A port access control strategy quantitative evaluation method based on distributed dynamic verification

By automating the verification of port access control policies through a distributed dynamic verification method, the problems of high difficulty in manual verification and incomplete scanning results in complex networks are solved, achieving efficient and accurate quantitative evaluation and reducing detection costs and time.

CN122137579APending Publication Date: 2026-06-02CHINESE PEOPLES LIBERATION ARMY UNIT 96901

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
CHINESE PEOPLES LIBERATION ARMY UNIT 96901
Filing Date
2026-01-26
Publication Date
2026-06-02

AI Technical Summary

Technical Problem

In complex networks, manual verification of port access control policies is difficult, and the results of scanning with a single port scanning device are incomplete. There is a lack of accurate quantitative evaluation methods, resulting in high detection costs, long processing times, and inaccurate results.

Method used

A quantitative evaluation method for port access control policies based on distributed dynamic verification is adopted. By configuring software distribution, dynamic verification task scheduling and quantitative evaluation subsystems on the detection terminal and the terminal under test, automated verification and data integration are achieved. This method bypasses access control policies to collect port open information and calculates the set of potential connected terminals and the number of high-risk ports.

Benefits of technology

Significantly reduce labor costs, improve detection efficiency, ensure the comprehensiveness and accuracy of port open information collection, and reasonably quantify and evaluate the rationality of network access control policies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122137579A_ABST
    Figure CN122137579A_ABST
Patent Text Reader

Abstract

This invention proposes a quantitative evaluation method for port access control policies based on distributed dynamic verification, used for network security baseline verification, belonging to the field of network information security technology. Addressing the port access control policy verification problem in network security baseline verification, this invention designs a quantitative evaluation method for port access control policies based on distributed dynamic verification, including: a distributed dynamic verification subsystem, a software distribution subsystem, a dynamic verification task scheduling subsystem, and a quantitative evaluation subsystem. This method achieves fine-grained measurement and evaluation of port access control policies in the network through distributed port open information collection and distributed dynamic verification design, thereby improving the coverage and accuracy of network security baseline verification.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application belongs to the technical field of network information security, and particularly relates to a port access control policy quantitative evaluation method based on distributed dynamic verification, which is used for network security checking and detection. BACKGROUND

[0002] The access control function based on TCP / UDP ports has been widely integrated into various products such as firewalls, switches, routers and operating system software firewalls, and port access control is an important part of the information system security baseline. Checking the network port access control policy is an important part of network security detection work. In the traditional checking work, the method of combining manual checking with port scanning is often used. On the one hand, the firewall, switch, terminal user access control policy configuration is checked manually in a static way, and on the other hand, the terminal port opening is probed by using port scanning tools such as asset detection equipment. This method faces the following challenges in actual operation.

[0003] First, manual checking is more and more difficult in complex networks. Users in the network may set access control policies on different devices such as firewalls, switches and terminals according to their own needs. In the manual checking process, it is impossible to understand the overall access control policy configuration of the network by checking a single device. The access control policies configured by the devices in the network must be integrated and analyzed. As the network structure becomes more and more complex, the difficulty of manual analysis becomes greater and greater.

[0004] Second, the scanning results of a single port scanning device are not comprehensive. In the case of network firewall, switch configuration access control policy (especially using white list strategy), the detection personnel's port scanning device may be blocked by the access control policy, resulting in that the port scanning result cannot truly reflect the opening situation of the terminal port in the network.

[0005] Third, the port access control policy checking lacks accurate quantitative evaluation method. The manual checking method is difficult to quantitatively evaluate the effectiveness of the access control policy in the complex network. At the same time, due to the influence of the network access control policy on the port scanning device, the port scanning device cannot fully scan the port opening situation in the network, so it is impossible to accurately quantitatively evaluate the port access control policy in the network. SUMMARY

[0006] In view of the above technical status, the present application provides a port access control policy quantitative evaluation method based on distributed dynamic verification, which is used to solve the problems of high cost and long time of manual port access control policy checking in complex network structure, and to obtain comprehensive port opening and access control information of the terminal under test without changing the port access control in the network.

[0007] The application discloses a port access control strategy quantitative evaluation method based on distributed dynamic verification. S1, configure the detection terminal and the measured terminal; configure a software distribution subsystem, a dynamic verification task scheduling subsystem and a quantitative evaluation subsystem on the detection terminal, and configure a distributed dynamic verification subsystem on the measured terminal; S2, the distributed dynamic verification subsystem of the measured terminal collects terminal open information and sends the terminal open information to the dynamic verification task scheduling subsystem of the detection terminal, and the dynamic verification task scheduling subsystem integrates the terminal open information; S3, the dynamic verification task scheduling subsystem of the detection terminal generates a dynamic verification task for the corresponding measured terminal based on the terminal open information and dispatches the dynamic verification task to the measured terminal, the distributed dynamic verification subsystem of the measured terminal executes the dynamic verification task and reports the task execution result to the quantitative evaluation subsystem of the detection terminal; S4, the quantitative evaluation subsystem of the detection terminal integrates the task execution result, calculates a potential connection terminal set of a terminal port in the measured network, a potential connection terminal set of a terminal, an un-limited access port number and an un-limited access high-risk port number, and further quantitatively evaluates the security of the port access control strategy of the measured network based on the calculation result.

[0008] In S1, The software distribution subsystem, the dynamic verification task scheduling subsystem and the quantitative evaluation subsystem configured on the detection terminal and the distributed dynamic verification subsystem configured on the measured terminal are in software form; The detection terminal is a terminal used for accessing the measured network and performing a port access control strategy checking task, the measured terminal is a terminal with a general operating system and capable of installing software in the measured network, and the detection terminal and the measured terminal maintain normal communication.

[0009] In S1, the software distribution subsystem on the detection terminal configures the measured terminal to download the distributed dynamic verification subsystem software from a target website, so that the distributed dynamic verification subsystem is deployed on the measured terminal.

[0010] In S2, The terminal open information refers to TCP / UDP port open information; The distributed dynamic verification subsystem of the measured terminal is configured with a terminal port open information collection module to check and collect TCP / UDP port open information of the terminal itself and report the information to the dynamic verification task scheduling subsystem of the detection terminal; The dynamic verification task scheduling subsystem of the detection terminal is configured with a terminal port information integration module to integrate and store the TCP / UDP port open information uploaded by the measured terminal.

[0011] In S3: The dynamic verification task scheduling subsystem of the detection terminal is configured with a dynamic verification task dispatch module to dispatch the dynamic verification task to the terminal under test; The dynamic verification task verifies whether a specified port of the terminal specified by the task can be successfully accessed by the terminal executing the task through port probing. The task execution result is passed through a quadruple. To represent it in shape, Indicates the terminal executing the task. Indicates the terminal being probed. Indicates the port being probed. This indicates the port detection result.

[0012] In S3: The dynamic verification task dispatch module generates a dynamic verification task for each terminal under test based on the terminal open information and dispatches it to the corresponding terminal under test. The distributed dynamic verification subsystem of the terminal under test is configured with a dynamic verification task execution module to receive dynamic verification tasks one by one, obtain the task execution results, and report them to the quantitative evaluation subsystem of the testing terminal.

[0013] In S4: The potential set of connected terminals for a terminal port refers to the set of terminals that can access that terminal port; terminal The set of open ports is , This represents the set of terminals that can access the i-th port opened by terminal a. , , ,…, express; The potential set of connected terminals for a terminal refers to the set of terminals that can access any open port of that terminal; the potential set of connected terminals for terminal a is... , ; High-risk ports refer to network ports in the tested network that are exploited by attackers for unauthorized access, intrusion, or attacks. A set of high-risk ports is defined as follows: express, Indicate whether port p is a high-risk port; hour ,otherwise 0; An unrestricted access port refers to a port that is open to terminals without being restricted by any network access control policies. For a port open by a terminal, if at least two terminals can access it, the port is considered an unrestricted access port. Indicates whether port p is an unrestricted access port; hour ,otherwise 0; Unrestricted access to high-risk ports refers to high-risk ports among the unrestricted access ports of a terminal; the number of unrestricted access ports refers to the total number of unrestricted access ports of all terminals in the network. The term "unrestricted access to high-risk ports" refers to the total number of unrestricted access to high-risk ports by all terminals on the network. express; The calculation method for the number of access ports without limitation is as follows: The calculation method for the number of high-risk ports that are not restricted is as follows: The set of terminals in the network is denoted by T.

[0014] The technical effects of this invention include: significantly reducing manual costs and improving detection efficiency by utilizing each tested terminal in a distributed dynamic verification manner for automated checks; by configuring a terminal port open information collection module to collect the terminal's own port open information, bypassing network access control policies and ensuring the comprehensiveness of port open information collection; and by designing a method for terminals to conduct dynamic verification with each other to collect port access control policies between terminals, ensuring the accuracy and comprehensiveness of the data. Furthermore, by calculating the potential set of connected terminals for each terminal port in the network, the potential set of connected terminals for each terminal, the number of unrestricted access ports, and the number of unrestricted high-risk access ports, the invention provides a reasonable quantitative assessment of the exposure of terminal ports in the network and the rationality of network access control policies. Attached Figure Description

[0015] To more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the drawings used in the description of the specific embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.

[0016] Figure 1 This is a schematic diagram illustrating the principle of quantitative evaluation of port access control policies based on distributed dynamic verification according to an embodiment of the present invention. Detailed Implementation

[0017] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0018] This invention proposes a quantitative evaluation method for port access control policies based on distributed dynamic verification, the method comprising: S1. Configure the testing terminal and the terminal under test; configure the software distribution subsystem, dynamic verification task scheduling subsystem, and quantitative evaluation subsystem on the testing terminal, and configure the distributed dynamic verification subsystem on the terminal under test. S2. The distributed dynamic verification subsystem of the tested terminal collects the terminal open information and sends the terminal open information to the dynamic verification task scheduling subsystem of the test terminal, which then integrates the terminal open information. S3. The dynamic verification task scheduling subsystem of the testing terminal generates dynamic verification tasks for the corresponding terminal under test based on the terminal open information and dispatches the dynamic verification tasks to the terminal under test. The distributed dynamic verification subsystem of the terminal under test executes the dynamic verification tasks and reports the task execution results to the quantitative evaluation subsystem of the testing terminal. S4. The quantitative evaluation subsystem for detecting terminals integrates the task execution results and calculates the potential connected terminal set, the potential connected terminal set, the number of unrestricted access ports, and the number of unrestricted access high-risk ports in the network under test. Based on the calculation results, it further quantitatively evaluates the security of the port access control policy of the network under test.

[0019] like Figure 1 As shown, the testing terminal is equipped with a software distribution subsystem, a dynamic verification task scheduling subsystem, and a quantitative evaluation subsystem. The computers, servers, and other terminals under test in the network are equipped with a distributed dynamic verification subsystem.

[0020] The distributed dynamic verification subsystem, software distribution subsystem, dynamic verification task scheduling subsystem, and quantitative evaluation subsystem are all in software form.

[0021] The software distribution subsystem, dynamic verification task scheduling subsystem, and quantitative evaluation subsystem are deployed on the testing terminal.

[0022] The distributed dynamic verification subsystem is deployed on the terminal under test in the network.

[0023] The testing terminal refers to the terminal used by testing personnel to access the network under test and perform port access control policy verification tasks; the terminal under test refers to a computer, server, or other terminal in the network under test that has a general operating system and can install software. The testing terminal can communicate normally with all terminals under test in the network under test.

[0024] The software distribution subsystem is configured with a software download website for the distributed dynamic verification subsystem. The network management unit under test notifies personnel to download and install the software from the website, thereby enabling rapid deployment of the distributed dynamic verification subsystem software.

[0025] The distributed dynamic verification subsystem is configured with a terminal port open information collection module. This module is used to verify and collect the TCP / UDP port open status of the terminal itself and report it to the terminal dynamic verification task scheduling subsystem.

[0026] The dynamic verification task scheduling subsystem is configured with a terminal port information integration module, which is used to integrate and store the TCP / UDP port open information uploaded by the terminal under test.

[0027] The dynamic verification task scheduling subsystem is also configured with a dynamic verification task dispatch module, which is used to dispatch dynamic verification tasks to the terminal under test. The dynamic verification task refers to verifying whether a specified port of the terminal to which the task is executed is accessible by the terminal executing the task, through port probing. This includes the terminal executing the task, the specified terminal to be probed, and the port. The result of executing the dynamic verification task is expressed as a quadruple. Formal representation, in which Indicates the terminal executing the task. Indicates the terminal being detected, Indicates the port being probed, This indicates the port probe results. The dynamic verification task dispatch module, based on the port openness information of the tested terminal provided by the terminal port information integration module, generates a dynamic verification task set for each tested terminal and dispatches it to the corresponding tested terminal for execution. The dynamic verification task set refers to a set of dynamic verification tasks that verify whether the open ports of all other terminals in the network can be accessed by the terminal executing the task through port probes, and includes a series of dynamic verification tasks.

[0028] The distributed dynamic verification subsystem is also configured with a dynamic verification task execution module, which is used to receive a set of dynamic verification tasks, execute them one by one, obtain the task execution results, and report them to the detection terminal quantitative evaluation subsystem.

[0029] The quantitative evaluation subsystem is used to integrate the dynamic verification task execution results reported by each tested terminal, and calculate indicators such as the potential connected terminal set of terminal ports in the network, the potential connected terminal set of the terminal, the number of unrestricted access ports, and the number of unrestricted access high-risk ports to quantitatively evaluate the security of the network's port access control policy.

[0030] The potential set of connected terminals for the terminal port refers to the set of terminals that can access that terminal port. Assume the terminal... The set of open ports is ,in Let represent the i-th port opened by terminal t, and the set of terminals that can access each port be represented by . , , ,…, express.

[0031] The potential connection terminal set of the terminal refers to the set of terminals that can access any open port of the terminal. The potential connection terminal set of terminal a is used... In other words, then High-risk ports refer to a set of network ports that are easily exploited by attackers for unauthorized access, intrusion, or attacks; these can be defined by the user. The high-risk port set is used... Indicates the use of Whether port p is a high-risk port is determined by the following method: An unrestricted access port refers to a port that is open to terminals whose access is not restricted by any network access control policies. If at least two terminals can access a given port opened by a terminal, then that port is considered an unrestricted access port. Indicates whether port p is an unrestricted access port.

[0032] The unrestricted access to high-risk ports refers to high-risk ports among the unrestricted access ports of the terminal.

[0033] The number of unrestricted access ports refers to the total number of unrestricted access ports for all terminals in the network. The term "unrestricted access to high-risk ports" refers to the total number of unrestricted access to high-risk ports by all terminals in the network. Let T represent the set of terminals in the network. The number of unrestricted access ports can be calculated using the following formula: The number of high-risk ports that can be accessed without restriction is calculated using the following formula: In summary, the technical effects of this invention include: significantly reducing manual costs and improving detection efficiency by utilizing each tested terminal in a distributed dynamic verification manner for automated checks; by configuring a terminal port open information collection module to collect port open information of the tested terminal itself, bypassing network access control policies and ensuring the comprehensiveness of port open information collection; and by designing a method for terminals to conduct dynamic verification with each other to collect port access control policies between terminals, ensuring the accuracy and comprehensiveness of the data. Furthermore, by calculating the potential set of connected terminals for each terminal port in the network, the potential set of connected terminals for each terminal, the number of unrestricted access ports, and the number of unrestricted high-risk access ports, the invention provides a reasonable quantitative assessment of the exposure of terminal ports in the network and the rationality of network access control policies.

[0034] Please note that the technical features of the above embodiments can be combined arbitrarily. For the sake of brevity, not all possible combinations of the technical features in the above embodiments have been described. However, as long as the combination of these technical features does not contradict each other, it should be considered within the scope of this specification. The above embodiments only illustrate several implementations of the present invention, and their descriptions are relatively specific and detailed, but they should not be construed as limiting the scope of the invention patent. It should be pointed out that for those skilled in the art, several modifications and improvements can be made without departing from the concept of the present invention, and these all fall within the protection scope of the present invention. Therefore, the protection scope of the present invention should be determined by the appended claims.

Claims

1. A quantitative evaluation method for port access control policies based on distributed dynamic verification, characterized in that, The method includes: S1. Configure the testing terminal and the terminal under test; configure the software distribution subsystem, dynamic verification task scheduling subsystem, and quantitative evaluation subsystem on the testing terminal, and configure the distributed dynamic verification subsystem on the terminal under test. S2. The distributed dynamic verification subsystem of the tested terminal collects the terminal open information and sends the terminal open information to the dynamic verification task scheduling subsystem of the test terminal, which then integrates the terminal open information. S3. The dynamic verification task scheduling subsystem of the testing terminal generates dynamic verification tasks for the corresponding terminal under test based on the terminal open information and dispatches the dynamic verification tasks to the terminal under test. The distributed dynamic verification subsystem of the terminal under test executes the dynamic verification tasks and reports the task execution results to the quantitative evaluation subsystem of the testing terminal. S4. The quantitative evaluation subsystem for detecting terminals integrates the task execution results and calculates the potential connected terminal set, the potential connected terminal set, the number of unrestricted access ports, and the number of unrestricted access high-risk ports in the network under test. Based on the calculation results, it further quantitatively evaluates the security of the port access control policy of the network under test.

2. The method for quantitative evaluation of port access control policies based on distributed dynamic verification according to claim 1, characterized in that, In S1: The software distribution subsystem, dynamic verification task scheduling subsystem, quantitative evaluation subsystem configured on the testing terminal, and the distributed dynamic verification subsystem configured on the tested terminal are all in software form. The detection terminal refers to a terminal used to access the network under test and perform port access control policy verification tasks; the terminal under test refers to a terminal in the network under test that has a general operating system and can install software; the detection terminal and the terminal under test maintain normal communication.

3. The method for quantitative evaluation of port access control policies based on distributed dynamic verification according to claim 2, characterized in that, In S1: The software distribution subsystem on the detection terminal configures the terminal under test to download the distributed dynamic verification subsystem software from the target website, thereby enabling the deployment of the distributed dynamic verification subsystem on the terminal under test.

4. The method for quantitative evaluation of port access control policies based on distributed dynamic verification according to claim 3, characterized in that, In S2: Terminal open information refers to TCP / UDP port open information; The distributed dynamic verification subsystem of the tested terminal is configured with a terminal port open information collection module to verify and collect the terminal's own TCP / UDP port open information and report it to the dynamic verification task scheduling subsystem of the tested terminal. The dynamic verification task scheduling subsystem for the testing terminal is configured with a terminal port information integration module to integrate and store the TCP / UDP port open information uploaded by the terminal under test.

5. The method for quantitative evaluation of port access control policies based on distributed dynamic verification according to claim 4, characterized in that, In S3: The dynamic verification task scheduling subsystem of the detection terminal is configured with a dynamic verification task dispatch module to dispatch the dynamic verification task to the terminal under test; The dynamic verification task verifies whether a specified port of the terminal specified by the task can be successfully accessed by the terminal executing the task through port probing. The task execution result is passed through a quadruple. To represent it in shape, Indicates the terminal executing the task. Indicates the terminal being probed. Indicates the port being probed. This indicates the port detection result.

6. The method for quantitative evaluation of port access control policies based on distributed dynamic verification according to claim 5, characterized in that, In S3: The dynamic verification task dispatch module generates a dynamic verification task for each terminal under test based on the terminal open information and dispatches it to the corresponding terminal under test. The distributed dynamic verification subsystem of the terminal under test is configured with a dynamic verification task execution module to receive dynamic verification tasks one by one, obtain the task execution results, and report them to the quantitative evaluation subsystem of the testing terminal.

7. The method for quantitative evaluation of port access control policies based on distributed dynamic verification according to claim 6, characterized in that, In S4: The potential set of connected terminals for a terminal port refers to the set of terminals that can access that terminal port; terminal The set of open ports is , This represents the set of terminals that can access the i-th port opened by terminal a. , , ,…, express; The potential set of connected terminals for a terminal refers to the set of terminals that can access any open port of that terminal; the potential set of connected terminals for terminal a is... , ; High-risk ports refer to network ports in the tested network that are exploited by attackers for unauthorized access, intrusion, or attacks. A set of high-risk ports is defined as follows: express, Indicate whether port p is a high-risk port; hour ,otherwise 0; An unrestricted access port refers to a port that is open to terminals without being restricted by any network access control policies. For a port open by a terminal, if at least two terminals can access it, the port is considered an unrestricted access port. Indicates whether port p is an unrestricted access port; hour ,otherwise 0; Unrestricted access to high-risk ports refers to high-risk ports among the terminal's unrestricted access ports; Unrestricted access ports refer to the total number of unrestricted access ports for all terminals on the network. express; The number of unrestricted access high-risk ports refers to the total number of unrestricted access high-risk ports for all terminals in the network. express; The calculation method for the number of access ports without limitation is as follows: The calculation method for the number of high-risk ports that are not restricted is as follows: The set of terminals in the network is denoted by T.