A network security device vulnerability scanning method, device and electronic equipment

By combining multi-dimensional data collection and adaptive algorithms, the problem of inaccurate vulnerability scanning in existing technologies has been solved, enabling more accurate device screening and vulnerability localization, and improving the comprehensiveness and intelligence of vulnerability scanning for network security devices.

CN120675783BActive Publication Date: 2026-01-23GUANGDONG BITEBAO TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510931531.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-07-07
Publication Date
2026-01-23
Estimated Expiration
2045-07-07

AI Technical Summary

Technical Problem

Existing network security device vulnerability scanning technologies lack comprehensive consideration of the device environment and dynamic status, resulting in incomplete detection, inaccurate results, and weak targeting, making it difficult to effectively respond to complex network security threats.

Method used

By collecting and integrating multi-dimensional data on device movement status, signal strength, and environmental interference, and combining the importance of network topology location with adaptive algorithms, port status detection and vulnerability intelligence processing are performed to generate accurate key vulnerability detection information.

Benefits of technology

It enables more precise device screening and vulnerability location, improves the accuracy of port anomaly detection and adaptability to dynamic network environments, enhances the comprehensiveness and intelligence of vulnerability scanning, and provides precise guidance for network security management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120675783B_ABST
    Figure CN120675783B_ABST
Patent Text Reader

Abstract

The application discloses a network security device vulnerability scanning method and device and electronic equipment, and concretely relates to the technical field of Internet of Things security, which forms a basic data set by collecting device moving state and other data, obtains a target device preliminary screening and a final list through threshold comparison and the like, obtains a port exception determination result through port detection and the like, and finally generates a vulnerability detection key information set in combination with various information sets. The network security device vulnerability scanning method and device and electronic equipment provided by the application integrate device moving state, signal strength and environmental interference data into a structured data set through multi-dimensional data collection and integration, provide a standardized data basis for subsequent analysis, solve the problem of single data collection in the prior art, and lay a comprehensive data support for vulnerability scanning.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of Internet of Things (IoT) security technology, and in particular to a method, apparatus, and electronic device for scanning vulnerabilities in network security equipment. Background Technology

[0002] The field of IoT security technology encompasses multiple aspects, including device security, network security, data security, and authentication and access control. Its core objective is to protect IoT devices, networks, and data from unauthorized access, malicious attacks, and data breaches. Device security ensures the security of IoT device hardware and software, such as device authentication and firmware updates; network security protects communication networks, involving network isolation and firewalls; data security protects the security of data generation, transmission, and storage, including data encryption and backup; authentication and access control ensure that only authorized users or devices can access the system, with user and device authentication and access control policies.

[0003] Among them, network security device vulnerability scanning methods are based on vulnerability databases and involve scanning and detecting security vulnerabilities in specified remote or local computer systems to discover exploitable vulnerabilities. These methods target network devices and applications such as website systems, databases, ports, and application software. Specifically, host scanning determines whether the target network host is online; port scanning discovers open ports and services on remote hosts; OS identification technology identifies the operating system; vulnerability detection data collection technology scans the network system database; and vulnerability scanning is completed by combining intelligent port identification, multi-service detection, and automated database checks with instance discovery techniques.

[0004] Current technologies for vulnerability scanning of network security devices rely on vulnerability databases for single-dimensional detection, such as judging device status through host and port scanning, lacking a comprehensive consideration of the device environment and dynamic status. For example, device screening does not take into account mobility and environmental interference, easily leading to inaccurate signal strength judgments and false positives; the identification of key devices is based solely on data indicators such as connection frequency, without considering the importance of network topology location, making it difficult to accurately locate critical devices; port detection uses fixed thresholds to judge response latency, which cannot adapt to dynamic network changes, easily missing or misjudging abnormal ports; device system type identification mainly relies on configuration parameter comparison, without combining log time-series analysis, resulting in insufficient accuracy; vulnerability intelligence processing lacks multi-source intelligence weight adjustment and weighted aggregation, making it difficult to generate targeted detection information. These shortcomings lead to incomplete, inaccurate, and weakly targeted detection, making it difficult to efficiently respond to complex network security threats, potentially causing potential vulnerabilities to go undetected and addressed in a timely manner, increasing security risks. Summary of the Invention

[0005] The main objective of this invention is to provide a method, apparatus, and electronic device for scanning network security devices, which can effectively solve the problems involved in the background art.

[0006] To achieve the above objectives, the technical solution adopted by the present invention is as follows:

[0007] A method for scanning vulnerabilities in network security devices includes the following steps:

[0008] S1. Data acquisition: Collect data on device movement status, signal strength, and environmental interference to form a basic dataset for the device.

[0009] S2. Equipment screening: Set a signal strength threshold based on the movement status data of the equipment basic dataset, compare the signal strength data with the threshold, correct the environmental interference data, and compare again. Obtain the initial screening list of target equipment through the threshold comparison method.

[0010] S3. Device Confirmation: For the initial screening list of target devices, obtain the connection frequency and data exchange volume, compare them with the baseline values, and combine them with the importance of the network topology location to obtain the final list of target devices.

[0011] S4. Port Status Detection: Send port probe requests to the target devices in the final list of devices, record the response latency and calculate the latency gradient, use an adaptive algorithm to calculate the adaptive threshold, compare the response latency with the new threshold, and obtain the basic port status data.

[0012] S5. Port status determination: Based on the basic port status data, collect port traffic data and segment it, count the maximum and minimum values ​​and the number of changes, set standard values ​​and compare them, and combine the response latency to determine port anomalies and obtain the port anomaly determination result.

[0013] S6. Detection results are generated by collecting device configuration parameters, calculating correlation and matching templates, analyzing the time sequence of operation logs to obtain device system type determination results, collecting vulnerability intelligence data, setting and adjusting weights and weighted aggregation, and combining device connection relationships and business importance to generate a set of key vulnerability detection information.

[0014] Preferably, the data acquisition described in S1 specifically includes:

[0015] S1.1 Collect equipment movement status data, signal strength data, and environmental interference data from environmental monitoring nodes to obtain basic equipment data collection values;

[0016] S1.2 Integrate the collected equipment movement status data, signal strength data, and environmental interference data to establish a basic equipment dataset.

[0017] Preferably, the device screening in S2 specifically includes:

[0018] S2.1. Set a signal strength threshold based on the motion status data in the device's basic dataset, compare the signal strength data with the set threshold, and obtain the initial comparison signal strength value.

[0019] S2.2. Call the environmental interference data in the device's basic dataset to correct the initial comparison signal strength value, and then compare the corrected signal strength value with the signal strength threshold. Obtain the initial screening list of target devices through the threshold comparison method.

[0020] Preferably, the device verification in S3 specifically includes:

[0021] S3.1 For the devices in the initial screening list of target devices, obtain their connection frequency data with the network core devices to obtain the device connection frequency data value;

[0022] S3.2 Calculate the amount of data interaction of the devices in the initial screening list of target devices within a unit of time to obtain the data interaction value of the devices;

[0023] S3.3 Compare the device connection frequency data value with the set connection frequency benchmark value, compare the device data interaction quantity value with the set data interaction quantity benchmark value, and combine the network topology location importance judgment to obtain the final list of target devices.

[0024] Preferably, the port status monitoring in S4 specifically includes:

[0025] S4.1 Send port probe requests to the target devices in the final list, record the port response delay, and obtain the port response delay record value;

[0026] S4.2 Calculate the difference between adjacent response delays based on the port response delay record values ​​to obtain the delay gradient calculation value;

[0027] S4.3 Calculate the adaptive threshold based on the delay gradient using an adaptive algorithm, compare the port response delay record value with the new threshold, and obtain the port basic status data.

[0028] Preferably, the port status determination in S5 specifically includes:

[0029] S5.1 Based on the port basic status data, collect the traffic data of each port of the target device and segment it by time to obtain segmented port traffic data;

[0030] S5.2 Calculate the maximum, minimum and number of changes of traffic in each time period in the segmented port traffic data to obtain the statistical values ​​of the maximum and minimum traffic values ​​and the number of changes.

[0031] S5.3 Set the normal range standard values ​​for the traffic change rate and the number of changes, calculate the traffic change rate and compare it with the standard value, count the number of changes and compare it with the standard value, and combine the port response delay record value to determine whether the port is abnormal, and obtain the port abnormality judgment result.

[0032] Preferably, the generation of the detection result in S6 specifically includes:

[0033] S6.1 Collect the device configuration parameters in the final list of target devices, statistically analyze the parameter combinations of a large number of known system type devices, calculate the correlation between each parameter, and obtain the calculated value of device parameter correlation.

[0034] S6.2 Match the calculated value of the device parameter correlation degree with the parameter correlation degree template of the known system type, obtain the target device operation log, extract key event information to construct a time series, and obtain the device log time series value;

[0035] S6.3 Analyze the frequency and characteristics of events in the time sequence values ​​of the device logs, compare them with the typical log time sequence patterns of known system types, and obtain the device system type determination results;

[0036] S6.4 Collect vulnerability intelligence from multiple sources, obtain data on intelligence release time, credibility of the releasing organization, and number of intelligence verifications, set time weight, credibility weight, and number of verifications weight, calculate the initial weight of each intelligence source, and obtain the initial weight calculation value of the intelligence source.

[0037] S6.5 Adjust the initial weight calculation value of the intelligence source according to the device system type determination result and the port anomaly determination result, and aggregate the intelligence from different sources according to the adjusted weight to obtain vulnerability intelligence assessment data.

[0038] S6.6 Analyze the system function scope and data volume involved for each vulnerability in the vulnerability intelligence assessment data, and generate a set of key vulnerability detection information by combining the device's connection relationship in the IoT network and the importance of the business it carries.

[0039] A network security device vulnerability scanning apparatus, the apparatus being used to perform the aforementioned network security device vulnerability scanning method, the apparatus comprising the following modules:

[0040] The data acquisition module is used to execute step S1;

[0041] The equipment's initial screening module is used to perform step S2;

[0042] The device verification module is used to perform step S3.

[0043] The port detection module is used to perform step S4;

[0044] The port determination module is used to execute the S5 step;

[0045] The Type Analysis and Intelligence Processing module is used to execute the S6 steps.

[0046] An electronic device includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor runs the program, it performs the operation steps corresponding to each module in the aforementioned network security device vulnerability scanning device.

[0047] Compared with the prior art, the present invention has the following beneficial effects:

[0048] 1. This invention integrates device movement status, signal strength, and environmental interference data into a structured dataset through multi-dimensional data collection and integration, providing a standardized data foundation for subsequent analysis. This solves the problem of single data collection in existing technologies and lays a comprehensive data foundation for vulnerability scanning.

[0049] 2. This invention sets differentiated signal strength thresholds based on the device's movement status, corrects the signal strength value by combining environmental interference data, and simultaneously obtains the device connection frequency and data interaction volume and compares them with the benchmark value. It also combines the importance of the network topology location to make a judgment, which not only improves the accuracy of the initial screening of target devices, but also accurately locates key detection devices. This changes the limitations of existing technology in device screening and key determination, and achieves more accurate detection target positioning.

[0050] 3. This invention sends port probe requests, records response delays, calculates delay gradients, and uses an adaptive algorithm to calculate thresholds to dynamically determine the basic state of the port. At the same time, it collects port traffic data, statistically analyzes the maximum and minimum values ​​and the number of changes in segments, and combines the response delays to comprehensively determine port anomalies. This invention overcomes the drawbacks of fixed thresholds in existing port detection technologies, and improves the accuracy of port anomaly judgment and adaptability to dynamic network environments.

[0051] 4. This invention collects device configuration parameters to calculate correlation matching templates, analyzes log time-series sequences to determine system types, collects multi-source vulnerability intelligence and adjusts weighted aggregation based on system type and port anomaly results, and generates key vulnerability detection information by combining device connection relationships and business importance. This achieves intelligent and targeted processing from device system type identification to vulnerability intelligence processing, enhances the comprehensiveness and intelligence level of vulnerability scanning, and provides precise guidance for network security management. Attached Figure Description

[0052] Figure 1 This is a flowchart illustrating the overall workflow of the present invention;

[0053] Figure 2 This is a flowchart of the data acquisition process of the present invention;

[0054] Figure 3 This is a flowchart of the equipment screening process of the present invention;

[0055] Figure 4 This is a flowchart illustrating the device verification process of the present invention.

[0056] Figure 5 This is a flowchart of the port status detection process of the present invention;

[0057] Figure 6 This is a flowchart of the port status determination process of the present invention;

[0058] Figure 7 A flowchart for generating the detection results of this invention is provided. Detailed Implementation

[0059] To make the technical means, creative features, objectives and effects of this invention easier to understand, the invention will be further described below in conjunction with specific embodiments.

[0060] This invention mainly relates to a method for scanning vulnerabilities in network security devices, see reference. Figure 1 This method specifically includes the following steps:

[0061] S1. Collect data on device movement status, signal strength, and environmental interference to form a basic dataset for the device;

[0062] S2. Set a signal strength threshold based on the movement status data of the device's basic dataset, compare the signal strength data with the threshold, correct the environmental interference data, and compare again. Obtain the initial screening list of target devices through the threshold comparison method.

[0063] S3. For the initial screening list of target devices, obtain the connection frequency and data interaction volume, compare them with the baseline values, and combine them with the importance of the network topology location to obtain the final list of target devices;

[0064] S4. Send port probe requests to the target devices in the final list of devices, record the response latency and calculate the latency gradient, use an adaptive algorithm to calculate the adaptive threshold, compare the response latency with the new threshold, and obtain the basic port status data.

[0065] S5. Based on the port's basic status data, collect port traffic data and segment it, count the maximum and minimum values ​​and the number of changes, set standard values ​​and compare them, and combine the response latency to judge port anomalies and obtain port anomaly judgment results.

[0066] S6. Collect device configuration parameters, calculate correlation and match templates, analyze the time sequence of operation logs to obtain device system type determination results, collect vulnerability intelligence data, set and adjust weights and aggregate them, and generate a set of key vulnerability detection information by combining device connection relationships and business importance.

[0067] Specifically, the present invention also relates to a network security device vulnerability scanning apparatus, which includes the following modules:

[0068] The data acquisition module is used to execute step S1;

[0069] The equipment's initial screening module is used to perform step S2;

[0070] The device verification module is used to perform step S3.

[0071] The port detection module is used to perform step S4;

[0072] The port determination module is used to execute the S5 step;

[0073] The Type Analysis and Intelligence Processing module is used to execute the S6 steps.

[0074] Based on the above-mentioned network security device vulnerability scanning device and scanning method, the following detailed implementation method will be further disclosed.

[0075] Example 1, as Figure 2 As shown, this embodiment uses IoT sensors, signal receiving modules, and environmental monitoring nodes to collect device-related data.

[0076] In the technical framework of this solution, data acquisition is the foundation for all subsequent processing;

[0077] Specifically, during the data acquisition process, the device's movement status data is collected in real time through IoT sensors, the signal strength data of the device is obtained through the signal receiving module, and environmental interference data is collected through environmental monitoring nodes.

[0078] The collected data is then aligned with timestamps and stored as a structured dataset.

[0079] In an application scenario in an industrial park, at 10:00:00 on May 22, 2025, the system started the data acquisition process. The GPS sensor and accelerometer deployed on the mobile inspection robot collected the robot's coordinates (120.12, 30.15) and moving speed of 0.5m / s in real time, completing the acquisition of equipment movement status data.

[0080] At the same time, the signal receiving module collected the signal strength of a network security device in the park, and in the following 10 minutes, it successively recorded signal strength values ​​such as -65dBm, -70dBm, and -68dBm.

[0081] The environmental monitoring node (radio monitoring equipment) simultaneously detected an interference intensity of 80μV / m in the 2.4GHz band of the area.

[0082] After data collection is completed, the system performs alignment processing based on the timestamps generated by the data, and integrates the three types of data—device movement status, signal strength, and environmental interference—into a structured dataset.

[0083] Construct a table containing fields such as "time-movement coordinates-signal strength-interference strength", such as generating a data record: 2025-05-22 10:00:00, (120.12, 30.15), -68dBm, 75μV / m, and store it in the system database to lay a standardized data foundation for subsequent equipment screening and analysis.

[0084] Example 2, as Figure 3 As shown, this embodiment performs preliminary screening of network security devices based on the data collected in Embodiment 1;

[0085] Specifically, a signal strength threshold is set based on the device's movement status, and the collected signal strength data is compared with the threshold.

[0086] Then, the environmental interference data is used to correct the signal strength value, and the corrected signal strength value is compared with the threshold again to include the devices that meet the conditions in the initial screening list.

[0087] Based on the data collected in Example 1, the system sets differentiated signal strength thresholds according to the device's movement status:

[0088] When the device is stationary, the threshold is set to -80dBm;

[0089] When the device is in motion, the threshold is set to -90dBm to account for greater signal fluctuations.

[0090] Taking equipment within the park as an example, a network security device in a stationary state collects a signal strength of -75dBm. Compared with the stationary state threshold of -80dBm, since -75dBm > -80dBm, the device's signal is initially determined to be normal.

[0091] A device in motion collects a signal strength of -95dBm, which is less than the motion threshold of -90dBm. Therefore, it is initially determined to be a signal abnormality.

[0092] For mobile devices initially identified as having signal abnormalities, the system uses environmental interference data for correction: when the environmental interference intensity is >70μV / m, the formula "corrected signal strength = acquired value + environmental interference compensation coefficient" (the compensation coefficient is +5dBm) is used for calculation.

[0093] If the interference intensity of the aforementioned mobile device is 80μV / m, the corrected signal strength is -95dBm+5dBm=-90dBm. The corrected value is equal to the mobile state threshold, and the device signal is ultimately determined to be normal. It is then included in the initial screening list, thereby initially defining the target device range for subsequent processing.

[0094] Example 3, as Figure 4 As shown, this embodiment further identifies the target equipment for key testing based on the initial screening results of Embodiment 2;

[0095] Specifically, firstly, the frequency of connections between devices and core switches is counted, the amount of data exchanged between devices per unit time is calculated, and the connection frequency and data exchange amount are compared with the baseline value. The importance of devices is determined in combination with the network topology location, and devices that meet the importance criteria are included in the final list.

[0096] Based on the initial screening in Example 2, a network security device was monitored through the network management system. Within 1 hour, the device connected to the core switch 15 times, and its data exchange volume within 5 minutes was calculated to be 80MB. After conversion, the exchange volume per unit time reached 960MB / h.

[0097] The system sets the connection frequency baseline value to 10 times / h and the data exchange volume baseline value to 500MB / h. Comparing the monitoring data with the baseline values, the device's connection frequency of 15 times / h is greater than 10 times / h, and the data exchange volume of 960MB / h is greater than 500MB / h. Based on the data indicators, the device is preliminarily determined to be a critical device.

[0098] Further considering the network topology location, if the device is located in the aggregation layer and its importance level is rated as "high", it will be directly included in the final target device list; if the device is located in the access layer and its importance level is "medium", it needs to be further verified in combination with other factors before deciding whether to include it, so as to accurately locate the key devices for subsequent vulnerability scanning.

[0099] Example 4, as Figure 5 As shown, this embodiment obtains basic port status information based on the target device determined in Embodiment 3;

[0100] Specifically, a request is sent to the target device port, and the response latency is recorded; the difference between adjacent response latencies is calculated to obtain the latency gradient; an adaptive algorithm is used to calculate a threshold, and the response latency is compared with the threshold to mark abnormal latency.

[0101] Taking the target device port 80 determined in Example 3 as an example, the system sends a TCPSYN request to it and records the response delay of each request in sequence. The delays obtained from the five consecutive probes are 20ms, 22ms, 18ms, 25ms, and 21ms, respectively.

[0102] The time delay gradient is obtained by calculating the difference between adjacent response delays, such as 22-20=2ms, 18-22=-4ms, 25-18=7ms, 21-25=-4ms, thus forming the gradient sequence [2, -4, 7, -4].

[0103] The threshold is calculated using the moving average method. For the first three delays of 20ms, 22ms, and 18ms, the average value is calculated as (20+22+18)÷3=20ms. The standard deviation is approximately 1.63ms. Therefore, the threshold is 20+2×1.63=23.26ms.

[0104] The response latency is compared with the threshold each time. The fourth latency of 25ms > 23.26ms is marked as "latency abnormal"; the fifth latency of 21ms < 23.26ms is marked as "normal". This completes the initial detection of the basic status of the port.

[0105] Example 5, as Figure 6 As shown, this embodiment comprehensively determines the port status based on the basic port status obtained in Embodiment 4;

[0106] Specifically, port traffic is segmented by time; the maximum, minimum and number of changes of traffic in each segment are counted; the traffic characteristic values ​​are compared with the standard values, and combined with the response latency anomaly records, to determine whether the port is abnormal.

[0107] Based on the port basic status obtained in Example 4, the port traffic is segmented into 5-minute time periods;

[0108] For example, if a certain port has a traffic data segment of 10MB, 15MB, 8MB, 20MB, and 12MB, analyzing this traffic data segment reveals that the maximum value is 20MB, the minimum value is 8MB, and the number of traffic changes is 4 (adjacent value changes are counted).

[0109] The system sets the standard value for traffic change rate to ≤30% and the standard value for the number of changes to ≤3 times / 5 minutes. The maximum change rate of this traffic segment is calculated to be (20-8)÷8=150%, which is much greater than 30%; and the number of changes is 4 times > 3 times. Combined with the abnormal response delay recorded in Example 4, the port is determined to be "abnormal", thus providing a reliable basis for subsequent vulnerability analysis.

[0110] Example 6, as Figure 7 As shown, this embodiment generates key vulnerability detection information based on the port determination in Embodiment 5;

[0111] Specifically, the process involves: collecting device configuration parameters; analyzing log time-series sequences; identifying device system types based on the correlation between configuration parameters and log matching; collecting multi-source vulnerability intelligence; adjusting the weight of each source intelligence based on the device system type; weighted aggregation of vulnerability intelligence; and generating key vulnerability detection information by combining the device's business importance with the vulnerability intelligence.

[0112] Based on Example 5, configuration parameters of a certain device were collected, resulting in "Intel i5-1135G7 / 8GB / Windows 10 IoT". This was compared with a known system template, and the correlation with the Windows system template was calculated to be 92%.

[0113] Meanwhile, the device log information was analyzed, and the time sequence of key events, such as "system startup - service loading - data synchronization", was extracted. It was found that the frequency of occurrence matched the typical Windows mode by 85%, and it was determined that the device was running a Windows IoT system.

[0114] Multi-source vulnerability intelligence was collected: Intelligence A: Released on May 20, 2025 (time weight 0.3), the issuing organization's credibility is 90 (credibility weight 0.5), the number of verifications is 50 (verification weight 0.2), and the initial weight is 0.3×(3 / 3)+0.5×(90 / 100)+0.2×(50 / 100)=0.3+0.45+0.1=0.85;

[0115] Intelligence B: Released on May 15, 2025 (time weight 0.2), credibility score 80 (0.4), verification count 30 (0.06), initial weight 0.2+0.4+0.06=0.66;

[0116] Intelligence C: Release time 2025-05-22 (time weight 0.1), credibility 70 (0.3), verification count 20 (0.04), initial weight = 0.1 + 0.3 + 0.04 = 0.44;

[0117] Since the device system type is Windows, the weight of intelligence A targeting Windows vulnerabilities is increased to 0.9, the weight of intelligence B remains at 0.66, and intelligence C, which is a general vulnerability, remains at 0.44.

[0118] The final vulnerability risk value is calculated using a weighted aggregation method: Final risk value = 0.9 × 8.0 (A) + 0.66 × 6.0 (B) + 0.44 × 5.0 (C) = 7.2 + 3.96 + 2.2 = 13.36.

[0119] Combined with the fact that the device is connected to the core switch and has high business importance, the key information of the "high-priority vulnerability detection task" is finally generated, providing network security managers with accurate guidance on vulnerability handling.

[0120] The present invention also discloses an electronic device, including a memory and a processor. The memory stores a computer program that can run on the processor. When the processor runs the program, it executes the operation steps corresponding to each module in the above-mentioned network security device vulnerability scanning device.

[0121] Specifically, the processor first calls the data acquisition module to obtain real-time data from IoT sensors, signal receiving modules, and environmental monitoring nodes, and then stores this data in the memory;

[0122] The equipment screening module and the equipment confirmation module are triggered sequentially to filter the data in the memory, determine the final list of target equipment, and store the list back into the memory.

[0123] Next, the port detection module and port determination module are used to detect and determine the status of the target device's ports, generate port status data, and update it to the memory again.

[0124] Finally, the type analysis module and the intelligence assessment module perform device system type identification and vulnerability intelligence aggregation analysis based on the data stored in the memory, generate key vulnerability detection information, and output it to the management interface for security management personnel to view and process.

[0125] The foregoing has shown and described the basic principles, main features, and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited to the above embodiments. The embodiments and descriptions in the specification are merely illustrative of the principles of the invention. Various changes and modifications can be made to the invention without departing from its spirit and scope, and all such changes and modifications fall within the scope of the present invention as claimed. The scope of protection of this invention is defined by the appended claims and their equivalents.

Claims

1. A method for scanning vulnerabilities in network security devices, characterized in that, Includes the following steps: S1. Data acquisition: Collect data on device movement status, signal strength, and environmental interference to form a basic dataset for the device. S2. Equipment screening: Set a signal strength threshold based on the movement status data of the equipment basic dataset, compare the signal strength data with the threshold, correct the environmental interference data, and compare again. Obtain the initial screening list of target equipment through the threshold comparison method. S3. Device Confirmation: For the initial screening list of target devices, obtain the connection frequency and data exchange volume, compare them with the baseline values, and combine them with the importance of the network topology location to obtain the final list of target devices. S4. Port Status Detection: Send port probe requests to the target devices in the final list of devices, record the response latency and calculate the latency gradient, use an adaptive algorithm to calculate the adaptive threshold, compare the response latency with the new threshold, and obtain the basic port status data. S5. Port status determination: Based on the basic port status data, collect port traffic data and segment it, count the maximum and minimum values ​​and the number of changes, set standard values ​​and compare them, and combine the response latency to determine port anomalies and obtain the port anomaly determination result. S6. Detection result generation: Collect device configuration parameters, calculate correlation and match templates, analyze the time sequence of operation logs to obtain device system type determination results, collect vulnerability intelligence data, set and adjust weights and perform weighted aggregation, and combine device connection relationships and business importance to generate a set of key vulnerability detection information; The device screening described in S2 specifically includes: S2.

1. Set a signal strength threshold based on the motion status data in the device's basic dataset, compare the signal strength data with the set threshold, and obtain the initial comparison signal strength value. S2.

2. Use environmental interference data from the device's basic dataset to correct the initial signal strength value. Then compare the corrected signal strength value with the signal strength threshold to obtain the initial screening list of target devices using the threshold comparison method. The port status monitoring described in S4 specifically includes: S4.1 Send port probe requests to the target devices in the final list, record the port response delay, and obtain the port response delay record value; S4.2 Calculate the difference between adjacent response delays based on the port response delay record values ​​to obtain the delay gradient calculation value; S4.3 Calculate the adaptive threshold based on the delay gradient using an adaptive algorithm, compare the port response delay record value with the new threshold, and obtain the port basic status data; Send a request to the target device port and record the response latency; calculate the latency gradient by measuring the difference between adjacent response latencies; calculate a threshold using an adaptive algorithm, compare the response latency with the threshold, and mark abnormal latencies. The port status determination described in S5 specifically includes: S5.1 Based on the port basic status data, collect the traffic data of each port of the target device and segment it by time to obtain segmented port traffic data; S5.2 Calculate the maximum, minimum and number of changes of traffic in each time period in the segmented port traffic data to obtain the statistical values ​​of the maximum and minimum traffic values ​​and the number of changes. S5.3 Set the normal range standard values ​​for the traffic change rate and the number of changes, calculate the traffic change rate and compare it with the standard value, count the number of changes and compare it with the standard value, and combine the port response delay record value to determine whether the port is abnormal, and obtain the port abnormality judgment result.

2. The network security device vulnerability scanning method according to claim 1, characterized in that: The data acquisition described in S1 specifically includes: S1.1 Collect equipment movement status data, signal strength data, and environmental interference data from environmental monitoring nodes to obtain basic equipment data collection values; S1.2 Integrate the collected equipment movement status data, signal strength data, and environmental interference data to establish a basic equipment dataset.

3. The network security device vulnerability scanning method according to claim 1, characterized in that: The device verification mentioned in S3 specifically includes: S3.1 For the devices in the initial screening list of target devices, obtain their connection frequency data with the network core devices to obtain the device connection frequency data value; S3.2 Calculate the amount of data interaction of the devices in the initial screening list of target devices within a unit of time to obtain the data interaction value of the devices; S3.3 Compare the device connection frequency data value with the set connection frequency benchmark value, compare the device data interaction quantity value with the set data interaction quantity benchmark value, and combine the network topology location importance judgment to obtain the final list of target devices.

4. The network security device vulnerability scanning method according to claim 1, characterized in that: The generation of detection results described in S6 specifically includes: S6.1 Collect the device configuration parameters in the final list of target devices, statistically analyze the parameter combinations of a large number of known system type devices, calculate the correlation between each parameter, and obtain the calculated value of device parameter correlation. S6.2 Match the calculated value of the device parameter correlation degree with the parameter correlation degree template of the known system type, obtain the target device operation log, extract key event information to construct a time series, and obtain the device log time series value; S6.3 Analyze the frequency and characteristics of events in the time sequence values ​​of the device logs, compare them with the typical log time sequence patterns of known system types, and obtain the device system type determination results; S6.4 Collect vulnerability intelligence from multiple sources, obtain data on intelligence release time, credibility of the releasing organization, and number of intelligence verifications, set time weight, credibility weight, and number of verifications weight, calculate the initial weight of each intelligence source, and obtain the initial weight calculation value of the intelligence source. S6.5 Adjust the initial weight calculation value of the intelligence source according to the device system type determination result and the port anomaly determination result, and aggregate the intelligence from different sources according to the adjusted weight to obtain vulnerability intelligence assessment data. S6.6 Analyze the system function scope and data volume involved for each vulnerability in the vulnerability intelligence assessment data, and generate a set of key vulnerability detection information by combining the device's connection relationship in the IoT network and the importance of the business it carries.

5. A network security device vulnerability scanning apparatus, the apparatus being used to execute the network security device vulnerability scanning method of claim 1, characterized in that, The device includes: a data acquisition module for performing step S1; a device initial screening module for performing step S2; a device confirmation module for performing step S3; a port detection module for performing step S4; a port determination module for performing step S5; and a type analysis and information processing module for performing step S6.

6. An electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor runs the program, it executes the operation steps corresponding to each module in the network security device vulnerability scanning device as described in claim 5.

Citation Information

Patent Citations

  • Network security vulnerability position detection method and system

    CN117614741A

  • Network security detection method and system

    CN118101250A