Network equipment detection method and device and electronic equipment

By obtaining identity identifiers through port scanning, grouping devices based on their characteristics, and matching them with targeted password sets, the problem of low efficiency and insufficient accuracy in detecting network devices in large enterprises is solved, and efficient weak password detection is achieved.

CN120979749APending Publication Date: 2025-11-18CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511195430.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-25
Publication Date
2025-11-18

AI Technical Summary

Technical Problem

Weak password detection on internal network devices in large enterprises is inefficient and inaccurate. Conventional methods are time-consuming and cannot effectively improve detection efficiency and accuracy.

Method used

By scanning network device ports to obtain identity identifiers, grouping them according to device characteristics, and matching each group with a specific set of passwords, attempts with irrelevant account-password combinations are reduced, and login is performed using account-password combinations that match device characteristics.

Benefits of technology

Significantly shortens detection time, improves the efficiency and accuracy of weak password detection, and enhances the efficiency of network security maintenance for large enterprises.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120979749A_ABST
    Figure CN120979749A_ABST
Patent Text Reader

Abstract

The invention provides a network equipment detection method and device and electronic equipment, and relates to the technical field of network security. The network device detection method comprises the following steps: scanning a plurality of target network devices to be detected to obtain a port of each target network device, and detecting the target network devices through the ports to obtain identity labels of the target network devices; determining device characteristics of the target network devices according to the identity labels, and dividing the plurality of target network devices into a plurality of groups according to the device characteristics; determining a password set corresponding to each group of target network equipment according to the equipment characteristics, wherein the password set comprises a plurality of account-password combinations; logging in one group of target network equipment by using the account-password combination in the password set corresponding to the target network equipment; and marking the target network equipment which can be logged in through any account-password combination as security risk equipment. According to the embodiment of the invention, the network security detection efficiency can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of network security technology, and more specifically, to a method, apparatus, and electronic device for detecting network devices. Background Technology

[0002] Currently, weak password detection on internal network devices to identify vulnerabilities in enterprise network security defenses is a crucial daily task. However, due to the large number of network devices, systems, and services within large enterprises, the conventional method of traversing all network devices using common weak passwords (username-password combinations) is often time-consuming and inefficient. Therefore, a solution is needed that can simultaneously improve the efficiency and accuracy of weak password detection.

[0003] It should be noted that the information disclosed in the background section above is only used to enhance the understanding of the background of this disclosure, and therefore may include information that does not constitute prior art known to those skilled in the art. Summary of the Invention

[0004] The purpose of this disclosure is to provide a network device detection method, apparatus, and electronic device to simultaneously improve the efficiency and accuracy of weak password detection.

[0005] According to a first aspect of the present disclosure, a network device detection method is provided, comprising: scanning a plurality of target network devices to be detected to obtain ports of each target network device; probing the target network devices through the ports to obtain the identity identifiers of the target network devices; determining device characteristics of the target network devices based on the identity identifiers; dividing the plurality of target network devices into multiple groups based on the device characteristics; determining a password set corresponding to each group of target network devices based on the device characteristics, the password set including multiple username-password combinations; logging into a group of target network devices using username-password combinations from the corresponding password set; and marking target network devices that can be logged into using any of the username-password combinations as security risk devices.

[0006] According to a second aspect of the present disclosure, a network device detection apparatus is provided, comprising:

[0007] The device scanning module is configured to scan multiple target network devices to be detected to obtain the ports of each target network device, and to detect the target network device through the ports to obtain the identity of the target network device.

[0008] The device grouping module is configured to determine the device characteristics of the target network device based on the identity identifier, and divide the multiple target network devices into multiple groups based on the device characteristics;

[0009] The password set matching module is configured to determine the password set corresponding to each group of target network devices based on the device characteristics, wherein the password set includes multiple account-password combinations;

[0010] The group testing module is configured to log in to a group of the target network devices using username-password combinations from their corresponding password sets.

[0011] The result marking module is configured to mark the target network device that can be logged in using any of the aforementioned account-password combinations as a security risk device.

[0012] According to a third aspect of this disclosure, an electronic device is provided, comprising: a memory; and a processor coupled to the memory, the processor being configured to perform the method as described in any of the preceding methods based on instructions stored in the memory.

[0013] According to a fourth aspect of this disclosure, a computer-readable storage medium is provided having a program stored thereon that, when executed by a processor, implements the network device detection method as described in any of the preceding claims.

[0014] According to a fifth aspect of this disclosure, a computer program product is provided, comprising a computer program, characterized in that, when executed by a processor, the computer program implements the steps of the method as described in any of the preceding claims.

[0015] This disclosure avoids indiscriminate detection of a large number of assets by first scanning ports to obtain identity identifiers and then grouping them according to device characteristics. Simultaneously, it matches a targeted password set for each group of target network devices, reducing attempts at irrelevant account-password combinations, significantly shortening detection time, and improving weak password detection efficiency. Furthermore, account-password combinations matching the device characteristics of the target network device improve the accuracy of weak password detection. Therefore, this disclosure effectively solves the problems of low efficiency and low accuracy in routine weak password detection of network devices in large enterprises, improving the efficiency of internal network security maintenance within large enterprises.

[0016] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and are not intended to limit this disclosure. Attached Figure Description

[0017] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this disclosure and, together with the description, serve to explain the principles of this disclosure. It is obvious that the drawings described below are merely some embodiments of this disclosure, and those skilled in the art can obtain other drawings based on these drawings without any inventive effort.

[0018] Figure 1 This is a flowchart of a network device detection method in an exemplary embodiment of this disclosure.

[0019] Figure 2 This is a sub-flowchart of step S3 in an exemplary embodiment of this disclosure.

[0020] Figure 3 This is a flowchart of forming a derived password in an exemplary embodiment of this disclosure.

[0021] Figure 4 This is a sub-flowchart of step S4 in an exemplary embodiment of this disclosure.

[0022] Figure 5 This is a schematic diagram of an application scenario in an exemplary embodiment of this disclosure.

[0023] Figure 6 This is a block diagram of a network device detection apparatus according to an exemplary embodiment of the present disclosure.

[0024] Figure 7 This is a block diagram of an electronic device according to an exemplary embodiment of the present disclosure. Detailed Implementation

[0025] Example embodiments will now be described more fully with reference to the accompanying drawings. However, example embodiments can be implemented in many forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided to make this disclosure more comprehensive and complete, and to fully convey the concept of the example embodiments to those skilled in the art. The described features, structures, or characteristics can be combined in any suitable manner in one or more embodiments. In the following description, numerous specific details are provided to give a full understanding of embodiments of this disclosure. However, those skilled in the art will recognize that the technical solutions of this disclosure can be practiced with one or more of the specific details omitted, or other methods, components, apparatus, steps, etc., can be employed. In other instances, well-known technical solutions are not shown or described in detail to avoid obscuring various aspects of this disclosure.

[0026] Furthermore, the accompanying drawings are merely illustrative of this disclosure, and the same reference numerals in the drawings denote the same or similar parts, thus repeated descriptions of them will be omitted. Some block diagrams shown in the drawings are functional entities and do not necessarily correspond to physically or logically independent entities. These functional entities may be implemented in software, in one or more hardware modules or integrated circuits, or in different network and / or processor devices and / or microcontroller devices.

[0027] The exemplary embodiments of this disclosure will now be described in detail with reference to the accompanying drawings.

[0028] Figure 1 This is a flowchart of a network device detection method in an exemplary embodiment of this disclosure.

[0029] refer to Figure 1 The network device testing method 100 may include:

[0030] Step S1: Scan multiple target network devices to be detected to obtain the ports of each target network device, and probe the target network device through the ports to obtain the identity of the target network device;

[0031] Step S2: Determine the device characteristics of the target network device based on the identity identifier, and divide the multiple target network devices into multiple groups based on the device characteristics;

[0032] Step S3: Determine the password set corresponding to each group of target network devices based on the device characteristics. The password set includes multiple account-password combinations.

[0033] Step S4: Log in to a group of target network devices using the username-password combination from their corresponding password set;

[0034] Step S5: Mark the target network device that can be logged in using any of the account-password combinations as a security risk device.

[0035] This disclosure avoids indiscriminate detection of a large number of assets by first scanning ports to obtain identity identifiers and then grouping them according to device characteristics. Simultaneously, it matches a targeted password set for each group of target network devices, reducing attempts at irrelevant account-password combinations, significantly shortening detection time, and improving weak password detection efficiency. Furthermore, account-password combinations matching the device characteristics of the target network device improve the accuracy of weak password detection. Therefore, this disclosure effectively solves the problems of low efficiency and low accuracy in routine weak password detection of network devices in large enterprises, improving the efficiency of internal network security maintenance within large enterprises.

[0036] The following is a detailed explanation of each step in the network device testing method 100.

[0037] In step S1, multiple target network devices to be detected are scanned to obtain the ports of each target network device, and the target network devices are probed through the ports to obtain the identity of the target network devices.

[0038] In this embodiment of the disclosure, the target network device to be tested can be one or more network devices within an enterprise that are under the supervision of the operation and maintenance personnel (such as various network devices deployed in the headquarters and branches), or network devices within a local area network that is entrusted for testing (such as devices in a campus LAN, park LAN, or dedicated LAN of a government or enterprise department). It may also include cloud server nodes associated with the enterprise, terminal devices for remote office access, etc. As long as they belong to network assets that need to be investigated for weak password risks, this testing method is applicable.

[0039] In an exemplary embodiment, the types of target network devices include, but are not limited to, switches, routers, web servers, database servers, FT servers, SSH servers, Telnet servers, remote desktop (RDP) terminals, network storage devices (NAS), IoT gateway devices, industrial control devices (PLCs), and virtualization platform hosts. Any network device widely distributed within an enterprise's internal network architecture that may become a security vulnerability due to weak passwords falls under the core detection object of this method, i.e., the target network device.

[0040] In an exemplary embodiment, in step S1, a port scanning tool (such as a TCPSYN-based scan or a full connection scan) can be used to scan common port types of the target network device (e.g., port 21 (FTP service), port 22 (SSH service), port 23 (Telnet service), port 80 (HTTP service), port 443 (HTTPS service), port 3389 (Remote Desktop service), port 5900 (VNC service), port 1433 (SQL Server database service), port 3306 (MySQL database service)) to determine the open ports of each target network device that can be used for login.

[0041] Then, for each open port, a protocol probe packet (such as an SSH protocol version probe packet or an HTTP protocol GET request) is sent, and the response data returned by the device is received. The identification information is extracted from the response data. For example, the banner information returned by the SSH service may contain "Huawei Router SSHv2.0", and the response header or page title of the HTTP service may contain "Nacos Console V2.1.0". In this way, the device brand, system name, service type and version information are obtained.

[0042] In addition to using port scanning tools to scan ports and obtain the identity of target network devices, this embodiment of the disclosure can also capture broadcast packets and multicast packets (such as DHCP request frames and LLDP protocol frames) sent by the target network device through network traffic analysis, and extract the device model, manufacturer OUI, system version, and other identity identifiers of the target network device from these data packets. Furthermore, if it is determined that the target network device has SNMP service enabled, its sysDescr, sysName, and other fields can be queried through the SNMP protocol to directly obtain information such as manufacturer and model. Alternatively, the first 24 bits of the target network device's MAC address (manufacturer OUI) can be parsed and matched against an OUI database to determine the device brand. For devices with a web management interface, the device identity can also be identified by accessing the login page, parsing the page source code, icon hash values, or title information, and combining this with a feature database. Additionally, ICMP requests can be sent and the TTL value and operating system characteristics of the response messages can be analyzed to obtain device type-related identity identifiers. The above methods can be used individually or in combination to improve the comprehensiveness and accuracy of identity identifier acquisition.

[0043] In step S2, the device characteristics of the target network device are determined based on the identity identifier, and the multiple target network devices are divided into multiple groups based on the device characteristics.

[0044] In an exemplary embodiment, the identity identifier includes at least one of device brand, system name, service type, and version information. In step S2, determining the device characteristics of the target network device based on the identity identifier includes: determining the device brand, product series, and device type of the target network device based on at least one of device brand, system name, service type, and version information.

[0045] For example, if the identity of a target network device is obtained as "Device Brand: Huawei, Service Type: SSH, Version Information: V2.0, System Name: AR Series Firmware", then the device characteristics can be determined by combining this information: the device brand is Huawei, the "AR Series Firmware" indicates that the device belongs to the Huawei AR series product line, and considering the characteristic that SSH service is commonly used for remote router management, the device type is determined to be a router, ultimately forming the device characteristics of "Huawei-AR Series-Router". As another example, if the identity of a target network device is obtained as "System Name: Nacos, Service Type: HTTP, Version Information: V2.2.3", then the device brand can be determined to be Nacos (corresponding to the system developer), the device belongs to the Nacos core series product line, and the device type is Nacos server, i.e., the device characteristics are "Nacos-Nacos Core Series-Nacos Server".

[0046] When the device characteristics include device brand, device product series, and device type, multiple target network devices are divided into multiple groups based on the device characteristics, including grouping target network devices that have the same device brand, device type, and device product series into one group.

[0047] For example, the characteristics of the existing 6 devices are as follows:

[0048] (1) Huawei-AR Series-Router

[0049] (2) Huawei-S5700 Series-Switch

[0050] (3) Huawei-AR Series-Router

[0051] (4) H3C-S5700 Series Switch

[0052] (5) Huawei-S6700 Series-Switch

[0053] (6) H3C-AR Series Routers

[0054] When grouping:

[0055] Devices can be grouped by "same brand": Huawei brand devices (1, 2, 3, 5) are in one group, and H3C brand devices (4, 6) are in another group;

[0056] They can be grouped by "same device type": all routers (1, 3, 6) are in one group, and all switches (2, 4, 5) are in another group;

[0057] The equipment can be grouped according to the "same product series": AR series equipment (1, 3, 6) are grouped together, S5700 series equipment (2, 4) are grouped together, and S6700 series equipment (5) is grouped separately.

[0058] You can also group them by “equipment brand + equipment type”: Huawei brand routers (1, 3) are in one group, Huawei brand switches (2, 5) are in another group, and H3C brand routers (6) and switches (4) are in another group.

[0059] By flexibly selecting grouping dimensions, the grouping strategy can be adjusted according to actual detection needs. The grouping strategy with the highest detection efficiency can be selected through multiple detection results and iteratively updated into the next network device detection task.

[0060] The above grouping criteria are merely examples. Those skilled in the art can infer the possible types of target network devices based on the network environment in which the target network devices are located, and then set up their own methods to extract device features based on the identity identifier and how to divide the target network devices into multiple groups based on the extracted device features.

[0061] In some embodiments, in step S2, multiple target network devices can be automatically grouped according to the clustering results by obtaining the identity identifiers of multiple target network devices, automatically extracting features from these identity identifiers, automatically using a clustering algorithm to cluster them.

[0062] For example, by using a clustering algorithm to automatically extract key features (such as "target network device brand", "service type", and "system name") from the identifiers of 100 target network devices, and then clustering them, we can group 30 of them into one category (high feature similarity) based on the fact that their identifiers all contain "Huawei", "SSH", and "AR series firmware"; 40 of them are clustered into a second category because their identifiers contain "Nacos", "HTTP", and "V2.x version"; and the remaining 30 are clustered into a third category because their identifiers contain "H3C", "Telnet", and "S5700 series".

[0063] In some embodiments, since the number of target network devices is large, the target network model can be grouped by clustering, or a classification model can be pre-trained.

[0064] By using models or clustering algorithms to automatically identify the similarity of identity identifiers, target network devices with similar characteristics can be grouped into the same group without the need for manual pre-setting of grouping rules. This is especially suitable for large-scale network environments with complex target network device types and diverse characteristics.

[0065] Regardless of the method used to group target network devices, the starting point for grouping strategy selection is that the potentially valid passwords (username-password combinations) corresponding to target network devices in the same group are highly similar.

[0066] The packet strategy can be iteratively optimized manually or automatically based on the detection results of each network device inspection.

[0067] In step S3, a password set corresponding to each group of target network devices is determined based on the device characteristics. The password set includes multiple account-password combinations.

[0068] Figure 2 This is a sub-flowchart of step S3 in an exemplary embodiment of this disclosure.

[0069] refer to Figure 2 In an exemplary embodiment, step S3 may include:

[0070] Step S31: Generate multiple candidate accounts based on the equipment brand and the product series to which the equipment belongs;

[0071] Step S32: Determine multiple preset detection accounts, including default accounts and preset weak accounts;

[0072] Step S33: Generate multiple candidate passwords based on device characteristics;

[0073] Step S34: Determine multiple preset detection passwords, including default passwords and preset weak passwords;

[0074] Step S35: Based on the correlation of device features, multiple candidate accounts, multiple preset detection accounts, multiple candidate passwords, and multiple preset detection passwords are arranged and combined to form a password set.

[0075] exist Figure 2 In the illustrated embodiment, multiple weak accounts with brand and product series characteristics can be generated as candidate accounts based on the device brand and product series to which the device belongs. For example, for Huawei-AR series routers, weak accounts such as "huawei_ar", "ar_huawei", "hw_ar_admin", and "ar_router" can be set; for H3C-S5700 series switches, weak accounts such as "h3c_s5700", "s5700_h3c", "h3c_switch", and "s5700_admin" can be set.

[0076] Then, add default accounts and preset weak accounts that are applicable to all network devices, such as common ones like "admin", "root", "user", and "admin123". This way, you can retain device-specific accounts while also covering general weak accounts, thus improving the comprehensiveness of the password set.

[0077] Next, in step S33, multiple candidate passwords with device-specific characteristics are generated based on device features (such as brand, product series, and type). For example, for Huawei-AR series routers, passwords that integrate brand and series identifiers, such as "huawei@ar", "ar123456", "hw_ar_2023", and "ar_router!@#", can be generated; for H3C-S5700 series switches, passwords that directly relate to device characteristics, such as "h3c$s5700", "s5700_h3c", "h3c_switch888", and "s5700@admin", can be generated, showing a very high degree of matching with this type of device.

[0078] In step S34, a preset detection password applicable to this type of device is determined, including the manufacturer's default password (such as "Admin@123" for Huawei devices and "h3c@123" for H3C devices) and common preset weak passwords (such as "123456", "password", "111111", "abcdef", etc.), thereby forming a password set for the target network devices that covers both the factory default configuration of the devices and common simple passwords.

[0079] In step S35, firstly, an account is selected from multiple candidate accounts and multiple preset detection accounts, and then a password is selected from multiple candidate passwords and multiple preset detection passwords to form an account-password combination. It should be noted that in the process of arranging and combining accounts and passwords to form multiple account-password combinations, the arrangement and combination need to be based on the correlation of the device characteristics of the group of devices.

[0080] For example, accounts and passwords associated with the same device characteristics are preferentially matched (e.g., the "huawei_ar" account paired with the "huawei@ar" password). In some embodiments, cross-combination forms (e.g., the "admin" account paired with the "s5700_h3c" password) and common weak password combinations (e.g., the "admin" account paired with the "000000" password) may also be retained.

[0081] pass Figure 3 The illustrated embodiment can form a password set that includes both device-specific feature combinations and general weak password combinations, maximizing coverage of potential weak password risks while ensuring targeted detection.

[0082] In some embodiments of this disclosure, multiple password sets corresponding to various device characteristics can be pre-formed. After scanning the target network devices and grouping them, the corresponding password set can be automatically matched according to the mapping relationship of device characteristics (for example, saving the password set corresponding to Huawei-AR series routers for Huawei-AR series routers) to improve detection efficiency.

[0083] In other embodiments of this disclosure, after grouping target network devices, new password sets can be generated in real time based on the characteristics of newly emerging devices that do not have corresponding password sets. When forming a new password set, existing password sets with similar device characteristics can be referenced to enrich the account-password combinations in the new password set.

[0084] In some embodiments of this disclosure, the password set can be dynamically optimized by combining historical detection data. For example, account-password combinations that have successfully logged into similar devices from the existing password set can be added to the password set corresponding to the target network devices. At the same time, combinations that have failed multiple consecutive tests from the existing password set can be downgraded or removed to avoid wasting resources on invalid attempts. In addition, the preset weak account password database can be updated periodically based on industry security reports and other information (such as adding commonly exposed weak passwords of the year) to ensure that the existing password set or the newly generated password set can maintain its coverage of new weak password risks.

[0085] In step S4, the target network devices are logged in using the username-password combination from their corresponding password sets.

[0086] In an exemplary embodiment, the sequence numbers of the target network devices within the group and the account-password combinations in the password set corresponding to the target network devices in the group can be edited first. Let the number of target network devices in a group be N, and the number of account-password combinations in the password set corresponding to the target network devices in the group be M, where both N and M are greater than or equal to 1.

[0087] Then, select a target network device with index i (i can be initially set to 1) and perform login checks using each of the M username-password combinations. Let the index of the currently used username-password combination be j (j can be initially set to 1). When the j-th username-password combination successfully logs into the i-th target network device, record the correspondence between the i-th target network device and the j-th username-password combination. Then, continue to check the login of the (i+1)-th target network device in the same group. This j-th username-password combination can be called a valid password.

[0088] In this embodiment of the disclosure, in order to improve the success rate and efficiency of subsequent detection of target network devices within the group, a derived password is generated based on a valid password, and the password set corresponding to the target network devices in the group is updated.

[0089] Figure 3 This is a flowchart of forming a derived password in an exemplary embodiment of this disclosure.

[0090] refer to Figure 3 In an exemplary embodiment, the process of generating a derived password during the login detection process in step S4 may include:

[0091] Step S41: When a target network device can log in using an account-password combination, determine the naming feature corresponding to the account-password combination. The naming feature includes account features and password features. The account features and / or password features include the identifier corresponding to the device features and the naming format.

[0092] Step S42: Generate multiple derived account-password combinations based on naming characteristics;

[0093] Step S43: Add multiple derived account-password combinations to the password set corresponding to the group where the target network device is located, so as to perform login detection on other target network devices in the group.

[0094] For example, if it is detected that the i-th target network device can successfully log in using the j-th username-password combination "huawei_ar-Ar@2023" in the packet corresponding to the Huawei-AR series router, then "huawei_ar-Ar@2023" will be recorded as the valid password for the packet corresponding to the Huawei-AR series router.

[0095] Next, we analyze the naming characteristics of this valid password: the account characteristics are the concatenation format of "brand name (huawei) + product series (ar)", and the password characteristics include "product series abbreviation (Ar) + year (2023)" and the special symbol "@".

[0096] In step S42, multiple derived accounts and multiple derived passwords are generated based on the naming feature, and then multiple derived account-password combinations are formed by arranging and combining the multiple derived accounts and multiple derived passwords.

[0097] For example, multiple derived accounts can be "hw_ar" (brand abbreviation + series), "ar_huawei" (series + brand name), "huawei_ar1" (original account plus numbers); multiple derived passwords can be "Ar@2022" (decreasing year), "Ar@2024" (increasing year), "ar#2023" (replacement of special characters), "AR@2023" (change of letter case).

[0098] Furthermore, multiple derived accounts and multiple derived passwords are combined to form derived account-password combinations such as "hw_ar+Ar@2022" and "ar_huawei+ar#2023".

[0099] In addition, the derived account-password combination can also include the account from the valid password (recorded as a valid account) and the password from the valid password (recorded as a valid password). For example, the valid password is "huawei_ar-Ar@2023", the valid account is huawei_ar, and the valid password is Ar@2023.

[0100] Multiple derived ciphers can be derived from the valid cipher, such as uppercase and lowercase variants of "Ar@2023" such as "ar@2023" and "AR@2023", year-replaced "Ar@2021" and "Ar@2024", special character-replaced "Ar#2023" and "Ar!2023", and length-adjusted "Ar@23" and "Ar@202300", etc.

[0101] Then, multiple derived accounts are generated based on the valid account, such as the abbreviation of "huawei_ar" "hw_ar" and "h_ar", the order adjustment of "ar_huawei" and "ar_hw", the addition of a number suffix "huawei_ar1" and "huawei_ar88", and the expansion of the full brand name "huawei_router_ar", etc.

[0102] Furthermore, based on the valid account "huawei_ar" and multiple derived passwords, derived account-password combinations such as "huawei_ar-ar@2023" and "huawei_ar-AR@2024" are formed. Based on multiple derived accounts and the valid password "Ar@2023", derived account-password combinations such as "hw_ar-Ar@2023" and "ar_huawei-Ar@2023" are formed. By retaining the core characteristics of the valid account or password and making local variations, the system maximizes the coverage of similar weak password rules that may be used by devices in the same group.

[0103] In step S43, these derived account-password combinations are added to the password set corresponding to the Huawei-AR series router. When detecting target network devices in the same group, the valid password and its corresponding derived combinations are used first, thereby improving the efficiency of detecting weak passwords that use similar naming rules (such as the i+1th target network device may use "huawei_ar-Ar@2023" or "huawei_ar-Ar@2024" to log in), and significantly improving the detection efficiency and success rate of devices in the same group.

[0104] Figure 4 This is a sub-flowchart of step S4 in an exemplary embodiment of this disclosure.

[0105] refer to Figure 4 In an exemplary embodiment, step S4 may further include:

[0106] Step S44: For the i-th target network device in a group, use the j-th username-password combination in the password set to perform login detection, i≥1, j≥1;

[0107] Step S45: When the i-th target network device can log in using the j-th username-password combination, use the j-th username-password combination to perform login detection on the (i+1)-th target network device;

[0108] Step S46: When the (i+1)th target network device cannot log in using the jth account-password combination, use the derived account-password combination corresponding to the jth account-password combination to perform login detection on the (i+1)th target network device.

[0109] Figure 4 The embodiment shown illustrates an exemplary method for performing login detection on subsequent target network devices within a group when real-time derived account-password generation is performed during the detection process, and the password set is updated in real time.

[0110] exist Figure 4 In the illustrated embodiment, the number of target network devices in a group is N, and the number of username-password combinations in the password set corresponding to this group of target network devices is M, where both N and M are greater than or equal to 1. When the j-th username-password combination successfully logs into the i-th target network device, the j-th username-password combination is recorded as a valid password, and a derived password is generated based on this valid password and added to the password set corresponding to this group of target network devices.

[0111] Next, the (i+1)th target network device in the group is detected. First, the j-th recorded valid password is used for login. If login is successful, it indicates that the valid password is universal across devices in the same group and can be used for the (i+2)th device, reducing the need to repeatedly generate derived passwords and improving detection efficiency. If login fails, derived passwords generated in steps S41-S43 (variant combinations based on the j-th valid password) can be used. For example, if the original valid password is "huawei_ar-Ar@2023", derived passwords include "hw_ar-ar@2023", "ar_huawei-AR@2024", etc., and these can be tried on the (i+1)th device in sequence.

[0112] Therefore, by setting the password usage priority of "first reuse of valid passwords → supplementary detection of derived passwords", the order of attempts can be dynamically adjusted in the detection of devices in the same group. For devices with highly similar characteristics, detection can be completed quickly by reusing valid passwords. For devices with slight differences, more possibilities can be covered by real-time derived variant combinations. This avoids redundant attempts of invalid combinations and ensures the depth of weak password detection, which is especially suitable for scenarios where there are configuration differences among devices in the same series.

[0113] By performing login checks on a single target network device using a set of passwords from a password set, and adjusting the password usage strategy for subsequent target network devices within the same group based on the results, detection efficiency can be significantly improved. Firstly, it eliminates the need to repeatedly try all passwords from the password set on all devices within the group; by directly reusing valid passwords from earlier devices, the number of invalid login attempts is greatly reduced, significantly improving overall detection efficiency. Secondly, when password reuse fails, supplementary checks can be performed by invoking derived passwords in real time, covering potential password variations within the same group (such as differences in username capitalization or password year adjustments), thus avoiding missed detections due to minor differences in device configuration, and improving both detection efficiency and accuracy. Furthermore, by focusing on detecting a single target network device over a specific period, access pressure on the target network device can be reduced (e.g., avoiding high-frequency invalid requests triggering device protection mechanisms within a short period), ensuring detection effectiveness while minimizing interference with normal enterprise network operations.

[0114] In other embodiments of this disclosure, the system may first use the j-th password (username-password combination) from the password set to perform login checks on N target network devices. If the password is effective (successfully logs in) on any device in the group, it is marked as a valid password, and multiple derived passwords are generated based on the valid password. The derived password corresponding to the valid password is set to the highest priority so that it is preferentially applied to the detection of other target network devices in the same group that have failed to log in successfully using the valid password.

[0115] Therefore, once a password becomes effective on any device within the group, its derived passwords can be quickly generated and assigned the highest priority for efficient detection of devices in the same group that have not logged in using that valid password. For example, when "huawei_ar-Ar@2023" becomes effective on a Huawei-AR router, its derived passwords such as "hw_ar-ar@2023" and "ar_huawei-AR@2024" will be prioritized for use on other devices in the same group that have not successfully logged in. By leveraging the correlation of password rules among devices in the same group, the probability of capturing similar weak passwords is greatly improved.

[0116] Therefore, by using a single password to detect devices within the same group, it's possible to identify target network devices for which the password is valid in advance, avoiding redundant detection of devices already covered by valid passwords. Furthermore, the high-priority application of derived passwords ensures detection depth while reducing invalid attempts, making it particularly suitable for scenarios where devices in the same group share common password variations (e.g., devices in the same series use similar naming rules but have subtle differences). Simultaneously, setting derived passwords to the highest priority and using the most likely valid password for login detection within a short time significantly shortens the detection cycle, thereby improving overall detection efficiency and achieving the technical effect of "discovering one, covering a whole area."

[0117] In step S5, the target network device that can log in using any of the account-password combinations is marked as a security risk device.

[0118] In this embodiment, each group of target network devices is identified as having security risks if they can be logged into with any password (including multiple derived passwords) from their corresponding password set. These risky devices are then centrally processed, for example, by notifying the user to immediately change their username-password combination or automatically resetting passwords for critical devices. Those skilled in the art can configure how to handle these risky devices according to actual needs.

[0119] Figure 5 This is a schematic diagram of an application scenario in an exemplary embodiment of this disclosure.

[0120] refer to Figure 5 In one application scenario, under event 501, a port and service scan is performed on the target network device to explore the port information exposed by the target network device and the types of network services running on the ports.

[0121] In Event 502, based on the scan results of Event 501, login services were discovered. From a large number of port services, services that can be used for device login were selected, such as common login or remote access services like SSH, TELNET, FTP, RDP, and HTTP.

[0122] In Incident 503, device characteristics were identified through the login service, and devices were grouped based on these characteristics. Devices with similar characteristics were grouped together according to features such as device identifier, system type, and brand model associated with the login service.

[0123] In Event 503, device feature identification is performed on the login service from Event 502. For example, assets can be categorized and grouped based on features such as banner information, page title, and logo in the login service response. Grouping can be defined as {Company, Product or System, Login Service}, such as {H3C, Switch, SSH}, {NACOS, NACOS System, HTTP}, etc.

[0124] In event 504, output device grouping.

[0125] In Event 505, the corresponding password set is loaded based on the device group. This step can either load an existing password set or create a new password set based on the device characteristics corresponding to that group of devices. The password set includes common default passwords corresponding to that group of devices and common weak passwords collected from the internet that are specific to the corresponding products. This password set is highly targeted and concise.

[0126] In Event 506, a set of passwords corresponding to a group of devices is used to perform login detection on the group of devices. The username-password combination in the loaded password set is used to attempt to log in to the corresponding group of devices to verify whether the password can successfully bypass the login verification.

[0127] In event 507, determine whether the login was successful. If the login was successful, proceed to event 508; otherwise, proceed to event 510 to continue the detection.

[0128] In Incident 508, upon successful login, the device with security risks was flagged, the valid password was recorded, and the password characteristics of the valid password were analyzed.

[0129] In Incident 509, derived passwords were generated based on password characteristics and added to the password set. For example, if a loginable username-password combination was discovered, relevant characteristic analysis could be performed on that combination. For example: 1) admin / admin123, the username uses the common keyword admin, and the characteristic is username + numbers, which can be derived as admin / admin456, admin / admin12345, etc. 2) huawei / Huawei@1234, the characteristic is manufacturer name + @ + numbers, which can be derived as huawei@1234, Huawei@123, etc.

[0130] In event 510, continue testing until all devices in the group have been tested based on all passwords in the password set. Use the remaining passwords in the password set to continuously test the devices in the group until the password set is exhausted.

[0131] In event 511, output the security risk devices corresponding to this group.

[0132] In event 512, after completing the testing of one group of devices, the next group of devices is tested, until the testing of all groups of devices is completed.

[0133] In summary, the embodiments of this disclosure, by automatically classifying target network devices based on their device characteristics, can perform grouped detection on a large number of targets, resulting in high targeting and detection efficiency. By using password sets corresponding to device groups for login detection, highly targeted and personalized password cracking tasks can be executed, improving detection efficiency. Furthermore, by generating derived passwords based on successful login passwords and updating the password set, the detection efficiency of devices within the same group can be effectively improved. Therefore, the embodiments of this disclosure can achieve comprehensive weak password security screening of target network devices, constructing a complete process from device port service probing and grouping to password detection, risk identification, and password optimization iteration, helping to promptly discover security vulnerabilities in the network device login process.

[0134] Corresponding to the above method embodiments, this disclosure also provides a network device detection apparatus, which can be used to execute the above method embodiments.

[0135] Figure 6 This is a block diagram of a network device detection apparatus according to an exemplary embodiment of the present disclosure.

[0136] refer to Figure 6 The network device testing device 600 may include:

[0137] The device scanning module 61 is configured to scan multiple target network devices to be detected to obtain the port of each target network device, and to detect the target network device through the port to obtain the identity of the target network device.

[0138] The device grouping module 62 is configured to determine the device characteristics of the target network device based on the identity identifier, and divide the multiple target network devices into multiple groups based on the device characteristics;

[0139] The password set matching module 63 is configured to determine the password set corresponding to each group of target network devices based on the device characteristics, wherein the password set includes multiple account-password combinations.

[0140] The group testing module 64 is configured to log in to a group of the target network devices using account-password combinations from the corresponding password set.

[0141] The result marking module 65 is configured to mark the target network device that can be logged in using any of the account-password combinations as a security risk device.

[0142] Since the functions of the device 600 have been described in detail in their respective method embodiments, they will not be repeated here.

[0143] It should be noted that although several modules or units for the device used to perform actions have been mentioned in the detailed description above, this division is not mandatory. In fact, according to embodiments of this disclosure, the features and functions of two or more modules or units described above can be embodied in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided and embodied by multiple modules or units.

[0144] In an exemplary embodiment of this disclosure, an electronic device capable of implementing the above-described method is also provided.

[0145] Those skilled in the art will understand that various aspects of the present invention can be implemented as systems, methods, or program products. Therefore, various aspects of the present invention can be specifically implemented in the following forms: entirely hardware implementations, entirely software implementations (including firmware, microcode, etc.), or implementations combining hardware and software aspects, collectively referred to herein as “circuits,” “modules,” or “systems.”

[0146] The following reference Figure 7 To describe an electronic device 700 according to this embodiment of the present invention. Figure 7 The electronic device 700 shown is merely an example and should not impose any limitations on the functionality and scope of use of the embodiments of the present invention.

[0147] like Figure 7 As shown, the electronic device 700 is presented in the form of a general-purpose computing device. The components of the electronic device 700 may include, but are not limited to: at least one processor 710, at least one memory 720, and a bus 730 connecting different system components (including memory 720 and processor 710).

[0148] The memory stores program code that can be executed by the processor 710, causing the processor 710 to perform the steps described in the "Exemplary Methods" section above, according to various exemplary embodiments of the present invention. For example, the processor 710 can perform methods as shown in embodiments of this disclosure.

[0149] The memory 720 may include a readable medium in the form of volatile memory, such as random access memory (RAM) 7201 and / or cache 7202, and may further include read-only memory (ROM) 7203.

[0150] The memory 720 may also include a program / utility 7204 having a set (at least one) of program modules 7205, including but not limited to: an operating system, one or more application programs, other program modules, and program data, each or some combination of these examples may include an implementation of a network environment.

[0151] Bus 730 can represent one or more of several types of bus structures, including a memory bus or memory controller, peripheral bus, graphics acceleration port, processor, or a local bus using any of the various bus structures.

[0152] Electronic device 700 can also communicate with one or more external devices 800 (e.g., keyboard, pointing device, Bluetooth device, etc.), and with one or more devices that enable a user to interact with electronic device 700, and / or with any device that enables electronic device 700 to communicate with one or more other computing devices (e.g., router, modem, etc.). This communication can be performed via input / output (I / O) interface 750. Furthermore, electronic device 700 can also communicate with one or more networks (e.g., local area network (LAN), wide area network (WAN), and / or public networks, such as the Internet) via network adapter 760. As shown, network adapter 760 communicates with other modules of electronic device 700 via bus 730. It should be understood that, although not shown in the figures, other hardware and / or software modules can be used in conjunction with electronic device 700, including but not limited to: microcode, device drivers, redundant processors, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.

[0153] From the above description of the embodiments, those skilled in the art will readily understand that the exemplary embodiments described herein can be implemented by software or by combining software with necessary hardware. Therefore, the technical solutions according to the embodiments of this disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, USB flash drive, external hard drive, etc.) or on a network, including several instructions to cause a computing device (such as a personal computer, server, terminal device, or network device, etc.) to execute the methods according to the embodiments of this disclosure.

[0154] In exemplary embodiments of this disclosure, a computer-readable storage medium is also provided, on which a program product capable of implementing the methods described above is stored. In some possible embodiments, various aspects of the invention may also be implemented as a program product comprising program code that, when the program product is run on a terminal device, causes the terminal device to perform the steps of the various exemplary embodiments of the invention described in the "Exemplary Methods" section of this specification.

[0155] The program product for implementing the above-described method according to embodiments of the present invention may employ a portable compact disc read-only memory (CD-ROM) and include program code, and may run on a terminal device, such as a personal computer. However, the program product of the present invention is not limited thereto. In this document, the readable storage medium may be any tangible medium containing or storing a program that may be used by or in conjunction with an instruction execution system, apparatus, or device.

[0156] The program product may employ any combination of one or more readable media. A readable medium may be a readable signal medium or a readable storage medium. A readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of readable storage media (a non-exhaustive list) include: an electrical connection having one or more wires, a portable disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0157] Computer-readable signal media may include data signals propagated in baseband or as part of a carrier wave, carrying readable program code. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A readable signal medium may also be any readable medium other than a readable storage medium, capable of sending, propagating, or transmitting programs for use by or in conjunction with an instruction execution system, apparatus, or device.

[0158] The program code contained on the readable medium may be transmitted using any suitable medium, including but not limited to wireless, wired, optical fiber, RF, etc., or any suitable combination thereof.

[0159] Program code for performing the operations of this invention can be written in any combination of one or more programming languages, including object-oriented programming languages ​​such as Java and C++, and conventional procedural programming languages ​​such as C or similar languages. The program code can execute entirely on the user's computing device, partially on the user's device, as a standalone software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server. In cases involving remote computing devices, the remote computing device can be connected to the user's computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (e.g., via the Internet using an Internet service provider).

[0160] Furthermore, the above figures are merely illustrative of the processes included in the method according to exemplary embodiments of the present invention, and are not intended to be limiting. It is readily understood that the processes shown in the above figures do not indicate or limit the temporal order of these processes. Additionally, it is readily understood that these processes may be executed synchronously or asynchronously, for example, in multiple modules.

[0161] Other embodiments of this disclosure will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of this disclosure that follow the general principles of this disclosure and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and concept of this disclosure are indicated by the claims.

Claims

1. A network device detection method, characterized by, The method comprises the following steps: scanning a plurality of target network devices to be detected to obtain a port of each of the target network devices, and detecting the target network devices through the port to obtain an identity of the target network devices; determining a device feature of the target network devices according to the identity, and dividing the plurality of target network devices into a plurality of groups according to the device feature; determining a password set corresponding to each group of the target network devices according to the device feature, wherein the password set comprises a plurality of account-password combinations; logging in a group of the target network devices using an account-password combination in the password set corresponding to the group; marking the target network device capable of logging in through any of the account-password combinations as a security risk device.

2. The network device detection method of claim 1, wherein, The method further comprises the following steps: when a target network device is capable of logging in through the account-password combination, determining a naming feature corresponding to the account-password combination, wherein the naming feature comprises an account feature and a password feature, and the account feature and / or the password feature comprises an identifier corresponding to the device feature and a naming format; generating a plurality of derived account-password combinations according to the naming feature; adding the plurality of derived account-password combinations to the password set corresponding to the group to which the target network device belongs, so as to log in other target network devices in the group.

3. The network device detection method of claim 2, wherein, The method of logging in a group of the target network devices using an account-password combination in the password set corresponding to the group comprises the following steps: for the i-th target network device in the group, using the j-th account-password combination in the password set for login detection, wherein i≥1 and j≥1; when the i-th target network device is capable of logging in through the j-th account-password combination, using the j-th account-password combination to log in the i+1-th target network device; when the i+1-th target network device is incapable of logging in through the j-th account-password combination, using a derived account-password combination corresponding to the j-th account-password combination to log in the i+1-th target network device.

4. The network device detection method of claim 1, wherein, The identity comprises at least one of a device brand, a system name, a service type, and version information, and determining the device feature of the target network devices according to the identity comprises the following steps: determining a device brand, a product series to which the device belongs, and a device type of the target network devices according to at least one of the device brand, the system name, the service type, and the version information.

5. The network device detection method of claim 1 or 4, wherein, The device feature comprises a device brand, a product series to which the device belongs, and a device type, and dividing the plurality of target network devices into a plurality of groups according to the device feature comprises the following steps: grouping the target network devices having at least one of the same device brand, the same device type, and the same product series to which the device belongs into a group.

6. The network device detection method of claim 5, wherein, Determining a password set corresponding to each group of the target network devices according to the device feature comprises the following steps: forming a plurality of candidate accounts according to the device brand and the product series to which the device belongs; determining a plurality of preset detection accounts, wherein the preset detection accounts comprise a default account and a preset weak account; forming a plurality of candidate passwords according to the device feature; determining a plurality of preset detection passwords, the preset detection passwords comprising a default password and a preset weak password; performing permutation and combination on the plurality of candidate accounts, the plurality of preset detection accounts, the plurality of candidate passwords and the plurality of preset detection passwords based on the relevance of the device features to form the password set.

7. A network device detection apparatus, comprising: Comprising: a device scanning module configured to scan a plurality of target network devices to be detected to obtain a port of each of the target network devices, and to probe the target network devices through the port to obtain an identity of the target network devices; a device grouping module configured to determine a device feature of the target network devices according to the identity, and to group the plurality of target network devices according to the device feature; a password set matching module configured to determine a password set corresponding to each group of the target network devices according to the device feature, the password set comprising a plurality of account-password combinations; a grouping test module configured to log in to a group of the target network devices using an account-password combination in the password set corresponding to the group of the target network devices; a result marking module configured to mark the target network devices capable of being logged in through any of the account-password combinations as a security risk device.

8. An electronic device, comprising: Comprising: a memory; and a processor coupled to the memory, the processor being configured to execute a method as claimed in any one of claims 1-6 based on instructions stored in the memory.

9. A computer readable storage medium having stored thereon a program which, when executed by a processor, implements a method as claimed in any one of claims 1-6.

10. A computer program product comprising a computer program, characterized in that, The computer program, when executed by a processor, implements the steps of the method as claimed in any one of claims 1-6.