Network security evaluation method and device

Through multiple rounds of verification mechanisms, the problem of incomplete security evaluation caused by shadow assets in the enterprise network is solved, accurate screening and security evaluation of network equipment is achieved, and the reliability of network security management is improved.

CN120474812AActive Publication Date: 2025-08-12GUONENG (HUIZHOU) THERMAL POWER CO LTD
View PDF 9 Cites 0 Cited by

Patent Information

Application Number
CN202510770671.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-10
Publication Date
2025-08-12
Estimated Expiration
2045-06-10

AI Technical Summary

Technical Problem

There are a large number of shadow assets in the enterprise network, resulting in incomplete and timely evaluation of network security, affecting network security management.

Method used

Using multiple rounds of verification mechanism, a preliminary identity screening is performed by generating a first verification fingerprint, distinguishing the first network device from the second network device, and then generating the second verification fingerprint for further verification, identifying the equipment to be matched and the shadow device, and integrating all device information for security evaluation.

Benefits of technology

It improves the reliability of network security evaluation, can timely discover and locate shadow devices, provide comprehensive and accurate network security status assessment, and provides a reliable basis for network security management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120474812A_ABST
    Figure CN120474812A_ABST
Patent Text Reader

Abstract

The invention provides a network security evaluation method and device, and belongs to the field of network security evaluation, and the method comprises the steps: responding to a received security evaluation instruction, and transmitting a first verification fingerprint to all network devices connected with a server; respectively matching the identity verification information fed back by each network device with each standard identity information in a standard identity library in sequence; in response to existence of the second network equipment, sending the second verification fingerprint to all the second network equipment; marking the second network device which feeds back the preset verification information as a device to be matched, and marking the second network device which does not feed back the preset verification information as a shadow device; and performing network security evaluation according to the information of all the first network devices, the information of all the to-be-matched devices and the information of all the shadow devices. According to the network security evaluation method and device provided by the invention, the reliability of network security evaluation can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application belongs to the technical field of network security evaluation, and more specifically, relates to a network security evaluation method and device. Background Art

[0002] Network security assessments play a crucial role in enterprise network security. Based on the results, enterprises can develop different network protection strategies to effectively safeguard their network assets. As enterprise networks become increasingly digital, digital assets continue to grow, and the number of electronic devices outside of enterprise control continues to increase, leading to a growing number of shadow assets.

[0003] Shadow assets may make it difficult for enterprises to make comprehensive and timely network security assessments, which will have an impact on the enterprise's network security. In serious cases, it may cause losses to the enterprise's network assets. Summary of the Invention

[0004] The purpose of this application is to provide a network security evaluation method and device to improve the reliability of network security evaluation and maintain network security.

[0005] In a first aspect of an embodiment of the present application, a network security evaluation method is provided, which is applied to a server and includes: In response to receiving the security evaluation instruction, generating a first verification fingerprint, and sending the first verification fingerprint to all network devices connected to the server, the first verification fingerprint being used to instruct each network device to feedback identity authentication information; Matching the identity authentication information fed back by each network device with each standard identity information in the standard identity library in sequence, marking the network device that matches the standard identity library as a first network device, and marking the network device that does not match the standard identity library as a second network device; In response to the existence of the second network device, a second verification fingerprint is generated and sent to all the second network devices, where the second verification fingerprint is used to instruct each second network device to feedback preset verification information; the second network device that feedbacks the preset verification information is marked as a device to be matched, and the second network device that does not feedback the preset verification information is marked as a shadow device; A network security evaluation is performed based on the information of all first network devices, the information of all devices to be matched, and the information of all shadow devices.

[0006] A second aspect of the embodiments of the present application provides a network security evaluation device, applied to a server, comprising: A first verification module is configured to generate a first verification fingerprint in response to receiving a security evaluation instruction, and send the first verification fingerprint to all network devices connected to the server, wherein the first verification fingerprint is used to instruct each network device to feedback identity authentication information; A second verification module is used to match the identity authentication information fed back by each network device with each standard identity information in the standard identity library in sequence, mark the network device that matches the standard identity library as a first network device, and mark the network device that does not match the standard identity library as a second network device; a third verification module, configured to generate a second verification fingerprint in response to the presence of a second network device, and send the second verification fingerprint to all second network devices, wherein the second verification fingerprint is used to instruct each second network device to feedback preset verification information; mark the second network device that feedbacks the preset verification information as a to-be-matched device, and mark the second network device that does not feedback the preset verification information as a shadow device; The security evaluation module is used to perform network security evaluation based on the information of all first network devices, the information of all devices to be matched, and the information of all shadow devices.

[0007] According to a third aspect of an embodiment of the present application, an electronic device is provided, including a memory, a processor, and a computer program stored in the memory and running on the processor, wherein the processor implements the steps of the above-mentioned network security evaluation method when executing the computer program.

[0008] According to a fourth aspect of the embodiments of the present application, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the above-mentioned network security evaluation method are implemented.

[0009] In a fifth aspect of the embodiments of the present application, a computer program product is provided, including a computer program or computer executable instructions. When the computer program or computer executable instructions are executed by a processor, the steps of the above-mentioned network security evaluation method are implemented.

[0010] The network security evaluation method and device provided by the embodiments of the present application have the following beneficial effects: The embodiment of the present application effectively improves the reliability of network security evaluation through a multi-round verification mechanism. First, a first verification fingerprint is generated to perform preliminary identity screening on network devices, distinguishing the first network device from the second network device, and realizing preliminary security filtering of the devices. Then, a second verification fingerprint is generated for the second network device to further verify its legitimacy, accurately identifying the device to be matched and the shadow device. Through a layered verification method, the identity of the device is checked layer by layer, avoiding the limitations of a single verification, and being able to timely discover and locate security risks such as shadow devices. Finally, all device information is integrated to perform a security evaluation, so that the evaluation results can more comprehensively and accurately reflect the network security status, providing a reliable basis for network security management. BRIEF DESCRIPTION OF THE DRAWINGS

[0011] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the embodiments or descriptions of the prior art. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0012] Figure 1 A flowchart of a network security evaluation method provided in one embodiment of the present application; Figure 2 A structural block diagram of a network security evaluation device provided in one embodiment of the present application; Figure 3 A schematic block diagram of an electronic device provided in one embodiment of the present application. DETAILED DESCRIPTION

[0013] In the following description, specific details such as specific system structures and techniques are provided for purposes of illustration rather than limitation to facilitate a thorough understanding of the embodiments of the present application. However, it will be apparent to those skilled in the art that the present application may be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to avoid obscuring the description of the present application with unnecessary detail.

[0014] In order to make the purpose, technical solutions and advantages of this application clearer, specific embodiments will be described below with reference to the accompanying drawings.

[0015] Please refer to Figure 1 , Figure 1 A flowchart of a network security evaluation method provided in an embodiment of the present application can be applied to a server. The method may include S101 to S104.

[0016] S101 , in response to receiving a security evaluation instruction, generating a first verification fingerprint, and sending the first verification fingerprint to all network devices connected to the server, the first verification fingerprint being used to instruct each network device to feedback identity authentication information.

[0017] In an embodiment of the present application, upon receiving a "Start Network Security Assessment" instruction, the server can generate a "digital token," also known as a first verification fingerprint, for device identity verification. This instruction can be generated by an administrator clicking a security assessment button, or by a periodic scheduled task triggering the generation of a security assessment instruction. The security assessment instruction in the embodiment of the present application is used to perform a network security assessment on the network system in which the server resides.

[0018] After generating the corresponding first verification fingerprint, the server can send the first verification fingerprint as a "digital token" to all network devices connected to the server through network broadcasting or targeted push.

[0019] In an embodiment of the present application, the first verification fingerprint includes a network verification rule, which requires each network device to reply with an "electronic receipt" containing its own identity characteristics after receiving it, so as to prove that the network device is an authorized asset of the enterprise where the server is located, so as to avoid being judged as a shadow asset.

[0020] Generally speaking, network devices that return correct authentication information are usually authorized assets of the enterprise, and network devices that return incorrect or no authentication information may be shadow devices. The first round of verification can preliminarily identify shadow devices and suspected shadow devices.

[0021] Exemplarily, the first verification fingerprint may include the following verification fields: verification timestamp, enterprise unique identifier, encryption challenge code, and verification algorithm identifier.

[0022] S102, matching the identity authentication information fed back by each network device with each standard identity information in the standard identity library in sequence, marking the network device that matches the standard identity library as a first network device, and marking the network device that does not match the standard identity library as a second network device.

[0023] In the embodiments of this application, the standard identity library serves as a "digital ID ledger" for an enterprise's authorized assets. Data sources may include: registered device information in the configuration management database, manually entered special assets, and device identity information verified in historical security assessments. By standardizing device identity information from these various data sources, the standard identity information corresponding to each device in the standard identity library can be obtained.

[0024] The embodiment of the present application can perform vector extraction on the authentication information fed back by each network device to obtain an identity feature vector characterized by the MAC address, system version, and positive fingerprint.

[0025] The obtained device identity feature vector is then compared to the feature vector corresponding to the standard identity information in the system. If a device with standard identity information highly similar to the network device exists, the network device is determined to be the first network device. If no device with standard identity information highly similar to the network device exists, the network device is determined to be the second network device.

[0026] In the embodiment of the present application, different similarity thresholds can be set for network devices in different areas.

[0027] For high-risk areas, the similarity threshold can be set to 0.9 for strict matching, preventing malicious shadow devices from forging departmental features. For office areas, the similarity threshold can be set to 0.7 for fuzzy matching, allowing for misidentification of network devices due to normal upgrades. For IoT areas, the similarity threshold can be set to 0.5 for loose matching, allowing for more missing features given the limited computing power of industrial equipment. The specific similarity threshold can be set based on actual circumstances.

[0028] S103, in response to the existence of the second network device, generate a second verification fingerprint, and send the second verification fingerprint to all the second network devices, the second verification fingerprint is used to instruct each second network device to feedback preset verification information; mark the second network device that feedbacks the preset verification information as a device to be matched, and mark the second network device that does not feedback the preset verification information as a shadow device.

[0029] When the embodiment of the present application determines that a second network device exists, a secondary verification process can be initiated. While avoiding misjudgment of some second network devices, a more stringent verification can be performed through preset information to identify highly concealed shadow devices.

[0030] In the embodiments of this application, the second verification fingerprint includes a specific field associated with pre-set information, which points to the location of the verification information pre-stored on the device. This field allows legitimate devices to quickly locate the pre-set information and provide timely feedback, while unauthorized devices, which may not have pre-stored information, are unable to respond, effectively identifying shadow devices.

[0031] Optionally, for legitimate network devices, pre-set authentication information can be stored through hardware storage, software storage, or cloud connection. Specific settings can be made based on actual conditions.

[0032] For example, a legitimate device that fails a verification may be a newly purchased notebook that has not yet entered CMBD information. During a verification, it is marked as a second network device because its MAC address is not in the standard identity library.

[0033] Secondary verification process: The server sends the second verification fingerprint (including pre_verify_id=20250530); The device extracts the pre-installed enterprise purchase certificate (including the device serial number and MAC address hash value) from the TPM chip and responds after encryption. The server compares the preset information with the procurement system records, confirms the legitimacy of the equipment, marks it as "the first network equipment to be reported", and automatically creates an asset entry work order.

[0034] Secondary verification of a suspected shadow device. The IP address of this device was marked as a secondary network device during the first verification because the certificate was not issued by the enterprise CA.

[0035] Secondary verification process: The server sends the second verification fingerprint (including pre_verify_id=20250530); The device does not respond (because no verification information is preset); The server sends the fingerprint again with a different pre_verify_id, but still no response. The system identifies it as a shadow device and blocks access through the firewall, triggering the threat hunting process (such as analyzing the IP's historical traffic for data leakage). S104: Perform network security evaluation based on the information of all first network devices, the information of all devices to be matched, and the information of all shadow devices.

[0036] After obtaining the classification of each network device, network security evaluation can be performed according to the following methods: S1041, statistics on the proportion of each type of equipment classification.

[0037] S1042: Calculate the risk value of a single device. The device risk score can be determined based on the device type, vulnerability severity, and threat intelligence.

[0038] S1043: Determine the service relevance. Different weight coefficients may be assigned based on the importance of the services carried by the device.

[0039] S1044 , the score of each device may be calculated based on the information of different devices.

[0040] S1045: Set weights and calculate basic scores. Weights can be assigned based on the importance of the equipment.

[0041] Basic score = first device score * weight 1 + to-be-matched device score * weight 2 + shadow device score * weight 3.

[0042] S1046, normalize the total benchmark score to 0-100 points.

[0043] Total benchmark score = 100 * (weight 1 + weight 2 + weight 3) = 100 points Final network score = (basic score / total benchmark score) * 100.

[0044] Alternatively, after obtaining the classification of each network device, network security evaluation can also be performed according to the following method: Extracting the security dimension from the information of each first network device, determining a security score for each first network device based on the security dimension and the first weight, and summing the scores to obtain a first security score; Extracting the security dimension from the information of each device to be matched, determining a security score for each device to be matched based on the security dimension and the second weight, and summing the scores to obtain a second security score; Determine the criticality scores of all shadow devices based on the device type and number of each shadow device, and sum them up to obtain the target criticality score; The network security score is determined based on the first security score, the second security score and the target risk score.

[0045] The sum of the first security score and the second security score is calculated, the difference between the sum and the target hazard score is calculated, and the ratio of the difference to the number of all network devices is calculated as the network security score.

[0046] The embodiment of the present application effectively improves the reliability of network security evaluation through a multi-round verification mechanism. First, a first verification fingerprint is generated to perform preliminary identity screening on network devices, distinguishing the first network device from the second network device, and realizing preliminary security filtering of the devices. Then, a second verification fingerprint is generated for the second network device to further verify its legitimacy, accurately identifying the device to be matched and the shadow device. Through a layered verification method, the identity of the device is checked layer by layer, avoiding the limitations of a single verification, and being able to timely discover and locate security risks such as shadow devices. Finally, all device information is integrated to perform a security evaluation, so that the evaluation results can more comprehensively and accurately reflect the network security status, providing a reliable basis for network security management.

[0047] In some embodiments of the present application, the security evaluation instruction includes a first instruction and a second instruction, the first instruction is a periodic instruction, the second instruction is an external trigger instruction, and the first instruction and the second instruction are not generated at the same time; In response to receiving the security evaluation instruction, generating a first verification fingerprint includes: In response to receiving the first instruction, generating, according to an instruction cycle of the first instruction, a verification message including arranging the plurality of verification features in a first order, and marking the message as a first verification fingerprint; In response to receiving the second instruction, generating, according to the instruction authority of the second instruction, a verification message including arranging the plurality of verification features in a second order, and marking the verification message as a first verification fingerprint; Among them, the first order is different from the second order.

[0048] Specifically, the multiple verification features include at least two of the following features: a protocol feature, a port feature, a version feature, a service feature, and an address feature.

[0049] In an embodiment of the present application, the first instruction is a periodic instruction, which can be a security assessment instruction automatically triggered at a preset time period (such as daily / weekly) and used for normalized asset detection. For example, an enterprise sets the start of network-wide device verification at 2 a.m. every Monday.

[0050] The first instruction is used to instruct the corresponding network device to generate verification messages at a fixed period, and arrange verification features such as the device MAC address, IP, certificate fingerprint, etc. in the "first order" (such as the preset standard field order) to ensure the consistency of normalized detection.

[0051] The second instruction is an external trigger instruction, which is activated by an external event (such as manual triggering or security event alarm) and has higher authority. For example, after the security team discovers suspicious traffic, they manually send a verification instruction through the management platform.

[0052] The second instruction is used to instruct the corresponding network device to adjust the feature arrangement order ("second order") according to the instruction authority level, such as prioritizing the verification of certificate fingerprints and business relevance features of devices in high-risk areas to improve the targetedness of emergency detection.

[0053] In the embodiment of the present application, the first instruction or the second instruction can be identified by an instruction type identifier (such as the instruction header field type=periodic or type=trigger) to avoid simultaneous generation conflicts. For example, the first instruction is triggered periodically by the task scheduler, and the second instruction is manually activated through the API interface or management interface.

[0054] In this embodiment, a verification feature set (including 10+ features such as MAC address, IP address, certificate fingerprint, and business relevance) is pre-set, and feature sorting rules are configured for different instruction types. For example, the first instruction can be sorted in the order of "MAC → IP address → certificate", while the second instruction can be sorted in the order of "certificate → business relevance → MAC" (high-privilege instructions prioritize core security features).

[0055] In an embodiment of the present application, upon receiving the first instruction, the network device may retrieve the feature set according to a periodic rule and assemble it into a verification message (e.g., MAC|IP|certificate|...) in a first order, marking it as a first verification fingerprint. Upon receiving the second instruction, the network device may filter the features by permission level (e.g., selecting only high-risk features) and arrange them in a second order to generate a differentiated first verification fingerprint.

[0056] The first instruction in the embodiment of the present application is applicable to daily security inspections (such as weekly verification of office equipment), and the second instruction is applicable to emergency response (such as prioritizing verification of core server certificates in the event of a ransomware incident), achieving "normalization + emergency" dual-mode coverage, improving verification security, and reducing the harm of covert intrusion.

[0057] In some embodiments of the present application, each standard identity information in the standard identity library is a standard identity vector; The authentication information fed back by each network device is matched with each standard identity information in the standard identity library, including: Perform feature restoration on the authentication information fed back by each network device to obtain the verification feature vector of each network device; Perform time series transformation on each verification feature vector to obtain a verification feature vector with the same dimension as the standard identity vector; The verification feature vectors that are consistent with the dimension of the standard identity vectors are matched with each standard identity vector respectively.

[0058] In some embodiments of the present application, marking a network device that matches a standard identity library as a first network device and marking a network device that does not match the standard identity library as a second network device includes: For each network device, if there is a standard identity vector corresponding to the network device whose verification feature vector has the same dimension as the standard identity vector and whose similarity is greater than or equal to a preset similarity, then the network device is determined to be marked as the first network device; For each network device, if there is a verification feature vector corresponding to the network device and having the same dimension as the standard identity vector and a standard identity vector whose similarity is less than a preset similarity, the network device is determined to be marked as the second network device.

[0059] In an embodiment of the present application, each device identity information in the standard identity library can be abstracted into a multi-dimensional feature vector (such as a coordinate point composed of features such as MAC address, IP, certificate fingerprint, etc.). For example, the standard identity vector of a server is [MAC_001A2B, IP_192.168.1.1, Cert_Fingerprint_A1B2].

[0060] This embodiment of the present application can also parse the verification information fed back by the device into raw feature values (e.g., extracting fields such as MAC address and IP address). This restored content can then be time-sequenced, adjusting the order of the verification features to align their dimensions with the standard identity vector (e.g., a standard vector is arranged in the order of "MAC → IP → Certificate"; the verification vector must be converted to the same order).

[0061] Optionally, you can determine the legitimacy of the device by calculating the similarity between the verification feature vector and the standard identity vector (such as cosine similarity or Euclidean distance), and set a preset similarity threshold (such as 0.8) as the basis for classification.

[0062] Exemplarily, if the similarity is ≥ 0.8, it is marked as the first network device (legal asset).

[0063] If the similarity is less than 0.8, it is marked as the second network device (asset to be verified).

[0064] The embodiment of the present application converts the unified vector dimension to avoid misjudgment caused by different feature orders (for example, the device feedback reports IP first and MAC later, which is consistent with the standard vector order after conversion), thereby reducing the misjudgment rate.

[0065] In embodiments of the present application, the preset similarity threshold can also be adjusted based on the occurrence of a security incident. When a shadow device is detected as causing a security incident, the preset similarity threshold can be adjusted from a first similarity threshold to a second similarity threshold, with the first similarity threshold being greater than the second similarity threshold, to increase sensitivity to suspicious devices. For example, the threshold can be reduced from 70% to 60%.

[0066] In this embodiment, when new services are launched (such as deploying IoT devices) or the network architecture changes (such as expanding the DMZ), the threshold is dynamically adjusted based on the type of newly added devices. For example, after connecting a large number of low-profile IoT devices, the device similarity threshold is relaxed from 80% to 65% to avoid misjudgments due to insufficient device capabilities.

[0067] Corresponding to the network security evaluation method of the above embodiment, Figure 2 This is a structural block diagram of a network security evaluation device provided by an embodiment of the present application. For ease of explanation, only the parts related to the embodiment of the present application are shown. Figure 2 , the network security evaluation device 20 is applied to a server and includes: . The first verification module 201 is configured to generate a first verification fingerprint in response to receiving a security evaluation instruction, and send the first verification fingerprint to all network devices connected to the server, where the first verification fingerprint is used to instruct each network device to feedback identity authentication information; The second verification module 202 is configured to match the identity authentication information fed back by each network device with each standard identity information in the standard identity library, mark the network device that matches the standard identity library as the first network device, and mark the network device that does not match the standard identity library as the second network device; The third verification module 203 is configured to generate a second verification fingerprint in response to the existence of a second network device, and send the second verification fingerprint to all second network devices, where the second verification fingerprint is used to instruct each second network device to feedback preset verification information; mark the second network device that feedbacks the preset verification information as a to-be-matched device, and mark the second network device that does not feedback the preset verification information as a shadow device; The security evaluation module 204 is used to perform network security evaluation based on the information of all first network devices, the information of all devices to be matched, and the information of all shadow devices.

[0068] In one embodiment of the present application, the security evaluation instruction includes a first instruction and a second instruction, the first instruction is a periodic instruction, the second instruction is an external trigger instruction, and the first instruction and the second instruction are not generated at the same time; The first verification module 201 is specifically configured to, in response to receiving a first instruction, generate a verification message including arranging multiple verification features in a first order according to an instruction cycle of the first instruction, and mark the verification message as a first verification fingerprint; In response to receiving the second instruction, generating, according to the instruction authority of the second instruction, a verification message including arranging the plurality of verification features in a second order, and marking the verification message as a first verification fingerprint; Among them, the first order is different from the second order.

[0069] In one embodiment of the present application, the multiple verification features include at least two of the following features: a protocol feature, a port feature, a version feature, a service feature, and an address feature.

[0070] In one embodiment of the present application, each standard identity information in the standard identity library is a standard identity vector; The second verification module 202 is specifically configured to perform feature restoration on the identity authentication information fed back by each network device to obtain a verification feature vector for each network device; Perform time series transformation on each verification feature vector to obtain a verification feature vector with the same dimension as the standard identity vector; The verification feature vectors that are consistent with the dimension of the standard identity vectors are matched with each standard identity vector respectively.

[0071] In one embodiment of the present application, the second verification module 202 is specifically configured to, for each network device, determine that if there is a standard identity vector corresponding to the network device and the similarity of the verification feature vector with the same dimension as the standard identity vector is greater than or equal to a preset similarity, mark the network device as the first network device; For each network device, if there is a verification feature vector corresponding to the network device and having the same dimension as the standard identity vector and a standard identity vector whose similarity is less than a preset similarity, the network device is determined to be marked as the second network device.

[0072] In one embodiment of the present application, the security evaluation module 204 is specifically configured to extract the security dimension from the information of each first network device, determine the security score of each first network device based on the security dimension and the first weight, and sum the scores to obtain a first security score. Extracting the security dimension from the information of each device to be matched, determining a security score for each device to be matched based on the security dimension and the second weight, and summing the scores to obtain a second security score; Determine the criticality scores of all shadow devices based on the device type and number of each shadow device, and sum them up to obtain the target criticality score; The network security score is determined based on the first security score, the second security score and the target risk score.

[0073] In one embodiment of the present application, the security evaluation module 204 is specifically used to calculate the sum of the first security score and the second security score, calculate the difference between the sum and the target hazard score, and calculate the ratio of the difference to the number of all network devices as the network security score.

[0074] See also Figure 3 , Figure 3 This is a schematic block diagram of an electronic device provided in one embodiment of the present application. Figure 3 The electronic device 300 in the embodiment shown may include: one or more processors 301, one or more input devices 302, one or more output devices 303, and one or more memories 304. The processors 301, input devices 302, output devices 303, and memories 304 communicate with each other via a communication bus 305. The memory 304 is used to store computer programs, which include program instructions. The processor 301 is used to execute the program instructions stored in the memory 304. The processor 301 is configured to call the program instructions to execute the functions of the modules in the above-mentioned device embodiments, such as Figure 2 Shown are a first verification module 201 , a second verification module 202 , a third verification module 203 and a safety evaluation module 204 .

[0075] It should be understood that in the embodiment of the present application, the processor 301 may be a central processing unit (CPU), and the processor may also be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor, etc.

[0076] The input device 302 may include a touchpad, a fingerprint collection sensor (for collecting user fingerprint information and fingerprint direction information), a microphone, etc. The output device 303 may include a display (LCD, etc.), a speaker, etc.

[0077] The memory 304 may include a read-only memory and a random access memory, and provides instructions and data to the processor 301. A portion of the memory 304 may also include a nonvolatile random access memory.

[0078] In a specific implementation, the processor 301, input device 302, and output device 303 described in the embodiment of the present application can execute the implementation method described in the network security evaluation method provided in the embodiment of the present application, and can also execute the implementation method of the electronic device described in the embodiment of the present application, which will not be repeated here.

[0079] In another embodiment of the present application, a computer-readable storage medium is provided. The computer-readable storage medium stores a computer program. The computer program includes program instructions. When the program instructions are executed by a processor, all or part of the process of the method in the above embodiment is implemented. The computer program can also be used to instruct related hardware to complete the process. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by the processor, the steps of each of the above method embodiments are implemented. The computer program includes computer program code, which can be in source code form, object code form, executable file or some intermediate form. The computer-readable medium can include: any entity or device capable of carrying computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signal, telecommunication signal and software distribution medium.

[0080] The computer-readable storage medium can be an internal storage unit of the electronic device in any of the aforementioned embodiments, such as a hard disk or memory of the electronic device. The computer-readable storage medium can also be an external storage device of the electronic device, such as a plug-in hard disk, a Smart Media Card (SMC), a Secure Digital (SD) card, a flash memory card, etc. Furthermore, the computer-readable storage medium can include both an internal storage unit of the electronic device and an external storage device. The computer-readable storage medium is used to store computer programs and other programs and data required by the electronic device. The computer-readable storage medium can also be used to temporarily store data that has been output or is about to be output.

[0081] An embodiment of the present application provides a computer program product, which includes computer-executable instructions or a computer program, and the computer-executable instructions or computer program are stored in a computer-readable storage medium. The processor of the electronic device reads the computer-executable instructions from the computer-readable storage medium, and the processor executes the computer-executable instructions, so that the electronic device performs the network security evaluation method described above in the embodiment of the present application.

[0082] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described in terms of function in the above description. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.

[0083] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the electronic devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0084] In the several embodiments provided in this application, it should be understood that the disclosed electronic devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of units is merely a logical function division, and other division methods may be used in actual implementation.

[0085] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the embodiments of the present application.

[0086] The above are only specific embodiments of the present application, but the scope of protection of the present application is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or replacements within the technical scope disclosed in this application, and such modifications or replacements should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.

Claims

1. A network security evaluation method, characterized in that: Applicable to servers, including: In response to receiving the security evaluation instruction, generating a first verification fingerprint, and sending the first verification fingerprint to all network devices connected to the server, the first verification fingerprint being used to instruct each network device to feedback identity authentication information; Matching the identity authentication information fed back by each network device with each standard identity information in the standard identity library in sequence, marking the network device that matches the standard identity library as a first network device, and marking the network device that does not match the standard identity library as a second network device; In response to the existence of the second network device, a second verification fingerprint is generated and sent to all the second network devices, wherein the second verification fingerprint is used to instruct each second network device to feedback preset verification information; the second network device that feedbacks the preset verification information is marked as a device to be matched, and the second network device that does not feedback the preset verification information is marked as a shadow device; A network security evaluation is performed based on the information of all first network devices, the information of all devices to be matched, and the information of all shadow devices.

2. The network security evaluation method according to claim 1, wherein: The safety evaluation instruction includes a first instruction and a second instruction, the first instruction is a periodic instruction, the second instruction is an external trigger instruction, and the first instruction and the second instruction are not generated at the same time; The step of generating a first verification fingerprint in response to receiving a security evaluation instruction includes: In response to receiving the first instruction, generating, according to an instruction cycle of the first instruction, a verification message including arranging the plurality of verification features in a first order, and marking the verification message as a first verification fingerprint; In response to receiving the second instruction, generating, according to the instruction authority of the second instruction, a verification message including arranging the plurality of verification features in a second order, and marking the verification message as a first verification fingerprint; The first order is different from the second order.

3. The network security evaluation method according to claim 2, wherein: The multiple verification features include at least two of the following features: a protocol feature, a port feature, a version feature, a service feature, and an address feature.

4. The network security evaluation method according to claim 1, wherein: Each standard identity information in the standard identity database is a standard identity vector; The step of sequentially matching the identity authentication information fed back by each network device with each standard identity information in the standard identity library includes: Perform feature restoration on the authentication information fed back by each network device to obtain the verification feature vector of each network device; Perform time series transformation on each verification feature vector to obtain a verification feature vector with the same dimension as the standard identity vector; The verification feature vectors that are consistent with the dimension of the standard identity vectors are matched with each standard identity vector respectively.

5. The network security evaluation method according to claim 4, wherein: The step of marking a network device that matches the standard identity library as a first network device and marking a network device that does not match the standard identity library as a second network device includes: For each network device, if there is a standard identity vector corresponding to the network device whose verification feature vector has the same dimension as the standard identity vector and whose similarity is greater than or equal to a preset similarity, then the network device is determined to be marked as the first network device; For each network device, if there is a verification feature vector corresponding to the network device and having the same dimension as the standard identity vector and a standard identity vector whose similarity is less than a preset similarity, the network device is determined to be marked as the second network device.

6. The network security evaluation method according to claim 1, wherein: The network security evaluation is performed based on the information of all first network devices, the information of all devices to be matched, and the information of all shadow devices, including: Extracting the security dimension from the information of each first network device, determining a security score for each first network device based on the security dimension and the first weight, and summing the scores to obtain a first security score; Extracting the security dimension from the information of each device to be matched, determining a security score for each device to be matched based on the security dimension and the second weight, and summing the scores to obtain a second security score; Determine the criticality scores of all shadow devices based on the device type and number of each shadow device, and sum them up to obtain the target criticality score; A network security score is determined based on the first security score, the second security score, and the target criticality score.

7. The network security evaluation method according to claim 6, wherein: Determining a network security score according to the first security score, the second security score, and the target criticality score includes: The sum of the first security score and the second security score is calculated, the difference between the sum and the target hazard score is calculated, and the ratio of the difference to the number of all network devices is calculated as the network security score.

8. A network security evaluation device, characterized in that: Applicable to servers, including: A first verification module is configured to generate a first verification fingerprint in response to receiving a security evaluation instruction, and send the first verification fingerprint to all network devices connected to the server, wherein the first verification fingerprint is used to instruct each network device to feedback identity authentication information; a second verification module, configured to match the identity authentication information fed back by each network device with each standard identity information in the standard identity library, mark the network device that matches the standard identity library as a first network device, and mark the network device that does not match the standard identity library as a second network device; a third verification module, configured to generate a second verification fingerprint in response to the presence of a second network device, and send the second verification fingerprint to all second network devices, wherein the second verification fingerprint is used to instruct each second network device to feedback preset verification information; mark the second network device that feedbacks the preset verification information as a to-be-matched device, and mark the second network device that does not feedback the preset verification information as a shadow device; The security evaluation module is used to perform network security evaluation based on the information of all first network devices, the information of all devices to be matched, and the information of all shadow devices.

9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.

10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.

Citation Information

Patent Citations

  • Network asset risk assessment method and device, switch, equipment and server

    CN113326514A

  • Security risk analysis method and security monitoring management system taking network data assets as core

    CN114650185A

  • Network detection method and device and non-instantaneous computer readable storage medium

    CN115085959A

  • Network security assessment method and device, equipment and storage medium

    CN116582360A

  • Network port security protection method and device, electronic equipment and storage medium

    CN118473825A