Network security assessment method and device, equipment and storage medium

By obtaining the security information of the target system in the network security assessment, selecting the attack payload and simulating the attack, forming a full-link attack link, solving the one-sided problem of evaluation in the existing technology and achieving a more comprehensive security assessment.

CN120165890APending Publication Date: 2025-06-17BEIJING HONGTENG INTELLIGENT TECH CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202311723853.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-14
Publication Date
2025-06-17

AI Technical Summary

Technical Problem

In network security assessment, the existing technology separates simulated attacks at the public service level and post-penetration attacks at the terminal level, and lacks a mechanism to connect simulated attacks at the two levels into a complete attack link, resulting in one-sidedness of security assessment.

Method used

By obtaining the security information of the target system, selecting the target attack payload, simulate the attack on the service layer, confirming the attack based on the attack results, and simulated attacks on the terminal layer to form the full-link simulation attack results, and finally conducting security assessment.

Benefits of technology

It realizes the connection between simulated attacks between the service layer and the terminal layer into a complete attack link, improves the effectiveness and comprehensiveness of network security assessment, and ensures that the security assessment of the target system is more accurate and comprehensive.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120165890A_ABST
    Figure CN120165890A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of information security, and discloses a network security assessment method and device, equipment and a storage medium. The method comprises the following steps: acquiring security information of a target system; selecting a target attack load according to the security information; performing simulation attack on a service layer of the target system according to the target attack load to obtain an attack result; determining a post-penetration attack according to the attack result, and performing a simulation attack on a terminal layer of the target system according to the post-penetration attack to obtain a full-link simulation attack result; and performing security assessment according to the full-link simulation attack result. According to the scheme, the attack load of the terminal level is screened according to the attack result of the simulation attack on the service layer of the target system through the target attack load, so that the simulation attacks of the two levels are joined, and a complete attack link based on south-north flow is formed; and the effect and comprehensiveness of target system security evaluation are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and in particular, to a network security assessment method, device, equipment and storage medium. Background Art

[0002] At present, when talking about network security, it is inseparable from a series of measures and practices to protect computer networks and systems from unauthorized access, data leakage, malware and other network threats. Therefore, the importance of network security is increasing day by day, because with the popularization of the Internet and the development of digitalization, the risks of network attacks and data leakage are also increasing continuously.

[0003] There is a problem with current network security evaluations on the market. The simulation attacks for public services (such as at the web level) and post - penetration (terminal level) simulation attacks are split based on security assessment scenarios, and there is no mechanism to connect the simulation attacks at these two levels, thus failing to form a complete attack link based on north - south traffic, which further leads to the one - sidedness of security assessment.

[0004] The above content is only used to assist in understanding the technical solution of the present invention, and does not represent an admission that the above content is prior art. Summary of the Invention

[0005] The main purpose of the present invention is to provide a network security assessment method, device, equipment and storage medium, aiming to solve the technical problem of incomplete network security assessment in the prior art.

[0006] To achieve the above purpose, the present invention provides a network security assessment method, and the method includes the following steps:

[0007] Obtain the security information of the target system;

[0008] Select a target attack payload according to the security information;

[0009] Perform a simulation attack on the service layer of the target system according to the target attack payload to obtain an attack result;

[0010] Determine a post - penetration attack according to the attack result, and perform a simulation attack on the terminal layer of the target system according to the post - penetration attack to obtain a full - link simulation attack result;

[0011] Perform a security assessment according to the full - link simulation attack result.

[0012] Optionally, the determining a post - penetration attack according to the attack result includes:

[0013] Analyze the attack result to obtain an attack effect;

[0014] Determine asset information based on the attack effect;

[0015] Generate a post - penetration attack based on the asset information.

[0016] Optionally, the analysis of the attack result to obtain the attack effect includes:

[0017] Analyze the attack result to determine system confidentiality and system integrity;

[0018] Determine the attack effect based on the system confidentiality and system integrity.

[0019] Optionally, the analysis of the attack result to determine system confidentiality and system integrity includes:

[0020] Determine system confidentiality and system integrity based on the log analysis result and vulnerability assessment result in the attack result.

[0021] Optionally, the generation of a post - penetration attack based on the asset information includes:

[0022] Determine the level of the obtained privilege according to the asset information;

[0023] Obtain system environment information;

[0024] Determine the attack means and attack strategy according to the obtained privilege level and system environment information;

[0025] Generate a post - penetration attack according to the attack means and attack strategy.

[0026] Optionally, the selection of the target attack payload according to the security information includes:

[0027] Match the security information with the general defect library to obtain the vulnerability type to be attacked;

[0028] Screen the attack payload according to the vulnerability type to be attacked to determine the target attack payload.

[0029] Optionally, the screening of the attack payload according to the vulnerability type to be attacked to determine the target attack payload includes:

[0030] Evaluate the vulnerability according to the vulnerability type to be attacked and the preset vulnerability scoring database to determine the multi - dimensional security evaluation of the vulnerability;

[0031] Select the target attack payload according to the multi - dimensional security evaluation.

[0032] Optionally, the screening of the attack payload according to the vulnerability type to be attacked to determine the target attack payload includes:

[0033] Analyze the vulnerability type to be attacked, and determine the attack vector, attack complexity, attack privilege requirements, and attack interaction requirements;

[0034] Select a target attack payload according to the attack vector, attack complexity, attack privilege requirements, and attack interaction requirements.

[0035] Optionally, the security assessment based on the full-link simulation attack results includes:

[0036] Determine the full-link vulnerability information, attack path, and loss assessment according to the full-link simulation attack results;

[0037] Quantitatively analyze the full-link vulnerability information and loss assessment to obtain a security score; conduct a security assessment based on the security score and the attack path.

[0038] Optionally, the security assessment based on the full-link simulation attack results includes:

[0039] Generate vulnerability repair information, access control information, and system configuration information according to the evaluation results obtained from the security assessment;

[0040] Generate network security suggestions according to the vulnerability repair information, access control information, and system configuration information.

[0041] In addition, to achieve the above object, the present invention also proposes a network security assessment device, which includes:

[0042] An acquisition module for acquiring the security information of the target system;

[0043] A processing module for selecting a target attack payload according to the security information;

[0044] The processing module is further configured to perform a first simulation attack on the service layer of the target system according to the target attack payload to obtain an attack result;

[0045] The processing module is further configured to determine a post-exploitation attack according to the attack result, and perform a simulation attack on the terminal layer of the target system according to the post-exploitation attack to obtain a full-link simulation attack result;

[0046] The processing module is further configured to perform a security assessment according to the full-link simulation attack results.

[0047] Optionally, the processing module is further configured to analyze the attack result to obtain an attack effect;

[0048] Determine asset information according to the attack effect;

[0049] Generate a post - exploitation attack based on the asset information.

[0050] Optionally, the processing module is further configured to analyze the attack result to determine system confidentiality and system integrity.

[0051] Determine the attack effect based on the system confidentiality and system integrity.

[0052] Optionally, the processing module is further configured to determine system confidentiality and system integrity according to the log analysis result and vulnerability assessment result in the attack result.

[0053] Optionally, the processing module is further configured to determine the level of the obtained permissions according to the asset information.

[0054] Obtain system environment information.

[0055] Determine the attack means and attack strategy according to the level of the obtained permissions and the system environment information.

[0056] Generate a post - exploitation attack according to the attack means and attack strategy.

[0057] Optionally, the processing module is further configured to match the security information with a common vulnerability database to obtain the types of vulnerabilities to be attacked.

[0058] Screen the attack payload according to the types of vulnerabilities to be attacked to determine the target attack payload.

[0059] Optionally, the processing module is further configured to evaluate the vulnerability according to the types of vulnerabilities to be attacked and a preset vulnerability scoring database to determine the multi - dimensional security evaluation of the vulnerability.

[0060] Select the target attack payload according to the multi - dimensional security evaluation.

[0061] Optionally, the processing module is further configured to analyze the types of vulnerabilities to be attacked to determine the attack vector, attack complexity, attack privilege requirements, and attack interaction requirements.

[0062] Select the target attack payload according to the attack vector, attack complexity, attack privilege requirements, and attack interaction requirements.

[0063] In addition, to achieve the above object, the present invention also provides a network security assessment device, which includes: a memory, a processor, and a network security assessment program stored on the memory and executable on the processor. The network security assessment program is configured to implement the steps of the network security assessment method as described above.

[0064] In addition, to achieve the above object, the present invention further provides a storage medium, on which a network security assessment program is stored. When the network security assessment program is executed by a processor, the steps of the network security assessment method described above are implemented.

[0065] The present invention obtains the security information of the target system; selects a target attack payload according to the security information; performs a simulated attack on the service layer of the target system according to the target attack payload to obtain an attack result; determines a post-exploitation attack according to the attack result, and performs a simulated attack on the terminal layer of the target system according to the post-exploitation attack to obtain a full-link simulated attack result; and performs a security assessment according to the full-link simulated attack result. Through the above solution, the attack result of the simulated attack on the service layer of the target system by the target attack payload is used to screen the attack payloads at the terminal level, so as to connect the simulated attacks at the two levels, thereby forming a complete attack link based on north-south traffic, improving the effect and comprehensiveness of the security assessment of the target system. BRIEF DESCRIPTION OF THE DRAWINGS

[0066] Figure 1 is a schematic structural diagram of a network security assessment device in a hardware operating environment related to the solution of an embodiment of the present invention;

[0067] Figure 2 is a schematic flowchart of a first embodiment of the network security assessment method of the present invention;

[0068] Figure 3 is a schematic flowchart of a second embodiment of the network security assessment method of the present invention;

[0069] Figure 4 is a schematic block diagram of a first embodiment of the network security assessment device of the present invention.

[0070] The implementation, functional features and advantages of the object of the present invention will be further described with reference to the embodiments and the accompanying drawings. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0071] It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.

[0072] Referring to Figure 1 , Figure 1 is a schematic structural diagram of a network security assessment device in a hardware operating environment related to the solution of an embodiment of the present invention.

[0073] As Figure 1As shown in the figure, the network security assessment device may include: a processor 1001, such as a Central Processing Unit (CPU), a communication bus 1002, a user interface 1003, a network interface 1004, and a memory 1005. Among them, the communication bus 1002 is used to realize the connection and communication between these components. The user interface 1003 may include a display screen and an input unit such as a keyboard. Optionally, the user interface 1003 may further include a standard wired interface and a wireless interface. The network interface 1004 may optionally include a standard wired interface and a wireless interface (such as a Wireless-Fidelity (Wi-Fi) interface). The memory 1005 may be a high-speed Random Access Memory (RAM) or a stable Non-Volatile Memory (NVM), such as a disk memory. Optionally, the memory 1005 may also be a storage device independent of the aforementioned processor 1001.

[0074] Those skilled in the art can understand that Figure 1 the structure shown in does not constitute a limitation on the network security assessment device, and it may include more or fewer components than shown in the figure, or combine certain components, or have different component arrangements.

[0075] As Figure 1 shown, the memory 1005, as a storage medium, may include an operating system, a network communication module, a user interface module, and a network security assessment program.

[0076] In Figure 1 the network security assessment device shown, the network interface 1004 is mainly used for data communication with a network server; the user interface 1003 is mainly used for data interaction with a user; the processor 1001 and the memory 1005 in the network security assessment device of the present invention may be arranged in the network security assessment device. The network security assessment device calls the network security assessment program stored in the memory 1005 through the processor 1001 and executes the network security assessment method provided by the embodiments of the present invention.

[0077] The embodiments of the present invention provide a network security assessment method. Referring to Figure 2 , Figure 2 it is a schematic flowchart of the first embodiment of a network security assessment method of the present invention.

[0078] In this embodiment, the network security assessment method includes the following steps:

[0079] Step S10: Obtain the security information of the target system.

[0080] It should be noted that the execution subject of this embodiment is an intelligent terminal, which can be a server, a computer, or other devices with the same or similar functions as the server. This embodiment does not limit this, and only takes the server as an example for illustration.

[0081] It can be understood that this embodiment is applied to the process of security assessment of the target system. Since the target system includes a service layer (such as web, application, front-end service, and communication program, etc.) and a terminal layer (operating system, underlying system, etc.), and there is currently a problem in the network security system that the simulation attacks for public services (such as web level) and post-penetration (terminal level) are split based on the security assessment scenario, and there is no mechanism to connect the simulation attacks at the two levels, thus forming a complete attack link based on north-south traffic. This results in inconsistent and incomplete evaluation results, affecting the comprehensiveness of user security evaluation. For example: in an attack, the attack effect of the attack payload corresponding to a certain level may be very good, but after obtaining certain resources, it may not necessarily be very effective in exploiting the vulnerabilities at the terminal level, which easily causes the neglect or misjudgment of security problems at the terminal level, leading to deviations in the test results and the neglect of real threats. Therefore, this embodiment proposes that after an attack is carried out at the service level or the service layer, the subsequent penetration process is guided according to the attack results to form an attack at the terminal level, forming a complete attack link for security assessment. The specific method can be, for example: in the simulation attack for public services (such as web level), select the simulation attack payload of the appropriate vulnerability based on CVE (Common Vulnerabilities and Exposures) general defect and disclosure enumeration and CVSS (Common Vulnerability Scoring System) version 3.0 of the general defect scoring system, and determine the subsequent post-penetration (terminal level) simulation attack according to the CVSS metadata of the vulnerability and the execution result of the simulation attack payload.

[0082] It should be noted that the security information is the relevant information of the client system, which includes the basic information of the target system, service architecture, vulnerability information, etc. Obtaining the vulnerability information of the system is an important prerequisite for conducting simulated attack tests, which is generally provided by the user. Specifically, it can be detected through vulnerability scanning tools. For example, automated vulnerability scanning tools such as Nessus and OpenVAS can be used to scan the target system. These tools can detect known vulnerabilities in the system and provide detailed vulnerability reports. Or, based on the results of previous penetration tests and security assessments, determine the information of previous penetration test or security assessment projects. It should be noted that obtaining the vulnerability information of the system is for legitimate simulated attacks and security tests and will not cause damage to the target system.

[0083] Step S20: Select a target attack payload according to the security information.

[0084] It should be noted that different service architectures may be suitable for different attack payloads. Therefore, according to aspects such as the components, communication protocols, and data transmission methods involved in the service architecture of the system, these factors will affect the selection and effectiveness of the attack payload.

[0085] On the other hand, the vulnerability information in the security information is a more direct factor for attack payload matching. This is because the vulnerability information has an important impact on the selection and construction of the attack payload. The vulnerability information provides a detailed description of the known security vulnerabilities in the system, including the vulnerability type, location, scope of influence, and possible attack methods. According to the vulnerability information, the attacker can select an appropriate attack payload and construct an attack targeting a specific vulnerability.

[0086] In some embodiments, match the security information with a common defect library to obtain the type of vulnerability to be attacked; screen the attack payload according to the type of vulnerability to be attacked to determine the target attack payload.

[0087] It can be understood that the common defect library can be: CVE (Common Vulnerabilities and Exposures) common defect and disclosure enumeration or other vulnerability providers. By searching the common defect library in various dimensions of the security information, determine the attack payload that conforms to the current security information and complete the confirmation of the target attack payload.

[0088] In some embodiments, analyze the security information to determine the attack vector, attack complexity, attack privilege requirements, and attack interaction requirements; select the target attack payload according to the attack vector, attack complexity, attack privilege requirements, and attack interaction requirements.

[0089] It should be noted that determining the attack vector, attack complexity, attack privilege requirements, and attack interaction requirements presents the most important several analysis dimensions in this embodiment. Through the above analysis dimensions, the attack payload requirements can be determined more accurately, and based on the above content, the corresponding attack payload can be found to conduct an effective service layer attack.

[0090] In specific implementation, attack vector: According to the vulnerability description and the system architecture, analyze the possible attack vectors. An attack vector refers to the path or method by which an attacker uses a vulnerability to enter the system or execute an attack. By analyzing the attack vector, the possible attack paths and entry points that the attacker may use can be determined. Attack complexity: According to the vulnerability description and the attack vector, evaluate the complexity of the attack. The complexity depends on the technical knowledge, tools, and resources that the attacker needs to possess. A more complex attack may require advanced technology and professional knowledge, while a simple attack may only require basic skills and common tools. Attack privilege requirements: Analyze the vulnerability description and the system's permission control mechanism to determine the permission level required by the attacker when exploiting the vulnerability. Attack privilege requirements involve the system access permissions and privilege levels that the attacker needs to possess. This helps to determine the permissions that the attacker may need to obtain and the difficulty of providing the attack. Attack interaction requirements: Analyze the vulnerability description and the attack vector to determine the interaction requirements between the attacker and the target system. This includes the communication and interaction methods between the attacker and the target system, such as network connection, protocol interaction, user interaction, etc. Understanding the attack interaction requirements helps to determine the interaction method between the attacker and the target system and the possible attack paths.

[0091] In some embodiments, the vulnerability is evaluated according to the type of the vulnerability to be attacked and a preset vulnerability scoring database to determine the multi-dimensional security evaluation of the vulnerability; and a target attack payload is selected according to the multi-dimensional security evaluation.

[0092] It should be noted that this embodiment proposes another preferred attack payload determination scheme. For example, in a simulation attack on public services (such as at the web level), a simulation attack payload for a suitable vulnerability is selected based on the Common Vulnerabilities and Exposures (CVE) and the 3.0 version of the Common Vulnerability Scoring System (CVSS). Subsequently, a post-exploitation (terminal level) simulation attack is determined based on the CVSS metadata of the vulnerability and the execution results of the simulation attack payload. The CVSS metadata mainly consists of the following elements: AV: Attack Vector, Network / Local; AC: Attack Complexity, High (conditions required) / Low (no conditions required); PR: Privileges Required before the attack, None / Low user / High (high privileges); UI: User Interaction, None (no user interaction required) / R (user interaction required); C: Confidentiality, degree of leakage of system sensitive data after a successful attack, High / Low / None; I: Integrity, degree of damage to the system integrity after a successful attack, High / Low / None. By matching the type of vulnerability to be attacked with the CVSS metadata of the current attack payload, the screening of the attack payload is completed, and a suitable attack payload is selected as the target attack payload for the attack. The CVSS references more dimensions, making the determination process more comprehensive and accurate compared to simply determining based on the attack vector, attack complexity, attack privilege requirements, and attack interaction requirements. However, the cost is higher at the same time.

[0093] It can be understood that the preset vulnerability scoring database can be the Common Vulnerability Scoring System (CVSS), which evaluates the types of attack vulnerabilities from multiple dimensions to obtain CVSS metadata and matches it with the corresponding attack payload to determine the target attack payload.

[0094] It should be noted that the following preferred method is proposed in this embodiment to illustrate the matching process of the target attack payload. For example, taking the Microsoft Exchange service remote code execution vulnerability CVE-2021-26855 as an example, the CVSS metadata description is as follows: CVE-2021-26855 is attacked through the network, and the attack difficulty is low. It does not require any permissions to the system or the current application, and does not require user interaction, which can cause serious damage to the integrity and confidentiality sensitivity of the target system. The first step of the present invention will be based on the current simulated attack asset: Exchange Server, that is, the current attack asset information is described as follows: Asset information: Exchange Server (set to run as a high-privilege user). Select the attack payload of the appropriate vulnerability. Based on the CVSS metadata of all publicly disclosed vulnerabilities, refer to the following screening strategy: Vulnerability information: AV(Network), AC(Low), PR(None), UI(None). Match the vulnerability information with the attack payload to determine the attack payload, which means AV(Network): indicating that the attack payload can be propagated and exploited through the network. AC(Low): indicating that the attacker has low access control requirements for exploiting the vulnerability. PR(None): indicating that the attacker does not require prior privileges or authentication to exploit the vulnerability. UI(None): indicating that the attacker does not need to interact with the user interface to exploit the vulnerability. Further matching, the attack payload can be propagated and exploited through the network, so the attacker can use remote attack vectors, such as network connection, remote code execution, etc. The attacker has low access control requirements for exploiting the vulnerability, which means that the attacker may not need to have specific permissions or privilege levels to exploit the vulnerability. This may mean that the vulnerability exists in the lower-privilege components or functions of the system. The attacker does not require prior privileges or authentication to exploit the vulnerability, which means that the attacker can successfully exploit the vulnerability without any authentication or credentials. The attacker does not need to interact with the user interface to exploit the vulnerability, which means that the attack can be carried out in the background or without user intervention. Finally, the attack payload that meets the requirements is obtained.

[0095] Step S30: Perform a simulated attack on the service layer of the target system according to the target attack payload to obtain an attack result.

[0096] It should be noted that a simulated attack is performed on the service layer of the target system according to the target attack payload to obtain an attack result. Among them, the attack result mainly includes determining the severity of the vulnerability, that is, how much impact the vulnerability has caused. According to the impact caused by the vulnerability, subsequent penetration can be determined. For example: which permissions are obtained according to the vulnerability, how high the permissions are, and then the subsequent penetration strategy can be determined.

[0097] Step S40: Determine post - penetration attacks based on the attack results, and perform simulated attacks on the terminal layer of the target system according to the post - penetration attacks to obtain full - link simulated attack results.

[0098] After determining the attack results, collect detailed asset information of the target system based on the attack results, including the type and version of the operating system, installed applications, services, acquired privilege information, patches, etc. Based on the attack results, simulate attacks on the terminal layer. In this way, the simulated attacks on both the service layer and the terminal layer are completed. Moreover, the post - penetration attacks are determined according to the attack results of the service - layer attacks, forming a complete attack link. Based on this, the most threatening offensive means for the target system can be obtained, thereby comprehensively evaluating the security of the target system. This embodiment provides a comprehensive and coherent attack - link simulation, thus comprehensively evaluating and testing the security of the system under north - south traffic. This ensures that security vulnerabilities are discovered and fully evaluated as much as possible, thereby reducing the risk of the system being attacked.

[0099] Step S50: Conduct a security assessment based on the full - link simulated attack results.

[0100] Specifically, the path of the full - link simulated attack can be determined through the full - link simulated attack results for evaluation. For example: Based on the collected asset information, determine the attack link, that is, a series of attack steps and paths that an attacker may use. This includes identifying possible entry points, lateral movement paths, and attack targets to specifically specify defense strategies and means to complete the assessment.

[0101] In some embodiments, determine full - link vulnerability information, attack paths, and loss assessment based on the full - link simulated attack results; perform quantitative analysis on the full - link vulnerability information and loss assessment to obtain a security score; conduct a security assessment according to the security score and attack paths.

[0102] It should be noted that performing quantitative analysis on the full - link vulnerability information and loss assessment means quantifying the vulnerability information and the loss assessment. The specific quantification method can be carried out through a scoring method. For example: Based on the simulated attack results, evaluate the possible losses of the attack on the system. This may include data leakage, service interruption, confidential information leakage, reputation loss, etc. For each type of loss, evaluate its potential impact and the possible degree of loss caused, and score each loss to obtain the loss assessment result. The quantification of vulnerability information, such as risk assessment matrices, threat models, potential impact analysis, etc. Quantify the severity of the vulnerability, key nodes in the attack path, and loss assessment indicators, and calculate the corresponding security score.

[0103] Further, the attack path evaluation can be as follows: Determine the attack path based on the steps of the simulated attack and the attacker's behavior path. This involves how the attacker uses different vulnerabilities and weaknesses for lateral movement, privilege escalation, and achieving the attack goal. Record each step and key node in the attack path. Finally, complete the security evaluation by comprehensively considering the security score and the attack path.

[0104] In some embodiments, vulnerability repair information, access control information, and system configuration information are generated according to the evaluation results obtained from the security evaluation; network security suggestions are generated according to the vulnerability repair information, access control information, and system configuration information.

[0105] It should be noted that for a comprehensive and stable security evaluation result, a comprehensive security suggestion is also required to complete the business closed-loop. Therefore, this embodiment proposes: Provide corresponding suggestions and solutions for the customer according to the risk assessment results. This may include patching vulnerabilities (recommending corresponding security patches or update programs), strengthening access control (recommending measures such as strong password policies, multi-factor authentication, access control lists, etc.), improving system configuration (opening, restricting, or closing service ports), strengthening network security, etc. (changing firewall configurations) to mitigate risks and improve the security of the system.

[0106] This embodiment obtains the security information of the target system; selects the target attack payload according to the security information; performs a simulated attack on the service layer of the target system according to the target attack payload to obtain an attack result; determines the post-exploitation attack according to the attack result, and performs a simulated attack on the terminal layer of the target system according to the post-exploitation attack to obtain a full-link simulation attack result; performs a security evaluation according to the full-link simulation attack result. Through the above solution, the attack result of performing a simulated attack on the service layer of the target system through the target attack payload is used to screen the attack payloads at the terminal level, so as to connect the simulated attacks at the two levels, thereby forming a complete attack link based on north-south traffic, improving the effectiveness and comprehensiveness of the security evaluation of the target system.

[0107] Reference Figure 3 , Figure 3 is a schematic flowchart of the second embodiment of a network security evaluation method of the present invention.

[0108] Based on the above first embodiment, in step S40 of the network security evaluation method of this embodiment, it further includes:

[0109] Step S41: Analyze the attack result to obtain the attack effect.

[0110] It should be noted that the attack result includes the content of obtaining permissions, sensitive data, etc. According to these contents, it can be determined how effective this attack is.

[0111] In some embodiments, the attack result is analyzed to determine system confidentiality and system integrity; the attack effect is determined according to the system confidentiality and system integrity.

[0112] It should be noted that the system confidentiality may be that the Confidentiality indicator represents the degree to which sensitive data in the system may be leaked due to a vulnerability after a successful attack. Its value can be High, indicating that sensitive data may be completely leaked after a successful attack; Low, indicating that some sensitive data may be leaked; None, indicating that no sensitive data will be leaked. On the other hand, the system integrity may be that the Integrity indicator represents the degree of damage that a vulnerability may cause to the integrity of the system after a successful attack. Its value can be High, indicating that the integrity of the system may be completely damaged after a successful attack; Low, indicating that the integrity of the system may be damaged to a certain extent; None, indicating that the integrity of the system will not be damaged.

[0113] It can be understood that in this embodiment, the attack effect is evaluated through the two dimensions of system confidentiality and system integrity because these two indicators reflect the degree of impact of the attack on the system. Since the confidentiality of the system refers to the degree of protection of sensitive information in the system. After a successful attack, the attacker may obtain sensitive data in the system, such as user passwords, personal identity information, business secrets, etc. To evaluate the impact of the attack on system confidentiality, it can be measured according to the type and quantity of sensitive information that the attacker can obtain. If the attack can cause a large amount of sensitive data to be leaked, then the attack effect will be evaluated as serious. Similarly, the integrity of the system refers to the integrity and accuracy of the data and functions in the system. After a successful attack, the attacker may tamper with, delete, or damage the data in the system, or damage the functions of the system. To evaluate the impact of the attack on system integrity, factors such as the degree of tampering with system data by the attacker, the degree of data loss, and the degree of damage to system functions can be considered. If the attack causes the data to be completely tampered with or lost, or the system cannot run normally, then the attack effect will be evaluated as serious. By evaluating the impact of the attack on system confidentiality and integrity, the effect and potential losses of the attack can be more comprehensively understood.

[0114] In some embodiments, system confidentiality and system integrity are determined according to the log analysis result and vulnerability assessment result in the attack result.

[0115] It should be noted that since evaluating the user's target system is a full-link evaluation process with a very large amount of data, a comprehensive analysis will be extremely costly and time-consuming. Therefore, this example proposes to complete the system confidentiality and system integrity analysis relatively quickly through the log analysis results and vulnerability assessment results. This is because logs are very easy to obtain and can intuitively determine the changes in the system during the simulated attack. For example, by analyzing the system logs generated during the attack, it is possible to determine the actions and operations of the attacker on the system. If the logs show that the attacker has successfully accessed sensitive data or performed unauthorized operations, then the confidentiality of the system may be threatened. If the logs show that the attacker has tampered with data or damaged the system function, then the integrity of the system may be threatened. And evaluating through the vulnerability assessment results is the most intuitive indicator: by conducting a vulnerability assessment on the system, it is possible to determine the security vulnerabilities and weaknesses existing in the system. If the vulnerability assessment results show that the system has multiple high-risk vulnerabilities, then the confidentiality and integrity of the system may be greatly threatened. The severity of the vulnerabilities and the possible ways of exploitation will also affect the assessment of confidentiality and integrity. Therefore, combining the log analysis and vulnerability assessment results, consider the potential impact of the attack and the possible losses. For example, if the attacker successfully obtains a database containing sensitive customer information and there are multiple vulnerabilities in the system that can be exploited by the attacker, then the degree of threat to the confidentiality and integrity of the system may be higher. Through the log analysis results and vulnerability assessment results, both the actual threats and potential threats caused by the simulated attack can be evaluated, improving the comprehensiveness of the system confidentiality and system integrity assessment, enhancing efficiency while avoiding omissions.

[0116] Step S42: Determine the asset information according to the attack effect.

[0117] It can be understood that asset information is generally represented by an asset inventory. After determining the attack effect, the results obtained from the attack or the possible results can be collected in the form of an asset list, which may include understanding the network topology, reviewing system configuration files, identifying running applications and services, etc. By collecting this information, an accurate asset inventory can be established and the specific configuration and running status of each asset can be understood.

[0118] Specifically, the asset information can be the permissions and sensitive information of a specific system or application, i.e., Exchange Server. In this example, Exchange Server is set to run with ordinary user permissions. Asset information is usually used to describe specific entities in a system, application, or network to better understand and evaluate security threats and risks. In this case, Exchange Server is the asset under consideration, and the assessment of its security and vulnerabilities will be based on the specific configuration and operating environment of this asset.

[0119] Step S43: Generate a post-exploitation attack based on the asset information.

[0120] It should be noted that the asset information also tells the user what permissions have been obtained currently and what sensitive information can be accessed. According to the level and type of permissions, different attack methods and payloads can be determined. For example, if it is determined from the asset information that ordinary user permissions have been obtained, the attack path can be determined, and the attacker can use different vulnerabilities and weaknesses for lateral movement, privilege escalation, and achieving the attack goal to implement the post-exploitation attack.

[0121] In some embodiments, determine the level of permissions obtained according to the asset information; obtain system environment information; determine the attack means and attack strategy according to the level of permissions obtained and the system environment information; generate a post-exploitation attack according to the attack means and attack strategy.

[0122] It should be noted that planning post - penetration attacks based on the privilege levels in asset information is a very straightforward approach. Because privileges directly determine the available space for attack paths. Take the front - end attack target "Exchange Server" as an example: According to the results of simulated intrusion, determine the post - penetration plan on the subsequent terminal. If the simulated attack with the selected vulnerability payload is successful, that is, the attack is not blocked by security devices, then according to the following CVSS screening strategy, determine what privileges have been obtained: Vulnerability information: C(High), I(High). If the vulnerability metadata of the successful attack satisfies both C and I being High, it is considered that the current simulated attack has obtained the same high - privilege user capabilities as Exchange Server. Then, subsequent attacks can conduct corresponding post - penetration simulated attacks based on the high - privilege user, such as dumping user credentials from the LSASS process memory as a high - privilege user (T1003.001). If Exchange Server in the asset information is set to run as an ordinary user, then when the vulnerability metadata of the successful attack satisfies both C and I being High, it is also considered that the current simulated attack has obtained the same ordinary - user capabilities as Exchange Server. Subsequent attacks can conduct corresponding post - penetration simulated attacks based on the ordinary user, such as first simulating bypassing Windows UAC (T1548.002) to elevate the current user's privilege from an ordinary user to a high - privilege user. Only after success can one continue to dump user credentials from the LSASS process memory as a high - privilege user (T1003.001). It can be seen that under different asset information scenarios, choosing different attack paths can achieve better attack effects.

[0123] In this embodiment, the attack results are analyzed to obtain the attack effects; the asset information is determined according to the attack effects; and post - penetration attacks are generated according to the asset information. Through the above - mentioned method, the evaluation of the first - attack results is completed, and post - penetration attacks are determined based on the asset information, ensuring that after the service - layer attack is completed, the selection of secondary attacks is made according to the asset information obtained from the attack, making the entire attack link complete and further improving the comprehensiveness and efficiency of security evaluation.

[0124] In addition, an embodiment of the present invention also proposes a storage medium, on which a network security assessment program is stored. When the network security assessment program is executed by a processor, it implements the steps of the network security assessment method as described above.

[0125] Refer to Figure 4 , Figure 4 which is the structural block diagram of the first embodiment of the network security assessment device of the present invention.

[0126] As Figure 4 shown, the network security assessment device proposed by the embodiment of the present invention includes:

[0127] An acquisition module 10 for acquiring security information of a target system;

[0128] A processing module 20 for selecting a target attack payload according to the security information;

[0129] The processing module 20 is further configured to perform a first simulated attack on the service layer of the target system according to the target attack payload to obtain an attack result;

[0130] The processing module 20 is further configured to determine a post-exploitation attack according to the attack result, and perform a simulated attack on the terminal layer of the target system according to the post-exploitation attack to obtain a full-link simulated attack result;

[0131] The processing module 20 is further configured to perform a security assessment according to the full-link simulated attack result.

[0132] It should be understood that the above is only an example and does not constitute any limitation to the technical solution of the present invention. In specific applications, those skilled in the art can set according to needs, and the present invention does not limit this.

[0133] In this embodiment, the acquisition module 10 acquires the security information of the target system; the processing module 20 selects a target attack payload according to the security information; the processing module 20 performs a simulated attack on the service layer of the target system according to the target attack payload to obtain an attack result; the processing module 20 determines a post-exploitation attack according to the attack result, and performs a simulated attack on the terminal layer of the target system according to the post-exploitation attack to obtain a full-link simulated attack result; the processing module 20 performs a security assessment according to the full-link simulated attack result. Through the above solution, the attack result of the simulated attack on the service layer of the target system by the target attack payload is realized, and the attack payload at the terminal level is screened, so as to connect the simulated attacks at the two levels, thereby forming a complete attack link based on north-south traffic, improving the effect and comprehensiveness of the security assessment of the target system.

[0134] In some embodiments, the processing module 20 is further configured to analyze the attack result to obtain an attack effect;

[0135] Determine asset information according to the attack effect;

[0136] Generate a post-exploitation attack according to the asset information.

[0137] In some embodiments, the processing module 20 is further configured to analyze the attack result to determine system confidentiality and system integrity;

[0138] Determine the attack effect according to the system confidentiality and system integrity.

[0139] In some embodiments, the processing module 20 is further configured to determine the system confidentiality and system integrity according to the log analysis result and vulnerability assessment result in the attack result.

[0140] In some embodiments, the processing module 20 is further configured to determine the level of acquired permissions according to the asset information;

[0141] Obtain system environment information;

[0142] Determine the attack means and attack strategy according to the level of acquired permissions and the system environment information;

[0143] Generate a post-exploitation attack according to the attack means and attack strategy.

[0144] In some embodiments, the processing module 20 is further configured to match the security information with a common defect library to obtain the types of vulnerabilities to be attacked;

[0145] Screen the attack payload according to the types of vulnerabilities to be attacked to determine the target attack payload.

[0146] In some embodiments, the processing module 20 is further configured to evaluate the vulnerabilities according to the types of vulnerabilities to be attacked and a preset vulnerability scoring database to determine the multi-dimensional security evaluation of the vulnerabilities;

[0147] Select the target attack payload according to the multi-dimensional security evaluation.

[0148] In some embodiments, the processing module 20 is further configured to analyze the types of vulnerabilities to be attacked to determine the attack vector, attack complexity, attack privilege requirements, and attack interaction requirements;

[0149] Select the target attack payload according to the attack vector, attack complexity, attack privilege requirements, and attack interaction requirements.

[0150] In some embodiments, the processing module 20 is further configured to determine the full-link vulnerability information, attack path, and loss assessment according to the full-link simulation attack result;

[0151] Quantitatively analyze the full-link vulnerability information and the loss assessment to obtain a security score; perform a security assessment according to the security score and the attack path.

[0152] In some embodiments, the processing module 20 is further configured to generate vulnerability repair information, access control information, and system configuration information according to the evaluation result obtained from the security assessment;

[0153] Generate network security suggestions based on the vulnerability repair information, access control information, and system configuration information.

[0154] It should be noted that the above-described work process is only illustrative and does not limit the protection scope of the present invention. In actual applications, those skilled in the art can select some or all of them according to actual needs to achieve the purpose of the solution of this embodiment, and no limitation is made here.

[0155] In addition, for the technical details not described in detail in this embodiment, reference can be made to the network security assessment method provided in any embodiment of the present invention, and details will not be repeated here.

[0156] In addition, it should be noted that in this article, the terms "including", "comprising", or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article, or system including a series of elements not only includes those elements, but also includes other elements not explicitly listed, or further includes elements inherent to such process, method, article, or system. Without more limitations, the element defined by the statement "including one..." does not exclude the existence of additional identical elements in the process, method, article, or system including that element.

[0157] The serial numbers of the above embodiments of the present invention are only for description and do not represent the advantages or disadvantages of the embodiments.

[0158] Through the description of the above embodiments, those skilled in the art can clearly understand that the above embodiment methods can be implemented by means of software plus a necessary general hardware platform. Of course, they can also be implemented by hardware, but in many cases, the former is a better implementation method. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. The computer software product is stored in a storage medium (such as Read Only Memory (ROM) / RAM, magnetic disk, optical disk), and includes several instructions to enable a terminal device (which can be a mobile phone, computer, server, or network device, etc.) to execute the methods described in various embodiments of the present invention.

[0159] The above are only the preferred embodiments of the present invention, and do not limit the patent scope of the present invention accordingly. Any equivalent structure or equivalent process transformation made by using the content of the specification and drawings of the present invention, or directly or indirectly applied to other related technical fields, shall be equally included in the patent protection scope of the present invention.

[0160] A1. A network security assessment method, the network security assessment method includes:

[0161] Obtain the security information of the target system;

[0162] Select a target attack payload according to the security information;

[0163] Conduct a simulated attack on the service layer of the target system according to the target attack payload to obtain an attack result;

[0164] Determine a post-exploitation attack according to the attack result, and conduct a simulated attack on the terminal layer of the target system according to the post-exploitation attack to obtain a full-link simulated attack result;

[0165] Conduct a security assessment according to the full-link simulated attack result.

[0166] A2. The method as described in A1, wherein determining the post-exploitation attack according to the attack result includes:

[0167] Analyze the attack result to obtain an attack effect;

[0168] Determine asset information according to the attack effect;

[0169] Generate a post-exploitation attack according to the asset information.

[0170] A3. The method as described in A2, wherein analyzing the attack result to obtain an attack effect includes:

[0171] Analyze the attack result to determine system confidentiality and system integrity;

[0172] Determine the attack effect according to the system confidentiality and system integrity.

[0173] A4. The method as described in A3, wherein analyzing the attack result to determine system confidentiality and system integrity includes:

[0174] Determine system confidentiality and system integrity according to the log analysis result and vulnerability assessment result in the attack result.

[0175] A5. The method as described in A2, wherein generating a post-exploitation attack according to the asset information includes:

[0176] Determine the level of the obtained privilege according to the asset information;

[0177] Obtain system environment information;

[0178] Determine attack means and attack strategies according to the level of the obtained privilege and the system environment information;

[0179] Generate a post-exploitation attack according to the attack means and attack strategies.

[0180] A6. The method as described in A1, where the selection of the target attack payload according to the security information includes:

[0181] Match the security information with a general vulnerability library to obtain the vulnerability types to be attacked;

[0182] Filter the attack payloads according to the vulnerability types to be attacked, and determine the target attack payload.

[0183] A7. The method as described in A6, where the filtering of the attack payloads according to the vulnerability types to be attacked and determining the target attack payload includes:

[0184] Evaluate the vulnerabilities according to the vulnerability types to be attacked and a preset vulnerability scoring database to determine the multi-dimensional security evaluation of the vulnerabilities;

[0185] Select the target attack payload according to the multi-dimensional security evaluation.

[0186] A8. The method as described in A6, where the filtering of the attack payloads according to the vulnerability types to be attacked and determining the target attack payload includes:

[0187] Analyze the vulnerability types to be attacked to determine the attack vector, attack complexity, attack privilege requirements, and attack interaction requirements;

[0188] Select the target attack payload according to the attack vector, attack complexity, attack privilege requirements, and attack interaction requirements.

[0189] A9. The method as described in A1, where the security evaluation according to the full-link simulation attack results includes:

[0190] Determine the full-link vulnerability information, attack path, and loss assessment according to the full-link simulation attack results;

[0191] Quantitatively analyze the full-link vulnerability information and loss assessment to obtain a security score; conduct a security evaluation according to the security score and the attack path.

[0192] A10. The method as described in A1, where the security evaluation according to the full-link simulation attack results includes:

[0193] Generate vulnerability repair information, access control information, and system configuration information according to the evaluation results obtained from the security evaluation;

[0194] Generate network security suggestions according to the vulnerability repair information, access control information, and system configuration information.

[0195] B11. A network security evaluation device, where the network security evaluation device includes:

[0196] An acquisition module, configured to acquire security information of a target system;

[0197] A processing module, configured to select a target attack payload according to the security information;

[0198] The processing module is further configured to perform a first simulated attack on the service layer of the target system according to the target attack payload to obtain an attack result;

[0199] The processing module is further configured to determine a post-exploitation attack according to the attack result, and perform a simulated attack on the terminal layer of the target system according to the post-exploitation attack to obtain a full-link simulated attack result;

[0200] The processing module is further configured to perform a security assessment according to the full-link simulated attack result.

[0201] B12. The device as described in B11, wherein the processing module is further configured to analyze the attack result to obtain an attack effect;

[0202] Determine asset information according to the attack effect;

[0203] Generate a post-exploitation attack according to the asset information.

[0204] B13. The device as described in B12, wherein the processing module is further configured to analyze the attack result to determine system confidentiality and system integrity;

[0205] Determine the attack effect according to the system confidentiality and system integrity.

[0206] B14. The device as described in B13, wherein the processing module is further configured to determine system confidentiality and system integrity according to the log analysis result and vulnerability assessment result in the attack result.

[0207] B15. The device as described in B12, wherein the processing module is further configured to determine the level of acquired permissions according to the asset information;

[0208] Acquire system environment information;

[0209] Determine attack means and attack strategies according to the level of acquired permissions and system environment information;

[0210] Generate a post-exploitation attack according to the attack means and attack strategies.

[0211] B16. The device as described in B11, wherein the processing module is further configured to match the security information with a general defect library to obtain a vulnerability type to be attacked;

[0212] Screen the attack payload according to the type of vulnerability to be attacked to determine the target attack payload.

[0213] B17. The device as described in B16, wherein the processing module is further configured to

[0214] Evaluate the vulnerability according to the type of vulnerability to be attacked and a preset vulnerability scoring database to determine the multi-dimensional security evaluation of the vulnerability;

[0215] Select the target attack payload according to the multi-dimensional security evaluation.

[0216] B18. The device as described in B16, wherein the processing module is further configured to analyze the type of vulnerability to be attacked to determine the attack vector, attack complexity, attack privilege requirements, and attack interaction requirements;

[0217] Select the target attack payload according to the attack vector, attack complexity, attack privilege requirements, and attack interaction requirements.

[0218] C19. A network security assessment device, the device includes: a memory, a processor, and a network security assessment program stored on the memory and executable on the processor, the network security assessment program is configured to implement the steps of the network security assessment method as described in any one of A1 to A10.

[0219] D20. A storage medium, on which a network security assessment program is stored, and when the network security assessment program is executed by a processor, it implements the steps of the network security assessment method as described in any one of A1 to A10.

Claims

1. A network security assessment method, characterized in that, The network security assessment method includes: Obtaining the security information of the target system; Selecting a target attack payload according to the security information; Performing a simulated attack on the service layer of the target system according to the target attack payload to obtain an attack result; Determining a post-exploitation attack according to the attack result, and performing a simulated attack on the terminal layer of the target system according to the post-exploitation attack to obtain a full-link simulated attack result; Performing a security assessment according to the full-link simulated attack result.

2. The method according to claim 1, characterized in that, The determining of the post-exploitation attack according to the attack result includes: Analyzing the attack result to obtain an attack effect; Determining asset information according to the attack effect; Generating a post-exploitation attack according to the asset information.

3. The method according to claim 2, characterized in that, The analyzing of the attack result to obtain an attack effect includes: Analyzing the attack result to determine system confidentiality and system integrity; Determining the attack effect according to the system confidentiality and system integrity.

4. The method according to claim 3, characterized in that, The analyzing of the attack result to determine system confidentiality and system integrity includes: Determining system confidentiality and system integrity according to the log analysis result and vulnerability assessment result in the attack result.

5. The method according to claim 2, characterized in that, The generating of the post-exploitation attack according to the asset information includes: Determining the level of the obtained privilege according to the asset information; Obtaining system environment information; Determining attack means and attack strategies according to the obtained privilege level and system environment information; Generating a post-exploitation attack according to the attack means and attack strategies.

6. The method according to claim 1, characterized in that, The selecting of the target attack payload according to the security information includes: Matching the security information with a general defect library to obtain the type of vulnerability to be attacked; Screening the attack payload according to the type of vulnerability to be attacked to determine the target attack payload.

7. The method according to claim 6, characterized in that, The screening of the attack payload according to the type of vulnerability to be attacked to determine the target attack payload includes: Evaluating the vulnerability according to the type of vulnerability to be attacked and a preset vulnerability scoring database to determine the multi-dimensional security evaluation of the vulnerability; Selecting the target attack payload according to the multi-dimensional security evaluation.

8. A network security assessment device, characterized in that, The network security assessment device includes: An obtaining module, configured to obtain the security information of the target system; A processing module, configured to select a target attack payload according to the security information; The processing module is further configured to perform a first simulated attack on the service layer of the target system according to the target attack payload to obtain an attack result; The processing module is further configured to determine a post-exploitation attack according to the attack result, and perform a simulated attack on the terminal layer of the target system according to the post-exploitation attack to obtain a full-link simulated attack result; The processing module is further configured to perform a security assessment according to the full-link simulated attack result.

9. A network security assessment device, characterized in that, The device includes: a memory, a processor, and a network security assessment program stored on the memory and executable on the processor, and the network security assessment program is configured to implement the steps of the network security assessment method according to any one of claims 1 to 7.

10. A storage medium, characterized in that, A network security assessment program is stored on a storage medium, and when the network security assessment program is executed by a processor, it implements the steps of the network security assessment method according to any one of claims 1 to 7.

Citation Information

Cited By

  • Vulnerability identification method and device for virtual terminal and nonvolatile storage medium

    CN120785609A