Method for realizing cross-system security test based on abnormal monitoring information collection
Through real-time data collection and dynamic updating of policy libraries, the shortcomings of traditional single-system security testing are solved, the flexibility and real-time performance of cross-system security testing are achieved, and the response speed and defense capabilities to new threats are improved.
Patent Information
- Application Number
- CN202510851494.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-24
- Publication Date
- 2025-09-19
AI Technical Summary
Traditional single-system security testing methods rely on static security case libraries, which are unable to promptly identify and respond to emerging cross-system security threats, and are difficult to adapt to the unique needs of different systems, resulting in insufficient testing flexibility and real-time performance.
By collecting data in real time, performing data preprocessing, updating the policy library, and retesting the entire system, security policies are dynamically generated or updated to cover the latest attack methods and system vulnerabilities, forming a closed-loop management.
It enables real-time updates of the security testing platform, improves the response speed and defense capabilities to new security threats, ensures that the policy library contains the latest protection measures, and improves the accuracy and effectiveness of cross-system security testing.
Smart Images

Figure CN120675776A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of system security testing, and in particular to a method for implementing cross-system security testing based on abnormal monitoring information collection. Background Art
[0002] In modern software development, information security has become a crucial issue for businesses and organizations. With the rapid advancement of technology, the interconnectivity between various systems and networks has become increasingly close. While this has brought significant convenience, it has also increased security risks. Malicious attackers often exploit vulnerabilities between systems to launch cross-system security threats, posing a severe challenge to information system security. Therefore, the development of an effective cross-system security testing method is particularly urgent.
[0003] Traditional security testing methods are often limited to a single system, making it difficult to comprehensively assess cross-system security risks. However, cross-system security testing methods based on anomaly monitoring information collection can promptly identify potential security threats by monitoring system operating status in real time, collecting and analyzing anomaly information. This approach not only improves the efficiency and accuracy of security testing but also helps organizations better prevent and respond to cross-system security attacks.
[0004] Technical solutions in the prior art:
[0005] Single system security testing strategy
[0006] During a single system's security penetration test, security penetration testing tools or platforms are typically used. These tools and platforms come pre-configured with a series of basic penetration scenario strategies based on historically common security vulnerabilities and attack patterns. By simulating potential hacker attack methods, they conduct multi-angle and multi-layered testing of the target system to uncover potential security vulnerabilities.
[0007] Use the policy templates in the tool or platform to select an appropriate testing strategy. For example, a penetration test for a web application might include common attack methods such as SQL injection, cross-site scripting (XSS), and file upload vulnerabilities.
[0008] Once the test begins, the tool automatically runs pre-defined penetration scenarios, attempting to attack various system interfaces. These attacks may involve different layers, from the network layer to the application layer, and even the operating system layer. This allows for a comprehensive assessment of the system's security capabilities.
[0009] During the testing process, the tool records all actions and results, generating a detailed log. If any vulnerabilities or unusual behavior are discovered, the tool will take screenshots, document the steps taken, and generate a report. Some advanced tools can also automatically analyze scan results, providing risk ratings and remediation recommendations. Upon completion, security penetration testing tools generate a comprehensive security report.
[0010] Single-system security testing faces numerous challenges in today's complex and ever-changing network environment. One significant drawback is its over-reliance on security cases from security testing platforms. This reliance limits the flexibility and real-time nature of testing, making it difficult for security testing to keep pace with the rapidly evolving threat landscape.
[0011] Because single-system security testing is primarily based on an existing security case library, it may not be able to promptly identify and respond to emerging security threats. If the full testing platform cannot update the case library in real time, the test results may miss critical security vulnerabilities.
[0012] The diversity between different systems requires security testing to be flexible and adaptable to various environments and configurations. However, a single security testing platform often fails to cover the unique requirements of all systems, which may result in security testing failing to accurately assess system security in certain scenarios. Summary of the Invention
[0013] In view of the above problems, the present invention is proposed to provide a method for implementing cross-system security testing based on abnormal monitoring information collection to overcome the above problems or at least partially solve the above problems.
[0014] According to one aspect of the present invention, a method for implementing cross-system security testing based on abnormal monitoring information collection is provided, the testing method comprising:
[0015] Collect data in real time and summarize local issues;
[0016] performing data preprocessing on the collected data to obtain preprocessed data;
[0017] The strategy library is updated based on the pre-processed data, and the entire system is retested.
[0018] Optionally, the real-time data collection and aggregation of local issues specifically include:
[0019] Through the Internet and the log files of the monitored system, the latest security issues, vulnerability information and attack methods, as well as various security incidents and abnormal behaviors occurring in the system are collected.
[0020] Optionally, the data sources of the collected data include security communities, vulnerability databases, security blogs and forums.
[0021] Optionally, various security events and abnormal behaviors occurring in the system specifically include:
[0022] By connecting with the log files and event records of the monitored system, various security events and abnormal behaviors occurring in the system are collected.
[0023] Optionally, performing data preprocessing on the collected data to obtain preprocessed data specifically includes:
[0024] De-duplicate, clean, and classify the collected data;
[0025] Extract key security threats and risk points;
[0026] Based on the processed data, security policies are dynamically generated or updated to cover the latest known attack methods, system vulnerabilities and abnormal behavior patterns, and prioritized according to actual conditions.
[0027] Optionally, the deduplication, cleaning and classification processing of the collected data specifically includes:
[0028] Remove duplicate data items;
[0029] Eliminate incomplete, erroneous or abnormal data through data cleaning;
[0030] By classifying the data, different types of security threats, vulnerability information and attack methods are classified.
[0031] Optionally, updating the policy library according to the pre-processed data and retesting the entire system specifically includes:
[0032] Update the newly generated policies to the original policy library in a timely manner, and conduct security tests on all monitored systems regularly through the scheduling system;
[0033] Feedback security test results to the policy generation module to form a closed-loop management;
[0034] Continuously optimize and adjust strategies based on actual test results.
[0035] Optionally, the security testing includes vulnerability scanning, penetration testing, and security assessment.
[0036] This invention provides a cross-system security testing method based on anomaly monitoring information collection. The method includes: real-time data collection and aggregation of local issues; preprocessing the collected data to obtain preprocessed data; updating the policy library based on the preprocessed data, and retesting the entire system. This method addresses the inability of traditional security testing platforms to dynamically update the policy library when relying on a free security static library. It also ensures that the policy library always contains protection measures against the latest security threats, improving response speed and defense capabilities.
[0037] The above description is only an overview of the technical solution of the present invention. In order to more clearly understand the technical means of the present invention, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present invention more obvious and easy to understand, the specific implementation methods of the present invention are specifically listed below. BRIEF DESCRIPTION OF THE DRAWINGS
[0038] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0039] Figure 1 A flowchart of a method for implementing cross-system security testing based on abnormal monitoring information collection provided by an embodiment of the present invention;
[0040] Figure 2 A flowchart for collecting data in real time and summarizing local issues provided by an embodiment of the present invention;
[0041] Figure 3 A flowchart of performing data preprocessing on collected data to obtain preprocessed data provided by an embodiment of the present invention;
[0042] Figure 4 This is a flowchart of the update strategy library retesting the entire system provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0043] Exemplary embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although exemplary embodiments of the present disclosure are shown in the accompanying drawings, it should be understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments set forth herein. Rather, these embodiments are provided to enable a more thorough understanding of the present disclosure and to fully convey the scope of the present disclosure to those skilled in the art.
[0044] The terms "comprises" and "comprising" and any variations thereof in the description, embodiments, claims and drawings of the present invention are intended to cover non-exclusive inclusions, for example, including a series of steps or units.
[0045] The technical solution of the present invention is further described in detail below with reference to the accompanying drawings and embodiments.
[0046] like Figure 1 As shown, a cross-system security testing method based on abnormal monitoring information collection includes: real-time data collection and summarizing local problems; preprocessing the collected data to obtain preprocessed data; updating the policy library according to the preprocessed data, and retesting the entire system.
[0047] Real-time data collection and local problem aggregation. Collect the latest security issues, vulnerability information, and attack methods, as well as various security incidents and abnormal behaviors occurring in the system, from the internet and the monitored system's log files. This data comes from security communities, vulnerability databases (such as CVE), security blogs, and forums.
[0048] Collected data is deduplicated, cleaned, and classified to ensure high quality and relevance. Key security threats and risk points are extracted. Based on the processed data, security policies are dynamically generated or updated, covering the latest known attack methods, system vulnerabilities, and abnormal behavior patterns, and prioritized based on actual conditions.
[0049] Newly generated policies are promptly updated to the original policy library, and a scheduling system is used to periodically conduct security testing on all monitored systems. Testing includes, but is not limited to, vulnerability scanning, penetration testing, and security assessments to promptly identify potential security risks. Security testing results are fed back to the policy generation module, forming a closed-loop management system. Based on actual test results, policies are continuously optimized and adjusted to improve their accuracy and effectiveness.
[0050] like Figure 2 As shown, real-time data collection and local problem summary:
[0051] Using web crawlers and APIs, we collect the latest security issues, vulnerability information, and attack methods from the internet in real time. This data comes from sources including, but not limited to, security communities, vulnerability databases (such as CVE), security blogs, and forums. Furthermore, by connecting to the log files and event records of the monitored systems, we collect various security events and abnormal behaviors occurring in the systems. This local data provides a crucial reference for policy updates. Through in-depth analysis of this data, we can promptly identify potential security risks and provide strong support for the formulation of effective security policies.
[0052] In addition to acquiring data from the internet, we also collect various security incidents and abnormal behaviors that occur in the monitored system by connecting to the log files and event records of the monitored system. This local data is also of great reference value because it directly reflects the security issues faced by the system during actual operation.
[0053] like Figure 3 As shown, data processing:
[0054] Deduplication, cleaning, and classification of collected data are key steps to ensure high data quality and relevance. This process begins by removing duplicate data items to prevent redundant information from impacting subsequent analysis. Next, data cleaning can eliminate incomplete, erroneous, or abnormal data, ensuring data reliability and accuracy. Finally, data classification allows for the categorization of different security threats, vulnerability information, and attack methods, facilitating subsequent analysis and strategy development.
[0055] After data preprocessing, key security threats and risk points are extracted. This critical information serves as an essential foundation for security policy formulation. Based on the processed data, security policies are dynamically generated or updated. These policies cover the latest known attack vectors, system vulnerabilities, and abnormal behavior patterns. To ensure the effectiveness and relevance of policies, they are prioritized based on actual circumstances. This means prioritizing policies based on factors such as the severity of the security threat, the scope of impact, and system vulnerabilities. This ensures the most efficient use of limited resources, thereby improving the security performance of the entire system.
[0056] like Figure 4 As shown, update the strategy library and retest the entire system:
[0057] Newly generated policies are promptly updated to the original policy library to ensure the system always has the latest security protection capabilities to cope with ever-changing security threats. To verify the effectiveness and reliability of the policies, the scheduling system is also required to regularly conduct security tests on all monitored systems.
[0058] The security testing process encompasses multiple aspects, including vulnerability scanning, penetration testing, and security assessments. Vulnerability scanning helps identify security vulnerabilities in the system, allowing timely remediation. Penetration testing simulates attacker behavior to verify the system's defense capabilities. Security assessments comprehensively evaluate the system's security performance and provide a comprehensive security report.
[0059] Through security testing, potential security risks are promptly discovered and the test results are fed back to the strategy generation module. Based on the actual test results, the strategy is continuously optimized and adjusted to improve its accuracy and effectiveness.
[0060] Beneficial effects:
[0061] 1. Dynamically Updated Policy Library: This invention introduces a policy update mechanism based on dynamic data streams, enabling the security testing platform to collect the latest security issues, vulnerability information, and attack vectors in real time. This mechanism not only addresses the inability of traditional security testing platforms to dynamically update the policy library when relying on a free security static library, but also ensures that the policy library always contains protection measures against the latest security threats.
[0062] 2. Improved Response Speed and Defense Capabilities: This method improves the platform's response speed and defense capabilities against new security threats. Through key steps such as real-time data collection, local problem aggregation, and data analysis and processing, the system can quickly identify and respond to potential security risks.
[0063] The above specific implementation methods further illustrate the objectives, technical solutions and beneficial effects of the present invention in detail. It should be understood that the above are only specific implementation methods of the present invention and are not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.
Claims
1. A cross-system security testing method based on abnormal monitoring information collection, characterized in that: The test method includes: Collect data in real time and summarize local issues; performing data preprocessing on the collected data to obtain preprocessed data; The strategy library is updated based on the pre-processed data, and the entire system is retested.
2. A cross-system security testing method based on abnormal monitoring information collection according to claim 1, characterized in that: The real-time data collection and summary of local issues specifically include: Through the Internet and the log files of the monitored system, the latest security issues, vulnerability information and attack methods, as well as various security incidents and abnormal behaviors occurring in the system are collected.
3. The method for implementing cross-system security testing based on abnormal monitoring information collection according to claim 1, characterized in that: The data sources of the collected data include security communities, vulnerability databases, security blogs and forums.
4. The method for implementing cross-system security testing based on abnormal monitoring information collection according to claim 2, characterized in that: The various security incidents and abnormal behaviors that occurred in the system specifically include: By connecting with the log files and event records of the monitored system, various security events and abnormal behaviors occurring in the system are collected.
5. The method for implementing cross-system security testing based on abnormal monitoring information collection according to claim 1, characterized in that: The performing data preprocessing on the collected data to obtain preprocessed data specifically includes: De-duplicate, clean, and classify the collected data; Extract key security threats and risk points; Based on the processed data, security policies are dynamically generated or updated to cover the latest known attack methods, system vulnerabilities and abnormal behavior patterns, and prioritized according to actual conditions.
6. A cross-system security testing method based on abnormal monitoring information collection according to claim 5, characterized in that: The deduplication, cleaning and classification processing of the collected data specifically includes: Remove duplicate data items; Eliminate incomplete, erroneous or abnormal data through data cleaning; By classifying the data, different types of security threats, vulnerability information and attack methods are classified.
7. The method for implementing cross-system security testing based on abnormal monitoring information collection according to claim 1, characterized in that: The updating of the strategy library according to the pre-processed data and retesting the entire system specifically includes: Update the newly generated policies to the original policy library in a timely manner, and conduct security tests on all monitored systems regularly through the scheduling system; Feedback security test results to the policy generation module to form a closed-loop management; Continuously optimize and adjust strategies based on actual test results.
8. A cross-system security testing method based on abnormal monitoring information collection according to claim 7, characterized in that: The security testing content includes vulnerability scanning, penetration testing and security assessment.