Network vulnerability visualization mining analysis system
By generating protocol meta-action sequences and visual vulnerability maps, this solution addresses the problem that existing tools cannot visualize the TLS/SSL protocol version negotiation process. It enables accurate identification and protection against protocol version rollback points and downgrade attacks, improving vulnerability analysis efficiency and security.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2026-01-15
- Publication Date
- 2026-03-27
AI Technical Summary
Existing network vulnerability analysis tools cannot visualize the detailed message flow and version rollback points during the handshake phase of the TLS/SSL protocol version negotiation process, resulting in low analysis efficiency and difficulty in identifying protocol version downgrade attacks.
By generating protocol meta-action sequences, security context state chains, protocol state transition diagrams, and visualized vulnerability maps, the system accurately captures protocol version rollback points and downgrade attack anomaly patterns, and intuitively presents the detailed message flow and state transitions of the handshake phase.
It improves the accuracy of vulnerability identification and analysis efficiency, enabling quick understanding of detailed message flows and attack causal logic, and providing full-link, visualized security protection for enterprise intranet multi-TLS protocol version services.
Smart Images

Figure CN121530758B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of security protocol vulnerability analysis, and particularly relates to a network vulnerability visual mining and analysis system. BACKGROUND
[0002] At present, when mining and analyzing network vulnerabilities, protocol analysis tools such as Wireshark or vulnerability scanners are usually used to detect security weaknesses in network protocols, especially for encrypted protocols such as TLS / SSL. These tools mainly identify vulnerabilities by analyzing protocol data packets, checking the strength of encryption algorithms, or verifying the validity of certificates, and often focus on static analysis of individual data packets.
[0003] However, in the above vulnerability analysis, the following defects still exist in enterprise applications: At present, when the enterprise intranet uses services of multiple TLS protocol versions, an attacker may force the server to use a weak version protocol through a protocol version downgrade attack, thereby exploiting known vulnerabilities. However, the existing analysis technology cannot visually display the version negotiation sequence and state transition between the client and the server in the handshake process, making it difficult for analysts to intuitively discover abnormal patterns of downgrade attacks. For example, existing tools may only output protocol version matching results, but cannot visually display detailed message flows and version rollback points in the handshake phase, resulting in low analysis efficiency and inability to accurately identify vulnerabilities. SUMMARY
[0004] In view of the deficiencies of the prior art, the present application provides a network vulnerability visual mining and analysis system, which solves the above problems.
[0005] The above technical purpose of the present application is achieved by the following technical scheme:
[0006] The network vulnerability visual mining and analysis system comprises:
[0007] An extraction unit acquires a complete protocol session in a target network security protocol, extracts protocol meta-actions at the semantic level from each protocol message constituting the protocol session, records core security parameters associated with each protocol meta-action, arranges the entire protocol session, and generates a protocol meta-action sequence;
[0008] A security analysis unit performs deductive analysis on the protocol meta-action sequence to obtain the instantaneous composite security state after each action is executed, connects all instantaneous composite security states in chronological order to generate a security context state chain;
[0009] A protocol mapping unit maps the security context state chain to obtain a protocol state transition graph, analyzes each state node of the protocol state transition graph, and obtains a state update vector;
[0010] a vulnerability identification unit, which identifies and separates abnormal state nodes from all state nodes in the state update vector to generate a logical vulnerability anchor point;
[0011] an attack analysis unit, which performs attack analysis in the protocol state transition graph starting from the logical vulnerability anchor point to generate a multi-step attack causal chain;
[0012] a vulnerability mining unit, which superimposes and fuses the protocol state transition graph and the multi-step attack causal chain to generate a visual protocol vulnerability atlas.
[0013] Further, protocol meta-actions in a semantic layer are extracted from each protocol message constituting a protocol session, and core security parameters associated with each protocol meta-action are recorded, and the entire protocol session is arranged to generate a protocol meta-action sequence, including:
[0014] context-embedded analysis is performed on each message in the protocol session to generate an embedded feature set;
[0015] protocol meta-actions in a semantic layer are analyzed based on the embedded feature set, and corresponding core security parameters are recorded to generate a dynamic association cluster of actions-parameters;
[0016] a logical timing weight is calculated for each dynamic association cluster to generate a protocol meta-action sequence.
[0017] Further, the protocol meta-action sequence is deduced and analyzed to obtain an instantaneous compound security state after each action is executed, and all instantaneous compound security states are connected in time sequence to generate a security context state chain, including:
[0018] Based on the protocol meta-action sequence, bidirectional security conduction features of each meta-action corresponding to the core security parameters are mined to generate a security conduction feature atlas;
[0019] Based on the security conduction feature atlas, the security state after each meta-action is executed is analyzed to generate an instantaneous compound security state;
[0020] According to the security conduction feature atlas, the security conduction association of adjacent meta-actions is analyzed to generate a state bidirectional correction coefficient.
[0021] Further, the protocol meta-action sequence is deduced and analyzed to obtain an instantaneous compound security state after each action is executed, and all instantaneous compound security states are connected in time sequence to generate a security context state chain, including:
[0022] Based on the state bidirectional correction coefficient, the instantaneous compound security state is bidirectionally dynamically optimized and corrected in combination with changes in the core security parameters to generate a compound security state vector;
[0023] According to the time sequence of the meta-actions in the protocol meta-action sequence and the complex safe state vector, the logical association relationship of adjacent complex safe state vectors is analyzed and marked to generate a state transition logic label set;
[0024] The marks of the state transition logic label set are embedded into the connection nodes of the complex safe state vector to realize dynamic chain integration and generate a secure context state chain.
[0025] Further, the secure context state chain is mapped to obtain a protocol state transition graph, and each state node of the protocol state transition graph is analyzed to obtain a state update vector, including:
[0026] The secure context state chain is analyzed to generate a node fusion feature matrix;
[0027] Based on the node fusion feature matrix, the features and transition correlation weights of the state nodes are mapped to generate a protocol state transition graph;
[0028] All state nodes in the protocol state transition graph are analyzed to obtain a state update vector.
[0029] Further, in the state update vector, all state nodes are identified and separated from abnormal state nodes to generate a logical vulnerability anchor point, including:
[0030] The state update vector, the complex safe state vector, and the node fusion feature matrix are analyzed to construct a state node dynamic baseline that dynamically adjusts with the protocol session;
[0031] Based on the state node dynamic baseline and the state transition logic label set, the deviation degree and the conduction influence degree of each node are calculated to generate an abnormal state node conduction set.
[0032] Further, in the state update vector, all state nodes are identified and separated from abnormal state nodes to generate a logical vulnerability anchor point, including:
[0033] According to the abnormal state node conduction set, the paths affected by abnormal conduction in the protocol state transition graph are traced back, and the risk paths are screened to generate a risk abnormal path set;
[0034] The risk abnormal path set is analyzed to determine the first deviated node in each path, and the corresponding protocol meta-action is reversely associated to serve as a logical vulnerability anchor point.
[0035] Further, taking the logical vulnerability anchor point as the starting point, attack analysis is performed in the protocol state transition graph to generate a multi-step attack causal chain, including:
[0036] Taking the logical vulnerability anchor point as the core, the complex safe state vector is fused to calculate the trigger condition of the anchor point attack and the tolerance threshold of each security dimension to generate an anchor point attack trigger matrix;
[0037] Based on the anchor point attack trigger matrix and the protocol state transition graph, the risk transmission gain of each potential attack step is analyzed in association with the security state destruction, and a risk transmission gain set is generated.
[0038] Further, starting from the logical vulnerability anchor point, attack analysis is performed in the protocol state transition graph to generate a multi-step attack causal chain, which also includes:
[0039] The risk transmission gain set is analyzed to eliminate invalid paths with no gain, and a multi-step attack causal chain is generated.
[0040] Further, the protocol state transition graph and the multi-step attack causal chain are superimposed and fused to generate a visual protocol vulnerability atlas, including:
[0041] The protocol state transition graph and the risk abnormal path set are superimposed to calculate the association strength between the state nodes and the abnormal paths, and a protocol state- abnormal association graph is generated.
[0042] The protocol state- abnormal association graph and the multi-step attack causal chain are dynamically mapped to analyze the causal logic and risk transmission gain between attacks, and the attack chain is injected as an attribute to the corresponding path of the association graph to generate an attack-enhanced state transition graph.
[0043] Based on the attack-enhanced state transition graph, a visual protocol vulnerability atlas is generated.
[0044] In summary, the present application mainly has the following beneficial effects:
[0045] By generating a protocol meta-action sequence through context embedding analysis, the association between core security parameters and protocol meta-actions is accurately captured, the security context state chain generated by the security analysis unit clearly presents the dynamic transition of the protocol state, the protocol mapping unit maps the state chain into a two-dimensional protocol state transition graph, and the handshake phase version negotiation sequence and state conversion are intuitively displayed, and the abnormal nodes selected by the vulnerability identification unit can accurately locate the logical vulnerability anchor point, the attack analysis unit traces the multi-step attack causal chain to understand the gain of risk transmission, and the visual protocol vulnerability atlas generated by the vulnerability mining unit intuitively presents the vulnerability nodes, node threat values, attack paths and state jump points with highlighted nodes and differentiated lines. BRIEF DESCRIPTION OF DRAWINGS
[0046] Figure 1It is a schematic diagram of a network vulnerability visualization mining analysis system of the present application. DETAILED DESCRIPTION
[0047] The technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative work fall within the scope of protection of the present application.
[0048] Reference Figure 1 The network vulnerability visualization mining analysis system comprises:
[0049] The extraction unit obtains a complete protocol session in a target network security protocol, extracts protocol meta-actions in a semantic layer from each protocol message constituting the protocol session, records core security parameters associated with each protocol meta-action, arranges the entire protocol session, and generates a protocol meta-action sequence.
[0050] The protocol meta-actions include but are not limited to proposals, responses, changes, etc.
[0051] The core security parameters include but are not limited to password suite identifiers, authentication credential digests, protocol version identifiers, etc.
[0052] The security analysis unit performs deduction analysis on the protocol meta-action sequence to obtain an instantaneous composite security state after execution of each action, connects all the instantaneous composite security states in time sequence, and generates a security context state chain.
[0053] The protocol mapping unit maps the security context state chain to obtain a protocol state transition graph, analyzes each state node of the protocol state transition graph, and obtains a state update vector.
[0054] The vulnerability identification unit identifies and separates abnormal state nodes in the state update vector, and generates a logical vulnerability anchor point.
[0055] The attack analysis unit performs attack analysis in the protocol state transition graph starting from the logical vulnerability anchor point, and generates a multi-step attack causal chain.
[0056] The vulnerability mining unit superimposes and fuses the protocol state transition graph and the multi-step attack causal chain to generate a visual protocol vulnerability graph.
[0057] In one case of the present embodiment, from each protocol message constituting a protocol session, protocol meta-actions in a semantic layer are extracted, and core security parameters associated with each protocol meta-action are recorded, and the entire protocol session is arranged to generate a protocol meta-action sequence, which comprises:
[0058] Context-embedded analysis is performed on each message in the protocol session to generate an embedded feature set, specifically including: for each message of the protocol session, the message format is explicitly based on the protocol specification document (RFC), and a protocol field identifier library is constructed, the protocol field identifier library predefines the exact offset, length and semantic mapping table of each field in the message binary stream; for example, the field is located at offset 0 of the message binary stream, the length is 1 byte, and the value is mapped to the protocol meta-action, and the value 1 corresponds to the protocol meta-action as proposal, and the value 2 corresponds to the protocol meta-action as response;
[0059] Based on the preset offset and length in the protocol field identifier library, the corresponding byte sequence is extracted from the binary stream of the current message field by field; for example, 8 bytes are continuously extracted as the cipher suite identifier starting from the 16th byte of the offset, 32 bytes are continuously extracted as the authentication credential digest starting from the 24th byte of the offset, and 2 bytes are continuously extracted as the protocol version identifier starting from the 8th byte of the offset, and then the extracted byte sequence is parsed and converted according to the encoding rule of the RFC specification, and then the core security parameters associated with the current protocol meta-action are obtained;
[0060] The protocol meta-action (action A) of the previous message and the protocol meta-action (action B) of the current message are obtained, and the protocol state transition matrix is queried, with action A as the row and action B as the column, so that a probability value between 0 and 1 is retrieved, which is the semantic dependency degree; wherein the protocol state transition matrix is obtained by analyzing a plurality of normal protocol session logs through a machine learning model, and the transition frequency of all protocol meta-action pairs is normalized to obtain the probability;
[0061] Based on the expected message sequence defined by the protocol standard state machine, it is used as a protocol ideal path template, and it is checked whether the action B matches the protocol ideal path template after the current session sequence has been executed: if the action B is the only expected action, the context consistency factor is 1; if the action B is one of the multiple optional expected actions, the context consistency factor is 0.5, otherwise the context consistency factor is 0;
[0062] If the semantic dependency degree is greater than 0.1, the protocol flow continuity flag is true, otherwise it is false;
[0063] The protocol meta-action, the core security parameter, the semantic dependency degree, the context consistency factor, and the protocol flow continuity flag are combined to obtain the embedded feature set.
[0064] The semantic level protocol meta-action is analyzed based on the embedded feature set, and the corresponding core security parameters are recorded to generate a dynamic association cluster of action-parameters, specifically including: for each pair of protocol meta-action and core security parameter, setting the weight of semantic dependency degree as 0.6, and the weight of context consistency factor as 0.4, multiplying the semantic dependency degree and the context consistency factor by the corresponding weight respectively, and then adding them to obtain a dynamic association weight; only retaining the action-parameter pairs with a dynamic association weight greater than the average of all dynamic association weights, each action-parameter pair being an entry, adding a timestamp to each entry, the timestamp being derived from the original time sequence of the protocol message, and combining all entries to generate a dynamic association cluster of action-parameters.
[0065] The semantic dependency degree is derived from machine learning training on multiple normal session logs, which reflects the historical and statistical closeness between two actions in a real and complex network environment, so a higher weight of 0.6 is given to make the system take the actual historical probability as the primary basis for judging credibility, so that the system can adapt to the legal variants of the protocol that may occur in actual application and conform to statistical rules, and will not be mistaken due to deviation from the ideal path; and the context consistency factor is based on the protocol standard, which represents the theoretical correctness, and then a relatively low weight of 0.4 is given, not to deny its importance, but to reduce its absolute veto power, so that when an attack method (such as protocol downgrade) intentionally constructs a sequence that is legal on the ideal path but has a very low statistical probability, the system can sensitively identify the anomaly due to its very low semantic dependency degree, rather than being blinded by theoretical compliance.
[0066] The logical time sequence weight of each dynamic association cluster is calculated to generate a protocol meta-action sequence, specifically including: arranging all entries in the dynamic association cluster in ascending order of timestamp, for the first entry in the sequence, directly taking its dynamic association weight as the logical time sequence weight; for subsequent entries, multiplying the dynamic association weight of the current entry by 0.7 and multiplying the logical time sequence weight of the previous entry by 0.3 to obtain the logical time sequence weight of the current entry, and arranging the protocol meta-actions and their logical time sequence weights in chronological order to form a protocol meta-action sequence.
[0067] By performing context embedding analysis on each message of the protocol session, the protocol meta-action and the core security parameter are accurately extracted, and finally a protocol meta-action sequence is generated, which can visualize the detailed message flow in the handshake phase, the version negotiation sequence and the state transition process, and intuitively expose the protocol version rollback point and the downgrade attack anomaly pattern, which not only adapts to the legal variants of various TLS protocol versions in the enterprise intranet, but also sensitively identifies the low-probability compliance sequence constructed by attacks, and improves the efficiency and accuracy of vulnerability analysis.
[0068] In one case of the embodiment, the protocol meta-action sequence is analyzed to obtain the instantaneous composite security state after each action execution, all the instantaneous composite security states are connected in time sequence to generate a security context state chain, including:
[0069] Based on the protocol meta-action sequence, the bidirectional security conduction characteristics of each meta-action corresponding to the core security parameter are mined to generate a security conduction feature map, specifically including: for each core security parameter in the protocol meta-action sequence, multiplying the logical time sequence weight of the current core security parameter by 0.6 and multiplying the logical time sequence weight average of the same core security parameter in the next two actions by 0.4 to obtain the forward conduction intensity; multiplying the logical time sequence weight of the current core security parameter by 0.7 and multiplying the logical time sequence weight average of the same core security parameter in the previous two actions by 0.3 to obtain the backward conduction intensity.
[0070] The forward conduction intensity and the backward conduction intensity of each core security parameter form a conduction feature two-tuple, and the conduction feature two-tuple is connected in time sequence of the protocol session to form a time-evolving directed graph structure, i.e. a security conduction feature map.
[0071] Based on the security conduction feature map, the security state after each meta-action execution is analyzed to generate an instantaneous composite security state, specifically including: multiplying the forward conduction intensity of the current protocol meta-action cryptographic suite identifier and the forward conduction intensity average of the previous two protocol meta-action cryptographic suite identifiers, and normalizing the sum to the interval of 0-1, i.e. the cryptographic suite intensity coefficient;
[0072] The backward conduction intensity of the current protocol meta-action authentication credential digest is multiplied by 0.6 and the previous protocol meta-action authentication phase identifier is multiplied by 0.4, rounded to an integer in the interval of 1-4, to obtain the authentication phase identifier, 1 to 4 representing four stages of authentication not started, in progress, completed, and failed, respectively;
[0073] Check whether the combination of the two items of the cryptographic suite identifier and the authentication credential digest exists in the dynamic association cluster constituted by the current and all previous protocol meta-actions, if they exist at the same time, the key material completeness flag bit is 1, representing completeness; otherwise, the key material completeness flag bit is 0, representing incompleteness;
[0074] The cryptographic suite intensity coefficient, the authentication phase identifier, and the key material completeness flag bit are combined to form a multi-dimensional vector, which is the instantaneous composite security state after the current action execution.
[0075] According to the security conduction feature map, the security conduction correlation of adjacent meta-actions is analyzed, and a state bidirectional correction coefficient is generated, specifically including: for the password suite identifier, the Euclidean distance of the conduction feature binary tuple of the current state node and the previous state node is calculated respectively, and the Euclidean distance of the current state is divided by the Euclidean distance of the previous state to obtain a forward correction coefficient;
[0076] For the authentication credential digest, the Manhattan distance of the conduction feature binary tuple of the current state node and the previous state node is calculated respectively; the absolute value of the difference between the Manhattan distance of the current state and the Manhattan distance of the previous state is calculated to obtain a backward correction coefficient;
[0077] The forward correction coefficient and the backward correction coefficient are added to obtain the state bidirectional correction coefficient.
[0078] In one case of the embodiment, the protocol meta-action sequence is deduced and analyzed to obtain an instantaneous composite security state after each action is executed, and all the instantaneous composite security states are connected in time sequence to generate a security context state chain, which also includes:
[0079] The instantaneous composite security state is bidirectionally dynamically optimized based on the state bidirectional correction coefficient, and is corrected in combination with the change of the core security parameter to generate a complex security state vector, specifically including: the state bidirectional correction coefficient is multiplied by the password suite strength coefficient, the authentication phase identifier, and the key material completeness flag of the instantaneous composite security state to obtain an optimized password suite strength coefficient in the interval of 0-1, an optimized authentication phase identifier, and an optimized key material completeness flag of 0 or 1. The optimized authentication phase identifier is an integer of 1-4.
[0080] A security level mapping is set for the protocol version identifier, mapping TLS1.3 to 3, mapping TLS1.2 to 2, and mapping SSL3.0 to 1.
[0081] The variance of the current protocol version identifier and the protocol version identifier of the previous two actions is calculated, and if the variance is greater than 0.25, it is determined that the version has abnormal fluctuations, and the optimized password suite strength coefficient is reduced by 0.2 to obtain a processed password suite strength coefficient.
[0082] The processed password suite strength coefficient, the optimized authentication phase identifier, and the optimized key material completeness flag are combined to form a complex security state vector.
[0083] According to the time sequence and the complex security state vector of the protocol meta-action sequence, the logical association relationship of adjacent complex security state vectors is analyzed and marked, and a state transition logic label set is generated, specifically including: calculating the absolute value of the difference value of the cryptographic suite strength coefficient in adjacent complex security state vectors, and marking as a cryptographic suite mutation when the absolute value is greater than 0.15; marking as authentication rollback when the authentication phase identifier appears to transfer from a high-order phase (3 or 4) to a low-order phase (1 or 2); when the key material completeness flag changes from 1 to 0, and the difference between the protocol version identification of the previous and subsequent states exceeds 0.25, mark as key material loss.
[0084] The influence intensity value is calculated for each mark, and the square sum of the difference value of the cryptographic suite strength coefficient, the difference value of the authentication phase identifier, and the difference value of the key material completeness is calculated, and then the square root is taken, that is, the influence intensity of the mark is obtained; wherein each mark contains three elements of timestamp, mark content and influence intensity; all marks are combined in time sequence to obtain the state transition logic label set.
[0085] The marks of the state transition logic label set are embedded in the connection nodes of the complex security state vector to realize dynamic chain integration and generate a security context state chain, specifically including: arranging each complex security state vector in time sequence and creating a connection node between adjacent complex security state vectors;
[0086] For each connection node, traverse each mark in the state transition logic label set, locate the corresponding connection node according to the timestamp of the mark, and write the mark content (cryptographic suite mutation, authentication rollback, key material loss) into the node attribute, and at the same time, take the influence intensity value of the mark as the node weight;
[0087] Calculate the average value of the node weights of the first three connection nodes, and trigger a security alarm when the node weight is lower than the average value; combine the time-ordered complex security state vector sequence, connection nodes, node attributes, node weights, and security alarm times to generate a security context state chain.
[0088] By mining the bidirectional security conduction characteristics of core security parameters, a security conduction feature map is generated, and a transient complex security state is determined, which is optimized by a state bidirectional correction coefficient to obtain a complex security state vector, combined with a generated state transition logic label set, and finally integrated into a security context state chain. Not only can it visually present the version negotiation sequence and state transition process of the TLS protocol handshake, accurately locate the version rollback point, but also can understand the abnormal influence intensity and trigger a security alarm, improving the identification accuracy of abnormal patterns such as protocol downgrade attacks, and intuitively mastering the security state transition, improving the vulnerability analysis efficiency.
[0089] In one case of the embodiment, the security context state chain is mapped to obtain a protocol state transition graph, each state node of the protocol state transition graph is analyzed to obtain a state update vector, including:
[0090] The security context state chain is analyzed to generate a node fusion feature matrix, specifically including: the average of the Euclidean distance from each state node to the directly connected state node before and the average of the Manhattan distance of all directly connected state nodes after, to obtain a node topology density;
[0091] The product of the cryptographic suite strength coefficient and the authentication phase identifier is calculated, and the square root of the product is multiplied by the key material completeness flag to obtain a security situation product;
[0092] The standard deviation of the cryptographic suite strength coefficient of the state node and the previous three state nodes is calculated, and then divided by the authentication phase identifier to obtain a timing change value;
[0093] The node topology density, the security situation product and the timing change value are combined to form a feature vector of each state node, the feature vector of each state node is taken as a row of the matrix, and the feature vectors of all state nodes are stacked in time sequence to form a node fusion feature matrix with a dimension of N x 3, where N represents the total number of state nodes, and 3 represents the feature dimension of each node.
[0094] Based on the node fusion feature matrix, the features and transition correlation weights of the state nodes are mapped to generate a protocol state transition graph, specifically including: for the three features: node topology density, security situation product and timing change value in the feature vector of the state node in the node fusion feature matrix;
[0095] The variance of each feature in the three features is calculated respectively, and the covariance between each two features is calculated respectively, and these variances and covariances are arranged in a fixed order to form a 3x3 symmetric matrix, which is a covariance matrix; the covariance matrix is decomposed to obtain eigenvalues and eigenvectors;
[0096] The eigenvector corresponding to the maximum eigenvalue is taken as the projection axis, and the three features in the feature vector of each state node are multiplied by the projection axis and then added to obtain a comprehensive security projection value;
[0097] The time sequence of the state node is taken as the horizontal coordinate, and the comprehensive security projection value is taken as the vertical coordinate to locate the state node coordinates on a two-dimensional plane;
[0098] The node weight of the security context state chain is taken as the edge weight, and each connected node in the security context state chain is mapped as a directed edge, and the adjacent state nodes are sequentially connected using the directed edges in the time sequence of the protocol session, and the visual width of each directed edge is proportional to the edge weight corresponding to the directed edge, and the greater the edge weight value, the thicker the edge;
[0099] The position coordinates of the state nodes in the two-dimensional plane are drawn using graphical elements, the adjacent state nodes are sequentially connected using directed edges and marked using arrowed line segments, and the width of the directed edges is set according to the edge weight, thereby forming a complete protocol state transition graph.
[0100] All the state nodes in the protocol state transition graph are analyzed to obtain a state update vector, specifically including: based on the coordinate distribution of the state nodes in the two-dimensional plane, the geometric center point coordinates of the entire node set are calculated; for each state node, the reciprocal of the Euclidean distance from the state node to the geometric center point is multiplied by 100 to obtain a radial density value; the standard deviation of the average distance from the state node to all adjacent state nodes is calculated to obtain a dispersion value; the absolute value of the difference between the longitudinal coordinate of the state node and the longitudinal coordinate of the state node directly connected before the state node is calculated to obtain a height difference value;
[0101] The radial density value, the dispersion value and the height difference value are combined to form a new state vector, that is, the state update vector.
[0102] Through the generated protocol state transition graph, the node weight is intuitively embodied by the width of the directed edges, the version negotiation sequence and the state conversion of the TLS protocol handshake are clearly visualized, and through the node topology density, the security situation product, and the radial density value, the height difference value and other parameters of the state update vector, the version rollback point and the abnormal mode can be accurately captured, and then the detailed message flow can be directly grasped, which not only improves the vulnerability analysis efficiency, but also strengthens the recognition accuracy of abnormal attacks such as downgrade attacks, thereby providing support for the security protection of the enterprise intranet multi-TLS version service.
[0103] In one case of the embodiment, in the state update vector, all the state nodes are identified and separated from the abnormal state nodes, and a logical vulnerability anchor point is generated, including:
[0104] The state update vector, the recovery state vector and the node fusion feature matrix are analyzed to construct a state node dynamic baseline dynamically adjusted with the protocol session, specifically including: for the recovery state vectors of the last five state nodes in the protocol session, the 75% quantile of the cryptographic suite strength coefficient is calculated as a strength reference value; at the same time, the mean of the radial density values of these state nodes in the state update vector is calculated as a density reference value; the security situation products of the last three nodes in the node fusion feature matrix are arranged in time sequence, and the linear regression slope of the security situation product is calculated as a situation change reference value;
[0105] The dynamic adjustment state node dynamic baseline is composed of three elements of the strength reference value, the density reference value, and the trend change reference value.
[0106] Based on the state node dynamic baseline and the state transition logic label set, the deviation degree and the conduction influence degree of each node are calculated, and an abnormal state node conduction set is generated, specifically including: calculating the absolute difference value of the current cryptographic suite strength coefficient of the state node and the strength reference value, multiplying the absolute difference value by the square of the height difference value in the state update vector to obtain a primary deviation amount;
[0107] The natural logarithm of the ratio of the time sequence change value in the node fusion feature matrix to the trend change reference value in the state node dynamic baseline is taken to the absolute value, and then multiplied by the primary deviation amount to obtain the final deviation degree;
[0108] The standard deviation of the marked influence strength value in all connection nodes directly connected to the state node is calculated, and the standard deviation is multiplied by the reciprocal of the dispersion value in the state update vector to obtain the conduction influence degree;
[0109] The nodes with a final deviation degree greater than 0.35 and a conduction influence degree greater than 1.2 are marked as abnormal nodes, and all abnormal nodes and their final deviation degrees and conduction influence degrees constitute an abnormal state node conduction set.
[0110] In one case of the embodiment, in the state update vector, all state nodes are identified and separated from abnormal state nodes, and a logical vulnerability anchor point is generated, further including:
[0111] According to the abnormal state node conduction set, the paths affected by the abnormal conduction in the protocol state transition graph are traced back, and the risk paths are screened to generate a risk abnormal path set, specifically including: selecting the node with the highest conduction influence degree from the abnormal state node conduction set as the starting point, traversing adjacent nodes in the protocol state transition graph along the out-edge and in-edge directions respectively, for each traversal direction, counting the number of nodes continuously accessed from the starting point as the path length, for each traversed path, calculating the product of the conduction influence degrees of all nodes on the path to obtain the path conduction strength;
[0112] At the same time, the number of nodes with a final deviation degree greater than 0.25 continuously appearing in the path is counted, when the path length exceeds 3 nodes, and the path conduction strength is greater than 2, and the number of continuous abnormal nodes reaches two-thirds of the path length, the path is marked as a risk path; all risk paths meeting the conditions and their path conduction strengths are combined to generate a risk abnormal path set.
[0113] The risk abnormal path set is analyzed, a first deviated node in each path is determined, and a corresponding protocol meta-action is reversely associated as a logical vulnerability anchor point, specifically including: for each risk path in the risk abnormal path set, starting from the risk path starting node, each node state update vector is checked one by one, when it is found that the radial density value of a certain state node is increased by more than 50% compared with the previous state node, and the height difference value of the state node is greater than the average value of the height difference values of the first three state nodes in the risk path, the state node is marked as a first deviated state node; the protocol meta-action corresponding to the first deviated state node is found through the time mapping relationship of the protocol state transition graph, and the protocol meta-action is marked as a logical vulnerability anchor point.
[0114] Through the generated state node dynamic baseline, the abnormal nodes are screened in combination with the final deviation and the conduction influence degree, the risk path is traced back and the first deviated node is located, the logical vulnerability anchor point is finally generated, the version negotiation sequence, the state transition and the version rollback point of the TLS protocol handshake are intuitively presented, the abnormal conduction influence is understood, the abnormal mode of the downgrade attack is accurately captured, and the accuracy of vulnerability identification is strengthened.
[0115] In one case of the embodiment, starting from the logical vulnerability anchor point, attack analysis is performed in the protocol state transition graph, and a multi-step attack causal chain is generated, including:
[0116] Taking the logical vulnerability anchor point as the core, the complex security state vector is fused, the trigger condition of the anchor point attack and the tolerance threshold of each security dimension are calculated, the anchor point attack trigger matrix is generated, and specifically including: for each logical vulnerability anchor point, the complex security state vector corresponding to the anchor point and the complex security state vectors of the next three state nodes are extracted, to form a data group containing four continuous state nodes;
[0117] The range of the protocol version identifiers in the four state nodes is calculated, when the range exceeds the average value of all protocol version identifiers, the version abnormal trigger is recorded, at this time, the version abnormal trigger flag is 1, otherwise it is 0; the number of times that the authentication phase identifier jumps from a high order (3 or 4) to a low order (1 or 2) in the four state nodes is counted, when the number of times exceeds 2, the authentication abnormal trigger is recorded; the version abnormal trigger and the authentication abnormal trigger are taken as the trigger condition of the logical vulnerability anchor point;
[0118] The average value of the decline rate of the cipher suite strength coefficient in the four state nodes is calculated, which is taken as the strength tolerance threshold;
[0119] A feature vector is constructed for each logical vulnerability anchor point, and the feature vector includes: the trigger condition and the strength tolerance threshold; the feature vectors of all logical vulnerability anchor points are arranged in rows to form a two-dimensional matrix structure, that is, the anchor point attack trigger matrix.
[0120] Based on the anchor point attack trigger matrix and the protocol state transition graph, the risk transmission gain of each potential attack step is analyzed and the correlation with the security state destruction is generated, including: in the protocol state transition graph, the directed edge between each logical vulnerability anchor point and its direct successor state node is taken as a potential attack step;
[0121] For each attack step, the sine value of the angle between the state update vectors of the starting state node and the target state node is calculated, including: first, the dot product of the two vectors is calculated, then the dot product is divided by the respective module length to obtain the cosine value, and then the sine value is converted through the trigonometric identity to obtain the basic value of the risk transmission gain; multiply the basic value by the strength tolerance threshold of the corresponding logical vulnerability anchor point in the anchor point attack trigger matrix, and then multiply by the edge weight of the directed edge corresponding to the attack step, if the version abnormal trigger flag of the logical vulnerability anchor point is 1, then multiply the calculation result by 1.5 to obtain the risk transmission gain value, otherwise directly take the calculation result as the risk transmission gain value; combine the risk transmission gain values of all attack steps and their corresponding starting-target node pairs to form the risk transmission gain set.
[0122] In one case of the embodiment, starting from the logical vulnerability anchor point, attack analysis is performed in the protocol state transition graph to generate a multi-step attack causal chain, which also includes:
[0123] The risk transmission gain set is analyzed to eliminate invalid paths with no gain, and a multi-step attack causal chain is generated, including: calculating the mean of all risk transmission gain values in the risk transmission gain set, taking the mean as the gain threshold, starting from each logical vulnerability anchor point, traversing along the directed edges in the protocol state transition graph, and only selecting edges with a risk transmission gain value greater than the gain threshold as valid attack steps; in the traversal process, record the continuous valid attack steps as a sequence, and when the sequence length reaches 3 steps, mark the sequence as a candidate attack chain; sort all candidate attack chains according to the sequence starting time to combine into a multi-step attack causal chain.
[0124] By taking the logical vulnerability anchor point as the core and fusing the complex security state vector to generate the anchor point attack trigger matrix, and generating the multi-step attack causal chain, not only can the version negotiation sequence, state transition and version rollback point of the TLS protocol handshake be visually presented, but also the multi-step transmission path of the downgrade attack can be clearly restored, and the attack trigger condition and risk transmission law can be accurately captured, the causal logic of the attack can be mastered, the vulnerability analysis efficiency can be improved, and the identification accuracy and tracing ability of abnormal patterns such as downgrade attack can be strengthened, providing targeted security protection for enterprise intranet multi-TLS version services.
[0125] In one case of the embodiment, the protocol state transition graph and the multi-step attack causal chain are superimposed and fused to generate a visual protocol vulnerability map, including:
[0126] Superimpose the protocol state transition graph and the risk anomaly path set, calculate the association strength of the state node and the abnormal path, and generate a protocol state-abnormal association graph, specifically including: for each state node in the protocol state transition graph, taking the number of risk paths to which it belongs as the path coincidence degree;
[0127] Multiply the position weight of the state node in the risk path by the path conduction strength, then multiply it by the natural logarithm of the path coincidence degree, normalize the calculation result to the interval of 0-1 as the final association strength value, wherein the position weight of the starting state node of the risk path is set to 1, and the position weight of the next state node is reduced by 0.1, and the lowest position weight is 0.4;
[0128] The state node with a final association strength value greater than 0.6 is highlighted in red, and other state nodes are displayed in light red, thereby forming a protocol state-abnormal association graph.
[0129] Map the protocol state-abnormal association graph and the multi-step attack causal chain dynamically, analyze the causal logic and risk conduction gain between attacks, inject the attack chain as an attribute into the corresponding path of the association graph, and generate an attack-enhanced state transition graph, specifically including: mapping each attack step in the multi-step attack causal chain to the corresponding starting-target state node pair in the protocol state-abnormal association graph, for each mapped node pair;
[0130] Multiply the risk conduction gain value of the attack step in the risk conduction gain set by the geometric mean of the final association strength values of the starting state node and the target state node, then multiply it by the time attenuation factor based on the attack step, to obtain an attack influence coefficient; wherein the attenuation factor of the first attack step in the multi-step attack causal chain is 1, the attenuation factor of the second attack step is 0.8, and the attenuation factor of each subsequent attack step is reduced by 0.2, and the lowest attenuation factor is 0.1;
[0131] Inject the attack influence coefficient as an attack influence attribute into the connection relationship of the corresponding node pair, and simultaneously adaptively adjust the color saturation and dashed line style of the connection line between the nodes according to the attack influence coefficient, to form an attack-enhanced state transition graph.
[0132] Based on the attack-enhanced state transition graph, generate a visual protocol vulnerability map, specifically including: taking the state node with a final association strength greater than 0.75 in the protocol state-abnormal association graph as a vulnerability node, for each vulnerability node, multiplying its corresponding final association strength value by its corresponding conduction influence degree to obtain a node threat value; extracting the sequence of all attack steps from the multi-step attack causal chain as an attack path;
[0133] From the state transition logic label set, the label content is marked as a password suite mutation, an authentication rollback, and a key material loss mark as a state jump point;
[0134] The vulnerability node, the node threat value, the attack path, and the state jump point are visually encoded to form a protocol vulnerability graph.
[0135] By superimposing the protocol state transition graph and the risk abnormal path set, a visual protocol vulnerability graph containing the vulnerability node, the node threat value, the attack path, and the state jump point is generated, which intuitively presents the version negotiation sequence, the state conversion, and the version rollback point of the TLS protocol handshake. In addition, the attack influence and the node threat can be determined through color highlighting and style adjustment, the abnormal mode and the causal logic of the downgrade attack can be restored, and then the core vulnerability and the attack path can be quickly located, thereby improving the vulnerability identification accuracy and the analysis efficiency.
[0136] Although embodiments of the present application have been shown and described, it is to be understood that various modifications, substitutions, replacements, and variations can be made to these embodiments without departing from the principles and spirit of the present application, and the scope of the present application is defined by the appended claims and their equivalents.
Claims
1. A network vulnerability visualization mining analysis system, characterized in that, Comprise: The extraction unit obtains a complete protocol session in the target network security protocol, extracts the protocol meta-action at the semantic level from each protocol message constituting the protocol session, records the core security parameters associated with each protocol meta-action, arranges the entire protocol session, and generates a protocol meta-action sequence; The security analysis unit analyzes the protocol meta-action sequence, obtains the instantaneous compound security state after each action is executed, connects all the instantaneous compound security states in time sequence, and generates a security context state chain, including: Based on the protocol meta-action sequence, the bidirectional security conduction characteristics of each meta-action corresponding to the core security parameters are mined, and a security conduction feature map is generated; Based on the security conduction feature map, the security state after the execution of each meta-action is analyzed, and an instantaneous compound security state is generated, which is a multi-dimensional vector composed of a password suite strength coefficient, an authentication phase identifier, and a key material completeness flag bit; According to the security conduction feature map, the security conduction correlation of adjacent meta-actions is analyzed, and a state bidirectional correction coefficient is generated; The protocol mapping unit maps the security context state chain to obtain a protocol state transition graph, analyzes each state node of the protocol state transition graph, and obtains a state update vector; The vulnerability identification unit identifies and separates abnormal state nodes in the state update vector, and generates a logical vulnerability anchor point; The attack analysis unit takes the logical vulnerability anchor point as the starting point and performs attack analysis in the protocol state transition graph to generate a multi-step attack causal chain; The vulnerability mining unit superimposes and fuses the protocol state transition graph and the multi-step attack causal chain to generate a visual protocol vulnerability map.
2. The cyber vulnerability visualization mining analysis system of claim 1, wherein, From each protocol message constituting the protocol session, the protocol meta-action at the semantic level is extracted, and the core security parameters associated with each protocol meta-action are recorded, the entire protocol session is arranged, and a protocol meta-action sequence is generated, including: Context-embedded analysis is performed on each message in the protocol session to generate an embedded feature set; Based on the embedded feature set, the protocol meta-action at the semantic level is analyzed, and the corresponding core security parameters are recorded to generate a dynamic association cluster of actions-parameters; Calculate the logical time sequence weight for each dynamic association cluster to generate a protocol meta-action sequence.
3. The cyber vulnerability visualization mining analysis system of claim 1, wherein, Deductive analysis is performed on the protocol meta-action sequence to obtain the instantaneous compound security state after each action is executed, all the instantaneous compound security states are connected in time sequence to generate a security context state chain, also including: Based on the state bidirectional correction coefficient, the instantaneous compound security state is dynamically optimized in both directions, and is corrected in combination with the change of the core security parameters to generate a compound security state vector; According to the time sequence of the meta-action in the protocol meta-action sequence and the compound security state vector, the logical association relationship between adjacent compound security state vectors is analyzed and labeled to generate a state transition logic label set; The labels of the state transition logic label set are embedded into the connection nodes of the compound security state vector to realize dynamic chain integration and generate a security context state chain.
4. The cyber vulnerability visualization mining analysis system of claim 3, wherein, The security context state chain is mapped to obtain a protocol state transition graph, each state node of the protocol state transition graph is analyzed to obtain a state update vector, including: Analyze the security context state chain to generate a node fusion feature matrix; Map the features and transition association weights of the state nodes based on the node fusion feature matrix to generate a protocol state transition graph; Analyze all state nodes in the protocol state transition graph to obtain a state update vector.
5. The cyber vulnerability visualization mining analysis system of claim 4, wherein, In the state update vector, identify and separate abnormal state nodes to generate a logical vulnerability anchor point, including: Analyze the state update vector, the complex security state vector, and the node fusion feature matrix to construct a state node dynamic baseline that dynamically adjusts with the protocol session; Based on the state node dynamic baseline and the state transition logic label set, calculate the deviation degree and conduction influence degree of each node to generate an abnormal state node conduction set.
6. The cyber vulnerability visualization mining analysis system of claim 5, wherein, In the state update vector, identify and separate abnormal state nodes to generate a logical vulnerability anchor point, including: Trace the paths affected by abnormal conduction in the protocol state transition graph based on the abnormal state node conduction set, and filter the risk paths to generate a risk abnormal path set; Analyze the risk abnormal path set to determine the first deviated node in each path, and reversely associate the corresponding protocol meta-action as a logical vulnerability anchor point.
7. The cyber vulnerability visualization mining analysis system of claim 6, wherein, Starting from the logical vulnerability anchor point, perform attack analysis in the protocol state transition graph to generate a multi-step attack causal chain, including: Starting from the logical vulnerability anchor point, fuse the complex security state vector to calculate the trigger conditions and tolerance thresholds of each security dimension for the anchor point attack, generating an anchor point attack trigger matrix; Based on the anchor point attack trigger matrix and the protocol state transition graph, analyze the risk conduction gain and security state destruction association of each potential attack step to generate a risk conduction gain set.
8. The cyber vulnerability visualization mining analysis system of claim 7, wherein, Starting from the logical vulnerability anchor point, perform attack analysis in the protocol state transition graph to generate a multi-step attack causal chain, including: Analyze the risk conduction gain set to eliminate invalid paths with no gain, generating a multi-step attack causal chain.
9. The cyber vulnerability visualization mining analysis system of claim 8, wherein, Superimpose and fuse the protocol state transition graph and the multi-step attack causal chain to generate a visual protocol vulnerability map, including: Superimpose the protocol state transition graph and the risk abnormal path set to calculate the association strength between state nodes and abnormal paths, generating a protocol state-exception association graph; Dynamically map the protocol state-exception association graph and the multi-step attack causal chain to analyze the causal logic and risk conduction gain between attacks, and inject the attack chain as an attribute into the corresponding path of the association graph to generate an attack-enhanced state transition graph; Analyze the attack-enhanced state transition graph to generate a visual protocol vulnerability map.
Citation Information
Patent Citations
Matrix visualization method based on state transition graph
CN106549950A
Access control method and device thereof
CN111988319A