Penetration testing method and device for network information system security assessment
By conducting preliminary vulnerability scanning and internal network penetration assessment within the enterprise network, the problem of low penetration testing effectiveness caused by incomplete scanning is solved, achieving more comprehensive penetration testing and higher penetration results.
Patent Information
- Application Number
- CN202511832596.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-08
- Publication Date
- 2026-02-10
- Estimated Expiration
- 2045-12-08
AI Technical Summary
In existing technologies, the complexity of enterprise internal networks and security measures lead to incomplete vulnerability scanning, resulting in low effectiveness of penetration testing.
By obtaining scan coverage deviation results through initial vulnerability scanning, we can determine whether to conduct a vulnerability scanning effectiveness assessment, optimize the scan if necessary, and combine the effectiveness assessment with parameters from the internal network penetration process to ensure the comprehensiveness and depth of the penetration test.
It improves the coverage of vulnerability scanning and the effectiveness of penetration testing, ensures the comprehensiveness and depth of penetration testing, quantifies the effectiveness of vulnerability scanning in penetration testing, adapts to various network environments, and avoids the shortcomings of static evaluation.
Smart Images

Figure CN121283773B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of electric digital data processing, and in particular to a penetration testing method and device for security assessment of a network information system. BACKGROUND
[0002] Penetration testing refers to scanning a network system using automated tools (such as Nessus, OpenVAS, Qualys, etc.) to identify known security vulnerabilities. After identifying the vulnerabilities, the penetration tester will attempt to exploit the identified vulnerabilities using specific attack methods (such as the Metasploit framework) to simulate a hacking process to gain system access. After obtaining initial access, the penetration tester will use system vulnerabilities, configuration flaws, or social engineering to obtain system administrator privileges. After obtaining higher privileges, the penetration tester will attempt to move laterally from the compromised system to other computers, applications, or services in the internal network to further expand the attack range. Finally, the penetration tester will attempt to create a persistent access path in the target system, such as implanting a backdoor program or modifying system configurations, to allow the attacker to maintain access to the system for a long period of time. At the end of the penetration test, the tester needs to remove as much attack evidence (such as log files, malware, etc.) as possible from the target system to simulate the attacker's anti-forensic behavior.
[0003] For example, the invention patent with publication number CN114462048B discloses an automatic penetration testing method and system based on a network target range, which includes obtaining the running configuration information of the service to be tested, using an identification decision tree for classification, and sending different categories of running configuration information to corresponding vulnerability mining modules for processing based on the identification results to mine potential vulnerabilities and build a basic target range. Test scheme construction is performed based on the mined potential vulnerabilities and obtained running configuration information. The test scheme is executed, and it is determined whether the test is passed.
[0004] For example, the patent application with publication number CN118035075A discloses an automatic penetration testing method and device, which includes obtaining the penetration testing method selected by the user from the pre-defined penetration testing method set in the scanning task, and automatically constructing a scanning tree using the penetration testing method. The scanning tree is analyzed, and the penetration testing parameters of the scanning tree are automatically configured. The user's parameter adjustment instruction is obtained, and the penetration testing parameters are adjusted through the parameter adjustment instruction to obtain custom parameters. The scanning process of the scanning tree is executed using the custom parameters, and the scanning result is obtained.
[0005] However, in the process of implementing the technical solutions of the embodiments of the present application, the above-mentioned technologies at least have the following technical problems:
[0006] In the prior art, since the enterprise internal network usually contains multiple subnets, internal servers, workstations, databases and the like, and usually also has complex security measures such as firewalls, intrusion detection systems / intrusion prevention systems and virtual private networks (VPN), the detection of the scanning tool may be intercepted or affected, resulting in incomplete scanning results, thus causing false negatives and false positives of vulnerabilities; if the vulnerability scanning is incomplete, the penetration tester may not be able to effectively exploit the vulnerabilities for subsequent penetration testing, and there is a problem of low effectiveness of penetration testing caused by incomplete vulnerability scanning. SUMMARY
[0007] The embodiments of the present application provide a penetration testing method and device for network information system security evaluation, solve the problem of low effectiveness of penetration testing caused by incomplete vulnerability scanning in the prior art, and improve the effectiveness of penetration testing.
[0008] The embodiments of the present application provide a penetration testing method for network information system security evaluation, including the following steps: S1, using a penetration testing tool to perform preliminary vulnerability scanning on a to-be-tested enterprise network to obtain preliminary scanning vulnerabilities in the to-be-tested enterprise network, and obtaining a scanning coverage deviation result of the to-be-tested enterprise network based on the preliminary vulnerability scanning; S2, judging whether to perform vulnerability scanning effectiveness evaluation based on parameters in the preliminary vulnerability scanning process, if not, prompting a preset personnel to reselect a penetration testing tool, otherwise further judging whether to perform vulnerability scanning optimization on the to-be-tested enterprise network, if yes, performing vulnerability scanning on the to-be-tested enterprise network after the vulnerability scanning optimization to obtain scanning vulnerabilities in the to-be-tested enterprise network, performing internal network penetration on the to-be-tested enterprise network based on the obtained scanning vulnerabilities, otherwise performing internal network penetration on the to-be-tested enterprise network based on the obtained preliminary scanning vulnerabilities; S3, performing internal network penetration effectiveness evaluation based on parameters in the internal network penetration process, and judging whether to perform internal network penetration optimization on the to-be-tested enterprise network, if not, continuing the penetration testing until the penetration testing is completed, otherwise continuing the penetration testing until the penetration testing is completed after the internal network penetration optimization.
[0009] The embodiment of the application provides a penetration testing device for network information system security evaluation, comprising: a preliminary vulnerability scanning module, a vulnerability scanning evaluation module and an intranet penetration evaluation module; the preliminary vulnerability scanning module is used for performing preliminary vulnerability scanning on a to-be-tested enterprise network by using a penetration testing tool, obtaining preliminary scanning vulnerabilities in the to-be-tested enterprise network, and obtaining a scanning coverage deviation result of the to-be-tested enterprise network based on the preliminary vulnerability scanning; the vulnerability scanning evaluation module is used for judging whether to perform vulnerability scanning effectiveness evaluation based on parameters in the preliminary vulnerability scanning process, if not, prompting a preset person to reselect a penetration testing tool, otherwise, further judging whether to perform vulnerability scanning optimization on the to-be-tested enterprise network, if yes, performing vulnerability scanning on the to-be-tested enterprise network after the vulnerability scanning optimization to obtain scanning vulnerabilities, performing intranet penetration on the to-be-tested enterprise network based on the obtained scanning vulnerabilities, otherwise, performing intranet penetration on the to-be-tested enterprise network based on the obtained preliminary scanning vulnerabilities; and the intranet penetration evaluation module is used for performing intranet penetration effectiveness evaluation based on parameters in the intranet penetration process, and judging whether to perform intranet penetration optimization on the to-be-tested enterprise network, if not, continuing penetration testing until the penetration testing is completed, otherwise, continuing penetration testing until the penetration testing is completed after the intranet penetration optimization.
[0010] The one or more technical solutions provided in the embodiment of the application have at least the following technical effects or advantages:
[0011] 1. The scanning coverage deviation result of the to-be-tested enterprise network is obtained through preliminary vulnerability scanning, it is judged whether to perform vulnerability scanning effectiveness evaluation, the coverage rate of vulnerability scanning is ensured, then it is further judged whether to perform vulnerability scanning optimization on the to-be-tested enterprise network, the effectiveness of vulnerability scanning is improved, finally, the intranet penetration effectiveness evaluation is performed based on parameters in the intranet penetration process, and it is judged whether to perform intranet penetration optimization on the to-be-tested enterprise network, the penetration effect of penetration testing is improved, and the problem of low penetration detection effectiveness caused by incomplete vulnerability scanning in the prior art is effectively solved.
[0012] 2. The scanning completion rate comparison coefficient, the security device bypass coefficient comparison coefficient and the penetration scanning time deviation coefficient are processed as a vulnerability scanning effectiveness evaluation index, so that the vulnerability scanning effectiveness in penetration testing is quantified comprehensively, the introduction of the vulnerability scanning effectiveness evaluation adjustment factor can better adapt to enterprise networks in various network environments, avoids the problem that static evaluation cannot reflect the actual vulnerability scanning effect, is conducive to identifying potential problems in the vulnerability scanning process in time and optimizing, and further improves the effectiveness of penetration testing.
[0013] 3. The internal network penetration effectiveness evaluation index is obtained by introducing the vulnerability scanning effective evaluation index and correcting the internal network penetration effectiveness evaluation coefficient. The internal network penetration effectiveness evaluation index can be dynamically adjusted according to the actual situation of the vulnerability scanning and the actual internal network environment, so that the evaluation result is more in line with the actual situation. The internal network penetration evaluation comparison coefficient is used to quantify the activity ability in the internal network, and then the effectiveness of the internal network penetration in the penetration test is quantified comprehensively. BRIEF DESCRIPTION OF DRAWINGS
[0014] Figure 1 A flowchart of vulnerability scanning provided for the embodiments of the present application is provided.
[0015] Figure 2 A flowchart of the penetration testing method for network information system security evaluation provided for the embodiments of the present application is provided.
[0016] Figure 3 A flowchart of vulnerability scanning optimization provided for the embodiments of the present application is provided. DETAILED DESCRIPTION
[0017] The embodiments of the present application provide a penetration testing method and device for network information system security evaluation, solve the problem of low penetration detection effectiveness caused by incomplete vulnerability scanning in the prior art, obtain a scanning coverage deviation result of a to-be-tested enterprise network through preliminary vulnerability scanning, then judge whether to perform vulnerability scanning effectiveness evaluation based on parameters in the preliminary vulnerability scanning process, if yes, further judge whether to perform vulnerability scanning optimization on the to-be-tested enterprise network, otherwise, prompt a preset personnel to reselect a penetration testing tool, finally perform internal network penetration effectiveness evaluation based on parameters in an internal network penetration process, and judge whether to perform internal network penetration optimization on the to-be-tested enterprise network, so as to improve the penetration detection effectiveness.
[0018] The technical solution in the embodiments of the present application is to solve the problem of low penetration detection effectiveness caused by incomplete vulnerability scanning, and the general idea is as follows:
[0019] By judging whether to perform vulnerability scanning effectiveness evaluation and judging whether to perform vulnerability scanning optimization on the to-be-tested enterprise network, finally performing internal network penetration effectiveness evaluation based on parameters in an internal network penetration process and judging whether to perform internal network penetration optimization on the to-be-tested enterprise network, the penetration detection effectiveness is improved.
[0020] In order to better understand the above technical solution, the above technical solution will be described in detail in combination with the drawings in the specification and specific embodiments.
[0021] As Figure 1The diagram shows a flowchart of a vulnerability scanning process provided in this application embodiment. The specific logic is as follows: A preliminary vulnerability scan is performed to obtain preliminary vulnerabilities in the network of the enterprise under test. If the scan coverage deviation result of the network under test is not less than the preset scan coverage deviation result, the preset personnel are prompted to reselect the penetration testing tool. Otherwise, the effectiveness of the vulnerability scan is evaluated based on the parameters obtained during the preliminary vulnerability scan, and it is further determined whether to optimize the vulnerability scan of the network under test. If so, a vulnerability scan is performed after optimization to obtain the scan vulnerabilities in the network of the enterprise under test. Internal network penetration is performed based on the obtained scan vulnerabilities. Otherwise, internal network penetration is performed based on the obtained preliminary scan vulnerabilities. An internal network penetration effectiveness evaluation is performed based on the parameters obtained during the internal network penetration process, and it is determined whether to optimize the internal network penetration of the network under test. If internal network penetration optimization is not performed, the penetration test continues until the penetration test ends. Otherwise, the penetration test continues after internal network penetration optimization until the penetration test ends.
[0022] As an example of the first aspect, such as Figure 2 The flowchart shown is a penetration testing method for network information system security assessment provided in this application embodiment. This application embodiment provides a penetration testing method for network information system security assessment, applied in a penetration testing device for network information system security assessment. The method includes the following steps: S1, Preliminary vulnerability scanning: Using a penetration testing tool to perform a preliminary vulnerability scan of the network of the enterprise to be tested, obtaining the preliminary scan vulnerabilities and the number of scanned network topologies in the network of the enterprise to be tested. The ratio of the number of scanned network topologies to the total number of network topologies in the network of the enterprise to be tested is calculated to obtain the scan coverage rate; the scan coverage rate is then compared with a preset scan coverage ratio. The coverage rate is processed by relative deviation to obtain the scanning coverage deviation result of the network of the enterprise under test; the penetration testing tool refers to the automated tool (such as Nessus, OpenVAS, Qualys, etc.); the network topology includes but is not limited to multiple subnets, servers, workstations and databases in the enterprise's internal network; the relative deviation processing in this application means that the absolute value of the deviation value is compared with the preset value, and the deviation value is the difference between the actual value and the preset value; by analyzing the scanning coverage deviation result of the network of the enterprise under test, the coverage of the penetration testing tool in the network of the enterprise under test can be understood, ensuring the coverage of vulnerability scanning and avoiding the omission of important vulnerabilities.
[0023] S2, vulnerability scanning evaluation: if the scanning coverage deviation result of the enterprise network to be tested is not less than the preset scanning coverage deviation result, prompting the preset personnel to reselect the penetration testing tool, otherwise, based on the parameters in the preliminary vulnerability scanning process, the vulnerability scanning effectiveness evaluation is evaluated, the vulnerability scanning effectiveness evaluation index is obtained, and it is further judged whether to optimize the vulnerability scanning of the enterprise network to be tested, if yes, the scanning vulnerabilities in the enterprise network to be tested are obtained after the vulnerability scanning optimization, the internal network penetration of the enterprise network to be tested is carried out based on the obtained scanning vulnerabilities, otherwise, the internal network penetration of the enterprise network to be tested is carried out based on the obtained preliminary scanning vulnerabilities; through the execution of vulnerability scanning effectiveness evaluation and vulnerability scanning optimization, it is beneficial to improve the coverage and depth of vulnerability scanning, so as to find more vulnerabilities and improve the effectiveness of vulnerability scanning in penetration testing; through the internal network penetration of the enterprise network to be tested based on the obtained scanning vulnerabilities, the internal network penetration can be more targeted, and the range of penetration testing is expanded.
[0024] S3, internal network penetration evaluation: based on the parameters in the internal network penetration process, the internal network penetration effectiveness evaluation is evaluated, the internal network penetration effectiveness evaluation index is obtained, and it is judged whether to optimize the internal network penetration of the enterprise network to be tested, if not, the penetration testing is continued until the penetration testing is ended, otherwise, the penetration testing is continued after the internal network penetration optimization until the penetration testing is ended; through the evaluation of the internal network penetration process and the internal network penetration optimization, the penetration effect of the internal network penetration in the penetration testing is improved, the penetration testing is more in-depth, and it is beneficial to find more network risks in the enterprise network to be tested.
[0025] In the embodiment, the internal network of the enterprise usually includes multiple subnets, servers, workstations and databases, and the traffic and security protection measures between each subnet may be different. The penetration testing tool may not be able to adapt to these complex network configurations, resulting in incorrect scanning of all devices and thus false negatives. Enterprise networks usually use security devices to limit the access of internal network traffic, which may filter or block requests from penetration testing tools, resulting in false negatives. The network topology of the internal network environment of the enterprise may use segmented isolation or other access control strategies, thereby increasing the difficulty of lateral movement for penetration testers; the security device in the present application includes but is not limited to firewall, intrusion detection system / intrusion prevention system (Intrusion Detection System / Intrusion Prevention System, IDS / IPS) and virtual private network (Virtual Private Network, VPN).
[0026] In the present application, through the above steps, the penetration test ensures that the penetration test covers all aspects of the enterprise network as comprehensively and effectively as possible, which is conducive to discovering potential vulnerabilities and improving the effectiveness of the security measures of the enterprise network, and ensures the effectiveness and depth of the penetration test.
[0027] Further, the vulnerability scanning effectiveness is evaluated based on the parameters in the preliminary vulnerability scanning process, and the specific method is as follows:
[0028] The scanning completion rate in the preliminary vulnerability scanning process is compared with the preset scanning completion rate obtained from the preset database, and the scanning completion rate comparison coefficient is obtained, that is, ; in the formula, The scanning completion rate in the preliminary vulnerability scanning process is compared with the preset scanning completion rate obtained from the preset database, and the scanning completion rate comparison coefficient is obtained, that is, The scanning completion rate in the preliminary vulnerability scanning process is compared with the preset scanning completion rate obtained from the preset database, and the scanning completion rate comparison coefficient is obtained, that is,
[0029] The security device bypassing coefficient in the preliminary vulnerability scanning process is compared with the preset security device bypassing coefficient obtained from the preset database, and the security device bypassing coefficient comparison coefficient is obtained, that is, ; in the formula, The security device bypassing coefficient in the preliminary vulnerability scanning process is compared with the preset security device bypassing coefficient obtained from the preset database, and the security device bypassing coefficient comparison coefficient is obtained, that is, The security device bypassing coefficient in the preliminary vulnerability scanning process is compared with the preset security device bypassing coefficient obtained from the preset database, and the security device bypassing coefficient comparison coefficient is obtained, that is,
[0030] The extreme value influence deviation processing is performed on the penetration scanning time length in the preliminary vulnerability scanning process and the penetration scanning time length preset parameter obtained from the preset database, as a penetration scanning time length deviation coefficient. The penetration scanning time length preset parameter includes a preset minimum penetration scanning time length and a preset maximum penetration scanning time length. The penetration scanning time length is represented by the difference between the end time and the start time of the vulnerability scanning in the penetration test recorded by the scanning log. The preset scanning completion rate, the preset security device bypass coefficient, the preset minimum penetration scanning time length and the preset maximum penetration scanning time length are set by the preset personnel. By comparing the actual and preset penetration scanning time length, the rationality of the vulnerability scanning is evaluated. If the scanning time is too long or too short, it may mean that the coverage or depth of the scanning has a problem, which affects the accuracy of the vulnerability scanning result.
[0031] The specific limit expression of the penetration scanning time length deviation coefficient is:
[0032] ;
[0033] In the formula, represents the penetration scanning time length deviation coefficient, represents the penetration scanning time length, represents the preset minimum penetration scanning time length, represents the preset maximum penetration scanning time length.
[0034] The penetration scanning time length deviation coefficient is subjected to inverse proportional operation to obtain a penetration scanning time length deviation inverse coefficient. The vulnerability scanning effectiveness evaluation adjustment factor is introduced to perform assignment coupling processing on the scanning completion rate comparison coefficient, the security device bypass coefficient comparison coefficient and the penetration scanning time length deviation inverse coefficient, as a vulnerability scanning effectiveness evaluation index. The vulnerability scanning effectiveness evaluation index is used to quantitatively evaluate the effectiveness of the vulnerability scanning in the penetration test, to ensure the efficiency of the penetration test.
[0035] The specific limit expression of the vulnerability scanning effectiveness evaluation index is:
[0036] ;
[0037] In the formula, represents the vulnerability scanning effectiveness evaluation index in the preliminary vulnerability scanning process, represents the penetration scanning time length deviation coefficient in the preliminary vulnerability scanning process, represents a first vulnerability scanning effectiveness evaluation adjustment factor, represents a second vulnerability scanning effectiveness evaluation adjustment factor, represents a third vulnerability scanning effectiveness evaluation adjustment factor.
[0038] The vulnerability scanning effectiveness evaluation adjustment factor is obtained from a preset database, and specifically includes a first vulnerability scanning effectiveness evaluation adjustment factor, a second vulnerability scanning effectiveness evaluation adjustment factor, and a third vulnerability scanning effectiveness evaluation adjustment factor, which respectively represent the influence degree of the corresponding parameters in the preliminary vulnerability scanning process on the vulnerability scanning effectiveness evaluation index; the sum of the three is 1. For example, the parameters in the preliminary vulnerability scanning process and the corresponding preset vulnerability scanning effectiveness evaluation adjustment factors form a corresponding vulnerability scanning effectiveness evaluation mapping set, respectively input the real-time parameters in the preliminary vulnerability scanning process into the corresponding vulnerability scanning effectiveness evaluation mapping set, and obtain the corresponding vulnerability scanning effectiveness evaluation adjustment factor. The vulnerability scanning effectiveness evaluation mapping set includes a first vulnerability scanning effectiveness evaluation mapping set, a second vulnerability scanning effectiveness evaluation mapping set, and a third vulnerability scanning effectiveness evaluation mapping set.
[0039] In the embodiment, the higher the security device bypassing coefficient is, the higher the scanning completion rate is. If the penetration testing tool can bypass the security device, more target areas and ports can be scanned, thereby improving the scanning completion rate. The greater the penetration scanning time deviation coefficient is, the more likely it is that all attack surfaces of the enterprise network to be tested cannot be covered, especially in the case of complex network topology. The greater the penetration scanning time deviation coefficient is, the more likely it is that all scanning tasks cannot be completed, thereby resulting in a lower scanning completion rate. The greater the security device bypassing coefficient is, the more likely it is to reduce the penetration scanning time deviation coefficient. Bypassing the security device can enable the penetration testing tool to proceed smoothly and avoid interrupting the vulnerability scanning due to detection of malicious traffic, thereby saving the time required for repeated scanning.
[0040] Through the above steps, the effectiveness of vulnerability scanning in penetration testing is comprehensively quantified, which is conducive to timely identifying potential problems in the vulnerability scanning process and optimizing the process, thereby improving the effectiveness of subsequent penetration testing and providing a more reliable security evaluation result for the security of the enterprise network to be tested.
[0041] As Figure 3As shown, the flowchart of the vulnerability scanning optimization provided by the embodiment of the present application, the specific logic is: judging whether to perform vulnerability scanning optimization on the enterprise network to be tested, if the vulnerability scanning effective evaluation index is less than the first preset vulnerability scanning effective evaluation threshold, directly prompting the preset personnel of vulnerability scanning error, otherwise if the vulnerability scanning effective evaluation index is less than the second preset vulnerability scanning effective evaluation threshold obtained from the preset database, performing vulnerability scanning optimization on the enterprise network to be tested, otherwise performing segmented processing on the enterprise network to be tested, and directly performing intranet penetration on the enterprise network to be tested based on the obtained scanning vulnerabilities; if the vulnerability scanning effective evaluation index after the first vulnerability scanning optimization is less than the second preset vulnerability scanning effective evaluation threshold obtained from the preset database, performing second vulnerability scanning optimization on the enterprise network to be tested, otherwise ending the vulnerability scanning optimization; if the vulnerability scanning effective evaluation index after the second vulnerability scanning optimization is less than the second preset vulnerability scanning effective evaluation threshold, prompting the preset personnel of vulnerability scanning optimization failure, otherwise ending the vulnerability scanning optimization; after the vulnerability scanning optimization ends, using the penetration testing tool to perform vulnerability scanning, obtaining the scanning vulnerabilities in the enterprise network to be tested, and performing intranet penetration on the enterprise network to be tested based on the obtained scanning vulnerabilities.
[0042] Specifically, judging whether to perform vulnerability scanning optimization on the enterprise network to be tested, the specific process is as follows:
[0043] A1, if the vulnerability scanning effective evaluation index is less than the first preset vulnerability scanning effective evaluation threshold obtained from the preset database, directly prompting the preset personnel of vulnerability scanning error, otherwise executing A2.
[0044] It can be understood that through the judgment of the first preset vulnerability scanning effective evaluation threshold, the problem of insufficient scanning effect in the vulnerability scanning process can be found in time, avoiding further invalid vulnerability scanning, and improving the work efficiency of vulnerability scanning.
[0045] A2, if the vulnerability scanning effective evaluation index is less than the second preset vulnerability scanning effective evaluation threshold obtained from the preset database, performing vulnerability scanning optimization on the enterprise network to be tested, and executing A3, otherwise performing segmented processing on the enterprise network to be tested, and directly performing intranet penetration on the enterprise network to be tested based on the obtained scanning vulnerabilities; the first preset vulnerability scanning effective evaluation threshold and the second preset vulnerability scanning effective evaluation threshold are set by the preset personnel.
[0046] It can be understood that through the judgment of the second preset vulnerability scanning effective evaluation threshold, it can be further determined whether to perform vulnerability scanning optimization on the enterprise network to be tested, which is beneficial to improve the accuracy and comprehensiveness of vulnerability scanning.
[0047] It needs to be further understood that the vulnerability scanning optimization includes a first vulnerability scanning optimization and a second vulnerability scanning optimization, the first vulnerability scanning optimization represents regional division and segmented inspection on the enterprise network to be tested to improve the overall quality of vulnerability scanning, and the second vulnerability scanning optimization represents adjusting the scanning strategy according to the network topology to improve the effectiveness of vulnerability scanning.
[0048] The specific process of the first vulnerability scanning optimization is as follows:
[0049] The segmented processing of the enterprise network to be tested represents that the enterprise network to be tested is divided into a preset number of enterprise network regions to be tested, and each enterprise network region to be tested is subjected to segmented scanning; the preset number is set by a preset person. Through segmented parallel processing, the pertinence of vulnerability scanning can be improved, unnecessary scanning range can be reduced, the influence of vulnerability scanning on network performance can be reduced, thereby the efficiency and comprehensiveness of vulnerability scanning are improved, the omission that may occur due to one-time scanning of the entire enterprise network to be tested is avoided, and the accuracy and integrity of vulnerability scanning are improved.
[0050] The initial scanning rate is corrected according to the scanning rate correction factor to obtain a corrected scanning rate, and the corrected scanning rate represents a correction result of the product operation based on the initial scanning rate and the scanning rate correction factor. The specific steps of correction in the present application are product operation; the scanning rate correction factor is obtained by inputting the penetration scanning time length and the vulnerability scanning effective evaluation deviation coefficient into the scanning rate correction mapping set, the vulnerability scanning effective evaluation deviation coefficient is obtained by relative deviation processing of the vulnerability scanning effective evaluation index and the second preset vulnerability scanning effective evaluation threshold, and the scanning rate correction mapping set is a set representing the mapping relationship among the penetration scanning time length, the vulnerability scanning effective evaluation deviation coefficient and the scanning rate correction factor, which is obtained from a preset database. By correcting the initial scanning rate, the scanning speed can be dynamically adjusted according to the actual situation in the scanning process, thereby the efficiency and quality of vulnerability scanning are improved, and the vulnerability scanning process is more flexible and adaptive to different network environments; through the calculation of the scanning rate correction factor, the actual situation in the vulnerability scanning process can be more comprehensively reflected, thereby providing a more accurate basis for the correction of the initial scanning rate.
[0051] If the vulnerability scan effective evaluation index after the scan rate correction is less than the vulnerability scan effective evaluation index, the initial scan rate is restored, and a preset proportion of the corrected scan rate is taken as the scan rate adjustment amount, the initial scan rate is adjusted according to the scan rate adjustment amount, otherwise the current scan rate is maintained, and the judgment whether to perform vulnerability scan optimization on the enterprise network to be tested is continued; the preset proportion is set by the preset personnel. It should be understood that when it is found that the vulnerability scan effective evaluation index after the scan rate correction does not meet the requirements, the initial scan rate is restored in time, avoiding the decline of the vulnerability scan quality caused by the wrong correction, and at the same time, by taking the preset proportion of the corrected scan rate as the adjustment amount to adjust the initial scan rate, the beneficial information in the correction process can be retained to a certain extent, a more suitable scan rate is gradually explored, the stability and reliability of the vulnerability scan are improved, and finally the optimization of the scan efficiency and effect is realized.
[0052] A3, if the vulnerability scan effective evaluation index after the first vulnerability scan optimization is less than the second preset vulnerability scan effective evaluation threshold value obtained from the preset database, the second vulnerability scan optimization is performed on the enterprise network to be tested, and A4 is executed, otherwise the vulnerability scan optimization is ended.
[0053] It should be noted that the second vulnerability scan optimization means that the scan strategy is adaptively adjusted according to the topology of the enterprise network to be tested; the scan strategy includes a low-speed scan strategy, a packet camouflage strategy and a protocol confusion strategy, and the specific process is as follows:
[0054] D1, when the first scan strategy condition is met, that is, the penetration testing tool detects a security device, and the response time of the enterprise network to be tested is less than the preset response time of the enterprise network to be tested obtained from the preset database, the low-speed scan strategy is adopted, and D4 is executed, otherwise D2 is executed. Wherein, the ping command is input in the command line window (Windows) or terminal (Linux / MacOS), followed by the IP address or domain name of the server, for example, ping 192.168.1.1 or ping http: / / www.example.com, after waiting for a period of time, the command will display the average response time, and the response time of the enterprise network to be tested is represented by the average response time; the preset response time of the enterprise network to be tested is set by the preset personnel. In addition, the low-speed scan strategy means that the vulnerability scan is performed according to the twice corrected scan rate, the twice corrected scan rate is obtained by correcting the corrected scan rate by the response time of the enterprise network to be tested, and the response time of the enterprise network to be tested is obtained by comparing the response time of the enterprise network to be tested and the preset response time of the enterprise network to be tested.
[0055] It can be understood that the low-speed scanning can reduce the impact on the enterprise network to be tested, avoid being intercepted by the security device due to the greater scanning traffic being identified as an attack behavior, and adapt to the faster network response to ensure that the scanning process will not cause network congestion or affect normal business due to the faster scanning rate. By twice modifying the scanning rate, the actual situation of the current network can be more accurately matched, and the accuracy and stability of the vulnerability scanning are improved.
[0056] D2, when the second scanning strategy condition is met, that is, the port connection request frequency is greater than the preset port connection request frequency obtained from the preset database, and the number of connection request rejections recorded in the firewall log is greater than the preset connection request rejection number obtained from the preset database, the packet camouflage strategy is adopted, and D4 is executed, otherwise D3 is executed. Wherein, the port connection request frequency is obtained by counting the number of connection requests of the preset port in a unit time through network tools such as Wireshark and Ntop; the number of rejected connection requests can be counted by checking the firewall log such as / var / log / messages file, or using the command dmesg|grep -i REJECT|grep DPT=port number (for example, dmesg|grep -i REJECT|grep DPT=9200); the unit time in the present application refers to 1 second; the preset port connection request frequency, the preset connection request rejection number and the preset port are set by the preset personnel. In addition, the packet camouflage strategy means modifying the header information of the data packet (such as source IP address, target port number, protocol type, identification bit, etc.) and camouflaging the scanning traffic (such as camouflaging the HTTP traffic as normal web requests, and camouflaging the scanning request as a legal domain name system request); the source IP address (Source IP Address) refers to the Internet Protocol address (Internet Protocol Address, IP address) used by the sender (i.e. the source) of the data packet in network communication.
[0057] It can be understood that the packet camouflage strategy can make the scanning traffic look more like normal network traffic, thereby bypassing the detection of the security device, improving the success rate of vulnerability scanning, and obtaining more information about the enterprise network to be tested; thereby improving the effectiveness of vulnerability scanning in penetration testing.
[0058] D3, when the third scanning strategy condition is met, that is, the protocol used for scanning traffic is within the preset protocol range, and the traffic request frequency is greater than the preset traffic request frequency obtained from the preset database, the protocol obfuscation strategy is adopted, and D4 is executed, otherwise the preset personnel is prompted that the scanning strategy selection fails. Wherein, the preset protocol range includes but is not limited to HyperText Transfer Protocol (HTTP), Domain Name System (DNS), Simple Mail Transfer Protocol (SMTP); the traffic request frequency is represented by the number of traffic requests per unit time, which is counted by a network monitoring tool (such as Zabbix, Nagios or SolarWinds, etc.); the preset traffic request frequency is set by the preset personnel. In addition, the protocol obfuscation strategy means to camouflage the protocol used for scanning traffic; the specific implementation method is: HTTP camouflage: camouflage the scanning traffic as HTTPS request, camouflage the protocol header and request method of the scanning packet, so that the traffic is not easily identified in the inspection of firewall or IDS / IPS; DNS camouflage: use fake DNS query traffic for scanning, and camouflage the malicious scanning packet as normal DNS request.
[0059] It can be understood that, by adopting the protocol obfuscation strategy, the scanning behavior can be further hidden, and the abnormal traffic is avoided to be identified by the security device in the enterprise network to be tested, thereby improving the concealment and effectiveness of the vulnerability scanning.
[0060] D4, after the scanning strategy is executed, if the penetration scanning duration is greater than the preset maximum penetration scanning duration obtained from the preset database, the scanning task is allocated according to the preset parallel scanning number, otherwise the vulnerability scanning optimization is ended.
[0061] Wherein, the preset parallel scanning number is obtained by mapping the current penetration scanning duration relative deviation coefficient and the vulnerability scanning effective evaluation deviation coefficient into the parallel scanning number mapping set, and the parallel scanning number mapping set is a set representing the mapping relationship between the current penetration scanning duration relative deviation coefficient, the vulnerability scanning effective evaluation deviation coefficient and the preset parallel scanning number obtained from the preset database.
[0062] A4, if the vulnerability scanning effective evaluation index after the second vulnerability scanning optimization is less than the second preset vulnerability scanning effective evaluation threshold value obtained from the preset database, the preset personnel is prompted that the vulnerability scanning optimization fails, otherwise the vulnerability scanning optimization is ended.
[0063] After the vulnerability scanning optimization is completed, the vulnerability scanning is performed using the penetration testing tool to obtain the scanning vulnerabilities in the enterprise network to be tested, and the internal network penetration of the enterprise network to be tested is performed based on the obtained scanning vulnerabilities.
[0064] In the embodiment, through the above steps, the gradual judgment and optimization can timely find the problem of poor vulnerability scanning effect in the penetration test, thereby ensuring the penetration effect of the penetration testing tool, optimizing the overall scanning effect of the vulnerability scanning in the penetration test, improving the effectiveness and precision of the vulnerability scanning in the penetration test, and further providing more accurate data for subsequent internal network penetration.
[0065] Further, the internal network penetration effectiveness is evaluated based on the parameters in the internal network penetration process, and the specific method is as follows:
[0066] The internal network penetration effectiveness evaluation index is obtained by introducing the vulnerability scanning effectiveness evaluation index and correcting the internal network penetration effectiveness evaluation coefficient. The internal network penetration effectiveness evaluation coefficient is obtained by introducing the internal network penetration effectiveness evaluation adjustment factor, and performing value coupling processing on the internal network penetration evaluation comparison coefficient and the security device interception rate inverse comparison coefficient. The internal network penetration effectiveness evaluation index represents the correction result of the product operation based on the internal network penetration effectiveness evaluation coefficient and the vulnerability scanning effectiveness evaluation index, and is used for quantitatively evaluating the effectiveness of the internal network penetration in the penetration test to ensure the comprehensiveness of the penetration test.
[0067] The internal network penetration evaluation comparison coefficient is obtained by comparing the parameters in the internal network penetration process and the corresponding preset internal network penetration parameters obtained from the preset database, and specifically includes a horizontal movement success rate comparison coefficient and a horizontal movement time comparison coefficient; the preset internal network penetration parameters and the preset security device interception rate are set by preset personnel; the preset internal network penetration parameters include a preset horizontal movement success rate and a preset horizontal movement time.
[0068] The horizontal movement success rate comparison coefficient is obtained by comparing the horizontal movement success rate in the internal network penetration process and the preset horizontal movement success rate obtained from the preset database, that is, ; in the formula, represents the horizontal movement success rate of the nth enterprise network region to be tested in the internal network penetration process, which is obtained by simulating horizontal movement by the penetration testing tool, counting the number of successful horizontal movements and the total number of attempts, and performing ratio operation on the number of successful horizontal movements and the total number of attempts to obtain the horizontal movement success rate; represents the preset horizontal movement success rate; by comparing the actual and preset horizontal movement success rates, the penetration range in the internal network penetration process in the penetration test is reflected.
[0069] The transverse movement time contrast coefficient is obtained by contrast processing of the transverse average movement time in the internal network penetration process and the preset transverse movement time obtained from the preset database, that is, ; in the formula, represents the transverse average movement time of the nth enterprise network region to be tested in the internal network penetration process, the average time required for the attacker to perform transverse movement is calculated by checking the activity time interval of the attacker through the access log; represents the preset transverse movement time; by comparing the actual and preset transverse movement times, the efficiency of internal network penetration in penetration testing is reflected.
[0070] The security device interception rate inverse contrast coefficient is obtained by inverse contrast processing of the security device interception rate in the internal network penetration process and the preset security device interception rate obtained from the preset database, that is, ; in the formula, represents the security device interception rate of the nth enterprise network region to be tested in the internal network penetration process, the success rate of security device interception is calculated by recording the number of interception events of the security device, and it is set that the security device interception rate is not 0, by analyzing the logs of devices such as firewalls, intrusion detection systems / intrusion prevention systems (IDS / IPS) and checking whether the behavior of the attacker is successfully intercepted; represents the preset security device interception rate; by comparing the actual and preset security device interception rates, the network security protection strength of the internal network in the enterprise network to be tested is reflected.
[0071] In summary, the specific limit expression of the internal network penetration effectiveness evaluation index is:
[0072] ;
[0073] In the formula, n is the number of the enterprise network region to be tested, N is the total number of the enterprise network region to be tested, represents the internal network penetration effectiveness evaluation index of the nth enterprise network region to be tested in the internal network penetration process, represents the vulnerability scanning effective evaluation index, represents the first internal network penetration effectiveness evaluation adjustment factor, represents the second internal network penetration effectiveness evaluation adjustment factor, represents the third internal network penetration effectiveness evaluation adjustment factor.
[0074] The internal network penetration effectiveness evaluation adjustment factor is obtained from a preset database, and specifically includes a first internal network penetration effectiveness evaluation adjustment factor, a second internal network penetration effectiveness evaluation adjustment factor, and a third internal network penetration effectiveness evaluation adjustment factor, which respectively represent the influence degree of the corresponding parameter in the internal network penetration process on the internal network penetration effectiveness evaluation index; the sum of the three is 1. For example, the corresponding internal network penetration effectiveness evaluation mapping set is formed by the corresponding parameter in the internal network penetration process and the corresponding preset internal network penetration effectiveness evaluation adjustment factor. The real-time parameter in the internal network penetration process is input into the corresponding internal network penetration effectiveness evaluation mapping set to obtain the corresponding internal network penetration effectiveness evaluation adjustment factor. The internal network penetration effectiveness evaluation mapping set includes a first internal network penetration effectiveness evaluation mapping set, a second internal network penetration effectiveness evaluation mapping set, and a third internal network penetration effectiveness evaluation mapping set.
[0075] In the embodiment, the higher the interception rate of the security device, the lower the lateral movement success rate. If the security device can effectively prevent the lateral movement of the attacker, the penetration of the attacker in the network will be greatly limited. The higher the lateral movement success rate, the more internal networks the attacker can quickly penetrate in the enterprise network to be tested, increasing the control over the network and reducing the penetration time. Generally, it means that there are fewer isolation or protection measures in the network, and the attacker can quickly penetrate laterally, thereby reducing the average lateral movement time. The higher the interception rate of the security device, the lower the lateral movement success rate, because the security device can identify and block the lateral penetration behavior of the attacker.
[0076] By introducing the correction coefficient and the adjustment factor, the actual effect of the internal network penetration process in the penetration test can be more accurately reflected. Through the above steps, the effectiveness of the internal network penetration in the penetration test is comprehensively quantitatively evaluated, which is beneficial to timely identifying potential problems in the internal network penetration process and optimizing the internal network penetration, thereby improving the effectiveness of the internal network penetration and better identifying the weak links of the security protection of the enterprise network to be tested.
[0077] Further, whether to optimize the internal network penetration of the enterprise network to be tested is determined, and the specific process is as follows:
[0078] B1, if the internal network penetration effectiveness evaluation index is less than a first preset internal network penetration effectiveness evaluation threshold value obtained from a preset database, a preset personnel is prompted that the internal network penetration fails, otherwise, B2 is executed. The first preset internal network penetration effectiveness evaluation threshold value and a second preset internal network penetration effectiveness evaluation threshold value are set by the preset personnel. The comparison with the first preset internal network penetration effectiveness evaluation threshold value can timely find the problems in the internal network penetration process, timely prompt the preset personnel that the internal network penetration fails, avoid unnecessary subsequent operations, and save time and resources.
[0079] B2, if the internal network penetration effectiveness evaluation index is less than a second preset internal network penetration effectiveness evaluation threshold obtained from the preset database, performing internal network penetration optimization on the enterprise network to be tested, and performing B3, otherwise, directly continuing the penetration test until the penetration test is completed. The comparison with the second preset internal network penetration effectiveness evaluation threshold, if the internal network penetration optimization is performed, the efficiency of the penetration test can be improved, and more potential vulnerabilities can be found, otherwise, the penetration test is directly continued, unnecessary optimization operations can be avoided, and the process of the penetration test can be accelerated.
[0080] It should be further understood that the internal network penetration optimization includes a first internal network penetration optimization and a second internal network penetration optimization.
[0081] The first internal network penetration optimization means setting a scanning order and a corresponding scanning mode to improve the efficiency of the penetration test, and the specific process is as follows:
[0082] C1, inputting the internal network penetration effectiveness evaluation index corresponding to the region of the enterprise network to be tested and the corresponding encryption level (set by the preset personnel) into a preset scanning priority mapping set to obtain a corresponding scanning priority, setting a scanning order according to the scanning priority, and the region of the enterprise network to be tested with the largest scanning priority is scanned first; the preset scanning priority mapping set is a set obtained from the preset database and representing the mapping relationship among the internal network penetration effectiveness evaluation index, the corresponding encryption level, and the scanning priority.
[0083] C2, if the scanning priority corresponding to the region of the enterprise network to be tested is higher than a first preset scanning priority obtained from the preset database, performing a first scan, otherwise, performing C3; the first scan means performing a vulnerability scan according to a first scan rate and a first scan depth; the first preset scanning priority, the first scan rate, and the first scan depth are set by the preset personnel.
[0084] C3, if the scanning priority corresponding to the region of the enterprise network to be tested is lower than a second preset scanning priority obtained from the preset database, performing a second scan, otherwise, keeping the current scanning parameters unchanged; the second scan means performing a vulnerability scan according to a second scan rate and a second scan depth; the scanning parameters include the scan rate and the scan depth; the second preset scanning priority, the second scan rate, and the second scan depth are set by the preset personnel.
[0085] It can be understood that, according to the scanning priority of the region, the key vulnerabilities can be found first, the efficiency and effect of the penetration test are improved, and the most important enterprise network region to be tested is fully checked in a limited scanning time; the higher the scanning priority, the higher the security risk or the higher the importance of the enterprise network region to be tested, the first scanning rate and the first scanning depth can more accurately and deeply find vulnerabilities, and timely measures are taken to repair and reduce security risks; the lower the scanning priority, the lower the security risk or the smaller the importance of the enterprise network region to be tested, the second scanning rate and the second scanning depth can reduce the occupation of network resources in the enterprise network region to be tested under the premise of ensuring a certain scanning effect, and improve the overall efficiency of vulnerability scanning.
[0086] B3, if the first internal network penetration optimization internal network penetration effectiveness evaluation index is less than the second preset internal network penetration effectiveness evaluation threshold value obtained from the preset database, the second internal network penetration optimization is performed on the enterprise network to be tested, and B4 is executed, otherwise the internal network penetration optimization is ended.
[0087] The second internal network penetration optimization represents that the time management and control of the horizontal movement operation are performed to ensure the safety of the penetration test process, and the specific process is as follows:
[0088] D1, the maximum horizontal movement time is obtained by correcting the horizontal movement time according to the internal network penetration effectiveness evaluation deviation coefficient, and the internal network penetration effectiveness evaluation deviation coefficient is obtained by relative deviation processing of the internal network penetration effectiveness evaluation index and the second preset internal network penetration effectiveness evaluation threshold value. The obtained maximum horizontal movement time can more reasonably control the time length of the horizontal movement operation to adapt to the actual situation, avoid the horizontal movement operation time being too long, increase the risk detected by the enterprise network to be tested, and improve the success rate and efficiency of the horizontal movement;
[0089] D2, if the horizontal movement time of the current horizontal movement operation is not less than the maximum horizontal movement time, the current horizontal movement operation is stopped, and the horizontal movement operation is re-performed after the preset operation interval ends, otherwise D3 is executed; the preset operation interval is set by the preset personnel. Through the setting of the preset operation interval, the operation frequency can be reduced, the horizontal movement behavior is closer to the normal user operation, and the concealment of the penetration test is improved.
[0090] D3, if the current horizontal movement operation is ended, the next horizontal movement operation is performed after the preset operation interval ends, otherwise the current horizontal movement operation is continued.
[0091] B4, if the second internal network penetration optimization effective evaluation index is less than the second preset internal network penetration effective evaluation threshold obtained from the preset database, prompting the preset personnel that the internal network penetration optimization fails, otherwise ending the internal network penetration optimization; after the internal network penetration optimization ends, continue the penetration test until the penetration test ends.
[0092] In the embodiment, by the above steps, unnecessary penetration test or optimization operation is avoided, and the efficiency and accuracy of internal network penetration in penetration test are improved, vulnerabilities can be found faster, and potential losses caused by security vulnerabilities are reduced; thus, the concealment in the internal network penetration process in penetration test is improved, and the effectiveness of penetration test is realized.
[0093] Further, continuing the penetration test further includes clearing the penetration operation traces and the vulnerability detection report.
[0094] Clearing the penetration operation traces means that a preset identifier corresponding to a marking type is used to mark the penetration operation traces generated in the penetration test process, so that the penetration operation traces can be located and deleted more conveniently in subsequent penetration operation trace cleaning, and the penetration operation trace cleaning order is set according to the scanning priority, and the penetration operation traces of the enterprise network region to be tested with the largest scanning priority are cleaned first.
[0095] For example, in the log marking, identifiers such as #OPTIMIZATION_TAG# or #TESTER_ID# can be added to the log files for scanning logs and operation logs; when performing horizontal movement, special marks such as #MOVED# or #TEST_OPERATION# can be embedded in the metadata of the file when modifying the command history and file access record.
[0096] The vulnerability detection report includes the evaluation result, the executed optimization measures, the discovered vulnerabilities, the exploited vulnerabilities, the influence of the vulnerabilities, and the repair suggestions.
[0097] In the embodiment, by the above steps, the penetration tester can effectively hide the vulnerability test activity and avoid arousing the vigilance of the enterprise network to be tested; by recording the discovered vulnerabilities, the exploited vulnerabilities, the influence of the vulnerabilities, and the repair suggestions in detail in the test, the enterprise network to be tested can identify and repair network security problems, improve the overall protection level of the enterprise network to be tested, and improve the effectiveness of the penetration test.
[0098] As an embodiment of the second aspect, the embodiment of the present application provides a device for penetration test of network information system security evaluation, which applies the penetration test method for network information system security evaluation, and includes a data acquisition device, a storage device, and a processing device.
[0099] The data collection device is used to collect the preliminary scan vulnerability in the enterprise network to be tested, the parameters in the preliminary vulnerability scanning process and the parameters in the internal network penetration process; the parameters are collected by the penetration testing tool; the data collection device collects the data in the penetration testing process in real time, and provides basic data for subsequent analysis and evaluation.
[0100] The storage device is used to store the preliminary scan vulnerability in the enterprise network to be tested, the parameters in the preliminary vulnerability scanning process and the parameters in the internal network penetration process, and also includes storage of corresponding historical data; the storage device stores the data collected by the data collection device, provides data access and management services, not only saves the real-time collected data, but also records the historical data of each penetration test, so as to perform subsequent trend analysis, optimization evaluation and comparative analysis.
[0101] The processing device is used for calculation of the scan coverage deviation result of the enterprise network to be tested, vulnerability scanning effectiveness evaluation based on the parameters in the preliminary vulnerability scanning process, vulnerability scanning optimization, internal network penetration effectiveness evaluation based on the parameters in the internal network penetration process and internal network penetration optimization; the processing device obtains data from the storage device, performs data analysis, evaluation and optimization, and stores the optimized parameters and evaluation results in the storage device again for historical data comparison in the subsequent penetration testing process; the processing device performs real-time evaluation of the effectiveness in the vulnerability scanning and internal network penetration testing process, thereby ensuring the integrity, accuracy and efficiency of the penetration testing; and according to the evaluation result, it is determined whether to optimize the vulnerability scanning link and the internal network penetration testing link of the penetration testing, thereby improving the efficiency of the penetration testing; the data collection device, the storage device and the processing device are associated with each other through data collection, storage, processing and analysis, and cooperate to complete various tasks in the penetration testing process.
[0102] In summary, the embodiment of the present application obtains the scan coverage deviation result of the enterprise network to be tested through preliminary vulnerability scanning, judges whether to perform vulnerability scanning effectiveness evaluation, ensures the coverage rate of vulnerability scanning, further judges whether to perform vulnerability scanning optimization on the enterprise network to be tested, improves the vulnerability scanning effectiveness, finally performs internal network penetration effectiveness evaluation based on the parameters in the internal network penetration process, and judges whether to perform internal network penetration optimization on the enterprise network to be tested, improves the penetration effect of the penetration testing, and effectively solves the problem of low penetration detection effectiveness caused by incomplete vulnerability scanning in the prior art.
[0103] Those skilled in the art will appreciate that embodiments of the present application can be devised for a variety of applications. It is intended that the present application be limited only by the scope of the appended claims, and it is intended that various modifications and alterations made by those skilled in the art be considered as within the scope of the present application. The embodiments of the present application will be described with reference to the attached drawings, wherein:
[0104] The present application is described in reference to the drawings using a flowchart and / or a block diagram of the method, apparatus (system) and computer program product according to embodiments of the application. It will be understood that each block of the flowchart and / or block diagram, and combinations of blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general purpose computer, special purpose computer, embedded processing device or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions specified in the flowchart and / or block diagram block or blocks. Figure 1 one or more functions specified in the flowchart and / or block diagram block or blocks. Figure 1 means for performing each of the functions specified in the flowchart and / or block diagram block or blocks.
[0105] These computer program instructions can also be stored in a computer- readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including instructions which implement the function specified in the flowchart and / or block diagram block or blocks. Figure 1 one or more functions specified in the flowchart and / or block diagram block or blocks. Figure 1 means for performing each of the functions specified in the flowchart and / or block diagram block or blocks.
[0106] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart and / or block diagram block or blocks. Figure 1 one or more functions specified in the flowchart and / or block diagram block or blocks. Figure 1 means for performing each of the functions specified in the flowchart and / or block diagram block or blocks.
[0107] While the preferred embodiments of the application have been described, additional variations and modifications can be made to the embodiments by those skilled in the art once they learn of the basic inventive concepts. Therefore, the appended claims are intended to cover all such modifications and alterations as fall within the true spirit and scope of the application.
[0108] Obviously, many modifications and variations of the present application are possible in light of the above teachings. It is, therefore, to be understood that within the scope of the appended claims and their equivalents, the application can be practiced otherwise than as specifically described.
Claims
1. A penetration testing method for security assessment of network information systems, characterized in that, Includes the following steps: S1. Use penetration testing tools to perform a preliminary vulnerability scan of the network of the enterprise to be tested, obtain the preliminary scan vulnerabilities in the network of the enterprise to be tested, and obtain the scan coverage deviation results of the network of the enterprise to be tested based on the preliminary vulnerability scan. S2, determine whether to perform a vulnerability scan effectiveness assessment based on the parameters obtained during the initial vulnerability scan. If no vulnerability scan effectiveness assessment is performed, prompt the preset personnel to reselect the penetration testing tool. Otherwise, further determine whether to optimize the vulnerability scan of the enterprise network to be tested. If so, perform a vulnerability scan after optimization to obtain the scanning vulnerabilities in the enterprise network to be tested, and perform internal network penetration based on the obtained scanning vulnerabilities. Otherwise, perform internal network penetration based on the obtained initial scanning vulnerabilities. S3 evaluates the effectiveness of intranet penetration based on parameters during the intranet penetration process and determines whether to optimize the intranet penetration of the enterprise network to be tested. If intranet penetration optimization is not performed, the penetration test continues until the penetration test ends; otherwise, the penetration test continues after intranet penetration optimization until the penetration test ends.
2. The penetration testing method for network information system security assessment as described in claim 1, characterized in that: The method for evaluating the effectiveness of vulnerability scanning based on parameters from the initial vulnerability scanning process is as follows: The scan completion rate during the initial vulnerability scan process is compared with the preset scan completion rate obtained from the preset database, and used as the scan completion rate comparison coefficient. The security device bypass coefficient during the initial vulnerability scanning process is compared with the preset security device bypass coefficient obtained from the preset database, and the comparison coefficient is used as the security device bypass coefficient comparison coefficient. The security device bypass coefficient reflects the bypass of security devices recorded in the scan log. The penetration scan duration during the initial vulnerability scanning process and the preset penetration scan duration parameter obtained from the preset database are subjected to extreme value influence deviation processing, which is used as the penetration scan duration deviation coefficient. The preset penetration scan duration parameter includes a preset minimum penetration scan duration and a preset maximum penetration scan duration. The inverse coefficient of permeation scan duration deviation is obtained by performing an inverse proportional operation on the permeation scan duration deviation coefficient. A vulnerability scanning effectiveness evaluation adjustment factor is introduced, which assigns values to the scan completion rate comparison coefficient, the security device bypass coefficient comparison coefficient, and the penetration scan duration deviation inverse coefficient, and serves as a vulnerability scanning effectiveness evaluation index. This vulnerability scanning effectiveness evaluation index is used to quantitatively evaluate the effectiveness of vulnerability scanning in penetration testing, so as to ensure the efficiency of penetration testing.
3. The penetration testing method for network information system security assessment as described in claim 2, characterized in that: The specific process for determining whether to perform vulnerability scanning and optimization on the network of the enterprise to be tested is as follows: A1. If the vulnerability scan effective evaluation index is less than the first preset vulnerability scan effective evaluation threshold obtained from the preset database, the preset personnel will be directly prompted that the vulnerability scan is wrong; otherwise, A2 will be executed. A2. If the vulnerability scanning effective evaluation index is less than the second preset vulnerability scanning effective evaluation threshold obtained from the preset database, then the vulnerability scanning optimization is performed on the enterprise network to be tested; otherwise, after segmenting the enterprise network to be tested, the internal network penetration is directly performed on the enterprise network to be tested based on the obtained scanning vulnerabilities. The vulnerability scanning optimization includes a first vulnerability scanning optimization and a second vulnerability scanning optimization. The first vulnerability scanning optimization refers to dividing and segmenting the network of the enterprise to be tested into regions to improve the overall quality of vulnerability scanning. The second vulnerability scanning optimization refers to adjusting the scanning strategy according to the network topology to improve the effectiveness of vulnerability scanning. After vulnerability scanning and optimization are completed, penetration testing tools are used to scan for vulnerabilities in the network of the enterprise to be tested, and internal network penetration is carried out based on the obtained vulnerabilities.
4. The penetration testing method for network information system security assessment as described in claim 3, characterized in that: The specific process for optimizing the first vulnerability scan is as follows: The network of the enterprise to be tested is segmented, which means dividing the network of the enterprise to be tested into a preset number of network regions, and performing segmented scanning on each network region. The initial scan rate is corrected according to the scan rate correction factor to obtain the corrected scan rate, which represents the correction result based on the initial scan rate and the scan rate correction factor. The scan rate correction factor is obtained by inputting the penetration scan duration and the vulnerability scan effective evaluation deviation coefficient into the scan rate correction mapping set. The vulnerability scan effective evaluation deviation coefficient is obtained by performing relative deviation processing on the vulnerability scan effective evaluation index and the second preset vulnerability scan effective evaluation threshold. The scan rate correction mapping set is a set obtained from a preset database that represents the mapping relationship between penetration scan duration, vulnerability scan effective evaluation deviation coefficient and scan rate correction factor. If the vulnerability scan effectiveness evaluation index after the scan rate correction is less than the vulnerability scan effectiveness evaluation index, the initial scan rate is restored, and the scan rate correction amount of the preset ratio is used as the scan rate adjustment amount. The initial scan rate is adjusted according to the scan rate adjustment amount. Otherwise, the current scan rate is maintained, and it is still necessary to determine whether to perform vulnerability scan optimization on the network of the enterprise to be tested.
5. The penetration testing method for network information system security assessment as described in claim 3, characterized in that: The second vulnerability scanning optimization means adaptively adjusting the scanning strategy based on the network topology of the enterprise being tested; The scanning strategies include low-speed scanning strategy, packet spoofing strategy, and protocol obfuscation strategy; D1: When the conditions of the first scanning strategy are met, a low-speed scanning strategy is adopted and D4 is executed; otherwise, D2 is executed. The first scanning strategy condition is that the penetration testing tool detects a security device, and the network response time of the enterprise under test is less than the preset network response time of the enterprise under test obtained from the preset database; The low-speed scanning strategy means performing vulnerability scanning at a secondary corrected scanning rate. The secondary corrected scanning rate is obtained by correcting the corrected scanning rate using a comparison coefficient of the network response time of the enterprise under test. The comparison coefficient of the network response time of the enterprise under test is obtained by comparing the network response time of the enterprise under test with a preset network response time of the enterprise under test. D2: If the conditions of the second scanning strategy are met, the packet masquerading strategy is adopted and D4 is executed; otherwise, D3 is executed. The second scanning strategy condition is that the port connection request frequency is greater than the preset port connection request frequency obtained from the preset database, and the number of connection request denials recorded in the firewall log is greater than the preset number of connection request denials obtained from the preset database. The packet masquerading strategy refers to modifying the header information of data packets and masquerading as scanning traffic; D3. When the conditions of the third scanning strategy are met, the protocol obfuscation strategy is adopted and D4 is executed; otherwise, the preset personnel scanning strategy selection fails. The third scanning strategy condition is that the protocol used to scan the traffic is within the preset protocol range, and the traffic request frequency is greater than the preset traffic request frequency obtained from the preset database. The protocol obfuscation strategy means that the protocol used to scan traffic is disguised; D4. After the scanning strategy is executed, if the penetration scan duration is longer than the preset maximum penetration scan duration obtained from the preset database, the scanning tasks will be allocated according to the preset number of parallel scans. The preset number of parallel scans is obtained by mapping the current penetration scan duration relative deviation coefficient and vulnerability scan effective evaluation deviation coefficient into the parallel scan number mapping set. The parallel scan number mapping set is a collection obtained from a preset database that represents the mapping relationship between the current penetration scan duration relative deviation coefficient, vulnerability scan effective evaluation deviation coefficient and preset number of parallel scans.
6. The penetration testing method for network information system security assessment as described in claim 1, characterized in that: The method for evaluating the effectiveness of internal network penetration based on parameters during the internal network penetration process is as follows: By introducing a vulnerability scanning effectiveness evaluation index, the internal network penetration effectiveness evaluation coefficient is corrected to obtain the internal network penetration effectiveness evaluation index. The internal network penetration effectiveness evaluation index represents the correction result based on the internal network penetration effectiveness evaluation coefficient and the vulnerability scanning effectiveness evaluation index. It is used to quantitatively evaluate the effectiveness of internal network penetration in penetration testing to ensure the comprehensiveness of penetration testing. The internal network penetration effectiveness evaluation coefficient is obtained by introducing an internal network penetration effectiveness evaluation adjustment factor and performing a value coupling process on the internal network penetration evaluation comparison coefficient and the security device interception rate inverse comparison coefficient. The internal network penetration assessment comparison coefficient is obtained by comparing the parameters in the internal network penetration process with the corresponding preset internal network penetration parameters obtained from the preset database. Specifically, it includes the lateral movement success rate comparison coefficient and the lateral movement time comparison coefficient. The inverse comparison coefficient of the security device interception rate is obtained by inversely comparing the security device interception rate during the intranet penetration process with the preset security device interception rate obtained from the preset database.
7. The penetration testing method for network information system security assessment as described in claim 6, characterized in that: The specific process for determining whether to perform internal network penetration testing and optimization on the network of the enterprise to be tested is as follows: B1: If the internal network penetration effectiveness assessment index is less than the first preset internal network penetration effectiveness assessment threshold obtained from the preset database, then prompt the preset personnel that the internal network penetration has failed; otherwise, proceed to B2. B2. If the internal network penetration effectiveness assessment index is less than the second preset internal network penetration effectiveness assessment threshold obtained from the preset database, then the internal network penetration optimization will be performed on the network of the enterprise to be tested; otherwise, the penetration test will continue until the penetration test ends. The internal network penetration optimization includes a first internal network penetration optimization and a second internal network penetration optimization. The first internal network penetration optimization refers to setting the scanning order and corresponding scanning method to improve the efficiency of penetration testing. The second internal network penetration optimization refers to time management and control of lateral movement operations to ensure the security of the penetration testing process. After the internal network penetration optimization is completed, continue penetration testing until the penetration testing is finished.
8. The penetration testing method for network information system security assessment as described in claim 7, characterized in that: The specific process for the first intranet penetration optimization is as follows: C1: Input the internal network penetration effectiveness assessment index and the corresponding encryption level of the network area of the enterprise to be tested into the preset scanning priority mapping set to obtain the corresponding scanning priority, and set the scanning order according to the scanning priority; C2, if the scanning priority of the network area of the enterprise to be tested is higher than the first preset scanning priority obtained from the preset database, then the first scan is performed; otherwise, C3 is executed. The first scan means performing vulnerability scanning according to the first scan rate and the first scan depth. C3. If the scanning priority of the network area of the enterprise to be tested is lower than the second preset scanning priority obtained from the preset database, then a second scan is performed; otherwise, the current scanning parameters remain unchanged. The second scan means performing vulnerability scanning according to the second scan rate and the second scan depth. The scanning parameters include the scan rate and the scan depth. The specific process for the second internal network penetration optimization is as follows: D1, the maximum lateral movement time is obtained by correcting the lateral movement time according to the internal network penetration effectiveness assessment deviation coefficient. The internal network penetration effectiveness assessment deviation coefficient is obtained by performing relative deviation processing on the internal network penetration effectiveness assessment index and the second preset internal network penetration effectiveness assessment threshold. D2. If the current lateral movement time is not less than the maximum lateral movement time, stop the current lateral movement operation and restart the lateral movement operation after the preset operation interval ends; otherwise, execute D3. D3. If the current lateral movement operation ends, the next lateral movement operation will be performed after the preset operation interval ends; otherwise, the current lateral movement operation will continue.
9. The penetration testing method for network information system security assessment as described in claim 1, characterized in that: The continued penetration testing also includes removing traces of penetration operations and vulnerability detection reports; The removal of penetration operation traces means using a preset identifier of the corresponding mark type to mark the penetration operation traces generated during the penetration test, and setting the penetration operation trace removal order according to the scan priority; The vulnerability detection report includes the assessment results, the optimization measures implemented, the vulnerabilities discovered, the vulnerabilities that have been exploited, the impact of the vulnerabilities, and remediation recommendations.
10. An apparatus for applying the penetration testing method for security assessment of network information systems as described in any one of claims 1-9, characterized in that, include: Data acquisition equipment, storage equipment, and processing equipment; The data acquisition device is used to collect preliminary vulnerability scans, parameters during the preliminary vulnerability scan process, and parameters during the internal network penetration process in the network of the enterprise under test. The storage device is used to store preliminary scan vulnerabilities in the enterprise network to be tested, parameters during the preliminary vulnerability scanning process, and parameters during the internal network penetration process, as well as the storage of corresponding historical data; The processing device is used to calculate the scanning coverage deviation results of the enterprise network under test, evaluate the effectiveness of vulnerability scanning based on parameters in the initial vulnerability scanning process, optimize vulnerability scanning, evaluate the effectiveness of internal network penetration based on parameters in the internal network penetration process, and optimize internal network penetration.
Citation Information
Patent Citations
Automated penetration testing method and system based on network target range
CN114462048B
Automatic penetration testing method and device
CN118035075A
Remote permeation evidence obtaining method for industrial control system
CN110399718A
Network security protection security method and system based on unit cell
CN114978584A