An industrial control device vulnerability detection method and system combining firmware analysis and network scanning
Patent Information
- Application Number
- CN202511380422.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-25
- Publication Date
- 2026-09-29
- Estimated Expiration
- 2045-09-25
AI Technical Summary
[0005]固件静态分析的漏洞检测通过逆向工程与代码特征扫描检测漏洞,适用于闭源固件,具有低系统依赖性和资源消耗优势,可高效识别特定漏洞类型;但高误报率制约其实际应用
[0041]1、减少误报漏报。通过固件分析与网络扫描结果的深度融合与互验机制,确保漏洞检测结果的准确性。网络扫描验证了固件分析漏洞的实际可达性,有效剔除误报;基于固件分析指导网络扫描对潜在未激活服务进行探测和验证,显著减少漏报,全面提升漏洞检出率和准确率。
Smart Images

Figure CN121356818B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of vulnerability detection technology, specifically relating to a method and system for detecting vulnerabilities in industrial control equipment that combines firmware static analysis with network dynamic scanning. Background Technology
[0002] Vulnerability detection primarily employs two techniques: network scanning-based vulnerability detection and firmware analysis-based vulnerability detection. Network scanning-based vulnerability detection mainly includes rule-based signature-based methods and simulated attack methods. Firmware analysis-based vulnerability detection mainly includes methods for detecting known vulnerabilities in firmware sensitive information and methods for detecting vulnerabilities in open-source firmware components.
[0003] Network scanning-based vulnerability detection mainly includes two methods: rule-based signature analysis and simulated attack analysis. Rule-based signature analysis obtains system feedback through data packet interaction and combines it with vulnerability databases (such as version comparison) for non-intrusive vulnerability analysis. Simulated attack analysis, on the other hand, simulates hacker attack behavior and uses plug-in technology to dynamically detect different vulnerabilities.
[0004] Firmware-based vulnerability detection can be broadly categorized into three aspects: methods for detecting known vulnerabilities based on sensitive firmware information, methods for detecting vulnerabilities based on open-source firmware components, and methods for detecting known vulnerabilities based on firmware web interfaces. Methods for detecting known vulnerabilities based on sensitive firmware information traverse the firmware file system through rule matching, matching preset sensitive features to quickly locate high-risk vulnerabilities such as weak passwords and key leaks. Methods for detecting vulnerabilities based on open-source firmware components scan and match existing vulnerability knowledge bases to discover vulnerable open-source components. Methods for detecting vulnerabilities based on firmware web interfaces dynamically simulate the target runtime environment using firmware emulation technology, reconstructing the web service runtime conditions to achieve interface interaction and vulnerability trigger verification.
[0005] Static firmware analysis-based vulnerability detection uses reverse engineering and code signature scanning to detect vulnerabilities. It is suitable for closed-source firmware and has advantages in low system dependency and resource consumption, and can efficiently identify specific vulnerability types; however, its high false positive rate limits its practical application. Network scanning-based vulnerability detection combines high efficiency and low system impact, but it suffers from a certain degree of false negatives. Summary of the Invention
[0006] To address the aforementioned problems, this invention provides a method and system for detecting vulnerabilities in industrial control equipment that combines firmware analysis and network scanning. This effectively combines firmware analysis and network scanning technologies, allowing them to complement each other and verify each other's results. This significantly reduces the false positive rate of vulnerability detection based on firmware analysis and the false negative rate of vulnerability detection based on network scanning during the vulnerability detection process for industrial control equipment, and improves the detection capability for specific types of vulnerabilities (such as hard-coded passwords and weak passwords).
[0007] The technical solution adopted in this invention is as follows:
[0008] A method for detecting vulnerabilities in industrial control equipment that combines firmware analysis and network scanning includes the following steps:
[0009] Static fingerprints of industrial control equipment components are extracted through firmware reverse analysis.
[0010] Dynamic fingerprints of industrial control equipment are obtained through network traffic scanning;
[0011] Cross-validate the static and dynamic fingerprints of components, eliminate unreachable vulnerabilities and discover hidden vulnerabilities through cross-validation, and obtain a component-level potential vulnerability information table.
[0012] Based on the results of cross-validation, hard-coded passwords and weak passwords of industrial control equipment are detected and verified, and a list of hard-coded passwords and a list of weak passwords are generated.
[0013] Based on the component-level potential vulnerability information table, the hard-coded password list, and the weak password list, the effectiveness of the vulnerabilities is assessed, and a structured vulnerability list is formed.
[0014] Furthermore, the extraction of static fingerprints of industrial control equipment components through firmware reverse engineering includes:
[0015] Obtain the firmware image file of industrial control equipment;
[0016] The firmware image file is subjected to feature analysis. The software bill of materials for industrial control equipment is obtained according to preset rules. The file system type and operating system architecture are identified. The basic feature information of the firmware is composed of the software bill of materials, file system type and operating system architecture.
[0017] Unpack, disassemble, or decompile firmware image files to extract analyzable code snippets and configuration files;
[0018] By analyzing the firmware content, the operating system, third-party components, and their version numbers used by the industrial control equipment are identified as static fingerprint information. At the same time, authoritative vulnerability databases are queried to obtain a list of known vulnerabilities corresponding to the component versions, forming a preliminary component-level potential vulnerability information table.
[0019] Furthermore, the step of obtaining the dynamic fingerprint of industrial control equipment through network traffic scanning includes:
[0020] The network traffic and behavior data of the target industrial control equipment are collected by combining active detection and passive monitoring.
[0021] The active detection includes: constructing protocol messages according to industrial control protocol specifications and general network protocols, sending a detection request to the target industrial control device, and capturing and analyzing its response messages;
[0022] The passive monitoring includes: deploying a traffic capture device in a bypass mode to capture the network traffic of the target industrial control device in normal communication mode, and analyzing and obtaining the open ports, running services, and versions of related components of the device by parsing the protocol header and load characteristics.
[0023] Furthermore, the cross-verification of the component's static fingerprint and dynamic fingerprint includes:
[0024] For potential vulnerabilities discovered through firmware analysis, the network scan results are used to verify whether the corresponding components or services are actually running on the device and are reachable by the network. If a component exists in the firmware, but the network scan shows that its related services are not started, or the exploit path is not reachable at the network level, the vulnerability is removed from the component-level potential vulnerability information table or marked as low risk, thereby effectively reducing false alarms.
[0025] For components identified by firmware analysis but whose corresponding services cannot be found by network scanning, we attempt to activate the services by simulating device configuration. After successful activation, we perform targeted vulnerability scanning and verification to discover vulnerabilities that exist at the firmware level but are not visible to the network by default, thereby reducing false negatives.
[0026] Furthermore, the detection and verification of hard-coded passwords and weak passwords for industrial control equipment includes:
[0027] During firmware analysis, hard-coded passwords, keys, and API token information are detected in the device firmware.
[0028] For hard-coded passwords discovered during firmware analysis, network scanning is used to attempt to log in to the device's open network services to verify their validity. At the same time, for all identified open network services, a preset weak password dictionary is used to perform automated weak password brute-force attacks.
[0029] Based on the combined firmware analysis and network verification results, a list of hard-coded passwords and a list of weak passwords related to device network services are generated.
[0030] Furthermore, the assessment of vulnerability effectiveness based on the component-level potential vulnerability information table, the hard-coded password list, and the weak password list includes:
[0031] Use publicly disclosed vulnerability information to write exploit scripts or directly use publicly available scripts to scan and test the vulnerabilities of third-party components of industrial control equipment, and output a list of component vulnerabilities based on the vulnerability detection results;
[0032] Each type of vulnerability is associated with static feature information, dynamic verification screenshots, and remediation priorities, and customized suggestions for industrial control scenarios are added to ultimately form a report list that can be directly used for security hardening.
[0033] Furthermore, the dynamic verification screenshots include: screenshots of the identification results of network service scanning, screenshots of commands and responses attempting to activate the service, screenshots of successfully logging into the service using a weak password, and screenshots of successfully performing exploitation, etc.
[0034] A vulnerability detection system for industrial control equipment that combines firmware analysis and network scanning, comprising:
[0035] The firmware analysis module is used to extract static fingerprints of components in industrial control equipment through firmware reverse analysis.
[0036] The network scanning module is used to obtain the dynamic fingerprint of industrial control equipment by scanning network traffic;
[0037] The dynamic and static fingerprint cross-verification module is used to cross-verify the static and dynamic fingerprints of components. Through cross-verification, unreachable vulnerabilities are eliminated and hidden vulnerabilities are discovered, resulting in a component-level potential vulnerability information table.
[0038] The hard-coded password and weak password detection and verification module is used to detect and verify the hard-coded passwords and weak passwords of industrial control equipment based on the results of cross-validation, and to form a hard-coded password list and a weak password list.
[0039] The comprehensive assessment module is used to evaluate the effectiveness of vulnerabilities based on the component-level potential vulnerability information table, the hard-coded password list, and the weak password list, and to generate a structured vulnerability list.
[0040] Compared with the prior art, the beneficial effects of the present invention are as follows:
[0041] 1. Reduce false positives and false negatives. Through deep integration and cross-verification of firmware analysis and network scanning results, the accuracy of vulnerability detection results is ensured. Network scanning verifies the actual reachability of vulnerabilities analyzed by firmware, effectively eliminating false positives; firmware analysis guides network scanning to probe and verify potentially inactive services, significantly reducing false negatives and comprehensively improving vulnerability detection rate and accuracy.
[0042] 2. Enhance hard-coded and weak password detection. Staticly inspect hard-coded information at the firmware level, perform actual verification through network scanning, and combine this with weak password scanning of active services to form a closed loop from discovery to verification, thereby improving the detection capability of such vulnerabilities.
[0043] 3. Deep Adaptation to Industrial Control Systems. This method considers the characteristics of industrial control equipment during implementation, such as customized vulnerability verification scripts and dynamic fingerprint recognition supporting multiple industrial control protocols like S7Comm and DNP3. The final vulnerability report includes customized remediation suggestions for industrial control scenarios, making it more instructive and actionable. Attached Figure Description
[0044] Figure 1This is a flowchart of the industrial control equipment vulnerability detection method that combines firmware analysis and network scanning according to the present invention.
[0045] Figure 2 This is a flowchart of static fingerprint extraction.
[0046] Figure 3 This is a flowchart of the dynamic fingerprint extraction process.
[0047] Figure 4 This is a flowchart of hard-coded and weak password detection. Detailed Implementation
[0048] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, the present invention will be further described in detail below with reference to specific embodiments and accompanying drawings.
[0049] This invention provides a method for detecting vulnerabilities in industrial control equipment that combines firmware analysis and network scanning, such as... Figure 1 As shown, it includes the following steps:
[0050] 1. Extract component static fingerprints (such as version number and code characteristics) through firmware reverse engineering.
[0051] The static fingerprint extraction process is as follows: Figure 2 As shown. First, the firmware image file of the industrial control equipment is obtained. Preliminary feature analysis is performed on the firmware image file, such as recursively scanning the firmware structure, obtaining the software bill of materials of the industrial control equipment according to preset rules (such as file system feature libraries, magic number matching tables), identifying the file system type and operating system architecture, and constructing basic firmware feature information. The firmware image file is then unpacked, disassembled, or decompiled to extract analyzable code snippets and configuration files. By analyzing the firmware content (including binary files, scripts, configuration files, etc.), static fingerprint information such as the operating system used by the industrial control equipment, third-party components (such as library files, applications, web services), and their version numbers is identified. Simultaneously, authoritative vulnerability databases (such as NVD, CNVD, etc.) are queried to obtain a list of known vulnerabilities corresponding to the versions of these third-party components, forming a preliminary component-level potential vulnerability information table.
[0052] 2. Obtain dynamic fingerprints (such as protocol response characteristics and port services) through network traffic scanning.
[0053] The static fingerprint extraction process is as follows: Figure 3As shown, a combination of active probing and passive monitoring is used to collect network traffic and behavioral data from the target industrial control equipment (ICS). For active probing, protocol messages are constructed based on ICS protocol specifications (such as Modbus, S7Comm, DNP3, OPC UA, etc.) and common network protocols (TCP / IP, HTTP, etc.) to send probing requests to the target ICS, capturing and analyzing its response messages. For passive monitoring, a traffic capture device is deployed in a bypass manner to capture the network traffic of the target ICS under normal communication conditions. By parsing the protocol header and payload characteristics, dynamic fingerprint information such as the device's open ports, running services, and the versions of relevant components (if identifiable) is obtained.
[0054] 3. Cross-validation of static and dynamic fingerprints, mutual verification of results, elimination of unreachable vulnerabilities and discovery of hidden vulnerabilities, reducing false positives and false negatives.
[0055] The component-level potential vulnerability information table obtained from firmware analysis in step 1 is cross-validated with the service and dynamic fingerprint information obtained from network scanning in step 2.
[0056] Verifying reachability and reducing false positives: For potential vulnerabilities discovered through firmware analysis, network scanning results are used to verify whether the corresponding components or services are actually running on the device and are network reachable. If a component exists in the firmware, but network scanning shows that its related services are not running, or the exploit path is unreachable at the network level, the vulnerability is removed from the component-level potential vulnerability information table or marked as low-risk (unexploitable), thereby effectively reducing false positives.
[0057] Supplementary scanning to reduce false negatives: For components identified by firmware analysis but whose corresponding services were not found by network scanning (services are not enabled by default, are hidden, or are improperly configured), attempt to activate the services by simulating device configuration (based on the default configuration file or general configuration logic in the firmware, attempt to send configuration commands to the device to enable the relevant services, or load the configuration and start the services in the simulation environment). After successfully activating the services, perform targeted vulnerability scanning and verification to discover vulnerabilities that exist at the firmware level but are not visible to the network by default, thereby reducing false negatives.
[0058] 4. Hard-coded password and weak password detection and verification.
[0059] Step 4 utilizes the verification results from Step 3 to perform hard-coded and weak password detection and verification. Services verified as active and reachable in Step 3 are valid targets for weak password brute-force attacks and hard-coded password verification in Step 4. If Step 3 discovers a service that exists in the firmware but is unreachable by the network, there is no need to perform password testing on that service, thus avoiding invalid attempts and improving detection efficiency.
[0060] The hard-coding and weak password detection process is as follows: Figure 4 As shown. During the firmware analysis process in step 1, sensitive information such as hard-coded passwords, keys, and API tokens are specifically detected in the device firmware.
[0061] For hard-coded passwords discovered during firmware analysis, network scans are conducted to attempt to log in to the device's open network services (such as Telnet, SSH, FTP, and web management interfaces) using these passwords to verify their validity. Simultaneously, for all identified open network services, automated brute-force attacks are performed using a pre-defined weak password dictionary.
[0062] Based on the combined firmware analysis and network verification results, a list of hard-coded passwords and a list of weak passwords related to device network services are generated.
[0063] 5. Conduct a comprehensive assessment to confirm the effectiveness of the vulnerabilities and create a structured vulnerability list.
[0064] Based on the component-level potential vulnerability information table, hard-coded password list, and weak password list obtained from the above steps, the confirmed vulnerabilities are evaluated. Exploit scripts (exp) are written using publicly disclosed vulnerability information, or publicly available scripts are directly used to scan and test third-party components of industrial control equipment. Based on the vulnerability detection results, a component vulnerability list is output, and each type of vulnerability is associated with static characteristic information (such as code offset address), dynamic verification screenshots, and remediation priority (high-risk / medium-risk / low-risk), along with customized suggestions for the industrial control scenario (such as disabling dangerous protocol ports and enabling PLC instruction signing), ultimately forming a report list that can be directly used for security hardening.
[0065] The component-level potential vulnerability information table provided in step 3 is used in step 5 to determine the actual validity of the vulnerabilities. The hard-coded password list and weak password list provided in step 4 are used in step 5 to supplement and verify login and permission-related vulnerabilities.
[0066] Step 5 involves writing exploit scripts based on publicly disclosed vulnerability information or directly using publicly available scripts to further verify the validity of the vulnerability list obtained from the cross-validation in Step 3. The script testing is limited to component vulnerabilities confirmed in Step 3 (e.g., Step 3 identifies a device running OpenSSL version 1.0.2 with a Heartbleed vulnerability). A matching exploit script must be written or invoked based on the publicly available technical details of the vulnerability (e.g., vulnerability principles, exploitation conditions). If the test involves permissions, a valid password from Step 4 is further invoked to complete the pre-login process, ultimately confirming whether the vulnerability can be actually exploited (e.g., whether sensitive device data can be obtained or malicious commands can be executed through the exploit).
[0067] The vulnerability detection results mentioned in step 5 refer to: the vulnerabilities that were retained after cross-validation in step 3 and successfully exploited by EXP in step 5 (confirmed as real high-risk vulnerabilities), the valid hard-coded passwords and weak passwords discovered in step 4 (which are themselves vulnerabilities), and the false positive vulnerabilities excluded in steps 3 and 5 (marked as invalid or fixed).
[0068] The static feature information mentioned in step 5 is directly derived from step 1. Code offset addresses, the library file or application name, etc., are all component static fingerprint information extracted during firmware reverse engineering. Associating these with vulnerabilities can provide developers with fixes and location information.
[0069] The dynamic verification screenshots mentioned in step 5 mainly come from the verification processes in steps 2, 3, and 5. For example: screenshots of the identification results of the network service scan in step 2; screenshots of the command and response when attempting to activate the service in step 3; screenshots of successfully logging into the service using a weak password in step 4; and screenshots of successful exploitation in step 5 (such as the echo of successful command execution, proof of obtaining the content of a specific file, etc.).
[0070] The key point of this invention is:
[0071] 1) Vulnerability Detection Method Based on Mutual Verification of Firmware Analysis and Network Scanning Results. This method combines vulnerability detection based on firmware analysis with vulnerability detection based on network scanning, allowing for mutual verification and reducing false positive and false negative rates in industrial control equipment vulnerability detection. Static firmware analysis obtains information on device components and potential vulnerabilities, which is then cross-verified using information obtained from dynamic network scanning, including service and component activity status and network reachability. Network scanning verifies the reachability of vulnerabilities identified through firmware analysis, eliminating false positives caused by unused components or unreachable networks. Furthermore, supplementary scanning targets services present in the firmware but not directly exposed by the network, uncovering hidden vulnerabilities and reducing false negatives.
[0072] 2) A collaborative detection and verification method for hard-coded passwords and weak passwords, combining firmware analysis and network scanning. First, firmware analysis is used to deeply mine sensitive information such as hard-coded passwords and keys in the device; then, network scanning is used to verify the online connectivity of these hard-coded credentials and to detect weak passwords for all network services, forming a list of hard-coded passwords and weak passwords for the device.
[0073] Another embodiment of the present invention provides an industrial control equipment vulnerability detection system combining firmware analysis and network scanning, comprising:
[0074] The firmware analysis module is used to extract static fingerprints of components in industrial control equipment through firmware reverse analysis.
[0075] The network scanning module is used to obtain the dynamic fingerprint of industrial control equipment by scanning network traffic;
[0076] The dynamic and static fingerprint cross-verification module is used to cross-verify the static and dynamic fingerprints of components. Through cross-verification, unreachable vulnerabilities are eliminated and hidden vulnerabilities are discovered, resulting in a component-level potential vulnerability information table.
[0077] The hard-coded password and weak password detection and verification module is used to detect and verify the hard-coded passwords and weak passwords of industrial control equipment based on the results of cross-validation, and to form a hard-coded password list and a weak password list.
[0078] The comprehensive assessment module is used to evaluate the effectiveness of vulnerabilities based on the component-level potential vulnerability information table, the hard-coded password list, and the weak password list, and to generate a structured vulnerability list.
[0079] The above division of modules is merely illustrative. In practical applications, the functions described above can be assigned to different functional modules as needed to complete all or part of the functions described in the aforementioned method. The specific working process of each module can be found in the corresponding process in the aforementioned method embodiments, and will not be repeated here.
[0080] Another embodiment of the present invention provides a computer device (computer, server, smartphone, etc.) including a memory and a processor, the memory storing a computer program configured to be executed by the processor, the computer program including instructions for performing steps of the method of the present invention.
[0081] Another embodiment of the present invention provides a computer-readable storage medium (such as ROM / RAM, disk, optical disk) that stores a computer program, which, when executed by a computer, implements the steps of the method of the present invention.
[0082] Another embodiment of the present invention provides a computer program product, the computer program product including a computer program, which, when executed by a computer, implements the steps of the method of the present invention.
[0083] The specific embodiments of the present invention disclosed above are intended to help understand the content of the present invention and to implement it accordingly. Those skilled in the art will understand that various substitutions, changes, and modifications are possible without departing from the spirit and scope of the present invention. The present invention should not be limited to the content disclosed in the embodiments of this specification; the scope of protection of the present invention is defined by the claims.
Claims
1. A method for detecting vulnerabilities in industrial control equipment that combines firmware analysis and network scanning, characterized in that, Includes the following steps: Static fingerprints of industrial control equipment components are extracted through firmware reverse analysis. Dynamic fingerprints of industrial control equipment are obtained through network traffic scanning; Cross-validate the static and dynamic fingerprints of components, eliminate unreachable vulnerabilities and discover hidden vulnerabilities through cross-validation, and obtain a component-level potential vulnerability information table. Based on the results of cross-validation, hard-coded passwords and weak passwords of industrial control equipment are detected and verified, and a list of hard-coded passwords and a list of weak passwords are generated. Based on the component-level potential vulnerability information table, the hard-coded password list, and the weak password list, assess the effectiveness of the vulnerabilities and form a structured vulnerability list; The extraction of static fingerprints of industrial control equipment components through firmware reverse engineering includes: Obtain the firmware image file of industrial control equipment; The firmware image file is subjected to feature analysis. The software bill of materials for industrial control equipment is obtained according to preset rules. The file system type and operating system architecture are identified. The basic feature information of the firmware is composed of the software bill of materials, file system type and operating system architecture. Unpack, disassemble, or decompile firmware image files to extract analyzable code snippets and configuration files; By analyzing the firmware content, the operating system, third-party components and their version numbers used by the industrial control equipment are identified as static fingerprint information. At the same time, authoritative vulnerability databases are queried to obtain a list of known vulnerabilities corresponding to the component versions, forming a preliminary component-level potential vulnerability information table. The method of obtaining the dynamic fingerprint of industrial control equipment through network traffic scanning includes: The network traffic and behavior data of the target industrial control equipment are collected by combining active detection and passive monitoring. The active detection includes: constructing protocol messages according to industrial control protocol specifications and general network protocols, sending a detection request to the target industrial control device, and capturing and analyzing its response messages; The passive monitoring includes: deploying a traffic capture device in a bypass mode to capture the network traffic of the target industrial control device in normal communication mode, and analyzing and obtaining the open ports, running services, and versions of related components of the device by parsing the protocol header and load characteristics.
2. The method according to claim 1, characterized in that, The cross-validation of the component's static and dynamic fingerprints includes: For potential vulnerabilities discovered through firmware analysis, the network scan results are used to verify whether the corresponding components or services are actually running on the device and are reachable by the network. If a component exists in the firmware, but the network scan shows that its related services are not started, or the exploit path is not reachable at the network level, the vulnerability is removed from the component-level potential vulnerability information table or marked as low risk, thereby effectively reducing false alarms. For components identified by firmware analysis but whose corresponding services cannot be found by network scanning, we attempt to activate the services by simulating device configuration. After successful activation, we perform targeted vulnerability scanning and verification to discover vulnerabilities that exist at the firmware level but are not visible to the network by default, thereby reducing false negatives.
3. The method according to claim 1, characterized in that, The detection and verification of hard-coded passwords and weak passwords for industrial control equipment includes: During firmware analysis, hard-coded passwords, keys, and API token information are detected in the device firmware. For hard-coded passwords discovered during firmware analysis, network scanning is used to attempt to log in to the device's open network services to verify their validity. At the same time, for all identified open network services, a preset weak password dictionary is used to perform automated weak password brute-force attacks. Based on the combined firmware analysis and network verification results, a list of hard-coded passwords and a list of weak passwords related to device network services are generated.
4. The method according to claim 1, characterized in that, The assessment of vulnerability effectiveness based on the component-level potential vulnerability information table, hard-coded password list, and weak password list includes: Use publicly disclosed vulnerability information to write exploit scripts or directly use publicly available scripts to scan and test the vulnerabilities of third-party components of industrial control equipment, and output a list of component vulnerabilities based on the vulnerability detection results; Each type of vulnerability is associated with static feature information, dynamic verification screenshots, and remediation priorities, and customized suggestions for industrial control scenarios are added to ultimately form a report list that can be directly used for security hardening.
5. The method according to claim 4, characterized in that, The dynamic verification screenshots include: screenshots of the network service scan identification results, screenshots of commands and responses to attempt to activate the service, screenshots of successfully logging into the service using a weak password, and screenshots of successfully performing an exploit.
6. A vulnerability detection system for industrial control equipment combining firmware analysis and network scanning, characterized in that, The system comprising performing the method of any one of claims 1 to 5, wherein the system includes: The firmware analysis module is used to extract static fingerprints of components in industrial control equipment through firmware reverse analysis. The network scanning module is used to obtain the dynamic fingerprint of industrial control equipment by scanning network traffic; The dynamic and static fingerprint cross-verification module is used to cross-verify the static and dynamic fingerprints of components. Through cross-verification, unreachable vulnerabilities are eliminated and hidden vulnerabilities are discovered, resulting in a component-level potential vulnerability information table. The hard-coded password and weak password detection and verification module is used to detect and verify the hard-coded passwords and weak passwords of industrial control equipment based on the results of cross-validation, and to form a hard-coded password list and a weak password list. The comprehensive assessment module is used to evaluate the effectiveness of vulnerabilities based on the component-level potential vulnerability information table, the hard-coded password list, and the weak password list, and to generate a structured vulnerability list.
7. A computer device, characterized in that, It includes a memory and a processor, the memory storing a computer program configured to be executed by the processor, the computer program including instructions for performing the method of any one of claims 1 to 5.
8. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, which, when executed by a computer, implements the method according to any one of claims 1 to 5.
Citation Information
Patent Citations
User data deep forensic analysis method and system oriented to Internet of Things equipment
CN114884717A
Vulnerability mining method based on equipment firmware simulation under novel power system and storage medium
CN115062309A