Distributed device vulnerability scanning method and management system based on cloud computing and SDWAN
Through the distributed device vulnerability scanning method based on cloud computing and SDWAN, combined with network security reporting parameters and regional attribute information, vulnerability scanning parameters are determined, which solves the problem that SDWAN is not smart in distributed device vulnerability scanning, and realizes full-range monitoring and efficient vulnerability scanning.
Patent Information
- Application Number
- CN202510679149.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-26
- Publication Date
- 2025-08-15
AI Technical Summary
The existing software-defined wide area network (SDWAN) is not intelligent enough in distributed device vulnerability scanning, making it difficult to achieve efficient full-range monitoring and vulnerability scanning.
Through the distributed device vulnerability scanning method based on cloud computing and SDWAN, combined with network security reporting parameters, regional attribute information and cloud computing technology, vulnerability scanning parameters are determined and network nodes are controlled to perform vulnerability scanning, so that the full range of monitoring of the SDWAN management system is realized.
It improves the intelligence of distributed device vulnerability scanning of SDWAN, ensures the efficiency and accuracy of vulnerability scanning, and realizes full-range monitoring of the SDWAN management system.
Smart Images

Figure CN120498796A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communication technology or computer technology, and specifically to a distributed device vulnerability scanning method and management system based on cloud computing and SDWAN. Background Art
[0002] Software-defined networking in a wide area network (SDWAN) is a collection of technologies that apply software-defined networking (SDN) technologies to wide area network (WAN) management. Currently, SDWANs lack intelligent distributed device vulnerability scanning capabilities. Therefore, improving the intelligence of SDWAN's distributed device vulnerability scanning is an urgent issue. Summary of the Invention
[0003] The embodiments of the present application provide a distributed device vulnerability scanning method and management system based on cloud computing and SDWAN, which can improve the intelligence of distributed device vulnerability scanning of SDWAN.
[0004] In a first aspect, an embodiment of the present application provides a distributed device vulnerability scanning method based on cloud computing and SDWAN, which is applied to an SDWAN management system. The SDWAN management system includes m network nodes, where m is an integer greater than 1, and each network node corresponds to a vulnerability scanning task in a network area. The method includes:
[0005] Determining network security reporting parameters of m network areas corresponding to the m network nodes within a preset time period to obtain m network security reporting parameters;
[0006] Determining m network security assessment parameters based on the m network security reporting parameters;
[0007] Acquire area attribute information of each of the m network areas to obtain m pieces of area attribute information;
[0008] Determining m vulnerability scanning parameters using cloud computing technology based on the m network security assessment parameters and the m area attribute information;
[0009] The m network nodes are controlled to perform vulnerability scanning according to the m vulnerability scanning parameters.
[0010] In a second aspect, an embodiment of the present application provides an SDWAN management system for distributed device vulnerability scanning based on cloud computing and SDWAN, wherein the SDWAN management system includes m network nodes, where m is an integer greater than 1, and each network node corresponds to a vulnerability scanning task in a network area; the SDWAN management system includes: a first determination unit, an acquisition unit, a second determination unit, and a scanning unit, wherein:
[0011] The first determining unit is configured to determine network security reporting parameters of the m network areas corresponding to the m network nodes within a preset time period to obtain m network security reporting parameters; and determine m network security assessment parameters based on the m network security reporting parameters;
[0012] The acquiring unit is configured to acquire the area attribute information of each of the m network areas to obtain m pieces of area attribute information;
[0013] The second determining unit is configured to determine m vulnerability scanning parameters using cloud computing technology based on the m network security assessment parameters and the m area attribute information;
[0014] The scanning unit is used to control the m network nodes to perform vulnerability scanning according to the m vulnerability scanning parameters.
[0015] The implementation of the embodiments of this application has the following beneficial effects:
[0016] It can be seen that the distributed device vulnerability scanning method and management system based on cloud computing and SDWAN described in the embodiments of the present application is applied to the SDWAN management system. The SDWAN management system includes m network nodes, where m is an integer greater than 1. Each network node corresponds to a vulnerability scanning task in a network area. The network security reporting parameters of the m network areas corresponding to the m network nodes within a preset time period are determined to obtain m network security reporting parameters. M network security assessment parameters are determined based on the m network security reporting parameters. Regional attribute information of each of the m network areas is obtained to obtain m regional attribute information. Based on the m network security assessment parameters and the m regional attribute information, m vulnerability scanning parameters are determined using cloud computing technology. The m network nodes are controlled to perform vulnerability scanning based on the m vulnerability scanning parameters. On the one hand, the corresponding vulnerability scanning parameters can be determined based on the network security status of the network area for which the network node is responsible and the regional characteristics of the corresponding network area, which helps to ensure vulnerability scanning efficiency. On the other hand, for each network node, the corresponding vulnerability scanning parameters can be used by the corresponding network node to perform vulnerability scanning on the corresponding network area, thereby achieving full-range monitoring of the SDWAN management system. In this way, the intelligence of the distributed device vulnerability scanning of the SDWAN can be improved. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0018] Figure 1 This is a flow chart of a distributed device vulnerability scanning method based on cloud computing and SDWAN provided in an embodiment of the present application;
[0019] Figure 2 This is a schematic diagram of the structure of an SDWAN management system provided in an embodiment of the present application;
[0020] Figure 3 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present application;
[0021] Figure 4 This is a block diagram of the functional units of an SDWAN management system for distributed device vulnerability scanning based on cloud computing and SDWAN provided in an embodiment of the present application. DETAILED DESCRIPTION
[0022] The terms "first," "second," and the like in the specification and claims of this application and the accompanying drawings are used to distinguish between different objects, not to describe a particular order. Furthermore, the terms "including," "having," and any variations thereof, are intended to cover non-exclusive inclusions. For example, a process, method, system, product, or apparatus comprising a series of steps or elements is not limited to the listed steps or elements, but may also include steps or elements not listed, or may include other steps or elements inherent to the process, method, product, or apparatus.
[0023] References herein to "embodiments" mean that a particular feature, structure, or characteristic described in connection with the embodiments may be included in at least one embodiment of the present application. The appearance of this phrase in various places in the specification does not necessarily refer to the same embodiment, nor does it constitute an independent or alternative embodiment that is mutually exclusive of other embodiments. It is understood, both explicitly and implicitly, by those skilled in the art that the embodiments described herein may be combined with other embodiments.
[0024] In order to enable those skilled in the art to better understand the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.
[0025] In the embodiment of the present application, the electronic device may include any electronic device with a specific communication function, and the electronic device may include but is not limited to: an intelligent robot, a smart phone, a server, a router, a gateway, a smart switch, a tablet computer, a wearable device, a smart car, a smart watch, a network node, a smart bracelet, smart glasses, a vehicle-mounted device, a computing device or other processing device connected to a wireless modem, as well as various forms of user equipment (UE), mobile station (MS), terminal device, etc., which are not limited here.
[0026] See also Figure 1 , Figure 1 This is a flow chart of a distributed device vulnerability scanning method based on cloud computing and SDWAN provided in an embodiment of the present application. The SDWAN management system includes m network nodes, where m is an integer greater than 1, and each network node corresponds to a vulnerability scanning task in a network area. The distributed device vulnerability scanning method based on cloud computing and SDWAN includes:
[0027] 101. Determine network security reporting parameters of m network areas corresponding to the m network nodes within a preset time period to obtain m network security reporting parameters.
[0028] In the embodiment of the present application, the preset time period can be pre-set or system default.
[0029] Among them, such as Figure 2 As shown, the SDWAN management system includes m network nodes, where m is an integer greater than 1. Each network node is responsible for vulnerability scanning in a specific network area. In other words, each network node corresponds to a specific network area, and network nodes may include cloud servers. The m network nodes are connected to each other, and the SDWAN management system uses Software-Defined Wide Area Network (SDWAN) technology to form an SDWAN network.
[0030] Among them, network security reporting parameters may include at least one of the following: system garbage, system vulnerabilities, number of firewall attacks, firewall access status, system disconnection status, access volume, etc., which are not limited here.
[0031] In the specific implementation, the network security reporting parameters of m network areas corresponding to m network nodes within a preset time period can be determined, and m network security reporting parameters can be obtained, that is, the network range corresponding to the SDWAN management system can be fully monitored.
[0032] In a specific implementation, firewall technology can be used to determine the network security reporting parameters of m network areas corresponding to m network nodes within a preset time period to obtain m network security reporting parameters, or cloud security protection technology can be used to determine the network security reporting parameters of m network areas corresponding to m network nodes within a preset time period to obtain m network security reporting parameters.
[0033] 102. Determine m network security assessment parameters according to the m network security reporting parameters.
[0034] In the embodiment of the present application, the network security reporting parameters reflect the network security situation to a certain extent. Specifically, m network security evaluation parameters can be determined based on m network security reporting parameters.
[0035] Optionally, the first network security reporting parameter includes multiple network security reporting parameters within the preset time period, each network security reporting parameter corresponds to a reporting time; the first network security reporting parameter is any one of the m network security reporting parameters;
[0036] The above step 102, determining m network security assessment parameters based on the m network security reporting parameters, can be implemented as follows:
[0037] Determining a first fitting straight line according to the plurality of network security reporting parameters and corresponding reporting times;
[0038] Obtaining the absolute value of the slope of the first fitting straight line to obtain a first absolute value;
[0039] Determining a network security assessment parameter corresponding to each of the plurality of network security reporting parameters to obtain a plurality of reference network security assessment parameters;
[0040] A network security assessment parameter corresponding to the first network security reporting parameter is determined according to the multiple reference network security assessment parameters and the first absolute value.
[0041] In a specific implementation, taking the first network security reporting parameter as an example, the first network security reporting parameter is any network security reporting parameter among the m network security reporting parameters. The first network security reporting parameter includes multiple network security reporting parameters within a preset time period, and each network security reporting parameter corresponds to a reporting time. Therefore, each network security reporting parameter and the corresponding reporting time can be regarded as a coordinate point, resulting in multiple coordinate points. The horizontal axis of the coordinate system corresponding to the multiple coordinate points is time, and the vertical axis is the network security reporting parameter.
[0042] Next, a first fitting straight line can be determined based on multiple network security reporting parameters and the corresponding reporting time, that is, a straight line fitting is performed based on the multiple coordinate points to obtain the first fitting straight line, and then the absolute value of the slope of the first fitting straight line is obtained to obtain the first absolute value. The first absolute value reflects the network stability or network change trend.
[0043] Next, the network security evaluation parameters corresponding to each of the multiple network security reporting parameters can be determined to obtain multiple reference network security evaluation parameters, that is, the correlation between the network security reporting parameters and the network security evaluation parameters can be established. Specifically, the mapping relationship between the preset network security reporting parameters and the network security evaluation parameters can be pre-stored, and then, the network security evaluation parameters corresponding to each network security reporting parameter can be determined.
[0044] Finally, the network security assessment parameter corresponding to the first network security reporting parameter can be determined based on multiple reference network security assessment parameters and the first absolute value. In this way, the actual network security situation can be accurately assessed based on the continuous (over a period of time) network security reporting parameters, which helps to implement subsequent deep vulnerability scanning operations.
[0045] Optionally, the above step of determining the network security assessment parameter corresponding to the first network security reporting parameter according to the multiple reference network security assessment parameters and the first absolute value may be implemented as follows:
[0046] determining a minimum value and a maximum value among the plurality of reference network security assessment parameters;
[0047] determining a length of a first interval between the maximum value and the minimum value;
[0048] Determining mean values of the plurality of reference network security assessment parameters to obtain a first mean value;
[0049] determining a first adjustment parameter corresponding to the first interval length;
[0050] determining a first fine-tuning parameter corresponding to the first absolute value;
[0051] A network security assessment parameter corresponding to the first network security reporting parameter is determined according to the first adjustment parameter, the first fine-tuning parameter, and the first mean value.
[0052] In a specific implementation, the minimum and maximum values of multiple reference network security assessment parameters can be determined, as well as the length of a first interval between the maximum and minimum values, where the first interval length = maximum value - minimum value. The mean of the multiple reference network security assessment parameters can then be determined to obtain a first mean value, which reflects the overall level of network security.
[0053] Next, the mapping relationship between the preset interval length and the adjustment parameter can be pre-stored. Based on the mapping relationship, the first adjustment parameter corresponding to the first interval length can be determined. The interval length reflects the stability of the network security assessment to a certain extent. Accordingly, the mapping relationship between the preset absolute value and the fine-tuning parameter can be pre-stored. Based on the mapping relationship, the first fine-tuning parameter corresponding to the first absolute value can be determined. The first absolute value reflects the network stability or network change trend. Next, the network security assessment parameter corresponding to the first network security reporting parameter can be determined according to the first adjustment parameter, the first fine-tuning parameter and the first mean, that is, the network security assessment parameter corresponding to the first network security reporting parameter = the first mean × (1 + first adjustment parameter) × (1 + first fine-tuning parameter). In this way, the mean of the reference network security assessment parameter can be dynamically adjusted based on the stability of the actual network security assessment and the network stability or network change trend, so that the final network security assessment parameter depth conforms to the network stability and network change trend, which helps to ensure the stability and adaptability of the vulnerability scanning algorithm in the future.
[0054] 103. Obtain area attribute information of each of the m network areas to obtain m pieces of area attribute information.
[0055] The area attribute information of each of the m network areas may include at least one of the following: area size, area function, area data volume, area level, area location, etc., which are not limited here.
[0056] In a specific implementation, the regional attribute information of each of the m network areas can be obtained, resulting in m regional attribute information. That is, each network area can correspond to a regional attribute information. The regional attribute information can characterize the regional characteristics of the network area, and thus, the corresponding vulnerability scanning parameters can be determined in a targeted manner, thereby ensuring vulnerability scanning performance.
[0057] 104. Determine m vulnerability scanning parameters based on the m network security assessment parameters and the m area attribute information using cloud computing technology.
[0058] In an embodiment of the present application, the network security assessment parameters reflect to a certain extent the network security situation of the network area that the network node is responsible for, and the regional attribute information can characterize the regional characteristics of the network area. Furthermore, cloud computing technology can be used to determine m vulnerability scanning parameters based on m network security assessment parameters and m regional attribute information. That is, the corresponding vulnerability scanning parameters can be determined in combination with the network security situation of the network area that the network node is responsible for and the regional characteristics of the corresponding network area, which helps to ensure the efficiency of vulnerability scanning.
[0059] Optionally, the above step 104, determining m vulnerability scanning parameters using cloud computing technology based on the m network security assessment parameters and the m area attribute information, includes:
[0060] Determining a first vulnerability scanning algorithm corresponding to a first network security assessment parameter, where the first network security assessment parameter is any one of the m network security assessment parameters;
[0061] Evaluate the first network area corresponding to the first network security evaluation parameter according to the first area attribute information corresponding to the first network security evaluation parameter to obtain a first evaluation value;
[0062] determining a first vulnerability scanning control parameter corresponding to the first evaluation value;
[0063] Determine a key vulnerability scanning area and a quick vulnerability scanning area according to the network security reporting parameter corresponding to the first network security assessment parameter;
[0064] Determining a first cloud resource corresponding to the key vulnerability scanning area;
[0065] Determining a second cloud resource corresponding to the rapid vulnerability scanning area;
[0066] determining first vulnerability scanning parameters based on the first cloud resource, the first vulnerability scanning algorithm, and the first vulnerability scanning control parameters;
[0067] determining a second vulnerability scanning parameter according to the first cloud resource, the second cloud resource, the first vulnerability scanning algorithm, and the first vulnerability scanning control parameter;
[0068] Determine vulnerability scanning parameters corresponding to the first network security assessment parameters according to the first vulnerability scanning parameters and the second vulnerability scanning parameters.
[0069] Among them, the first vulnerability scanning algorithm may include at least one of the following: static vulnerability scanning algorithm, dynamic vulnerability scanning algorithm, compound vulnerability scanning algorithm, machine learning-based vulnerability scanning algorithm, deep learning-based vulnerability scanning algorithm, rule matching-based vulnerability detection, etc., which are not limited here.
[0070] Among them, the second vulnerability scanning algorithm can include at least one of the following: static vulnerability scanning algorithm, dynamic vulnerability scanning algorithm, compound vulnerability scanning algorithm, machine learning-based vulnerability scanning algorithm, deep learning-based vulnerability scanning algorithm, rule matching-based vulnerability detection, etc., which are not limited here.
[0071] Among them, the first cloud resources may include at least one of the following: computing resources, storage resources, network resources, virtualization resource pools, intelligent service resources, etc., which are not limited here.
[0072] The second cloud resources may include at least one of the following: computing resources, storage resources, network resources, virtualized resource pools, intelligent service resources, etc., which are not limited here.
[0073] Among them, computing resources can include at least one of the following: virtual machines (VMs), container instances (such as Kubernetes Pod), bare metal servers, etc., which are not limited here.
[0074] Among them, storage resources can include at least one of the following: object storage (such as S3), block storage (cloud hard disk), file storage (NAS), hot and cold data tiered storage, etc., which are not limited here.
[0075] Among them, network resources may include at least one of the following: virtual private cloud (VPC), load balancer, content delivery network (CDN), SD-WAN, etc., which are not limited here.
[0076] In a specific implementation, taking a first network security assessment parameter as an example, the first network security assessment parameter is any one of m network security assessment parameters. A mapping relationship between a preset network security assessment parameter and a vulnerability scanning algorithm can be pre-stored, and then, based on this mapping relationship, a first vulnerability scanning algorithm corresponding to the first network security assessment parameter can be determined. The first network security assessment parameter represents the network security status to a certain extent, and then, based on the actual network security status, a corresponding vulnerability algorithm can be selected, so that the vulnerability algorithm is deeply adapted to the network security status.
[0077] Correspondingly, the first network area corresponding to the first network security evaluation parameter can be evaluated according to the first area attribute information corresponding to the first network security evaluation parameter to obtain a first evaluation value. Specifically, the mapping relationship between the preset area attribute information and the evaluation value can be pre-stored, and then the evaluation value of the first area attribute information of the first network area can be determined based on the mapping relationship to obtain the first evaluation value. In this way, the regional characteristics of the corresponding network area can be accurately determined based on the regional attribute information.
[0078] Next, the mapping relationship between the preset evaluation value and the vulnerability scanning control parameter can be pre-stored. Based on the mapping relationship, the first vulnerability scanning control parameter corresponding to the first evaluation value can be determined, that is, the corresponding vulnerability scanning control parameter can be determined based on the regional characteristics of the network area. The scanning control parameter can be used to control the vulnerability scanning effect of the first vulnerability scanning algorithm. The vulnerability scanning effect can include at least one of the following: vulnerability scanning speed, vulnerability scanning accuracy, vulnerability scanning depth, etc., which are not limited here.
[0079] In actual applications, since the network security reporting parameters corresponding to the first network security assessment parameters also include possible vulnerability locations and key vulnerability scanning areas that need to be focused on, the key vulnerability scanning areas (areas with higher security requirements, areas where network vulnerabilities may exist, etc.) and the quick vulnerability scanning areas (areas with lower security requirements, areas with a lower probability of network vulnerabilities, etc.) can be determined based on the network security reporting parameters corresponding to the first network security assessment parameters.
[0080] Furthermore, the first cloud resource corresponding to the key vulnerability scanning area can be determined. Specifically, the corresponding first cloud resource can be determined based on the area size of the key vulnerability scanning area and the area importance of the key vulnerability scanning area. For example, the mapping relationship between the preset area size and the cloud resource can be pre-stored, and the first reference cloud resource corresponding to the area size of the key vulnerability scanning area can be determined based on the mapping relationship. The mapping relationship between the preset area importance and the adjustment parameter can also be pre-stored. Furthermore, the first adjustment parameter corresponding to the area importance of the key vulnerability scanning area can be determined based on the mapping relationship. The first cloud resource can be determined based on the first adjustment parameter and the first reference cloud resource. For example, the first cloud resource = (1 + first adjustment parameter) × first reference cloud resource.
[0081] Correspondingly, specifically, the corresponding second cloud resource can be determined based on the area size of the rapid vulnerability scanning area and the area importance of the rapid vulnerability scanning area. For example, the mapping relationship between the preset area size and the cloud resource can be pre-stored, and the second reference cloud resource corresponding to the area size of the rapid vulnerability scanning area can be determined based on the mapping relationship. The mapping relationship between the preset area importance and the adjustment parameter can also be pre-stored, and then the second adjustment parameter corresponding to the area importance of the rapid vulnerability scanning area can be determined based on the mapping relationship. The second cloud resource can be determined based on the second adjustment parameter and the second reference cloud resource. For example, the second cloud resource = (1 + second adjustment parameter) × second reference cloud resource.
[0082] Next, the first vulnerability scanning parameters may be determined based on the first cloud resources, the first vulnerability scanning algorithm, and the first vulnerability scanning control parameters. That is, the first vulnerability scanning parameters may include the first cloud resources, the first vulnerability scanning algorithm, and the first vulnerability scanning control parameters.
[0083] Correspondingly, the second vulnerability scanning parameter can also be determined based on the first cloud resource, the second cloud resource, the first vulnerability scanning algorithm and the first vulnerability scanning control parameter. Finally, the vulnerability scanning parameter corresponding to the first network security assessment parameter can be determined based on the first vulnerability scanning parameter and the second vulnerability scanning parameter.
[0084] In this example, on the one hand, the key vulnerability scanning area and the fast vulnerability scanning area can be preliminarily divided based on the network security reporting parameters, and the corresponding cloud resources can be determined based on the key vulnerability scanning area and the fast vulnerability scanning area. On the other hand, for the key vulnerability scanning area, not only the corresponding vulnerability algorithm is selected based on the actual network security status, so that the vulnerability algorithm and the network security status are deeply adapted, but also the corresponding vulnerability scanning control parameters are determined based on the regional characteristics of the network area, and the corresponding cloud resources are determined based on the regional size of the key vulnerability scanning area and the regional importance of the key vulnerability scanning area, so that the final vulnerability scanning parameters are deeply adapted to the key vulnerability scanning area. For the fast vulnerability scanning area, not only the corresponding vulnerability algorithm is selected based on the actual network security status, so that the vulnerability algorithm and the network security status are deeply adapted, but also the corresponding vulnerability scanning control parameters are determined based on the regional characteristics of the network area, and the corresponding cloud resources are determined based on the regional size of the fast vulnerability scanning area and the regional importance of the fast vulnerability scanning area.
[0085] Optionally, the above step of determining the second vulnerability scanning parameter based on the first cloud resource, the second cloud resource, the first vulnerability scanning algorithm, and the first vulnerability scanning control parameter may be implemented as follows:
[0086] Determine, based on the first cloud resources and the second cloud resources, a proportion of the first resource corresponding to the second cloud resource;
[0087] Determining a first optimization parameter corresponding to the first resource proportion;
[0088] Optimizing the first vulnerability scanning control parameter according to the first optimization parameter to obtain a second vulnerability scanning control parameter;
[0089] The second vulnerability scanning parameter is determined according to the second cloud resource, the first vulnerability scanning algorithm, and the second vulnerability scanning control parameter.
[0090] In an embodiment of the present application, the first resource proportion corresponding to the second cloud resource can be determined based on the first cloud resource and the second cloud resource, where the first resource proportion = the second cloud resource / (the first cloud resource + the second cloud resource). A mapping relationship between a preset resource proportion and an optimization parameter can also be pre-stored. Then, based on the mapping relationship, the first optimization parameter corresponding to the first resource proportion can be determined. Then, based on the first optimization parameter, some or all of the vulnerability scanning control parameters in the first vulnerability scanning control parameter are optimized to obtain the second vulnerability scanning control parameter, where the second vulnerability scanning control parameter = (1 + the first optimization parameter) * the first vulnerability scanning control parameter. Finally, the second vulnerability scanning parameter can be determined based on the second cloud resource, the first vulnerability scanning algorithm, and the second vulnerability scanning control parameter. Furthermore, for the fast vulnerability scanning area, not only is the corresponding vulnerability algorithm selected based on the actual network security status, so that the vulnerability algorithm is deeply adapted to the network security status, but the corresponding vulnerability scanning control parameters are also determined based on the regional characteristics of the network area, and the corresponding cloud resources are determined based on the regional size of the fast vulnerability scanning area and the regional importance of the fast vulnerability scanning area. The vulnerability scanning control parameters are also dynamically optimized based on the cloud resource differences between the key vulnerability scanning area and the fast vulnerability scanning area to improve the vulnerability scanning speed.
[0091] The second vulnerability scanning parameters may include a second cloud resource, a first vulnerability scanning algorithm, and a second vulnerability scanning control parameter.
[0092] 105. Control the m network nodes to perform vulnerability scanning according to the m vulnerability scanning parameters.
[0093] In the specific implementation, for each network node, the corresponding network node can use the corresponding vulnerability scanning parameters to perform vulnerability scanning on the corresponding network area, thereby achieving full-range monitoring of the SDWAN management system, thereby improving the distributed device vulnerability scanning intelligence of SDWAN.
[0094] Optionally, the above step 105, controlling the m network nodes to perform vulnerability scanning according to the m vulnerability scanning parameters, can be implemented as follows:
[0095] Determine the scanning frequencies corresponding to the m network security assessment parameters to obtain m scanning frequencies;
[0096] According to the m scanning frequencies, the m network nodes are controlled to perform vulnerability scanning according to the m vulnerability scanning parameters.
[0097] Among them, if the network security assessment parameters are different, the larger the scanning frequency, the larger the network security assessment parameter, the more secure the network and the lower the scanning frequency. Conversely, the smaller the network security assessment parameter, the less secure the network and the higher the scanning frequency. That is, the mapping relationship between the preset network security assessment parameters and the scanning frequency can be pre-stored, and then, the scanning frequencies corresponding to the m network security assessment parameters can be determined based on the mapping relationship to obtain m scanning frequencies. Then, according to the m scanning frequencies, the m network nodes are controlled to perform vulnerability scanning according to the m vulnerability scanning parameters. In this way, for each network node, the corresponding network node adopts the corresponding vulnerability scanning parameters to perform vulnerability scanning on the corresponding network area, and also adaptively adjusts the scanning frequency based on the actual network security status to achieve a balance between power consumption and security. Thus, full-range monitoring of the SDWAN management system can be achieved, and the intelligence of the distributed device vulnerability scanning of SDWAN can be improved.
[0098] It can be seen that the distributed device vulnerability scanning method based on cloud computing and SDWAN described in the embodiment of the present application is applied to the SDWAN management system. The SDWAN management system includes m network nodes, where m is an integer greater than 1. Each network node corresponds to a vulnerability scanning task in a network area. The network security reporting parameters of the m network areas corresponding to the m network nodes within a preset time period are determined to obtain m network security reporting parameters. M network security assessment parameters are determined based on the m network security reporting parameters. Regional attribute information of each of the m network areas is obtained to obtain m regional attribute information. Based on the m network security assessment parameters and the m regional attribute information, m vulnerability scanning parameters are determined using cloud computing technology. The m network nodes are controlled to perform vulnerability scanning based on the m vulnerability scanning parameters. On the one hand, the corresponding vulnerability scanning parameters can be determined based on the network security status of the network area for which the network node is responsible and the regional characteristics of the corresponding network area, which helps to ensure the efficiency of vulnerability scanning. On the other hand, for each network node, the corresponding vulnerability scanning parameters can be used by the corresponding network node to perform vulnerability scanning on the corresponding network area, thereby achieving full-range monitoring of the SDWAN management system. In this way, the intelligence of the distributed device vulnerability scanning of the SDWAN can be improved.
[0099] See also Figure 3 , Figure 3: This is a structural diagram of an electronic device provided in an embodiment of the present application. The electronic device includes a processor, a memory, a communication interface, and one or more programs. The one or more programs are stored in the memory and configured to be executed by the processor. In an embodiment of the present application, the device is applied to an SDWAN management system. The SDWAN management system includes m network nodes, where m is an integer greater than 1, and each network node corresponds to a vulnerability scanning task in a network area. The program includes instructions for performing the following steps:
[0100] Determining network security reporting parameters of m network areas corresponding to the m network nodes within a preset time period to obtain m network security reporting parameters;
[0101] Determining m network security assessment parameters based on the m network security reporting parameters;
[0102] Acquire area attribute information of each of the m network areas to obtain m pieces of area attribute information;
[0103] Determining m vulnerability scanning parameters using cloud computing technology based on the m network security assessment parameters and the m area attribute information;
[0104] The m network nodes are controlled to perform vulnerability scanning according to the m vulnerability scanning parameters.
[0105] Optionally, the first network security reporting parameter includes multiple network security reporting parameters within the preset time period, each network security reporting parameter corresponds to a reporting time; the first network security reporting parameter is any one of the m network security reporting parameters;
[0106] In terms of determining the m network security assessment parameters based on the m network security reporting parameters, the program includes instructions for executing the following steps:
[0107] Determining a first fitting straight line according to the plurality of network security reporting parameters and corresponding reporting times;
[0108] Obtaining the absolute value of the slope of the first fitting straight line to obtain a first absolute value;
[0109] Determining a network security assessment parameter corresponding to each of the plurality of network security reporting parameters to obtain a plurality of reference network security assessment parameters;
[0110] A network security assessment parameter corresponding to the first network security reporting parameter is determined according to the multiple reference network security assessment parameters and the first absolute value.
[0111] Optionally, in determining the network security assessment parameter corresponding to the first network security reporting parameter based on the multiple reference network security assessment parameters and the first absolute value, the program includes instructions for performing the following steps:
[0112] determining a minimum value and a maximum value among the plurality of reference network security assessment parameters;
[0113] determining a length of a first interval between the maximum value and the minimum value;
[0114] Determining mean values of the plurality of reference network security assessment parameters to obtain a first mean value;
[0115] determining a first adjustment parameter corresponding to the first interval length;
[0116] determining a first fine-tuning parameter corresponding to the first absolute value;
[0117] A network security assessment parameter corresponding to the first network security reporting parameter is determined according to the first adjustment parameter, the first fine-tuning parameter, and the first mean value.
[0118] Optionally, in determining the m vulnerability scanning parameters using cloud computing technology based on the m network security assessment parameters and the m area attribute information, the program includes instructions for executing the following steps:
[0119] Determining a first vulnerability scanning algorithm corresponding to a first network security assessment parameter, where the first network security assessment parameter is any one of the m network security assessment parameters;
[0120] Evaluate the first network area corresponding to the first network security evaluation parameter according to the first area attribute information corresponding to the first network security evaluation parameter to obtain a first evaluation value;
[0121] determining a first vulnerability scanning control parameter corresponding to the first evaluation value;
[0122] Determine a key vulnerability scanning area and a quick vulnerability scanning area according to the network security reporting parameter corresponding to the first network security assessment parameter;
[0123] Determining a first cloud resource corresponding to the key vulnerability scanning area;
[0124] Determining a second cloud resource corresponding to the rapid vulnerability scanning area;
[0125] determining first vulnerability scanning parameters based on the first cloud resource, the first vulnerability scanning algorithm, and the first vulnerability scanning control parameters;
[0126] determining a second vulnerability scanning parameter according to the first cloud resource, the second cloud resource, the first vulnerability scanning algorithm, and the first vulnerability scanning control parameter;
[0127] Determine vulnerability scanning parameters corresponding to the first network security assessment parameters according to the first vulnerability scanning parameters and the second vulnerability scanning parameters.
[0128] Optionally, in determining the second vulnerability scanning parameter based on the first cloud resource, the second cloud resource, the first vulnerability scanning algorithm, and the first vulnerability scanning control parameter, the program includes instructions for performing the following steps:
[0129] Determine, based on the first cloud resources and the second cloud resources, a proportion of the first resource corresponding to the second cloud resource;
[0130] Determining a first optimization parameter corresponding to the first resource proportion;
[0131] Optimizing the first vulnerability scanning control parameter according to the first optimization parameter to obtain a second vulnerability scanning control parameter;
[0132] The second vulnerability scanning parameter is determined according to the second cloud resource, the first vulnerability scanning algorithm, and the second vulnerability scanning control parameter.
[0133] Optionally, in controlling the m network nodes to perform vulnerability scanning according to the m vulnerability scanning parameters, the program includes instructions for executing the following steps:
[0134] Determine the scanning frequencies corresponding to the m network security assessment parameters to obtain m scanning frequencies;
[0135] According to the m scanning frequencies, the m network nodes are controlled to perform vulnerability scanning according to the m vulnerability scanning parameters.
[0136] It can be seen that the electronic device described in the embodiment of the present application is applied to the SDWAN management system, which includes m network nodes, where m is an integer greater than 1, and each network node corresponds to a vulnerability scanning work of a network area. The network security reporting parameters of the m network areas corresponding to the m network nodes within a preset time period are determined to obtain m network security reporting parameters. M network security evaluation parameters are determined based on the m network security reporting parameters. Regional attribute information of each of the m network areas is obtained to obtain m regional attribute information. Cloud computing technology is used to determine m vulnerability scanning parameters based on the m network security evaluation parameters and the m regional attribute information. The m network nodes are controlled to perform vulnerability scanning according to the m vulnerability scanning parameters. On the one hand, the corresponding vulnerability scanning parameters can be determined in combination with the network security status of the network area for which the network node is responsible and the regional characteristics of the corresponding network area, which helps to ensure the efficiency of vulnerability scanning. On the other hand, for each network node, the corresponding vulnerability scanning parameters can be used by the corresponding network node to perform vulnerability scanning on the corresponding network area, thereby achieving full-range monitoring of the SDWAN management system. In this way, the intelligence of the distributed device vulnerability scanning of the SDWAN can be improved.
[0137] The electronic device may be a network node, or the electronic device may be a device in an SDWAN management system.
[0138] Figure 4 This is a functional unit composition block diagram of an SDWAN management system 400 for distributed device vulnerability scanning based on cloud computing and SDWAN involved in an embodiment of the present application. The SDWAN management system 400 for distributed device vulnerability scanning based on cloud computing and SDWAN includes m network nodes, where m is an integer greater than 1, and each network node corresponds to a vulnerability scanning task in a network area; the SDWAN management system 400 for distributed device vulnerability scanning based on cloud computing and SDWAN includes: a first determination unit 401, an acquisition unit 402, a second determination unit 403, and a scanning unit 404, wherein,
[0139] The first determining unit 401 is configured to determine network security reporting parameters of the m network areas corresponding to the m network nodes within a preset time period to obtain m network security reporting parameters; and determine m network security assessment parameters based on the m network security reporting parameters;
[0140] The acquiring unit 402 is configured to acquire area attribute information of each of the m network areas to obtain m pieces of area attribute information;
[0141] The second determining unit 403 is configured to determine m vulnerability scanning parameters using cloud computing technology according to the m network security assessment parameters and the m area attribute information;
[0142] The scanning unit 404 is configured to control the m network nodes to perform vulnerability scanning according to the m vulnerability scanning parameters.
[0143] Optionally, the first network security reporting parameter includes multiple network security reporting parameters within the preset time period, each network security reporting parameter corresponds to a reporting time; the first network security reporting parameter is any one of the m network security reporting parameters;
[0144] In determining the m network security assessment parameters according to the m network security reporting parameters, the first determining unit 401 is specifically configured to:
[0145] Determining a first fitting straight line according to the plurality of network security reporting parameters and corresponding reporting times;
[0146] Obtaining the absolute value of the slope of the first fitting straight line to obtain a first absolute value;
[0147] Determining a network security assessment parameter corresponding to each of the plurality of network security reporting parameters to obtain a plurality of reference network security assessment parameters;
[0148] A network security assessment parameter corresponding to the first network security reporting parameter is determined according to the multiple reference network security assessment parameters and the first absolute value.
[0149] Optionally, in determining the network security assessment parameter corresponding to the first network security reporting parameter according to the multiple reference network security assessment parameters and the first absolute value, the first determining unit 401 is specifically configured to:
[0150] determining a minimum value and a maximum value among the plurality of reference network security assessment parameters;
[0151] determining a length of a first interval between the maximum value and the minimum value;
[0152] Determining mean values of the plurality of reference network security assessment parameters to obtain a first mean value;
[0153] determining a first adjustment parameter corresponding to the first interval length;
[0154] determining a first fine-tuning parameter corresponding to the first absolute value;
[0155] A network security assessment parameter corresponding to the first network security reporting parameter is determined according to the first adjustment parameter, the first fine-tuning parameter, and the first mean value.
[0156] Optionally, in determining the m vulnerability scanning parameters using cloud computing technology according to the m network security assessment parameters and the m area attribute information, the second determining unit 403 is specifically configured to:
[0157] Determining a first vulnerability scanning algorithm corresponding to a first network security assessment parameter, where the first network security assessment parameter is any one of the m network security assessment parameters;
[0158] Evaluate the first network area corresponding to the first network security evaluation parameter according to the first area attribute information corresponding to the first network security evaluation parameter to obtain a first evaluation value;
[0159] determining a first vulnerability scanning control parameter corresponding to the first evaluation value;
[0160] Determine a key vulnerability scanning area and a quick vulnerability scanning area according to the network security reporting parameter corresponding to the first network security assessment parameter;
[0161] Determining a first cloud resource corresponding to the key vulnerability scanning area;
[0162] Determining a second cloud resource corresponding to the rapid vulnerability scanning area;
[0163] determining first vulnerability scanning parameters based on the first cloud resource, the first vulnerability scanning algorithm, and the first vulnerability scanning control parameters;
[0164] determining a second vulnerability scanning parameter according to the first cloud resource, the second cloud resource, the first vulnerability scanning algorithm, and the first vulnerability scanning control parameter;
[0165] Determine vulnerability scanning parameters corresponding to the first network security assessment parameters according to the first vulnerability scanning parameters and the second vulnerability scanning parameters.
[0166] Optionally, in determining the second vulnerability scanning parameter according to the first cloud resource, the second cloud resource, the first vulnerability scanning algorithm, and the first vulnerability scanning control parameter, the second determining unit 403 is specifically configured to:
[0167] Determine, based on the first cloud resources and the second cloud resources, a proportion of the first resource corresponding to the second cloud resource;
[0168] Determining a first optimization parameter corresponding to the first resource proportion;
[0169] Optimizing the first vulnerability scanning control parameter according to the first optimization parameter to obtain a second vulnerability scanning control parameter;
[0170] The second vulnerability scanning parameter is determined according to the second cloud resource, the first vulnerability scanning algorithm, and the second vulnerability scanning control parameter.
[0171] Optionally, in controlling the m network nodes to perform vulnerability scanning according to the m vulnerability scanning parameters, the scanning unit 404 is specifically configured to:
[0172] Determine the scanning frequencies corresponding to the m network security assessment parameters to obtain m scanning frequencies;
[0173] According to the m scanning frequencies, the m network nodes are controlled to perform vulnerability scanning according to the m vulnerability scanning parameters.
[0174] It can be seen that the SDWAN management system for distributed device vulnerability scanning based on cloud computing and SDWAN described in the embodiment of the present application includes m network nodes, where m is an integer greater than 1, and each network node corresponds to a vulnerability scanning task in a network area. The network security reporting parameters of the m network areas corresponding to the m network nodes within a preset time period are determined to obtain m network security reporting parameters. M network security assessment parameters are determined based on the m network security reporting parameters. Regional attribute information of each of the m network areas is obtained to obtain m regional attribute information. Based on the m network security assessment parameters and the m regional attribute information, m vulnerability scanning parameters are determined using cloud computing technology. The m network nodes are controlled to perform vulnerability scanning based on the m vulnerability scanning parameters. On the one hand, the corresponding vulnerability scanning parameters can be determined based on the network security status of the network area for which the network node is responsible and the regional characteristics of the corresponding network area, which helps to ensure the efficiency of vulnerability scanning. On the other hand, for each network node, the corresponding vulnerability scanning parameters can be used by the corresponding network node to perform vulnerability scanning on the corresponding network area, thereby achieving full-range monitoring of the SDWAN management system. In this way, the intelligence of the distributed device vulnerability scanning of the SDWAN can be improved.
[0175] It can be understood that the functions of each program module of the SDWAN management system for distributed device vulnerability scanning based on cloud computing and SDWAN in this embodiment can be specifically implemented according to the method in the above-mentioned method embodiment. The specific implementation process can refer to the relevant description of the above-mentioned method embodiment, and will not be repeated here.
[0176] An embodiment of the present application also provides a computer storage medium, wherein the computer storage medium stores a computer program for electronic data exchange, and the computer program enables a computer to execute part or all of the steps of any method described in the above method embodiments, and the above computer includes an electronic device.
[0177] The present application also provides a computer program product comprising a non-transitory computer-readable storage medium storing a computer program, wherein the computer program is operable to cause a computer to perform some or all of the steps of any of the methods described in the above method embodiments. The computer program product may be a software installation package, and the computer may comprise an electronic device.
[0178] It should be noted that for the aforementioned method embodiments, for the sake of simplicity, they are all expressed as a series of action combinations, but those skilled in the art should be aware that this application is not limited by the order of the actions described, because according to this application, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily required by this application.
[0179] In the above embodiments, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0180] In the several embodiments provided in this application, it should be understood that the disclosed devices can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the above-mentioned units is only a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, and the indirect coupling or communication connection of devices or units can be electrical or other forms.
[0181] The units described above as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0182] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0183] If the above-mentioned integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable memory. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product, which is stored in a memory and includes a number of instructions for enabling a computer device (which can be a personal computer, server or network device, etc.) to execute all or part of the steps of the above-mentioned methods of each embodiment of the present application. The aforementioned memory includes: various media that can store program codes, such as a USB flash drive, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk or an optical disk.
[0184] Those skilled in the art will appreciate that all or part of the steps in the various methods of the above embodiments can be completed by instructing related hardware through a program. The program can be stored in a computer-readable memory, and the memory can include: a flash drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, etc.
[0185] The above is a detailed introduction to the embodiments of the present application. Specific examples are used herein to illustrate the principles and implementation methods of the present application. The description of the above embodiments is only used to help understand the method and core idea of the present application. At the same time, for those skilled in the art, according to the idea of the present application, there may be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as a limitation on the present application.
Claims
1. A distributed device vulnerability scanning method based on cloud computing and SDWAN, characterized in that: Applied to an SDWAN management system, the SDWAN management system includes m network nodes, where m is an integer greater than 1, and each network node corresponds to a vulnerability scanning task in a network area; the method includes: Determining network security reporting parameters of m network areas corresponding to the m network nodes within a preset time period to obtain m network security reporting parameters; Determining m network security assessment parameters based on the m network security reporting parameters; Acquire area attribute information of each of the m network areas to obtain m pieces of area attribute information; Determining m vulnerability scanning parameters using cloud computing technology based on the m network security assessment parameters and the m area attribute information; The m network nodes are controlled to perform vulnerability scanning according to the m vulnerability scanning parameters.
2. The method according to claim 1, characterized in that The first network security reporting parameter includes multiple network security reporting parameters within the preset time period, each network security reporting parameter corresponds to a reporting time; the first network security reporting parameter is any one of the m network security reporting parameters; The determining m network security assessment parameters according to the m network security reporting parameters includes: Determining a first fitting straight line according to the plurality of network security reporting parameters and corresponding reporting times; Obtaining the absolute value of the slope of the first fitting straight line to obtain a first absolute value; Determining a network security assessment parameter corresponding to each of the plurality of network security reporting parameters to obtain a plurality of reference network security assessment parameters; A network security assessment parameter corresponding to the first network security reporting parameter is determined according to the multiple reference network security assessment parameters and the first absolute value.
3. The method according to claim 2, characterized in that The determining, according to the multiple reference network security assessment parameters and the first absolute value, a network security assessment parameter corresponding to the first network security reporting parameter includes: determining a minimum value and a maximum value among the plurality of reference network security assessment parameters; determining a length of a first interval between the maximum value and the minimum value; Determining mean values of the plurality of reference network security assessment parameters to obtain a first mean value; determining a first adjustment parameter corresponding to the first interval length; determining a first fine-tuning parameter corresponding to the first absolute value; A network security assessment parameter corresponding to the first network security reporting parameter is determined according to the first adjustment parameter, the first fine-tuning parameter, and the first mean value.
4. The method according to any one of claims 1 to 3, characterized in that Determining m vulnerability scanning parameters using cloud computing technology based on the m network security assessment parameters and the m area attribute information includes: Determining a first vulnerability scanning algorithm corresponding to a first network security assessment parameter, where the first network security assessment parameter is any one of the m network security assessment parameters; Evaluate the first network area corresponding to the first network security evaluation parameter according to the first area attribute information corresponding to the first network security evaluation parameter to obtain a first evaluation value; determining a first vulnerability scanning control parameter corresponding to the first evaluation value; Determine a key vulnerability scanning area and a quick vulnerability scanning area according to the network security reporting parameter corresponding to the first network security assessment parameter; Determining a first cloud resource corresponding to the key vulnerability scanning area; Determining a second cloud resource corresponding to the rapid vulnerability scanning area; determining first vulnerability scanning parameters based on the first cloud resource, the first vulnerability scanning algorithm, and the first vulnerability scanning control parameters; determining a second vulnerability scanning parameter according to the first cloud resource, the second cloud resource, the first vulnerability scanning algorithm, and the first vulnerability scanning control parameter; Determine vulnerability scanning parameters corresponding to the first network security assessment parameters according to the first vulnerability scanning parameters and the second vulnerability scanning parameters.
5. The method according to claim 4, characterized in that The determining the second vulnerability scanning parameter according to the first cloud resource, the second cloud resource, the first vulnerability scanning algorithm, and the first vulnerability scanning control parameter includes: Determine, based on the first cloud resources and the second cloud resources, a proportion of the first resource corresponding to the second cloud resource; Determining a first optimization parameter corresponding to the first resource proportion; Optimizing the first vulnerability scanning control parameter according to the first optimization parameter to obtain a second vulnerability scanning control parameter; The second vulnerability scanning parameter is determined according to the second cloud resource, the first vulnerability scanning algorithm, and the second vulnerability scanning control parameter.
6. The method according to any one of claims 1 to 3, characterized in that The controlling the m network nodes to perform vulnerability scanning according to the m vulnerability scanning parameters includes: Determine the scanning frequencies corresponding to the m network security assessment parameters to obtain m scanning frequencies; According to the m scanning frequencies, the m network nodes are controlled to perform vulnerability scanning according to the m vulnerability scanning parameters.
7. An SDWAN management system for distributed device vulnerability scanning based on cloud computing and SDWAN, characterized in that: The SDWAN management system includes m network nodes, where m is an integer greater than 1, and each network node corresponds to a vulnerability scanning task in a network area; the SDWAN management system includes: a first determining unit, an acquiring unit, a second determining unit, and a scanning unit, wherein: The first determining unit is configured to determine network security reporting parameters of the m network areas corresponding to the m network nodes within a preset time period to obtain m network security reporting parameters; and determine m network security assessment parameters based on the m network security reporting parameters; The acquiring unit is configured to acquire the area attribute information of each of the m network areas to obtain m pieces of area attribute information; The second determining unit is configured to determine m vulnerability scanning parameters using cloud computing technology based on the m network security assessment parameters and the m area attribute information; The scanning unit is used to control the m network nodes to perform vulnerability scanning according to the m vulnerability scanning parameters.
8. The SDWAN management system according to claim 7, wherein: The first network security reporting parameter includes multiple network security reporting parameters within the preset time period, each network security reporting parameter corresponds to a reporting time; the first network security reporting parameter is any one of the m network security reporting parameters; In determining the m network security assessment parameters according to the m network security reporting parameters, the first determining unit is specifically configured to: Determining a first fitting straight line according to the plurality of network security reporting parameters and corresponding reporting times; Obtaining the absolute value of the slope of the first fitting straight line to obtain a first absolute value; Determining a network security assessment parameter corresponding to each of the plurality of network security reporting parameters to obtain a plurality of reference network security assessment parameters; A network security assessment parameter corresponding to the first network security reporting parameter is determined according to the multiple reference network security assessment parameters and the first absolute value.
9. The SDWAN management system according to claim 8, characterized in that: In determining the network security assessment parameter corresponding to the first network security reporting parameter according to the multiple reference network security assessment parameters and the first absolute value, the first determining unit is specifically configured to: determining a minimum value and a maximum value among the plurality of reference network security assessment parameters; determining a length of a first interval between the maximum value and the minimum value; Determining mean values of the plurality of reference network security assessment parameters to obtain a first mean value; determining a first adjustment parameter corresponding to the first interval length; determining a first fine-tuning parameter corresponding to the first absolute value; A network security assessment parameter corresponding to the first network security reporting parameter is determined according to the first adjustment parameter, the first fine-tuning parameter, and the first mean value.
10. The SDWAN management system according to any one of claims 7 to 9, characterized in that: In the aspect of determining the m vulnerability scanning parameters using cloud computing technology based on the m network security assessment parameters and the m area attribute information, the second determining unit is specifically configured to: Determining a first vulnerability scanning algorithm corresponding to a first network security assessment parameter, where the first network security assessment parameter is any one of the m network security assessment parameters; Evaluate the first network area corresponding to the first network security evaluation parameter according to the first area attribute information corresponding to the first network security evaluation parameter to obtain a first evaluation value; determining a first vulnerability scanning control parameter corresponding to the first evaluation value; Determine a key vulnerability scanning area and a quick vulnerability scanning area according to the network security reporting parameter corresponding to the first network security assessment parameter; Determining a first cloud resource corresponding to the key vulnerability scanning area; Determining a second cloud resource corresponding to the rapid vulnerability scanning area; determining first vulnerability scanning parameters based on the first cloud resource, the first vulnerability scanning algorithm, and the first vulnerability scanning control parameters; determining a second vulnerability scanning parameter according to the first cloud resource, the second cloud resource, the first vulnerability scanning algorithm, and the first vulnerability scanning control parameter; Determine vulnerability scanning parameters corresponding to the first network security assessment parameters according to the first vulnerability scanning parameters and the second vulnerability scanning parameters.