A network device vulnerability assessment method

By statistically analyzing the cross-connection points within network devices, a vulnerability association risk prediction model is established, which solves the problem of the lack of pre-assessment in traditional network device vulnerability assessment and achieves a more rigorous and efficient vulnerability assessment.

CN120768705BActive Publication Date: 2026-03-27GRANPECT
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-09-11
Publication Date
2026-03-27

AI Technical Summary

Technical Problem

Traditional network device vulnerability assessment methods do not conduct prior vulnerability risk assessments, resulting in high vulnerability investigation costs, wasted resources, and inaccurate detection, thus reducing the rigor and efficiency of network device vulnerability assessments.

Method used

By statistically analyzing cross-connection points within network devices, assessing vulnerability risk values ​​under different cross-connection point conditions, establishing vulnerability association risk prediction models, and conducting targeted vulnerability simulation attack scans.

Benefits of technology

It enhances the rigor and systematic nature of network device vulnerability assessment, refines the severity levels of vulnerability risk assessment values, avoids resource waste and inefficiency, and provides targeted countermeasures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120768705B_ABST
    Figure CN120768705B_ABST
Patent Text Reader

Abstract

The application discloses a network device vulnerability evaluation method, and relates to the technical field of network device vulnerability evaluation.The method comprises the following steps: selecting a target intersection path, auxiliary measurement paths one and two from a network path with intersection points; if the target intersection path and the auxiliary measurement paths one and two have some intersection points in common, then the first to-be-measured risk characteristic data is counted; if the target intersection path and the auxiliary measurement path two have some intersection points in common, and the auxiliary measurement paths one and two have some intersection points in common, then the second to-be-measured risk characteristic data of the intersection points under the condition is counted; if the target intersection path and the auxiliary measurement path one or two have some intersection points in common, and the target intersection path, the auxiliary measurement path one and the auxiliary measurement path two are in a completely non-overlapping relationship, then the third to-be-measured risk characteristic data is counted; and according to the three kinds of to-be-measured risk characteristic data, the comprehensive vulnerability evaluation of the to-be-measured network path is evaluated.The application can improve the vulnerability mining accuracy.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of network device vulnerability assessment, and particularly relates to a network device vulnerability assessment method. BACKGROUND

[0002] With the popularization of cloud computing, Internet of Things (IoT), 5G and other technologies, the dependence of enterprises and individuals on network services is growing exponentially. A large number of devices access form a huge heterogeneous network environment (such as routers, switches, firewalls, etc.), which leads to a sharp expansion of the attack surface. For example, supply chain attacks can move laterally to core systems by penetrating edge devices, causing a chain reaction.

[0003] In the traditional technology, the assessment of network device vulnerabilities often directly takes the processing steps of attack simulation to implement the troubleshooting of vulnerabilities, without pre-vulnerability risk assessment, which easily increases the cost of vulnerability troubleshooting, causes resource waste, and fails to accurately and effectively detect actual risk points, thereby reducing the rigor and efficiency of the entire network device vulnerability assessment work. SUMMARY

[0004] In order to overcome the above-mentioned deficiencies of the prior art, the present application provides a network device vulnerability assessment method.

[0005] The network device vulnerability assessment method provided by the present application comprises:

[0006] Step S1, selecting a target cross-path, a first auxiliary measurement path and a second auxiliary measurement path from a network path in which cross-junctions exist in a network device, if the target cross-path and the first auxiliary measurement path and the second auxiliary measurement path have some cross-junctions that coincide, outputting a pre-processing condition one, according to the pre-processing condition one, assessing the associated influence degree value between the number of cross-junctions on the target cross-path and the vulnerability risk, and outputting a vulnerability risk estimate one;

[0007] Step S2, counting the logical distance between two adjacent cross-junctions in the pre-processing condition one to obtain a junction risk logical distance, and counting the ratio between the path distribution number and the area of each cross-junction in the pre-processing condition one to obtain a junction risk density, if the first auxiliary measurement path still has non-coincident cross-junctions under the condition of the pre-processing condition one, outputting a pre-processing condition two, according to the pre-processing condition two, the vulnerability risk estimate one, the junction risk logical distance and the junction risk density, counting first to-be-measured risk feature data;

[0008] Step S3, if the target intersection path and the auxiliary measurement path two exist part of the intersection node coincidence, and the auxiliary measurement path one and the auxiliary measurement path two exist part of the intersection node coincidence, the second to be measured risk characteristic data of the intersection node is counted, if the target intersection path and the auxiliary measurement path one or the auxiliary measurement path two exist intersection node coincidence, and the target intersection path, the auxiliary measurement path one, the auxiliary measurement path two are in complete non overlapping relationship, the third to be measured risk characteristic data is counted, according to three kinds of to be measured risk characteristic data, the comprehensive vulnerability estimation of the to be measured network path is carried out, and the vulnerability simulation attack scanning is carried out in the corresponding position, and the vulnerability detection result is output.

[0009] Preferably, the network path in the network equipment is detected, and the to be measured network path is output, if the intersection node exists in the to be measured network path, the network path with the most intersection nodes is selected from the to be measured network path, and the target intersection path is output.

[0010] The auxiliary measurement path one and the auxiliary measurement path two which exist intersection relationship with the target intersection path are extracted from the to be measured network path, the auxiliary measurement path one is the network path which exists intersection node with the target intersection path, and the auxiliary measurement path two is the network path which exists intersection node with the target intersection path except the auxiliary measurement path one.

[0011] Preferably, if the target intersection path and the auxiliary measurement path one and the auxiliary measurement path two exist part of the intersection node coincidence, preprocessing condition one is output, wherein the target intersection path and the auxiliary measurement path one partially coincide, and the target intersection path and the auxiliary measurement path two are in complete non overlapping relationship.

[0012] According to the preprocessing condition one, the number of intersection nodes on the target intersection path is counted, and the target node number is obtained.

[0013] The historical vulnerability detection data of the historical period network equipment encryption configuration weakened degradation is acquired, the historical path intersection node number and the historical vulnerability risk value are extracted from the historical vulnerability detection data, the risk correlation coefficient between the historical path intersection node number and the historical vulnerability risk value is counted, and the risk correlation factor is output.

[0014] The target node number and the risk correlation factor are multiplied, the vulnerability risk estimation value of the configuration weakened degradation is obtained, and the vulnerability risk estimation one is output.

[0015] Preferably, the logical distance between the adjacent two intersection nodes in the preprocessing condition one is counted, the node distribution logical distance is output, the average value of all logical distance values in the node distribution logical distance is calculated, and the node risk logical distance is output.

[0016] The path distribution area of each intersection in the pre-processing condition one is counted to obtain a path coverage area, and the number of path publications in the path coverage area is counted to obtain a path publication number, and the path distribution number and the path coverage area are compared to obtain a risk density of the intersection.

[0017] Preferably, if the auxiliary measurement path one also has non-coincident intersection points in addition to the pre-processing condition one, a pre-processing condition two is output, the path length of the intersection point in the pre-processing condition two to the starting data output end is counted, and a to-be-measured distance value one is output.

[0018] The path length of the intersection point on the target intersection path to the starting data output end is counted, and the shortest path length is extracted to output a to-be-measured distance value two, and the to-be-measured distance value two and the to-be-measured distance value one are compared to obtain a risk correlation distance ratio one of the intersection.

[0019] The intersection risk logical distance, the intersection risk density, and the intersection risk correlation distance ratio one are combined into first to-be-measured risk feature data.

[0020] Preferably, if the target intersection path and the auxiliary measurement path two have partially coincident intersection points, the auxiliary measurement path one and the auxiliary measurement path two have partially coincident intersection points, and the target intersection path, the auxiliary measurement path one, and the auxiliary measurement path two are in a completely non-coincident relationship, the path length of the coincident intersection point of the auxiliary measurement path one and the auxiliary measurement path two to the starting data output end is counted, and a to-be-measured distance value three is output.

[0021] The to-be-measured distance value three and the to-be-measured distance value one are compared to obtain a risk correlation distance ratio two, and the intersection risk logical distance and the risk correlation distance ratio two are combined into second to-be-measured risk feature data.

[0022] If the target intersection path and the auxiliary measurement path one or the auxiliary measurement path two have coincident intersection points, and the target intersection path, the auxiliary measurement path one, and the auxiliary measurement path two are in a completely non-coincident relationship, the intersection risk logical distance is taken as third to-be-measured risk feature data.

[0023] The first to-be-measured risk feature data, the second to-be-measured risk feature data, and the third to-be-measured risk feature data are combined into pre-processing comprehensive risk feature data.

[0024] Preferably, according to the to-be-measured risk feature data, historical risk feature data and corresponding historical comprehensive correlation risk values are extracted from historical vulnerability detection data, and a vulnerability correlation risk prediction model is established according to the historical risk feature data and the corresponding historical comprehensive correlation risk values.

[0025] inputting the preprocessed comprehensive risk feature data into the vulnerability correlation risk prediction model for testing to obtain vulnerability risk evaluation two;

[0026] summing the vulnerability risk evaluation one and the vulnerability risk evaluation two to obtain vulnerability evaluation of the target cross path, and obtaining comprehensive vulnerability evaluation of the network path in the cross junction network path according to the vulnerability evaluation;

[0027] According to the comprehensive vulnerability evaluation, the vulnerability simulation attack scanning of the corresponding position is carried out, and the vulnerability detection result is output.

[0028] Compared with the prior art, the present application has the following characteristics and beneficial effects:

[0029] By statistically analyzing whether there is a cross junction in the network path of the network device, if there is a cross junction between the network paths, it will cause a conflict between the encryption configurations, and then cause the encryption configuration to be weakened and degraded, so that the encryption information is more easily cracked by external attackers. The diversity of the related influence factor feature data of the induced vulnerability risk value of the cross junction between the network paths is distinguished and analyzed. The first case is that the target cross path and the auxiliary path one and the auxiliary path two have partial cross junction overlap, wherein the target cross path and the auxiliary path one have partial overlap relationship, and the target cross path and the auxiliary path two have complete non-overlap relationship. In this case, the induced degree of the vulnerability risk value is the largest (i.e. the related influence factor is the largest). The second case is that the target cross path and the auxiliary path two have partial cross junction overlap, the auxiliary path one and the auxiliary path two have partial cross junction overlap, and the target cross path, the auxiliary path one and the auxiliary path two are in complete non-overlap relationship. In this case, the induced degree of the vulnerability risk value is the second. The third case is that the target cross path and the auxiliary path one and the auxiliary path two have cross junction overlap, and the target cross path, the auxiliary path one and the auxiliary path two are in complete non-overlap relationship. In this case, the induced degree of the vulnerability risk value is the smallest. Through step-by-step analysis of the different cases, the rigor and orderliness of the network device vulnerability evaluation process are enhanced, and the severity level of the vulnerability risk evaluation value is further refined, so that subsequent targeted differentiated response measures can be taken, and the resource waste and low efficiency caused by direct vulnerability simulation attack scanning without prior vulnerability evaluation prediction in the traditional technology are avoided. BRIEF DESCRIPTION OF DRAWINGS

[0030] Figure 1 is a step block diagram of a network device vulnerability evaluation method mainly embodied by the present embodiment. DETAILED DESCRIPTION

[0031] The present application will be further described in detail below in combination with the following embodiments.

[0032] Referring to Figure 1 A network device vulnerability assessment method, the method comprising the following steps:

[0033] Step S1, selecting a target cross-path, a first auxiliary path and a second auxiliary path from a network path in which cross-junctions exist in a network device, if the target cross-path and the first auxiliary path and the second auxiliary path have some cross-junctions in common, outputting a pre-processing condition one, according to the pre-processing condition one, assessing the associated influence degree value between the number of cross-junctions on the target cross-path and the vulnerability risk, and outputting a vulnerability risk estimate one.

[0034] Step S2, counting the logical distance between adjacent two cross-junctions in the pre-processing condition one to obtain a junction risk logical distance, and counting the ratio between the path distribution number and the area of each cross-junction in the pre-processing condition one to obtain a junction risk density, if the first auxiliary path also has non-coincident cross-junctions under the condition of the pre-processing condition one, outputting a pre-processing condition two, according to the pre-processing condition two, the vulnerability risk estimate one, the junction risk logical distance and the junction risk density, counting the first to-be-tested risk feature data.

[0035] Step S3, if the target cross-path and the second auxiliary path have some cross-junctions in common, and the first auxiliary path and the second auxiliary path have some cross-junctions in common, then count the second to-be-tested risk feature data to which the cross-junctions belong, if the target cross-path and the first auxiliary path or the second auxiliary path have cross-junctions in common, and the target cross-path, the first auxiliary path and the second auxiliary path are in a completely non-coincident relationship with each other, then count the third to-be-tested risk feature data, according to the three kinds of to-be-tested risk feature data, assess the comprehensive vulnerability estimate of the to-be-tested network path, and output the vulnerability detection result after performing the vulnerability simulation attack scanning on the corresponding position.

[0036] Specifically, by counting whether there is a cross-junction in the network path in the network device, in the case of mutual cross-junction between network paths, it will cause conflict between encryption configurations, and then lead to the weakening and degradation of encryption configuration, so that it is easier for external attackers to crack encrypted information. The diversity of related influence factor characteristic data of the induced vulnerability risk value of different cross-junction situations between network paths is distinguished and analyzed. Different cross-junction situations: the first situation is that the target cross-path and the auxiliary measurement path one and the auxiliary measurement path two exist partially cross-junction overlap, wherein the target cross-path and the auxiliary measurement path one partially overlap, the target cross-path and the auxiliary measurement path two completely do not overlap, in this case, the induced degree of vulnerability risk value is the largest (i.e. the related influence factor is the largest), the second situation is that the target cross-path and the auxiliary measurement path two exist partially cross-junction overlap, the auxiliary measurement path one and the auxiliary measurement path two exist partially cross-junction overlap, and the target cross-path, the auxiliary measurement path one and the auxiliary measurement path two are in completely non-overlapping relationship, in this case, the induced degree of vulnerability risk value is the second, the third situation is that the target cross-path and the auxiliary measurement path one and the auxiliary measurement path two exist cross-junction overlap, and the target cross-path, the auxiliary measurement path one, the auxiliary measurement path two are in completely non-overlapping relationship, in this case, the induced degree of vulnerability risk value is the smallest. Through step-by-step analysis of different situations, the rigor and orderliness of the network device vulnerability evaluation process are enhanced, and the severity level of the vulnerability risk evaluation value is further refined, so as to facilitate subsequent corresponding targeted differential response measures, avoiding the resource waste and low efficiency caused by direct vulnerability simulation attack scanning without prior vulnerability evaluation prediction in traditional technology.

[0037] The specific step S1 includes the following sub-steps:

[0038] Detect the network path in the network device, output the network path to be tested, if there is a cross-junction in the network path to be tested, select the network path with the most cross-junctions from the network path to be tested, and output the target cross-path.

[0039] Extract the auxiliary measurement path one and the auxiliary measurement path two which exist cross relationship with the target cross-path from the network path to be tested, the auxiliary measurement path one is the network path which exists cross-junction with the target cross-path, and the auxiliary measurement path two is the network path which exists cross-junction with the target cross-path except the auxiliary measurement path one.

[0040] If the target cross-path and the auxiliary measurement path one and the auxiliary measurement path two exist partially cross-junction overlap, output pre-processing situation one, wherein the target cross-path and the auxiliary measurement path one partially overlap, and the target cross-path and the auxiliary measurement path two completely do not overlap.

[0041] According to the pre-processing condition one, the number of intersection nodes on the target intersection path is counted to obtain the target intersection node number.

[0042] The historical vulnerability detection data of the network equipment encryption configuration weakening degradation in the historical period is acquired, the historical path intersection node number and the historical vulnerability risk value are extracted from the historical vulnerability detection data, the risk correlation coefficient between the historical path intersection node number and the historical vulnerability risk value is counted, and the risk correlation factor is output.

[0043] The target intersection node number and the risk correlation factor are multiplied to obtain the vulnerability risk estimation value of the configuration weakening degradation, and the vulnerability risk estimation value one is output.

[0044] Specifically, the vulnerability assessment mentioned in the present application is a vulnerability assessment of the weakening and degradation of the encryption configuration, the network path to be tested (the network path refers to the route of data transmission in the network device, which may involve multiple physical or logical channels: such as routers, switches, servers, etc.), the target cross path, the auxiliary test path one and the auxiliary test path two (if multiple network paths in the device cross, it is most likely to cause synchronization conflict of the encryption configuration, so that the encryption configuration is weakened and degraded, and it is more conducive to the intrusion of external attackers. If the target cross path is L1, the auxiliary test path one is L2, and the auxiliary test path two is L3), the preprocessing condition one (for example, there are two overlapping intersection points of L1, L2 and L3, and if they are D1 and D2 (intersection point: for example, multiple network paths may cross with a specific function module or processing node, forming an "intersection point". The intersection point is essentially a key position for vulnerability mining, because an attacker may use these cross paths to implement unauthorized access or data tampering), for example, the path between L1 and L2 at D1 and D2 is the same, that is, the target cross path and the auxiliary test path one are partially overlapped, and there is no path overlap between L1 and L3, only the relationship of the intersection point, in this case, the risk influence degree of L2 on L1 is greater), the number of target intersection points (if it is i (for example, there are 2 intersection points (D1, D2) on L1 in the above example, the number of intersection points is positively correlated with the risk degree of the weakening of the encryption configuration, and the increase of the intersection points may lead to management oversight, for example, the encryption policy is not uniformly deployed, and some nodes (i.e. intersection points) become weak links), the risk correlation factor (historical vulnerability detection data (such as CVSS score: using v4.0 standard, scoring (0-10 points) from attack vector (AV), attack complexity (AC), impact range (IA) and other dimensions. The historical vulnerability risk value is R1, R2, Rn: for example, determined by the product of the security event probability and the potential loss. If the number of historical path intersection points is H1, H2, Hn, then R is the y-axis and H is the x-axis, the correlation characteristics between the historical vulnerability risk value and the number of historical path intersection points are drawn, (R2-R1) / (H2-H1), (Rn-Rm) / (Hn-Hm) are averaged, where n-m=1, and if it is Z, the risk correlation factor), vulnerability risk estimate one (i*Z is G1).

[0045] The specific step S2 includes the following sub-steps:

[0046] The logical distance between the adjacent two intersection points in the preprocessing condition one is counted, the intersection point distribution logical distance is output, and the average value of all logical distance values in the intersection point distribution logical distance is output.

[0047] The path distribution area of each intersection in the pre-processing condition one is counted to obtain the path coverage area, and the path distribution quantity in the path coverage area is counted to obtain the path publication quantity. The path distribution quantity and the path coverage area are compared to obtain the intersection risk density.

[0048] If the auxiliary measurement path one still exists a non-coincidence intersection in addition to the pre-processing condition one, output the pre-processing condition two, count the path length of the intersection in the pre-processing condition two to the starting data output end, and output the measured distance value one.

[0049] The path length of the intersection on the target intersection path to the starting data output end is counted, and the shortest path length is extracted to output the measured distance value two. The measured distance value two and the measured distance value one are compared to obtain the intersection risk correlation distance ratio one.

[0050] The intersection risk logical distance, the intersection risk density, and the intersection risk correlation distance ratio one are combined to obtain the first measured risk feature data.

[0051] Specifically, as the meeting point risk logic distance (the logic distance is the path length or hop count (such as the logic distance statistics in the present application: determining the nearest common node of two cross meeting points in the network topology, which is the subsequent starting data output end (such as data center, cluster, etc.), then adding the common path length from each cross meeting point to the starting data output end, and the sum is the logic distance. For example, if the common ancestor is a data center, the distance from cross meeting point D1 to the starting data output end is 3, and the distance from cross meeting point D2 to the starting data output end is 3, then the logic distance is 3+3=6, which is represented by b1, which is the logic distance of the meeting point distribution between D1 and D2. At this time, there is no need to average, if there are 3 cross meeting points in L1, and the third is D3, then by analogy, the logic distance of the meeting point distribution between D2 and D3 is calculated, and if it is b2, then the average value (b1+b2) / 2 is B, which is the meeting point risk logic distance), the logic distance is more directly related to the attenuation (weakening degradation) of the encryption strength (the update strength of the encryption configuration) and the increase of the vulnerability risk value), the path coverage area (such as the area covered by L1 and L2 distribution of D1 cross meeting point, if it is S1), the path publishing quantity (such as L1 and L2 are two, represented by N), the meeting point risk density (which is S1 / N if it is P1, and by analogy, for L1 and L3 of D2 cross meeting point, if it is P2, then (P1+P2) / 2 if it is Pi), the preprocessing condition two (for example, there are other cross meeting points d on L2 (not coinciding with L1 and L3), because L2 has an associated vulnerability risk impact on L1, the more cross meeting points on L2, the greater the associated impact on the vulnerability risk value of L1), the first to be measured distance value (such as the above-mentioned meeting point distribution logic distance statistics, and by analogy, if it is j1, it should be noted that the first to be measured distance value here is the path length between d and the starting data output end), the second to be measured distance value (if D1 and D2 are j2 and j3 respectively, and if j2 is the shortest, then j2 is selected as the second to be measured distance value), the first meeting point risk associated distance ratio (which is j2 / j1 if it is Ji1).

[0052] The specific step S3 includes the following sub-steps:

[0053] If the target cross path and the auxiliary measurement path two have some cross meeting points coinciding, the auxiliary measurement path one and the auxiliary measurement path two have some cross meeting points coinciding, and the target cross path, the auxiliary measurement path one and the auxiliary measurement path two are in a completely non-coinciding relationship, then the path lengths of the auxiliary measurement path one and the auxiliary measurement path two from the coinciding cross meeting points to the starting data output end are respectively calculated, and the third to be measured distance value is output.

[0054] The third to be measured distance value and the first to be measured distance value are compared to obtain the second meeting point risk associated distance ratio, and the second to be measured risk feature data is combined from the meeting point risk logic distance and the second meeting point risk associated distance ratio.

[0055] If the target cross-path and the auxiliary measurement path one or the auxiliary measurement path two exist intersection junction coincidence, and the target cross-path, the auxiliary measurement path one and the auxiliary measurement path two are in complete non-coincidence relationship, then the junction risk logic distance is taken as the third to-be-measured risk feature data.

[0056] The first to-be-measured risk feature data, the second to-be-measured risk feature data and the third to-be-measured risk feature data are combined into preprocessed comprehensive risk feature data.

[0057] According to the to-be-measured risk feature data, historical risk feature data and corresponding historical comprehensive correlation risk values are extracted from historical vulnerability detection data, and a vulnerability correlation risk prediction model is established according to the historical risk feature data and the corresponding historical comprehensive correlation risk values.

[0058] The preprocessed comprehensive risk feature data is input into the vulnerability correlation risk prediction model for testing, and vulnerability risk evaluation two is obtained.

[0059] The vulnerability risk evaluation one and the vulnerability risk evaluation two are summed to obtain a vulnerability estimated value of the target cross-path, and according to the vulnerability estimated value, a comprehensive vulnerability estimated value of a network path belonging to the network path in which the intersection junction exists is obtained.

[0060] According to the comprehensive vulnerability estimated value, a vulnerability simulation attack scan is performed at a corresponding position, and a vulnerability detection result is output.

[0061] Specifically, if the target intersection path and the auxiliary measurement path 2 partially coincide at the intersection point, the auxiliary measurement path 1 and the auxiliary measurement path 2 partially coincide at the intersection point, and the target intersection path, the auxiliary measurement path 1 and the auxiliary measurement path 2 are in a completely non-coincidence relationship (for example, the intersection relationship between L1, L2 and L3 is in the form of “≠”, if the intersection point is represented as w1 and w2, the vulnerability risk value in this case is lower than the first case, and the statistical vulnerability risk influence factor data is lower than the first case), the measured distance value three (for example, if the measured distance value between w1 and w2 in L1 and L2 is j4, and the measured distance value between w1 and w2 in L1 and L3 is also j4, then the measured distance value three is j4),The risk correlation distance ratio of the intersection point is two (if j4 / j1 is Ji2), if the target intersection path and the auxiliary measurement path one or the auxiliary measurement path two exist intersection point coincidence, and the target intersection path, the auxiliary measurement path one, the auxiliary measurement path two exist completely non-overlapping relationship (such as L1 and L2 exist intersection point w3, L3 also exists intersection point, but has no direct intersection correlation with L1 and L2 (L3 generates intersection point with other network paths, which is not considered to affect the vulnerability risk value of L1), the vulnerability risk value in this case is lower than the second case, so the vulnerability risk influence factor data is lower than the second case, at this time, the influence of the risk logic distance of the intersection point on the vulnerability risk value needs to be considered), the historical comprehensive correlation risk value (for example, taking the first to be measured risk characteristic data as an example: Y1=ax+by+cz, wherein Y1 refers to the historical comprehensive correlation risk value, a refers to the risk logic distance B of the intersection point, x refers to the correlation factor between the risk logic distance of the intersection point and the historical comprehensive correlation risk value, b refers to the risk density Pi of the intersection point, y refers to the correlation factor between the risk density of the intersection point and the historical comprehensive correlation risk value, c refers to the risk correlation distance ratio one Ji1, and z refers to the correlation factor between the risk correlation distance ratio one and the historical comprehensive correlation risk value. The known historical risk characteristic data and the corresponding historical comprehensive correlation risk value are substituted into the formula to obtain x, y and z, that is, the trained vulnerability correlation risk prediction model Y1=ax+by+cz is obtained. Similarly, taking the second to be measured risk characteristic data as an example: Y2=ax+cz, it should be noted that c here refers to the risk correlation distance ratio two, and z here refers to the correlation factor between the risk correlation distance ratio two and the historical comprehensive correlation risk value. Similarly, taking the third to be measured risk characteristic data as an example: Y3=ax), vulnerability risk estimate two (if taking the first to be measured risk characteristic data as an example, the vulnerability risk estimate two is G2), vulnerability estimate (if G1+G2 is Gi1, the comprehensive vulnerability estimate is Gi1+Gi2+Gi3+Gin, if it is Gz), vulnerability detection result (such as according to the comprehensive vulnerability estimate (risk level division is carried out, and comparison and judgment are carried out according to the historical vulnerability risk level value, such as the comprehensive vulnerability estimate is greater than or equal to the historical vulnerability risk level value, which is judged as a low-risk vulnerability, and the comprehensive vulnerability estimate is less than the historical vulnerability risk level value, which is judged as a high-risk vulnerability), high-risk vulnerability: perform full-port, full-protocol deep scanning, cover all network device interfaces, low-risk vulnerability: adopt sampling scanning, focus on key service port vulnerability simulation attack scanning, and record the vulnerability detection result).

[0062] The above are all preferred embodiments of the present application, and do not limit the protection scope of the present application, so that: all equivalent changes made according to the structure, shape, principle of the present application should be covered in the protection scope of the present application.

Claims

1. A method for assessing network device vulnerabilities, characterized in that, Includes the following steps: Step S1: Select the target cross path, auxiliary test path 1, and auxiliary test path 2 from the network paths containing cross nodes in the network device. If the target cross path overlaps with auxiliary test path 1 and auxiliary test path 2 in some cross nodes, output preprocessing situation 1. Based on preprocessing situation 1, evaluate the degree of correlation between the number of cross nodes on the target cross path and the vulnerability risk, and output vulnerability risk estimate 1. Step S2: Calculate the logical distance between two adjacent intersection points in preprocessing case 1 to obtain the intersection risk logical distance, and calculate the ratio between the number and area of ​​each intersection point in preprocessing case 1 to obtain the intersection risk density. If auxiliary test path 1 still has non-overlapping intersection points excluding those in preprocessing case 1, output preprocessing case 2. Based on preprocessing case 2, vulnerability risk assessment 1, intersection risk logical distance, and intersection risk density, calculate the first test risk feature data. Step S3: If the target cross path and auxiliary test path 2 have some overlapping cross points, and auxiliary test path 1 and auxiliary test path 2 have some overlapping cross points, then the second test risk feature data of the cross points is counted. If the target cross path and auxiliary test path 1 or auxiliary test path 2 have overlapping cross points, and the target cross path, auxiliary test path 1, and auxiliary test path 2 are completely non-overlapping, then the third test risk feature data is counted. Based on the three test risk feature data, the comprehensive vulnerability prediction value of the network path to be tested is evaluated, and the vulnerability exploitation detection results are output after performing vulnerability simulation attack scans at the corresponding locations.

2. The network device vulnerability assessment method according to claim 1, characterized in that, Step S1 includes: The network path within the network device is detected, and the network path to be tested is output. If there is a crossover point in the network path to be tested, the network path with the most crossover points is selected from the network paths to be tested and the target crossover path is output. From the network path to be tested, extract auxiliary test path one and auxiliary test path two that have a cross relationship with the target cross path. Auxiliary test path one is a network path that has a cross point with the target cross path, and auxiliary test path two is a network path other than auxiliary test path one that has a cross point with the target cross path.

3. The network device vulnerability assessment method according to claim 2, characterized in that, Step S1 also includes: If the target intersection path partially overlaps with auxiliary test path one and auxiliary test path two, output preprocessing case one, in which the target intersection path partially overlaps with the auxiliary test path, and the target intersection path does not overlap with auxiliary test path two at all. Based on the first preprocessing scenario, the number of intersection points on the target intersection path is counted to obtain the target intersection point count; Acquire historical vulnerability detection data showing that the encryption configuration of network devices was weakened or downgraded during historical periods. Extract the number of historical path intersections and the risk value of historical vulnerabilities from the historical vulnerability detection data. Statistically analyze the risk correlation coefficient between the number of historical path intersections and the risk value of historical vulnerabilities, and output the risk correlation factor. Multiply the target number of sinks and the risk correlation factor to obtain the vulnerability risk estimate of the weakened and downgraded configuration, and output the vulnerability risk estimate one.

4. The network device vulnerability assessment method according to claim 3, characterized in that, Step S2 includes: The logical distance between two adjacent intersection points in preprocessing case 1 is statistically analyzed, and the logical distance of the intersection point distribution is output. The average value of all logical distance values ​​in the logical distance of the intersection point distribution is calculated, and the logical distance of the intersection point risk is output. The path distribution area of ​​each intersection point in preprocessing scenario one is statistically analyzed to obtain the path coverage area. The number of paths published within the path coverage area is also statistically analyzed to obtain the number of paths published. The ratio of the number of paths distributed to the path coverage area is calculated to obtain the risk density of the intersection point.

5. The network device vulnerability assessment method according to claim 4, characterized in that, Step S2 also includes: If the auxiliary test path one still has non-overlapping intersection points excluding the conditions of preprocessing case one, output preprocessing case two, and count the path lengths of the intersection points in preprocessing case two to reach the starting data output end, and output the distance value to be tested one. The path lengths from the intersection points on the target intersection path to the starting data output end are statistically analyzed, and the shortest path length is extracted. The second distance value to be measured is output. The ratio of the second distance value to be measured and the first distance value to be measured is obtained to obtain the first risk association distance ratio of the intersection point. The sum of the logical distance of the sink risk, the density of the sink risk, and the correlation distance of the sink risk are compared to a set of synthesized first risk feature data to be tested.

6. The network device vulnerability assessment method according to claim 5, characterized in that, Step S3 includes: If the target intersection path and auxiliary test path 2 have some overlapping intersection points, and auxiliary test path 1 and auxiliary test path 2 have some overlapping intersection points, and the target intersection path, auxiliary test path 1 and auxiliary test path 2 are completely non-overlapping, then the path length from the overlapping intersection points of auxiliary test path 1 and auxiliary test path 2 to the starting data output end is calculated, and the distance value to be measured is output as 3. The ratio of the distance value to be measured (3) and the distance value to be measured (1) is calculated to obtain the sink risk correlation distance ratio (2). The sink risk logical distance and the sink risk correlation distance ratio (2) are combined to form the second risk feature data to be measured. If the target cross path and auxiliary test path one or auxiliary test path two have a cross point that coincides, and the target cross path, auxiliary test path one, and auxiliary test path two are completely non-overlapping, then the logical distance of the cross point risk will be used as the third risk feature data to be tested. The first risk feature data to be tested, the second risk feature data to be tested, and the third risk feature data to be tested are combined to form preprocessed comprehensive risk feature data.

7. The network device vulnerability assessment method according to claim 6, characterized in that, Step S3 also includes: Based on the risk feature data to be tested, historical risk feature data and corresponding historical comprehensive associated risk values ​​are extracted from historical vulnerability detection data. Based on the historical risk feature data and corresponding historical comprehensive associated risk values, a vulnerability association risk prediction model is established. The preprocessed comprehensive risk characteristic data is input into the vulnerability association risk prediction model for testing, and the vulnerability risk valuation 2 is obtained. The vulnerability risk assessment 1 and vulnerability risk assessment 2 are summed to obtain the vulnerability estimate of the target cross path. Based on the vulnerability estimate, the comprehensive vulnerability estimate of the network path with cross sink in the network path under test is obtained. Based on the comprehensive vulnerability estimate, perform vulnerability simulation attack scans at the corresponding locations and output vulnerability exploitation detection results.

Citation Information

Patent Citations

  • Attack deduction graph generation method and system based on network security evaluation process

    CN114915476A

  • Block chain-based big data analysis decision method and system

    CN120088068A