Evaluation system and method for oil-gas pipe network industrial control system
By obtaining the network traffic, logs and equipment status data of the oil and gas pipeline industrial control system, and combining OpenVAS and Metasploit frameworks for vulnerability scanning and penetration testing, the problem of lack of penetration attack simulation in the existing technology is solved, and a comprehensive security assessment and dynamic scoring of the oil and gas pipeline industrial control system is achieved, which improves the system's security and response capabilities.
Patent Information
- Application Number
- CN202510667381.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-22
- Publication Date
- 2025-07-18
AI Technical Summary
The existing safety assessment methods of industrial control systems in oil and gas pipelines lack the ability to simulate penetration attacks, making it difficult to conduct comprehensive assessment and analysis and dynamic scoring in a real environment, affecting the accuracy and reliability of safety assessment results.
The data acquisition module is used to obtain network traffic, logs and device status data, vulnerability scanning is performed using OpenVAS tool, the correlation between network data and system vulnerabilities is analyzed through the FP-growth algorithm, and a graded penetration test is carried out in combination with the Metasploit framework, a penetration test report is generated and the initial evaluation score is calculated, the target evaluation score is adjusted based on historical scores, and different evaluation levels and alarms are set.
A comprehensive safety assessment of the industrial control system of the oil and gas pipeline network has been realized, which has improved the comprehensiveness, accuracy and reliability of the assessment, and can promptly detect safety hazards and respond to them, improving the overall safety of the industrial control system.
Smart Images

Figure CN120342927A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of security assessment, and more particularly, to an oil and gas pipeline industrial control system assessment system and method. Background Art
[0002] With the rapid development of oil and gas pipelines, the information security problems faced by the industrial control information of oil and gas pipelines have become increasingly prominent, and the damage to the industrial control system of oil and gas pipelines has become increasingly severe. However, the existing security assessment methods lack the ability to simulate penetration attacks, making it difficult to simulate penetration attacks in a real environment, thus lacking a comprehensive assessment and analysis and dynamic scoring mechanism, which affects the results of the security assessment of the oil and gas pipeline industrial control system. Summary of the Invention
[0003] In view of this, this application proposes an oil and gas pipeline industrial control system assessment system and method, aiming to improve the effect of security assessment of the oil and gas pipeline industrial control system and effectively simulate the penetration attack on the oil and gas pipeline industrial control system in a real environment.
[0004] In a first aspect, this application provides an oil and gas pipeline industrial control system assessment system, including:
[0005] A data acquisition module, a vulnerability scanning module, a simulation attack module, a penetration testing module, and a security assessment module; the data acquisition module is configured to acquire network traffic data, log data, and device status data in the industrial control system of the oil and gas pipeline, and preprocess the network traffic data, log data, and device status data to obtain network data; the vulnerability scanning module is configured to acquire vulnerability data in the industrial control system; the simulation attack module is configured to determine the target to be penetrated and the penetration path to be penetrated according to the network data and the vulnerability data; the penetration testing module is configured to perform penetration testing according to the target to be penetrated, the penetration path to be penetrated, and the vulnerability data to obtain a penetration test report; the security assessment module is configured to obtain an initial assessment score according to the penetration test report, determine a target assessment score based on the initial assessment score and the historical assessment score, and obtain an assessment report according to the vulnerability data, the penetration test report, and the target assessment score.
[0006] In some embodiments, the preprocessing includes data cleaning and data standardization; the data acquisition module is specifically configured to: capture the data packets transmitted by the industrial control system using the Wireshark tool and decode and display the network traffic data, collect the log data in the industrial control system using the Datadog platform, and obtain the device status data in the industrial control system using the GE Predix platform.
[0007] In some embodiments, the vulnerability scanning module is specifically configured to: use the medium scanning method of the OpenVAS tool to scan for vulnerabilities such as SQL injection, cross-site scripting attacks, and cross-site request forgery in the Web application layer of the industrial control system, and use the deep scanning method of the OpenVAS tool to scan for vulnerabilities in the ports of the server and unencrypted communication in the industrial control system to obtain vulnerability data; the vulnerability scanning module is also configured to generate a vulnerability report based on the vulnerability data, and the vulnerability report adopts a standard output format.
[0008] In some embodiments, the simulation attack module is specifically configured to: convert network data and vulnerability data into the format of transaction data, count all transaction data and form a data set, create a root node as the starting point, use each item of the transaction data as a node to form an FP tree, and use a recursive method based on the minimum support threshold to mine all frequent item sets to generate association rules, and determine the target to be penetrated and the penetration path according to the association rules.
[0009] In some embodiments, the penetration testing module is further configured to use VMware to build a virtual penetration testing environment for simulating the industrial control system, set the virtual penetration testing environment as the target machine, and use the Metasploit penetration testing framework to perform hierarchical penetration on the target machine. Hierarchical penetration includes basic penetration, intermediate penetration, and advanced penetration; basic penetration is used to identify the open ports of the target machine, list the running services and penetrate the open ports, intermediate penetration is used to break through the network protection of the target machine using the open ports and execute remote code to obtain control of the network protection, and advanced penetration is used to perform lateral penetration and sensitive data acquisition on the network protection according to the obtained control of the network protection to obtain access rights.
[0010] In some embodiments, the penetration testing report includes first penetration data and second penetration data; the penetration testing module is specifically configured to: gradually perform penetration attacks on the target machine using basic penetration, intermediate penetration, and advanced penetration according to the target to be penetrated and the penetration path to obtain the first penetration data. The first penetration data includes penetration path success rate, penetration success rate, penetration testing time, hierarchical penetration score, and path utilization rate; gradually perform penetration attacks on the target machine using basic penetration, intermediate penetration, and advanced penetration according to the vulnerability data to obtain the second penetration data. The second penetration data includes vulnerability penetration success rate, vulnerability penetration time, hierarchical penetration score, and vulnerability utilization rate.
[0011] In some embodiments, the initial evaluation score is obtained by the following formula:
[0012]
[0013] Among them, Q represents the initial evaluation score, E represents the success rate of the penetration path, U1 represents the penetration success rate, U2 represents the vulnerability penetration success rate, K represents the hierarchical penetration score, T1 represents the penetration test time, T2 represents the vulnerability penetration time, J represents the path utilization rate, and L represents the vulnerability utilization rate.
[0014] In some embodiments, the security evaluation module is specifically configured to: compare the initial evaluation score with an evaluation score threshold to obtain a comparison result; the evaluation score threshold is determined based on historical evaluation scores; when the initial evaluation score is greater than or equal to the evaluation score threshold, determine the target evaluation score based on the initial evaluation score; when the initial evaluation score is less than the evaluation score threshold and the average value of all historical evaluation scores is greater than or equal to 2 times the initial evaluation score, determine the product value of the first preset score coefficient and the initial evaluation score as the target evaluation score; when the initial evaluation score is less than the evaluation score threshold, the average value is less than 2 times the initial evaluation score, and the average value is greater than 1.5 times the initial evaluation score, determine the product value of the second preset score coefficient and the initial evaluation score as the target evaluation score; the second preset score coefficient is less than the first preset score coefficient; when the initial evaluation score is less than the evaluation score threshold and the average value is less than or equal to 1.5 times the initial evaluation score, determine the product value of the third preset score coefficient and the initial evaluation score as the target evaluation score; the third preset score coefficient is less than the second preset score coefficient.
[0015] In some embodiments, the oil and gas pipeline industrial control system evaluation system further includes: a central management module; the central management module is configured to record the target evaluation score as N; the central management module is further configured to, when N is greater than or equal to 0.7, set it as the first evaluation level and issue a first-level alarm; the central management module is further configured to, when N is less than 0.7 and greater than or equal to 0.4, set it as the second evaluation level and issue a second-level alarm; the central management module is further configured to, when N is less than 0.4, set it as the second evaluation level and issue a third-level alarm; the emergency levels of the first-level alarm, the second-level alarm, and the third-level alarm decrease in sequence; the central management module is further configured to convert the evaluation report into a visual report and output it in a standard output format, and store the visual report.
[0016] Compared with the prior art, the beneficial effects of the present application are as follows: By using Wireshark, Datadog platform, and GE Predix platform to obtain network traffic data, log data, and device status data respectively, the comprehensiveness of the obtained data is ensured. Through vulnerability scanning with the OpenVAS tool, system vulnerabilities in the industrial control system can be deeply identified, further improving the comprehensiveness of security evaluation. By using the FP-growth algorithm to analyze the correlation between network data and system vulnerabilities, the target and path to be penetrated can be intelligently identified based on the actual situation of the data. Through the association rules generated by mining frequent itemsets, the pertinence and verisimilitude of penetration testing are improved. By using the Metasploit framework and hierarchical penetration mode, penetration attacks at different levels are simulated, ensuring the accuracy of the obtained penetration data, enhancing the reliability and scientificity of security evaluation. Different evaluation levels are set based on the target evaluation score, and corresponding alarms are issued according to the score level to ensure that security risks can be discovered and responded to in a timely manner. The security of the oil and gas pipeline network industrial control system is comprehensively evaluated, thereby improving the overall security of the industrial control system.
[0017] In a second aspect, the present application provides a method for evaluating an oil and gas pipeline network industrial control system, which is applied to an oil and gas pipeline network industrial control system evaluation system, and includes: obtaining network traffic data, log data, and device status data in the industrial control system of the oil and gas pipeline network, and preprocessing the network traffic data, log data, and device status data to obtain network data; obtaining vulnerability data in the industrial control system; determining the target and path to be penetrated according to the network data and the vulnerability data; performing penetration testing according to the target and path to be penetrated and the vulnerability data to obtain a penetration test report; obtaining an initial evaluation score according to the penetration test report, and determining a target evaluation score based on the initial evaluation score and the historical evaluation score, and obtaining an evaluation report according to the vulnerability data, the penetration test report, and the target evaluation score.
[0018] In some embodiments, the preprocessing includes data cleaning and data standardization; obtaining network traffic data, log data, and device status data in the industrial control system of the oil and gas pipeline network includes: using the Wireshark tool to capture and decode the data packets transmitted by the industrial control system to display the network traffic data, using the Datadog platform to collect the log data in the industrial control system, and using the GE Predix platform to obtain the device status data in the industrial control system.
[0019] In some embodiments, obtaining the vulnerability data in the industrial control system includes: using the medium scanning method of the OpenVAS tool to scan for vulnerabilities such as SQL injection, cross-site scripting attack, and cross-site request forgery in the Web application layer of the industrial control system, and using the deep scanning method of the OpenVAS tool to scan for vulnerabilities in the ports of the server and unencrypted communication in the industrial control system to obtain the vulnerability data;
[0020] The method further includes: generating a vulnerability report based on the vulnerability data, and the vulnerability report adopts a standard output format.
[0021] In some embodiments, determining a target to be penetrated and a penetration path according to network data and vulnerability data includes: converting the network data and vulnerability data into the format of transaction data, counting all the transaction data and forming a data set, creating a root node as the starting point, taking each item of the transaction data as a node to form an FP tree, mining all frequent item sets to generate association rules in a recursive manner based on a minimum support threshold, and determining the target to be penetrated and the penetration path according to the association rules.
[0022] In some embodiments, the method further includes: using VMware to build a virtual penetration testing environment for simulating an industrial control system, setting the virtual penetration testing environment as a target machine, and performing hierarchical penetration on the target machine using the Metasploit penetration testing framework. The hierarchical penetration includes basic penetration, intermediate penetration, and advanced penetration; the basic penetration is used to identify the open ports of the target machine, list the running services and penetrate the open ports, the intermediate penetration is used to break through the network protection of the target machine by using the open ports and execute remote code to obtain the control right of the network protection, and the advanced penetration is used to perform lateral penetration on the network protection and obtain sensitive data according to the obtained control right of the network protection to obtain access permissions.
[0023] In some embodiments, the penetration test report includes first penetration data and second penetration data; performing a penetration test according to the target to be penetrated, the penetration path, and the vulnerability data to obtain a penetration test report, including: gradually performing basic penetration, intermediate penetration, and advanced penetration on the target machine according to the target to be penetrated and the penetration path to obtain the first penetration data. The first penetration data includes the penetration path success rate, the penetration success rate, the penetration test time, the hierarchical penetration score, and the path utilization rate; gradually performing basic penetration, intermediate penetration, and advanced penetration on the target machine according to the vulnerability data to obtain the second penetration data. The second penetration data includes the vulnerability penetration success rate, the vulnerability penetration time, the hierarchical penetration score, and the vulnerability utilization rate.
[0024] In some embodiments, the initial evaluation score is obtained by the following formula:
[0025]
[0026] where Q represents the initial evaluation score, E represents the penetration path success rate, U1 represents the penetration success rate, U2 represents the vulnerability penetration success rate, K represents the hierarchical penetration score, T1 represents the penetration test time, T2 represents the vulnerability penetration time, J represents the path utilization rate, and L represents the vulnerability utilization rate.
[0027] In some embodiments, an initial evaluation score is obtained according to a penetration test report, and a target evaluation score is determined based on the initial evaluation score and historical evaluation scores, including: comparing the initial evaluation score with an evaluation score threshold to obtain a comparison result; the evaluation score threshold is determined based on historical evaluation scores; when the initial evaluation score is greater than or equal to the evaluation score threshold, the target evaluation score is determined based on the initial evaluation score; when the initial evaluation score is less than the evaluation score threshold and the average value of all historical evaluation scores is greater than or equal to 2 times the initial evaluation score, the product value of a first preset scoring coefficient and the initial evaluation score is determined as the target evaluation score; when the initial evaluation score is less than the evaluation score threshold, the average value is less than 2 times the initial evaluation score, and the average value is greater than 1.5 times the initial evaluation score, the product value of a second preset scoring coefficient and the initial evaluation score is determined as the target evaluation score; the second preset scoring coefficient is less than the first preset scoring coefficient; when the initial evaluation score is less than the evaluation score threshold and the average value is less than or equal to 1.5 times the initial evaluation score, the product value of a third preset scoring coefficient and the initial evaluation score is determined as the target evaluation score; the third preset scoring coefficient is less than the second preset scoring coefficient.
[0028] In some embodiments, the method further includes: recording the target evaluation score as N; when N is greater than or equal to 0.7, it is set to the first evaluation level and a first-level alarm is issued; when N is less than 0.7 and greater than or equal to 0.4, it is set to the second evaluation level and a second-level alarm is issued; when N is less than 0.4, it is set to the third evaluation level and a third-level alarm is issued; the urgency of the first-level alarm, the second-level alarm, and the third-level alarm decreases in sequence; the evaluation report is converted into a visual report and output in a standard output format, and the visual report is stored.
[0029] It can be understood that the above-mentioned oil and gas pipeline industrial control system evaluation system and method have the same beneficial effects, which will not be elaborated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0030] By reading the following detailed description of the preferred embodiments, various other advantages and benefits will become clear to those of ordinary skill in the art. The drawings are only for the purpose of showing the preferred embodiments and are not considered to be a limitation of the present application. Moreover, throughout the drawings, the same reference numerals are used to represent the same components. In the drawings:
[0031] Figure 1 is a functional block diagram of an oil and gas pipeline industrial control system evaluation system provided by an embodiment of the present application;
[0032] Figure 2 is a flowchart of an oil and gas pipeline industrial control system evaluation method provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0033] Exemplary embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although the exemplary embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided so that the present disclosure can be more thoroughly understood and the scope of the present disclosure can be fully conveyed to those skilled in the art. It should be noted that, without conflict, the embodiments in the present application and the features in the embodiments can be combined with each other. The present application will be described in detail below with reference to the drawings and in combination with the embodiments.
[0034] In some embodiments of the present application, referring to Figure 1 as shown, it is a functional block diagram of an industrial control system evaluation system for oil and gas pipeline networks provided by an embodiment of the present application. Figure 1 The industrial control system evaluation system for oil and gas pipeline networks in
[0035] includes: a data acquisition module, a vulnerability scanning module, a simulation attack module, a penetration testing module, and a security evaluation module.
[0036] The data acquisition module is configured to acquire network traffic data, log data, and device status data in the industrial control system of the oil and gas pipeline network, and preprocess the network traffic data, log data, and device status data to obtain network data.
[0037] The vulnerability scanning module is configured to acquire vulnerability data in the industrial control system.
[0038] The simulation attack module is configured to determine the target to be penetrated and the penetration path according to the network data and the vulnerability data.
[0039] The penetration testing module is configured to perform penetration testing according to the target to be penetrated, the penetration path, and the vulnerability data, and obtain a penetration testing report.
[0040] Specifically, the data acquisition module can be used to set an acquisition frequency in the industrial control system. The acquisition frequency is preferably once every two days, and can also be adjusted according to actual needs. For example, the data acquisition module can acquire network traffic data, log data, and device status data respectively through three different tools according to the acquisition frequency. By acquiring different types of data from multiple dimensions, the accuracy and reliability of the industrial control information security evaluation are improved, providing effective data support for subsequent penetration testing.
[0041] For example, the vulnerability scanning module can use the OpenVAS tool to scan the industrial control system for vulnerabilities, thereby identifying the vulnerabilities in the industrial control system, such as unpatched system vulnerabilities, application vulnerabilities, and configuration errors. This provides an important basis for subsequent simulated attacks and penetration tests, ensuring the pertinence of penetration tests.
[0042] For example, the simulated attack module can determine the correlation between network data and system vulnerabilities based on the FP-growth algorithm, and then determine the target and path to be penetrated, thereby achieving accurate penetration testing and improving the scientificity and rationality of security assessments.
[0043] For example, the penetration test module can use VMware technology to establish a virtual penetration test environment, and with the help of the Metasploit penetration test framework, adopt a hierarchical penetration mode to conduct penetration tests on the industrial control system of the oil and gas pipeline network, and conduct penetration tests through the target to be penetrated, the path to be penetrated, and the vulnerability data. Based on this, the oil and gas pipeline network industrial control system evaluation system can accurately evaluate the defense capability and response speed of the industrial control system when facing real attacks, laying the foundation for the subsequent initial evaluation score.
[0044] The security assessment module can calculate the initial assessment score based on the penetration test data, and determine the target assessment score based on the initial assessment score and historical assessment scores, thereby forming a complete assessment report, which helps to assess and manage the security status of industrial control systems and provide a basis for formulating security strategies for industrial control systems.
[0045] It is understandable that the oil and gas pipeline network industrial control system evaluation system can comprehensively evaluate the security status of the industrial control system through the collaborative work of multiple modules, from data collection, vulnerability scanning, simulated attacks to penetration testing. By analyzing multiple data, the limitations of a single evaluation are avoided, ensuring a comprehensive evaluation of the industrial control system. The initial evaluation score is generated through penetration testing, and the final target evaluation score is determined in combination with the historical evaluation score, which can accurately reflect the security performance of the industrial control system. Through dynamic evaluation methods, the security evaluation system can timely adjust the evaluation standards and strategies in the ever-changing industrial control system, ensure the accuracy and timeliness of the evaluation results, and provide a scientific basis for the optimization of the industrial control system.
[0046] In some embodiments of the present application, the above-mentioned preprocessing may include data cleaning and data standardization. The data acquisition module may use a first tool to acquire network flow data, a second tool to acquire log data, and a third tool to acquire device status data, and preprocess the network flow data, log data, and device status data to obtain network data. The first tool, the second tool, and the third tool are the Wireshark tool, the Datadog platform, and the GE Predix platform, respectively.
[0047] For example, the data acquisition module can use the Wireshark tool to capture the data packets transmitted by the industrial control system and decode and display the network traffic data, use the Datadog platform to collect the log data in the industrial control system, use the GE Predix platform to obtain the device status data in the industrial control system, and perform data cleaning and data standardization on the network traffic data, log data, and device status data to obtain network data.
[0048] It can be understood that by using the Wireshark tool to capture and decode and analyze the network traffic data packets of the industrial control system, detailed network traffic data in the industrial control system can be collected, enhancing the ability of the evaluation system to collect multi-dimensional data. By using the Datadog platform to collect the log data in the industrial control system, it can cover the operation logs, event logs, and application log data in the industrial control system, which helps to analyze the abnormal behaviors or errors of the industrial control system. By using the GE Predix platform to collect the device status data in the industrial control system, the running status of the device can be monitored in real time. Through the collaborative work of these three, the evaluation system can comprehensively and accurately capture the data in the network, application, and device aspects of the industrial control system, laying a foundation for subsequent security analysis and evaluation.
[0049] Furthermore, the data acquisition module not only collects relevant data but also preprocesses the data. Through data cleaning, data redundancy can be removed and noise can be eliminated. Through data standardization, the data formats of different data sources can be unified, ensuring that data from different dimensions can be effectively integrated. While improving the quality of network data, the usability of network data is also enhanced.
[0050] In some embodiments of the present application, the vulnerability scanning module can use the OpenVAS tool to obtain the system vulnerabilities in the industrial control system and generate a vulnerability report. For example, the vulnerability scanning module can use the medium scanning method of the OpenVAS tool to scan for vulnerabilities such as structured query language (SQL) injection, cross-site scripting attack, and cross-site request forgery in the Web application layer of the industrial control system, and use the deep scanning method of the OpenVAS tool to scan for vulnerabilities in the ports of the server and unencrypted communication in the industrial control system, and generate a vulnerability report based on the vulnerability data obtained from the medium scanning and deep scanning. Among them, the vulnerability report can adopt the standard output format. For example, the vulnerability scanning module can fill the vulnerability data in a preset vulnerability report template to generate a vulnerability report. The vulnerability report is used to record and summarize the system vulnerabilities existing in the industrial control system and present the security status of the industrial control system.
[0051] By adopting the medium scanning mode and the deep scanning mode in the OpenVAS tool, security vulnerabilities in the industrial control system can be efficiently and accurately identified, providing comprehensive data support for the security assessment system. The medium scanning mode is used to scan for vulnerabilities in the Web application layer, such as SQL injection, cross-site scripting (XSS), and cross-site request forgery (CSRF), to prevent these vulnerabilities from being exploited by attackers to launch network attacks on the industrial control system. The deep scanning mode is used to scan for vulnerabilities in the server ports and unencrypted communications in the industrial control system, enhancing the accuracy and comprehensiveness of subsequent security assessments. By obtaining vulnerability data through medium scanning and deep scanning and generating a vulnerability report, the security assessment system can provide clear and detailed vulnerability data and present the vulnerability report in standard output formats such as PDF, Excel, and Word for subsequent analysis and processing, thereby enhancing the network security protection ability of the industrial control system.
[0052] In some embodiments of the present application, the simulated attack module can use the FP-growth algorithm to obtain the correlation results between network data and system vulnerabilities, and determine the penetration targets and penetration paths based on the network data and the correlation results. For example, the simulated attack module can convert the obtained network data and vulnerability data into the format of transaction data, count all transaction data to form a data set, create a root node, and use the root node as the starting point. Each item of the transaction data is used as a node to form a frequent pattern tree (FP) tree. Set the minimum support threshold, and use a recursive method to mine all frequent item sets to generate association rules, and determine the penetration targets and penetration paths based on the association rules.
[0053] Based on this, by converting network data and vulnerability data into transaction data format, constructing all transaction data into a data set, creating a root node and using it as the starting point, an item represents a single data element in the data set, and each item of the transaction data is converted into a node to form an FP tree. Set the minimum support threshold, and the minimum support threshold is preferably 2, and can also be adjusted according to actual needs, so as to filter out the frequently occurring and relevant item sets in the data set.
[0054] Moreover, all frequent item sets are mined recursively, which represent the network data and vulnerability data that appear simultaneously multiple times. For example, abnormal network traffic data frequently appears when the network port is 15. Association rules between the frequent item sets can be established based on the obtained frequent item sets. According to the generated association rules, the simulated attack module can obtain the target to be penetrated and the penetration path. The target to be penetrated is the target of the association rule between the frequent item sets. For example, the simulated attack module can identify a relevant vulnerability combination by analyzing the frequent item sets and association rules in the network data and vulnerability data, and use this vulnerability combination as the target to be penetrated in the penetration attack. The penetration path is the attack path obtained according to the association rules, which is beneficial to precise penetration in subsequent penetration testing and reduces the blindness in the testing process. By generating association rules and mining the penetration path, the comprehensiveness and precision of the penetration testing are ensured.
[0055] In some embodiments of the present application, the penetration testing module can use VMware to establish a virtual penetration testing environment, adopt the Metasploit penetration testing framework, and set a hierarchical penetration mode. For example, the penetration testing module can use VMware to build a virtual penetration testing environment for simulating an industrial control system, set the virtual penetration testing environment as the target machine, and use the Metasploit penetration testing framework to perform hierarchical penetration on the target machine. Hierarchical penetration includes basic penetration, intermediate penetration, and advanced penetration. Basic penetration is used to identify the open ports of the target machine, list the running services, and penetrate the open ports. Intermediate penetration is used to break through the network protection of the target machine using the open ports and execute remote code to obtain control of the network protection. Advanced penetration is used to perform lateral penetration on the network protection and obtain sensitive data based on the obtained control of the network protection, and obtain access rights.
[0056] In some embodiments of the present application, the penetration test report can include first penetration data and second penetration data. The penetration testing module can specifically perform penetration attacks on the target machine using basic penetration, intermediate penetration, and advanced penetration step by step according to the target to be penetrated and the penetration path to obtain the first penetration data. The first penetration data includes penetration path success rate, penetration success rate, penetration test time, hierarchical penetration score, and path utilization rate. The penetration testing module can perform penetration attacks on the target machine using basic penetration, intermediate penetration, and advanced penetration step by step according to the vulnerability data to obtain the second penetration data. The second penetration data includes vulnerability penetration success rate, vulnerability penetration time, hierarchical penetration score, and vulnerability utilization rate.
[0057] Based on this, by building a virtual penetration testing environment and setting the industrial control system environment as the target machine, hierarchical penetration testing is adopted from open ports to sensitive data acquisition, covering all security levels of the industrial control system. Penetration testing is carried out according to the penetration target, penetration path and system vulnerabilities. Gradual penetration is carried out for the penetration target and penetration path, starting from basic penetration to intermediate penetration and finally to advanced penetration. The hierarchical penetration testing improves the comprehensiveness and strategy of the security assessment system, and thus improves the authenticity of the penetration testing. The system vulnerabilities also gradually increase the penetration level. By simulating the process of penetration attack, the security assessment system can timely detect the vulnerabilities in the industrial control system and obtain penetration data.
[0058] Among them, the penetration path success rate represents the probability of successful penetration according to the penetration path to be penetrated, and is obtained by the ratio of the number of paths that have successfully penetrated and the total number of penetration paths to be penetrated. Similarly, the penetration success rate can be obtained by the ratio of the number of penetration targets that have successfully penetrated and the total number of penetration targets to be penetrated. Similarly, the vulnerability penetration success rate is obtained in the same way as the penetration path success rate, and will not be repeated here.
[0059] The hierarchical penetration score can be determined by the hierarchical penetration mode. The hierarchical penetration score for basic penetration is 0.6, the hierarchical penetration score for intermediate penetration is 0.8, and the hierarchical penetration score for advanced penetration is 1. The selection of the hierarchical penetration score is obtained by the highest hierarchical penetration that can be carried out. When only basic penetration can be carried out and higher-level penetration cannot break through the protection, the hierarchical penetration score is determined to be 0.6. If both basic penetration and intermediate penetration can be carried out, and advanced penetration can also be carried out, the hierarchical penetration score is determined to be 1.
[0060] The path utilization rate is obtained by the ratio of the number of penetration paths to be penetrated used during the penetration attack and the total number of penetration paths to be penetrated. Similarly for the vulnerability utilization rate, it will not be elaborated. Obtaining the penetration data provides data support for obtaining the initial assessment score subsequently.
[0061] In some embodiments of the present application, the initial assessment score is obtained by the following formula:
[0062]
[0063] Among them, Q represents the initial assessment score, E represents the penetration path success rate, U1 represents the penetration success rate, U2 represents the vulnerability penetration success rate, K represents the hierarchical penetration score, T1 represents the penetration testing time, T2 represents the vulnerability penetration time, J represents the path utilization rate, and L represents the vulnerability utilization rate.
[0064] In some embodiments of the present application, the security assessment module can specifically compare the initial assessment score with the assessment score threshold to obtain a comparison result. Among them, the assessment score threshold is determined based on historical assessment scores. The assessment score threshold can be the historical assessment score with the closest generation time to the current time among all historical assessment scores, or the median of all historical assessment scores, etc.
[0065] When the initial assessment score is greater than or equal to the assessment score threshold, the target assessment score is determined based on the initial assessment score.
[0066] When the initial assessment score is less than the assessment score threshold, the security assessment module can determine to adjust the initial assessment score.
[0067] When it is determined to adjust the initial assessment score, the security assessment module can determine the score optimization coefficient according to the mean of all historical assessment scores. For example, the first preset score coefficient, the second preset score coefficient, and the third preset score coefficient can be preset in advance.
[0068] When the mean of all historical assessment scores is greater than or equal to twice the initial assessment score, the security assessment module can use the first preset score coefficient as the score optimization coefficient of the initial assessment score.
[0069] When the mean of all historical assessment scores is less than twice the initial assessment score and greater than 1.5 times the initial assessment score, the security assessment module can use the second preset score coefficient as the score optimization coefficient of the initial assessment score.
[0070] When the mean of all historical assessment scores is less than or equal to 1.5 times the initial assessment score, the security assessment module can use the third preset score coefficient as the score optimization coefficient of the initial assessment score. The target assessment score is the product value of the initial assessment score and the score optimization coefficient. The second preset score coefficient is less than the first preset score coefficient. The third preset score coefficient is less than the second preset score coefficient.
[0071] Exemplarily, when the success rate of the penetration path is 85%, the penetration success rate is 75%, the vulnerability penetration success rate is 80%, the hierarchical penetration score is 1, the penetration test time is 2 minutes, the vulnerability penetration time is 3 minutes, the path utilization rate is 80%, and the vulnerability utilization rate is 70%, then the initial assessment score is 0.78. When the initial assessment score is less than the historical assessment score, it means that the initial assessment score deviates from the normal range and needs to be optimized. The first preset score coefficient is preferably 1.5, the second preset score coefficient is preferably 1.3, and the third preset score coefficient is preferably 1.1. The score optimization coefficient is determined according to the mean of all historical assessment scores, and the initial assessment score is dynamically optimized, improving the accuracy of the target assessment score, and thus enhancing the rigor and reliability of the security assessment system.
[0072] In some embodiments of the present application, the evaluation system for the industrial control system of the oil and gas pipeline network may further include a central management module. The central management module may define the evaluation level for the target evaluation score, issue corresponding alarms based on the evaluation level, and store the evaluation report.
[0073] For example, the central management module may record the target evaluation score as N. When N is greater than or equal to 0.7, it is set as the first evaluation level and a first-level alarm is issued. When N is less than 0.7 and greater than or equal to 0.4, it is set as the second evaluation level and a second-level alarm is issued. When N is less than 0.4, it is set as the third evaluation level and a third-level alarm is issued. Among them, the emergency levels of the first-level alarm, the second-level alarm, and the third-level alarm decrease in sequence.
[0074] Furthermore, the central management module may convert the evaluation report into a visual report and output it in a standard output format, and store the visual report.
[0075] It can be understood that the security evaluation system automatically divides the evaluation level according to the target evaluation score, realizing the evaluation and rapid response of the industrial control system. When the target evaluation score reaches or exceeds 0.7, it is determined as the first evaluation level and a first-level alarm is issued, indicating that there is a severe danger in the industrial control system. When the target evaluation score is less than 0.7 and greater than or equal to 0.4, it is determined as the second evaluation level and a second-level alarm is issued, indicating that there is a medium danger. When the target evaluation score is lower than 0.4, it is determined as the third evaluation level and a third-level alarm is issued, indicating that there is a slight danger. In this way, by defining different evaluation levels according to the target evaluation score and issuing corresponding security alarms, it is possible to quickly respond according to the evaluation results in a timely manner, thereby improving the dynamic response and adaptability of the security evaluation system.
[0076] The evaluation report integrates the vulnerability report, the penetration test report, and the target evaluation score. The vulnerability report contains vulnerability data, and the penetration test report contains the first penetration data and the second penetration data. The central management module converts the evaluation report into a visual report and uses standard output formats such as PDF, Excel, and Word to record a complete evaluation result. The visual report intuitively presents information such as system vulnerability data, penetration paths to be tested, and target evaluation scores through charts, providing a decision-making basis for formulating security policies and enhancing the adaptability and scientificity of the security evaluation system.
[0077] In summary, the beneficial effects of the present application are as follows: By obtaining network traffic data, log data, and device status data through the Wireshark, Datadog platform, and GE Predix platform respectively, the comprehensiveness of the obtained data is ensured. Through the vulnerability scanning of the OpenVAS tool, system vulnerabilities in the industrial control system can be deeply identified, further improving the comprehensiveness of security evaluation. By using the FP-growth algorithm to analyze the correlation between network data and system vulnerabilities, the target and path to be penetrated can be intelligently identified based on the actual situation of the data. Through the association rules generated by mining frequent itemsets, the pertinence and authenticity of penetration testing are improved. By using the Metasploit framework and hierarchical penetration mode, penetration attacks at different levels are simulated, ensuring the accuracy of the obtained penetration data, enhancing the reliability and scientific nature of security evaluation. Different evaluation levels are set based on the target evaluation score, and corresponding alarms are issued according to the score level to ensure that security risks can be discovered and responded to in a timely manner. The security of the oil and gas pipeline network industrial control system is comprehensively evaluated, thereby improving the overall security of the industrial control system.
[0078] In another preferred embodiment based on the above embodiments, refer to Figure 2 As shown, it is a flowchart of a method for evaluating an oil and gas pipeline network industrial control system provided by an embodiment of the present application, which is used to apply the above oil and gas pipeline network industrial control system evaluation system, and includes:
[0079] S100: Obtain network traffic data, log data, and device status data in the industrial control system of the oil and gas pipeline network, and preprocess the network traffic data, log data, and device status data to obtain network data.
[0080] S200: Obtain vulnerability data in the industrial control system.
[0081] S300: Determine the target and path to be penetrated according to the network data and vulnerability data.
[0082] S400: Conduct penetration testing according to the target to be penetrated, the path to be penetrated, and the vulnerability data, and obtain a penetration test report.
[0083] S500: Obtain an initial evaluation score according to the penetration test report, determine the target evaluation score based on the initial evaluation score and the historical evaluation score, and obtain an evaluation report according to the vulnerability data, the penetration test report, and the target evaluation score.
[0084] In some embodiments, the preprocessing includes data cleaning and data standardization. Obtain the network traffic data, log data, and device status data in the industrial control system of the oil and gas pipeline network, including: using the Wireshark tool to capture the data packets transmitted by the industrial control system and decode and display the network traffic data, using the Datadog platform to collect the log data in the industrial control system, and using the GE Predix platform to obtain the device status data in the industrial control system.
[0085] In some embodiments, obtain the vulnerability data in the industrial control system, including: using the medium scanning method of the OpenVAS tool to scan the vulnerabilities of SQL injection, cross-site scripting attack, and cross-site request forgery in the Web application layer of the industrial control system, and using the deep scanning method of the OpenVAS tool to scan the ports of the server and the vulnerabilities of unencrypted communication in the industrial control system to obtain the vulnerability data.
[0086] The method further includes: generating a vulnerability report based on the vulnerability data, and the vulnerability report adopts a standard output format.
[0087] In some embodiments, according to the network data and the vulnerability data, determine the target to be penetrated and the penetration path, including: converting the network data and the vulnerability data into the format of transaction data, counting all the transaction data and forming a data set, creating a root node as the starting point, using each item of the transaction data as a node to form an FP tree, mining all frequent item sets to generate association rules in a recursive manner based on the minimum support threshold, and determining the target to be penetrated and the penetration path according to the association rules.
[0088] In some embodiments, the method further includes: using VMware to build a virtual penetration test environment for simulating the industrial control system, setting the virtual penetration test environment as the target machine, and using the Metasploit penetration test framework to perform hierarchical penetration on the target machine. The hierarchical penetration includes basic penetration, intermediate penetration, and advanced penetration. The basic penetration is used to identify the open ports of the target machine, list the running services and penetrate the open ports. The intermediate penetration is used to break through the network protection of the target machine by using the open ports and execute remote code to obtain the control right of the network protection. The advanced penetration is used to perform lateral penetration on the network protection and obtain sensitive data according to the obtained control right of the network protection to obtain the access right.
[0089] In some embodiments, the penetration test report includes first penetration data and second penetration data. A penetration test is performed based on the target to be penetrated, the path to be penetrated, and vulnerability data, and the penetration test report is obtained, including: gradually performing basic penetration, intermediate penetration, and advanced penetration on the target machine according to the target to be penetrated and the path to be penetrated to obtain the first penetration data. The first penetration data includes the penetration path success rate, the penetration success rate, the penetration test time, the hierarchical penetration score, and the path utilization rate. Gradually performing basic penetration, intermediate penetration, and advanced penetration on the target machine according to the vulnerability data to obtain the second penetration data. The second penetration data includes the vulnerability penetration success rate, the vulnerability penetration time, the hierarchical penetration score, and the vulnerability utilization rate.
[0090] In some embodiments, the initial evaluation score is obtained by the following formula:
[0091]
[0092] Where Q represents the initial evaluation score, E represents the penetration path success rate, U1 represents the penetration success rate, U2 represents the vulnerability penetration success rate, K represents the hierarchical penetration score, T1 represents the penetration test time, T2 represents the vulnerability penetration time, J represents the path utilization rate, and L represents the vulnerability utilization rate.
[0093] In some embodiments, the initial evaluation score is obtained based on the penetration test report, and the target evaluation score is determined based on the initial evaluation score and the historical evaluation score, including: comparing the initial evaluation score with the evaluation score threshold to obtain a comparison result. The evaluation score threshold is determined based on the historical evaluation score. When the initial evaluation score is greater than or equal to the evaluation score threshold, the target evaluation score is determined based on the initial evaluation score. When the initial evaluation score is less than the evaluation score threshold and the average value of all historical evaluation scores is greater than or equal to 2 times the initial evaluation score, the product value of the first preset scoring coefficient and the initial evaluation score is determined as the target evaluation score. When the initial evaluation score is less than the evaluation score threshold, the average value is less than 2 times the initial evaluation score, and the average value is greater than 1.5 times the initial evaluation score, the product value of the second preset scoring coefficient and the initial evaluation score is determined as the target evaluation score. The second preset scoring coefficient is less than the first preset scoring coefficient. When the initial evaluation score is less than the evaluation score threshold and the average value is less than or equal to 1.5 times the initial evaluation score, the product value of the third preset scoring coefficient and the initial evaluation score is determined as the target evaluation score. The third preset scoring coefficient is less than the second preset scoring coefficient.
[0094] In some embodiments, the method further includes: recording the target evaluation score as N. When N is greater than or equal to 0.7, it is set as the first evaluation level and a first-level alarm is issued. When N is less than 0.7 and greater than or equal to 0.4, it is set as the second evaluation level and a second-level alarm is issued. When N is less than 0.4, it is set as the third evaluation level and a third-level alarm is issued. The urgency levels of the first-level alarm, the second-level alarm, and the third-level alarm decrease in sequence. The evaluation report is converted into a visual report and output in a standard output format, and the visual report is stored.
[0095] It can be understood that the specific implementation manners of the steps in the above oil and gas pipeline industrial control system evaluation method can be understood with reference to the description in the above oil and gas pipeline industrial control system evaluation system, and will not be elaborated herein.
[0096] Based on this, by obtaining network traffic data, log data, and device status data and performing preprocessing, the diversity and accuracy of the data sources for security evaluation are ensured. The OpenVAS tool is used for vulnerability scanning, and the FP-growth algorithm is used to mine the association between network data and system vulnerabilities, accurately locking the targets to be penetrated and the penetration paths to be penetrated. The pertinence and effectiveness of penetration testing are improved. A virtual penetration testing environment is established through VMware, and hierarchical penetration testing is performed in combination with the Metasploit penetration framework, ensuring the authenticity and reality of the testing process. Moreover, an initial evaluation score is obtained based on the penetration data, and the initial evaluation score is dynamically adjusted in combination with historical data, improving the accuracy of the initial evaluation score. The evaluation levels are divided and corresponding alarms are issued, improving the dynamic responsiveness of security evaluation.
[0097] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0098] The present application is described with reference to the flowcharts and / or block diagrams of the methods and systems according to the embodiments of the present application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams can be implemented by computer program instructions, and the combination of the flows and / or blocks in the flowcharts and / or block diagrams can also be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate for implementing in the process Figure 1 one process or multiple processes and / or blocks Figure 1means for the functions specified in one or more boxes.
[0099] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory produce a manufactured article including an instruction means that implements the functions specified in one Figure 1 process or multiple processes and / or boxes Figure 1 or more boxes.
[0100] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to produce a computer-implemented process, so that the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one Figure 1 process or multiple processes and / or boxes Figure 1 or more boxes.
[0101] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application and are not intended to limit them. Although the present application has been described in detail with reference to the above embodiments, those of ordinary skill in the art should understand that: modifications or equivalent replacements can still be made to the specific implementation manners of the present application, and any modification or equivalent replacement that does not depart from the spirit and scope of the present application should be covered by the protection scope of the claims of the present application.
Claims
1. An evaluation system for industrial control systems of oil and gas pipeline networks, characterized in that, Including: A data acquisition module, a vulnerability scanning module, a simulated attack module, a penetration testing module, and a security assessment module; The data acquisition module is configured to acquire network traffic data, log data, and device status data in the industrial control system of the oil and gas pipeline network, and preprocess the network traffic data, the log data, and the device status data to obtain network data; The vulnerability scanning module is configured to acquire vulnerability data in the industrial control system; The simulated attack module is configured to determine a target to be penetrated and a penetration path to be penetrated according to the network data and the vulnerability data; The penetration testing module is configured to perform penetration testing according to the target to be penetrated, the penetration path to be penetrated, and the vulnerability data, and obtain a penetration testing report; The security assessment module is configured to obtain an initial assessment score according to the penetration testing report, determine a target assessment score based on the initial assessment score and a historical assessment score, and obtain an assessment report according to the vulnerability data, the penetration testing report, and the target assessment score.
2. The evaluation system for the industrial control system of oil and gas pipeline networks according to claim 1, wherein The preprocessing includes data cleaning and data standardization; the data acquisition module is specifically configured to: Use the Wireshark tool to capture the data packets transmitted by the industrial control system and decode and display the network traffic data, use the Datadog platform to collect the log data in the industrial control system, and use the GE Predix platform to obtain the device status data in the industrial control system.
3. The oil and gas pipeline network industrial control system evaluation system according to claim 2, wherein The vulnerability scanning module is specifically configured to: use the medium scanning method of the OpenVAS tool to scan the vulnerabilities of SQL injection, cross-site scripting attack, and cross-site request forgery in the Web application layer of the industrial control system, and use the deep scanning method of the OpenVAS tool to scan the ports of the server and the vulnerabilities of unencrypted communication in the industrial control system to obtain the vulnerability data; The vulnerability scanning module is further configured to generate a vulnerability report based on the vulnerability data, and the vulnerability report adopts a standard output format.
4. The oil and gas pipeline industrial control system evaluation system according to claim 1, characterized in that, The simulated attack module is specifically configured to: Convert the network data and the vulnerability data into the format of transaction data, count all the transaction data and form a data set, create a root node as the starting point, use each item of the transaction data as a node to form an FP tree, and use a recursive method based on the minimum support threshold to mine all frequent item sets to generate association rules, and determine the target to be penetrated and the penetration path to be penetrated according to the association rules.
5. The oil and gas pipeline industrial control system evaluation system according to claim 1, characterized in that The penetration testing module is further configured to use VMware to build a virtual penetration testing environment for simulating the industrial control system, set the virtual penetration testing environment as a target machine, and perform hierarchical penetration on the target machine using the Metasploit penetration testing framework. The hierarchical penetration includes basic penetration, intermediate penetration, and advanced penetration; The basic penetration is used to identify the open ports of the target machine, list the running services and penetrate the open ports. The intermediate penetration is used to break through the network protection of the target machine by using the open ports and execute remote code to obtain the control right of the network protection. The advanced penetration is used to conduct lateral penetration and sensitive data acquisition on the network protection according to the obtained control right of the network protection to obtain access rights.
6. The oil and gas pipeline industrial control system evaluation system according to claim 5, characterized in that, The penetration test report includes first penetration data and second penetration data; the penetration test module is specifically configured as: Gradually adopt the basic penetration, the intermediate penetration and the advanced penetration to conduct a penetration attack on the target machine according to the target to be penetrated and the penetration path to obtain the first penetration data. The first penetration data includes the penetration path success rate, the penetration success rate, the penetration test time, the hierarchical penetration score and the path utilization rate. Gradually adopt the basic penetration, the intermediate penetration and the advanced penetration to conduct a penetration attack on the target machine according to the vulnerability data to obtain the second penetration data. The second penetration data includes the vulnerability penetration success rate, the vulnerability penetration time, the hierarchical penetration score and the vulnerability utilization rate.
7. The oil and gas pipeline network industrial control system evaluation system according to claim 6, wherein, The initial evaluation score is obtained by the following formula: Where Q represents the initial evaluation score, E represents the penetration path success rate, U1 represents the penetration success rate, U2 represents the vulnerability penetration success rate, K represents the hierarchical penetration score, T1 represents the penetration test time, T2 represents the vulnerability penetration time, J represents the path utilization rate, and L represents the vulnerability utilization rate.
8. The oil and gas pipeline network industrial control system evaluation system according to claim 7, characterized in that The security evaluation module is specifically configured as: Compare the initial evaluation score with the evaluation score threshold to obtain a comparison result; the evaluation score threshold is determined based on historical evaluation scores; When the initial evaluation score is greater than or equal to the evaluation score threshold, determine the target evaluation score based on the initial evaluation score; When the initial evaluation score is less than the evaluation score threshold and the average of all historical evaluation scores is greater than or equal to 2 times the initial evaluation score, determine the product value of the first preset scoring coefficient and the initial evaluation score as the target evaluation score; When the initial evaluation score is less than the evaluation score threshold, the average is less than 2 times the initial evaluation score, and the average is greater than 1.5 times the initial evaluation score, determine the product value of the second preset scoring coefficient and the initial evaluation score as the target evaluation score; the second preset scoring coefficient is less than the first preset scoring coefficient; When the initial evaluation score is less than the evaluation score threshold and the average is less than or equal to 1.5 times the initial evaluation score, determine the product value of the third preset scoring coefficient and the initial evaluation score as the target evaluation score; the third preset scoring coefficient is less than the second preset scoring coefficient.
9. The evaluation system for the industrial control system of oil and gas pipelines according to claim 1, wherein It also includes: The central management module; The central management module is configured to record the target evaluation score as N; The central management module is also configured to set the first evaluation level and issue a first-level alarm when N is greater than or equal to 0.7; The central management module is further configured to set the second evaluation level and issue a secondary alarm when N is less than 0.7 and greater than or equal to 0.4; The central management module is further configured to set the second evaluation level and issue a tertiary alarm when N is less than 0.4; the emergency levels of the primary alarm, the secondary alarm, and the tertiary alarm decrease in sequence; The central management module is further configured to convert the evaluation report into a visual report, output it in a standard output format, and store the visual report.
10. A method for evaluating an industrial control system of an oil and gas pipeline network, which is applied to the evaluation system of the industrial control system of the oil and gas pipeline network according to any one of claims 1-9, characterized in that, including: Obtain network traffic data, log data, and device status data in the industrial control system of the oil and gas pipeline network, and preprocess the network traffic data, the log data, and the device status data to obtain network data; Obtain vulnerability data in the industrial control system; Determine the target to be penetrated and the penetration path according to the network data and the vulnerability data; Conduct a penetration test according to the target to be penetrated, the penetration path, and the vulnerability data to obtain a penetration test report; Obtain an initial evaluation score according to the penetration test report, determine a target evaluation score based on the initial evaluation score and the historical evaluation score, and obtain an evaluation report according to the vulnerability data, the penetration test report, and the target evaluation score.