Intelligent detection system and method for network security vulnerabilities
Through the device list library, data crawling module and black and white list module, the device is tracked using address codes, the list is divided and compared and analogy is solved, and the security vulnerability detection in the Internet of Things is weak, and security threats are timely discovered and handled, and the timeliness of network security protection is improved.
Patent Information
- Application Number
- CN202510803723.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-16
- Publication Date
- 2025-07-29
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
In the Internet of Things application stage, the lack of historical request data for new network-entry devices has led to weak detection of security vulnerabilities in new network-entry devices and the inability to detect security threats in time.
The device list library, data crawling module, black and white list module and filtering module are used to track the equipment through address code, divide the list and compare and compare, filter out abnormal items, and automatically or manually add them to the whitelist or blacklist to find vulnerabilities in a timely manner.
It improves the timeliness and timeliness of security protection of new network-entry equipment, can promptly detect and deal with security vulnerabilities, and reduce network security risks.
Smart Images

Figure CN120389905A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of network security communication devices, and in particular relates to a network security vulnerability intelligent detection system and method. Background Art
[0002] Network security vulnerability detection is a crucial means of maintaining the security of communication networks and their interconnected devices. It runs through every stage of the information system lifecycle and is a core component of ensuring network security. With the application of the Internet of Things (IoT), various information sensors, radio frequency identification (RFID), global positioning systems (GPS), infrared sensors, laser scanners, and other devices and technologies are collecting real-time data on any object or process that requires monitoring, connection, or interaction, including acoustic, optical, thermal, electrical, mechanical, chemical, biological, and location information. Through various possible network access options, ubiquitous connectivity between objects and between objects and people is achieved, enabling intelligent perception, identification, and management of objects and processes. This generates vast amounts of data, which, if not promptly monitored, could lead to network security vulnerabilities that could be exploited by unscrupulous individuals.
[0003] Actively discovering network security vulnerabilities can prevent the invasion of Trojan viruses, malicious programs, etc., thereby improving network protection. For example, after retrieving the Chinese invention network security vulnerability detection method, device and equipment with publication number CN119561757A, the target network's inbound and outbound network data are obtained from the full-flow backtracing device. After decrypting the inbound and outbound network data, sensitive information that affects data security is detected, the parameters of the request elements are replaced, and the request data is reconstructed using the request elements after the replacement parameters to obtain the target request data. In response to the detection of sensitive information in the target request data, it is determined that the target network has a network security vulnerability.
[0004] In the daily process of network security protection, the analysis of incoming and outgoing network data relies on historical request data to identify data security threats. However, in the IoT application stage, the lack of historical request data for newly connected devices makes periodic detection of new devices relatively weak, hindering the timely discovery of security vulnerabilities in newly connected devices. Therefore, the present invention proposes an intelligent network security vulnerability detection system and method. Summary of the Invention
[0005] The purpose of the present invention is to provide an intelligent network security vulnerability detection system and method, which associates the matched list with its function and position in the enterprise, and screens it to promptly discover abnormal vulnerabilities. These lists are used to compare and analogize new network devices, which can improve the timeliness and timeliness of security protection for new network devices.
[0006] The technical solutions adopted by the present invention are as follows: A network security vulnerability intelligent detection system, comprising: Device list library, which records the detailed information of all networked devices, classifies them according to the functions of the networked devices in the network, and divides them into first-level lists, second-level lists, and third-level lists; Data scraping module, which assigns a unique address code to all networked devices, supports the registration, cancellation, and tracking of networked devices, and collects the data corresponding to these address codes in real time; Black and white list module, which establishes a blacklist and a white list, and constructs sets in the white list according to the first-level list, second-level list, and third-level list 、 '、U、 '、I、 '、H、 '、T、 '、D; Screening module, which sets preset conditions to screen the data collected by the first-level extraction unit and the second-level extraction unit to find vulnerabilities and include newly networked devices in the temporary set D; Warning module, when the server, gateway, or networked device joins the temporary set D, it sends a pop-up window to the associated server to prompt the staff whether to add it to the white list.
[0007] As an optional solution, the first-level list is used to record the detailed information of the networked servers, numbered sequentially in the order of network access as 、 … 、 , and stored in an independent disk space; The detailed information includes the network access time, model, firmware version, location, and affiliated department.
[0008] As an optional solution, the second-level list is used to record the detailed information of the networked gateways, stored in an independent disk space, and divided into edge grids and cloud gateways according to different functions, as follows: Edge gateway, numbered sequentially in the order of network access as 、 … 、 ; Cloud gateway, responsible for data aggregation, numbered sequentially in the order of network access as 、 … 、 ; Among them, 、 、 are all constants.
[0009] As an alternative, the three - level list is used to record the detailed information of the network - connected devices, which is stored in an independent disk space. The network - connected devices include sensors, drive elements, display devices, monitoring devices, lighting devices, energy storage devices, liquid supply devices, ventilation devices, industrial robots, and numerical control machine tools.
[0010] As an alternative, the device list library further includes a cleaning unit. The cleaning unit sets the upper limit of the offline time of the device to 1 month, and screens the information in the first - level list, second - level list, and third - level list once a day. For devices whose offline time exceeds the upper limit, their information is deleted; Assume that the device reconnects to the network, then the screening period is recalculated.
[0011] As an alternative, the first - level extraction unit is responsible for collecting the data of servers 、 … 、 to achieve dynamic tracking of these servers, and collect the system performance, memory usage rate, and bandwidth resource usage rate of these servers, which are stored in an independent disk space; Among them, the system performance of the server includes CPU usage rate and GPU usage rate.
[0012] As an alternative, the second - level extraction unit is responsible for collecting the data of edge gateways 、 … 、 and the data of cloud gateways 、 … 、 and collect the system performance, memory usage rate, and bandwidth resource usage rate of these gateways, which are stored in an independent disk space.
[0013] As an alternative, the white list constructs a set of servers for receiving data , a set of servers for sending data ', a set of edge gateways for receiving data U, a set of servers for sending data ', a set of edge gateways for receiving data I, a set of servers for sending data ', a set of cloud gateways for receiving data H, a set of cloud gateways for sending data ', a set of cloud gateways for receiving data T, a set of cloud gateways for sending data ', as well as a temporary set D covering the first - level list, second - level list, and third - level list.
[0014] As an optional solution, the screening module includes: The comparison unit sets the whitelist corresponding to the server, gateway and network access device according to the pre-entered first-level list, second-level list and third-level list 、 '、U、 'I ', H, '、T、 ', as a preset condition, when a new network device is addressed according to the demand, it is compared with the whitelist. If the target is not on the whitelist, it is added to the temporary set D and sent to the staff, who will determine whether to add it to the whitelist. Once the time limit is exceeded, the servers, gateways and network devices in the temporary set D are automatically added to the blacklist and marked as security vulnerabilities; The analogy unit, based on the first-level list, the second-level list and the third-level list, records the servers, gateways and network access devices belonging to each function, associates the elements of their addressing relationship in the white list through the address code, references the location and the department to which they belong, and counts these elements in terms of the same function, and normalizes them, eliminating elements with a certain degree of deviation, and adding the remaining elements to the white list for automatic evaluation of the servers, gateways and network access devices in the temporary set D.
[0015] A method for intelligently detecting network security vulnerabilities, comprising the following steps: Step 1: Record detailed information of all connected devices through unique identification, mapping physical assets with digital systems. Record the entire process of equipment from procurement, deployment, maintenance, to retirement, and update device status in real time. Step 2: Classify the first-level list, second-level list and third-level list. The first-level list records the detailed information of the servers connected to the network and is numbered in the order of network access. 、 … 、 ,The secondary list records the detailed information of the gateways accessing the ,network and is stored in a separate disk space, and ,is divided into edge grid and cloud gateway according to different ,functions; Step 3: Assign a unique address code to each server, gateway, and network access device to avoid data confusion or conflict, support their registration, deregistration, and tracking, and build primary and secondary extraction units; Step 4: Create a blacklist and a whitelist. The whitelist is constructed based on the first-level list, the second-level list, and the third-level list. 、 '、U、 'I ', H, '、T、 ', and a temporary set D covering the first-level list, second-level list, and third-level list; Step Five: Filter the data collected by the first-level extraction unit and the second-level extraction unit through preset conditions to find loopholes, add newly networked devices to the temporary set D, and manually add them to the whitelist or blacklist by the staff. Once the time limit is exceeded, they will be automatically added to the blacklist; Step Six: When the server, gateway, or networked device joins the temporary set D, send a pop-up window to the associated server to prompt the staff whether to add it to the whitelist; when an element is added to the whitelist, send a pop-up window to the associated server to request the staff to confirm.
[0016] The technical effects achieved by the present invention are: The present invention provides an intelligent detection system equipped with a device list library, a data scraping module, a black and white list module, a screening module, and a warning module. By tracking the associated data of the address code, the first-level list, second-level list, third-level list, and associated black and white lists are divided. At the same time, preset conditions are set to screen the data collected by the first-level extraction unit and the second-level extraction unit. Through comparison or analogy, loopholes are found, and they can be automatically added to the blacklist after exceeding the limit, or the staff can judge whether to add them to the whitelist.
[0017] The present invention uses a first-level extraction unit to collect data from servers , … , , realizes the dynamic tracking of these servers, and collects the system performance, memory usage rate, and bandwidth resource usage rate of these servers. The second-level extraction unit is used to collect data from edge gateways , … , , and data from cloud gateways , … , , and collects the system performance, memory usage rate, and bandwidth resource usage rate of these gateways, discovers abnormal data in a timely manner, marks it as a loophole, and automatically adds it to the blacklist.
[0018] The present invention adopts the detection method from Step One to Step Six, follows the method of tracing using the address code, performs many-to-many data matching, associates the matched list with its functions and locations in the enterprise, and conducts screening. Abnormal items are discovered in a timely manner, and the staff can judge whether to add them to the whitelist or they will be automatically added to the blacklist after exceeding the limit. These lists are used for analogy of newly networked devices, facilitating the intelligent detection of network security loopholes, and improving the timeliness and promptness of the security protection of newly networked devices. Description of the Drawings
[0019] Figure 1 It is a block diagram of an intelligent network security vulnerability detection system in the first embodiment of the present invention; Figure 2 It is a flowchart of an intelligent network security vulnerability detection method in the second embodiment of the present invention. Detailed implementation manners
[0020] In order to make the purpose and advantages of the present invention clearer, the present invention will be specifically described below in conjunction with embodiments. It should be understood that the following text is only used to describe one or several specific implementation manners of the present invention, and does not strictly limit the specific protection scope claimed by the present invention.
[0021] Embodiment 1: As Figure 1 shown, an intelligent network security vulnerability detection system, applicable to network defense services in company or enterprise intranets, includes the following parts: 1. Equipment inventory library The equipment inventory library can help managers understand the situation of the enterprise's IoT (Internet of Things) system. Its value far exceeds that of static ledgers. It is the infrastructure for realizing safe, efficient, and intelligent operation. The lack of perfect inventory management may lead to security blind spots, chaotic operation and maintenance, and strategic inaccuracy. Especially in large-scale deployments (such as tens of thousands of devices), the differences will be significantly amplified. It is mainly achieved through the following means: Centralized tracking: Record detailed information (model, firmware version, location, department affiliation, etc.) of all networked devices through a unique identifier (such as device ID number, serial number), and realize the mapping of physical assets and digital systems; Status monitoring: Real-time update the device status (online / offline, faulty, under maintenance), and avoid security risks brought by "phantom devices" (devices that have been deprecated but are still in the network); Lifecycle management: Record the whole process of the device from procurement, deployment, maintenance to retirement, and optimize resource allocation (such as predictive maintenance or batch replacement); Due to the different uses of each device, the pressure of centralized management is relatively large. It is necessary to classify according to the functions of each device in the network and manage them at different levels for convenient and quick entry or search. The classification is as follows: First-level list: Used to record detailed information (network entry time, model, firmware version, location, department affiliation, etc.) of the servers accessing the network, and sequentially numbered as 、 … 、 , stored in an independent disk space and can be retrieved at any time; Secondary list: Used to record the detailed information of the gateways accessing the network (access time, model, firmware version, location, affiliated department, etc.), stored in an independent disk space for retrieval at any time. The communication methods of these gateways include serial ports, WIFI , IO ( Input / Output ) interfaces, LORA ( Long Range Radio ) interfaces or network cable interfaces, etc. And they are divided into edge gateways and cloud gateways according to different functions as follows: Edge gateways, such as WG583 series 4G Industrial intelligent gateways, WG783 series 5G Data acquisition gateways, etc., which support collecting data from devices accessing the network and can be connected to various industrial Internet platforms and software to be responsible for data filtering, alarm, jump change, formula, local programming, etc. on the device side accessing the network. These edge gateways are numbered sequentially according to the order of network access as , … , ; Cloud gateways, such as ISG-505-R0l General standards of the model EMS / EMU Carrier, ISG-503 High-performance edge computing gateway of the model, ISG-730 Energy storage of the model EMS Gateway, ARM Low-power energy storage gateway, XL-208G Industrial-grade gigabit 8-port switch of the model, XL-205G Industrial-grade gigabit 5-port switch of the model, XL-2216G-SFP Industrial-grade gigabit 2-light 16-electrical switch of the model, XL-2224G-SFP Industrial-grade gigabit 2-light 24-electrical switch of the model, etc. These cloud gateways are close to the cloud server and are mainly responsible for data aggregation. They can be numbered sequentially according to the order of network access as , … , ; Among them, , , are all constants. Edge gateways and cloud gateways can be independent of each other or interconnected with each other, arranged according to actual production needs. Also, lightweight AI models can be appropriately deployed on edge gateways, such as TensorFlow Lite ; Three - level list: Used to record detailed information of networked devices (network entry time, model, firmware version, location, affiliated department, etc.). These networked devices include sensors, drive components, display devices, monitoring devices, lighting devices, energy storage devices, liquid supply devices, ventilation devices, industrial robots, numerical control machine tools, etc. Their detailed information is stored in independent disk space and can be retrieved at any time; Cleaning unit: Set the upper limit of the offline time of the device, for example, 1 month. Screen the information in the first - level list, second - level list, and third - level list at least once a day. For devices whose offline time exceeds the upper limit, clear their information. If the device reconnects to the network, recalculate the screening period, which can regularly clear redundant data and reduce the system burden; 2. Data capture module In IoT (Internet of Things) systems, the address code is a key identifier used to uniquely identify and locate devices, data, or network nodes. Its core function is to ensure that data can be accurately and efficiently transmitted and routed in a complex Internet of Things environment. Assign a unique address code to each networked device or node (such as sensors, gateways, actuators) to avoid data confusion or conflicts. For example, when there are multiple industrial robots in the same network, distinguish the data sources through the address code; In the life - cycle management of networked devices, the address code can be used to support device registration, cancellation, and tracking. For example, in smart homes Zigbee the short - address assignment of devices. Among them, the gateway or router sends data to the target device or server according to the address code. For example MQTT in the protocol Topic contains device address information; Since the functions of networked devices in the network are different, which is reflected in the different amounts of data interaction in the first - level list and the second - level list. Among them, the data of networked devices in the third - level list is sent and received through the gateway in the second - level list, and the data of the gateway in the second - level list has to be sent, received, or relayed through the server in the first - level list. Therefore, in this embodiment, the data of the network of this Internet of Things is extracted in two layers as follows: First - level extraction unit, responsible for collecting data from servers 、 … 、 to achieve dynamic tracking of these servers, and collect the system performance of these servers (including CPU usage rate and GPU usage rate), memory usage rate, and bandwidth resource usage rate, and store them in independent disk space for retrieval at any time; Second - level extraction unit, responsible for collecting data from edge gateways 、 … 、 Data and cloud gateways 、 … 、 The data, as well as the system performance, memory usage, and bandwidth resource usage of these gateways, are stored in an independent disk space and can be retrieved at any time; Among them, the system performance of these gateways includes the following aspects: RTT (Round-Trip Time), which is the time required for the client to send a request and receive a response from the server. Network latency will cause an increase in RTT. However, it should be noted that since network data forwarding is dynamic and the path may also change, RTT does not absolutely indicate the problem; TTFB ( Time To First Byte ), which is the time required for the first byte of data to reach the client from the server after the connection is established, TTFB depending on two key factors: the time required for the backend service to process the request and the time required for the network request and response to return to the client. Therefore, TTFB is an important indicator for measuring business processing time and network lag, and is also the core reference basis for network transmission optimization and backend service optimization; QPS , which refers to the number of interface requests that the server can process in 1 second. It is generally used to measure the maximum performance index of the interface, and then calculate the corresponding horizontally scalable service quantity. Based on the 80 / 20 principle, the vast majority of requests are generated in 20% of the time period. Using wrk or ab to test the interface QPS , pay attention to the system locality principle. There will be a large number of requests penetrating the cache in the production environment; when using tools such as wrk to test concurrency, pay attention to the Latency index. Within a reasonable Latency range, QPS testing is meaningful; TPS Transactions per second, where the corresponding transaction is a complete event processing request; Network throughput, which represents the amount of data successfully transmitted per unit time. The unit is usually b / s (bits per second) or B / s (bytes per second). The throughput is limited by the bandwidth. The network usage rate = throughput / bandwidth; In terms of the system performance testing of the gateway, in order to objectively and reasonably evaluate the optimization test and its effects, the optimization criteria should be clarified first, that is, benchmark tests should be conducted on the system and application programs to obtain the benchmark performance of each layer. When conducting benchmark tests, they can be carried out layer by layer according to the protocol stack. Since the bottom layer is the foundation of the upper layers, the bottom layer performance determines the upper layer performance. For example, regarding the routing situation at both ends in the network layer, we can use MTR to detect the routing. In the transport layer, we can use iperf or netperf to test the performance of the transport layer. Then, in the application layer, tools such as wrk and ab are used to test the performance of the application program; 3. Black and white list module In a network with up to tens of thousands of networked devices, devices are constantly connecting to and disconnecting from the network, and there are also a continuous stream of new data requests. The supervision of newly connected devices is also very important. By establishing black and white lists, a foundation is laid for screening newly connected devices, and temporary data is selected from them for isolated processing; White list: According to the first-level list, second-level list, and third-level list, construct a set of servers for receiving data , a set of servers for sending data ', a set of edge gateways for receiving data U, a set of servers for sending data ', a set of edge gateways for receiving data I, a set of servers for sending data ', a set of cloud gateways for receiving data H, a set of cloud gateways for sending data ', a set of cloud gateways for receiving data T, a set of cloud gateways for sending data ', and a temporary set D covering the first-level list, second-level list, and third-level list. The temporary set D is used to count the newly connected devices associated with the temporary data; Black list: It includes servers, gateways, devices, etc. that are prohibited from entering this network, as well as servers, gateways, devices, etc. that send or receive malicious data in this network; 4. Screening module Facing the continuous stream of data, it is time-consuming and laborious for staff to manually screen. Therefore, in this embodiment, through preset conditions, the data collected by the first-level extraction unit and the second-level extraction unit is automatically screened to find loopholes, and newly connected devices are included in the temporary set D. Based on the address code, they can be manually added to the white list by the staff, and once the time limit is exceeded, they are automatically added to the black list. Specifically, it includes: Comparison unit: According to the pre-entered first-level list, second-level list, and third-level list, set the white lists corresponding to servers, gateways, and networked devices , ', U, ', I, ', H, ', T, ', as a preset condition, when a newly connected device addresses along the address code according to requirements and compares with the whitelist, if the required target is not in the whitelist, it is added to the temporary set D, which plays a certain buffering role and is sent to the staff for him to judge whether to add it to the whitelist. Once the time limit is exceeded, the servers, gateways, and connected devices in the temporary set D are automatically added to the blacklist and marked as security vulnerabilities; Furthermore, for the servers, gateways, and connected devices manually added to the whitelist by the staff, the associations between them and the first-level list, second-level list, and third-level list are automatically added to the whitelist as a supplement to facilitate intelligent optimization of the whitelist. At the same time, the cleaning unit is called to regularly clean up redundant data; The analogy unit, based on the first-level list, second-level list, and third-level list, records the servers, gateways, and connected devices belonging to each function, associates the elements of their addressing relationship in the whitelist through the address code, includes all possibilities in the analysis, refers to the location and department, and statistically analyzes these elements on the plane coordinate system for the same function and performs normalization processing. For elements that deviate to a certain extent, they need to be excluded, and the elements with stronger relevance are left and added to the whitelist, which can be used to automatically evaluate the servers, gateways, and connected devices in the temporary set D. If they meet the whitelist and the newly added elements, the corresponding servers, gateways, and connected devices are added to the whitelist, otherwise they are added to the blacklist; For newly connected devices, in the case of lack of historical data, the analogy unit can be called to make an analogy with the same function. If the elements that are not in the whitelist and deviate during addressing through the address code are directly added to the blacklist and marked as security vulnerabilities; 5. Warning module When a server, gateway, or connected device is added to the temporary set D, a pop-up window is sent to its associated server to prompt the staff whether to add it to the whitelist; When an element is added to the whitelist, a pop-up window is sent to its associated server to request confirmation from the staff; After the servers, gateways, and connected devices are added to the blacklist, a list is sent to all servers and gateways for data update.
[0022] Embodiment 2: To facilitate the staff to use the network security vulnerability intelligent detection system in Embodiment 1, this embodiment takes the enterprise Internet of Things system as an example to carry out all-weather intelligent detection based on servers, gateways, and connected devices, screen along the address code addressing, capture vulnerabilities in a timely manner, remind the staff to update patches regularly, and improve network security performance.
[0023] Such asFigure 2 As shown in the figure, an intelligent detection method for network security vulnerabilities includes the following steps: Step 1: Through unique identifiers, such as device ID , serial number, etc., record the detailed information (model, firmware version, location, department affiliation, etc.) of all networked devices, realize the mapping of physical assets and digital systems, and record the whole process of equipment from procurement, deployment, maintenance to retirement, and update the equipment status in real time; Step 2: Classify the first-level list, second-level list, and third-level list. The first-level list records the detailed information of the servers accessing the network (access time, model, firmware version, location, department affiliation, etc.), and is numbered sequentially according to the order of accessing the network as , … , , and stored in an independent disk space for retrieval at any time. The second-level list records the detailed information of the gateways accessing the network (access time, model, firmware version, location, department affiliation, etc.), stored in an independent disk space for retrieval at any time, and is divided into edge grids and cloud gateways according to different functions as follows: Edge gateways support collecting data of networked devices and can be connected to various industrial Internet platforms and software to be responsible for data filtering, alarm, jump change, formula, local programming, etc. on the side of networked devices. These edge gateways are numbered sequentially according to the order of accessing the network as , … , ; Cloud gateways are close to cloud servers and are mainly responsible for data aggregation. They can be numbered sequentially according to the order of accessing the network as , … , ; Among them, set the upper limit of the offline time of the device, for example, 1 month. Screen the information in the first-level list, second-level list, and third-level list at least once a day. For devices whose offline time exceeds the upper limit, clear the information. If the device accesses the network again, recalculate the screening cycle, which can regularly clear redundant data and reduce the system burden; Step 3: Assign a unique address code to each server, gateway, and networked device to avoid data confusion or conflict, and support their registration, cancellation, and tracking. Construct a first-level extraction unit and a second-level extraction unit, where: The first-level extraction unit is responsible for collecting data from servers , … , , realize the dynamic tracking of these servers, and collect the system performance of these servers (including CPUUtilization rate and GPU Usage rate), memory usage rate, and bandwidth resource usage rate are stored in a separate disk space and can be retrieved at any time; Secondary extraction unit, responsible for collecting edge gateway 、 … 、 Data and cloud gateway 、 … 、 The data, including system performance, memory usage, and bandwidth resource usage of these gateways, are stored in a separate disk space and can be retrieved at any time. Step 4: Establish blacklists and whitelists to lay the foundation for screening new devices, select temporary data from them, and process them in isolation, including: Whitelist, based on the first-level list, second-level list and third-level list, build a server set to receive data , the set of servers that send data ', the set of edge gateways that receive data U, and the set of servers that send data ', the edge gateway set I that receives data, the server set that sends data ', the cloud gateway set H that receives data, the cloud gateway set that sends data ', the set of cloud gateways that receive data T, the set of cloud gateways that send data ', and a temporary set D covering the first-level list, the second-level list, and the third-level list, the temporary set D is used to count new network-connected devices associated with temporary data; Blacklist, including servers, gateways, devices, etc. that are banned from the network, as well as servers, gateways, devices, etc. that send or receive malicious data on the network; Step 5: Based on preset conditions, the data collected by the primary and secondary extraction units are automatically screened to identify vulnerabilities and newly connected devices are placed in a temporary set D. Based on the address code, they can be manually added to the whitelist by staff. Once the time limit is exceeded, they are automatically added to the blacklist. The comparison unit sets the whitelist corresponding to the server, gateway and network access device according to the pre-entered first-level list, second-level list and third-level list 、 '、U、 'I ', H, '、T、 ', as a preset condition, when a newly networked device performs address resolution according to requirements and compares with the whitelist, if the required target is not in the whitelist, it is added to the temporary set D to play a certain buffering role and sent to the staff for them to determine whether to add it to the whitelist. Once the time limit is exceeded, the servers, gateways, and networked devices in the temporary set D are automatically added to the blacklist and marked as security vulnerabilities; Furthermore, for the servers, gateways, and networked devices manually added to the whitelist by the staff, the associations between them and the first-level list, second-level list, and third-level list are automatically added to the whitelist as a supplement to facilitate intelligent optimization of the whitelist. At the same time, the cleaning unit is called to regularly clean up redundant data; The analogy unit, based on the first-level list, second-level list, and third-level list, records the servers, gateways, and networked devices belonging to each function, associates the elements of their address resolution relationship in the whitelist, includes all possibilities in the analysis, refers to the location and the department to which they belong, statistically analyzes these elements on the plane coordinate system for the same function, and performs normalization processing. For elements that deviate to a certain extent, they need to be excluded, and the elements with stronger relevance are left and added to the whitelist, which can be used to automatically evaluate the servers, gateways, and networked devices in the temporary set D. If they meet the whitelist and the newly added elements, the corresponding servers, gateways, and networked devices are added to the whitelist, otherwise they are added to the blacklist; For newly networked devices, in the case of lack of historical data, the analogy unit can be called to make an analogy with the same function. If the elements that are not in the whitelist and deviate during address resolution, they are directly added to the blacklist and marked as security vulnerabilities; Step 6: When a server, gateway, or networked device is added to the temporary set D, a pop-up window is sent to its associated server to prompt the staff whether to add it to the whitelist; when an element is added to the whitelist, a pop-up window is sent to its associated server to request the staff to confirm.
[0024] In summary, this embodiment adopts the detection method from Step 1 to Step 6, uses the method of tracing along the address code, performs data matching for multiple pairs of servers, gateways, and networked devices, associates the matched list with their functions and locations in the enterprise, and performs screening to timely discover abnormal items. It can be judged by the staff whether to add them to the whitelist or automatically add them to the blacklist after exceeding the limit, and use these lists to make an analogy for newly networked devices, which can improve the timeliness and promptness of the security protection of newly networked devices.
[0025] This embodiment also provides a computer-readable storage medium, in which computer-executable instructions are stored. When the processor executes the computer-executable instructions, the above detection method is implemented.
[0026] The above-readable storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, a magnetic disk, or an optical disk. The readable storage medium can be any available medium accessible by a general-purpose or special-purpose computer.
[0027] An exemplary readable storage medium is coupled to the processor so that the processor can read information from the readable storage medium and write information to the readable storage medium. Of course, the readable storage medium can also be a component of the processor. The processor and the readable storage medium can be located in an application specific integrated circuit (ASIC). Of course, the processor and the readable storage medium can also exist as discrete components in the device.
[0028] The above are only alternative embodiments of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present invention. Structures, devices, and operation methods not specifically described and explained in the present invention, unless otherwise specified and limited, are implemented according to the conventional means in the art.
Claims
1. An intelligent detection system for network security vulnerabilities, characterized in that, It includes: An equipment list library that records the detailed information of all networked devices, classifies them according to the functions of the networked devices in the network, and divides them into first-level lists, second-level lists, and third-level lists; A data scraping module that assigns a unique address code to all networked devices to support the registration, cancellation, and tracking of networked devices, and collects the data corresponding to these address codes in real time; Black and white list module, establishing a black list and a white list, and constructing a set in the white list according to the first-level list, second-level list, and third-level list , ', U, ', I, ', H, ', T, ', D; A screening module that sets preset conditions to screen the data collected by the first-level extraction unit and the second-level extraction unit to find vulnerabilities and include newly networked devices in the temporary set D; An alert module that sends a pop-up window to the associated server when a server, gateway, or networked device joins the temporary set D to prompt the staff whether to add it to the whitelist.
2. The intelligent network security vulnerability detection system according to claim 1, characterized in that: The first-level list is used to record the detailed information of the servers connected to the network, and is sequentially numbered as , … , , and stored in an independent disk space; The detailed information includes the network access time, model, firmware version, location, and affiliated department.
3. An intelligent detection system for network security vulnerabilities according to claim 2, characterized in that: The second-level list is used to record the detailed information of the networked gateways, stored in an independent disk space, and divided into edge grids and cloud gateways according to different functions, as follows: Edge gateways, numbered in the order of network access as follows , ... , ; The cloud gateway is responsible for data aggregation and is numbered in sequence according to the order of network access as 、 … 、 ; Among them, , , are all constants.
4. An intelligent network security vulnerability detection system according to claim 2, characterized in that: The third-level list is used to record the detailed information of networked devices, stored in an independent disk space, and the networked devices include sensors, drive elements, display devices, monitoring devices, lighting devices, energy storage devices, liquid supply devices, ventilation devices, industrial robots, and numerically controlled machine tools.
5. An intelligent network security vulnerability detection system according to claim 1, characterized in that: The equipment list library also includes a cleaning unit that sets the upper limit of the offline time of the device to 1 month, screens the information in the first-level list, second-level list, and third-level list once a day, and deletes the information of devices whose offline time exceeds the upper limit; Assume that the device reconnects to the network, and the screening period is recalculated.
6. The intelligent network security vulnerability detection system according to claim 1, characterized in that: The first-level extraction unit is responsible for collecting servers , … , ' data, achieving dynamic tracking of these servers, as well as collecting the system performance, memory usage rate, and bandwidth resource usage rate of these servers, and storing them in an independent disk space; Among them, the system performance of the server includes CPU usage rate and GPU usage rate.
7. An intelligent network security vulnerability detection system according to claim 1, characterized in that: The secondary extraction unit is responsible for collecting data from edge gateways 、 … 、 , data from cloud gateways 、 … 、 , as well as the system performance, memory usage, and bandwidth resource usage of these gateways, and stores them in an independent disk space.
8. An intelligent detection system for network security vulnerabilities according to claim 1, characterized in that: The whitelist constructs a set of servers for receiving data according to the first-level list, the second-level list, and the third-level list , a set of servers for sending data ', a set of edge gateways for receiving data U, a set of servers for sending data ', a set of edge gateways for receiving data I, a set of servers for sending data ', a set of cloud gateways for receiving data H, a set of cloud gateways for sending data ', a set of cloud gateways for receiving data T, a set of cloud gateways for sending data ', and a temporary set D covering the first-level list, the second-level list, and the third-level list.
9. An intelligent detection system for network security vulnerabilities according to claim 1, characterized in that: The screening module includes: The comparison unit sets the whitelists corresponding to the server, gateway, and network access device according to the pre-entered first-level list, second-level list, and third-level list. , ', U, ', I, ', H, ', T, ', as a preset condition. When a newly networked device performs address search according to requirements and compares with the whitelist, if the required target is not in the whitelist, it is added to the temporary set D and sent to the staff for him to judge whether to add it to the whitelist. Once the time limit is exceeded, the server, gateway, and network access device in the temporary set D are automatically added to the blacklist and marked as security vulnerabilities. An analogy unit that, based on the first-level list, second-level list, and third-level list, records the servers, gateways, and networked devices belonging to each function, associates the elements of their addressing relationship through the address code in the whitelist, refers to the location and affiliated department, and statistically processes these elements in terms of the same function, eliminates the elements with a certain degree of deviation, and adds the remaining elements to the whitelist for automatically evaluating the servers, gateways, and networked devices in the temporary set D.
10. A method for intelligent detection of network security vulnerabilities, applied to a system for intelligent detection of network security vulnerabilities according to any one of claims 1-9, characterized in that, It includes the following steps: Step 1: Record the detailed information of all networked devices through a unique identifier to realize the mapping between physical assets and digital systems, and record the whole process of equipment from procurement, deployment, maintenance to retirement, and update the equipment status in real time; Step 2: Classify the first-level list, second-level list, and third-level list. The first-level list records the detailed information of the servers connected to the network, numbered sequentially in the order of connection to the network as , … , . The second-level list records the detailed information of the gateways connected to the network and stores it in an independent disk space, and is divided into edge grids and cloud gateways according to different functions; Step 3: Assign a unique address code to each server, gateway, and networked device to avoid data confusion or conflict, support their registration, cancellation, and tracking, and construct a first-level extraction unit and a second-level extraction unit; Step 4: Establish a blacklist and a whitelist. The whitelist constructs a set based on the first-level list, second-level list, and third-level list. , ', U, ', I, ', H, ', T, ', and a temporary set D covering the first-level list, second-level list, and third-level list. Step 5: Screen the data collected by the first-level extraction unit and the second-level extraction unit through preset conditions to find vulnerabilities, include newly networked devices in the temporary set D, and manually add them to the whitelist by the staff. Once the time limit is exceeded, they will be automatically added to the blacklist; Step 6: When a server, gateway, or networked device joins the temporary set D, send a pop-up window to the associated server to prompt the staff whether to add it to the whitelist; when an element is added to the whitelist, send a pop-up window to the associated server to request the staff to confirm.
Citation Information
Patent Citations
Network security vulnerability detection method, device and equipment
CN119561757A