Enterprise network exposure surface determination method and device, equipment and storage medium
By screening and verifying enterprise network exposure surfaces, and utilizing an asynchronous concurrent architecture and a multi-layered asset filtering mechanism, the problem of low identification efficiency in existing technologies is solved, achieving efficient and accurate network exposure surface identification.
Patent Information
- Application Number
- CN202511716667.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-21
- Publication Date
- 2026-02-10
AI Technical Summary
Existing technologies are inefficient and have limited coverage in identifying enterprise network exposure surfaces, have low automation levels, and are difficult to adapt to the management needs of large-scale enterprise assets.
By determining domain asset data, port data, and network application data based on the target enterprise's domain name, valid subdomains are screened using preset keywords and fingerprint recognition technology, and access verification, port authenticity verification, and network application consistency verification are performed. Combined with an asynchronous concurrent architecture and a multi-layer asset filtering mechanism, multi-format reports are generated.
It improves the efficiency and accuracy of identifying enterprise network exposure surfaces, reduces the false positive rate, and enhances data quality and automation.
Smart Images

Figure CN121508991A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network technology, and in particular to a method, apparatus, device, and storage medium for determining the exposure surface of an enterprise network. Background Technology
[0002] With the continuous development of the internet and the application of digital technologies such as 5G and cloud computing, the number of enterprise assets connected to networks is growing rapidly, leading to a corresponding increase in the network exposure surface and placing greater pressure on enterprise network security management. Currently, enterprises mainly rely on a combination of traditional tools and manual operations to identify network exposure surfaces.
[0003] However, relying on traditional tools and extensive manual operations results in low efficiency and limited coverage in exposure surface discovery, with a low degree of automation in the overall process, making it difficult to meet the management needs of large-scale enterprise assets. Therefore, improving the efficiency of exposure surface discovery and the accuracy of exposure surface identification has become an urgent problem to be solved. Summary of the Invention
[0004] In view of this, embodiments of this application provide a method, apparatus, device, and storage medium for determining the enterprise network exposure surface, thereby improving the efficiency and accuracy of enterprise exposure surface identification.
[0005] This application mainly includes the following aspects: In a first aspect, embodiments of this application provide a method for determining the exposed surface of an enterprise network, the method comprising: Based on the target enterprise domain name, determine the domain asset data, port data, and network application data of multiple subdomains related to the target enterprise domain name, as well as the associated data of the target enterprise domain name; Based on the first preset keyword, the second preset keyword, and the first preset field, subdomains that meet the valid rules are selected from all subdomains, and the subdomains that meet the valid rules are determined as valid subdomains; Based on the domain name asset data, access verification is performed on each valid subdomain, and valid subdomains that have successfully passed access verification are selected from all valid subdomains. Based on the expected port service and port data, the authenticity of the port of each subdomain is verified, and the ports that have been successfully verified are selected from all the ports of the subdomains. Based on the expected network application fingerprint and network application data, the network application corresponding to each subdomain is verified for consistency, and the network application that has successfully verified for consistency is selected from the network applications of the subdomain. The associated data, the domain asset data corresponding to the filtered subdomains, the port data corresponding to the filtered ports, and the network application data corresponding to the filtered network applications are identified as the publicly available data of the target enterprise.
[0006] Furthermore, the domain name asset data includes: ICP filing information and certificate information; The step of filtering subdomains that meet the valid rules from all subdomains based on the first preset keyword, the second preset keyword, and the first preset field, and determining the subdomains that meet the valid rules as valid subdomains, includes: Match multiple subdomains with CDN domain characteristics, and mark each subdomain that matches the CDN domain characteristics as a CDN domain; Each subdomain that does not match the CDN domain characteristics is matched with the intermediate domain characteristics, and each subdomain that matches the intermediate domain characteristics is marked as an intermediate domain. Filter out the ICP filing information containing the first preset keyword from the subdomains marked as CDN domains and intermediate domains, and determine the subdomains corresponding to the filtered ICP filing information as the first initial subdomains; From all the certificate information corresponding to the first initial subdomain, filter out the certificate information that contains the second preset keyword, and determine the first initial subdomain corresponding to the filtered certificate information as the second initial subdomain; From all the certificate information corresponding to the second initial subdomain, filter out the certificate information that contains the first preset field, and determine the second initial subdomain corresponding to the filtered certificate information as the valid subdomain.
[0007] Furthermore, based on the domain name asset data, access verification is performed on each valid subdomain, and subdomains that have successfully passed access verification are selected from all valid subdomains to obtain the selected subdomains, including: For each valid subdomain, DNS is used to resolve the valid subdomain. If at least one IP address corresponding to the valid subdomain is not resolved, it is determined that the valid subdomain is inaccessible; if the IP address corresponding to the valid subdomain is resolved, it is determined whether the network application service corresponding to the valid subdomain is accessible. If the network application service corresponding to the valid subdomain is accessible, the access verification of the valid subdomain is successful; if the network application service corresponding to the valid subdomain is inaccessible, it is determined whether the IP address corresponding to the valid subdomain is online. If the IP address corresponding to the valid subdomain is online, the access verification for the valid subdomain is successful; if the IP address corresponding to the valid subdomain is offline, the valid subdomain is inaccessible.
[0008] Furthermore, the determination method also includes: For each technology type corresponding to each subdomain, when a second preset field is matched from the response header corresponding to that technology type, the first confidence level corresponding to that technology type is determined based on the weight corresponding to the second preset field. When a service identifier corresponding to a technology type is matched from the fingerprint rules corresponding to that technology type, the second confidence level corresponding to that technology type is determined based on the weight corresponding to the service identifier. When a third preset field is matched from the rule base corresponding to the technology type, the third confidence level corresponding to the technology type is determined based on the weight corresponding to the third preset field. The sum of the first confidence level, the second confidence level, and the third confidence level is determined as the confidence level of this technology type. Filter out confidence levels greater than the preset confidence threshold from all technology types; The average of the filtered confidence scores is determined as the confidence score of the subdomain. Match the port corresponding to each subdomain with the high-risk port database, and determine the matched port as the high-risk port of the subdomain. The preset fingerprint recognition features corresponding to each subdomain are matched with the vulnerability feature database, and the matched preset fingerprint recognition features are determined as the vulnerability features of the subdomain. The confidence level of each subdomain, the high-risk port of at least one subdomain, and the vulnerability characteristics of at least one subdomain are identified as data for enhancing network applications.
[0009] Furthermore, the associated data includes: certificate information for multiple subdomains related to the target enterprise domain; the determination method further includes: Based on the target enterprise domain name, filter out the subdomains containing certificate data from all subdomains, and parse the certificate data corresponding to each filtered subdomain. The parsed certificate data is identified as certificate information.
[0010] Furthermore, the associated data includes: the registration information of the target company's domain name, and the names of subsidiaries under the target company that exceed a preset shareholding ratio, and their corresponding association data.
[0011] Furthermore, the determination method also includes: Based on publicly available data from the target company, generate a report in a preset format to display the target company's exposure.
[0012] Secondly, embodiments of this application also provide an apparatus for determining the enterprise network exposure surface, the apparatus comprising: The data determination module is used to determine the domain asset data, port data, and network application data of multiple subdomains related to the target enterprise domain name, as well as the associated data of the target enterprise domain name, based on the target enterprise domain name. The first subdomain filtering module is used to filter subdomains that meet the valid rules from all subdomains based on the first preset keyword, the second preset keyword and the first preset field, and to determine the subdomains that meet the valid rules as valid subdomains. The second subdomain filtering module is used to perform access verification on each valid subdomain based on the domain asset data, and to filter out the valid subdomains that have successfully passed the access verification from all valid subdomains. The port filtering module is used to verify the authenticity of ports for each subdomain based on expected port services and port data, and to filter out ports that have successfully passed the authenticity verification from all subdomain ports. The network application filtering module is used to perform consistency verification on the network applications corresponding to each subdomain based on the expected network application fingerprint and network application data, and to filter out the network applications that have successfully passed the consistency verification from the network applications of the subdomain. The exposure surface determination module is used to determine the associated data, the domain asset data corresponding to the filtered subdomains, the port data corresponding to the filtered ports, and the network application data corresponding to the filtered network applications as the public data of the target enterprise.
[0013] Thirdly, embodiments of this application also provide an electronic device, including: a processor, a memory, and a bus, wherein the memory stores machine-readable instructions executable by the processor, and when the electronic device is running, the processor communicates with the memory through the bus, and the machine-readable instructions are executed by the processor to perform the steps of the method for determining the enterprise network exposure surface as described in the first aspect or any possible implementation of the first aspect.
[0014] Fourthly, embodiments of this application also provide a computer-readable storage medium storing a computer program, which, when executed by a processor, performs the steps of the method for determining the enterprise network exposure surface described in the first aspect or any possible implementation of the first aspect.
[0015] This application provides a method, apparatus, device, and storage medium for determining the network exposure surface of an enterprise. The method determines domain asset data, port data, and network application data of multiple subdomains related to a target enterprise domain, as well as associated data of the target enterprise domain. It then filters subdomains that meet valid rules from all subdomains, designating them as valid subdomains; filters valid subdomains that have successfully undergone access verification from all valid subdomains; filters ports that have successfully undergone authenticity verification from all subdomain ports; filters network applications that have successfully undergone consistency verification from the network applications of the subdomains; and determines the associated data, the domain asset data corresponding to the filtered subdomains, the port data corresponding to the filtered ports, and the network application data corresponding to the filtered network applications as the publicly available data of the target enterprise.
[0016] This improves the efficiency and accuracy of identifying enterprise exposure surfaces.
[0017] To make the above-mentioned objectives, features and advantages of this application more apparent and understandable, preferred embodiments are described below in detail with reference to the accompanying drawings. Attached Figure Description
[0018] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of this application and should not be regarded as a limitation of the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.
[0019] Figure 1 This document illustrates one of the flowcharts for a method of determining an enterprise network exposure surface provided in an embodiment of this application; Figure 2 A second flowchart of a method for determining an enterprise network exposure surface provided in an embodiment of this application is shown; Figure 3 A schematic diagram of the structure of an apparatus for determining the exposure surface of an enterprise network provided in an embodiment of this application is shown; Figure 4 A schematic diagram of the structure of an electronic device provided in an embodiment of this application is shown. Detailed Implementation
[0020] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. It should be understood that the drawings in this application are for illustrative and descriptive purposes only and are not intended to limit the scope of protection of this application. Furthermore, it should be understood that the schematic drawings are not drawn to scale. The flowcharts used in this application illustrate operations implemented according to some embodiments of this application. It should be understood that the operations in the flowcharts may not be implemented in sequence, and steps without logical contextual relationships may be reversed or implemented simultaneously. In addition, those skilled in the art, guided by the content of this application, may add one or more other operations to the flowcharts, or remove one or more operations from the flowcharts.
[0021] Furthermore, the described embodiments are merely some, not all, of the embodiments of this application. The components of the embodiments of this application described and illustrated herein can typically be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of this application provided in the accompanying drawings is not intended to limit the scope of the claimed application, but merely to illustrate selected embodiments of the application. All other embodiments obtained by those skilled in the art based on the embodiments of this application without inventive effort are within the scope of protection of this application.
[0022] The methods, apparatus, electronic devices, or computer-readable storage media described in this application can be applied to any scenario that requires determining the enterprise network exposure surface. This application does not limit the specific application scenario, and any scheme using the enterprise network exposure surface determination method and apparatus provided in this application is within the protection scope of this application.
[0023] It is worth noting that with the continuous development of the internet and the application of digital technologies such as 5G and cloud computing, the number of enterprise assets connected to networks is growing rapidly, leading to a corresponding increase in the network exposure surface and placing greater pressure on enterprise network security management. Currently, enterprises mainly rely on a combination of traditional tools and manual operations to identify network exposure surfaces. However, relying on traditional tools and extensive manual operations results in low efficiency and limited coverage in exposure surface discovery, low automation of the overall process, and difficulty in meeting the management needs of large-scale enterprise assets. Therefore, improving the efficiency and accuracy of exposure surface discovery has become an urgent problem to be solved.
[0024] To address the aforementioned issues, this application proposes a method, apparatus, device, and storage medium for determining enterprise network exposure surfaces, thereby improving the efficiency and accuracy of enterprise exposure surface identification.
[0025] To facilitate understanding of this application, the technical solutions provided in this application will be described in detail below with reference to specific embodiments.
[0026] In this embodiment, the traditional process for identifying network exposure surfaces is as follows: First, input the target domain name, then use a subdomain discovery tool (such as Sublist3r, Amass) to search for subdomains; next, use a port scanning tool (such as Nmap, Masscan) to scan ports; then manually query information such as FOFA and WHOIS; then manually filter invalid data, performing CDN-free and intermediate state filtering; next, manually verify the asset liveness status (including subdomains, ports, Web, etc.); finally, output a single-format report (TXT, JSON).
[0027] Existing technologies suffer from the following problems: 1. Subdomain discovery: While tools like Sublist3r and Amass are used to obtain subdomains through DNS brute-force attacks and third-party interfaces, these methods only support basic domain collection and lack intelligent filtering mechanisms, failing to effectively exclude irrelevant domains. 2. Port scanning: Relying on tools like Nmap and Masscan for synchronous or low-concurrency port scanning, these tools can only output port numbers and basic protocol information, unable to correlate with specific web application information. 3. External data query: Manual queries through web space search engines like FOFA require manual processing of large amounts of page data and lack optimization for API request frequency, making them prone to being blocked due to frequent queries. 4. WHOIS information acquisition: Using WHOIS command-line tools or web page queries, the synchronous execution method makes large-scale domain query efficiency extremely low, lacks caching mechanisms, and repeat queries are time-consuming. 5. Efficiency: Traditional tools use synchronous execution modes, requiring several hours for large-scale asset scanning; WHOIS queries lack concurrency control, resulting in long processing times. 6. Accuracy: Web fingerprinting relies on single-dimensional information and cannot effectively distinguish between reliable and suspected results. 7. Invalid Information Interference: Insufficient subdomain filtering functionality, only able to exclude obviously invalid domains, failing to identify CDN domains and intermediate domains, resulting in a large number of invalid assets. 8. API Calls: Web search engines like FOFA lack intelligent retry and latency control, leading to low success rates for retrieving multi-page data and easily triggering frequency limits. 9. Reports: Most tools only support a single format; multi-format reports require manual conversion, and critical information such as vulnerability severity levels and confidence scores is easily lost, failing to meet enterprise compliance analysis needs. 10. Automated Asset Verification: Manual verification of subdomain viability and port service authenticity is required; large-scale asset verification is time-consuming and prone to omissions, failing to ensure the authenticity of scan results.
[0028] Please see Figure 1 , Figure 1This is one of the flowcharts for a method of determining an enterprise network exposure surface provided in an embodiment of this application.
[0029] like Figure 1 As shown in the embodiments of this application, the method for determining the enterprise network exposure surface includes the following steps: Step S101: Based on the target enterprise domain name, determine the domain name asset data, port data, and network application data of multiple subdomains related to the target enterprise domain name, as well as the associated data of the target enterprise domain name.
[0030] Here, the associated data of the target company's domain name includes: the registration information of the target company's domain name, the certificate information of multiple subdomains related to the target company's domain name, and the names of subsidiaries under the target company that exceed the preset shareholding ratio and their corresponding association data.
[0031] In this embodiment, the WHOIS database is used to obtain the registration information of the target domain name. The registration information includes the registrant's name, organization, email address, telephone number, registrar, domain status, creation date, update date, expiration date, and DNS server information. A limit of up to 10 concurrent queries is set using WHOIS to ensure effective management of system resources and efficient execution of query operations. To improve query efficiency and reduce duplicate requests, a 1-hour caching mechanism is implemented, storing the domain name, its corresponding results, and timestamps for each query in a dictionary. Furthermore, a 10-second control is set to address potential network latency or service response delays.
[0032] In this embodiment, the certificate information of multiple subdomains related to the target enterprise domain is determined through the following steps: Based on the target enterprise domain, subdomains containing certificate data are selected from all subdomains, and the certificate data corresponding to each selected subdomain is parsed; the parsed certificate data is determined as certificate information. Here, subdomains with SSL certificates are filtered and selected, and an asynchronous concurrent SSL connection is opened using the asyncio library to obtain detailed certificate information, including the certificate issuer, validity period, and Subject Alternate Name (SAN) extended data.
[0033] In this embodiment, the names of subsidiaries holding more than a preset controlling stake and their corresponding relationship data under the target company are determined through the following steps: Based on the target company's ID and the target company itself, the names of subsidiaries holding more than a preset controlling stake and their corresponding relationship data are determined. The relationship data represents the controlling stake. As an example, the preset controlling stake is 50%. Specifically, the target company's equity relationship data is obtained by concatenating the target company's ID and domain name into the URL of the API request. From the obtained data, companies with a controlling stake exceeding 50% are selected, and their names and controlling stakes are extracted.
[0034] In the embodiments of this application, the FOFA search engine interface can be used to query the target enterprise domain name entered by the user, and obtain multiple subdomains related to the target domain name, as well as domain asset data, port data, and network application data of the multiple subdomains, and the registration information of the target enterprise domain name. Here, the request retry process of the FOFA search engine interface is optimized by implementing an exponential backoff algorithm and a random jitter mechanism. After the initial request fails, the script will wait for time t. If it fails again, the delay is increased to 2t, and a ±10% random jitter is added to each retry to reduce the possibility of request conflicts. In addition, an intelligent retry mechanism is set up to perform a maximum of 3 attempts to ensure that the required data can be obtained to the maximum extent when the network is unstable or there are service response problems, while avoiding excessive requests from affecting system performance.
[0035] Step S102: Based on the first preset keyword, the second preset keyword, and the first preset field, select subdomains that meet the valid rules from all subdomains, and determine the subdomains that meet the valid rules as valid subdomains.
[0036] Here, the domain name asset data includes: ICP filing information and certificate information, etc.
[0037] Regarding step S102, as an example in specific implementation, it may include the following steps: Step S1021: Match multiple subdomains with CDN domain characteristics, and mark each subdomain that matches the CDN domain characteristics as a CDN domain.
[0038] Step S1022: Match each subdomain that does not match the CDN domain name feature with the intermediate domain name feature, and mark each subdomain that matches the intermediate domain name feature as an intermediate domain name.
[0039] Step S1023: Filter out the ICP filing information containing the first preset keyword from the subdomains marked as CDN domains and intermediate domains, and determine the subdomains corresponding to the filtered ICP filing information as the first initial subdomains.
[0040] Here, the first preset keyword is related to ICP filing information.
[0041] Step S1024: Select certificate information containing the second preset keyword from all certificate information corresponding to the first initial subdomain, and determine the first initial subdomain corresponding to the selected certificate information as the second initial subdomain.
[0042] Here, the second preset keyword is related to certificate information. As an example, the second preset keyword is Subject.
[0043] Step S1025: Filter out the certificate information containing the first preset field from all the certificate information corresponding to the second initial subdomain, and determine the second initial subdomain corresponding to the filtered certificate information as a valid subdomain.
[0044] Here, the first preset field is the cert.not_after field of the certificate information. The first preset field is compared with the current time; if it has expired, the subdomain is determined to be invalid.
[0045] Return to reference Figure 1 Step S103: Based on the domain name asset data, perform access verification on each valid subdomain and select the valid subdomains that have successfully passed the access verification from all valid subdomains.
[0046] Regarding step S103, as an example in specific implementation, it may include the following steps: Step S1031: For each valid subdomain, use DNS to resolve the valid subdomain. If at least one IP address corresponding to the valid subdomain is not resolved, then it is determined that the valid subdomain cannot be accessed.
[0047] Step S1032: If the IP address corresponding to the valid subdomain is resolved, determine whether the network application service corresponding to the valid subdomain can be accessed.
[0048] Here, if the network application service corresponding to the valid subdomain returns a status code indicating access failure, it is determined that the network application service corresponding to the valid subdomain is inaccessible.
[0049] Step S1033: If the network application service corresponding to the valid subdomain can be accessed, then the access verification of the valid subdomain is confirmed to be successful.
[0050] Step S1034: If the network application service corresponding to the valid subdomain is inaccessible, then determine whether the IP address corresponding to the valid subdomain is online.
[0051] Here, a ping command is sent to the IP address corresponding to the valid subdomain. If the IP address does not respond, it is determined that the IP address corresponding to the valid subdomain is offline.
[0052] Step S1035: If the IP address corresponding to the valid subdomain is online, then the access verification of the valid subdomain is confirmed to be successful.
[0053] Step S1036: If the IP address corresponding to the valid subdomain is offline, then the valid subdomain is determined to be inaccessible.
[0054] Here, by combining DNS resolution and optional ping operations to verify the liveness status of subdomains, the false judgment of service unavailability that may be caused by relying solely on DNS resolution is effectively avoided.
[0055] Step S104: Based on the expected port service and port data, verify the authenticity of the port of each subdomain, and select the ports that have successfully verified authenticity from all the ports of the subdomains.
[0056] Here, port data includes: IP address, communication port, port communication protocol, port service type, and port service fingerprint. For each subdomain, if the port corresponding to the subdomain is open and the port service corresponding to the subdomain matches the expected service, the port verification for that subdomain is considered successful.
[0057] Step S105: Based on the expected network application fingerprint and network application data, perform consistency verification on the network application corresponding to each subdomain, and select the network application that has successfully passed the consistency verification from the network applications of the subdomain.
[0058] Here, web application data includes: links, page titles, server and banner information, etc. For each subdomain's corresponding web application, when the existence of the web application service corresponding to that subdomain is detected and the fingerprint of the web application corresponding to that subdomain matches the expected web application fingerprint, it is determined that the web application corresponding to that subdomain has been successfully verified.
[0059] In one possible implementation, the determining method further includes: Step S201: For each technology type corresponding to each subdomain, when a second preset field is matched from the response header corresponding to the technology type, the first confidence level corresponding to the technology type is determined based on the weight corresponding to the second preset field.
[0060] The types of technologies here include: web application (Web) frameworks, web application servers, and front-end technologies.
[0061] In this application, the second preset field is the Server field (e.g., Django's X-Powered-By: Django). The Server field contains server response header information. As an example, the weight of the second preset field is 50%. Specifically, this step involves counting the total number of header fields (total_headers) in the set rule base. If the rule base defines 3 Servers, then total_headers is 3. Next, the actual server response headers are checked, and the number of Servers is counted. Then, the confidence score of the Server is calculated using the formula (header_matches / total_headers) × 50%. If a Server is matched, the source of the match is recorded. As an example, if a rule specifies that Django has 3 specific Servers, and 2 are actually matched, then the confidence score of the Server is calculated as (2 / 3) × 50% ≈ 33.3%.
[0062] Step S202: When a service identifier corresponding to a technology type is matched from the fingerprint rules corresponding to that technology type, the second confidence level corresponding to that technology type is determined based on the weight corresponding to the service identifier.
[0063] Here, the service identifier is "banner". As an example, the weight corresponding to the service identifier is 30%. When the HTTP response header has no header, the fingerprint rules are checked for the presence of "banner" (e.g., "nginx / " for Nginx). If at least one matching feature (e.g., "nginx / ") is found in the fingerprint rules, the confidence level is 30%. The source of the match is also recorded (e.g., "banner:nginx / ").
[0064] Step S203: When a third preset field is matched from the rule base corresponding to the technology type, the confidence level corresponding to the technology type is determined based on the weight corresponding to the third preset field.
[0065] As an example, the third preset field is the `html` field (tags, specific JS libraries). The weight of the third preset field is 20%. In this step, the total number of HTML features (total_patterns) in the set rules is counted. For example, if there are 3 HTML rules for WordPress, then `total_patterns` is 3. Next, the HTML code of the page is analyzed, and the number of features actually matched (html_matches) is calculated. For example, if the page contains two features, "wp-content" and "WordPress", then `html_matches` is 2. Subsequently, the confidence of the HTML contribution is calculated based on the matching results, using the formula (html_matches / total_patterns) × 20%. The source of the match is also recorded (e.g., "html:wp-content"). As an example, if a rule has 3 HTML rules for WordPress and actually matches 2, then the confidence of the HTML is calculated as (2 / 3) × 20% ≈ 13.3%.
[0066] Step S204: The sum of the first confidence level, the second confidence level, and the third confidence level is determined as the confidence level of the technology type.
[0067] Step S205: Filter out confidence scores that are greater than the preset confidence threshold from all technology types.
[0068] Here, the preset confidence threshold is 30%. In this embodiment, if at least one of the first, second, and third confidence levels of a technology type is less than the preset confidence threshold, the corresponding confidence level is not recorded.
[0069] Step S206: The average value of the filtered confidence scores is determined as the confidence score of the subdomain.
[0070] As an example, if Django's confidence level is 33.3%, Nginx's is 30%, and jQuery's is 13.3%, then jQuery is excluded because its confidence level does not reach the preset confidence threshold of 30%. Ultimately, the overall confidence level is (33.3% + 30%) / 2 ≈ 31.6%.
[0071] In this embodiment, if a middleware name, such as "nginx" in "Server: nginx", is directly found in the Server field of the HTTP response header, and this middleware (web application server) has not yet been identified by the above method, the second confidence level will be directly determined to be 60%, and the source will be marked. As an HTTP standard header, the Server field directly identifies the service type with high accuracy, so there is no need to calculate it by splitting it into multiple dimensions.
[0072] Step S207: Match the port corresponding to each subdomain with the high-risk port database, and determine the matched port as the high-risk port of the subdomain.
[0073] Step S208: Match the preset fingerprint recognition features corresponding to each subdomain with the vulnerability feature database, and determine the matched preset fingerprint recognition features as the vulnerability features of the subdomain.
[0074] Here, the preset fingerprint recognition features are the second preset field, the service identifier, and the third preset field.
[0075] Step S209: The confidence level of each subdomain, the high-risk port of at least one subdomain, and the vulnerability characteristics of at least one subdomain are identified as enhanced network application data.
[0076] Here, enhanced network application data can be synchronously generated into reports to assist in the analysis of exposure surfaces.
[0077] In one possible implementation, such as Figure 2 As shown, the determination method further includes: generating a report in a preset format based on the publicly available data of the target company to display the exposure of the target company.
[0078] Here, the preset formats can include JSON, HTML, and Excel.
[0079] This application improves the efficiency and accuracy of enterprise exposure surface identification by adopting an asynchronous concurrent architecture and multi-layered asset processing combined with automated verification and consistency report output. Core technologies include an asynchronous parallel processing architecture implemented using asyncio, significantly increasing asset scanning speed; multi-dimensional network service fingerprinting and confidence scoring, effectively reducing false positive rates; and a multi-layered asset filtering mechanism to reduce interference from invalid assets and improve data quality.
[0080] This application provides a method for determining the network exposure surface of an enterprise, which improves the efficiency and accuracy of enterprise exposure surface identification.
[0081] Based on the same application concept, this application also provides an enterprise network exposure surface determination device corresponding to the enterprise network exposure surface determination method provided in the above embodiments. Since the principle of the device in this application embodiment is similar to the enterprise network exposure surface determination method in the above embodiments of this application, the implementation of the device can refer to the implementation of the method, and the repeated parts will not be described again.
[0082] Please see Figure 3 , Figure 3 This is a schematic diagram of a device for determining the exposure surface of an enterprise network, provided in an embodiment of this application.
[0083] like Figure 3 As shown in the embodiment of this application, the enterprise network exposure surface determination device 310 includes: The data determination module 311 is used to determine, based on the target enterprise domain name, the domain asset data, port data, and network application data of multiple subdomains related to the target enterprise domain name, as well as the associated data of the target enterprise domain name; The first subdomain filtering module 312 is used to filter subdomains that meet the valid rules from all subdomains based on the first preset keyword, the second preset keyword and the first preset field, and to determine the subdomains that meet the valid rules as valid subdomains. The second subdomain filtering module 313 is used to perform access verification on each valid subdomain based on the domain asset data, and to filter out the valid subdomains that have successfully passed the access verification from all valid subdomains. The port filtering module 314 is used to verify the authenticity of the ports of each subdomain based on the expected port service and port data, and to filter out the ports that have been successfully verified from all the ports of the subdomains. The network application filtering module 315 is used to perform consistency verification on the network applications corresponding to each subdomain based on the expected network application fingerprint and network application data, and to filter out the network applications that have successfully passed the consistency verification from the network applications of the subdomain. The exposure surface determination module 316 is used to determine the associated data, the domain asset data corresponding to the filtered subdomains, the port data corresponding to the filtered ports, and the network application data corresponding to the filtered network applications as the public data of the target enterprise.
[0084] Furthermore, the domain name asset data includes: ICP filing information and certificate information; The first subdomain filtering module 312 is specifically used for: Match multiple subdomains with CDN domain characteristics, and mark each subdomain that matches the CDN domain characteristics as a CDN domain; Each subdomain that does not match the CDN domain characteristics is matched with the intermediate domain characteristics, and each subdomain that matches the intermediate domain characteristics is marked as an intermediate domain. Filter out the ICP filing information containing the first preset keyword from the subdomains marked as CDN domains and intermediate domains, and determine the subdomains corresponding to the filtered ICP filing information as the first initial subdomains; From all the certificate information corresponding to the first initial subdomain, filter out the certificate information that contains the second preset keyword, and determine the first initial subdomain corresponding to the filtered certificate information as the second initial subdomain; From all the certificate information corresponding to the second initial subdomain, filter out the certificate information that contains the first preset field, and determine the second initial subdomain corresponding to the filtered certificate information as the valid subdomain.
[0085] Furthermore, the second subdomain filtering module 313 is specifically used for: For each valid subdomain, DNS is used to resolve the valid subdomain. If at least one IP address corresponding to the valid subdomain is not resolved, it is determined that the valid subdomain is inaccessible; if the IP address corresponding to the valid subdomain is resolved, it is determined whether the network application service corresponding to the valid subdomain is accessible. If the network application service corresponding to the valid subdomain is accessible, the access verification of the valid subdomain is successful; if the network application service corresponding to the valid subdomain is inaccessible, it is determined whether the IP address corresponding to the valid subdomain is online. If the IP address corresponding to the valid subdomain is online, the access verification for the valid subdomain is successful; if the IP address corresponding to the valid subdomain is offline, the valid subdomain is inaccessible.
[0086] Furthermore, the determining device further includes: a confidence level determination module; the confidence level determination module is specifically used for: For each technology type corresponding to each subdomain, when a second preset field is matched from the response header corresponding to that technology type, the first confidence level corresponding to that technology type is determined based on the weight corresponding to the second preset field. When a service identifier corresponding to a technology type is matched from the fingerprint rules corresponding to that technology type, the second confidence level corresponding to that technology type is determined based on the weight corresponding to the service identifier. When a third preset field is matched from the rule base corresponding to the technology type, the third confidence level corresponding to the technology type is determined based on the weight corresponding to the third preset field. The sum of the first confidence level, the second confidence level, and the third confidence level is determined as the confidence level of this technology type. Filter out confidence levels greater than the preset confidence threshold from all technology types; The average of the filtered confidence scores is determined as the confidence score of the subdomain. Match the port corresponding to each subdomain with the high-risk port database, and determine the matched port as the high-risk port of the subdomain. The preset fingerprint recognition features corresponding to each subdomain are matched with the vulnerability feature database, and the matched preset fingerprint recognition features are determined as the vulnerability features of the subdomain. The confidence level of each subdomain, the high-risk port of at least one subdomain, and the vulnerability characteristics of at least one subdomain are identified as data for enhancing network applications.
[0087] Furthermore, the associated data includes: certificate information for multiple subdomains related to the target enterprise domain; the determination method further includes: Based on the target enterprise domain name, filter out the subdomains containing certificate data from all subdomains, and parse the certificate data corresponding to each filtered subdomain. The parsed certificate data is identified as certificate information.
[0088] Furthermore, the associated data includes: the registration information of the target company's domain name, and the names of subsidiaries under the target company that exceed a preset shareholding ratio, and their corresponding association data.
[0089] Furthermore, the determining device also includes a report generation module; the report generation module is specifically used to generate a report in a preset format that displays the exposure of the target company based on the publicly available data of the target company.
[0090] This application provides a device for determining the network exposure surface of an enterprise, which improves the efficiency and accuracy of identifying the network exposure surface.
[0091] Please see Figure 4 , Figure 4 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application.
[0092] like Figure 4 As shown, the electronic device 400 includes a processor 410, a memory 420, and a bus 430.
[0093] The memory 420 stores machine-readable instructions executable by the processor 410. When the electronic device 400 is running, the processor 410 communicates with the memory 420 via the bus 430. When the machine-readable instructions are executed by the processor 410, they can perform the operations described above. Figure 1 and Figure 2 The steps of the method for determining the enterprise network exposure surface in the illustrated method embodiment can be found in the method embodiment for specific implementation, and will not be repeated here.
[0094] This application also provides a computer-readable storage medium storing a computer program, which, when executed by a processor, can perform the above-described actions. Figure 1 and Figure 2 The steps of the method for determining the enterprise network exposure surface in the illustrated method embodiment can be found in the method embodiment for specific implementation, and will not be repeated here.
[0095] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems and devices described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here. In the several embodiments provided in this application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of units is only a logical functional division; in actual implementation, there may be other division methods. Furthermore, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Another point is that the displayed or discussed mutual coupling or direct coupling or communication connection may be through some communication interfaces; the indirect coupling or communication connection of devices or units may be electrical, mechanical, or other forms.
[0096] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0097] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.
[0098] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a processor-executable, non-volatile, computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0099] The above are merely specific embodiments of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A method for determining the network exposure surface of an enterprise, characterized in that, The determination method includes: Based on the target enterprise domain name, determine the domain asset data, port data, and network application data of multiple subdomains related to the target enterprise domain name, as well as the associated data of the target enterprise domain name; Based on the first preset keyword, the second preset keyword, and the first preset field, subdomains that meet the valid rules are selected from all subdomains, and the subdomains that meet the valid rules are determined as valid subdomains; Based on the domain name asset data, access verification is performed on each valid subdomain, and valid subdomains that have successfully passed access verification are selected from all valid subdomains. Based on the expected port service and port data, the authenticity of the port of each subdomain is verified, and the ports that have been successfully verified are selected from all the ports of the subdomains. Based on the expected network application fingerprint and network application data, the network application corresponding to each subdomain is verified for consistency, and the network application that has successfully verified consistency is selected from the network applications of the subdomain. The associated data, the domain asset data corresponding to the filtered subdomains, the port data corresponding to the filtered ports, and the network application data corresponding to the filtered network applications are identified as the publicly available data of the target enterprise.
2. The method for determining the enterprise network exposure surface according to claim 1, characterized in that, The domain name asset data includes: ICP filing information and certificate information; The step of filtering subdomains that meet the valid rules from all subdomains based on the first preset keyword, the second preset keyword, and the first preset field, and determining the subdomains that meet the valid rules as valid subdomains, includes: Match multiple subdomains with CDN domain characteristics, and mark each subdomain that matches the CDN domain characteristics as a CDN domain; Each subdomain that does not match the CDN domain characteristics is matched with the intermediate domain characteristics, and each subdomain that matches the intermediate domain characteristics is marked as an intermediate domain. Filter out the ICP filing information containing the first preset keyword from the subdomains marked as CDN domains and intermediate domains, and determine the subdomains corresponding to the filtered ICP filing information as the first initial subdomains; From all the certificate information corresponding to the first initial subdomain, filter out the certificate information that contains the second preset keyword, and determine the first initial subdomain corresponding to the filtered certificate information as the second initial subdomain; From all the certificate information corresponding to the second initial subdomain, filter out the certificate information that contains the first preset field, and determine the second initial subdomain corresponding to the filtered certificate information as the valid subdomain.
3. The method for determining the enterprise network exposure surface according to claim 2, characterized in that, Based on the domain name asset data, access verification is performed on each valid subdomain, and subdomains that have successfully passed access verification are selected from all valid subdomains to obtain the selected subdomains, including: For each valid subdomain, DNS is used to resolve the valid subdomain. If at least one IP address corresponding to the valid subdomain is not resolved, it is determined that the valid subdomain is inaccessible; if the IP address corresponding to the valid subdomain is resolved, it is determined whether the network application service corresponding to the valid subdomain is accessible. If the network application service corresponding to the valid subdomain is accessible, the access verification of the valid subdomain is successful; if the network application service corresponding to the valid subdomain is inaccessible, it is determined whether the IP address corresponding to the valid subdomain is online. If the IP address corresponding to the valid subdomain is online, the access verification for the valid subdomain is successful; if the IP address corresponding to the valid subdomain is offline, the valid subdomain is inaccessible.
4. The method for determining the enterprise network exposure surface according to claim 1, characterized in that, The determination method further includes: For each technology type corresponding to each subdomain, when a second preset field is matched from the response header corresponding to that technology type, the first confidence level corresponding to that technology type is determined based on the weight corresponding to the second preset field. When a service identifier corresponding to a technology type is matched from the fingerprint rules corresponding to that technology type, the second confidence level corresponding to that technology type is determined based on the weight corresponding to the service identifier. When a third preset field is matched from the rule base corresponding to the technology type, the third confidence level corresponding to the technology type is determined based on the weight corresponding to the third preset field. The sum of the first confidence level, the second confidence level, and the third confidence level is determined as the confidence level of this technology type. Filter out confidence levels greater than the preset confidence threshold from all technology types; The average of the filtered confidence scores is determined as the confidence score of the subdomain. Match the port corresponding to each subdomain with the high-risk port database, and determine the matched port as the high-risk port of the subdomain. The preset fingerprint recognition features corresponding to each subdomain are matched with the vulnerability feature database, and the matched preset fingerprint recognition features are determined as the vulnerability features of the subdomain. The confidence level of each subdomain, the high-risk port of at least one subdomain, and the vulnerability characteristics of at least one subdomain are identified as data for enhancing network applications.
5. The method for determining the enterprise network exposure surface according to claim 1, characterized in that, The associated data includes: certificate information for multiple subdomains related to the target enterprise domain; the determination method further includes: Based on the target enterprise domain name, filter out the subdomains containing certificate data from all subdomains, and parse the certificate data corresponding to each filtered subdomain. The parsed certificate data is identified as certificate information.
6. The method for determining the enterprise network exposure surface according to claim 1, characterized in that, The associated data includes: the registration information of the target company's domain name, and the names of subsidiaries under the target company that exceed the preset shareholding ratio and their corresponding association data.
7. The method for determining the enterprise network exposure surface according to claim 1, characterized in that, The determination method further includes: Based on publicly available data from the target company, generate a report in a preset format to display the target company's exposure.
8. A device for determining the exposed surface of an enterprise network, characterized in that, The determining device includes: The data determination module is used to determine the domain asset data, port data, and network application data of multiple subdomains related to the target enterprise domain name, as well as the associated data of the target enterprise domain name, based on the target enterprise domain name. The first subdomain filtering module is used to filter subdomains that meet the valid rules from all subdomains based on the first preset keyword, the second preset keyword and the first preset field, and to determine the subdomains that meet the valid rules as valid subdomains. The second subdomain filtering module is used to perform access verification on each valid subdomain based on the domain asset data, and to filter out the valid subdomains that have successfully passed the access verification from all valid subdomains. The port filtering module is used to verify the authenticity of ports for each subdomain based on expected port services and port data, and to filter out ports that have successfully passed the authenticity verification from all subdomain ports. The network application filtering module is used to perform consistency verification on the network applications corresponding to each subdomain based on the expected network application fingerprint and network application data, and to filter out the network applications that have successfully passed the consistency verification from the network applications of the subdomain. The exposure surface determination module is used to determine the associated data, the domain asset data corresponding to the filtered subdomains, the port data corresponding to the filtered ports, and the network application data corresponding to the filtered network applications as the public data of the target enterprise.
9. An electronic device, characterized in that, include: The device includes a processor, a memory, and a bus, wherein the memory stores machine-readable instructions executable by the processor, and when the electronic device is running, the processor communicates with the memory via the bus, and the machine-readable instructions are executed by the processor to perform the steps of the method for determining the enterprise network exposure surface as described in any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, performs the steps of the method for determining the enterprise network exposure surface as described in any one of claims 1 to 7.