A method and system for processing intranet device fingerprints
Patent Information
- Application Number
- CN202510672546.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-23
- Publication Date
- 2026-09-25
- Estimated Expiration
- 2045-05-23
AI Technical Summary
[0004]基于上述现有技术的不足,本申请提供了一种内网设备指纹的处理方法与系统,以解决现有技术降低了整体安全防护流程的效率的问题
[0084]本申请提供的一种内网设备指纹的处理方法,通过从预先建立的通信链路中获取目标设备的目标信息,其中,目标信息至少包括服务响应数据、设备指纹数据、设备响应数据序列、扫描数据以及图片信息,其次利用大模型对服务响应数据进行识别,得到目标设备的目标识别信息,接着利用大模型对设备指纹数据进行漏洞风险分析,得到预测分析列表,然后利用大模型对设备响应数据序列进行配置分析,得到目标设备的配置信息,随后利用大模型对图片信息进行对比,得到目标设备的指纹确定信息,再根据扫描数据,确定目标设备的异常模式,并将识别信息、预测分析列表、指纹确定信息以及异常模式输入至大模型中,预测得到攻击路径,最后利用大模型对识别信息、预测分析列表、异常模式、配置信息以及攻击路径进行整合,得到安全评估报告。从而通过云服务器技术与大模型智能分析能力的协同融合,整体构建了内网设备指纹识别与安全评估技术架构,能够有效解决现存技术方案中部署复杂、识别精准度低、缺乏漏洞预测分析能力等问题,进而也提高了整体安全防护流程的效率。
Smart Images

Figure CN120474788B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security technology, and in particular to a method and system for processing fingerprints of intranet devices. Background Technology
[0002] Network device fingerprinting refers to the process of identifying and distinguishing different devices by analyzing their characteristics (such as operating system, hardware model, service port, and applications). As networks continue to expand and the types and categories of devices increase, manually identifying and managing these devices has become extremely difficult. Therefore, how to utilize new technologies to improve the accuracy and efficiency of device identification is currently a hot topic in network security research.
[0003] Traditional fingerprinting methods rely on scanning and analyzing device response data within the network. However, this approach often suffers from poor accuracy, low efficiency, and vulnerability to attacks. Furthermore, traditional methods fail to automatically generate actionable security hardening recommendations based on specific vulnerabilities and security threats, still requiring further manual analysis and remediation design, thus reducing the overall efficiency of the security protection process. Summary of the Invention
[0004] In view of the shortcomings of the prior art, this application provides a method and system for processing fingerprints of intranet devices to solve the problem that the prior art reduces the efficiency of the overall security protection process.
[0005] To achieve the above objectives, this application provides the following technical solution:
[0006] The first aspect of this application provides a method for processing fingerprints of intranet devices, including:
[0007] Target information of the target device is obtained from a pre-established communication link; wherein the target information includes at least service response data, device fingerprint data, device response data sequence, scan data, and image information.
[0008] The target identification information of the target device is obtained by using a large model to identify the service response data.
[0009] The large model is used to perform vulnerability risk analysis on the device fingerprint data to obtain a predictive analysis list.
[0010] The configuration information of the target device is obtained by performing configuration analysis on the device response data sequence using the large model.
[0011] The image information is compared using the large model to obtain the fingerprint identification information of the target device;
[0012] Based on the scan data, the abnormal pattern of the target device is determined, and the identification information, the predictive analysis list, the fingerprint determination information, and the abnormal pattern are input into the large model to predict the attack path;
[0013] The large model is used to integrate the identification information, the predictive analysis list, the anomaly patterns, the configuration information, and the attack paths to obtain a security assessment report.
[0014] Optionally, in the above-described method for processing fingerprints of intranet devices, the method for establishing the communication link includes:
[0015] Obtain a secure remote connection command and execute the secure remote connection command on the intranet client to establish a reverse tunnel between the intranet client and the cloud server;
[0016] Based on the reverse tunnel, configure traffic forwarding rules on the cloud server;
[0017] A communication link is constructed based on the reverse tunnel and the traffic forwarding rules;
[0018] or,
[0019] Obtain a first target secure remote connection command and a second target secure remote connection command, and execute the first target secure remote connection command on the intranet client to map the connection service port of the intranet client to the cloud server;
[0020] Once the mapping is complete, execute the second target secure remote connection command on the cloud server to establish a proxy server and configure target traffic forwarding rules;
[0021] A communication link is constructed based on the proxy server and the target traffic forwarding rules.
[0022] Optionally, in the above-described method for processing intranet device fingerprints, the step of using a large model to identify the service response data to obtain the target identification information of the target device includes:
[0023] The target device is identified by calling an internet mapping platform based on the service response data using a large model, and identification information is obtained.
[0024] Search the database to see if there is a device that matches or is similar to the identification information;
[0025] If a device with the same or similar identification information exists in the database, then the fingerprint information of that device is obtained;
[0026] The identification information and the fingerprint information are matched using the large model;
[0027] If the identification information and the fingerprint information match successfully, the identification information and the fingerprint information are fused using the large model to obtain the target identification information of the target device;
[0028] If no device with the same or similar identification information exists in the database, or if the identification information and the fingerprint information fail to match, then the identification information will be used as the target identification information of the target device.
[0029] Optionally, in the above-described method for processing intranet device fingerprints, the step of using the large model to perform vulnerability risk analysis on the device fingerprint data to obtain a predictive analysis list includes:
[0030] Using the large model, historical vulnerabilities of the target device are searched from the vulnerability database based on the device fingerprint data;
[0031] The historical vulnerabilities are analyzed using the large model to obtain the vulnerability risks of the target device;
[0032] Based on the aforementioned vulnerability risks, a predictive analysis list is generated.
[0033] Optionally, in the above-described method for processing fingerprints of intranet devices, the step of comparing the image information using the large model to obtain the fingerprint identification information of the target device includes:
[0034] Extract the configuration interface image of the target device from the image information, and search for the configuration image of the target device from the Internet;
[0035] Compare whether the configuration interface image is consistent with the configuration image;
[0036] If the configuration interface image is consistent with the configuration image, then the image information of the target device will be used as fingerprint identification information.
[0037] Optionally, in the above-described method for processing fingerprints of intranet devices, determining the abnormal mode of the target device based on the scan data includes:
[0038] Obtain baseline data for the target device from the baseline library;
[0039] Compare the scan data with the baseline data to determine if there are any inconsistencies in the target data.
[0040] If there are target data that are inconsistent with the baseline data, then the abnormal information of the target device is identified based on the target data;
[0041] Based on the anomaly information, the anomaly mode of the target device is determined.
[0042] Optionally, the above-mentioned method for processing fingerprints of intranet devices further includes:
[0043] Obtain the predictive analysis list and the anomaly pattern;
[0044] The predictive analysis list and the anomaly patterns are input into the large model to obtain the security policy of the target device.
[0045] A second aspect of this application provides a fingerprint processing system for intranet devices, comprising:
[0046] An information acquisition unit is used to acquire target information of a target device from a pre-established communication link; wherein the target information includes at least service response data, device fingerprint data, device response data sequence, scan data, and image information;
[0047] The identification unit is used to identify the service response data using a large model to obtain the target identification information of the target device;
[0048] The vulnerability analysis unit is used to perform vulnerability risk analysis on the device fingerprint data using the large model to obtain a predictive analysis list.
[0049] The configuration analysis unit is used to perform configuration analysis on the device response data sequence using the large model to obtain the configuration information of the target device.
[0050] The comparison unit is used to compare the image information using the large model to obtain the fingerprint identification information of the target device;
[0051] The pattern determination unit is used to determine the abnormal pattern of the target device based on the scan data, and input the identification information, the predictive analysis list, the fingerprint determination information and the abnormal pattern into the large model to predict the attack path;
[0052] The integration unit is used to integrate the identification information, the predictive analysis list, the anomaly patterns, the configuration information, and the attack paths using the large model to obtain a security assessment report.
[0053] Optionally, the above-mentioned intranet device fingerprint processing system further includes:
[0054] The first command acquisition unit is used to acquire a secure remote connection command and execute the secure remote connection command on the intranet client to establish a reverse tunnel between the intranet client and the cloud server.
[0055] The rule configuration unit is used to configure traffic forwarding rules on the cloud server according to the reverse tunnel;
[0056] The first construction unit is used to construct a communication link based on the reverse tunnel and the traffic forwarding rules;
[0057] or,
[0058] The second command acquisition unit is used to acquire the first target secure remote connection command and the second target secure remote connection command, and execute the first target secure remote connection command on the intranet client to map the connection service port of the intranet client to the cloud server;
[0059] An execution unit is used to execute the second target secure remote connection command on the cloud server after the mapping is completed, so as to establish a proxy server and configure target traffic forwarding rules;
[0060] The second construction unit is used to construct a communication link based on the proxy server and the target traffic forwarding rules.
[0061] Optionally, in the above-described intranet device fingerprint processing system, the identification unit includes:
[0062] The identification subunit is used to call the Internet mapping platform through the large model to identify the target device based on the service response data and obtain identification information;
[0063] The first search unit is used to search the database for a device that is consistent with or similar to the identification information.
[0064] The fingerprint acquisition unit is used to acquire the fingerprint information of the device if a device that is consistent with or similar to the identification information exists in the database.
[0065] A matching unit is used to match the identification information and the fingerprint information using the large model;
[0066] The fusion unit is used to fuse the identification information and the fingerprint information using the large model if the identification information and the fingerprint information match successfully, so as to obtain the target identification information of the target device.
[0067] The first unit is configured to use the identification information as the target identification information of the target device if there is no device in the database that is consistent with or similar to the identification information, or if the identification information and the fingerprint information fail to match.
[0068] Optionally, in the aforementioned intranet device fingerprinting system, the vulnerability analysis unit includes:
[0069] The second search unit is used to search for historical vulnerabilities of the target device from the vulnerability database based on the device fingerprint data using the large model;
[0070] The analysis unit is used to analyze the historical vulnerabilities using the large model to obtain the vulnerability risks of the target device;
[0071] The list generation unit is used to generate a predictive analysis list based on the vulnerability risks.
[0072] Optionally, in the above-described intranet device fingerprint processing system, the comparison unit includes:
[0073] The extraction unit is used to extract the configuration interface image of the target device from the image information and to search for the configuration image of the target device from the Internet;
[0074] An image comparison unit is used to compare whether the configuration interface image is consistent with the configuration image;
[0075] The second unit is used to, if the configuration interface image is consistent with the configuration image, use the image information of the target device as fingerprint identification information.
[0076] Optionally, in the above-described intranet device fingerprint processing system, the pattern determination unit includes:
[0077] A data acquisition unit is used to acquire baseline data of the target device from a baseline library;
[0078] A data comparison unit is used to compare the scanned data with the baseline data to determine whether there is any inconsistency in target data.
[0079] An information identification unit is used to identify abnormal information of the target device based on the target data if there is target data that is inconsistent with the baseline data;
[0080] The determining unit is used to determine the abnormal mode of the target device based on the abnormal information.
[0081] Optionally, the above-mentioned intranet device fingerprint processing system further includes:
[0082] The acquisition unit is used to acquire the predictive analysis list and the anomaly pattern;
[0083] The input unit is used to input the predictive analysis list and the anomaly pattern into the large model to obtain the security policy of the target device.
[0084] This application provides a method for processing fingerprints of intranet devices. The method involves acquiring target information of a target device from a pre-established communication link. This target information includes at least service response data, device fingerprint data, device response data sequences, scan data, and image information. Next, a large-scale model is used to identify the service response data, obtaining target identification information for the target device. Then, the large-scale model is used to perform vulnerability risk analysis on the device fingerprint data, obtaining a predictive analysis list. Following this, the large-scale model is used to perform configuration analysis on the device response data sequences, obtaining the target device's configuration information. Subsequently, the large-scale model is used to compare the image information, obtaining the target device's fingerprint confirmation information. Then, based on the scan data, the abnormal patterns of the target device are determined. The identification information, predictive analysis list, fingerprint confirmation information, and abnormal patterns are input into the large-scale model to predict attack paths. Finally, the large-scale model integrates the identification information, predictive analysis list, abnormal patterns, configuration information, and attack paths to obtain a security assessment report. By synergistically integrating cloud server technology with large-scale intelligent analysis capabilities, an overall technical architecture for fingerprint recognition and security assessment of intranet devices has been constructed. This architecture effectively solves problems such as complex deployment, low recognition accuracy, and lack of vulnerability prediction and analysis capabilities in existing technical solutions, thereby improving the efficiency of the overall security protection process. Attached Figure Description
[0085] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of this application. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.
[0086] Figure 1 This application provides a schematic diagram of the structure of a security assessment system for intranet device fingerprint recognition that integrates cloud servers and large models.
[0087] Figure 2 A flowchart illustrating a method for processing fingerprints of an intranet device, provided as another embodiment of this application;
[0088] Figure 3 A flowchart illustrating a method for acquiring target identification information according to another embodiment of this application;
[0089] Figure 4 A schematic diagram illustrating the process of generating a predictive analysis list, provided for another embodiment of this application;
[0090] Figure 5 A flowchart illustrating a method for determining fingerprint identification information according to another embodiment of this application;
[0091] Figure 6 A flowchart illustrating a method for determining an abnormal mode, provided in another embodiment of this application;
[0092] Figure 7 A flowchart illustrating a method for obtaining a security policy, provided in another embodiment of this application;
[0093] Figure 8 A schematic diagram of an execution flow provided in another embodiment of this application;
[0094] Figure 9 This is a schematic diagram of the structure of an intranet device fingerprint processing system provided in another embodiment of this application. Detailed Implementation
[0095] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0096] In this application, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0097] This application provides a method for processing fingerprints of intranet devices, applied to a security assessment system for intranet device fingerprint recognition machines that integrates cloud servers and large models. In other words, it is an intranet device fingerprint processing system to solve the problem that existing technologies reduce the efficiency of the overall security protection process.
[0098] Optionally, such as Figure 1 As shown in the figure, this application embodiment provides a security assessment system for intranet device fingerprint recognition that integrates cloud server and large model, including public network area, intranet area and analysis layer domain.
[0099] The public network area includes the cloud server (hostA): which has a public IP address and provides data forwarding, communication channel establishment, and large model interface calls.
[0100] The intranet zone includes the intranet client (hostB) and the target device (hostC).
[0101] Internal Network Client (hostB): An internal network terminal device with basic permissions, used to proxy internal network traffic.
[0102] Target device (hostC): Other devices on the internal network to be scanned and analyzed, no special configuration required.
[0103] The analysis layer domain includes the large model server (hostD, which can be deployed in conjunction with hostA): it runs large language models (such as the GPT series) and multimodal analysis models, and has functions such as in-depth data analysis, fusion and report generation.
[0104] The large model server includes a large language model analysis module, a reference data platform module, an attack path and assessment generation module, and a report and suggestion generation module.
[0105] Based on the aforementioned cloud server and large-scale model fusion security assessment system for intranet device fingerprint recognition, this application embodiment provides a method for processing intranet device fingerprints, such as... Figure 2 As shown, the specific steps include:
[0106] S201. Obtain target information of the target device from the pre-established communication link.
[0107] Specifically, first, it is necessary to ensure that the communication link has been successfully established and is stable. After the communication link is established, both the public network and the internal network send information requests to the target device. These requests typically follow specific communication protocols, such as HTTP, Modbus, MQTT, etc. After receiving the request, the target device returns the target information according to predefined protocol rules. The target information may include service response data, device fingerprint data, device response data sequence, scan data, and image information.
[0108] Optionally, before obtaining target information of the target device from a pre-established communication link, it is necessary to construct the communication link. Therefore, in this embodiment, a method for establishing a communication link is also provided, specifically including the following steps:
[0109] Obtain a secure remote connection command and execute it on the intranet client to establish a reverse tunnel between the intranet client and the cloud server.
[0110] Specifically, first obtain the SSH command (secure remote connection command) on the intranet client (hostB), and then execute the SSH command on the intranet client to establish a reverse tunnel, which is suitable for targeted scanning of the service ports of fixed target devices.
[0111] The specific SSH command is:
[0112] ssh -R portA:hostC:portC root@hostA-N where:
[0113] portA is the mapped port on the cloud server;
[0114] hostC is the internal IP address of the target device;
[0115] portC is the service port of the target device to be scanned;
[0116] root@hostA is the login credential for the cloud server;
[0117] The -N parameter indicates that remote commands should not be executed.
[0118] Configure traffic forwarding rules on the cloud server based on the reverse tunnel.
[0119] Understandably, after establishing a reverse tunnel, it's necessary to configure iptables (Linux firewall) or firewalld (newer Linux systems) on the cloud server, which are traffic forwarding rules, to forward external access requests to the mapped port A. Assume an external request accesses hostA via port A, and then is forwarded to port C of the target device (hostC) via the SSH tunnel.
[0120] Specifically, when setting iptables rules, traffic from external access port A needs to be forwarded to a local port on host A, and then forwarded through a reverse tunnel to the target device (host C) on host B.
[0121] A communication link is constructed based on reverse tunneling and traffic forwarding rules.
[0122] Understandably, after establishing a reverse tunnel and configuring traffic forwarding rules, placing the traffic forwarding rules within the reverse tunnel will allow you to obtain a communication link.
[0123] It should be noted that when you need to change the target device or port, you can do so by modifying the parameters in the SSH command: ssh -R portB:hostC:portC root@hostA -N, where hostC is the new target address.
[0124] or,
[0125] Obtain the first target secure remote connection command and the second target secure remote connection command, and execute the first target secure remote connection command on the intranet client to map the intranet client's connection service port to the cloud server.
[0126] It is understood that, in the embodiments of this application, in addition to establishing a communication link by establishing a reverse tunnel, an SSH tunnel can also be used to establish a SOCKS5 proxy service, thereby achieving more flexible intranet access control and thus obtaining a communication link.
[0127] Specifically, you need to first obtain the secure remote connection command (SSH command) for the first target and the secure remote connection command for the second target, and then execute the SSH command on the intranet client (hostB) to map the local SSH service port to the cloud server: ssh -R portA:localhost:22 root@hostA -N Where:
[0128] portA is the mapped port on the cloud server;
[0129] localhost:22 represents the SSH service mapped to an internal network client;
[0130] The -N parameter indicates that remote commands should not be executed.
[0131] Once the mapping is complete, execute the second target secure remote connection command on the cloud server to establish a proxy server and configure target traffic forwarding rules.
[0132] Understandably, after executing the first target secure remote connection command (SSH command), you need to execute the SSH command (second target secure remote connection command) on the cloud server (hostA) to establish a SOCKS5 proxy. The specific second target secure remote connection command is: ssh -D 1080 root@localhost -p portA -N, where: -D 1080 indicates that a SOCKS proxy is established on the local port 1080, -p portA specifies the port to connect to the internal network client, and the -N parameter indicates that the remote command is not executed.
[0133] After executing the second target secure remote connection command, you need to configure a traffic forwarding tool on the cloud server (hostA), which will forward network requests to the target device through a SOCKS5 proxy.
[0134] Specifically, in order to forward traffic from the SOCKS5 proxy port of the cloud server hostA to the target device (hostC), iptables forwarding rules need to be configured to ensure that traffic forwarded from the outside through the SOCKS5 proxy can correctly reach the target device.
[0135] Finally, a SOCKS5 proxy is used to connect to the target device.
[0136] On the client or other machines, you can configure a SOCKS5 proxy to forward traffic to the target device hostC through the proxy port of hostA.
[0137] For example, when using a browser, you can fill in the following in the proxy settings:
[0138] SOCKS5 proxy address: hostA, port: portA.
[0139] Alternatively, if using curl in the command line, you can use a SOCKS5 proxy with the following command:
[0140] curl --socks5 hostA:portA http: / / hostC:portC.
[0141] A communication link is constructed based on the proxy server and the target traffic forwarding rules.
[0142] Specifically, after completing the configuration, you can test whether the proxy has successfully connected to hostC by accessing hostA:portA, thereby determining whether the communication link has been successfully established. You can also use a browser or other client application to connect using the SOCKS5 proxy and check whether you can access the services on the target device normally.
[0143] In addition, when changing the target device, you only need to adjust the target address in the traffic forwarding rules.
[0144] S202. Use the large model to identify the service response data to obtain the target identification information of the target device.
[0145] Specifically, the service response data is input into a large model, which identifies information such as the target device's system and fingerprint version, and searches the network for devices with similar fingerprint features. Finally, the target device's system and fingerprint version information is fused with the information of devices with similar fingerprint features to obtain the target device's target identification information.
[0146] Optionally, in another embodiment of this application, one specific implementation of step S202 is as follows: Figure 3 As shown, the specific steps include:
[0147] S301. By calling the Internet mapping platform through the large model, the target device is identified based on the service response data to obtain identification information.
[0148] Specifically, large models are used to call the APIs of internet mapping platforms such as Shodan, FOFA, and ZoomEye. Typically, these platforms' APIs allow you to send requests and receive response data.
[0149] 3. Device Identification
[0150] Based on the data provided by the mapping platform, the large model can identify the location, type, status and other information of the target device. After successfully identifying the response data, the data can be parsed to extract the relevant identification information of the target device, such as system and fingerprint version information.
[0151] S302. Check the database to see if there is a device that matches or is similar to the identification information.
[0152] It should be noted that, in order to improve the accuracy of device identification and solve the problem of identification error from a single fingerprint database, it is necessary to search the internet database for devices that are consistent with or similar to the identification information. If a device consistent with or similar to the identification information exists in the database, then step S303 is executed. If no device consistent with or similar to the identification information exists in the database, then step S307 is executed.
[0153] S303, Obtain the device's fingerprint information.
[0154] Specifically, when a device with the same or similar identification information exists in the database, it is necessary to match and fuse the relevant information of that device with the target device to improve the accuracy of device identification. Therefore, it is necessary to obtain the fingerprint information of the device from the Internet database.
[0155] S304. Use a large model to match the identification information and fingerprint information.
[0156] Specifically, the identification and fingerprint information can be preprocessed first to remove redundancy, format, and standardize it into an analyzable form to improve matching accuracy. Then, a machine learning model can be used to predict or identify the match between the target device and the fingerprint information.
[0157] Alternatively, to improve the accuracy and intelligence of matching, one can: extract more meaningful features from the identification and fingerprint information, such as considering factors like time and environment; or use deep neural networks (such as convolutional neural networks or recurrent neural networks) to learn more complex data patterns; or continuously optimize the model based on new data and feedback to improve the accuracy of real-time matching.
[0158] S305. Determine whether the identification information and fingerprint information match successfully.
[0159] Understandably, if the identification information and fingerprint information match successfully, step S306 is executed. If the identification information and fingerprint information do not match successfully, step S307 is executed.
[0160] S306. The identification information and fingerprint information are fused using a large model to obtain the target identification information of the target device.
[0161] Specifically, when the identification information and fingerprint information are successfully matched, it means that the identification information and fingerprint information can be fused. Therefore, optionally, weighted fusion can be used: different weights are assigned to the identification information and fingerprint information respectively, and the weights are calculated based on the reliability and importance of the data.
[0162] Alternatively, multimodal fusion can be used: multimodal fusion technology can be used to merge different data sources into a unified representation, thereby obtaining target recognition information for the target device with higher accuracy.
[0163] S307. Use the identification information as the target identification information of the target device.
[0164] It is understandable that when there is no device in the database that matches or is similar to the identification information, or when the identification information and fingerprint information fail to match, it means that there are no devices with the same or similar fingerprint features on the Internet. Therefore, the identification information can only be used as the target identification information of the target device for subsequent processing.
[0165] S203. Utilize a large model to perform vulnerability risk analysis on device fingerprint data and obtain a predictive analysis list.
[0166] Understandably, in order to identify potential vulnerability risks and enhance the foresight of security assessments, this application embodiment utilizes the ability of large models to correlate device fingerprint data with historical vulnerability data, thereby enabling risk prediction of vulnerabilities.
[0167] Optionally, in another embodiment of this application, one specific implementation of step S203 is as follows: Figure 4 As shown, the specific steps include:
[0168] S401. Use a large model to search for historical vulnerabilities of the target device in the vulnerability database based on the device fingerprint data.
[0169] Understandably, large models use device fingerprint data to search for historical vulnerabilities corresponding to target devices in publicly available vulnerability databases such as CVE and CNNVD, and can also search for exploit tools such as GitHub and exploit-db. CVE (Common Vulnerabilities and Exposures) is the world's most widely used publicly available vulnerability database, providing information on known vulnerabilities in software and hardware.
[0170] CNNVD (China National Vulnerability Database): A vulnerability database specifically for cybersecurity in China, providing vulnerability information tailored to the Chinese market.
[0171] Device fingerprint data typically includes the device's hardware information (such as manufacturer, model, operating system version, etc.) and network characteristics (such as MAC address, IP address, protocol type, etc.).
[0172] Specifically, you can query these parameters through the API interfaces provided by CVE and CNNVD.
[0173] S402. Analyze historical vulnerabilities using a large model to obtain the vulnerability risks of the target device.
[0174] Specifically, historical vulnerabilities are input into a large-scale model, which can then be trained using machine learning or deep learning algorithms to automatically identify potential patterns. This large-scale model can predict potential vulnerability risks based on device characteristics and the environment. For example, based on historical data, the model can identify whether the operating system and firmware version currently used by the device are vulnerable to specific attack methods, thereby determining the vulnerability risk of the target device.
[0175] S403. Generate a predictive analysis list based on vulnerability risks.
[0176] Understandably, leveraging vulnerability risks to generate a vulnerability risk prediction and analysis list helps security teams or operations personnel understand the current vulnerability risks of a device. This list typically includes the following information:
[0177] Vulnerability type: Possible vulnerability types (such as buffer overflow, privilege escalation, etc.).
[0178] Risk level: The risk level (high, medium, low) is assessed based on the vulnerability's CVSS score and impact scope.
[0179] Vulnerability ID: Corresponding CVE number or other vulnerability identifier.
[0180] Vulnerability Description: A brief description of each vulnerability.
[0181] Patch status: Are there any available patches? Are there any mitigation measures?
[0182] Recommended actions: Provide possible fixes or mitigations for each vulnerability.
[0183] S204. Use a large model to perform configuration analysis on the device response data sequence to obtain the configuration information of the target device.
[0184] The response data sequence of the target device can come from the target device's logs, monitoring system, etc., and includes the device's operating status.
[0185] Specifically, the device response data sequence can be preprocessed first, including data cleaning: removing noise, missing values and outliers; normalization / standardization: normalizing or standardizing data of different dimensions so that large models can handle it better; and time series processing: converting the data into a time series format to ensure the continuity and consistency of the time sequence.
[0186] To better predict the specific configuration information of the device, features need to be extracted from the processed device response data sequence, such as historical data trends, periodic features, and interaction effects. Finally, the extracted features are input into a large model for configuration analysis. This model can analyze the device's hardware configuration (e.g., CPU model, memory size, hard drive configuration) and software version (e.g., operating system version, firmware version, installed software packages). By integrating this data, the configuration information of the target device can be obtained.
[0187] S205. Use a large model to compare the image information to obtain the fingerprint identification information of the target device.
[0188] Understandably, in order to improve the accuracy of fingerprint classification, large models are used to automatically identify features of image information, thereby obtaining accurate fingerprint identification information.
[0189] Optionally, in another embodiment of this application, one specific implementation of step S205 is as follows: Figure 5 As shown, the specific steps include:
[0190] S501. Extract the configuration interface image of the target device from the image information, and search for the configuration image of the target device on the Internet.
[0191] Specifically, the configuration interface image or device management page screenshot and device log text of the target device are extracted from the image information and compared with the image information of the target device on the Internet to determine whether the target device accessed is correct.
[0192] S502. Compare whether the configuration interface image is consistent with the configuration image.
[0193] Specifically, the deep learning model contained in the large model is used to complete this task, especially the visual Transformer or convolutional neural network. This model can efficiently extract the spatial features of the image and judge the similarity between the configuration interface image and the configuration image. Therefore, if the configuration interface image is consistent with the configuration image, it means that the configuration interface image and the configuration image have a high degree of similarity, so step S503 is executed.
[0194] Optionally, if the configuration interface image is inconsistent with the configuration image, it means that the similarity between the configuration interface image and the configuration image is low, that is, the target device being accessed may be incorrect. In this case, the information that the target device may be incorrect needs to be used as fingerprint identification information.
[0195] S503, The image information is described to the target device as fingerprint identification information.
[0196] Specifically, when the configuration interface image matches the configuration image, it means that the target device being accessed is correct, and therefore step S206 can be continued.
[0197] S206. Based on the scan data, determine the abnormal pattern of the target device, and input the identification information, predictive analysis list, fingerprint determination information and abnormal pattern into the large model to predict the attack path.
[0198] Understandably, before identifying abnormal patterns in the target device, the scan data can be processed to remove irrelevant information or noise. Data cleaning methods (such as imputing missing values and standardization) can be used to ensure data quality. By analyzing the processed scan data, normal and abnormal operating patterns can be identified. That is, by analyzing the target device's behavior and status, combined with the scan data, abnormal behaviors that differ from the normal pattern can be identified. Anomalies may include unauthorized access, abnormal network traffic, device configuration changes, etc. Finally, the identified information, predictive analysis list, fingerprint identification information, and abnormal patterns are used as input to a large model (such as deep neural networks, graph neural networks, etc.). This input data can be analyzed, combined with a cybersecurity knowledge base, to predict potential attack paths. The large model will predict potential attack paths based on the data analysis results and provide possible attack methods or security vulnerabilities.
[0199] Optionally, in another embodiment of this application, a specific implementation of step S206, which determines the abnormal mode of the target device based on the scan data, is as follows: Figure 6 As shown, the specific steps include:
[0200] S601. Obtain the baseline data of the target device from the baseline library.
[0201] Specifically, the first step is to establish a baseline database of devices exhibiting normal behavior. This database stores data representing devices operating without abnormalities, including network behavior, system configuration, resource usage, port open status, and service operation. By collecting data from devices under normal operating conditions, reference standards for normal behavior are established.
[0202] Baseline data collection: Collect data on normal operation from different devices and time periods, including:
[0203] System logs: such as operating system logs, application logs, network traffic logs, etc.
[0204] Device configuration data: including network configuration, service settings, port status, etc.
[0205] Port scan data: Scans open ports, service status, and other information.
[0206] Therefore, in the implementation of this application, it is necessary to obtain the baseline data of the target device from the baseline library in advance, so as to determine whether the target device is experiencing any abnormalities.
[0207] S602. Compare the scan data with the baseline data to determine if there are any discrepancies in the target data.
[0208] Understandably, this involves periodically or in real-time scanning of device configurations and status to obtain data such as port openness, service versions, and network traffic. The scanned data is then compared with data in a baseline database to identify inconsistencies. For example, abnormal settings might be found in the device's configuration file, incorrectly configured service ports, or the target device opening infrequently used or high-risk ports. Furthermore, the comparison might reveal sensitive information (such as passwords or keys) leaked in inappropriate places. In essence, the scanned data is compared with baseline data reflecting normal behavior to determine if any anomalies exist.
[0209] If the scan data and the baseline data are inconsistent with the target data, it indicates that the target device is malfunctioning, so step S603 is executed.
[0210] Optionally, if the scan data and the baseline data show consistent target data, it indicates that the target device is not abnormal. In this case, the large model can be used to integrate the identification information, predictive analysis list, and configuration information to obtain a security assessment report for the target device.
[0211] S603. Identify abnormal information of the target device based on the target data.
[0212] Specifically, when there are discrepancies between the scanned data and the baseline data, it is necessary to conduct a comprehensive analysis by combining multiple indicators, such as system resources, service status, network traffic, and file changes, in order to identify the target data and thus detect any abnormalities in the target device.
[0213] S604. Based on the abnormal information, determine the abnormal mode of the target device.
[0214] Understandably, integrating the identified anomaly information allows us to determine the target's anomaly patterns. For example: performance anomalies: a sudden surge in CPU or memory usage may indicate malware operation or an attack on the device; port anomalies: if an infrequently used port is open, or an unauthorized port is accidentally enabled, it may signify a security vulnerability or attack; service anomalies: the sudden appearance of a new service or the abnormal termination of an existing service may be due to attacker intrusion or system misconfiguration; network anomalies: including abnormal traffic, packet loss, and IP address changes, may indicate that the device is being remotely controlled or is under DDoS attack; log anomalies: a large number of errors, failed login attempts, or other abnormal activity in the logs usually indicate a security incident; abnormal configuration changes: unauthorized changes to the device's configuration files may indicate that attackers are exploiting vulnerabilities to modify the configuration for further attacks.
[0215] S207. By integrating identification information, predictive analysis lists, abnormal patterns, configuration information, and attack paths using a large model, a security assessment report is obtained.
[0216] Specifically, the large language model has the characteristic of automatically integrating information and analyzing data, and can generate easy-to-understand and specific security assessment reports. Furthermore, the security assessment reports are interactive, allow online personalization of analysis details, and are automatically generated to be authoritative and easy for users to read. Therefore, in this embodiment of the application, the large language model will be used to integrate and analyze the above-mentioned identification information, predictive analysis list, abnormal patterns, configuration information, and attack paths to obtain a security assessment report.
[0217] Optionally, in another embodiment of this application, after obtaining the predictive analysis list and abnormal patterns, targeted security alert strategies and preventative measures can be generated. Therefore, another embodiment of this application provides a method for generating security strategies, such as... Figure 7 As shown, the specific steps include:
[0218] S701. Obtain the list of predictive analysis and anomaly patterns.
[0219] S702. Input the predictive analysis list and anomaly patterns into the large model to obtain the security policy of the target device.
[0220] Specifically, before inputting the predictive analytics list and anomaly patterns into the large model, the predictive analytics list and anomaly patterns can be converted into a format that the machine learning model can process, typically numerical and structured data. For example, the predictive analytics list might include historical trend data for devices (such as CPU utilization, memory leaks, abnormal network traffic, etc.) and the system's risk level.
[0221] Abnormal patterns: Characteristics associated with potential attacks, such as abnormal network traffic, high CPU usage, and memory leaks.
[0222] The transformed predictive analytics list and anomaly patterns are then input into a large model (such as a deep learning model, machine learning classifier, or predictive model) for analysis. The large model processes the input data to generate a security policy suitable for the target device. This security policy typically includes the following:
[0223] Patch management: Provides recommendations for patches and updates for known vulnerabilities.
[0224] Security configurations include closing unnecessary ports, strengthening access control, and enhancing authentication mechanisms.
[0225] Network monitoring: It is recommended to enable stricter network traffic monitoring, especially alerts and response measures for abnormal traffic.
[0226] Anomaly detection: Configure more automated security alerts and protection strategies to detect potential attack patterns, such as memory leaks and abnormal CPU usage.
[0227] Intrusion Detection and Prevention: Enhance Intrusion Detection System (IDS) and firewall configurations to prevent malicious traffic.
[0228] For ease of understanding, the fingerprint processing procedure for the intranet device in this application can be described below as an execution flow. Please refer to [link / reference]. Figure 8 .
[0229] This application provides a method for processing fingerprints of intranet devices. The method involves acquiring target information of a target device from a pre-established communication link. This target information includes at least service response data, device fingerprint data, device response data sequences, scan data, and image information. Next, a large-scale model is used to identify the service response data, obtaining target identification information for the target device. Then, the large-scale model is used to perform vulnerability risk analysis on the device fingerprint data, obtaining a predictive analysis list. Following this, the large-scale model is used to perform configuration analysis on the device response data sequences, obtaining the target device's configuration information. Subsequently, the large-scale model is used to compare the image information, obtaining the target device's fingerprint confirmation information. Then, based on the scan data, the abnormal patterns of the target device are determined. The identification information, predictive analysis list, fingerprint confirmation information, and abnormal patterns are input into the large-scale model to predict attack paths. Finally, the large-scale model integrates the identification information, predictive analysis list, abnormal patterns, configuration information, and attack paths to obtain a security assessment report. By synergistically integrating cloud server technology with large-scale intelligent analysis capabilities, an overall technical architecture for fingerprint recognition and security assessment of intranet devices has been constructed. This architecture effectively solves problems such as complex deployment, low recognition accuracy, and lack of vulnerability prediction and analysis capabilities in existing technical solutions, thereby improving the efficiency of the overall security protection process.
[0230] Another embodiment of this application provides a fingerprint processing system for intranet devices, such as... Figure 9 As shown, it includes the following units:
[0231] The information acquisition unit 901 is used to acquire target information of the target device from a pre-established communication link. The target information includes at least service response data, device fingerprint data, device response data sequence, scan data, and image information.
[0232] The identification unit 902 is used to identify the service response data using a large model to obtain the target identification information of the target device.
[0233] Vulnerability analysis unit 903 is used to perform vulnerability risk analysis on device fingerprint data using a large model to obtain a predictive analysis list.
[0234] Configuration analysis unit 904 is used to perform configuration analysis on the device response data sequence using a large model to obtain the configuration information of the target device.
[0235] The comparison unit 905 is used to compare image information using a large model to obtain fingerprint identification information of the target device.
[0236] The pattern determination unit 906 is used to determine the abnormal pattern of the target device based on the scan data, and input the identification information, predictive analysis list, fingerprint determination information and abnormal pattern into the large model to predict the attack path.
[0237] Integration unit 907 is used to integrate identification information, predictive analysis list, abnormal patterns, configuration information and attack paths using a large model to obtain a security assessment report.
[0238] It should be noted that the specific working process of the above modules in the embodiments of this application can be referred to steps S101 to S107 in the above method embodiments, and will not be repeated here.
[0239] Optionally, another embodiment of this application provides a fingerprint processing system for intranet devices, which further includes:
[0240] The first command acquisition unit is used to acquire secure remote connection commands and execute secure remote connection commands on the intranet client to establish a reverse tunnel between the intranet client and the cloud server.
[0241] The rule configuration unit is used to configure traffic forwarding rules on the cloud server based on the reverse tunnel.
[0242] The first building unit is used to build communication links based on reverse tunneling and traffic forwarding rules.
[0243] or,
[0244] The second command acquisition unit is used to acquire the first target secure remote connection command and the second target secure remote connection command, and execute the first target secure remote connection command on the intranet client to map the connection service port of the intranet client to the cloud server.
[0245] The execution unit is used to execute the second target secure remote connection command on the cloud server after the mapping is completed, in order to establish the proxy server and configure the target traffic forwarding rules.
[0246] The second building unit is used to construct communication links based on proxy servers and target traffic forwarding rules.
[0247] Optionally, in another embodiment of this application, a fingerprint processing system for an intranet device includes an identification unit 902 comprising:
[0248] The identification subunit is used to identify the target device based on the service response data by calling the Internet mapping platform through the large model, and obtain identification information.
[0249] The first search unit is used to search the database for devices that are consistent with or similar to the identification information.
[0250] The fingerprint acquisition unit is used to acquire the fingerprint information of a device if a device with the same or similar identification information exists in the database.
[0251] The matching unit is used to match identification information and fingerprint information using a large model.
[0252] The fusion unit is used to fuse the identification information and fingerprint information using a large model if the identification information and fingerprint information match successfully, so as to obtain the target identification information of the target device.
[0253] The first unit is used to use the identification information as the target identification information of the target device if there is no device in the database that is consistent with or similar to the identification information, or if the identification information and fingerprint information fail to match.
[0254] Optionally, in another embodiment of this application, a vulnerability analysis unit 903 in an intranet device fingerprinting system includes:
[0255] The second search unit is used to search for historical vulnerabilities of the target device from the vulnerability database based on the device fingerprint data using a large model.
[0256] The analysis unit is used to analyze historical vulnerabilities using a large model to obtain the vulnerability risks of the target device.
[0257] The list generation unit is used to generate a predictive analysis list based on vulnerability risks.
[0258] Optionally, in another embodiment of this application, a fingerprint processing system for an intranet device includes a comparison unit 905 comprising:
[0259] The extraction unit is used to extract the configuration interface image of the target device from the image information and to search for the configuration image of the target device from the Internet.
[0260] The image comparison unit is used to compare whether the configuration interface image is consistent with the configuration image.
[0261] The second unit is used to, if the configuration interface image is consistent with the configuration image, describe the image information of the target device as fingerprint identification information.
[0262] Optionally, in another embodiment of this application, a fingerprint processing system for an intranet device includes a pattern determination unit 906, comprising:
[0263] The data acquisition unit is used to acquire baseline data of the target device from the baseline library.
[0264] The data comparison unit is used to compare the scanned data with the baseline data to see if there are any discrepancies in the target data.
[0265] The information identification unit is used to identify abnormal information of the target device based on the target data if there is a discrepancy between the scanned data and the baseline data.
[0266] The determination unit is used to determine the abnormal mode of the target device based on the abnormal information.
[0267] Optionally, another embodiment of this application provides a fingerprint processing system for intranet devices, which further includes:
[0268] The acquisition unit is used to obtain the list of predictive analytics and anomaly patterns.
[0269] The input unit is used to input the predictive analysis list and anomaly patterns into the large model to obtain the security policy of the target device.
[0270] It should be noted that the specific working process of each module provided in the above embodiments of this application can be referred to the corresponding steps in the above method embodiments, and will not be repeated here.
[0271] It should also be noted that the intranet device fingerprint processing system provided in this application has the technical effects of any of the above embodiments, and will not be described in detail here.
[0272] Those skilled in the art will further recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0273] The above description of the disclosed embodiments enables those skilled in the art to make or use this application. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of this application. Therefore, this application is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A method for processing fingerprints on intranet devices, characterized in that, include: Target information of the target device is obtained from a pre-established communication link; wherein the target information includes at least service response data, device fingerprint data, device response data sequence, scan data, and image information. The target identification information of the target device is obtained by using a large model to identify the service response data. The large model is used to perform vulnerability risk analysis on the device fingerprint data to obtain a predictive analysis list. The configuration information of the target device is obtained by performing configuration analysis on the device response data sequence using the large model. The image information is compared using the large model to obtain the fingerprint identification information of the target device; Based on the scan data, the abnormal pattern of the target device is determined, and the identification information, the predictive analysis list, the fingerprint determination information, and the abnormal pattern are input into the large model to predict the attack path; The large model is used to integrate the identification information, the predictive analysis list, the anomaly patterns, the configuration information, and the attack paths to obtain a security assessment report.
2. The method according to claim 1, characterized in that, The method for establishing the communication link includes: Obtain a secure remote connection command and execute the secure remote connection command on the intranet client to establish a reverse tunnel between the intranet client and the cloud server; Based on the reverse tunnel, configure traffic forwarding rules on the cloud server; A communication link is constructed based on the reverse tunnel and the traffic forwarding rules; or, Obtain a first target secure remote connection command and a second target secure remote connection command, and execute the first target secure remote connection command on the intranet client to map the connection service port of the intranet client to the cloud server; Once the mapping is complete, execute the second target secure remote connection command on the cloud server to establish a proxy server and configure target traffic forwarding rules; A communication link is constructed based on the proxy server and the target traffic forwarding rules.
3. The method according to claim 1, characterized in that, The process of using a large model to identify the service response data to obtain target identification information for the target device includes: The target device is identified by calling an internet mapping platform based on the service response data using a large model, and identification information is obtained. Search the database to see if there is a device that matches or is similar to the identification information; If a device with the same or similar identification information exists in the database, then the fingerprint information of that device is obtained; The identification information and the fingerprint information are matched using the large model; If the identification information and the fingerprint information match successfully, the identification information and the fingerprint information are fused using the large model to obtain the target identification information of the target device; If no device with the same or similar identification information exists in the database, or if the identification information and the fingerprint information fail to match, then the identification information will be used as the target identification information of the target device.
4. The method according to claim 1, characterized in that, The method of using the large model to perform vulnerability risk analysis on the device fingerprint data to obtain a predictive analysis list includes: Using the large model, historical vulnerabilities of the target device are searched from the vulnerability database based on the device fingerprint data; The historical vulnerabilities are analyzed using the large model to obtain the vulnerability risks of the target device; Based on the aforementioned vulnerability risks, a predictive analysis list is generated.
5. The method according to claim 1, characterized in that, The step of comparing the image information using the large model to obtain the fingerprint identification information of the target device includes: Extract the configuration interface image of the target device from the image information, and search for the configuration image of the target device from the Internet; Compare whether the configuration interface image is consistent with the configuration image; If the configuration interface image is consistent with the configuration image, then the image information is used as the fingerprint identification information of the target device.
6. The method according to claim 1, characterized in that, The step of determining the abnormal mode of the target device based on the scan data includes: Obtain the baseline data of the target device from the baseline library; Compare the scan data with the baseline data to determine if there are any inconsistencies in the target data. If there are target data that are inconsistent with the baseline data, then the abnormal information of the target device is identified based on the target data; Based on the anomaly information, the anomaly mode of the target device is determined.
7. The method according to claim 1, characterized in that, Also includes: Obtain the predictive analysis list and the anomaly pattern; The predictive analysis list and the anomaly patterns are input into the large model to obtain the security policy of the target device.
8. A fingerprint processing system for intranet devices, characterized in that, include: An information acquisition unit is used to acquire target information of a target device from a pre-established communication link; wherein the target information includes at least service response data, device fingerprint data, device response data sequence, scan data, and image information; The identification unit is used to identify the service response data using a large model to obtain the target identification information of the target device; The vulnerability analysis unit is used to perform vulnerability risk analysis on the device fingerprint data using the large model to obtain a predictive analysis list. The configuration analysis unit is used to perform configuration analysis on the device response data sequence using the large model to obtain the configuration information of the target device. The comparison unit is used to compare the image information using the large model to obtain the fingerprint identification information of the target device; The pattern determination unit is used to determine the abnormal pattern of the target device based on the scan data, and input the identification information, the predictive analysis list, the fingerprint determination information and the abnormal pattern into the large model to predict the attack path; The integration unit is used to integrate the identification information, the predictive analysis list, the anomaly patterns, the configuration information, and the attack paths using the large model to obtain a security assessment report.
9. The system according to claim 8, characterized in that, Also includes: The first command acquisition unit is used to acquire a secure remote connection command and execute the secure remote connection command on the intranet client to establish a reverse tunnel between the intranet client and the cloud server. The rule configuration unit is used to configure traffic forwarding rules on the cloud server according to the reverse tunnel; The first construction unit is used to construct a communication link based on the reverse tunnel and the traffic forwarding rules; or, The second command acquisition unit is used to acquire the first target secure remote connection command and the second target secure remote connection command, and execute the first target secure remote connection command on the intranet client to map the connection service port of the intranet client to the cloud server; An execution unit is used to execute the second target secure remote connection command on the cloud server after the mapping is completed, so as to establish a proxy server and configure target traffic forwarding rules; The second construction unit is used to construct a communication link based on the proxy server and the target traffic forwarding rules.
10. The system according to claim 8, characterized in that, The identification unit includes: The identification subunit is used to call the Internet mapping platform through the large model to identify the target device based on the service response data and obtain identification information; The first search unit is used to search the database for a device that is consistent with or similar to the identification information. The fingerprint acquisition unit is used to acquire the fingerprint information of the device if a device that is consistent with or similar to the identification information exists in the database. A matching unit is used to match the identification information and the fingerprint information using the large model; The fusion unit is used to fuse the identification information and the fingerprint information using the large model if the identification information and the fingerprint information match successfully, so as to obtain the target identification information of the target device. The first unit is configured to use the identification information as the target identification information of the target device if there is no device in the database that is consistent with or similar to the identification information, or if the identification information and the fingerprint information fail to match.
Citation Information
Patent Citations
Rapid vulnerability scanning method and system based on asset categories
CN110321708A
Intranet risk asset identification method and device based on flow, and related equipment
CN115603954A