Method and system for automatically checking security of network equipment

By obtaining the security verification task type of network equipment, extracting and classifying security verification parameters, and capturing device status changes and task switching signals, automated security verification of network equipment is achieved, solving the problems of low efficiency and poor accuracy in existing technologies and improving the adaptability and accuracy of verification.

CN120658494APending Publication Date: 2025-09-16STATE GRID GRID GANSU ELECTRIC POWER CO QINGYANG POWER SUPPLY CO
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510967812.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-14
Publication Date
2025-09-16

AI Technical Summary

Technical Problem

Existing network equipment security verification methods are difficult to quickly adapt to diverse security needs and dynamically changing network environments, resulting in low verification efficiency, poor accuracy and reliability, and complex parameter management.

Method used

By obtaining the security verification task type of network equipment, extracting security verification parameters, capturing the trigger signals of equipment operation status changes and task type switching, classifying parameter change nodes, and obtaining general and special parameters, automated security verification is achieved.

Benefits of technology

It achieves efficient and accurate network equipment security verification in complex environments, reduces verification omissions and misjudgments, reduces the complexity of parameter management, and improves adaptability and accuracy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120658494A_ABST
    Figure CN120658494A_ABST
Patent Text Reader

Abstract

The invention provides a network equipment security automatic checking method and system, and belongs to the technical field of network security operation and maintenance. The method comprises the following steps: acquiring a security check task type and extracting security check parameters, wherein the task type covers a device security state and a state switching node; extracting parameter change nodes based on the safety trigger signal, wherein the parameter change nodes comprise parameter adjustment nodes which are changed due to the running state of equipment in the same task type and parameter reset nodes when different task types are switched; classifying the changed nodes to obtain security check offset parameters, wherein the security check offset parameters comprise parameter offsets in the same task type and in switching of different task types; similar parameters containing general parameters and special parameters are obtained based on the offset parameters, the control equipment performs automatic checking, the general parameters can be reused across tasks, and the special parameters are suitable for specific task types. According to the method, automatic checking of network equipment security is realized by dynamically processing parameters and nodes.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security operation and maintenance technology, and more specifically, to a method and system for automated network equipment security verification. Background Art

[0002] With the rapid development of network technology, the types and number of network devices are constantly increasing, and their operating environments are becoming increasingly complex. As the core nodes of network communications, the security of network devices is directly related to the stable operation of the entire network system. Currently, network device security verification mainly relies on manual operations or semi-automated tools, which presents numerous problems when faced with diverse security requirements and dynamically changing network environments.

[0003] In practical applications, network equipment must handle various security verification tasks, such as daily operational status monitoring and safety checks during equipment upgrades or maintenance. Different security verification tasks require different device security parameters, and traditional verification methods often struggle to quickly adapt to changing task types, resulting in low verification efficiency. Furthermore, network equipment's operating status constantly changes during operation, due to load fluctuations and network traffic changes. These changes require real-time adjustment of security verification parameters. However, existing verification methods lack effective mechanisms for dynamic parameter adjustment, making verification omissions and misjudgments more likely.

[0004] Furthermore, differences in the models, configurations, and network environments of different network devices make it difficult to balance the universality and specificity of security verification parameters. Universal parameters may face adaptation issues due to differences in device characteristics when reused across devices and task types. Dedicated parameters, however, increase the difficulty of parameter management and maintenance due to their customization. In scenarios involving multiple task type switching and dynamic changes in device status, traditional security verification methods are unable to accurately extract parameter change nodes or effectively calculate parameter offsets, severely impacting the accuracy and reliability of automated security verification and making it difficult to meet the high standards for device security in modern networks. Summary of the Invention

[0005] The purpose of this application is to provide a method and system for automated network device security verification to solve the problems raised in the above background technology.

[0006] To achieve the above objectives, the present invention provides a method for automated network device security verification, the method comprising: S1: Obtain a security verification task type of a network device, and extract security verification parameters of the network device based on the security verification task type; the security verification task type includes a device security state and a switching node of the device security state; S2: Extracting a security trigger signal of a network device based on the security verification parameter; extracting a security verification parameter change node based on the security trigger signal of the network device; the security verification parameter change node includes: a parameter adjustment node triggered by a change in the device operating status within the same security verification task type; and a parameter reset node triggered when switching between different security verification task types; S3: Based on the security verification parameter change nodes, classify the nodes according to the same security verification parameter change nodes and the nodes with different security verification parameter change nodes to obtain a security verification offset parameter; the security verification offset parameter includes the security parameter offset of the network device itself during the verification process of the same security verification task type and the security parameter offset generated by the network device during the process of changing the task type of different security verification tasks; S4: Based on the security verification offset parameters, obtain security verification similarity parameters; based on the security verification similarity parameters, control the network equipment to perform security automation verification; the security verification similarity parameters include general parameters and special parameters; the general parameters refer to basic security rule parameters that are reusable across task types; the special parameters refer to customized security rule parameters that are only applicable to specific security verification task types.

[0007] In one embodiment of the present application, the obtaining of the security verification task type of the network device extracts the security verification parameters of the network device based on the security verification task type; the security verification task type includes a device security state and a switching node of the device security state, including: Based on the device security status, obtain an initial rule set for network device identity authentication, access control, and log auditing, and a time period corresponding to the initial rule set; Based on the switching node of the device security status, obtaining a set of adjustment rules for network device identity authentication, access control, and log audit and a time period corresponding to the set of adjustment rules; Based on the initial rule set and the time period corresponding to the initial rule set, a revised adjustment rule set is obtained using an adjustment rule verification method; Based on the initial rule set and the revised adjustment rule set, security verification parameters of the network device are obtained.

[0008] In one embodiment of the present application, the modified adjustment rule set is obtained by using the adjustment rule verification method based on the initial rule set and the time period corresponding to the initial rule set, including: obtaining the rule deviation amount of each stage through the adjustment rule verification method, and obtaining the adjustment rule correction amount through the adjustment rule correction method; the adjustment rule verification method is to statistically calculate the degree of deviation between the rule execution results of each stage and the expected results; the adjustment rule correction method is to perform linear correction on the original rule value according to the degree of deviation.

[0009] In one embodiment of the present application, extracting a security trigger signal of a network device based on the security check parameter includes: Extracting an adjustment rule set based on the safety verification parameters to generate a first safety trigger signal; extracting a revised set of adjustment rules based on the safety verification parameters and generating a second safety trigger signal; Based on the first security trigger signal and the second security trigger signal, obtaining security signal trigger trends in the three stages of identity authentication, access control, and log audit for the same security verification task type and different security verification task types; Based on the safety signal triggering trend, the safety triggering signal of the network device is obtained in advance or in a delayed manner.

[0010] In one embodiment of the present application, extracting the security verification parameter change node based on the security trigger signal of the network device includes: By calculating the matching degree between the safety trigger signal and the benchmark time series data corresponding to the historical parameter adjustment node, if the matching degree is greater than the preset matching degree threshold, it is determined to be a trend consistency parameter adjustment node and used as a parameter adjustment node of the same safety verification task type; By calculating the matching degree between the safety trigger signal and the benchmark time series data corresponding to the historical parameter reset node, if the matching degree is less than the preset matching degree threshold, it is determined to be a trend reversal parameter adjustment node, which serves as the parameter reset node for different safety verification task types.

[0011] In one embodiment of the present application, the degree of matching between the safety trigger signal and the benchmark timing data corresponding to the historical parameter adjustment node is calculated, including: the matching degree calculation method is the overlapping ratio of the timing data of the safety trigger signal and the benchmark timing data, wherein the overlapping ratio is the proportion of data points that simultaneously meet the time window and rule type conditions.

[0012] In one embodiment of the present application, obtaining the security trigger signal of the network device in advance or in delay based on the security signal trigger trend includes: If the safety signal trigger trend is greater than a preset safety signal trigger trend threshold, a safety trigger signal of the network device is obtained in advance; If the safety signal trigger trend is less than a preset safety signal trigger trend threshold, obtaining the safety trigger signal of the network device is delayed.

[0013] In one embodiment of the present application, the obtaining of the safety check offset parameter by classifying the safety check parameter change nodes according to the same safety check parameter change nodes and different safety check parameter change nodes based on the safety check parameter change nodes includes: Extract parameter adjustment nodes triggered by changes in equipment operating status within the same safety verification task type and mark them as the same safety verification parameter change nodes; Extract the parameter reset nodes triggered when switching between different safety verification task types and mark them as different safety verification parameter change nodes; Based on the same safety check parameter change node, calculate the parameter offset within the same task type and record it as the first safety check offset parameter; Based on different safety check parameter change nodes, the parameter offset when the task type is switched is calculated and recorded as the second safety check offset parameter; A weighted sum of the first safety check offset parameter and the second safety check offset parameter is taken as a final safety check offset parameter.

[0014] In one embodiment of the present application, obtaining a security verification similarity parameter based on the security verification offset parameter; and controlling a network device to perform automated security verification based on the security verification similarity parameter includes: Using identity authentication, access control, and log auditing as benchmark time series, we analyze the common features of security verification offset parameters, extract reusable parameter sets across task types, and mark them as common parameters. Analyze the differential features of the safety verification offset parameters, extract the parameter set that is only applicable to a specific task type, and mark it as a dedicated parameter; Use common parameters as a global verification benchmark and apply them to the verification process for all mission types; Dynamically adjust the verification parameters of specific task types based on dedicated parameters, and combine with general parameters to achieve adaptive verification control.

[0015] The present invention also includes a network equipment security automated verification system for implementing the above-mentioned network equipment security automated verification method, the system comprising: The parameter classification and offset calculation module extracts parameter adjustment nodes of the same safety verification task type and parameter reset nodes of different task types, counts the number of changes of each type of node, and sums them to generate the safety verification offset parameter. It also monitors changes in equipment operating status and task switching signals in real time, records parameter adjustment time points, and quantifies the degree of parameter offset through frequency statistics. The similarity parameter extraction and control module analyzes the commonalities and differences between identity authentication, access control, and log auditing stages based on security verification offset parameters. It extracts common parameters that can be reused across tasks as a global benchmark and dynamically adjusts them based on the dedicated parameters for specific task types. It determines the reusability of parameters through time series data matching and optimizes parameter values ​​using deviation correction methods to achieve adaptive verification control. The safety trigger signal optimization module analyzes the safety signal trigger trend, advances or delays the trigger parameter adjustment instruction, calculates the correlation between the signal and the historical node based on the matching degree, and sets the threshold to determine the adjustment node type.

[0016] The beneficial effects of the network equipment security automated verification system provided by the present invention are: This automated network device security verification method effectively addresses the diverse security verification needs of network devices in complex operating environments. By clearly classifying security verification tasks into distinct categories, encompassing device security states and state transition points, the verification process can precisely address security requirements in different scenarios, avoiding the adaptation challenges of traditional methods during task switching.

[0017] During parameter extraction and processing, this method extracts security trigger signals and security verification parameter change nodes, enabling it to sensitively capture parameter adjustments caused by state changes in network devices during operation, as well as parameter resets when switching between different task types. This meticulous processing of parameter change nodes enables the verification system to respond to dynamic device changes in real time, reducing verification errors caused by parameter lag or mismatches.

[0018] By classifying safety verification parameter change nodes and extracting offset parameters, this method can clearly distinguish between device parameter offsets within the same task type and parameter offsets when switching between different task types, providing accurate basic data for subsequent similar parameter extraction. The similar parameters derived based on offset parameters include both common parameters reused across tasks and task-specific parameters. This classification method balances parameter reusability and targeting, ensuring comprehensive verification while reducing the complexity of parameter management.

[0019] This method realizes the automation of network equipment security verification, gets rid of excessive reliance on manual operations, can maintain efficient verification capabilities in a dynamically changing network environment, adapt to different equipment types and task requirements, reduces omissions and misjudgments in the verification process, and improves the adaptability and accuracy of network equipment security verification. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the embodiments or descriptions of the prior art. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0021] Figure 1 This is a working principle diagram of the network device security automated verification method according to the present invention; Figure 2 Flowchart for parameter extraction for safety verification; Figure 3 Flowchart for safety trigger signal generation; Figure 4 Flowchart for classification and calculation of offset parameters for safety verification. DETAILED DESCRIPTION

[0022] In the following description, specific details such as specific system structures and techniques are provided for purposes of illustration rather than limitation to facilitate a thorough understanding of the embodiments of the present application. However, it will be apparent to those skilled in the art that the present application may be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to avoid obscuring the description of the present application with unnecessary detail.

[0023] In order to make the purpose, technical solutions and advantages of this application clearer, specific embodiments will be described below with reference to the accompanying drawings.

[0024] See also Figures 1-4 The present invention provides a method for automatically verifying network device security, and the specific implementation steps are as follows: S1: Obtain the security verification task type of the network device, and based on the security verification task type, extract the security verification parameters of the network device; the security verification task type includes the device security status and the device security status switching node. First, clarify the type of security verification task that the current network device needs to perform, such as a routine security status verification for daily device operation, or a security status switching node verification generated by the device accessing a new network environment. Based on these task types, extract parameters related to security verification from the device's configuration information, operation logs and other data. These parameters cover the device's rules and settings in terms of identity authentication, access control, log auditing, etc.

[0025] S2: Based on the security verification parameters, extract the security trigger signal of the network device; based on the security trigger signal of the network device, extract the security verification parameter change node; the security verification parameter change node includes: a parameter adjustment node triggered by a change in the device operating status within the same security verification task type; a parameter reset node triggered when different security verification task types are switched. After obtaining the security verification parameters, through real-time monitoring and analysis of the parameters, capture the signal that can trigger a change in the security status, that is, the security trigger signal. Based on these signals, further determine the node where the parameter has changed. When the device's operating status changes under the same task type, such as when the load is too high, the parameter adjustment node will be triggered; and when the task type switches from a regular check to a special vulnerability scan, the parameter reset node will be triggered.

[0026] S3: Based on the security verification parameter change nodes, classify them into the same security verification parameter change nodes and different security verification parameter change nodes to obtain a security verification offset parameter; the security verification offset parameter includes the security parameter offset of the network device itself during the verification process of the same security verification task type, and the security parameter offset generated by the network device during the change of task type for different security verification task types. The extracted parameter change nodes are classified, and the parameter adjustment nodes belonging to the same task type are classified as the same change nodes, and the parameter reset nodes when different task types are switched are classified as different change nodes. By analyzing and calculating these two types of nodes, a security verification offset parameter is obtained, which reflects the degree of deviation of the device safety parameters under different circumstances. The parameter offset in the same task type may be caused by equipment aging, and the parameter offset may be caused by rule differences when different task types are switched.

[0027] S4: Based on the security verification offset parameters, obtain security verification similarity parameters; based on the security verification similarity parameters, control the network device to perform automated security verification; the security verification similarity parameters include general parameters and special parameters; the general parameters refer to basic security rule parameters that are reusable across task types; the special parameters refer to customized security rule parameters that are only applicable to specific security verification task types. Based on the security verification offset parameters, parameters with similar characteristics are screened out, where general parameters are applicable to multiple task types, such as basic authentication format requirements; special parameters are targeted at specific tasks, such as a certain type of encryption algorithm that is only used for specific security protocol verification. Utilizing these similar parameters, an automated verification mechanism is constructed to achieve efficient and accurate automated verification of the security status of network devices.

[0028] Example 1: Obtain the security verification task type of the network device, and extract the security verification parameters of the network device based on the security verification task type; the security verification task type includes the device security state and the switching node of the device security state. The specific process is as follows: Based on the device's security state, obtain the initial rule set for network devices in the three dimensions of identity authentication, access control, and log auditing, along with the corresponding time period. The device's security state refers to the basic security configuration of a network device in a specific operating scenario. Different device security states correspond to different security protection levels and operating specifications. Regarding identity authentication, the initial rule set may include user account creation standards, password complexity requirements (e.g., password length of at least 8 characters, including uppercase and lowercase letters and special symbols), and authentication failure handling mechanisms (e.g., locking an account for 30 minutes after five consecutive failures). These rules take effect during the initial device deployment or system initialization and correspond to the time period from device boot to the first security state transition. The initial access control rule set may address the scope of network port access (e.g., only allowing common ports like 80 and 443 to be open to the public), the allocation of permissions for different user groups (e.g., administrators can modify configurations, while regular users can only view status), and data transmission encryption protocol requirements (e.g., using TLS 1.2 and above). The corresponding time periods for these rules align with those for the initial authentication rule set, forming the basic access control framework for the device in its initial security state. The initial set of rules for log auditing includes the log content (such as user login time, operation type, device status changes, etc.), the log storage format (such as using a structured data format for easy retrieval), the log retention period (such as keeping audit logs for 90 days), etc., which also correspond to the specific time period of the initial operation stage of the device.

[0029] Based on the device's security status switching node, the network device's adjustment rule sets for identity authentication, access control, and log auditing, along with the corresponding time periods, are obtained. A device's security status switching node refers to the point in time when the device transitions from one security state to another due to changes in the external environment, adjustments to business needs, or security incidents. For example, if a device detects frequent malicious scanning from the external network, its security state will switch from Standard Protection to Enhanced Protection. At this point, the authentication adjustment rule set may require additional multi-factor authentication (e.g., adding SMS verification codes to password authentication), shorten password validity periods (e.g., from 90 days to 30 days), etc. The corresponding time period for the adjustment rule set is from the security status switching node until the next security status switching. The access control adjustment rule set may further restrict the port access range (e.g., temporarily closing non-essential backend management ports), tighten user permissions (e.g., temporarily revoking some viewing permissions for the general user group), or increase data transmission encryption strength (e.g., using the AES-256 encryption algorithm). The corresponding time period matches the time period for the authentication adjustment rule set under that switching node. The log audit adjustment rule set may increase the frequency of log recording (such as changing from hourly recording to real-time recording), expand the scope of log recording (such as adding detailed records of abnormal traffic), extend the log retention period (such as from 90 days to 180 days), etc., to meet the higher demand for security incident tracing under the enhanced protection state.

[0030] Based on the initial rule set and the time period corresponding to the initial rule set, a revised adjustment rule set is obtained using an adjustment rule verification method. This method evaluates the rationality and effectiveness of the adjustment rules by comparing the actual execution of the initial rules within their corresponding time period with the preset expected results. For example, in the initial rule set, the expected result for identity authentication is that 100% of user accounts meet password complexity requirements. However, during actual execution, an inspection of user accounts within the initial time period reveals that some accounts have passwords shorter than 8 characters. The degree of deviation between the actual execution result of the rule and the expected result can be calculated. For access control rules, if the expected result is a 100% interception rate for access requests from unauthorized IP addresses, but actual monitoring reveals that a small number of unauthorized IP addresses successfully access the system, the degree of deviation can also be quantified. Based on these deviations, the adjustment rule correction method is used to modify the adjustment rule set. For example, if enabling multi-factor authentication in identity authentication significantly reduces user login efficiency, the triggering conditions for the authentication method can be appropriately adjusted (for example, enabling multi-factor authentication only for remote logins). If excessive port closures in access control impact normal business operations, the necessity of these ports can be reassessed, and some temporarily closed ports can be selectively opened. This verification and correction process ensures that the adjusted rule set meets the new security requirements while maintaining the normal operating efficiency of the device.

[0031] Based on the initial rule set and the revised adjustment rule set, network device security verification parameters are obtained. These parameters are formed by integrating and refining the initial and revised adjustment rule sets, covering all security rules and configuration requirements that devices must follow in different security states and transitions. Regarding identity authentication, the security verification parameters include the initial password complexity rules and authentication failure handling mechanism, as well as the revised multi-factor authentication rules and password expiration rules. These parameters define the specific standards for device authentication of user identities during different time periods. The security verification parameters for access control integrate the initial port opening rules, permission allocation rules, encryption protocol requirements, as well as the revised port adjustment rules and temporary permission change rules, specifying the specific measures for controlling network access in different security states. The security verification parameters for log auditing combine the initial log content, storage format, and retention period with the revised log frequency and scope adjustment rules to define the specific specifications for device recording and tracing security events at different stages. These security verification parameters together constitute the basic basis for automated security verification of network equipment, and provide clear reference standards for subsequent steps such as security trigger signal extraction and parameter change node analysis.

[0032] Example 2: Based on the initial rule set and the time period corresponding to the initial rule set, a modified adjustment rule set is obtained using an adjustment rule verification method. The specific operations are as follows: Explicitly adjust the execution logic of the rule validation method. This method is used to measure the deviation between the rule execution results and the expected results at each stage, thereby determining the rule deviation for each stage. The initial rule set will operate according to the pre-set expectations within its corresponding time period. However, during actual execution, due to fluctuations in the network environment, changes in device operating status, or limitations within the rules themselves, the execution results may differ from the expected results. For example, in the authentication phase, the initial rule set may specify that "users will be locked out after more than five failed login attempts." During the corresponding time period, continuous tracking of login logs reveals that the actual lockout threshold for failed login attempts in some scenarios may not meet the preset threshold. For example, under conditions of high network latency, some users may repeatedly submit login requests, resulting in up to seven failed login attempts. This difference between the actual and expected thresholds represents the deviation for the authentication rules at that stage. Similarly, in the access control phase, if the initial rule set specifies "only designated IP segments are allowed to access the management port," dynamic IP address allocation may result in successful access from devices outside the designated IP segments. By measuring the frequency and proportion of these abnormal access attempts, the deviation for the access control rules at that stage can be determined. During the log audit phase, if the initial rule requires "generating an audit report every hour," the actual execution may result in report generation delays or missing content due to excessive system load. By recording the delay duration and the number of missing entries, the deviation of the log audit rule at this stage can be quantified.

[0033] Based on the deviation obtained above, the original rule value is linearly corrected using the rule adjustment method to obtain the rule correction amount. The key to linear correction is to proportionally adjust the original rule parameters based on the deviation, making the revised rule more consistent with actual operating conditions. For example, in the authentication phase, if network latency causes repeated deviations from the lockout threshold, and the average deviation is 2 (i.e., the actual lockout failure count exceeds the preset value by 2), the original rule's "lockout after 5 failures" can be corrected to "lockout after 3 failures" to offset the impact of network latency by lowering the threshold. In the access control phase, if abnormal access from non-specified IP segments accounts for 10%, indicating that the initial IP whitelist coverage is insufficient, the IP segment can be linearly expanded, for example, from the original IP segment 192.168.1.0 / 24 to 192.168.1.0 / 23, to cover more legitimate devices. For the report delay problem in log audit, if the average delay time is 15 minutes, the original "generate report every hour" can be adjusted to "generate report every 45 minutes" to compensate for the delay time by triggering the generation mechanism in advance.

[0034] During the implementation process, the adjusted rule set must be verified and corrected in stages. Each stage corresponds to a time period within the initial rule set. At the end of each time period, the rule execution status is immediately reviewed. For example, the first time period of the initial rule set is 24 hours after device startup. After this time period, all execution data for authentication, access control, and log auditing during this period is extracted, and the rule deviation for each link is calculated. For authentication, the difference between the actual lockout threshold for failed logins and the preset value is calculated; for access control, the frequency of abnormal IP access is calculated; and for log auditing, the duration of report delays is calculated. Based on these deviations, the corresponding rule parameters are adjusted one by one using a linear correction method to form the corrected rules for that stage. At the next time period, the corrected rules are used as the new execution standard, and deviations are monitored again. If deviations still exist, linear correction is continued. This cycle continues until the deviation between the actual rule execution results and the expected results is within an acceptable range.

[0035] The above process ultimately resulted in a revised set of adjusted rules. Each rule in this set underwent multi-stage verification and revision, preserving the core security logic of the original rule set while adapting to the actual needs of the device under different operating conditions. In terms of identity authentication, the revised rules can more accurately respond to login anomalies caused by network fluctuations; in terms of access control, the adjusted IP whitelist and permission settings can effectively reduce unauthorized access; and in terms of log auditing, the optimized report generation mechanism ensures the timeliness and integrity of audit data.

[0036] Example 3: Based on the security verification parameters, the security trigger signal of the network device is extracted. The specific process is as follows: According to the security verification parameters, the adjustment rule set is extracted to generate the first security trigger signal. The security verification parameters include various rules for the device in different security states, and the adjustment rule set is the part that changes due to the security state switch. When these adjustment rules are activated or changed, the system will capture the corresponding signals, which are the first security trigger signals. For example, in the access control adjustment rule set, if the rule changes from allowing access to a specific IP segment to only allowing access to a narrower range of IP segments, this rule change will be monitored by the system, and then a corresponding first security trigger signal will be generated. The signal contains information such as the specific content of the rule change and the time of occurrence.

[0037] The revised set of adjustment rules is extracted based on the security verification parameters to generate a second security trigger signal. The revised set of adjustment rules is a verified and revised set of adjustment rules that is more in line with the actual operation of the device than the original set of adjustment rules. When the revised adjustment rules are changed or executed, a signal, namely the second security trigger signal, will also be generated. For example, in the revised rules of log audit, if the log retention period is revised from 90 days to 180 days and then adjusted to 120 days due to storage capacity issues, this revised rule change will generate a second security trigger signal. This signal not only contains the details of the rule change, but also associates the previous revision records to trace the evolution of the rules.

[0038] Based on the first and second security trigger signals, we obtain security signal trigger trends for the three stages of identity authentication, access control, and log auditing for the same and different security verification task types. Within the same security verification task type, the device's security status may fluctuate within a certain range, but the overall task objective remains unchanged. By analyzing the first and second security trigger signals over a period of time, we can identify patterns in signal variation across the three stages. For example, in a routine security inspection task, identity authentication trigger signals may be more frequent during weekday rush hours, access control trigger signals may occur more frequently during peak business hours, and log audit trigger signals may maintain relatively stable intervals. Security signal trigger trends vary significantly between different security inspection task types due to differences in task objectives and rule systems. When switching from a routine inspection to a vulnerability scan task, identity authentication trigger signals may surge due to frequent permission verification, access control trigger signals may fluctuate erratically due to changes in scanned ports, and log audit trigger signals may become more frequent due to the generation of a large number of scan records.

[0039] Based on security signal trigger trends, security trigger signals from network devices can be obtained earlier or later. Security signal trigger trends reflect the direction and intensity of signal changes over time. By setting a preset security signal trigger trend threshold, the timing of signal acquisition can be adjusted. If the security signal trigger trend exceeds the preset threshold, it indicates a rapid increase in signal frequency and intensity, foreshadowing a potential significant change in the device's security status. For example, during the access control phase, if the trigger signal trend shows that the frequency of abnormal access attempts significantly exceeds the threshold within a short period of time, the system will obtain potential security trigger signals in advance, allowing for earlier protection. If the security signal trigger trend is lower than the preset threshold, it indicates that signal occurrence is flat or decreasing, and the device's security status is relatively stable. In this case, the acquisition of non-urgent security trigger signals can be appropriately delayed to avoid excessive system resource consumption due to frequent signal processing. For example, if the trigger signal trend during the log audit phase is flat and below the threshold, signals acquired in real time can be adjusted to batched, improving system efficiency while ensuring security monitoring.

[0040] Through the above process, the security trigger signals of network devices can be captured more accurately. Combined with the characteristics of different task types and three stages, the signal acquisition is timely and efficient, providing an accurate signal basis for the subsequent extraction of security verification parameter change nodes.

[0041] Example 4: Based on the security trigger signal of the network device, the security verification parameter change node is extracted. The specific process is as follows: calculate the matching degree of the security trigger signal and the benchmark time series data corresponding to the historical parameter adjustment node. The calculation of the matching degree needs to combine the two conditions of time window and rule type. The time window refers to a preset time interval, which is used to limit the time range for comparing the security trigger signal with the benchmark time series data; the rule type includes security rule categories of different dimensions such as identity authentication, access control, and log auditing. During the calculation, first filter out the data points in the security trigger signal that are in the same time window as the benchmark time series data, and then extract the data points with the same rule type from these data points. Count the number of data points that meet both conditions at the same time, and the ratio of the number of data points to the total number of data points of the security trigger signal is the matching degree. The calculation formula is: P=(S m / S t )×100% Among them, P represents the matching degree, S m Indicates the number of data points that meet both the time window and rule type conditions, S tRepresents the total number of data points for the security trigger signal. If the matching degree exceeds the preset matching degree threshold, the current security trigger signal and the historical parameter adjustment node have the same changing trend. The node is identified as a trend-consistent parameter adjustment node and serves as a parameter adjustment node for the same security verification task type. For example, in a vulnerability scanning task, the historical parameter adjustment node indicates that the scan frequency will be reduced when the device CPU utilization exceeds 80%. If the current security trigger signal also shows excessive CPU utilization and a scan frequency adjustment signal within the same time window, and the matching degree exceeds the threshold, the node is marked as a parameter adjustment node for the same task type. If the matching degree calculated for the baseline time series data corresponding to the security trigger signal and the historical parameter reset node is less than the preset matching degree threshold, the current signal and the historical parameter reset node have opposite trends. The node is identified as a trend-reversing parameter adjustment node and serves as a parameter reset node for a different security verification task type. For example, when switching from a vulnerability scanning task to a log auditing task, the historical parameter reset node indicates that the scan-related parameters will be cleared. If the parameter changes of the current security trigger signal within the corresponding time window do not match the historical records, the node is marked as a parameter reset node for a different task type.

[0042] Based on security verification parameter change nodes, we categorize them into identical and different security verification parameter change nodes to obtain security verification offset parameters. The specific operation is as follows: Parameter adjustment nodes triggered by changes in device operating status within the same security verification task type are extracted and marked as identical security verification parameter change nodes. Device operating status changes include fluctuations in metrics such as CPU utilization, memory usage, and network bandwidth usage. When these metrics exceed normal ranges, parameter adjustments are triggered. For example, in a continuous traffic monitoring task, when network bandwidth usage exceeds 90%, the device automatically adjusts the packet capture frequency. Nodes triggered by bandwidth changes are identical change nodes. Parameter reset nodes triggered by switching between different security verification task types are extracted and marked as different security verification parameter change nodes. Task type switching can be triggered manually by the administrator or automatically by the system based on security levels. This switching requires resetting some parameters to adapt to the new task requirements. For example, when switching from a general access control task to an emergency response task, the device resets the access permission list. These nodes are classified as different change nodes.

[0043] Based on the same security verification parameter change node, the parameter offset within the same task type is calculated, denoted as the first security verification offset parameter. The parameter offset is the difference between the actual parameter value and the initial parameter value. The calculation takes into account the magnitude and duration of the parameter change. For example, in an identity authentication task, the initial lockout period for incorrect passwords is 5 minutes. After multiple brute force cracking attempts, the lockout period is adjusted to 10 minutes. This 5-minute difference is the parameter offset for that node. The offsets of all parameter adjustment nodes within the same task type are summed to obtain the first security verification offset parameter. Based on different security verification parameter change nodes, the parameter offset when switching task types is calculated, denoted as the second security verification offset parameter. Parameter changes during task type switching are often more significant, potentially involving enabling or disabling parameters or significantly adjusting their values. For example, in an access control task, the allowed IP whitelist contains 10 addresses. After switching to an isolation protection task, only 2 addresses remain in the whitelist. This difference in numbers is the parameter offset for that node. The parameter offsets for all different task type switches are summed to obtain the second security verification offset parameter.

[0044] The weighted sum of the first safety verification offset parameter and the second safety verification offset parameter is used as the final safety verification offset parameter. The setting of the weight needs to be determined according to the degree of influence of the two offset parameters on the safety verification of the equipment. The degree of influence can be evaluated by the correlation between the parameter change and the effect of the execution of the safety rules. For example, if the parameter adjustment within the same task type has a greater impact on the verification accuracy, the first safety verification offset parameter can be given a higher weight; if the parameter reset when the task type is switched has a more significant impact on the integrity of the verification process, the second safety verification offset parameter is given a higher weight. Through weighted calculation, the two types of parameter offsets are integrated into a comprehensive safety verification offset parameter, which comprehensively reflects the deviation of the safety parameters of the equipment in different scenarios, and provides a quantitative basis for the subsequent extraction of similar safety verification parameters. During the calculation process, the offset of each parameter change node needs to be recorded and updated in real time to ensure that the weighted sum can accurately reflect the parameter offset status of the current equipment, so that the final safety verification offset parameter is timely and reliable.

[0045] Example 5: Based on security verification offset parameters, similar security verification parameters are obtained; based on these similar security verification parameters, network devices are controlled to perform automated security verification. The specific process is as follows: Using identity authentication, access control, and log auditing as the benchmark time series, common features in the security verification offset parameters are analyzed, and a set of parameters that are reusable across task types are extracted and marked as universal parameters. In the identity authentication phase, regardless of the security verification task type, user identity verification is required. The username format requirements (e.g., consisting of letters and numbers and a length of at least 6 characters) remain consistent across tasks. These parameters are universal parameters. In the access control phase, all task types involve protecting sensitive ports, such as prohibiting direct external network access to the device's management ports (e.g., ports 22 and 3389). This rule applies to tasks such as vulnerability scanning, log auditing, and traffic monitoring, and therefore forms part of the universal parameters. In the log audit phase, logs must contain basic information such as operation time, operator, and operation content. This requirement is independent of task type and is also included in the universal parameters.

[0046] Analyze the differential features in the security verification offset parameters, extract the parameter sets that are only applicable to specific task types, and mark them as dedicated parameters. In terms of identity authentication, for remote maintenance tasks, it may be necessary to enable a temporary access password, and the password is only valid for 24 hours. This temporary password mechanism is only applicable to remote maintenance scenarios and is a dedicated parameter. In access control, when performing internal employee authority verification tasks, it is necessary to verify the matching of the employee's department and the access resources (for example, employees in the technical department can access the R&D server, but employees in the administrative department cannot access it). In external visitor access control tasks, such verification is not required, so the department and resource matching rules are dedicated parameters for internal authority verification tasks. In the log audit link, in the tracing task of virus attack incidents, logs are required to record detailed information such as virus signatures and infection paths. The recording requirements of such specific content are only applicable to virus event tracing tasks and are dedicated parameters.

[0047] Use universal parameters as a global verification benchmark and apply them to the verification process for all task types. During the identity authentication process, regardless of the task being performed, the system will first verify the username entered by the user according to the username format requirements in the universal parameters. Login requests that do not conform to the format will be directly rejected. During access control, the global verification benchmark will forcibly prohibit external network access to the management port. This rule cannot be circumvented under any task type. During log auditing, logs generated by all tasks must include basic information such as operation time, operator, and operation content to ensure the basic integrity and consistency of the logs.

[0048] Verification parameters for specific task types are dynamically adjusted based on dedicated parameters, and combined with general parameters to achieve adaptive verification control. In remote maintenance tasks, based on the identity authentication rules in the general parameters, a temporary password valid for 24 hours is generated according to the temporary password mechanism in the dedicated parameters. Maintenance personnel are required to provide both their permanent account and password for dual verification. In internal employee access verification tasks, in addition to general access control rules (such as prohibiting external access to management ports), employee access requests are secondary verified based on dedicated department-resource matching rules. Only requests with a matching department and resource are permitted. In virus attack incident tracing tasks, in addition to general logging requirements, dedicated parameters are used to prioritize log entries containing information such as virus signatures and infection paths, while ignoring redundant logs unrelated to the virus incident, improving tracing efficiency. By combining general and dedicated parameters, the system can flexibly adapt to the specific needs of different task types while maintaining consistent basic security standards, making the automated security verification process more tailored to actual application scenarios.

[0049] It should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that includes a list of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus.

[0050] While embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions, and variations may be made to these embodiments without departing from the principles and spirit of the invention, and that the scope of the invention is defined by the appended claims and their equivalents.

[0051] The above are only specific embodiments of the present application, but the scope of protection of the present application is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in this application, and such modifications or substitutions should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.

Claims

1. A method for automated network device security verification, characterized in that: The following steps are involved: S1: Obtain a security verification task type of a network device, and extract security verification parameters of the network device based on the security verification task type; the security verification task type includes a device security state and a switching node of the device security state; S2: extracting a security trigger signal of the network device based on the security verification parameter; Extracting a security verification parameter change node based on a security trigger signal of the network device; The safety verification parameter change nodes include: parameter adjustment nodes triggered by changes in equipment operating status within the same safety verification task type; parameter reset nodes triggered when switching between different safety verification task types; S3: Based on the security verification parameter change nodes, classify the nodes according to the same security verification parameter change nodes and the nodes with different security verification parameter change nodes to obtain a security verification offset parameter; the security verification offset parameter includes the security parameter offset of the network device itself during the verification process of the same security verification task type and the security parameter offset generated by the network device during the process of changing the task type of different security verification tasks; S4: Based on the security verification offset parameters, obtain security verification similarity parameters; based on the security verification similarity parameters, control the network equipment to perform security automation verification; the security verification similarity parameters include general parameters and special parameters; the general parameters refer to basic security rule parameters that are reusable across task types; the special parameters refer to customized security rule parameters that are only applicable to specific security verification task types.

2. A network equipment security automated verification method according to claim 1, characterized in that: The obtaining of the security verification task type of the network device and extracting the security verification parameters of the network device based on the security verification task type; The security verification task type includes the device security status and the switching node of the device security status, including: Based on the device security status, obtain an initial rule set for network device identity authentication, access control, and log auditing, and a time period corresponding to the initial rule set; Based on the switching node of the device security status, obtaining a set of adjustment rules for network device identity authentication, access control, and log audit and a time period corresponding to the set of adjustment rules; Based on the initial rule set and the time period corresponding to the initial rule set, a revised adjustment rule set is obtained using an adjustment rule verification method; Based on the initial rule set and the revised adjustment rule set, security verification parameters of the network device are obtained.

3. A network equipment security automated verification method according to claim 2, characterized in that: The modified adjustment rule set is obtained by using the adjustment rule verification method based on the initial rule set and the time period corresponding to the initial rule set, including: obtaining the rule deviation amount of each stage through the adjustment rule verification method, and obtaining the adjustment rule correction amount through the adjustment rule correction method; the adjustment rule verification method is to count the degree of deviation between the rule execution results of each stage and the expected results; the adjustment rule correction method is to linearly correct the original rule value according to the degree of deviation.

4. A method for automated network device security verification according to claim 1, characterized in that: The extracting the security trigger signal of the network device based on the security verification parameter includes: Extracting an adjustment rule set based on the safety verification parameters to generate a first safety trigger signal; extracting a revised set of adjustment rules based on the safety verification parameters and generating a second safety trigger signal; Based on the first security trigger signal and the second security trigger signal, obtaining security signal trigger trends in the three stages of identity authentication, access control, and log audit for the same security verification task type and different security verification task types; Based on the safety signal triggering trend, the safety triggering signal of the network device is obtained in advance or in a delayed manner.

5. A method for automated network device security verification according to claim 1, characterized in that: The extracting of the security verification parameter change node based on the security trigger signal of the network device includes: By calculating the matching degree between the safety trigger signal and the benchmark time series data corresponding to the historical parameter adjustment node, if the matching degree is greater than the preset matching degree threshold, it is determined to be a trend consistency parameter adjustment node and used as a parameter adjustment node of the same safety verification task type; By calculating the matching degree between the safety trigger signal and the benchmark time series data corresponding to the historical parameter reset node, if the matching degree is less than the preset matching degree threshold, it is determined to be a trend reversal parameter adjustment node, which serves as the parameter reset node for different safety verification task types.

6. A method for automated network device security verification according to claim 5, characterized in that: The calculation of the matching degree between the safety trigger signal and the benchmark time series data corresponding to the historical parameter adjustment node includes: the matching degree calculation method is the overlapping ratio of the time series data of the safety trigger signal and the benchmark time series data, wherein the overlapping ratio is the proportion of data points that simultaneously meet the time window and rule type conditions.

7. A method for automated network device security verification according to claim 4, characterized in that: The obtaining of the security trigger signal of the network device in advance or in delay based on the security signal trigger trend includes: If the safety signal trigger trend is greater than a preset safety signal trigger trend threshold, a safety trigger signal of the network device is obtained in advance; If the safety signal trigger trend is less than a preset safety signal trigger trend threshold, obtaining the safety trigger signal of the network device is delayed.

8. A method for automated network device security verification according to claim 1, characterized in that: The step of classifying the safety verification parameter change nodes according to the same safety verification parameter change nodes and different safety verification parameter change nodes based on the safety verification parameter change nodes to obtain the safety verification offset parameter includes: Extract parameter adjustment nodes triggered by changes in equipment operating status within the same safety verification task type and mark them as the same safety verification parameter change nodes; Extract the parameter reset nodes triggered when switching between different safety verification task types and mark them as different safety verification parameter change nodes; Based on the same safety check parameter change node, calculate the parameter offset within the same task type and record it as the first safety check offset parameter; Based on different safety check parameter change nodes, the parameter offset when the task type is switched is calculated and recorded as the second safety check offset parameter; A weighted sum of the first safety check offset parameter and the second safety check offset parameter is taken as a final safety check offset parameter.

9. A method for automated network device security verification according to claim 1, characterized in that: obtaining a safety verification similarity parameter based on the safety verification offset parameter; Based on the security verification similarity parameters, control the network device to perform automated security verification, including: Using identity authentication, access control, and log auditing as benchmark time series, we analyze the common features of security verification offset parameters, extract reusable parameter sets across task types, and mark them as common parameters. Analyze the differential features of the safety verification offset parameters, extract the parameter set that is only applicable to a specific task type, and mark it as a dedicated parameter; Use common parameters as a global verification benchmark and apply them to the verification process for all mission types; Dynamically adjust the verification parameters of specific task types based on dedicated parameters, and combine with general parameters to achieve adaptive verification control.

10. A network equipment security automated verification system, used to implement a network equipment security automated verification method according to any one of claims 1 to 9, characterized in that: include: The parameter classification and offset calculation module extracts parameter adjustment nodes of the same safety verification task type and parameter reset nodes of different task types, counts the number of changes of the two types of nodes respectively, and sums them to generate the safety verification offset parameter; Monitor changes in equipment operating status and task switching signals in real time, record parameter adjustment time points, and quantify the degree of parameter deviation through frequency statistics; The similarity parameter extraction and control module analyzes the commonalities and differences between identity authentication, access control, and log auditing stages based on security verification offset parameters. It extracts common parameters that can be reused across tasks as a global benchmark and dynamically adjusts them based on the dedicated parameters for specific task types. It determines the reusability of parameters through time series data matching and optimizes parameter values ​​using deviation correction methods to achieve adaptive verification control. The safety trigger signal optimization module analyzes the safety signal trigger trend, advances or delays the trigger parameter adjustment instruction, calculates the correlation between the signal and the historical node based on the matching degree, and sets the threshold to determine the adjustment node type.