Analysis method for high-risk port identification and security risk measurement

By combining protocol detection and secret detection technology, combined with hidden scanning and fuzzy comprehensive evaluation methods, the risks of high-risk ports are identified and evaluated, and the problems of low accuracy and difficulty in multi-dimensional assessment in traditional technologies are solved, and dynamic and professional risk assessment of high-risk ports are achieved.

CN120378166APending Publication Date: 2025-07-25FUJIAN FUJITSU COMM SOFTWARE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510532115.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-25
Publication Date
2025-07-25

AI Technical Summary

Technical Problem

Traditional high-risk port security technology has low accuracy and is difficult to assess risks in multiple dimensions. It is difficult to find high-risk ports in complex network environments, affecting the stability of the enterprise's business.

Method used

Protocol detection and secret detection combined with concealment technology are used to perform preliminary scanning to identify port classification, behavioral status and security strategies, and risk assessment models are constructed through fuzzy comprehensive evaluation method, and three-dimensional risk values are calculated based on vulnerabilities, baselines and POC detection.

Benefits of technology

It improves the discovery rate of high-risk ports and the accuracy of risk assessment, provides multi-dimensional risk measurement, and supports enterprises to make more scientific decisions on port management strategies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120378166A_ABST
    Figure CN120378166A_ABST
Patent Text Reader

Abstract

The invention discloses a high-risk port identification and security risk measurement analysis method, which combines a port detection technology, and carries out hidden port detection by combining modes of datagram fragmentation, frequency change, protocol hidden scanning and the like with conventional scanning. Compared with a traditional scanning technology, the method is easier to discover hidden ports, bypasses a protection strategy of part of safety equipment, and improves the port discovery rate. A research and judgment model is constructed through a fuzzy comprehensive evaluation method, protocol elements, port behavior elements and security policy elements are extracted and then comprehensively researched and judged, port property dynamic research and judgment are achieved, and evaluation of high-risk ports is more dynamic and specialized. Through a risk measurement model, comprehensive analysis of security data is realized, three-dimensional risk measurement of security policy effectiveness, security protection effectiveness and port state health degree is realized, and a multi-dimensional risk measurement value is provided for risk presentation.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to an analysis method for identifying high-risk ports and measuring security risks. Background Art

[0002] With the advent of the wave of Internet digital transformation, network attack incidents occur frequently and their potential hazards are increasing. In this context, as the key entrance and exit for application communication, ports play a core role in the necessary path of data circulation, and their security has also become an indispensable part of the enterprise network security defense system. However, network port management faces multiple challenges: First, the large number of ports significantly increases the management difficulty; second, the decision-making on port opening and closing needs to comprehensively consider various factors, and the impact assessment is intricate; third, the port status is directly related to the continuity and stability of business operations. Once a problem occurs, the business impact is profound; fourth, the detection technology for port anomalies not only requires a high degree of specialization but also needs to cope with increasingly complex attack means. Traditional high-risk port security technologies use tools such as nmap and fscan to perform list scans, and after the scan is completed, they are judged by comparing with the high-risk port list, and combined with vulnerability scanning technology for detection and analysis to carry out high-risk port governance work.

[0003] Traditional high-risk port security technologies mainly focus on the scanning and detection of the alive status, combined with the comparison of port lists, and the accuracy is relatively low. In today's increasingly severe security confrontation trend, most enterprises adopt the method of avoiding conventional high-risk ports for actual business implementation, and will increase corresponding security policies for avoidance. Although the security is improved, it also increases the difficulty of discovering high-risk ports, and traditional high-risk port technologies do not achieve multi-dimensional security risk measurement, and it is difficult for decision-makers to judge the risk of ports. Summary of the Invention

[0004] The purpose of the present invention is to provide an analysis method for identifying high-risk ports and measuring security risks, which comprehensively analyzes the key security data of high-risk ports and can provide multi-dimensional risk measurement values for risk presentation.

[0005] The technical solution adopted by the present invention is:

[0006] An analysis method for identifying high-risk ports and measuring security risks, which includes the following steps:

[0007] Step 1, perform a preliminary scan on the target IP / IP segment using the protocol detection method and the stealth detection method;

[0008] Further, in Step 1, the protocol detection method includes TCP scan, UDP scan, SYN scan, ACK scan, window scan; the stealth detection method includes FIN scan, NULL scan, XMAS scan.

[0009] Further, during the preliminary scan in Step 1, TCP scan, UDP scan, SYN scan, ACK scan, window scan, FIN scan, NULL scan, and XMAS scan are performed in sequence;

[0010] In Step 2, enhanced scanning is combined with stealth technology to bypass the anti-scanning strategies of security devices and network devices and obtain port scan result information.

[0011] Further, the enhanced scanning of the stealth technology in Step 2 includes packet fragmentation scanning, frequency change scanning, and random source IP scanning.

[0012] In Step 3, port classification is identified based on the port scan result information to obtain port classification protocol element information; meanwhile, the port behavior status and port security policy are analyzed to obtain port behavior element information and security policy element information respectively;

[0013] Further, the specific steps of Step 3 are as follows:

[0014] Step 3-1, identify port classification: classify and identify the detected live ports, first identify the protocol type and then perform application classification to identify the application service type provided by the port and the corresponding version;

[0015] Step 3-2, analyze port behavior status: judge the payload situation according to the response duration, and at the same time identify the abnormal type of the port with abnormal response, and perform abnormal level mapping according to the abnormal type to evaluate the abnormal risk value;

[0016] Specifically, by analyzing the port scan result information, judge the payload situation according to the response duration, where the greater the payload value, the heavier the payload;

[0017] Further, the abnormal types in Step 3-2 include network - type abnormalities, data - type abnormalities, resource - type abnormalities, logic - type abnormalities, and permission - type abnormalities.

[0018] Step 3-3, analyze port security policy: analyze the port security policy according to the result characteristics of the port scan result information, and the security policy includes whitelist policy, blacklist policy, IDS protection policy, and WAF protection policy.

[0019] Specifically, in Step 3-3, the whitelist and blacklist policies are identified through random source IP technology, and it is judged whether there is IDS and WAF protection according to the returned data packet body information.

[0020] In Step 4, a comprehensive evaluation vector is constructed based on the port classification protocol element information, port behavior element information, and security policy element messages to calculate the element scores, and the element scores are compared with the set threshold to judge whether the corresponding port is high - risk;

[0021] Further, step 4 specifically includes the following steps:

[0022] Step 4-1: Extract the port classification protocol element information, port behavior element information, and security policy element messages to construct an evaluation factor set U;

[0023] Step 4-2: Define the evaluation grade set V as {high, medium, low}, define the fuzzy relation matrix R to represent the membership degree of each evaluation factor to the evaluation grade, define the membership function for the evaluation factors, and calculate the fuzzy relation matrix R by mapping the actual observed values to the membership degrees on the evaluation grade set V;

[0024] Step 4-3: Define the weight vector W = [0.3, 0.3, 0.4] according to expert experience, synthesize the weight vector W and the fuzzy relation matrix R, B = W·R, to obtain the comprehensive evaluation vector B;

[0025] Step 4-4: Calculate the score S of each element based on the comprehensive evaluation vector B total ; Specifically, the calculation formula is as follows:

[0026]

[0027] where n is the number of evaluation grades, b i is the membership degree of the i-th element in the comprehensive evaluation vector B, and v i is the grade value of the i-th element in the evaluation grade set V;

[0028] Step 4-5: Determine whether the element score exceeds the set high-risk threshold; if so, determine the corresponding port as a high-risk port; otherwise, determine it as a non-high-risk port;

[0029] Specifically, when the element score result value is higher than 6, it is a high-risk port;

[0030] Specifically, extract the port classification protocol element information, port behavior element information, and security policy element messages to construct an evaluation factor set U, define the evaluation grade set V as {high, medium, low}, define the fuzzy relation matrix R to represent the membership degree of each evaluation factor to the evaluation grade, define its membership function for the evaluation factors, calculate the fuzzy relation matrix R by mapping the actual observed values to the membership degrees on the evaluation grade set V, define the weight vector W = [0.3, 0.3, 0.4] according to expert experience, synthesize the weight vector W and the fuzzy relation matrix R, B = W·R, to obtain the comprehensive evaluation vector B, calculate the score of the element, where n is the number of evaluation grades, b i is the membership degree of the i-th element in the comprehensive evaluation vector B, and v iis the value of the i-th level in the evaluation level set V. When the result value is higher than 6, it is a high-risk port.

[0031] Step 5: Conduct vulnerability scanning, baseline scanning, and POC detection on high-risk ports, and calculate the vulnerability security risk value Va, norm baseline security risk value Ba, norm and POC security risk value Po norm ;

[0032] Furthermore, Step 5 specifically includes the following steps:

[0033] Step 5-1: Conduct vulnerability scanning on high-risk ports, collect security events, log data, and application service version construction risks related to high-risk ports, and calculate the vulnerability security risk value according to the vulnerability risk measurement calculation model; the vulnerability security risk value Va z is calculated according to the following formula:

[0034] Va z = ∑ j w 1j ·P z ·S zj + ∑ k w 2k ·E zk + ∑ l w 3l ·L zl + ∑ m w 4m ·V zm ;

[0035] where w 1j , w 2k , w 3l , w 4m are weight coefficients, indicating the importance of each factor in the calculation of vulnerability security risk, and are defined according to expert experience; P z is the probability of finding a vulnerability on the high-risk port z, S zj is the severity of the vulnerability j on the port z, E zk is the vulnerability security impact degree of the security event k related to the port z, L zl is the abnormality degree of the log data l on the port z, V zm is the vulnerability degree of the application service version m on the port z;

[0036] Step 5-2: Conduct baseline scanning on high-risk ports, collect the number of security events, the number of abnormal log data, and the old coefficient of the application service version related to high-risk ports to construct a risk model, and calculate according to the baseline risk measurement calculation model Ba z The calculation formula is as follows:

[0037] Ba z = ∑ g w 1g ·Pb z ·Sb zg + ∑ k w 2kg ·Eb zk + ∑ l w 3lg ·Lb zl + ∑ m w 4mg ·Vb zm ;

[0038] Among them, w 1g , w 2kg , w 3lg , w 4mg are weight coefficients, indicating the importance of each factor in the baseline risk calculation; Pb z is the probability of finding a baseline violation on the high-risk port z, Sb zg is the severity of the baseline violation g on the port z, Eb zk is the impact degree of the baseline violation of the security event k related to the port z, Lb zl is the abnormality degree of the log data l on the port z, Vb zm is the baseline violation degree of the application service version m on the high-risk port z;

[0039] Step 5-3, conduct POC detection on the high-risk port, and collect security events, log data, and application service versions related to the high-risk port to build a risk model. The calculation formula for the model Ba z is as follows:

[0040] Po z = ∑ h w 1h ·Pp z ·Sp zh + ∑ k w 2kh ·Ep zk + ∑ l w 3lh ·Lp zl + ∑ m w 4mh ·Vp zm ;

[0041] Among them, w 1h , w 2kh , w 3lh , w 4mj are weight coefficients, indicating the importance of each factor in the POC security risk calculation; Pp z is the probability of finding a POC vulnerability on the high-risk port z, Spzh The severity of the POC vulnerability h on port z, Ep zk The impact degree of the POC vulnerability on the security event k related to port z, Lp zl The abnormality degree of the log data l on port z, Vp zm The impact degree of the POC vulnerability of the application service version m on the high-risk port z.

[0042] Step 6, extract three types of security risk values, and calculate the three-dimensional metric value Ri to measure the three-dimensional risk value of the high-risk port; the calculation formula of the three-dimensional metric value Measure the three-dimensional risk value of the high-risk port through the effectiveness of the security policy (baseline risk value), the effectiveness of security protection (POC risk value), and the health of the port status (vulnerability risk value) of the high-risk port.

[0043] The present invention adopts the above technical solutions, and uses three modules of port detection, high-risk judgment, and security risk measurement to cooperate, expands the traditional scanning technology, increases the discovery rate of port survival by adding combined scanning technology, comprehensively analyzes the detection results, judges the nature of the port, and finally comprehensively measures the security data to form a three-dimensional risk measurement map for decision-makers to judge. Description of the Drawings

[0044] The following further describes the present invention in detail in conjunction with the drawings and specific embodiments;

[0045] Figure 1 It is a schematic diagram of the principle architecture of an analysis method for identifying high-risk ports and measuring security risks of the present invention. Specific Embodiments

[0046] To make the objectives, technical solutions, and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application.

[0047] As Figure 1 shown, the present invention discloses an analysis method for identifying high-risk ports and measuring security risks, including the following steps:

[0048] Step 1, perform a preliminary scan on the target IP / IP segment using the protocol detection method and the secret detection method;

[0049] Furthermore, in step 1, the protocol detection method includes TCP scan, UDP scan, SYN scan, ACK scan, window scan; the secret detection method includes FIN scan, NULL scan, XMAS scan.

[0050] Further, during the preliminary scan in Step 1, TCP scan, UDP scan, SYN scan, ACK scan, window scan, FIN scan, NULL scan, and XMAS scan are performed in sequence;

[0051] In Step 2, enhanced scanning is combined with stealth technology to bypass the anti-scanning strategies of security devices and network devices and obtain port scan result information.

[0052] Further, the enhanced scanning of the stealth technology in Step 2 includes packet fragmentation scanning, frequency change scanning, and random source IP scanning.

[0053] In Step 3, based on the port scan result information, port classification is identified to obtain port classification protocol element information; meanwhile, the port behavior status and port security policies are analyzed to obtain port behavior element information and security policy element information respectively;

[0054] Further, the specific steps of Step 3 are as follows:

[0055] Step 3-1, identify port classification: classify and identify the detected live ports. First, identify the protocol type and then perform application classification to identify the application service type provided by the port and the corresponding version;

[0056] Step 3-2, analyze port behavior status: judge the payload situation according to the response duration, and at the same time identify the abnormal type of the port with abnormal response, and perform abnormal level mapping based on the abnormal type to evaluate the abnormal risk value;

[0057] Specifically, by analyzing the port scan result information, judge the payload situation according to the response duration, where the greater the payload value, the heavier the payload;

[0058] Further, the abnormal types in Step 3-2 include network - type anomalies, data - type anomalies, resource - type anomalies, logic - type anomalies, and permission - type anomalies.

[0059] Step 3-3, analyze port security policies: analyze the port security policies according to the result characteristics of the port scan result information. The security policies include whitelist policies, blacklist policies, IDS protection policies, and WAF protection policies.

[0060] Specifically, in Step 3-3, the whitelist and blacklist policies are identified through random source IP technology, and whether there are IDS and WAF protections is judged according to the packet body information of the returned data packets.

[0061] In Step 4, a comprehensive evaluation vector is constructed based on the port classification protocol element information, port behavior element information, and security policy element messages to calculate the element scores, and the element scores are compared with the set threshold to judge whether the corresponding port is high - risk;

[0062] Furthermore, step 4 specifically includes the following steps:

[0063] Step 4-1: Extract the port classification protocol element information, port behavior element information, and security policy element messages to construct an evaluation factor set U;

[0064] Step 4-2: Define the evaluation grade set V as {high, medium, low}, define the fuzzy relation matrix R to represent the membership degree of each evaluation factor to the evaluation grade, define the membership function for the evaluation factors, and calculate the fuzzy relation matrix R by mapping the actual observed values to the membership degrees on the evaluation grade set V;

[0065] Step 4-3: Define the weight vector W = [0.3, 0.3, 0.4] according to expert experience, synthesize the weight vector W and the fuzzy relation matrix R, B = W·R, to obtain the comprehensive evaluation vector B;

[0066] Step 4-4: Calculate the scores S of each element based on the comprehensive evaluation vector B total ; Specifically, the calculation formula is as follows:

[0067]

[0068] where n is the number of evaluation grades, b i is the membership degree of the i-th element in the comprehensive evaluation vector B, and v i is the grade value of the i-th element in the evaluation grade set V;

[0069] Step 4-5: Judge whether the element score exceeds the set high-risk threshold; if so, determine the corresponding port as a high-risk port; otherwise, judge it as a non-high-risk port;

[0070] Specifically, when the element score result value is higher than 6, it is a high-risk port;

[0071] Specifically, extract the port classification protocol element information, port behavior element information, and security policy element messages to construct an evaluation factor set U, define the evaluation grade set V as {high, medium, low}, define the fuzzy relation matrix R to represent the membership degree of each evaluation factor to the evaluation grade, define the membership function for the evaluation factors, calculate the fuzzy relation matrix R by mapping the actual observed values to the membership degrees on the evaluation grade set V, define the weight vector W = [0.3, 0.3, 0.4] according to expert experience, synthesize the weight vector W and the fuzzy relation matrix R, B = W·R, to obtain the comprehensive evaluation vector B, calculate the scores of the elements, where n is the number of evaluation grades, b i is the membership degree of the i-th element in the comprehensive evaluation vector B, and v iis the value of the i-th level in the evaluation level set V. When the result value is higher than 6, it is a high-risk port.

[0072] Step 5: Conduct vulnerability scanning, baseline scanning, and POC detection on high-risk ports, and calculate the vulnerability security risk value, baseline security risk value, and POC security risk value respectively;

[0073] Furthermore, Step 5 specifically includes the following steps:

[0074] Step 5-1: Conduct vulnerability scanning on high-risk ports, collect security events, log data, and application service version construction risks related to high-risk ports, and calculate the vulnerability security risk value according to the vulnerability risk measurement calculation model; Vulnerability security risk value Va z The calculation formula is as follows:

[0075] Va z = ∑ j w 1j ·P z ·S zj + ∑ k w 2k ·E zk + ∑ l w 3l ·L zl + ∑ m w 4m ·V zm ;

[0076] Among them, w 1j , w 2k , w 3l , w 4m are weight coefficients, indicating the importance of each factor in the calculation of vulnerability security risk, and are defined according to expert experience; P z is the probability of finding a vulnerability on the high-risk port z, S zj is the severity of vulnerability j on port z, E zk is the vulnerability security impact degree of security event k related to port z, L zl is the abnormality degree of log data l on port z, V zm is the vulnerability degree of application service version m on port z;

[0077] Step 5-2: Conduct baseline scanning on high-risk ports, collect the number of security events, the number of abnormal log data, and the old version coefficient of application services related to high-risk ports to construct a risk model, and calculate according to the baseline risk measurement calculation model Ba z The calculation formula is as follows:

[0078] Ba z = ∑ g w 1g·Pb z ·Sb zg +∑ k w 2kg ·Eb zk +∑ l w 3lg ·Lb zl +∑ m w 4mg ·Vb zm ;

[0079] Among them, w 1g , w 2kg , w 3lg , w 4mg are weight coefficients, indicating the importance of each factor in the baseline risk calculation; Pb z is the probability of finding a baseline violation on the high-risk port z, Sb zg is the severity of the baseline violation g on the port z, Eb zk is the impact degree of the baseline violation of the security event k related to the port z, Lb zl is the abnormality degree of the log data l on the port z, Vb zm is the baseline violation degree of the application service version m on the high-risk port z;

[0080] Step 5-3: Conduct POC detection on the high-risk port, and collect security events, log data, and application service versions related to the high-risk port to build a risk model. The calculation formula of the POC risk metric calculation model Ba z is as follows:

[0081] Po z =∑ h w 1h ·Pp z ·Sp zh +∑ k w 2kh ·Ep zk +∑ l w 3lh ·Lp zl +∑ m w 4mh ·Vp zm ;

[0082] Among them, w 1h , w 2kh , w 3lh , w 4mj are weight coefficients, indicating the importance of each factor in the POC security risk calculation; Pp z is the probability of finding a POC vulnerability on the high-risk port z, Sp zh is the severity of the POC vulnerability h on the port z, Ep zkLp is the impact degree of the POC vulnerability for the security event k related to port z. zl Vp is the abnormality degree of the log data l on port z. zm Lm is the impact degree of the POC vulnerability of the application service version m on the high-risk port z.

[0083] Step 6: Extract three types of security risk values. According to the risk measurement formula Calculate the three-dimensional measurement values, and measure the three-dimensional risk values of the high-risk port through the effectiveness of the security policy (baseline risk value), the effectiveness of the security protection (POC risk value), and the health degree of the port status (vulnerability risk value) of the high-risk port.

[0084] The present invention adopts the above technical solutions, combines port detection technologies, and combines through methods such as datagram fragmentation, frequency change, and protocol hiding scanning with conventional scanning for stealth port detection. Compared with traditional scanning technologies, it is easier to discover stealth ports and bypass the protection strategies of some security devices, improving the port discovery rate. A judgment model is constructed through the fuzzy comprehensive evaluation method, and after extracting protocol elements, port behavior elements, and security policy elements, comprehensive judgment is carried out to realize dynamic judgment of port properties, and the evaluation of high-risk ports is more dynamic and professional. Through the risk measurement model, comprehensive analysis of security data is realized, three-dimensional risk measurement of the effectiveness of security policies, the effectiveness of security protection, and the health degree of port status is realized, and multi-dimensional risk measurement values are provided for risk presentation.

[0085] Obviously, the described embodiments are part of the embodiments of the present application, rather than all embodiments. Without conflict, the embodiments in the present application and the features in the embodiments can be combined with each other. Usually, the components of the embodiments of the present application described and shown in the drawings here can be arranged and designed in various different configurations. Therefore, the detailed description of the embodiments of the present application is not intended to limit the scope of the present application claimed, but merely represents the selected embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present application.

Claims

1. An analysis method for identifying high-risk ports and measuring security risks, characterized in that: It includes the following steps: Step 1: Conduct a preliminary scan on the target IP / IP segment using protocol detection methods and secret detection methods; Step 2: Combine and use stealth technologies for enhanced scanning to bypass the anti-scanning strategies of security devices and network devices and obtain port scan result information; Step 3: Identify port classifications based on the port scan result information to obtain port classification protocol element information; at the same time, analyze the port behavior status and port security policies to obtain port behavior element information and security policy element information respectively; Step 4: Construct a comprehensive evaluation vector based on the port classification protocol element information, port behavior element information, and security policy message to calculate the element scores, and compare the element scores with the set threshold to determine whether the corresponding port is high-risk; Step 5: Conduct vulnerability scanning, baseline scanning, and POC detection on high-risk ports, and respectively calculate the vulnerability security risk value Va norm , the baseline security risk value Ba norm , and the POC security risk value Po norm ; Step 6, extract three types of security risk values, and calculate the three-dimensional metric value Ri to measure the three-dimensional risk value of high-risk ports; the calculation formula of the three-dimensional metric value 2. The analysis method for identifying high-risk ports and measuring security risks according to claim 1, wherein: The protocol detection methods in Step 1 include TCP scan, UDP scan, SYN scan, ACK scan, and window scan; the secret detection methods include FIN scan, NULL scan, and XMAS scan.

3. The analysis method for identifying high-risk ports and measuring security risks according to claim 2, wherein: During the preliminary scan in Step 1, TCP scan, UDP scan, SYN scan, ACK scan, window scan, FIN scan, NULL scan, and XMAS scan are performed in sequence.

4. The analysis method for identifying high-risk ports and measuring security risks according to claim 1, wherein: The enhanced scan of the stealth technology in Step 2 includes packet fragmentation scan, frequency change scan, and random source IP scan.

5. The analysis method for identifying high-risk ports and measuring security risks according to claim 1, wherein: The specific steps of Step 3 are as follows: Step 3-1: Identify port classifications: Classify and identify the detected live ports. First, identify the protocol type and then perform application classification to identify the application service type provided by the port and the corresponding version; Step 3-2: Analyze the port behavior status: Judge the payload situation based on the response duration, and at the same time identify the abnormal types of ports with abnormal responses, and perform abnormal level mapping according to the abnormal types to evaluate the abnormal risk value; Step 3-3: Analyze the port security policy: Analyze the port security policy according to the result characteristics of the port scan result information. The security policies include whitelist policy, blacklist policy, IDS protection policy, and WAF protection policy.

6. The analysis method for identifying high-risk ports and measuring security risks according to claim 5, characterized in that: The abnormal types in Step 3-2 include network anomalies, data anomalies, resource anomalies, logical anomalies, and permission anomalies.

7. An analysis method for identifying high-risk ports and measuring security risks according to claim 5, characterized in that: In Step 3-3, the whitelist and blacklist policies are identified through the random source IP technology, and it is judged whether there is IDS and WAF protection according to the returned data packet body information.

8. The analysis method for identifying high-risk ports and measuring security risks according to claim 1, characterized in that: Step 4 specifically includes the following steps: Step 4-1: Extract the port classification protocol element information, port behavior element information, and security policy message to construct an evaluation factor set U; Step 4-2: Define the evaluation grade set V as {high, medium, low}, define the fuzzy relation matrix R to represent the membership degree of each evaluation factor to the evaluation grade, define the membership function for the evaluation factors, and calculate the fuzzy relation matrix R by mapping the actual observed values to the membership degrees on the evaluation grade set V; Step 4-3: Define the weight vector W = [0.3, 0.3, 0.4] according to expert experience, synthesize the weight vector W and the fuzzy relation matrix R, B = W·R, to obtain the comprehensive evaluation vector B; Step 4-4, calculate the score S of each element based on the comprehensive evaluation vector B total ; specifically, the calculation formula is as follows: where n is the number of evaluation levels, and b i is the membership degree of the i-th element in the comprehensive evaluation vector B, and v i is the level value of the i-th element in the evaluation level set V; Step 4-5: Judge whether the element score exceeds the set high-risk threshold; if so, determine that the corresponding port is a high-risk port; otherwise, judge it as a non-high-risk port.

9. The analysis method for identifying high-risk ports and measuring security risks according to claim 1, wherein: Step 5 specifically includes the following steps: Step 5-1: Conduct vulnerability scanning on high-risk ports, collect security events, log data, and application service version related to high-risk ports to build a risk model, and calculate the vulnerability security risk value according to the vulnerability risk measurement calculation model; the vulnerability security risk value Va z is calculated according to the following formula: Va z = ∑ j w 1j ·P z ·S zj + ∑ k w 2k ·E zk + ∑ l w 3l ·L zl + ∑ m w 4m ·V zm ; Among them, w 1j , w 2k , w 3l , w 4m are weight coefficients, indicating the importance of each factor in the calculation of vulnerability security risk; P z is the probability of discovering a vulnerability on high-risk port z, S zj is the severity of vulnerability j on port z, E zk is the vulnerability security impact degree of security event k related to port z, L zl is the abnormality degree of log data l on port z, Vz zm is the vulnerability degree of application service version m on port z; Step 5-2: Conduct a baseline scan on high-risk ports, collect the number of security events related to high-risk ports, the number of abnormal log data, and the aging coefficient of application service versions to build a risk model, and calculate the model Ba according to the baseline risk metric z The calculation formula is as follows: Ba z = ∑ g w 1g · Pb z · Sb zg + ∑ k w 2kg · Eb zk + ∑ l w 3lg · Lb zl + ∑ m w 4mg · Vb zm ; Among them, w 1g , w 2kg , w 3lg , w 4mg are weight coefficients, indicating the importance of each factor in the baseline risk calculation; Pb z is the probability of finding a baseline violation on the high-risk port z, Sb zg is the severity of the baseline violation g on the port z, Eb zk is the impact degree of the baseline violation of the security event k related to the port z, Lb zl is the abnormality degree of the log data l on the port z, Vb zm is the baseline violation degree of the application service version m on the high-risk port z; Step 5-3, conduct POC detection on high-risk ports, collect security events, log data, and application service version related to high-risk ports to build a risk model, and calculate model Ba according to the POC risk metric z The calculation formula is as follows: Po z = ∑ h w 1h · Pp z · Sp zh + ∑ k w 2kh · Ep zj + ∑ l w зlh · Lp zl + ∑ m w 4mh · Vp zm ; Among them, w 1h , w 2kh , w 3lh , w 4mh are weight coefficients, indicating the importance of each factor in the POC security risk calculation; Pp z is the probability of discovering a POC vulnerability on the high-risk port z, Sp zh is the severity of the POC vulnerability h on the port z, Ep zk is the impact degree of the POC vulnerability of the security event k related to the port z, Lp zl is the anomaly degree of the log data l on the port z, Vp zm is the impact degree of the POC vulnerability of the application service version m on the high-risk port z.