Wide Web service system and probe system of the background of the equipment to be inspected:

[0056] Based on the security assessment report of the device to be inspected, each network device, host, storage device, database, intermediate device, service object, World Wide Web service system and probe system project is associated with the security assessment result of the script;

[0057] Determine the security assessment score for each project based on the security assessment results of the script;

[0058] Include the safety assessment score of each project in the daily statistics table;

[0059] Include each daily statistics sheet in the audit log.

[0060] According to another specific embodiment of the present invention, using the security assessment report of the device to be inspected to establish a verification log and determine the security risk of the verification log also includes:

[0061] Select an item in the daily statistics table;

[0062] Based on the project's security assessment score and security threshold, determine whether the project's security assessment score is greater than the security threshold;

[0063] If the safety assessment score of the project is greater than the safety threshold, return to select a project in the daily statistics table until all projects are completed;

[0064] If the security assessment score of the project is greater than or equal to the security threshold, the project is judged to have security risks and returns to select a project in the daily statistics table until all projects are selected and completed.

[0065] According to a network configuration benchmark verification method based on deep features provided by the present invention, it can provide advanced system support for the construction and operation and maintenance of the full life cycle management and control system of the equipment to be inspected, and lay a good foundation for the security system of the equipment to be inspected. In addition, the method provided by the present invention has strong scalability. At the beginning of design and construction, the service capability of the system and the diversity of the system should be considered when the information scale is expanded. By receiving the operating system type of the equipment to be inspected, the target operating system type is configured according to the operating system type of the equipment to be inspected, and the network configuration benchmark verification system is connected to the equipment to be inspected, which greatly improves the management efficiency. In this process, the background of the equipment to be inspected is entered based on the identifier, command prefix and command parameters when executing the baseline in the target operating system type in the target operating system type; while obtaining the description rules of the deep features of the inspection item type and the weights of each feature, a general script management inspection folder and a specific version script inspection folder are established, and the general script and the specific version script are distinguished. The script classification of each inspection type is completed, which improves the security protection of the general script and the specific version script, and improves the management efficiency. After obtaining the security assessment report, this security assessment report is used to establish a verification log to achieve the actual effect of the verification. BRIEF DESCRIPTION OF THE DRAWINGS

[0066] Figure 1 A flowchart of a network configuration benchmark verification method based on deep features provided in one embodiment of the present application. DETAILED DESCRIPTION

[0067] The following specific embodiments illustrate the implementation of the present invention, and those skilled in the art can easily understand other advantages and effects of the present invention from the contents disclosed in this specification. Although the description of the present invention will be introduced in conjunction with the preferred embodiment, this does not mean that the features of this invention are limited to this implementation. On the contrary, the purpose of introducing the invention in conjunction with the implementation is to cover other options or modifications that may extend based on the claims of the present invention. In order to provide a deep understanding of the present invention, the following description will include many specific details. The present invention can also be implemented without using these details. In addition, in order to avoid confusion or blurring the focus of the present invention, some specific details will be omitted in the description. It should be noted that the embodiments of the present invention and the features in the embodiments can be combined with each other without conflict.

[0068] It should be noted that in this specification, similar reference numerals and letters denote similar items in the following drawings, and therefore, once an item is defined in one drawing, it does not need to be further defined and explained in the subsequent drawings.

[0069] In order to make the objectives, technical solutions and advantages of the present invention more clear, the embodiments of the present invention will be further described in detail below with reference to the accompanying drawings.

[0070] like Figure 1 As shown, Figure 1 A flowchart of a network configuration benchmark verification method based on deep features is provided in one embodiment of the present invention. In this embodiment, the network configuration benchmark verification method based on deep features includes:

[0071] Step S101: Obtain the operating system type of the device to be inspected, and configure the target operating system type according to the operating system type of the device to be inspected;

[0072] Step S102: Entering the backend of the device to be inspected based on the identifier in the target operating system type, the command prefix, and the command parameters when executing the baseline in the target operating system type;

[0073] Step S103: obtaining description rules for deep features of the inspection item type and weights of each feature, where the deep features of the inspection item type include an identifier of the target operating system type, a command prefix, and command parameters;

[0074] Step S104: establishing a general script management inspection folder and a specific version script inspection folder, and according to the description rules of the inspection item type deep features and the weights of each feature, the general script of the background of the device to be inspected is included in the general script management inspection folder, and the specific version script of the background of the device to be inspected is included in the specific version script inspection folder;

[0075] Step S105: for each script in the general script management check folder and the specific version script check folder, each feature of the script is checked based on the description rules of the deep features of the inspection item type, and the script is security evaluated using the weights of each feature until all the scripts in the general script management check folder and the specific version script check folder have completed the security evaluation, and a security evaluation report for the device to be inspected is generated;

[0076] Step S106: Using the security assessment report of the device to be inspected, establish a verification log and determine the security risk of the verification log.

[0077] The adoption of this technical solution can provide advanced system support for the construction and operation and maintenance of the full life cycle management and control system of the equipment to be inspected, and lay a good foundation for the security system of the equipment to be inspected. In addition, the method provided by the present invention has strong scalability. At the beginning of design and construction, the service capability of the system and the diversity of the system should be considered when the information scale is expanded. By receiving the operating system type of the equipment to be inspected, the target operating system type is configured according to the operating system type of the equipment to be inspected, and the network configuration benchmark verification system is connected to the equipment to be inspected, which greatly improves the management efficiency. In this process, the background of the equipment to be inspected is entered based on the identifier, command prefix and command parameters when executing the baseline in the target operating system type; while obtaining the description rules of the deep features of the inspection item type and the weights of each feature, a general script management inspection folder and a specific version script inspection folder are established, and the general script and the specific version script are distinguished. The script classification of each inspection type is completed, which improves the security protection of the general script and the specific version script, and improves the management efficiency. After obtaining the security assessment report, this security assessment report is used to establish a verification log to achieve the actual effect of the verification.

[0078] It is worth mentioning that in this embodiment, the general script is applicable to all terminals within a project or enterprise and is customized according to the baseline requirements of the industry. The specific version script is set separately according to the special industrial control system and is used for fixed-point detection.

[0079] Furthermore, in this embodiment, the network configuration benchmark verification method based on deep features also includes: determining the priority of the special script according to the weight of the special script, and the verification probe of the special script screens the special script according to the priority of the special script.

[0080] With the above technical solution, the special scripts are scripts based on different operating systems. These special scripts may be temporarily set up to perform baseline checks on very few devices that are not included in the general scripts and specific version scripts. Since special scripts have many vulnerabilities when running normally in the system environment and are more vulnerable to network attacks, special scripts based on special formats are screened to further improve protection efficiency, thereby improving management efficiency.

[0081] Specifically, in this implementation, based on the identifier in the operating system, the command prefix, and the command parameters when executing the baseline in the operating system, the background of the device to be inspected is entered, and the verification probe of the special script will screen the special script. The screening order is based on the weight ratio. The higher the weight ratio, the higher the priority.

[0082] Furthermore, in step S101, the operating system type of the device to be inspected is obtained, and the target operating system type is configured according to the operating system type of the device to be inspected, including:

[0083] Step S111: Establish a work order script for baseline inspection;

[0084] Step S112: Obtain the operating system type of the device to be inspected;

[0085] Step S113: When the operating system type of the device to be inspected is the Windows operating system, modify the work order script of the baseline inspection based on the Windows operating system to form a first inspection component to adapt to the Windows operating system;

[0086] Step S114: When the operating system type of the device to be inspected is the Linux operating system, the work order script of the baseline inspection is modified based on the Linux operating system to form a second inspection component to adapt to the Linux operating system.

[0087] Step S115: When the operating system type of the device to be inspected is a Unix operating system, the work order script of the baseline inspection is modified based on the Unix operating system to form a third inspection component to adapt to the Unix operating system.

[0088] This technical solution is used to generate inspection components, which reduces the risk of reinstalling the operating system of the device to be inspected and greatly improves management efficiency.

[0089] In step S112, the operating system types of the device to be inspected include Windows, Linux and Unix operating systems, and the type of the operating system of the device to be inspected is obtained to establish software adapted to the device to be inspected.

[0090] Currently, Windows, Linux, and Unix are the most commonly used operating systems on the market. In fact, the kernels of other operating systems on the market can basically be classified as Windows, Linux, and Unix. It is understandable that other operating systems on the market are mostly derivative models of Windows, Linux, and Unix. Therefore, Windows, Linux, and Unix can basically meet the operating system types of the devices to be tested that are exposed to the network configuration benchmark verification method based on deep features.

[0091] Furthermore, in step S101, the operating system type of the device to be inspected is obtained, and the target operating system type is configured according to the operating system type of the device to be inspected, and the following further includes:

[0092] Step S121: Establish a network configuration benchmark verification framework, and incorporate the first inspection component, the second inspection component, and the third inspection component into the network configuration benchmark verification framework;

[0093] Step S122: generating a selection catalog based on the first inspection component, the second inspection component and the third inspection component;

[0094] Step S123: receiving various versions of Windows operating systems, various versions of Linux operating systems, and various versions of Unix operating systems;

[0095] Step S124: respectively adapting the first inspection component to each version of the Windows operating system, respectively adapting the second inspection component to each version of the Linux operating system, respectively adapting the third inspection component to each version of the Unix operating system;

[0096] Step S125: forming a mapping relationship between the selected directory and the first inspection component, the second inspection component, and the third inspection component.

[0097] By adopting this technical solution, a network configuration benchmark verification framework is established and the first inspection component, the second inspection component and the third inspection component are incorporated into the network configuration benchmark verification framework to facilitate the selection of the required operating system. In addition, the network configuration benchmark verification framework includes different versions of operating systems in order to make the inspection items applicable to various different operating system versions under the same operating system type. Different versions of operating systems can improve the adaptability of the network configuration benchmark verification framework, thereby reducing the risk of reinstalling the operating system of the device to be inspected, which greatly improves management efficiency.

[0098] For example, if you want to download Windows 10 operating system, you can select the required Windows 10 operating system version in the list containing multiple Windows system types. For another example, under Linux operating system type, the configuration files that need to be checked in CentOS 6 and Ubuntu 22.04 are different.

[0099] Further, in step S102, based on the identifier in the target operating system type, the command prefix, and the command parameters in the target operating system type when executing the baseline, the backend of the device to be inspected is entered, including:

[0100] Step S211: establishing communication with the background of the device to be inspected;

[0101] Step S212: parsing the operating system type of the background of the device to be inspected;

[0102] Step S213: Select an operating system in the selection catalog that matches the operating system type of the background of the device to be inspected;

[0103] Step S214: Based on the matched operating system, execute the background identifier, command prefix and command parameter screening program of the device to be inspected to obtain the background identifier, command prefix and command parameters.

[0104] By adopting this technical solution, a method for communicating with the background of the device to be inspected is established.

[0105] In this embodiment, after establishing communication with the background of the device to be inspected, the code identifier, command prefix and command parameters of the background of the device to be inspected are screened through a screening program to formulate description rules of the deep features of the inspection item type of the device to be inspected and the weights of each feature. In addition, the script to be screened is guided by the identifier, command prefix and command parameters of the background, so that the network configuration benchmark verification is efficient and convenient. It is worth mentioning that the identifier, command prefix and command parameters of the background can be the code deep features of the background of the device to be inspected.

[0106] Furthermore, in step S103, description rules for the deep features of the inspection item type and weights of each feature are obtained, including:

[0107] Step S311: Based on the identifier, a first identification rule is established regarding the backend network device, host, storage device and database of the device to be inspected;

[0108] Step S312: establishing a second identification rule about the background intermediate device, service object and World Wide Web service system of the device to be inspected based on the command prefix;

[0109] Step S313: Based on the command parameters, a third identification rule of the backend probe system of the device to be inspected is established;

[0110] Step S314: using the first recognition rule, the second recognition rule and the third recognition rule, obtain the description rules of the background deep features of the device to be inspected and the weights of each feature.

[0111] By adopting this technical solution, the description rules of the deep features of the background of the device to be inspected and the weights of each feature can be obtained. Since different deep feature recognition rules are different, different recognition rules need to be established according to different deep features. Based on different recognition rules, the description rules of the deep features of the background of the device to be inspected and the weights of each feature are obtained, which can effectively realize the background network configuration benchmark verification of the device to be inspected.

[0112] Further, in step S104, a general script management inspection folder and a specific version script inspection folder are established, and according to the description rules of the inspection item type deep features and the weights of each feature, the general script of the background of the device to be inspected is included in the general script management inspection folder, and the specific version script of the background of the device to be inspected is included in the specific version script inspection folder, including:

[0113] Step S411: using the description rule of the deep feature based on the first recognition rule, the script of the background network device, host, storage device and database of the device to be inspected executes the first scanning task;

[0114] Step S412: using the description rule of the deep feature based on the second recognition rule, the script of the background intermediate device, service object and World Wide Web service system of the device to be inspected performs the second scanning task;

[0115] Step S413: using the description rule of the deep feature based on the third recognition rule, the script of the background probe system of the device to be inspected executes the third scanning task;

[0116] Step S414: Acquire the script database through the first scanning task, the second scanning task and the third scanning task.

[0117] By adopting this technical solution, a script database can be established. The description rules of deep features are actually generated based on the recognition rules. Therefore, when executing a scanning task, it is also necessary to describe the script according to different recognition rules. Through the description of the script, it is actually the background data of the device to be inspected for baseline inspection. The identification and replication of the script constitute a complete scanning task. Each scanning task can form a baseline verification in the background network configuration of the corresponding device to be inspected. This is conducive to ensuring the safety of the device to be inspected.

[0118] Furthermore, in step S104, a general script management inspection folder and a specific version script inspection folder are established, and according to the description rules of the inspection item type deep features and the weights of each feature, the general script of the background of the device to be inspected is included in the general script management inspection folder, and the specific version script of the background of the device to be inspected is included in the specific version script inspection folder, and the following is also included:

[0119] Step S421: calling the selection directory;

[0120] Step S422: Select a specific version script;

[0121] Step S423: Select an operating system version in the selection directory;

[0122] Step S424: based on the selected operating system version, the specific version script is parsed to determine whether the parsing is successful;

[0123] Step S425: If the analysis is successful, a mapping relationship is formed between the operating system version and the specific version script;

[0124] Step S426: If the analysis fails, return to step S423 until all operating system versions are selected;

[0125] Step S427: Return to step S422 until all specific version scripts are selected and completed.

[0126] By adopting this technical solution, the operating system version of a specific version script can be identified.

[0127] The operating system version identification of a specific version script can be realized through different operating systems, or even different versions of operating systems. The network configuration benchmark verification is realized with the operating system corresponding to the specific version script, which further improves the security protection of the specific version script and improves the management efficiency. In addition, it is conducive to improving the applicability of this method to the specific version script, improving the adaptability of this method, thereby reducing the risk of reinstalling the operating system of the device to be inspected and improving the management efficiency.

[0128] Specifically, the identification process of a specific version of the script is as follows:

[0129] Detection script step, set the detection command or script.

[0130] The script parsing step uses regular expressions to parse the detection script and returns the parsed results.

[0131] Parsing exception step, this step is the operation triggered when the logic expression is wrong, resulting in abnormal parsing results. If the default detection passes, when the parsing is abnormal, the check item returns the result of passing. If the default detection fails, when the parsing is abnormal, the check item returns the result of failing.

[0132] The judgment script step judges the successfully parsed content. Specifically, in some cases, the result of the test passing or failing after parsing may not be the desired result. In this case, it is possible to manually judge whether the result of the test passing or failing after the above parsing is correct. The judgment script should be a logical expression and support Java logical operators. The capture group function in the regular expression is supported. When used, it starts with a lowercase English letter p and the sequence number of the capture group. For example, the first capture group is p1. At the same time, the script also supports Java String class methods.

[0133] Variable definition step, when using capture groups, you can define the meaning of each capture group name (JSON format). If this is set, the corresponding content in the generated baseline inspection report will be replaced with the definition here. Specifically, for the inspection results of the equipment to be inspected, use variables to replace the inspection results.

[0134] By adopting this technical solution, when it is impossible to determine whether a script is a general script or a specific version script, it is possible to determine whether the script is a specific version script through the above-mentioned specific version script identification process.

[0135] Furthermore, in step S106, a verification log is established using the security assessment report of the device to be inspected, and the security risk of the verification log is determined, including:

[0136] Step S611: Establish a daily statistical table of network devices, hosts, storage devices, databases, intermediate devices, service objects, World Wide Web service systems and probe systems in the background of the device to be inspected;

[0137] Step S612: Based on the security assessment report of the device to be inspected, each network device, host, storage device, database, intermediate device, service object, World Wide Web service system and probe system project is associated with the security assessment result of the script;

[0138] Step S613: Determine the security assessment score of each project based on the security assessment result of the script;

[0139] Step S614: Include the safety assessment score of each project into the daily statistics table;

[0140] Step S615: Include each daily statistical table into the verification log.

[0141] Using this technical solution, a verification log is established.

[0142] The network configuration baseline check is a firewall to ensure the network security of the equipment to be inspected. This firewall has a certain periodicity, that is, a baseline check is required in each inspection cycle. Depending on the inspection cycle, there may be multiple inspection cycles in the daily statistics table. In one inspection cycle, the daily statistics table treats each network device, host, storage device, database, intermediate device, service object, World Wide Web service system and probe system as a project. After the baseline check, each project will have a security assessment score. The daily statistics table is generated according to the security assessment score corresponding to the project. The establishment of the daily statistics table is conducive to the risk control engineer to intuitively understand the security status of the equipment to be inspected.

[0143] Furthermore, in step S106, using the security assessment report of the device to be inspected, establishing a verification log, and determining the security risk of the verification log also include:

[0144] Step S621: Select an item in the daily statistics table;

[0145] Step S622: Based on the safety assessment score and the safety threshold of the project, determine whether the safety assessment score of the project is greater than the safety threshold;

[0146] Step S623: If the safety assessment score of the project is greater than the safety threshold, return to step S621 until all projects are completed;

[0147] Step S624: If the security assessment score of the project is greater than or equal to the security threshold, it is determined that the project has a security risk and returns to step S621 until all projects are selected to be completed.

[0148] With this technical solution, the safety threshold is used to determine whether the items in the daily statistics table have risks. Since the daily statistics table is periodic and there are many sub-devices to be inspected, the introduction of the safety threshold can timely detect whether the sub-devices have security risks.

[0149] According to the network configuration benchmark verification method based on deep features provided by the present invention, it can provide advanced system support for the construction and operation and maintenance of the full life cycle management and control system of the equipment to be inspected, and lay a good foundation for the security system of the equipment to be inspected. In addition, the method provided by the present invention has strong scalability. At the beginning of design and construction, the service capability of the system and the diversity of the system should be considered when the information scale is expanded. By receiving the operating system type of the equipment to be inspected, the target operating system type is configured according to the operating system type of the equipment to be inspected, and the network configuration benchmark verification system is connected to the equipment to be inspected, which greatly improves the management efficiency. In this process, the background of the equipment to be inspected is entered based on the identifier, command prefix and command parameters when executing the baseline in the target operating system type in the target operating system type; while obtaining the description rules of the deep features of the inspection item type and the weights of each feature, a general script management inspection folder and a specific version script inspection folder are established, and the general script and the specific version script are distinguished. The script classification of each inspection type is completed, which improves the security protection of the general script and the specific version script, and improves the management efficiency. After obtaining the security assessment report, this security assessment report is used to establish a verification log to achieve the actual effect of the verification.

[0150] Although the present invention has been illustrated and described with reference to certain preferred embodiments of the present invention, it should be understood by those skilled in the art that the above is a further detailed description of the present invention in conjunction with specific embodiments, and it cannot be determined that the specific implementation of the present invention is limited to these descriptions. Those skilled in the art may make various changes in form and details, including making several simple deductions or substitutions, without departing from the spirit and scope of the present invention.

Claims

1. A network configuration benchmark verification method based on deep features, It is characterized in that include: Acquire the operating system type of the device to be inspected, and configure the target operating system type according to the operating system type of the device to be inspected; Entering the backend of the device to be inspected based on the identifier in the target operating system type, the command prefix, and the command parameters when executing the baseline in the target operating system type; Acquire description rules for deep features of the inspection item type and weights of each feature, wherein the deep features of the inspection item type include an identifier of the target operating system type, a command prefix, and command parameters; Establish a general script management inspection folder and a specific version script inspection folder, and according to the description rules of the inspection item type deep features and the weights of the respective features, include the general script of the background of the device to be inspected into the general script management inspection folder, and include the specific version script of the background of the device to be inspected into the specific version script inspection folder; For each script in the general script management check folder and the specific version script check folder, each feature of the script is checked based on the description rules of the deep features of the inspection item type, and the script is security evaluated using the weights of the features until all the scripts in the general script management check folder and the specific version script check folder have completed security evaluation, and a security evaluation report for the device to be inspected is generated; Using the security assessment report of the device to be inspected, a verification log is established to determine the security risk of the verification log.

2. According to the network configuration benchmark verification method based on deep features in claim 1, It is characterized in that Also includes: The priority of the special script is determined according to the weight of the special script, and the special script checking probe screens the special script according to the priority of the special script.

3. The network configuration benchmark verification method based on deep features according to claim 2, It is characterized in that The step of obtaining the operating system type of the device to be inspected and configuring the target operating system type according to the operating system type of the device to be inspected includes: Establish work order scripts for baseline checks; Obtaining the operating system type of the device to be inspected; When the operating system type of the device to be inspected is a Windows operating system, modifying the work order script of the baseline inspection based on the Windows operating system to form a first inspection component to adapt to the Windows operating system; When the operating system type of the device to be inspected is a Linux operating system, modifying the work order script of the baseline inspection based on the Linux operating system to form a second inspection component to adapt to the Linux operating system; When the operating system type of the device to be inspected is a Unix operating system, the work order script of the baseline inspection is modified based on the Unix operating system to form a third inspection component to adapt to the Unix operating system.

4. The network configuration benchmark verification method based on deep features according to claim 3, It is characterized in that The step of obtaining the operating system type of the device to be inspected and configuring the target operating system type according to the operating system type of the device to be inspected further includes: Establishing a network configuration benchmark verification framework, and incorporating the first inspection component, the second inspection component, and the third inspection component into the network configuration benchmark verification framework; generating a selection catalog based on the first inspection component, the second inspection component, and the third inspection component; Receive various versions of Windows operating system, various versions of Linux operating system and various versions of Unix operating system; Adapting the first inspection component to each version of the Windows operating system, adapting the second inspection component to each version of the Linux operating system, and adapting the third inspection component to each version of the Unix operating system; A mapping relationship is formed between the selection directory and the first inspection component, the second inspection component, and the third inspection component.

5. The network configuration benchmark verification method based on deep features according to claim 4, It is characterized in that The step of entering the backend of the device to be inspected based on the identifier in the target operating system type, the command prefix, and the command parameters in the target operating system type when executing the baseline includes: Establishing communication with the background of the device to be inspected; Analyze the operating system type of the background of the device to be inspected; Select an operating system in the selection catalog that matches the operating system type of the background of the device to be inspected; Based on the matched operating system, a background identifier, command prefix and command parameter screening program of the device to be inspected is executed to obtain a background identifier, command prefix and command parameter.

6. The network configuration benchmark verification method based on deep features according to claim 5, It is characterized in that The obtaining of description rules for deep features of inspection item types and weights of each feature includes: Based on the identifier, establish a first identification rule about the background network device, host, storage device and database of the device to be inspected; Based on the command prefix, a second identification rule is established regarding the background intermediate device, service object and World Wide Web service system of the device to be inspected; Based on the command parameters, a third identification rule of the backend probe system of the device to be inspected is established; The first recognition rule, the second recognition rule and the third recognition rule are used to obtain description rules of the background deep features of the device to be inspected and the weights of each feature.

7. The network configuration benchmark verification method based on deep features according to claim 6, It is characterized in that Before establishing a general script management inspection folder and a specific version script inspection folder, and according to the description rules of the inspection item type deep features and the weights of the respective features, incorporating the general script of the background of the device to be inspected into the general script management inspection folder, and incorporating the specific version script of the background of the device to be inspected into the specific version script inspection folder, the method further comprises: Using the description rule of the deep feature based on the first recognition rule, the script of the background network device, host, storage device and database of the device to be inspected executes the first scanning task; Using the description rule of the deep feature based on the second recognition rule, the script of the background intermediate device, service object and World Wide Web service system of the device to be inspected performs the second scanning task; Using the description rule of the deep features based on the third recognition rule, the script of the backend probe system of the device to be inspected executes the third scanning task; A script database is acquired through the first scanning task, the second scanning task, and the third scanning task.

8. The network configuration benchmark verification method based on deep features according to claim 7, It is characterized in that Before establishing a general script management inspection folder and a specific version script inspection folder, and according to the description rules of the inspection item type deep features and the weights of the respective features, incorporating the general script of the background of the device to be inspected into the general script management inspection folder, and incorporating the specific version script of the background of the device to be inspected into the specific version script inspection folder, the method further comprises: selecting a script in a database of scripts, the script comprising a command script; Using an operating system that matches the operating system type of the background of the device to be inspected, determining whether the script matches the current operating system; If the script matches the current operating system, determining that the script is a universal script; If the script does not match the current operating system, determining that the script is a specific version script; Returning to selecting a script in the script database until all scripts in the script database are selected.

9. The network configuration benchmark verification method based on deep features according to claim 8, It is characterized in that Before establishing a general script management inspection folder and a specific version script inspection folder, and according to the description rules of the inspection item type deep features and the weights of the respective features, incorporating the general script of the background of the device to be inspected into the general script management inspection folder, and incorporating the specific version script of the background of the device to be inspected into the specific version script inspection folder, the method further comprises: calling the selection directory; Select a specific version of the script; Select an operating system version from the selection catalog; Based on the selected operating system version, the specific version script is parsed to determine whether the parsing is successful; If the analysis is successful, a mapping relationship is formed between the selected operating system version and the specific version script; If the parsing fails, returning to the step of selecting an operating system version from the selection directory until all operating system versions are selected; Return to the step of selecting a specific version script until all specific version scripts are selected.

10. The network configuration benchmark verification method based on deep features according to claim 9, It is characterized in that The method of using the security assessment report of the device to be inspected to establish a verification log and determining the security risk of the verification log includes: Establish a daily statistical table of the network devices, hosts, storage devices, databases, intermediate devices, service objects, World Wide Web service system and probe system in the background of the device to be inspected: Based on the security assessment report of the device to be inspected, each network device, host, storage device, database, intermediate device, service object, World Wide Web service system and probe system project is respectively associated with the security assessment result of the script; Determine a security assessment score for each project based on the security assessment result of the script; Include the safety assessment score of each of the items in the daily statistics table; Include each of the daily statistical sheets described in the audit log.

11. The network configuration benchmark verification method based on deep features according to claim 10, It is characterized in that The method of using the security assessment report of the device to be inspected to establish a verification log and determine the security risk of the verification log also includes: Select an item in the daily statistics table; Based on the safety assessment score and the safety threshold of the project, determining whether the safety assessment score of the project is greater than the safety threshold; If the safety assessment score of the project is greater than the safety threshold, return to select an project in the daily statistics table until all projects are selected and completed; If the security assessment score of the project is greater than or equal to the security threshold, it is determined that the project has a security risk, and the method returns to select an item in the daily statistical table until all items are selected and completed.

Citation Information

Cited By

  • Selecting periods of time for payload transmission based on detected attributes

    US12695704B2

  • Determining Operations For Device Payload Transmission Using Dynamic Manifests

    US20250321731A1