Information security testing and forensics platform

By automating assessments and enabling plug-in extensions of the information security testing and forensics platform, the problems of high reliance on manual labor and low detection efficiency in existing technologies have been solved, achieving efficient and accurate network security assessments and forensics.

CN120915615BActive Publication Date: 2025-12-23CHENGDU CHUANGXIN HUATONG INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511448286.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-10-11
Publication Date
2025-12-23
Estimated Expiration
2045-10-11

AI Technical Summary

Technical Problem

Existing cybersecurity assessment and evidence collection methods rely on manual inspection, which leads to errors, insufficient execution, excessively long project execution time, and omission of key evidence, failing to meet the requirements of high-depth and high-accuracy security assessments.

Method used

Design an information security testing and forensics platform that integrates a graphical user interface module, a protocol simulation module, a compliance rule judgment module, and a plugin management module. It supports multi-dimensional evaluation algorithms and standard rule bases to achieve automated and flexible security assessment and forensics.

Benefits of technology

Through automated assessment and plug-in extensions, the efficiency of security assessment and forensics is improved, human intervention is reduced, the accuracy and adaptability of assessments are enhanced, and the integrity and credibility of assessment results are ensured.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120915615B_ABST
    Figure CN120915615B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of information security, and discloses an information security test and evidence collection platform, which comprises a graphic user interface module, a protocol simulation module and a compliance rule judgment module.The graphic user interface module collects project information, project types, device information and task information, and stores the project information in a relational database; the device information is encrypted and stored.The protocol simulation module integrates SSH, HTTP and MySQL protocol client libraries, realizes remote device login, dynamically loads plug-in configuration and executes multi-dimensional evaluation algorithms such as regular matching, keyword scanning and configuration priority analysis.The compliance rule judgment module is internally provided with a standard rule library, generates quantitative evaluation results through Boolean operation, and integrates an SM2 signature engine to perform data signature and integrity verification.The summary is recalculated through a public key data packet and compared with a signature value, so that the data integrity is ensured.The application guarantees the accuracy and pertinence of device security evaluation.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of information security, in particular to an information security testing and forensics platform. BACKGROUND

[0002] With the increasing network security threats, information security testing and forensics become crucial. Most of the existing network security assessment and emergency response forensics methods mainly rely on manual detection, which is subject to the experience and ability of the inspectors, and is prone to cause misoperation, insufficient execution, too long project execution time, and missing key evidence, etc., affecting the accuracy of security assessment and the effectiveness of forensics.

[0003] In the field of network security assessment, according to the laws and regulations and standards such as GB / T 28827.1-2022 "Information Technology Service Operation and Maintenance Part 1: General Requirements", GB / T 20984-2022 "Information Security Technology Information Security Risk Assessment Method", GB / T 22239-2019 "Information Security Technology Network Security Protection Basic Requirements", etc., the depth and accuracy of network security assessment are required to be higher and higher. These standards stipulate the basic requirements and evaluation methods of network security protection, aiming to discover the security risks of the system in time through regular detection, so as to improve the overall network security protection capability.

[0004] However, the existing evaluation tools and forensics platforms mostly have the problems of strong manual dependence, low detection efficiency, insufficient security assessment depth, lack of automation and flexibility, and insufficient forensics capability.

[0005] Therefore, it is necessary to design an information security testing and forensics platform to solve the problems existing in the current technology. SUMMARY

[0006] In view of this, the present application provides an information security testing and forensics platform, which aims to solve the problems of strong manual dependence, low detection efficiency, insufficient security assessment depth, lack of automation and flexibility, and insufficient forensics capability.

[0007] The present application provides an information security testing and forensics platform, which comprises:

[0008] A graphical user interface module is used to collect project information, project type, device information and task information, the project information is stored in a project information table of a relational database, corresponding plug-in configurations are dynamically loaded from a built-in plug-in library according to the project information and project type, and the device information is stored in a device information table after encryption;

[0009] A protocol simulation module is configured to implement remote device login, integrate an SSH protocol client library, an HTTP protocol client library, and a MySQL protocol client library; trigger plug-in selection logic according to the project type and the task information, filter a matching built-in plug-in from the built-in plug-in library, the built-in plug-in including a predefined evaluation index set; and execute a multi-dimensional evaluation algorithm, the multi-dimensional evaluation algorithm including regular expression matching, keyword scanning, and configuration priority analysis.

[0010] A compliance rule judgment module is configured to compare the parameter result set with standard clauses item by item, generate a quantitative evaluation result through Boolean logic operation, integrate an SM2 cryptographic algorithm signature engine, the SM2 cryptographic algorithm signature engine performing a signature operation using a private key data packet, the signature operation generating a digest using an SM3 hash algorithm and calculating a signature value through an SM2 elliptic curve algorithm, the signature value being stored in a signature field of an evaluation record table, and automatically triggering an integrity verification process when a user accesses the evaluation record, the integrity verification process recalculating a data packet digest using a public key data packet and comparing the recalculated data packet digest with the stored signature value, and marking a data abnormal state when the comparison fails.

[0011] Further, the project type includes a CIPR evaluation type, a risk evaluation type, a security operation and maintenance type, and an emergency response type.

[0012] The CIPR evaluation type triggers a CIPR special plug-in set, the CIPR special plug-in set including a security general requirement detection module and a cloud computing extension requirement detection module, the detection modules generating a secondary or tertiary evaluation report; the risk evaluation type activates a risk quantification plug-in, the risk quantification plug-in performing a three-stage process of asset value evaluation, threat possibility calculation, and vulnerability analysis; the security operation and maintenance type calls a periodic detection task template, the periodic detection task template presetting an inspection frequency parameter and a baseline comparison rule; and the emergency response type loads a rapid evidence collection plug-in, the rapid evidence collection plug-in preferentially performing log collection, process snapshot, and network connection state capture operations.

[0013] Further, when the protocol simulation module integrates the SSH protocol client library, the HTTP protocol client library, and the MySQL protocol client library, the following is included.

[0014] The SSH protocol client library calls an SSH open source library of golang.org to implement encrypted channel establishment and command interaction, the HTTP protocol client library constructs a GET / POST request to simulate a user session based on an HTTP library of golang.org, and the MySQL protocol client library uses a MySQL library of gorm.io to perform a database query operation, and a multi-threaded scheduling mechanism is used to handle concurrent connection requests in the login process.

[0015] Further, when the protocol simulation module executes the multi-dimensional evaluation algorithm, the method comprises the following steps of:

[0016] The regular expression matching dynamically loads a regular rule set, the regular rule set is stored in a regular rule section of a plug-in configuration file, each regular rule section includes a matching mode field, an extraction group index field and an error threshold field; the keyword scanning uses a finite state automaton to achieve efficient matching, the finite state automaton is constructed based on an Aho-Corasick algorithm, a state transition table is generated by preprocessing a set of security keywords, and the keyword appearance line number and context fragments are recorded in real time during the scanning process; the configuration priority analysis maintains a priority decision tree, a node of the priority decision tree includes a configuration item path field, a priority value field and a conflict resolution strategy field, a depth-first search is performed by traversing the decision tree, when multiple versions of data of the same configuration item are detected, the highest priority result is selected according to the priority value, and if the priority is the same, the merging rule in the conflict resolution strategy is applied.

[0017] Further, when the protocol simulation module executes the multi-dimensional evaluation algorithm, the method comprises the following steps of:

[0018] The multi-dimensional evaluation algorithm further includes a parameter verification submodule, the parameter verification submodule performs type checking and range verification on the extracted parameter results, a character set analyzer is called for the password complexity parameter to detect the proportion of special characters, and port range legality verification is performed on the port opening parameter.

[0019] Further, the compliance rule judgment module has a built-in standard rule library, which comprises the following steps of:

[0020] The standard rule library is a structured storage security standard clause, including a network security protection requirement item table and a risk assessment item table, the network security protection requirement item table defines a control item field, a requirement content field and a detection method field, and the detection method field is associated with a specific evaluation index; the risk assessment item table defines an asset type field, a threat scenario field and a risk calculation formula field; in the comparison process, the structured storage security standard clause mapping operation is performed, and the configuration parameters in the parameter result set are logically matched with the detection conditions of the structured storage security standard clause.

[0021] Further, the method further comprises the following steps of:

[0022] The plug-in management module provides an external plug-in extension interface, the external plug-in extension interface adopts a RESTful API specification, and sets a plug-in upload endpoint, a plug-in query endpoint and a plug-in activation endpoint; plug-in metadata is maintained through a plug-in registration table, and the plug-in metadata includes a plug-in identification field, a device type field, a version number field, an author information field and a creation timestamp field.

[0023] Further, when the plug-in management module provides an external plug-in extension interface, the plug-in management module comprises:

[0024] The plug-in management module receives an Excel template file uploaded by a user, the Excel template file complies with a predefined structure specification, and contains a project type worksheet, a task level worksheet, an evaluation standard set worksheet, an evaluation command set worksheet, and a note information worksheet; an Excel parsing engine is called to process the uploaded file, the Excel parsing engine is implemented based on the excelize library of github.com, and cell data is read in a worksheet by worksheet manner, wherein the project type worksheet parses a project type enumeration value list, the task level worksheet parses a level value mapping table, the evaluation standard set worksheet extracts a correlation matrix of standard clauses and detection items, and the evaluation command set worksheet converts a command string into an executable instruction sequence.

[0025] Further, when the plug-in management module provides an external plug-in extension interface, the plug-in management module further comprises:

[0026] When the plug-in management module performs a plug-in generation operation, the plug-in management module encapsulates parsed data into a plug-in configuration object, the plug-in configuration object contains a device type identifier, an evaluation index list, and a command execution strategy; a plug-in storage directory is automatically created, the plug-in configuration object is serialized into a JSON format configuration file, and a corresponding Golang execution script framework is generated; the plug-in management module updates a plug-in registry after generating a new plug-in, inserts metadata records of the new plug-in, triggers a plug-in index reconstruction process, ensures that the new plug-in is immediately visible in a task creation interface, sets a template verification rule, performs format verification on an Excel file, including worksheet name verification, missing detection of required fields, and data type consistency checking, and returns a structured error code when verification fails.

[0027] Further, a compatible full protocol stack device type is included, which includes a network device subset, a security device subset, a server subset, a middleware subset and a database subset; the network device subset covers switch devices and router devices, the SNMP protocol module is called for the switch devices to perform VLAN configuration detection, and the SSH or Telnet protocol module is used for the router devices to obtain routing table information; the security device subset covers firewall devices, intrusion detection system devices and intrusion prevention system devices, the access control list of the firewall devices is parsed, and the log analysis interface of the intrusion detection system devices is called; the server subset covers Windows servers and Linux servers, the WMI protocol is used for the Windows servers to query registry items, and the SSH is used for the Linux servers to execute sysctl commands to obtain kernel parameters; the middleware subset covers WebLogic middleware and Nginx middleware, the system parses the domain configuration file of the WebLogic middleware, and checks the server block configuration instruction of the Nginx middleware; the database subset covers MySQL databases and Oracle databases, the SHOW VARIABLES command is executed for the MySQL databases, and the data dictionary view is called for the Oracle databases to query; a device type fingerprint library is maintained, the fingerprint library stores a device feature identification set, including port opening mode, service Banner string and protocol response characteristics, and is used for automatic identification of the device type.

[0028] Compared with the prior art, the beneficial effects of the present application are that: by integrating multiple protocol client libraries and plug-in mechanisms, a variety of network security assessment tasks can be automatically performed, reducing the need for manual intervention and improving the efficiency of security assessment and forensics. Flexible plug-in extension is supported, which can dynamically load and execute corresponding plug-in sets according to different project types, improving the adaptability and scalability of the platform. By integrating multiple common protocol client libraries, the platform supports remote login and configuration detection of multiple network devices, enabling comprehensive security detection of different types of devices and enhancing adaptability in complex network environments. The built-in standard rule library combines structured storage and logical mapping to automatically compare assessment results with security standards item by item, generating quantitative assessment reports in real time. Through automated compliance verification, human error and execution omissions are reduced. The SM2 cryptographic algorithm signature engine is integrated, combined with the SM3 hash algorithm to generate signature digests, ensuring the integrity and credibility of assessment records during storage and access. Digital signature and public key verification mechanisms are used to prevent data tampering and inconsistencies, ensuring the credibility and legal effectiveness of the forensic process. Different types of devices are automatically identified and adapted, and corresponding assessment strategies and tasks are selected according to the device type, improving identification efficiency and ensuring the accuracy and relevance of device security assessment. Attached Figure Description

[0029] Various other advantages and benefits will become apparent to those skilled in the art upon reading the following detailed description of preferred embodiments. The accompanying drawings are for illustrative purposes only and are not intended to limit the invention. Furthermore, the same reference numerals denote the same parts throughout the drawings. In the drawings:

[0030] Figure 1 Functional block diagram of the information security testing and forensics platform provided in the embodiments of the present invention;

[0031] Figure 2 System architecture diagram of the information security testing and forensics platform provided in this embodiment of the invention;

[0032] Figure 3 The multi-dimensional evaluation algorithm and automated verification flowchart of the information security testing and forensics platform provided in this embodiment of the invention;

[0033] Figure 4 A flowchart illustrating the generation process of the original configuration evidence chain for the information security testing and forensics platform provided in this embodiment of the invention;

[0034] Figure 5 The modular architecture and full protocol stack compatibility flowchart of the information security testing and forensics platform provided in the embodiments of the present invention. Detailed Implementation

[0035] Exemplary embodiments of the present disclosure will now be described in more detail with reference to the accompanying drawings. While exemplary embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure may be implemented in various forms and should not be limited to the embodiments set forth herein. Rather, these embodiments are provided to enable a more thorough understanding of the present disclosure and to fully convey its scope to those skilled in the art. It should be noted that, unless otherwise specified, embodiments and features described herein can be combined with each other. The present invention will now be described in detail with reference to the accompanying drawings and embodiments.

[0036] For this, please refer to Figure 1 As shown, an information security testing and forensics platform is proposed, including:

[0037] The graphical user interface module is used to collect project information, project type, equipment information, and task information. Project information is stored in a project information table in a relational database. The corresponding plugin configuration is dynamically loaded from the built-in plugin library based on the project information and project type. Equipment information is stored in an encrypted device information table.

[0038] A protocol simulation module is configured to implement remote device login, integrate an SSH protocol client library, an HTTP protocol client library, and a MySQL protocol client library; trigger plug-in selection logic according to project types and task information, filter matching built-in plug-ins from a built-in plug-in library, the built-in plug-ins including a predefined evaluation index set; and execute a multi-dimensional evaluation algorithm, the multi-dimensional evaluation algorithm including regular expression matching, keyword scanning, and configuration priority analysis.

[0039] A compliance rule judgment module is configured to have a built-in standard rule library, compare the parameter result set with standard clauses item by item, generate a quantitative evaluation result through Boolean logic operation, integrate an SM2 cryptographic algorithm signature engine, use a private key data packet to perform a signature operation, use an SM3 hash algorithm to generate a digest, and use an SM2 elliptic curve algorithm to calculate a signature value, store the signature value in a signature field of an evaluation record table, automatically trigger an integrity verification process when a user accesses the evaluation record, call a public key data packet to recalculate a data packet digest and compare the recalculated data packet digest with the stored signature value, and mark a data abnormal state when verification fails.

[0040] Specifically, the graphical user interface module: this module is used to collect project information, project type, device information and task information, all project information is stored in the project information table in the relational database. According to different project information and project type, this module can dynamically load the corresponding plug-in configuration in the built-in plug-in library, which facilitates flexible security assessment for different projects. At the same time, the device information is stored in the device information table after encryption processing, ensuring the security of the device information. Protocol simulation module: this module is used to realize the login of remote device, integrating a variety of protocol client libraries, including SSH protocol client library, HTTP protocol client library and MySQL protocol client library. According to the project type and task information, this module can trigger plug-in selection logic to filter out suitable plug-ins from the built-in plug-in library for dynamic loading. These plug-ins contain a set of pre-defined evaluation indicators, which can execute complex multi-dimensional evaluation algorithms, mainly including regular expression matching, keyword scanning and configuration priority parsing, etc. These algorithms help the system efficiently find security risks and ensure the accuracy of the evaluation results. Compliance rule judgment module: this module has a built-in standard rule library, which can compare evaluation parameters with standard clauses one by one, and use Boolean logic operations to generate quantitative evaluation results. Through comparison, it can determine whether the target system meets the requirements of relevant laws and regulations and industry standards. The module also integrates the SM2 password algorithm signature engine, which uses private key data packets for signature operation. In the signature process, the SM3 hash algorithm is used to generate data digest, and the SM2 elliptic curve algorithm is used to calculate the signature value. The signature value is stored in the signature field of the evaluation record table to ensure the integrity and credibility of the evaluation results. When the user accesses the evaluation record, the system will automatically trigger the integrity verification process, recalculate the digest of the data packet through the public key data packet, and compare it with the stored signature value. If the verification fails, the system will mark the data as abnormal state, ensuring that the data has not been tampered with in the storage and transmission process.

[0041] As a preferred embodiment, the scheme of the application is implemented as follows:

[0042] In practical applications, users input project information (such as project name, type, etc.) through a graphical interface and upload device information. The system stores these information in the project information table of the relational database, and also stores the device information in an encrypted manner. According to the type of the project (such as the equal protection evaluation), the system dynamically loads the plug-in configuration that matches the project from the built-in plug-in library. The system remotely logs into the target device through the integrated SSH protocol client library and MySQL protocol client library, and obtains relevant information. According to the project type and task information, the system automatically triggers the plug-in selection logic, filters out the plug-ins that meet the conditions from the built-in plug-in library, and executes the pre-defined evaluation index set, for example, checks the SSH configuration of the device and the security of the MySQL database. The system analyzes whether the configuration of the target device meets the security standard by executing multi-dimensional evaluation algorithms. These algorithms include regular expression matching, keyword scanning, and configuration priority parsing, etc., which further refine the inspection items, such as verifying the password strength, the port open state, etc., and generate an evaluation report according to the results. The evaluation results are compared with the equal protection requirements in the standard clause library one by one. Through Boolean logic operation, the system generates a quantitative evaluation result. For example, if it is detected that the SSH configuration of a certain device does not enable strong encryption algorithm, the system will be marked as non-compliant. All evaluation records will also be digitally signed through the SM2 algorithm to ensure the integrity and security of the evaluation results. When the user accesses the evaluation record, the system will automatically trigger the integrity verification process, recalculate the digest of the data packet through the public key data packet, and compare it with the stored signature value. If the signature value is found to be inconsistent, the system will mark the data as an abnormal state, ensuring that the evaluation data has not been tampered with.

[0043] Through the above scheme, project information is collected through the graphical user interface module, and matching plug-in configurations are automatically loaded according to the project type and task, which improves the efficiency of security evaluation and forensics and reduces the need for manual intervention. Through the built-in plug-in library, it supports dynamic loading and selection of plug-ins according to different project types, which can meet various security evaluation needs, such as equal protection evaluation, risk assessment, emergency response, etc. The compliance rule judgment module can automatically verify whether the target system meets the requirements of relevant laws, regulations and industry standards through comparison with the standard rule library. The SM2 cryptographic algorithm signature engine is integrated, and the digital signature mechanism is used to protect the integrity and non-tamperability of the data. The signature value is generated through the private key signature operation, and the integrity is verified through the public key, which ensures that the evaluation record has not been modified or tampered with during storage and transmission, thereby improving the data credibility.

[0044] The present application further proposes that the project type includes an equal protection evaluation type, a risk assessment type, a security operation type, and an emergency response type.

[0045] The equal protection evaluation type triggers the equal protection special plug-in set, the equal protection special plug-in set includes a security general requirement detection module and a cloud computing extension requirement detection module, and the detection module generates a secondary or tertiary evaluation report; the risk assessment type activates the risk quantification plug-in, the risk quantification plug-in executes three-stage processes of asset value evaluation, threat possibility calculation and vulnerability analysis; the security operation and maintenance type calls a periodic detection task template, the periodic detection task template presets a patrol frequency parameter and a baseline comparison rule; the emergency response type loads a rapid evidence collection plug-in, and the rapid evidence collection plug-in preferentially executes log collection, process snapshot and network connection state capture operations.

[0046] Specifically, when the equal protection evaluation type is selected, the system triggers the equal protection special plug-in set, which includes a security general requirement detection module and a cloud computing extension requirement detection module. The security general requirement detection module is used to check whether the infrastructure such as network equipment and servers meets the basic requirements of network security protection, covering firewall configuration, identity authentication and access control, etc. The cloud computing extension requirement detection module checks the security of the cloud platform, such as data encryption and security control of the virtualization environment. The detection results of these modules will generate a secondary or tertiary evaluation report, which will be evaluated in detail according to the specific security requirements, helping users understand the compliance of the system in network security. When the risk assessment type is selected, the system activates the risk quantification plug-in, which executes a three-stage process of asset value evaluation, threat possibility calculation and vulnerability analysis. The preset rules are: asset value evaluation: evaluate the business importance and value of various assets in the system, and preferentially identify critical assets. Threat possibility calculation: calculate the threat possibility against assets in combination with the current threat situation, and output potential risks. Vulnerability analysis: analyze whether the assets have vulnerabilities according to the system configuration and known vulnerability library. The system generates a detailed risk report according to these evaluations, helping enterprises identify high-risk areas and develop priority reinforcement measures. Under the security operation and maintenance type, the platform calls a periodic detection task template. The preset rules include: patrol frequency parameter: such as once a month, once a quarter, etc., and the user can customize the frequency according to the needs. Baseline comparison rule: the system automatically compares the configuration of the device with the known security baseline (such as operating system patch, network configuration, etc.), checks whether it meets the industry standard. Through automated detection, it ensures that the security configuration of the system always meets the specified standard, and timely discovers and repairs potential security risks. The emergency response type loads the rapid evidence collection plug-in, which preferentially executes log collection, process snapshot and network connection state capture operations. The preset rules of the rapid evidence collection plug-in include: log collection: preferentially collect system logs, application logs and security device logs for event traceability analysis. Process snapshot: capture process state, especially abnormal processes, and capture their memory data and execution commands. Network connection state capture: real-time acquisition of network connection state, checking whether there are abnormal external connections.

[0047] Through the technical solution, the corresponding plug-in is automatically selected and executed, the platform simplifies the security assessment process, reduces manual intervention, and improves efficiency. Through the automatic three-stage process, the risk assessment type project can accurately calculate the risk values of various assets, provide high-priority risk points, identify and respond to potential threats in the shortest time, and enhance the risk control capability.

[0048] The application further proposes that when the protocol simulation module integrates the SSH protocol client library, the HTTP protocol client library and the MySQL protocol client library, it includes:

[0049] The SSH protocol client library calls the SSH open source library of golang.org to realize the establishment of an encrypted channel and command interaction, the HTTP protocol client library constructs GET / POST request simulation user sessions based on the HTTP library of golang.org, and the MySQL protocol client library uses the MySQL library of gorm.io to execute database query operations. The login process adopts a multi-threaded scheduling mechanism to handle concurrent connection requests.

[0050] Specifically, the protocol simulation module plays a crucial role in simulating the communication methods of different protocols by integrating multiple protocol client libraries and conducting security testing and forensics on remote devices. This module integrates three main protocol client libraries: the SSH protocol client library, the HTTP protocol client library, and the MySQL protocol client library. Each library is integrated based on its specific functional requirements, providing the platform with flexible remote device management and data access capabilities. The SSH protocol client library integrates the golang.org open-source SSH library to implement remote login and command execution functions for the SSH protocol. The golang.org SSH library provides efficient and secure encrypted channels, ensuring that all communication data is protected by encryption to prevent data theft or tampering during transmission. Through this protocol, the platform can establish secure SSH connections with remote servers or network devices, execute commands, collect system logs, and obtain configuration files, etc. The platform can dynamically select appropriate commands and parameters based on different tasks to achieve in-depth inspection and operation of devices. This encrypted communication method is suitable for performing sensitive operations such as system configuration modification and vulnerability scanning, ensuring the security of operations. The HTTP protocol client library uses the golang.org HTTP library to simulate standard HTTP requests (including GET and POST requests) in order to test the security of web applications. The HTTP client library can simulate real user interactions with web applications, performing operations such as login, form submission, and page access, and detecting security vulnerabilities in web applications (such as SQL injection, XSS attacks, CSRF vulnerabilities, etc.). This function is particularly suitable for web security assessment, as the platform can deeply detect configuration and code vulnerabilities in web servers by simulating normal user behavior. With the help of the golang.org HTTP library, the platform can accurately simulate various attack scenarios by setting different HTTP header information, request parameters, and request methods, and comprehensively evaluate the security of web applications. MySQL protocol client library: The platform integrates the gorm.io MySQL library to connect to MySQL databases and perform SQL query operations. Through the MySQL protocol client, the platform can automatically perform database configuration audits, permission checks, and SQL injection tests, etc. The platform can use this library to check the security settings of databases, such as account permissions, table structure, and query logs, to assess whether the database has security risks. This function is crucial for security assessment at the database level, especially when performing SQL injection vulnerability detection, as it can automatically identify potential vulnerabilities and errors, providing protection for database security.

[0051] Through the technical solution, the client library integrating multiple protocols can support multiple types of devices and applications, ensuring that security testing and forensics can be performed in different environments. Whether it is a remote server, a web application or a database system, security assessment can be performed through a unified interface, improving the compatibility and scalability of the system.

[0052] The application further proposes that when the protocol simulation module executes a multi-dimensional evaluation algorithm, it includes:

[0053] The regular expression matching dynamically loads a regular rule set, which is stored in a regular rule section of a plug-in configuration file. Each regular rule section includes a matching pattern field, an extraction group index field, and an error threshold field. The keyword scanning uses a finite state automaton to achieve efficient matching. The finite state automaton is constructed based on the Aho-Corasick algorithm. A state transition table is generated by preprocessing a set of security keywords. During the scanning process, the line number and context fragments of the keywords are recorded in real time. The configuration priority parsing maintains a priority decision tree. The nodes of the priority decision tree include a configuration item path field, a priority value field, and a conflict resolution strategy field. A depth-first search is performed by traversing the decision tree. When multiple versions of data for the same configuration item are detected, the highest priority result is selected based on the priority value. If the priorities are the same, the merge rule in the conflict resolution strategy is applied.

[0054] Specifically, the regular expression matching dynamically loads a predefined regular rule set when performing security assessment. The rules are stored in the "regular rule section" of the plugin configuration file. Each rule section contains multiple fields, such as the matching pattern field, the extraction group index field, and the error threshold field. The matching pattern field defines the matching pattern of the regular expression, which is used to detect potential risks in the input data. For example, the platform can be used to detect SQL injection attacks, XSS attacks, or other common security vulnerabilities. The extraction group index field helps the platform extract specific data from the matching results, further analyzing the source of the risk. The error threshold field sets the maximum number of errors allowed during the matching process. Once the threshold is exceeded, the platform will mark the assessment result as abnormal, prompting the user to correct it. The keyword scanning uses the finite state automaton (FSM) technology combined with the Aho-Corasick algorithm to efficiently scan and match multiple security keywords. The Aho-Corasick algorithm pre-processes the security keyword set to generate a state transition table. During the scanning process, the FSM records the line number and context fragment of each keyword in real time, helping the platform accurately locate the problem. For example, when performing sensitive data leakage detection, the platform scans network traffic or log files to detect the presence of keywords such as "password" or "username", thereby quickly identifying potential leakage risks. The configuration priority resolution resolves multiple versions of configuration data by constructing a priority decision tree based on the configuration item's path, priority value, and conflict resolution strategy. Each node of the decision tree contains the configuration item's path field, priority value field, and conflict resolution strategy field. When the platform detects multiple versions of the same configuration item, it will sort them according to the priority value field and preferentially select the highest priority configuration for evaluation. If the priority of multiple configuration items is the same, the platform will merge the results according to the merging rules in the conflict resolution strategy to ensure the rationality and consistency of the final evaluation results.

[0055] Through the technical solution, the platform can adaptively update and execute detection rules according to different project types and task requirements by dynamically loading regular rule sets. Each rule segment contains a matching pattern, an extraction group index, and an error threshold, ensuring accurate capture of potential risks in different security assessment scenarios. This design effectively avoids human operation errors and rule update lags, improving the system's automated detection capabilities and reducing the error rate caused by human intervention. By using finite state automata (FSM) and Aho-Corasick algorithms, the platform can quickly and efficiently scan large amounts of data streams or log files to locate security vulnerabilities or sensitive information leaks in real time. The state transition table structure of this algorithm ensures fast response during the scanning process, while the function of recording the line number and context fragment of the keyword appearance provides accurate context for subsequent security analysis, helping security analysts quickly locate the problem source and improving problem discovery efficiency.

[0056] The application further proposes that when the protocol simulation module executes the multi-dimensional evaluation algorithm, it further includes:

[0057] The multi-dimensional evaluation algorithm further includes a parameter verification sub-module that performs type checking and range verification on the extracted parameter results. For password complexity parameters, a character set analyzer is called to detect the proportion of special characters, and for port opening parameters, a port range legality verification is performed.

[0058] Specifically, the parameter verification submodule mainly functions to ensure that the extracted parameters meet the preset standards and rules, further improving the accuracy and security of the evaluation results. The parameter verification submodule performs the following functions: type checking and range verification: for each parameter extracted from the system, the submodule first checks whether its data type is consistent with the expected type. For example, a numerical type parameter will not be misjudged as a string type; a date type parameter meets the date format requirements. In addition to type checking, the value of the parameter is also compared with the preset valid range to ensure that it meets the system security requirements. For example, the port number parameter is verified whether it is within the valid port range. Password complexity detection: for parameters related to password settings in the system, the platform calls a character set analyzer to evaluate the complexity of the password. The analyzer checks whether the password contains special characters and calculates the proportion of special characters in the total number of characters to evaluate whether the password meets the security requirements. In this way, the existence of weak passwords can be effectively prevented, thereby improving the security of the system and avoiding security vulnerabilities caused by improper password settings. Port opening legality verification: for the open port parameters in the system, the parameter verification submodule performs port range legality verification to ensure that the open port meets the industry standards and security regulations. For example, the platform checks whether the system has inadvertently opened a port that should not be public or whether the port number is within the legal range. This verification can effectively prevent port leakage or unnecessary port exposure, reducing the potential risk of network attacks.

[0059] Through the above technical solutions, by checking the type and range of the extracted parameters, the platform can effectively avoid parameter format errors or non-compliance with predetermined standards. The parameter verification submodule can identify and correct in advance, thereby ensuring the accuracy and consistency of the evaluation process. By calling the character set analyzer to detect password complexity, the system can perform real-time evaluation of password security, especially the proportion of special characters. This process helps to improve the system's ability to identify password weaknesses, ensuring that only passwords that meet high security standards can pass, thereby effectively reducing the risk of security vulnerabilities caused by weak passwords and improving the system's resistance to attacks.

[0060] The present application further proposes that the compliance rule judgment module has a built-in standard rule library, including:

[0061] The standard rule library is a structured storage of security standard clauses, including a network security protection requirement item table and a risk assessment item table. The network security protection requirement item table defines a control item field, a requirement content field, and a detection method field, and the detection method field is associated with specific evaluation indicators. The risk assessment item table defines an asset type field, a threat scenario field, and a risk calculation formula field. In the comparison process, a structured storage security standard clause mapping operation is performed to logically match the configuration parameters in the parameter result set with the detection conditions of the structured storage security standard clauses.

[0062] Specifically, the compliance rule judgment module realizes the automatic evaluation and quantitative analysis of the system security state through the built-in standard rule library. The standard rule library adopts a structured storage method to refine the security standard clauses into executable data tables, including the item table of the requirement of the network security protection and the item table of the risk assessment. In the item table of the requirement of the network security protection, each control item is defined as a control item field, a requirement content field and a detection method field, and the detection method field is associated with a specific evaluation index, so that the system can automatically perform the corresponding detection operation according to the clause content. The item table of the risk assessment defines an asset type field, a threat scenario field and a risk calculation formula field, and through the quantitative calculation of the threat possibility and potential loss of different assets, scientific risk assessment is realized. In the comparison process, the platform will logically match the extracted parameter result set with the clauses in the standard rule library. Through the execution of the structured storage security standard clause mapping operation, the system can automatically map the parameter data to the corresponding detection condition, so as to judge whether it meets the security requirements and generate accurate quantitative evaluation results.

[0063] Through the above technical solution, the control item, the detection method and the evaluation index are directly associated, the detection operation of each security clause can be accurately performed, and the omission or error caused by manual judgment is avoided. In the item table of the risk assessment, the asset type, the threat scenario and the risk calculation formula are used to realize scientific quantification, so that the security evaluation result can be directly used for decision support, and high-risk assets and potential threats can be easily found.

[0064] The application further proposes that the plug-in management module further comprises a plug-in management module;

[0065] The plug-in management module provides an external plug-in extension interface, the external plug-in extension interface adopts the RESTful API specification, sets a plug-in uploading endpoint, a plug-in query endpoint and a plug-in activation endpoint; the plug-in metadata is maintained through a plug-in registry, and the plug-in metadata includes a plug-in identification field, a device type field, a version number field, an author information field and a creation timestamp field.

[0066] Specifically, the plug-in management module is responsible for providing the extension and flexibility of the system function. The module realizes seamless connection with third-party or custom plug-ins through the external plug-in extension interface, the interface is designed by adopting the RESTful API specification, sets the plug-in uploading endpoint, the query endpoint and the activation endpoint, so that the user can conveniently upload new plug-ins, query existing plug-in information and activate the required plug-ins to participate in the security evaluation task. In order to efficiently manage the plug-ins, the platform maintains the metadata of all plug-ins through the plug-in registry. Each metadata record includes the plug-in identification, the device type, the version number, the author information and the creation timestamp, etc. fields, which ensures that the platform can accurately identify and track the source, version and scope of each plug-in.

[0067] By introducing the plug-in management module and its external expansion interface, the information security testing and forensics platform has significantly improved in terms of functional expansion and flexibility. By using the RESTful API specification plug-in upload, query, and activation endpoints, users can quickly integrate new plug-ins or update existing plug-ins, supporting different types of devices and diverse security tasks.

[0068] By centrally managing plug-in metadata through the plug-in registry, the system's scalability and maintainability are improved, ensuring that security assessment tasks can call the latest or most appropriate plug-ins instantly, reducing manual management burden, enhancing overall assessment efficiency, and reducing security risks caused by improper plug-in management.

[0069] The application further provides that when the plug-in management module provides an external plug-in expansion interface, it includes:

[0070] The plug-in management module receives a user-uploaded Excel template file, which follows a predefined structure specification and includes a project type worksheet, a task level worksheet, an evaluation standard set worksheet, an evaluation command set worksheet, and a note information worksheet. The Excel parsing engine is called to process the uploaded file, which is implemented based on the excelize library from github.com. The cell data is read row by row, where the project type worksheet parses the enumeration value list of project types, the task level worksheet parses the level value mapping table, the evaluation standard set worksheet extracts the association matrix of standard clauses and detection items, and the evaluation command set worksheet converts command strings into executable instruction sequences.

[0071] Specifically, the plug-in management module provides an external plug-in expansion interface, allowing users to easily upload custom plug-in configurations. The module supports receiving Excel template files that follow a predefined structure specification, which includes a project type worksheet, a task level worksheet, an evaluation standard set worksheet, an evaluation command set worksheet, and a note information worksheet. After uploading, the platform calls the Excel parsing engine based on the excelize library from github.com to read and parse the cell data in each worksheet row by row. The project type worksheet parses the enumeration value list of project types, the task level worksheet parses the level value mapping relationship, the evaluation standard set worksheet extracts the corresponding matrix of standard clauses and detection items, and the evaluation command set worksheet converts command strings into executable instruction sequences, thereby automatically generating and configuring the plug-in. This design makes the plug-in creation process more standardized and automated, reduces manual configuration errors, improves the accuracy and execution efficiency of the plug-in in security assessment tasks, and ensures that the platform can quickly adapt to different project types and evaluation requirements.

[0072] The information security testing and forensics platform supports uploading Excel template files and automatic parsing through the plug-in management module, and realizes high automation and standardization of plug-in configuration. The platform can parse project types, task levels, evaluation standards and command sets according to pre-defined structure specifications, directly convert data in Excel into executable plug-in configurations and instruction sequences, thereby avoiding errors and inconsistencies in manual configuration.

[0073] The plug-in management module further provides an external plug-in extension interface, which includes:

[0074] When the plug-in management module performs the plug-in generation operation, it encapsulates the parsed data into a plug-in configuration object, which includes device type identification, evaluation index list and command execution strategy. The plug-in management module automatically creates a plug-in storage directory, serializes the plug-in configuration object into a JSON format configuration file, and generates a corresponding Golang execution script framework. After generating a new plug-in, the plug-in management module updates the plug-in registry, inserts the metadata record of the new plug-in, and triggers the plug-in index reconstruction process to ensure that the new plug-in is immediately visible in the task creation interface. The module also sets template verification rules to perform format verification on Excel files, including worksheet name verification, missing required field detection and data type consistency check. If the verification fails, a structured error code is returned.

[0075] Specifically, the plug-in management module ensures the automated creation and management of plug-in configurations by performing plug-in generation operations. When the plug-in generation operation is triggered, the plug-in management module encapsulates the parsed data into a plug-in configuration object, which includes device type identification, evaluation index list and command execution strategy. These configurations are then serialized into JSON format for easy storage and transmission, while generating corresponding Golang execution script frameworks to support actual evaluation task execution. After generating a new plug-in, the plug-in management module automatically updates the plug-in registry, inserts the metadata record of the new plug-in, and triggers the plug-in index reconstruction process to ensure that the new plug-in can be immediately displayed to users in the task creation interface, thereby improving the system's response speed and plug-in visibility. To ensure the correctness and standardization of plug-in data, the module also sets template verification rules to comprehensively check the format of uploaded Excel files, including worksheet name verification, missing required field detection and data type consistency check. If the verification fails, the system will return a structured error code to help users quickly locate and solve the problem, thereby ensuring the accuracy of plug-in configuration and the stability of the platform.

[0076] Through the above technical solution, the plug-in management module provides an external plug-in extension interface, realizes the automatic generation and management of plug-ins, and improves the flexibility and scalability of the system.

[0077] The application further proposes to include compatible full protocol stack device types, the full protocol stack device types including a network device subset, a security device subset, a server subset, a middleware subset and a database subset; the network device subset covers switch devices and router devices, the switch devices call an SNMP protocol module to perform VLAN configuration detection, and the router devices use an SSH or Telnet protocol module to obtain routing table information; the security device subset covers firewall devices, intrusion detection system devices and intrusion prevention system devices, the firewall devices perform access control list analysis, and the intrusion detection system devices call a log analysis interface; the server subset covers Windows servers and Linux servers, the Windows servers use a WMI protocol to query registry entries, and the Linux servers execute sysctl commands through SSH to obtain kernel parameters; the middleware subset covers WebLogic middleware and Nginx middleware, the system analyzes domain configuration files for the WebLogic middleware and checks server block configuration instructions for the Nginx middleware; the database subset covers MySQL databases and Oracle databases, the MySQL databases execute a SHOW VARIABLES command, and the Oracle databases call a data dictionary view query; a device type fingerprint library is maintained, the fingerprint library stores a device characteristic identifier set, including port opening modes, service Banner strings and protocol response characteristics, and is used for device type automatic identification.

[0078] Specifically, the compatible full protocol stack device type covers multiple device subsets, including a network device subset, a security device subset, a server subset, a middleware subset, and a database subset, each having specific detection modules and protocol support to meet the security assessment needs in different environments. In terms of the network device subset, the system supports detailed security checks on switch and router devices. For switch devices, the system performs VLAN configuration detection through the SNMP protocol module to ensure the secure isolation of virtual local area networks. For router devices, the system uses the Telnet protocol module to obtain routing table information to check the integrity and correctness of network routing configurations. In terms of the security device subset, the system can comprehensively check firewall devices, intrusion detection system (IDS) devices, and intrusion prevention system (IPS) devices. The system identifies potential network security risks through firewall device access control list (ACL) parsing and uses IDS device log analysis interfaces to detect and analyze possible attack behaviors in real time. For the server subset, the system supports security assessment of Windows servers and Linux servers. Windows servers query registry entries through the WMI protocol to check the security of operating system configurations, and Linux servers execute sysctl commands through the SSH protocol to obtain kernel parameters and ensure the security of operating systems. WebLogic and Nginx middleware in the middleware subset are also included in the detection range. The system parses domain configuration files for WebLogic middleware to ensure that the middleware configuration has no vulnerabilities, and for Nginx middleware, the system checks server block configuration instructions to ensure that their security settings comply with best practices. The database subset includes MySQL and Oracle databases, and the system checks MySQL database configuration information through the SHOW VARIABLES command, and queries Oracle database data dictionary views to ensure that database configurations meet security requirements.

[0079] Through the above technical solution, by compatible full protocol stack device type, the types of supported devices are effectively expanded, covering network devices, security devices, servers, middleware, and databases, and other multiple subsets. This extensive compatibility enables the system to perform comprehensive security assessment and forensics in complex and diverse network environments. Through the support of various device-specific protocol modules, security detection of different device types can be flexibly performed.

[0080] In summary, by integrating multiple protocol client libraries and plugin mechanisms, the platform can automatically perform various network security assessment tasks, reducing the need for manual intervention and improving the efficiency of security assessment and forensics. The platform supports flexible plugin extension, allowing dynamic loading and execution of corresponding plugin sets based on different project types, enhancing the adaptability and scalability of the platform. By integrating multiple common protocol client libraries, the platform supports remote login and configuration detection for various network devices, enabling comprehensive security detection for different types of devices and enhancing adaptability in complex network environments. The built-in standard rule library, combined with structured storage and logical mapping, can automatically compare assessment results with security standards item by item, generating quantitative assessment reports in real time. Through automated compliance verification, human error and execution omissions are reduced. The integrated SM2 cryptographic algorithm signature engine, combined with the SM3 hash algorithm, generates signature digests, ensuring the integrity and credibility of assessment records during storage and access. The use of digital signatures and public key verification mechanisms prevents data tampering and inconsistencies, ensuring the credibility and legal effectiveness of the forensic process. The platform automatically identifies and adapts to different types of devices and selects appropriate assessment strategies and tasks based on device type, improving identification efficiency and ensuring the accuracy and relevance of device security assessment.

[0081] Those skilled in the art will appreciate that embodiments of the application can be provided as methods, systems or computer program products. Accordingly, the application can be embodied in the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the application can be embodied in the form of a computer program product on one or more computer-usable storage media (including, but not limited to, disk memory, CD-ROMs, optical storage media, etc.) having computer usable program code embodied therein.

[0082] The application is described with reference to the flowcharts and / or block diagrams of the methods, apparatus (systems) and computer program products according to embodiments of the application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams can be implemented by computer program instructions, and the combination of flows and / or blocks in the flowcharts and / or block diagrams. These computer program instructions can be provided to a general-purpose computer, a special-purpose computer, an embedded processor or other programmable data processing apparatus to produce a machine, so that the instructions executed by the computer or other programmable data processing apparatus produce a device that implements the functions specified in the flowcharts and / or block diagrams. Figure 1 The functions specified in one or more flows and / or blocks. Figure 1 The device that implements the functions specified in one or more flows and / or blocks.

[0083] These computer program instructions can also be stored in a computer readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer readable memory produce an article of manufacture including instructions which implement the flow Figure 1 one or more flows and / or blocks Figure 1 one or more blocks or multiple blocks.

[0084] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the flow Figure 1 one or more flows and / or blocks Figure 1 one or more blocks or multiple blocks.

[0085] Finally, it should be noted that the above-mentioned embodiments are merely used to illustrate the technical solutions of the present application, rather than limiting the same. Even though the present application has been described in detail with reference to the above-mentioned embodiments, those skilled in the art should understand that the specific embodiments of the present application can be modified or replaced equivalently, and any modification or replacement without departing from the spirit and scope of the present application should be covered within the protection scope of the claims of the present application.

Claims

1. An information security testing and forensics platform, characterized by, Comprise: A graphical user interface module for collecting project information, project type, device information and task information, the project information being stored in a project information table of a relational database; According to the project information and project type, corresponding plug-in configurations are dynamically loaded from a built-in plug-in library; the device information is stored in a device information table after encryption; A protocol simulation module for realizing remote device login, integrating an SSH protocol client library, an HTTP protocol client library and a MySQL protocol client library; according to the project type and task information, plug-in selection logic is triggered to screen matching built-in plug-ins from the built-in plug-in library, the built-in plug-ins including a predefined evaluation index set; a multi-dimensional evaluation algorithm is executed, the multi-dimensional evaluation algorithm including regular expression matching, keyword scanning and configuration priority analysis; A compliance rule judgment module with a built-in standard rule library for comparing a parameter result set with standard clauses item by item to generate a quantitative evaluation result through Boolean logic operation; the parameter result set includes password strength and port open state; when at least one item in the parameter result set is detected to be inconsistent with the standard clauses, it is marked as non-compliant; an SM2 cryptographic algorithm signature engine is integrated, the SM2 cryptographic algorithm signature engine performs a signature operation using a private key data packet, the signature operation generates a digest using an SM3 hash algorithm and calculates a signature value through an SM2 elliptic curve algorithm, the signature operation is used to sign the evaluation result; the signature value is stored in a signature field of an evaluation record table; the evaluation record table is used to store the quantitative evaluation result with the signature value; when a user accesses the evaluation record, an integrity verification process is automatically triggered, the integrity verification process recalculates a data packet digest using a public key data packet and compares it with the stored signature value, and marks the data as an abnormal state when the verification fails; when the signature value is found to be inconsistent with the data packet digest, the data is marked as an abnormal state.

2. The information security testing and forensics platform of claim 1, wherein, The project type includes a CIPR evaluation type, a risk assessment type, a security operation and maintenance type and an emergency response type; The CIPR evaluation type is used to make the protocol simulation module trigger a CIPR dedicated plug-in set, the CIPR dedicated plug-in set including a security general requirement detection module and a cloud computing extension requirement detection module, the detection modules generating a two-level or three-level evaluation report; the risk assessment type is used to make the protocol simulation module activate a risk quantification plug-in, the risk quantification plug-in executing a three-stage process of asset value evaluation, threat possibility calculation and vulnerability analysis; The security operation and maintenance type is used to make the protocol simulation module call a periodic detection task template, the periodic detection task template presetting a patrol frequency parameter and a baseline comparison rule; the emergency response type is used to make the protocol simulation module load a rapid evidence collection plug-in, the rapid evidence collection plug-in preferentially executing log collection, process snapshot and network connection state capture operations.

3. The information security testing and forensics platform of claim 2, wherein, When the protocol simulation module integrates the SSH protocol client library, the HTTP protocol client library and the MySQL protocol client library, it comprises: The SSH protocol client library calls the SSH open source library of golang.org to implement the encryption channel establishment and command interaction, the HTTP protocol client library constructs GET / POST request to simulate user session based on the HTTP library of golang.org, and the MySQL protocol client library uses the MySQL library of gorm.io to execute database query operations, and the login process adopts a multi-threaded scheduling mechanism to process concurrent connection requests.

4. The information security testing and forensics platform of claim 3, wherein, When the protocol simulation module executes the multi-dimensional evaluation algorithm, the following steps are included: The regular expression matching dynamically loads a regular rule set, the regular rule set is stored in a regular rule section of a plug-in configuration file, each regular rule section includes a matching mode field, an extraction group index field and an error threshold field; the keyword scanning adopts a finite state automaton to realize efficient matching, the finite state automaton is constructed based on the Aho-Corasick algorithm, a state transition table is generated by preprocessing a set of security keywords, and the keyword appearance line number and context fragments are recorded in real time during the scanning process; the configuration priority analysis maintains a priority decision tree, a node of the priority decision tree includes a configuration item path field, a priority value field and a conflict resolution strategy field, a depth-first search is performed by traversing the decision tree, when multiple versions of data of the same configuration item are detected, the highest priority result is selected according to the priority value, and if the priority is the same, the merging rule in the conflict resolution strategy is applied.

5. The information security testing and forensics platform of claim 4, wherein, When the protocol simulation module executes the multi-dimensional evaluation algorithm, the following steps are included: The multi-dimensional evaluation algorithm further includes a parameter verification submodule, the parameter verification submodule performs type checking and range verification on the extracted parameter results, calls a character set analyzer to detect the proportion of special characters for the password complexity parameter, and performs port range legality verification for the port opening parameter.

6. The information security testing and forensics platform of claim 5, wherein, The compliance rule judgment module has a built-in standard rule library, including: The standard rule library is a structured storage security standard clause, including a network security protection requirement item table and a risk assessment item table, the network security protection requirement item table defines a control item field, a requirement content field and a detection method field, and the detection method field is associated with a specific evaluation index; the risk assessment item table defines an asset type field, a threat scenario field and a risk calculation formula field; in the comparison process, the structured storage security standard clause mapping operation is performed, and the configuration parameters in the parameter result set are logically matched with the detection conditions of the structured storage security standard clause.

7. The information security testing and forensics platform of claim 6, wherein, Further including a plug-in management module; The plug-in management module provides an external plug-in extension interface, the external plug-in extension interface adopts the RESTful API specification, and sets a plug-in upload endpoint, a plug-in query endpoint and a plug-in activation endpoint; Plug-in metadata is maintained through a plug-in registry, and the plug-in metadata includes a plug-in identification field, a device type field, a version number field, an author information field and a creation timestamp field.

8. The information security testing and forensics platform of claim 7, wherein, When the plug-in management module provides the external plug-in extension interface, the following steps are included: The plug-in management module receives a user-uploaded Excel template file, the Excel template file complies with a predefined structure specification, contains a project type worksheet, a task level worksheet, an evaluation standard set worksheet, an evaluation command set worksheet, and a note information worksheet; calls an Excel parsing engine to process the uploaded file, the Excel parsing engine is implemented based on the excelize library of github.com, reads cell data by worksheet, wherein the project type worksheet parses a project type enumeration value list, the task level worksheet parses a level value mapping table, the evaluation standard set worksheet extracts a standard clause and a detection item association matrix, and the evaluation command set worksheet converts a command string into an executable instruction sequence.

9. The information security testing and forensics platform of claim 8, wherein, When the plug-in management module provides an external plug-in extension interface, it further includes: When the plug-in management module performs plug-in generation operations, it encapsulates the parsed data into a plug-in configuration object, the plug-in configuration object contains a device type identifier, an evaluation index list, and a command execution strategy; automatically creates a plug-in storage directory, serializes the plug-in configuration object into a JSON format configuration file, and generates a corresponding Golang execution script framework; the plug-in management module updates the plug-in registry after generating a new plug-in, inserts the metadata record of the new plug-in, and triggers a plug-in index reconstruction process to ensure that the new plug-in is immediately visible in the task creation interface; it also sets template verification rules, performs format verification on the Excel file, including worksheet name verification, missing required field detection, and data type consistency check, and returns a structured error code when verification fails.

10. The information security testing and forensics platform of claim 9, wherein, It includes compatible full protocol stack device types, including a network device subset, a security device subset, a server subset, a middleware subset, and a database subset; the network device subset covers switch devices and router devices, calls an SNMP protocol module to perform VLAN configuration detection for switch devices, and uses an SSH or Telnet protocol module to obtain routing table information for router devices; the security device subset covers firewall devices, intrusion detection system devices, and intrusion prevention system devices, performs access control list parsing for firewall devices, calls a log analysis interface for intrusion detection system devices; The server subset covers Windows servers and Linux servers, the Windows servers are queried by using a WMI protocol to register a registry item, and the Linux servers are queried by executing a sysctl command through SSH to obtain kernel parameters; the middleware subset covers WebLogic middleware and Nginx middleware, the system parses a domain configuration file for the WebLogic middleware, and checks a server block configuration instruction for the Nginx middleware; the database subset covers MySQL databases and Oracle databases, a SHOWVARIABLES command is executed for the MySQL databases, and a data dictionary view is called for the Oracle databases to query; a device type fingerprint library is maintained, the fingerprint library stores a device feature identifier set, including a port opening mode, a service Banner string and a protocol response feature, and is used for automatic identification of device types.

Citation Information

Patent Citations

  • Communication information security risk early warning management and control method and system based on big data

    CN117955712A

  • Data security capability detection method and system

    CN118427843A