A network security evaluation method and device
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- GUONENG (HUIZHOU) THERMAL POWER CO LTD
- Filing Date
- 2025-06-10
- Publication Date
- 2026-07-21
Smart Images

Figure CN120474812B_ABST
Abstract
Description
Technical Field
[0001] This application belongs to the field of network security evaluation technology, and more specifically, relates to a network security evaluation method and apparatus. Background Technology
[0002] Cybersecurity assessments play a crucial role in enterprise cybersecurity. Enterprises can develop different network protection strategies based on the assessment results to effectively protect their network assets. As enterprise networks become increasingly digitalized, digital assets are constantly increasing, and the number of electronic devices outside of enterprise control is also growing, leading to a rise in shadow assets.
[0003] Shadow assets may make it difficult for enterprises to conduct comprehensive and timely cybersecurity assessments, impacting enterprise cybersecurity and, in severe cases, causing losses to enterprise network assets. Summary of the Invention
[0004] The purpose of this application is to provide a network security evaluation method and apparatus to improve the reliability of network security evaluation and maintain network security.
[0005] A first aspect of this application provides a network security evaluation method applied to a server, comprising:
[0006] In response to receiving a security evaluation instruction, a first verification fingerprint is generated and sent to all network devices connected to the server. The first verification fingerprint is used to instruct each network device to provide authentication information.
[0007] The authentication information returned by each network device is matched sequentially with each standard identity information in the standard identity database. The network device that matches the standard identity database is marked as the first network device, and the network device that does not match the standard identity database is marked as the second network device.
[0008] In response to the presence of a second network device, a second verification fingerprint is generated and sent to all second network devices. The second verification fingerprint is used to instruct each second network device to provide preset verification information. Second network devices that provide preset verification information are marked as devices to be matched, and second network devices that do not provide preset verification information are marked as shadow devices.
[0009] A network security assessment is conducted based on information from all primary network devices, all devices to be matched, and all shadow devices.
[0010] A second aspect of this application provides a network security evaluation device applied to a server, comprising:
[0011] The first verification module is used to generate a first verification fingerprint in response to receiving a security evaluation instruction, and send the first verification fingerprint to all network devices connected to the server. The first verification fingerprint is used to instruct each network device to provide authentication information.
[0012] The second verification module is used to match the authentication information returned by each network device with each standard identity information in the standard identity database in turn, and to mark the network device that matches the standard identity database as the first network device and the network device that does not match the standard identity database as the second network device.
[0013] The third verification module is used to generate a second verification fingerprint in response to the presence of a second network device, and send the second verification fingerprint to all the second network devices. The second verification fingerprint is used to instruct each second network device to provide preset verification information. The second network device that provides preset verification information is marked as a device to be matched, and the second network device that does not provide preset verification information is marked as a shadow device.
[0014] The security evaluation module is used to perform network security evaluation based on information from all primary network devices, all devices to be matched, and all shadow devices.
[0015] A third aspect of this application provides an electronic device, including a memory, a processor, and a computer program stored in the memory and running on the processor, wherein the processor executes the computer program to implement the steps of the above-described network security evaluation method.
[0016] A fourth aspect of this application provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps of the network security evaluation method described above.
[0017] A fifth aspect of this application provides a computer program product, including a computer program or computer executable instructions, wherein when the computer program or computer executable instructions are executed by a processor, the steps of the above-described network security evaluation method are implemented.
[0018] The beneficial effects of the network security evaluation method and apparatus provided in this application are as follows:
[0019] This application's embodiments effectively improve the reliability of network security evaluation through a multi-round verification mechanism. First, a first verification fingerprint is generated to perform preliminary identity screening of network devices, distinguishing between the first and second network devices, thus achieving initial security filtering. Next, a second verification fingerprint is generated for the second network device to further verify its legitimacy, accurately identifying the device to be matched and any shadow devices. This layered verification approach progressively checks device identity, avoiding the limitations of single verification methods and enabling timely detection and location of security vulnerabilities such as shadow devices. Finally, a comprehensive security evaluation is conducted based on all device information, making the evaluation results more comprehensive and accurate in reflecting the network security status and providing a reliable basis for network security management. Attached Figure Description
[0020] To more clearly illustrate the technical solutions in the embodiments of this application, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0021] Figure 1 A flowchart illustrating a network security evaluation method provided in an embodiment of this application;
[0022] Figure 2 This is a structural block diagram of a network security evaluation device provided in an embodiment of this application;
[0023] Figure 3 This is a schematic block diagram of an electronic device provided in an embodiment of this application. Detailed Implementation
[0024] In the following description, specific details such as particular system architectures and techniques are set forth for illustrative purposes and not for limitation, in order to provide a thorough understanding of the embodiments of this application. However, those skilled in the art will understand that this application may also be implemented in other embodiments without these specific details. In other instances, detailed descriptions of well-known systems, apparatuses, circuits, and methods have been omitted so as not to obscure the description of this application with unnecessary detail.
[0025] To make the objectives, technical solutions, and advantages of this application clearer, the following description will be provided in conjunction with the accompanying drawings and specific embodiments.
[0026] Please refer to Figure 1 , Figure 1 This is a flowchart illustrating a network security evaluation method provided in an embodiment of this application. It can be applied to a server, and the method may include steps S101 to S104.
[0027] S101, in response to receiving the security evaluation instruction, generates a first verification fingerprint and sends the first verification fingerprint to all network devices connected to the server. The first verification fingerprint is used to instruct each network device to provide authentication information.
[0028] In the embodiments of this application, after receiving the instruction to "start network security evaluation," the server can generate a "digital token," also known as a first verification fingerprint, for device identity verification. This can be achieved either by an administrator clicking a security evaluation button or by a periodic, scheduled task triggering the generation of the security evaluation instruction. The security evaluation instruction in the embodiments of this application is used to perform a network security evaluation on the network system where the server resides.
[0029] After generating the first verification fingerprint, the server can send the first verification fingerprint, which serves as a "digital token," to all network devices accessing the server via network broadcast or targeted push.
[0030] In the embodiments of this application, the first verification fingerprint includes network verification rules, which require each network device to reply with an "electronic receipt" containing its own identity characteristics after receiving it, so as to prove that the network device is an authorized asset of the enterprise where the server is located, and avoid being judged as a shadow asset.
[0031] Generally speaking, network devices that provide correct authentication information are usually authorized assets of the enterprise, while network devices that provide incorrect or no authentication information may be shadow devices. The first round of verification can preliminarily identify shadow devices and suspected shadow devices.
[0032] For example, the first verification fingerprint may include the following verification fields: verification timestamp, enterprise unique identifier, encryption challenge code, and verification algorithm identifier.
[0033] S102, the authentication information returned by each network device is matched sequentially with each standard identity information in the standard identity database. The network device that matches the standard identity database is marked as the first network device, and the network device that does not match the standard identity database is marked as the second network device.
[0034] In the embodiments of this application, the standard identity database is a "digital ID ledger" of enterprise authorized assets. The data sources may include: registered device information in the configuration management database, manually entered special assets, and device identity information verified in historical security assessments. By standardizing the device identity information from these different data sources, standard identity information corresponding to each device in the standard identity database can be obtained.
[0035] This application embodiment can extract the identity verification information returned by various network devices into a vector, and obtain an identity feature vector with MAC address, system version and positive fingerprint as features.
[0036] Then, the similarity between the obtained device's identity feature vector and the feature vector corresponding to the standard identity information in the system is calculated. If a device with standard identity information that is highly similar to the network device exists, then the network device is identified as the first network device. If no device with standard identity information that is highly similar to the network device exists, then the network device is identified as the second network device.
[0037] The embodiments of this application allow setting different similarity thresholds for network devices in different regions.
[0038] For high-risk areas, a similarity threshold of 0.9 can be set for strict matching to prevent malicious shadow devices from spoofing departmental features. For office areas, a similarity threshold of 0.7 can be set for fuzzy matching, allowing for the possibility of network devices being misidentified due to normal upgrades. For IoT areas, a similarity threshold of 0.5 can be set for lenient matching, allowing for more missing features considering the limited computing power of industrial equipment. The specific similarity threshold can be set according to the actual situation.
[0039] S103, in response to the existence of a second network device, a second verification fingerprint is generated and sent to all second network devices. The second verification fingerprint is used to instruct each second network device to provide preset verification information. The second network device that provides preset verification information is marked as a device to be matched, and the second network device that does not provide preset verification information is marked as a shadow device.
[0040] When the existence of a second network device is determined in this embodiment, a secondary verification process can be initiated. This avoids some second network devices being misjudged and allows for more rigorous verification through preset information, thus identifying highly concealed shadow devices.
[0041] In embodiments of this application, the second verification fingerprint includes a specific field associated with preset information, which points to the location of verification information pre-stored by the device. Legitimate devices can quickly locate the preset information and provide timely feedback through this field, while unauthorized devices may be unable to respond due to the lack of pre-stored information, thus efficiently identifying unauthorized devices.
[0042] Optionally, for legitimate network devices, pre-configured verification information can be stored through hardware storage, software storage, or cloud-based association. Specific settings can be configured according to the actual situation.
[0043] For example, a legitimate device fails verification on the first attempt. This device could be a newly purchased laptop that has not yet been entered into the CMBD database, and is flagged as a second network device during the first verification because its MAC address is not in the standard identity database.
[0044] Secondary verification process:
[0045] The server sends a second verification fingerprint (containing pre_verify_id=20250530);
[0046] The device extracts the pre-installed enterprise procurement certificate (including device serial number and MAC address hash value) from the TPM chip, encrypts it, and then responds.
[0047] The server compares the pre-set information with the procurement system records to confirm the legality of the equipment, marks it as "the first network device to be reported", and automatically creates an asset entry work order.
[0048] The suspected shadow device was identified during the second verification process. The device's IP address was marked as a second network device during the first verification because the certificate was not issued by an enterprise CA.
[0049] Secondary verification process:
[0050] The server sends a second verification fingerprint (containing pre_verify_id=20250530);
[0051] The device is not responding (due to the lack of pre-set verification information);
[0052] The server sent fingerprints with different pre_verify_ids again, but there was still no response;
[0053] The system identified the device as a shadow device and activated the firewall to block access. This triggered a threat hunting process (such as analyzing the IP's historical traffic to see if there was any data breach).
[0054] S104. Conduct a network security evaluation based on information from all primary network devices, all devices to be matched, and all shadow devices.
[0055] After classifying the various network devices, network security evaluation can be conducted using the following methods:
[0056] S1041, Statistics on the percentage of each type of equipment.
[0057] S1042 calculates the risk score for a single device. The device risk score can be determined based on device type, vulnerability severity, and threat intelligence.
[0058] S1043, Determine the business relevance. Different weighting coefficients can be assigned based on the importance of the business carried by the equipment.
[0059] S1044 can calculate the score of each device based on information from different devices.
[0060] S1045, set weights and calculate the base score. Weights can be assigned according to the importance of the equipment.
[0061] Base score = First device score * weight 1 + Matching device score * weight 2 + Shadow device score * weight 3.
[0062] S1046 normalizes the baseline total score to 0-100 points.
[0063] Baseline total score = 100 * (weight 1 + weight 2 + weight 3) = 100 points
[0064] Final online score = (base score / baseline total score) * 100.
[0065] Alternatively, after classifying the various network devices, network security evaluation can be conducted in the following manner.
[0066] Extract the security dimension from the information of each first network device, determine the security score of each first network device based on the security dimension and the first weight, and sum them to obtain the first security score;
[0067] Extract the security dimension from the information of each device to be matched, determine the security score of each device to be matched based on the security dimension and the second weight, and sum them to obtain the second security score;
[0068] Based on the device type and quantity of each shadow device, determine the hazard score of all shadow devices, and sum them to obtain the target hazard score;
[0069] The cybersecurity score is determined based on the first security score, the second security score, and the target hazard score.
[0070] Calculate the sum of the first security score and the second security score, calculate the difference between this sum and the target hazard score, and calculate the ratio of this difference to the total number of network devices, which is used as the network security score.
[0071] This application's embodiments effectively improve the reliability of network security evaluation through a multi-round verification mechanism. First, a first verification fingerprint is generated to perform preliminary identity screening of network devices, distinguishing between the first and second network devices, thus achieving initial security filtering. Next, a second verification fingerprint is generated for the second network device to further verify its legitimacy, accurately identifying the device to be matched and any shadow devices. This layered verification approach progressively checks device identity, avoiding the limitations of single verification methods and enabling timely detection and location of security vulnerabilities such as shadow devices. Finally, a comprehensive security evaluation is conducted based on all device information, making the evaluation results more comprehensive and accurate in reflecting the network security status and providing a reliable basis for network security management.
[0072] In some embodiments of this application, the security evaluation instruction includes a first instruction and a second instruction, wherein the first instruction is a periodic instruction and the second instruction is an externally triggered instruction, and the first instruction and the second instruction are not generated simultaneously;
[0073] In response to receiving a security assessment instruction, a first verification fingerprint is generated, including:
[0074] In response to receiving a first instruction, a verification message is generated according to the instruction cycle of the first instruction, which includes arranging multiple verification features in a first order and marking it as a first verification fingerprint.
[0075] In response to receiving a second instruction, a verification message is generated according to the instruction permissions of the second instruction, including arranging multiple verification features in a second order, and marked as a first verification fingerprint;
[0076] The first order is different from the second order.
[0077] Specifically, multiple verification features include at least two of the following features: protocol feature, port feature, version feature, service feature, and address feature.
[0078] In the embodiments of this application, the first instruction is a periodic instruction, which can be a security evaluation instruction that is automatically triggered at a preset time period (such as daily / weekly) for routine asset detection. For example, an enterprise may set up a network-wide device verification to start at 2:00 AM every Monday.
[0079] The first instruction is used to instruct the corresponding network device to generate verification messages at fixed intervals, arranging verification features such as device MAC address, IP address, and certificate fingerprint in a "first order" (such as the preset standard field order) to ensure consistency in routine testing.
[0080] The second type of instruction is an externally triggered instruction, which is activated by an external event (such as manual triggering or security event alarm). It has higher privileges. For example, after the security team discovers suspicious traffic, it can manually send a verification instruction through the management platform.
[0081] The second instruction is used to instruct the corresponding network devices to adjust the feature arrangement order ("second order") according to the instruction permission level. For example, it can prioritize verifying the certificate fingerprint and business relevance features of devices in high-risk areas to improve the targeting of emergency detection.
[0082] In this embodiment, the first or second instruction can be identified by an instruction type identifier (such as the instruction header field type=periodic or type=trigger) to avoid simultaneous generation conflicts. For example, the first instruction can be triggered periodically by a task scheduler, while the second instruction can be manually activated through an API interface or management interface.
[0083] In this embodiment, a preset verification feature set (including 10+ features such as MAC address, IP address, certificate fingerprint, and business relevance) is established, and feature arrangement rules are configured for different instruction types. For example, the first instruction can be arranged in the order of "MAC → IP → Certificate", and the second instruction can be arranged in the order of "Certificate → Business Relevance → MAC" (high-privilege instructions prioritize the verification of core security features).
[0084] In this embodiment, when the network device receives a first instruction, it can retrieve a feature set according to a periodic rule and concatenate it into a verification message (such as MAC|IP|certificate|...) in a first order, marking it as a first verification fingerprint. When the network device receives a second instruction, it can filter features according to permission levels (such as selecting only high-risk features) and arrange them in a second order to generate a differentiated first verification fingerprint.
[0085] The first instruction in this application embodiment is applicable to routine security inspections (such as weekly verification of office equipment), and the second instruction is applicable to emergency response (such as prioritizing verification of core server certificates during ransomware incidents), achieving dual-mode coverage of "normalization + emergency response", improving verification security and reducing the harm of covert intrusions.
[0086] In some embodiments of this application, each standard identity information in the standard identity library is a standard identity vector;
[0087] The authentication information returned by each network device is matched sequentially with the standard identity information in the standard identity database, including:
[0088] The authentication information returned by each network device is feature-reconstructed to obtain the authentication feature vector of each network device;
[0089] Perform a time-series transformation on each verification feature vector to obtain a verification feature vector with the same dimensions as the standard identity vector;
[0090] The verification feature vectors, which have the same dimensions as the standard identity vectors, are matched with each standard identity vector.
[0091] In some embodiments of this application, network devices that match the standard identity database are marked as first network devices, and network devices that do not match the standard identity database are marked as second network devices, including:
[0092] For each network device, if there exists a standard identity vector whose verification feature vector has the same dimension as the standard identity vector and whose similarity is greater than or equal to the preset similarity, then the network device is identified as the first network device.
[0093] For each network device, if there exists a standard identity vector whose verification feature vector has the same dimension as the standard identity vector and whose similarity is less than the preset similarity, then the network device is identified as the second network device.
[0094] In this embodiment of the application, the identity information of each device in the standard identity library can be abstracted into a multi-dimensional feature vector (such as coordinate points composed of features such as MAC address, IP, certificate fingerprint, etc.). For example, the standard identity vector of a certain server is [MAC_001A2B, IP_192.168.1.1, Cert_Fingerprint_A1B2].
[0095] This application embodiment can also parse the verification information returned by the device into raw feature values (such as extracting fields such as MAC address and IP). Then, the restored content can be time-series transformed to adjust the arrangement order of the verification features so that its dimensions are consistent with the standard identity vector (e.g., the standard vector is arranged in "MAC→IP→certificate", and the verification vector needs to be converted to the same order).
[0096] This is an option. You can determine the legality of a device by calculating the similarity between the verification feature vector and the standard identity vector (such as cosine similarity or Euclidean distance), and set a preset similarity threshold (such as 0.8) as the classification criterion.
[0097] For example, if the similarity is ≥0.8, it is marked as the first network device (legitimate asset).
[0098] If the similarity is less than 0.8, it is marked as the second network device (asset to be verified).
[0099] This application embodiment avoids misjudgment caused by different feature order by converting to a unified vector dimension (such as the device reporting IP first and then MAC, which is consistent with the standard vector order after conversion), and can reduce the misjudgment rate.
[0100] In this embodiment, the preset similarity threshold can also be adjusted based on the occurrence of a security event. When a shadow device is detected causing a security event, the preset similarity threshold can be adjusted from a first similarity threshold to a second similarity threshold, where the first similarity threshold is greater than the second similarity threshold, to increase the sensitivity to suspicious devices. For example, it can be reduced from 70% to 60%.
[0101] In this embodiment, when a new service is launched (such as deploying IoT devices) or the network architecture changes (such as DMZ zone expansion), the threshold is dynamically adjusted according to the type of newly added device. For example, after a large number of low-configuration IoT devices are connected, the device similarity threshold is relaxed from 80% to 65% to avoid misjudgment due to insufficient device capabilities.
[0102] Corresponding to the network security evaluation method in the above embodiments, Figure 2 This is a structural block diagram of a network security evaluation device provided according to an embodiment of this application. For ease of explanation, only the parts relevant to the embodiment of this application are shown. References Figure 2 The network security evaluation device 20 is applied to a server and includes:
[0103] The first verification module 201 is used to generate a first verification fingerprint in response to receiving a security evaluation instruction, and send the first verification fingerprint to all network devices connected to the server. The first verification fingerprint is used to instruct each network device to provide authentication information.
[0104] The second verification module 202 is used to match the authentication information returned by each network device with each standard identity information in the standard identity database in turn, and to mark the network device that matches the standard identity database as the first network device and the network device that does not match the standard identity database as the second network device.
[0105] The third verification module 203 is used to generate a second verification fingerprint in response to the presence of a second network device, and send the second verification fingerprint to all the second network devices. The second verification fingerprint is used to instruct each second network device to provide preset verification information. The second network device that provides preset verification information is marked as a device to be matched, and the second network device that does not provide preset verification information is marked as a shadow device.
[0106] The security evaluation module 204 is used to perform a network security evaluation based on information from all first network devices, information from all devices to be matched, and information from all shadow devices.
[0107] In one embodiment of this application, the security evaluation instruction includes a first instruction and a second instruction. The first instruction is a periodic instruction, and the second instruction is an externally triggered instruction. The first instruction and the second instruction are not generated simultaneously.
[0108] The first verification module 201 is specifically used to respond to receiving a first instruction and generate a verification message according to the instruction cycle of the first instruction, including arranging multiple verification features in a first order and marking it as a first verification fingerprint.
[0109] In response to receiving a second instruction, a verification message is generated according to the instruction permissions of the second instruction, including arranging multiple verification features in a second order, and marked as a first verification fingerprint;
[0110] The first order is different from the second order.
[0111] In one embodiment of this application, the plurality of verification features include at least two of the following features: protocol feature, port feature, version feature, service feature, and address feature.
[0112] In one embodiment of this application, each standard identity information in the standard identity library is a standard identity vector;
[0113] The second verification module 202 is specifically used to perform feature restoration on the authentication information returned by each network device to obtain the verification feature vector of each network device.
[0114] Perform a time-series transformation on each verification feature vector to obtain a verification feature vector with the same dimensions as the standard identity vector;
[0115] The verification feature vectors, which have the same dimensions as the standard identity vectors, are matched with each standard identity vector.
[0116] In one embodiment of this application, the second verification module 202 is specifically used to determine that the network device is marked as the first network device if there is a verification feature vector with the same dimension as the standard identity vector corresponding to the network device and the similarity is greater than or equal to the preset similarity for each network device.
[0117] For each network device, if there exists a standard identity vector whose verification feature vector has the same dimension as the standard identity vector and whose similarity is less than the preset similarity, then the network device is identified as the second network device.
[0118] In one embodiment of this application, the security evaluation module 204 is specifically used to extract the security dimension from the information of each first network device, determine the security score of each first network device according to the security dimension and the first weight, and sum them to obtain the first security score.
[0119] Extract the security dimension from the information of each device to be matched, determine the security score of each device to be matched based on the security dimension and the second weight, and sum them to obtain the second security score;
[0120] Based on the device type and quantity of each shadow device, determine the hazard score of all shadow devices, and sum them to obtain the target hazard score;
[0121] The cybersecurity score is determined based on the first security score, the second security score, and the target hazard score.
[0122] In one embodiment of this application, the security evaluation module 204 is specifically used to calculate the sum of the first security score and the second security score, calculate the difference between the sum and the target hazard score, and calculate the ratio of the difference to the number of all network devices as a network security score.
[0123] See Figure 3 , Figure 3 This is a schematic block diagram of an electronic device provided according to an embodiment of this application. Figure 3 The electronic device 300 in this embodiment may include one or more processors 301, one or more input devices 302, one or more output devices 303, and one or more memories 304. The processors 301, input devices 302, output devices 303, and memories 304 communicate with each other via a communication bus 305. The memories 304 store computer programs, including program instructions. The processors 301 execute the program instructions stored in the memories 304. Specifically, the processors 301 are configured to invoke the program instructions to perform the functions of the modules in the aforementioned device embodiments, for example... Figure 2 The first verification module 201, the second verification module 202, the third verification module 203, and the security evaluation module 204 are shown.
[0124] It should be understood that, in the embodiments of this application, the processor 301 may be a central processing unit (CPU), or it may be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor.
[0125] Input device 302 may include a touchpad, a fingerprint sensor (for collecting the user's fingerprint information and fingerprint orientation information), a microphone, etc., and output device 303 may include a display (LCD, etc.), a speaker, etc.
[0126] The memory 304 may include read-only memory and random access memory, and provides instructions and data to the processor 301. A portion of the memory 304 may also include non-volatile random access memory.
[0127] In specific implementations, the processor 301, input device 302, and output device 303 described in the embodiments of this application can execute the implementation methods described in the network security evaluation methods provided in the embodiments of this application, or they can execute the implementation methods of the electronic devices described in the embodiments of this application, which will not be repeated here.
[0128] In another embodiment of this application, a computer-readable storage medium is provided. This computer-readable storage medium stores a computer program, which includes program instructions. When executed by a processor, the program instructions implement all or part of the processes in the methods described above. Alternatively, the computer program can instruct related hardware to complete the process. The computer program can be stored in a computer-readable storage medium, and when executed by a processor, it can implement the steps of the various method embodiments described above. The computer program includes computer program code, which can be in the form of source code, object code, executable files, or certain intermediate forms. The computer-readable medium can include any entity or device capable of carrying computer program code, a recording medium, a USB flash drive, a portable hard drive, a magnetic disk, an optical disk, a computer memory, a read-only memory (ROM), a random access memory (RAM), an electrical carrier signal, a telecommunication signal, and a software distribution medium, etc.
[0129] The computer-readable storage medium can be an internal storage unit of the electronic device in any of the foregoing embodiments, such as a hard disk or memory of the electronic device. The computer-readable storage medium can also be an external storage device of the electronic device, such as a plug-in hard disk, smart media card (SMC), secure digital card (SD), flash card, etc., equipped on the electronic device. Furthermore, the computer-readable storage medium can include both internal and external storage units of the electronic device. The computer-readable storage medium is used to store computer programs and other programs and data required by the electronic device. The computer-readable storage medium can also be used to temporarily store data that has been output or will be output.
[0130] This application provides a computer program product, which includes computer-executable instructions or a computer program. The computer-executable instructions or computer program are stored in a computer-readable storage medium. The processor of an electronic device reads the computer-executable instructions from the computer-readable storage medium and executes the computer-executable instructions, causing the electronic device to perform the network security evaluation method described in this application.
[0131] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this application.
[0132] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working process of the electronic devices and units described above can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.
[0133] In the several embodiments provided in this application, it should be understood that the disclosed electronic devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and other division methods may be used in actual implementation.
[0134] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of the embodiments of this application, depending on actual needs.
[0135] The above are merely specific embodiments of this application, but the scope of protection of this application is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in this application, and these modifications or substitutions should all be covered within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A network security evaluation method, characterized in that, Applied to servers, including: In response to receiving a security evaluation instruction, a first verification fingerprint is generated and sent to all network devices connected to the server. The first verification fingerprint is used to instruct each network device to provide authentication information. The authentication information returned by each network device is matched sequentially with each standard identity information in the standard identity database. The network device that matches the standard identity database is marked as the first network device, and the network device that does not match the standard identity database is marked as the second network device. In response to the presence of a second network device, a second verification fingerprint is generated and sent to all second network devices. The second verification fingerprint is used to instruct each second network device to provide preset verification information. Second network devices that provide preset verification information are marked as devices to be matched, and second network devices that do not provide preset verification information are marked as shadow devices. A network security assessment is conducted based on information from all primary network devices, all devices to be matched, and all shadow devices.
2. The network security evaluation method as described in claim 1, characterized in that, The security evaluation instruction includes a first instruction and a second instruction. The first instruction is a periodic instruction, and the second instruction is an externally triggered instruction. The first instruction and the second instruction are not generated simultaneously. The step of generating a first verification fingerprint in response to receiving a security evaluation instruction includes: In response to receiving a first instruction, a verification message is generated according to the instruction cycle of the first instruction, which includes arranging multiple verification features in a first order and marking it as a first verification fingerprint. In response to receiving a second instruction, a verification message is generated according to the instruction permissions of the second instruction, including arranging multiple verification features in a second order, and marked as a first verification fingerprint; The first order is different from the second order.
3. The network security evaluation method as described in claim 2, characterized in that, Multiple verification features include at least two of the following features: protocol feature, port feature, version feature, service feature, and address feature.
4. The network security evaluation method as described in claim 1, characterized in that, Each standard identity information in the standard identity database is a standard identity vector; The step of sequentially matching the authentication information returned by each network device with the standard identity information in the standard identity database includes: The authentication information returned by each network device is feature-reconstructed to obtain the authentication feature vector of each network device; Perform a time-series transformation on each verification feature vector to obtain a verification feature vector with the same dimensions as the standard identity vector; The verification feature vectors, which have the same dimensions as the standard identity vectors, are matched with each standard identity vector.
5. The network security evaluation method as described in claim 4, characterized in that, The step of marking network devices that match the standard identity database as first network devices and marking network devices that do not match the standard identity database as second network devices includes: For each network device, if there exists a standard identity vector whose verification feature vector has the same dimension as the standard identity vector and whose similarity is greater than or equal to the preset similarity, then the network device is identified as the first network device. For each network device, if there exists a standard identity vector whose verification feature vector has the same dimension as the standard identity vector and whose similarity is less than the preset similarity, then the network device is identified as the second network device.
6. The network security evaluation method as described in claim 1, characterized in that, The network security evaluation based on information from all first network devices, all devices to be matched, and all shadow devices includes: Extract the security dimension from the information of each first network device, determine the security score of each first network device based on the security dimension and the first weight, and sum them to obtain the first security score; Extract the security dimension from the information of each device to be matched, determine the security score of each device to be matched based on the security dimension and the second weight, and sum them to obtain the second security score; Based on the device type and quantity of each shadow device, determine the hazard score of all shadow devices, and sum them to obtain the target hazard score; A cybersecurity score is determined based on the first security score, the second security score, and the target hazard score.
7. The network security evaluation method as described in claim 6, characterized in that, The process of determining the cybersecurity score based on the first security score, the second security score, and the target hazard score includes: Calculate the sum of the first security score and the second security score, calculate the difference between the sum and the target hazard score, and calculate the ratio of the difference to the total number of network devices as the network security score.
8. A network security evaluation device, characterized in that, Applied to servers, including: The first verification module is used to generate a first verification fingerprint in response to receiving a security evaluation instruction, and send the first verification fingerprint to all network devices connected to the server. The first verification fingerprint is used to instruct each network device to provide authentication information. The second verification module is used to match the authentication information returned by each network device with each standard identity information in the standard identity database in turn, and to mark the network device that matches the standard identity database as the first network device, and the network device that does not match the standard identity database as the second network device. The third verification module is used to generate a second verification fingerprint in response to the presence of a second network device, and send the second verification fingerprint to all the second network devices. The second verification fingerprint is used to instruct each second network device to provide preset verification information. The second network device that provides preset verification information is marked as a device to be matched, and the second network device that does not provide preset verification information is marked as a shadow device. The security evaluation module is used to perform network security evaluation based on information from all primary network devices, all devices to be matched, and all shadow devices.
9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that, When the processor executes the computer program, it implements the steps of the method as described in any one of claims 1 to 7.
10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method as described in any one of claims 1 to 7.