Multi-information and multi-attribute combined internet basic resource security situation awareness method and device
By acquiring multi-source, multi-attribute data from DNS servers to perform situational awareness risk scoring, the problems of data silos and insufficient real-time performance in existing technologies are solved, enabling real-time dynamic security situational awareness and efficient protection of Internet infrastructure resources.
Patent Information
- Application Number
- CN202511410587.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-29
- Publication Date
- 2026-01-13
AI Technical Summary
Existing security situation awareness technologies suffer from problems such as data silos, single attributes, and insufficient real-time performance in the security analysis of Internet infrastructure resources, making it difficult to comprehensively cope with complex and diverse network attacks.
By acquiring multi-source, multi-attribute data of DNS servers in real time through probe nodes and third-party websites, situational awareness risk scores are calculated, risk levels are determined in conjunction with risk level tables, and optimization measures are implemented for high-level threats.
It enables real-time dynamic security situation awareness of internet infrastructure resources, improves the pertinence and timeliness of security protection, and allows for timely early warning and optimization measures.
Smart Images

Figure CN121333652A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of security situation awareness of Internet infrastructure resources, and in particular to a method and apparatus for security situation awareness of Internet infrastructure resources that combines multiple information and attributes. Background Technology
[0002] Cyberspace has emerged as the fifth major domain after land, sea, air, and space, and ensuring its security is tantamount to safeguarding national sovereignty. Internet infrastructure resources, as the core underlying facilities supporting the entire network operation, encompass the Domain Name System (DNS), IP address resources, inter-domain routing systems, and more. The security of these resources directly affects the stability, availability, and trustworthiness of the network. Therefore, building a dedicated situational awareness system tailored to its technical characteristics and threat scenarios is particularly important.
[0003] As the internet continues to expand, the security threats facing its infrastructure are becoming increasingly complex and diverse, including DDoS attacks, route hijacking, and botnet attacks. However, existing security situation awareness technologies often face technical challenges in application, such as incomplete analysis and difficulty in effectively responding to rapidly changing network attacks. Summary of the Invention
[0004] This application provides a method and apparatus for joint multi-information and multi-attribute security situation awareness of Internet infrastructure resources. This method broadens the analytical dimensions by acquiring multi-dimensional data and multi-attribute information of Internet infrastructure resources in real time, and comprehensively scores the data to further enhance the depth of analysis, thereby achieving effective awareness of the real-time dynamic security situation of Internet infrastructure resources.
[0005] Firstly, this application provides a method for joint awareness of the security situation of Internet infrastructure resources involving multiple information and attributes, the method comprising:
[0006] The system uses probe nodes and third-party websites to obtain multi-source, multi-attribute data from DNS servers in real time.
[0007] Calculate the situational awareness risk score from multi-source, multi-attribute data to obtain the situational awareness risk score.
[0008] The risk level of the DNS server is determined based on the correspondence between the situational awareness risk score and the risk level table.
[0009] If the risk level of a DNS server is high or severe, optimization measures will be taken for the DNS server.
[0010] Optionally, the multi-source, multi-attribute data includes probe information and CVE vulnerability information. Multi-source, multi-attribute data of the DNS server is obtained in real-time using probe nodes and third-party websites, including:
[0011] The IP address of the DNS server is obtained in real time by probing the nodes;
[0012] The probe nodes obtain the probe information of the DNS server corresponding to the IP address of the DNS server in real time. The probe information includes: biand software version information, link packet loss rate, domain name service query response status, query traffic and DNSSEC support information.
[0013] Obtain CVE vulnerability information of the DNS server corresponding to the DNS server IP through a third-party website.
[0014] Optionally, a situational awareness risk score is calculated from multi-source, multi-attribute data to obtain the situational awareness risk score, including:
[0015] Multiple intermediate rating values are obtained based on multi-source, multi-attribute data;
[0016] The situational awareness risk score is obtained based on multiple intermediate scores and the perceived risk scoring formula.
[0017] Optionally, multiple intermediate values include the DNS server's own vulnerability score, the packet loss rate score of the link from the probe node to the DNS server, the DNS query success rate score over a period of time, the average query response time score over a period of time, the query traffic level score, and the server's DNSSEC support score. Multiple intermediate scores are obtained based on multi-source, multi-attribute data, including:
[0018] Based on the correspondence between the biand software version information and CVE vulnerability information, the CVE vulnerability score and the normalized CVE vulnerability duration are obtained. Then, based on the CVE vulnerability score and the normalized CVE vulnerability duration, the vulnerability score of the DNS server itself is calculated.
[0019] Substitute the link packet loss rate into the correspondence between link packet loss rate and score to obtain the link packet loss rate score from the probe node to the DNS server;
[0020] Based on the ratio of DNS query requests initiated by the domain name server to successful responses within a certain period of time in the domain name service query response data, a DNS query success rate score is obtained for a certain period of time.
[0021] The average query response time score is obtained by comparing the total response time of DNS query requests initiated by the domain name server with the total number of queries within a certain period of time in the domain name service query response data.
[0022] Substitute the query traffic into the correspondence between query traffic and score to obtain the query traffic level score;
[0023] Substitute the DNSSEC support information into the correspondence between DNSSEC support information and scores to obtain the server's DNSSEC support score.
[0024] Optionally, the process of setting up a risk level table includes:
[0025] When the situational awareness risk score of a DNS server is less than the first threshold, the corresponding risk level is set to low.
[0026] The risk level is defined as medium when the situational awareness risk score of a DNS server is greater than or equal to the first threshold but less than the second threshold.
[0027] The risk level is set to high when the situational awareness risk score of a DNS server is greater than or equal to the second threshold and less than the third threshold.
[0028] The risk level is set to severe when the situational awareness risk score of the DNS server is greater than or equal to the third threshold.
[0029] Optionally, optimization measures may be adopted for the DNS server, including:
[0030] Upgrade the bind software corresponding to the DNS server to a secure version;
[0031] Optimize the network lines corresponding to the DNS server;
[0032] The DNSSEC protocol employs a high-strength algorithm for DNS servers.
[0033] Optionally, before calculating the situational awareness risk score from multi-source, multi-attribute data, the following steps are also included:
[0034] The multi-source, multi-attribute data is preprocessed, including formatting and unification, noise reduction and deduplication.
[0035] Secondly, this application provides a multi-information, multi-attribute joint Internet infrastructure resource security situation awareness device, which includes:
[0036] The acquisition unit is used to obtain multi-source, multi-attribute data of the DNS server in real time using probe nodes and third-party websites;
[0037] The calculation unit is used to calculate the situational awareness risk score from multi-source, multi-attribute data to obtain the situational awareness risk score.
[0038] The determination unit is used to determine the risk level of the DNS server based on the correspondence between the situational awareness risk score and the risk level table.
[0039] The optimization unit is used to take optimization measures for the DNS server if the risk level of the DNS server is high or severe.
[0040] Optionally, the multi-source, multi-attribute data includes detection information and CVE vulnerability information, and the acquisition unit is specifically used for:
[0041] The IP address of the DNS server is obtained in real time by probing the nodes;
[0042] The probe nodes obtain the probe information of the DNS server corresponding to the IP address of the DNS server in real time. The probe information includes: biand software version information, link packet loss rate, domain name service query response status, query traffic and DNSSEC support information.
[0043] Obtain CVE vulnerability information of the DNS server corresponding to the DNS server IP through a third-party website.
[0044] Optionally, the computing unit is specifically used for:
[0045] Multiple intermediate rating values are obtained based on multi-source, multi-attribute data;
[0046] The situational awareness risk score is obtained based on multiple intermediate scores and the perceived risk scoring formula.
[0047] Optionally, multiple intermediate values include the DNS server's own vulnerability score, the packet loss rate score of the link from the probe node to the DNS server, the DNS query success rate score over a period of time, the average query response time score over a period of time, the query traffic level score, and the server's DNSSEC support score. The calculation unit obtains multiple intermediate scores based on multi-source, multi-attribute data, specifically used for:
[0048] Based on the correspondence between the biand software version information and CVE vulnerability information, the CVE vulnerability score and the normalized CVE vulnerability duration are obtained. Then, based on the CVE vulnerability score and the normalized CVE vulnerability duration, the vulnerability score of the DNS server itself is calculated.
[0049] Substitute the link packet loss rate into the correspondence between link packet loss rate and score to obtain the link packet loss rate score from the probe node to the DNS server;
[0050] Based on the ratio of DNS query requests initiated by the domain name server to successful responses within a certain period of time in the domain name service query response data, a DNS query success rate score is obtained for a certain period of time.
[0051] The average query response time score is obtained by comparing the total response time of DNS query requests initiated by the domain name server with the total number of queries within a certain period of time in the domain name service query response data.
[0052] Substitute the query traffic into the correspondence between query traffic and score to obtain the query traffic level score;
[0053] Substitute the DNSSEC support information into the correspondence between DNSSEC support information and scores to obtain the server's DNSSEC support score.
[0054] Optionally, the device further includes a setting unit, specifically used for:
[0055] When the situational awareness risk score of a DNS server is less than the first threshold, the corresponding risk level is set to low.
[0056] The risk level is defined as medium when the situational awareness risk score of a DNS server is greater than or equal to the first threshold but less than the second threshold.
[0057] The risk level is set to high when the situational awareness risk score of a DNS server is greater than or equal to the second threshold and less than the third threshold.
[0058] The risk level is set to severe when the situational awareness risk score of the DNS server is greater than or equal to the third threshold.
[0059] Optionally, the optimization unit is specifically used for:
[0060] Upgrade the bind software corresponding to the DNS server to a secure version;
[0061] Optimize the network lines corresponding to the DNS server;
[0062] The DNSSEC protocol employs a high-strength algorithm for DNS servers.
[0063] Optionally, the device further includes:
[0064] The preprocessing unit is used to preprocess multi-source, multi-attribute data, including formatting and unification, noise reduction and deduplication.
[0065] Thirdly, this application provides an electronic device including a memory and a processor:
[0066] Memory is used to store computer programs;
[0067] The processor is used to execute the method provided in the first aspect above according to the computer program.
[0068] Fourthly, this application provides a computer-readable storage medium for storing a computer program for performing the method provided in the first aspect above.
[0069] Therefore, this application has the following beneficial effects:
[0070] This application provides a method for security situation awareness of internet infrastructure resources based on multi-information and multi-attribute collaboration. First, it uses probe nodes and third-party websites to acquire multi-source, multi-attribute data of DNS servers in real time. Then, it calculates a situation awareness risk score based on this data. Next, it determines the risk level of the DNS server based on the correspondence between the situation awareness risk score and a risk level table. Finally, if the risk level of the DNS server is high or severe, optimization measures are implemented. In this process, the real-time collection of multi-source, multi-attribute data from DNS servers through globally distributed probe nodes and third-party websites addresses the problems of insufficient real-time performance and data homogeneity (single data source and single data attributes). Furthermore, it analyzes the correlation between multi-source, multi-attribute data, accurately quantifies security situation risks, and provides security warnings for high-level threats, thereby achieving real-time dynamic security situation awareness of internet infrastructure resources. Attached Figure Description
[0071] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments recorded in this application. For those skilled in the art, other drawings can be obtained based on these drawings.
[0072] Figure 1 This is a flowchart illustrating an embodiment of a multi-information, multi-attribute joint Internet infrastructure resource security situation awareness method in this application.
[0073] Figure 2 This is a flowchart illustrating another embodiment of a multi-information, multi-attribute joint Internet infrastructure resource security situation awareness method in the present application.
[0074] Figure 3 This is an architecture diagram of a multi-information, multi-attribute joint Internet infrastructure resource security situation awareness method in an embodiment of this application;
[0075] Figure 4 This is a schematic diagram of the structure of a multi-information, multi-attribute joint Internet infrastructure resource security situation awareness device in an embodiment of this application;
[0076] Figure 5 This is a schematic diagram of the structure of an electronic device according to an embodiment of this application. Detailed Implementation
[0077] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention are within the scope of protection of the present invention.
[0078] In the embodiments of this application, the word "first" in the name "first threshold" is only used for name identification and does not represent the first in order. This rule also applies to "second," "third," etc.
[0079] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of the relevant data shall comply with the relevant laws, regulations and standards of the relevant regions.
[0080] Currently, existing security situation awareness technologies have the following problems: (1) Data silos: They rely on a single data source (such as firewall logs) and lack joint analysis of multi-dimensional data, resulting in incomplete analysis; (2) Single attributes: They only focus on traffic or behavioral characteristics and ignore the correlation of resource attributes. For example, although the daily traffic of a DNS server is considerable, this only indicates that it may be an important resolution node and cannot directly reflect its security level. It is necessary to combine it with other attribute information for comprehensive analysis, which can also easily lead to incomplete analysis; (3) Insufficient real-time performance: Traditional awareness technologies are mostly based on static rules, which are difficult to effectively deal with highly variable network attacks (such as zero-day vulnerabilities).
[0081] In this embodiment, by using probe nodes and third-party websites to obtain multi-dimensional data and multi-attribute information of Internet infrastructure resources in real time, the analysis dimensions are broadened. Furthermore, situational awareness risk scores and threat level classifications are performed on multi-source and multi-attribute data to calculate the overall situational risk score of the current Internet infrastructure resources, thereby further improving the depth of analysis. This enables security early warning of high-level threats and achieves real-time dynamic security situational awareness of Internet infrastructure resources.
[0082] In specific implementation, this method may include, for example, the following steps: first, using probe nodes and third-party websites to obtain multi-source, multi-attribute data of the DNS server in real time; then, calculating a situational awareness risk score based on the multi-source, multi-attribute data; next, determining the risk level of the DNS server based on the correspondence between the situational awareness risk score and the risk level table; and finally, if the risk level of the DNS server is high or severe, taking optimization measures for the DNS server.
[0083] As can be seen, the method implemented in this application obtains comprehensive, multi-attribute information about internet infrastructure resources through real-time collaboration between probe nodes and third-party websites. Based on this, risk scores are calculated for situational awareness of the multi-source, multi-attribute data, accurately quantifying security situation risks. Finally, based on the risk scores and preset risk levels, timely warnings are issued for high-level threats, thereby significantly improving the targeting and timeliness of security protection.
[0084] To facilitate understanding of the specific implementation of the multi-information, multi-attribute joint Internet infrastructure resource security situation awareness method provided in the embodiments of this application, the following description will be provided in conjunction with the accompanying drawings.
[0085] It should be noted that the subject implementing this multi-information, multi-attribute joint Internet infrastructure resource security situation awareness method can be the multi-information, multi-attribute joint Internet infrastructure resource security situation awareness device provided in the embodiments of this application. This multi-information, multi-attribute joint Internet infrastructure resource security situation awareness device can be carried in an electronic device or a functional module of an electronic device. The electronic device in the embodiments of this application can be any device capable of implementing the multi-information, multi-attribute joint Internet infrastructure resource security situation awareness method in the embodiments of this application, such as an Internet of Things (IoT) device.
[0086] Figure 1 This is a flowchart illustrating a method for joint security situation awareness of internet infrastructure resources based on multiple information and attributes, provided in an embodiment of this application. This method can also be applied to a joint security situation awareness device for internet infrastructure resources based on multiple information and attributes. This joint security situation awareness device for internet infrastructure resources can be, for example, as shown in the diagram. Figure 4 The multi-information, multi-attribute joint Internet infrastructure resource security situation awareness device 400 shown, or the multi-information, multi-attribute joint Internet infrastructure resource security situation awareness device can also be integrated into... Figure 5 Functional modules in the electronic device 500 shown.
[0087] like Figure 1 As shown, the method includes the following steps S101 to S104:
[0088] S101: Use probe nodes and third-party websites to obtain multi-source, multi-attribute data of DNS servers in real time.
[0089] To achieve real-time dynamic security situation awareness of internet infrastructure resources, the system first acquires multi-source, multi-attribute data of DNS servers in real time using probe nodes and third-party websites. Then, it calculates a situation awareness risk score based on this data. Next, based on the correspondence between the situation awareness risk score and a risk level table, the risk level of the DNS server is determined. Finally, if the risk level of the DNS server is high or severe, optimization measures are implemented. In this embodiment, the acquisition of multi-source, multi-attribute data of the DNS server in step S101 serves as a prerequisite for obtaining the subsequent situation awareness risk score.
[0090] As an example, S101 may include: obtaining the IP address of the DNS server in real time through the probe node; obtaining the probe information of the DNS server corresponding to the DNS server IP address in real time through the probe node, wherein the probe information includes: biand software version information, link packet loss rate, domain name service query response status, query traffic and DNSSEC support information; and obtaining the CVE vulnerability information of the DNS server corresponding to the DNS server IP through a third-party website.
[0091] As an example, the process of obtaining the IP address of the DNS server in real time by probing the probe node can specifically include: using the zmap tool on the probe node to obtain a list of IPs with port 53 open, and then determining the IP address of the DNS server through the obtained IP list.
[0092] As an example, in this application embodiment, the biand software version information is obtained using the nmap tool; the link packet loss rate is obtained using the ping or traceroute command (which can be viewed via the ICMP protocol); the domain name service query response status is the situation of periodically initiating DNS query requests to the domain name server; the query traffic is statistically analyzed through logs, which has a certain lag but high accuracy; and the DNSSEC support information is obtained using the dig command.
[0093] In this embodiment, multiple probe nodes and third-party websites are used to obtain multi-information and multi-attribute data of Internet infrastructure resources in real time, including the software information, link information, query service information, vulnerability information, etc. of the DNS server itself; and it not only focuses on traffic characteristics, but also considers the vulnerability of resources, link status, service quality, security protocol support and other attributes, so as to realize the joint analysis of multi-source and multi-attribute data in the future, thereby comprehensively reflecting the security status of Internet infrastructure resources.
[0094] S102: Calculate the situational awareness risk score from multi-source, multi-attribute data to obtain the situational awareness risk score.
[0095] As an example, S102 may include: S1021, obtaining multiple intermediate scores based on multi-source, multi-attribute data; S1022, obtaining a situational awareness risk score based on the multiple intermediate scores and the perceived risk scoring formula.
[0096] As an example, the intermediate values in this application embodiment include the DNS server's own vulnerability score, the packet loss rate score of the link from the probe node to the DNS server, the DNS query success rate score over a period of time, the average query response time score over a period of time, the query traffic level score, and the server's DNSSEC support score. Therefore, S1021 mentioned above may include:
[0097] (1) Based on the correspondence between the biand software version information and the CVE vulnerability information, obtain the CVE vulnerability score and the normalized CVE vulnerability duration. Then, calculate the vulnerability score of the DNS server itself based on the CVE vulnerability score and the normalized CVE vulnerability duration. For details, please refer to formula (1):
[0098] VULS = (CVSS score × 8 + Dur × 20) / 10 (Formula 1)
[0099] Among them, VULS is the vulnerability score of the DNS server itself; cvss score is the CVE vulnerability score; and dur is the normalized duration of CVE vulnerability (the number of days from the discovery of the vulnerability to its resolution).
[0100] The process described above involves obtaining the CVE vulnerability score and the normalized duration of the CVE vulnerability based on the correspondence between BIND software version information and CVE vulnerability information. For example, CVE-2022-0667 affects the DNS server of BIND 9.18.0, with a corresponding CVSS score of 7.5. This vulnerability was discovered on March 22, 2022, and resolved on November 9, 2023 (existing for a total of 597 days).
[0101] (2) Substitute the link packet loss rate into the correspondence between link packet loss rate and score to obtain the link packet loss rate score from the probe node to the DNS server.
[0102] For the specific link packet loss rate and the corresponding relationship between the link packet loss rate and the score, please refer to formula (2):
[0103]
[0104] Specifically, when the link packet loss rate is less than or equal to 10%, the score is 0, meaning the LLRS score for the link packet loss rate from the probe node to the DNS server is 0; when the link packet loss rate is greater than 10% but less than 50%, the score is 4, meaning the LLRS score for the link packet loss rate from the probe node to the DNS server is 4; when the link packet loss rate is greater than or equal to 50% but less than 90%, the score is 8, meaning the LLRS score for the link packet loss rate from the probe node to the DNS server is 8; and when the link packet loss rate is greater than or equal to 90%, the score is 10, meaning the LLRS score for the link packet loss rate from the probe node to the DNS server is 10.
[0105] (3) Based on the ratio of DNS query requests initiated by the domain name server to successful responses within a certain period of time in the domain name service query response situation, obtain the DNS query success rate score within a certain period of time.
[0106] After obtaining the domain name service query response status, you can obtain the percentage of successful responses within a certain period of time (e.g., within 5 minutes). This means that after the probe nodes distributed in different locations (minimizing the impact of geographical factors) continuously send query requests to the DNS server within these 5 minutes, the percentage of successful queries is counted.
[0107] After obtaining the ratio of DNS query requests initiated by the domain name server to successful responses (query success rate) over a period of time, the DNS query success rate score can be obtained based on the correspondence between the query success rate and the score. The specific correspondence between the query success rate and the score can be found in formula (3):
[0108]
[0109] The score is calculated as follows: when the average success rate is greater than or equal to 95%, the score is 0, meaning the DNS query success rate score (DQS) for a given period is 0; when the average success rate is greater than or equal to 60% but less than 95%, the score is 4, meaning the DNS query success rate score (DQS) for a given period is 4; when the average success rate is greater than 20% but less than 60%, the score is 8, meaning the DNS query success rate score (DQS) for a given period is 8; and when the average success rate is less than or equal to 20%, the score is 10, meaning the DNS query success rate score (DQS) for a given period is 10.
[0110] (4) Based on the ratio of the total response time of DNS query requests initiated by the domain name server to the total number of queries within a certain period of time in the domain name service query response situation, the average query response time score within a certain period of time is obtained.
[0111] After obtaining the domain name service query response status, you can obtain the percentage of successful responses within a certain period of time (e.g., within 5 minutes). This is the average response time after the probe nodes distributed in different locations (minimizing the influence of geographical factors) continuously send query requests to the DNS server within these 5 minutes.
[0112] After obtaining the ratio of the total response time of DNS query requests initiated by the domain name server to the total number of queries over a period of time (average query response time), the average query response time score over a period of time can be obtained based on the correspondence between the average query response time and the score. The specific correspondence between the average query response time and the score can be found in formula (4):
[0113]
[0114] Specifically, when the average query response time is less than a predetermined threshold, the corresponding score is 0, meaning the average query response time score (QRTS) for a given period is 0; when the average query response time is responsive but exceeds the predetermined threshold, the corresponding score is 5, meaning the average query response time score (QRTS) for a given period is 5; and when the average query response time is unresponsive or times out, the corresponding score is 10, meaning the average query response time score (QRTS) for a given period is 10.
[0115] (5) Substitute the query traffic into the correspondence between query traffic and score to obtain the query traffic level score.
[0116] For details on the correspondence between query traffic and scores, please refer to formula (5):
[0117]
[0118] Specifically, a score of 10 is awarded when the number of queries exceeds 100 billion in a single day, resulting in a Query Traffic Rank (QTS) score of 10; a score of 7.5 is awarded when the number of queries is around 50 billion in a single day; a score of 5 is awarded when the number of queries is around 10 billion in a single day; and a score of 2.5 is awarded when the number of queries is less than 1 billion in a single day.
[0119] (6) Substitute the DNSSEC support information into the correspondence between DNSSEC support information and score to obtain the server's DNSSEC support score.
[0120] For specific DNSSEC support information and the correspondence between DNSSEC support information and scores, please refer to formula (6):
[0121]
[0122] Specifically, when DNSSEC support information is supported and the algorithm strength is high, the corresponding score is 0, meaning the obtained server DNSSEC support score (DSS) is 0; when DNSSEC support information is supported but the algorithm strength is low, the corresponding score is 5, meaning the obtained server DNSSEC support score (DSS) is 5; when DNSSEC support information is not supported, the corresponding score is 10, meaning the obtained server DNSSEC support score (DSS) is 10.
[0123] As an example, S1022 may include: after obtaining multiple intermediate scores, such as the vulnerability score of the DNS server itself, the packet loss rate score of the link from the probe node to the DNS server, the DNS query success rate score over a period of time, the average query response time score over a period of time, the query traffic level score, and the DNSSEC support score of the server, the situational awareness risk score can be obtained by using the perceived risk scoring formula. The specific perceived risk scoring formula can be found in formula (7):
[0124] S = VULS × 0.4 + LLRS × 0.2 + DQS × 0.1 + QRTS × 0.1 + QTS × 0.1 + DSS × 0.1 (Formula 7)
[0125] Wherein, S is the situational awareness risk score (0≤S≤10); VULS is the vulnerability score of the DNS server itself; LLRS is the packet loss rate score of the link from the probe node to the DNS server; DQS is the DNS query success rate score over a period of time; QRTS is the average query response time score over a period of time; QTS is the query traffic level score; and DSS is the server DNSSEC support score.
[0126] It should be noted that the specific numerical settings in the above formula can be changed according to the actual needs of those skilled in the art, and are not specifically limited here.
[0127] In this process, by comparing and analyzing the correlations between various attributes such as resource vulnerability, link status, service quality, and security protocol support, the situational awareness becomes more comprehensive and accurate, thereby improving the accuracy of subsequent analysis.
[0128] S103: Determine the risk level of the DNS server based on the correspondence between the situational awareness risk score and the risk level table.
[0129] As an example, S103 may include: first setting a risk level table, and then determining the risk level of the DNS server based on the correspondence between the situational awareness risk score and the risk level table.
[0130] As an example, the process of setting the risk level table in this application embodiment may include: setting the risk level as low when the situational awareness risk score of the DNS server is less than a first threshold; setting the risk level as medium when the situational awareness risk score of the DNS server is greater than or equal to the first threshold and less than a second threshold; setting the risk level as high when the situational awareness risk score of the DNS server is greater than or equal to the second threshold and less than a third threshold; and setting the risk level as severe when the situational awareness risk score of the DNS server is greater than or equal to the third threshold.
[0131] The risk level table in this application embodiment can be, for example, the situational awareness risk level table shown in Table 1.
[0132] Table 1 Situational Awareness Risk Level Table
[0133]
[0134] As shown in Table 1 above, the first threshold in this application can be 2.5; the second threshold can be 5; and the third threshold can be 7.5. Specifically, when the situational awareness risk score S of the DNS server is less than 2.5, the corresponding risk level is low; when the situational awareness risk score S of the DNS server is greater than or equal to 2.5 and less than 5, the corresponding risk level is medium; when the situational awareness risk score S of the DNS server is greater than or equal to 5 and less than 7.5, the corresponding risk level is high; and when the situational awareness risk score S of the DNS server is greater than or equal to 7.5, the corresponding risk level is severe.
[0135] In this process, in order to provide early warnings of high-level threats and make security protection more targeted and timely, a clear scoring formula and risk level classification standard can be adopted, which can make the calculation process clear and facilitate practical application and operation.
[0136] S104: If the risk level of the DNS server is high or severe, optimization measures will be taken for the DNS server.
[0137] As an example, S104 may include: issuing risk warnings for DNS servers with a risk level of high or higher, and making improvements and optimizations for high-scoring indicators. Specific optimization measures may include supporting the DNSSEC protocol with high-strength algorithms, upgrading the bind software to a secure version, and improving server redundancy.
[0138] During this process, risk warnings are issued for DNS servers with high or higher risk levels, and specific improvement measures are provided for reference, making security protection more targeted and timely, so as to reduce security risks.
[0139] As can be seen, the embodiments of this application collect multi-source, multi-attribute data from DNS servers in real time through globally distributed probe nodes and third-party websites to solve the problems of insufficient real-time performance and single data (single data source and single data attributes). Furthermore, it analyzes the correlation between multi-source, multi-attribute data, accurately quantifies security situation risks, and provides security warnings for high-level threats, thereby achieving real-time dynamic security situation awareness of Internet infrastructure resources.
[0140] To make the methods provided in the embodiments of this application clearer and easier to understand, the following is combined with... Figure 2 A specific example of this method will be used to illustrate the concept.
[0141] like Figure 2 As shown, this embodiment may include:
[0142] S201: Use probe nodes and third-party websites to obtain multi-source, multi-attribute data of DNS servers in real time.
[0143] The multi-source, multi-attribute data in this application embodiment may include probe information and CVE vulnerability information. The probe information is obtained in real time using probe nodes. Since CVE vulnerability information is public information, it can be obtained in real time using third-party websites.
[0144] The specific process of obtaining multi-source, multi-attribute data in this embodiment may include: obtaining the IP address of the DNS server in real time through probe nodes; obtaining the probe information of the DNS server corresponding to the DNS server IP address in real time through probe nodes, wherein the probe information includes: biand software version information, link packet loss rate, domain name service query response status, query traffic and DNSSEC support information; and obtaining the CVE vulnerability information of the DNS server corresponding to the DNS server IP through a third-party website.
[0145] In this process, for example Figure 3 The data acquisition layer in the architecture diagram uses different tools to obtain multi-attribute detection information in real time through detection or log statistics, and uses third-party websites to obtain CVE vulnerability information in real time, so that subsequent joint analysis of multi-source data can be realized to comprehensively reflect the security status of Internet infrastructure resources.
[0146] S202: Preprocess the multi-source, multi-attribute data, including formatting and unification, noise reduction and deduplication.
[0147] This application transforms raw data into data that is easier to analyze and calculate, thereby improving the reliability and accuracy of analytical conclusions (situational awareness risk scores). For example, this application implements... Figure 3The data processing layer in the architecture diagram shown will preprocess multi-source, multi-attribute data, which may include preprocessing processes such as formatting and unification, noise reduction and deduplication.
[0148] S203: Obtain multiple intermediate rating values based on multi-source, multi-attribute data.
[0149] In this embodiment of the application, in order to analyze the correlation between various attributes such as traffic characteristics, resource vulnerability, link status, service quality, and security protocol support, and to make situational awareness more comprehensive and accurate, it is conceivable to first calculate the corresponding scores, namely, the multiple intermediate scores in this embodiment of the application, specifically including: DNS server vulnerability score, link packet loss rate score from probe node to DNS server, DNS query success rate score over a period of time, average query response time score over a period of time, query traffic level score, and server DNSSEC support score.
[0150] The specific process of obtaining the DNS server's own vulnerability score, the packet loss rate score of the link from the probe node to the DNS server, the DNS query success rate score over a period of time, the average query response time score over a period of time, the query traffic level score, and the server's DNSSEC support score is as shown in the above embodiment and will not be repeated here.
[0151] In this embodiment, it is assumed that a DNS server uses an open-source Domain Name System (DNS) server software (Berkeley InternetName Daemon, BIND) version 4.9.1, with a corresponding CVE vulnerability score (CVSS score) of 10 and a normalized CVE vulnerability duration (DUR) of 0.818. The calculated information is as follows: DNS server self-vulnerability score (VULS) is 9.636, link packet loss rate score from probe node to DNS server (LLRS) is 4, DNS query success rate score (DQS) over a period of time is 4, average query response time score (QRTS) over a period of time is 5, query traffic level score (OTS) is 2.5, and server DNSSEC support score (QS) is 5.
[0152] S204: Obtain the situational awareness risk score based on multiple intermediate scores and the perceived risk scoring formula.
[0153] After obtaining multiple intermediate scores, these intermediate scores can be substituted into the situational awareness risk scoring formula to obtain the situational awareness risk score. The situational awareness risk scoring formula is as shown in the above embodiment and will not be repeated here.
[0154] Substituting the information obtained from the above calculations into the situational awareness risk scoring formula, the situational awareness risk score is obtained as follows: S=(10×8+0.818×20) / 10×0.4+4×0.2+4×0.1+5×0.1+2.5×0.1+5×0.1=6.3044.
[0155] In this process, for example Figure 3 The data analysis layer in the architecture diagram uses risk scoring to analyze the correlation between multi-source, multi-attribute data in order to obtain updated and comprehensive data. In order to classify the risk level of multi-source, multi-attribute data in the future, risk scoring is also used.
[0156] S205: Determine the risk level of the DNS server based on the correspondence between the situational awareness risk score and the risk level table.
[0157] The specific risk level table is shown in Table 1 of the above embodiments, and will not be repeated here. That is, in the embodiments of this application, as... Figure 3 The data analysis layer in the architecture diagram can correlate the situational awareness risk score obtained above with the risk level table to perform a mechanical risk level assessment. If the risk level of the DNS server is determined to be high, it indicates that the DNS server is relatively vulnerable, has poor service quality, and is susceptible to attacks.
[0158] S206: If the risk level of the DNS server is high or severe, optimization measures shall be taken for the DNS server.
[0159] In this embodiment of the application, after determining that the current risk level of the DNS server is high, for situations where the DNS server is at high risk or severe risk, the following can be done: Figure 3 The data feedback layer in the architecture diagram illustrates optimization measures for the current DNS server. Specifically, improvements and optimizations can be made to high-scoring metrics, such as upgrading the bind software to a secure version, optimizing network lines, and supporting the high-strength DNSSEC protocol, to effectively reduce security risks. Furthermore, the specific situation can be visualized, or real-time alert dashboards can be implemented for high-risk and severe-risk levels of the DNS server.
[0160] This embodiment provides a method for joint awareness of the security situation of Internet infrastructure resources based on multiple information and attributes. By acquiring multi-dimensional data and multi-attribute information of Internet infrastructure resources in real time, the method broadens the analysis dimensions and performs comprehensive scoring on the data to further enhance the analysis depth, thereby achieving effective awareness of the real-time dynamic security situation of Internet infrastructure resources.
[0161] See Figure 4This application provides a multi-information, multi-attribute joint Internet infrastructure resource security situation awareness device 400, which includes:
[0162] Acquisition unit 401 is used to acquire multi-source, multi-attribute data of the DNS server in real time using probe nodes and third-party websites;
[0163] The calculation unit 402 is used to calculate the situational awareness risk score from multi-source and multi-attribute data to obtain the situational awareness risk score.
[0164] The determination unit 403 is used to determine the risk level of the DNS server based on the correspondence between the situational awareness risk score and the risk level table.
[0165] Optimization unit 404 is used to take optimization measures for the DNS server if the risk level of the DNS server is high or severe.
[0166] Optionally, the multi-source, multi-attribute data includes detection information and CVE vulnerability information, and the acquisition unit 401 is specifically used for:
[0167] The IP address of the DNS server is obtained in real time by probing the nodes;
[0168] The probe nodes obtain the probe information of the DNS server corresponding to the IP address of the DNS server in real time. The probe information includes: biand software version information, link packet loss rate, domain name service query response status, query traffic and DNSSEC support information.
[0169] Obtain CVE vulnerability information of the DNS server corresponding to the DNS server IP through a third-party website.
[0170] Optionally, the computing unit 402 is specifically used for:
[0171] Multiple intermediate rating values are obtained based on multi-source, multi-attribute data;
[0172] The situational awareness risk score is obtained based on multiple intermediate scores and the perceived risk scoring formula.
[0173] Optionally, multiple intermediate values include the DNS server's own vulnerability score, the packet loss rate score of the link from the probe node to the DNS server, the DNS query success rate score over a period of time, the average query response time score over a period of time, the query traffic level score, and the server's DNSSEC support score. The calculation unit 402 obtains multiple intermediate scores based on multi-source, multi-attribute data, specifically for:
[0174] Based on the correspondence between the biand software version information and CVE vulnerability information, the CVE vulnerability score and the normalized CVE vulnerability duration are obtained. Then, based on the CVE vulnerability score and the normalized CVE vulnerability duration, the vulnerability score of the DNS server itself is calculated.
[0175] Substitute the link packet loss rate into the correspondence between link packet loss rate and score to obtain the link packet loss rate score from the probe node to the DNS server;
[0176] Based on the ratio of DNS query requests initiated by the domain name server to successful responses within a certain period of time in the domain name service query response data, a DNS query success rate score is obtained for a certain period of time.
[0177] The average query response time score is obtained by comparing the total response time of DNS query requests initiated by the domain name server with the total number of queries within a certain period of time in the domain name service query response data.
[0178] Substitute the query traffic into the correspondence between query traffic and score to obtain the query traffic level score;
[0179] Substitute the DNSSEC support information into the correspondence between DNSSEC support information and scores to obtain the server's DNSSEC support score.
[0180] Optionally, the device 400 further includes a setting unit, specifically used for:
[0181] When the situational awareness risk score of a DNS server is less than the first threshold, the corresponding risk level is set to low.
[0182] The risk level is defined as medium when the situational awareness risk score of a DNS server is greater than or equal to the first threshold but less than the second threshold.
[0183] The risk level is set to high when the situational awareness risk score of a DNS server is greater than or equal to the second threshold and less than the third threshold.
[0184] The risk level is set to severe when the situational awareness risk score of the DNS server is greater than or equal to the third threshold.
[0185] Optionally, the optimization unit is specifically used for:
[0186] Upgrade the bind software corresponding to the DNS server to a secure version;
[0187] Optimize the network lines corresponding to the DNS server;
[0188] The DNSSEC protocol employs a high-strength algorithm for DNS servers.
[0189] Optionally, the device 400 further includes:
[0190] The preprocessing unit is used to preprocess multi-source, multi-attribute data, including formatting and unification, noise reduction and deduplication.
[0191] It should be noted that the specific implementation method and achieved effects of the multi-information, multi-attribute joint Internet infrastructure resource security situation awareness device 400 can be found in the above. Figure 1 or Figure 2 The relevant descriptions in the provided methods will not be repeated here.
[0192] This application also provides an electronic device 500, such as... Figure 5 As shown, the electronic device 500 includes a memory 501 and a processor 502:
[0193] Memory 501 is used to store computer programs;
[0194] Processor 502 is used to execute the above according to the computer program. Figure 1 or Figure 2 The methods provided.
[0195] In addition, this application also provides a computer-readable storage medium for storing a computer program, the computer program being executed. Figure 1 or Figure 2 The methods provided.
[0196] As can be seen from the above description of the embodiments, those skilled in the art can clearly understand that all or part of the steps in the methods of the above embodiments can be implemented by means of software plus a general-purpose hardware platform. Based on this understanding, the technical solution of this application can be embodied in the form of a software product. This computer software product can be stored in a storage medium, such as a read-only memory (ROM) / RAM, magnetic disk, optical disk, etc., including several instructions to cause a computer device (which may be a personal computer, a server, or a network communication device such as a router) to execute the methods described in various embodiments or some parts of the embodiments of this application.
[0197] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on its differences from other embodiments. In particular, the device embodiments are basically similar to the method embodiments, so the description is relatively simple; relevant parts can be referred to the descriptions in the method embodiments. The device embodiments described above are merely illustrative. Modules described as separate components may or may not be physically separate. Components shown as modules may or may not be physical modules; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the objectives of this embodiment according to actual needs. Those skilled in the art can understand and implement this without creative effort.
[0198] The above description is merely an exemplary implementation of this application and is not intended to limit the scope of protection of this application.
Claims
1. A method for joint awareness of the security situation of Internet infrastructure resources involving multiple information and attributes, characterized in that, The method includes: The system uses probe nodes and third-party websites to obtain multi-source, multi-attribute data from DNS servers in real time. A situational awareness risk score is calculated by performing a situational awareness risk score on the multi-source, multi-attribute data. The risk level of the DNS server is determined based on the correspondence between the situational awareness risk score and the risk level table. If the risk level of the DNS server is high or severe, optimization measures will be taken for the DNS server.
2. The method according to claim 1, characterized in that, The multi-source, multi-attribute data includes probe information and CVE vulnerability information. The method of obtaining multi-source, multi-attribute data from DNS servers in real time using probe nodes and third-party websites includes: The IP address of the DNS server is obtained in real time through the detection nodes; The detection nodes obtain the DNS server information corresponding to the DNS server IP address in real time. The detection information includes: biand software version information, link packet loss rate, domain name service query response status, query traffic, and DNSSEC support information. The CVE vulnerability information of the DNS server corresponding to the DNS server IP is obtained through the third-party website.
3. The method according to claim 2, characterized in that, The process of calculating the situational awareness risk score from the multi-source, multi-attribute data to obtain the situational awareness risk score includes: Based on the multi-source, multi-attribute data, multiple intermediate rating values are obtained; The situational awareness risk score is obtained based on the multiple intermediate scores and the perceived risk scoring formula.
4. The method according to claim 3, characterized in that, The multiple intermediate values include the DNS server's own vulnerability score, the packet loss rate score of the link from the probe node to the DNS server, the DNS query success rate score over a period of time, the average query response time score over a period of time, the query traffic level score, and the server's DNSSEC support score. The multiple intermediate scoring values obtained based on the multi-source, multi-attribute data include: Based on the correspondence between the biand software version information and the CVE vulnerability information, the CVE vulnerability score and the normalized CVE vulnerability duration are obtained. Based on the CVE vulnerability score and the normalized CVE vulnerability duration, the vulnerability score of the DNS server itself is calculated. Substitute the link packet loss rate into the correspondence between link packet loss rate and score to obtain the link packet loss rate score from the probe node to the DNS server; Based on the ratio of DNS query requests initiated by the domain name server to successful responses within a certain period of time in the domain name service query response situation, the DNS query success rate score within that period of time is obtained. The average query response time score for a given period of time is obtained by comparing the total response time of DNS query requests initiated by the domain name server with the total number of queries within a given period of time in the domain name service query response data. Substitute the query traffic into the correspondence between query traffic and score to obtain the query traffic level score; Substitute the DNSSEC support information into the correspondence between DNSSEC support information and scores to obtain the server's DNSSEC support score.
5. The method according to claim 1, characterized in that, The process of setting the risk level table includes: When the situational awareness risk score of a DNS server is less than the first threshold, the corresponding risk level is set to low. When the situational awareness risk score of a DNS server is greater than or equal to the first threshold but less than the second threshold, the corresponding risk level is defined as medium. The risk level is set to high when the situational awareness risk score of the DNS server is greater than or equal to the second threshold and less than the third threshold. The risk level is set to severe when the situational awareness risk score of the DNS server is greater than or equal to the third threshold.
6. The method according to claim 1, characterized in that, The optimization measures adopted for the DNS server include: Upgrade the bind software corresponding to the DNS server to a secure version; Optimize the network lines corresponding to the DNS server; The DNS server employs the DNSSEC protocol with a high-strength algorithm.
7. The method according to claim 1, characterized in that, Before calculating the situational awareness risk score on the multi-source, multi-attribute data, the method further includes: The multi-source, multi-attribute data is preprocessed, including formatting and unification, and noise reduction and deduplication.
8. A multi-information, multi-attribute joint Internet infrastructure resource security situation awareness device, characterized in that, The device includes: The acquisition unit is used to obtain multi-source, multi-attribute data of the DNS server in real time using probe nodes and third-party websites; The calculation unit is used to calculate the situational awareness risk score on the multi-source, multi-attribute data to obtain the situational awareness risk score. The determining unit is used to determine the risk level of the DNS server based on the correspondence between the situational awareness risk score and the risk level table. An optimization unit is used to take optimization measures for the DNS server if the risk level of the DNS server is high or severe.
9. An electronic device, characterized in that, The device includes a memory and a processor, the processor being configured to execute a program stored in the memory, performing the method as described in any one of claims 1-7.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium is used to store a computer program for performing the method according to any one of claims 1-7.