Network security risk identification method and apparatus, medium, electronic device, and program product

By acquiring the target network topology and analyzing the attack chain, the problem of identifying critical network security risks in a multi-cloud environment was solved, enabling accurate identification and efficient remediation of critical risks, and ensuring business continuity and rational use of resources.

WO2026001011A1PCT designated stage Publication Date: 2026-01-02BEIJING VOLCANO ENGINE TECH CO LTD

Patent Information

Application Number
PCT/CN2025/077613
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-06-28
Filing Date
2025-02-17
Publication Date
2026-01-02

AI Technical Summary

Technical Problem

In multi-cloud and hybrid cloud environments, existing technologies struggle to accurately identify and prioritize critical cybersecurity risks, leading to unnecessary risk remediation taking up significant time and impacting business development.

Method used

By acquiring the target network topology map and combining it with the asset's business attributes and security characteristics to analyze the attack chain, we can identify security risks in the network, focus on key risks, and reduce the number of business remediation tasks.

Benefits of technology

It enables accurate identification of key risks, reduces the possibility of business interruption, improves the efficiency of risk remediation and business continuity, and reduces storage space requirements.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025077613_02012026_PF_FP_ABST
    Figure CN2025077613_02012026_PF_FP_ABST
Patent Text Reader

Abstract

The present disclosure relates to a network security risk identification method and apparatus, a medium, an electronic device, and a program product. The method comprises: acquiring a target network topology map based on a target object, the target network topology map being used for representing the relationship between the target object and an asset related to the target object; and performing attack link analysis on the target network topology map on the basis of a service attribute and a security feature of the asset in the target network topology map, to identify a security risk in the target network topology map. In this way, a network topology map can be used, the risk is combined with the service attribute and security characteristic of the asset in the network topology map, and attack link analysis is performed on the basis of an attacker's perspective, so that a key risk can be identified more accurately, the number of service repair risks can be reduced, the risk that is most likely to cause asset damage can be focused on, the continuity of a key service process can be ensured, and service interruption caused by a security problem can be reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Network security risk identification method, device, medium, electronic equipment and program product

[0001] This application claims priority to Chinese Patent Application No. 202410870283.9, filed on June 28, 2024, the disclosure of which is incorporated herein in its entirety as part of the present application. TECHNICAL FIELD

[0002] The present disclosure relates to a network security risk identification method, device, medium, electronic equipment and program product. BACKGROUND

[0003] With the migration of business to the cloud, the popularity of multi-cloud and hybrid cloud environments brings new security challenges. In the cloud environment, the heterogeneous assets, permissions provided by various cloud vendors, and the non-uniform security policies bring increasing risks in load, configuration, and permissions. A large number of risks and vulnerabilities make it impossible for business teams to repair them manually, and business development and security convergence are difficult to be compatible. At present, cloud vendors usually determine the severity of risks according to the classification and destructive power of risks, such as dividing vulnerabilities into high-risk, medium-risk, and low-risk. However, for businesses, some high-risk vulnerabilities are in isolated environments, or some serious configuration abnormalities are in test environments, and the severity of risks cannot truly reflect the urgency of risk repair, and the risk level is large, resulting in that a large amount of time is occupied in repairing unnecessary risks, and affecting business development. SUMMARY

[0004] This summary is provided to introduce a selection of concepts, which are further described below in the detailed description. This summary is not intended to identify key or essential features of the claimed subject matter, nor is it intended to be used in limiting the scope of the claimed subject matter.

[0005] In a first aspect, the present disclosure provides a network security risk identification method, comprising: obtaining a target network topology graph based on a target object, wherein the target network topology graph is used to represent the relationship between the target object and its related assets; performing attack link analysis on the target network topology graph based on the business attributes and security characteristics of the assets in the target network topology graph, to identify security risks in the target network topology graph.

[0006] In a second aspect, the present disclosure provides a network security risk identification device, comprising: a first obtaining module configured to obtain a target network topology graph based on a target object, wherein the target network topology graph is used to represent the relationship between the target object and its related assets; and a link analysis module configured to perform attack link analysis on the target network topology graph based on the business attributes and security characteristics of the assets in the target network topology graph, to identify security risks in the target network topology graph.

[0007] In a third aspect, the present disclosure provides a computer readable medium having stored thereon a computer program which, when executed by a processing device, implements the steps of the network security risk identification method according to the first aspect of the present disclosure.

[0008] In a fourth aspect, the present disclosure provides an electronic device comprising: a storage device having stored thereon a computer program; and a processing device configured to execute the computer program stored in the storage device to implement the steps of the network security risk identification method according to the first aspect of the present disclosure.

[0009] In a fifth aspect, the present disclosure provides a computer program product comprising a computer program which, when executed by a processor, implements the steps of the network security risk identification method according to the first aspect of the present disclosure. BRIEF DESCRIPTION OF DRAWINGS

[0010] The above and other features, aspects, and advantages of embodiments of the present disclosure will become more apparent from the following detailed description taken in conjunction with the accompanying drawings. Throughout the drawings, like or similar reference numerals are used to refer to like or similar elements, and the exemplary embodiments can be omitted or simplified for the sake of clarity. In the drawings:

[0011] FIG. 1 is a diagram illustrating the core principle of a network security risk identification method according to an exemplary embodiment.

[0012] FIG. 2 is a flowchart illustrating a network security risk identification method according to an exemplary embodiment.

[0013] FIG. 3 is a flowchart illustrating a method of generating a target network topology graph according to the connection relationship between assets and the mapping relationship between elastic public network IP and assets according to an exemplary embodiment.

[0014] FIG. 4 is a flowchart illustrating a method of adding assets and elastic public network IP related to a current node to a first network topology graph according to the connection relationship between assets and the mapping relationship between elastic public network IP and assets according to an exemplary embodiment.

[0015] FIGS. 5A to 5D are schematic diagrams illustrating a process of generating a target network topology graph according to the connection relationship between assets and the mapping relationship between elastic public network IP and assets according to an exemplary embodiment.

[0016] FIG. 6 is a flowchart illustrating a network security risk identification method according to another exemplary embodiment.

[0017] FIG. 7 is a flowchart illustrating a network security risk identification method according to yet another exemplary embodiment.

[0018] FIG. 8 is a block diagram of a network security risk identification apparatus according to an exemplary embodiment.

[0019] FIG. 9 is a structural schematic diagram of an electronic device according to another exemplary embodiment. DETAILED DESCRIPTION

[0020] Before introducing the specific embodiments of the present disclosure, first, the terms involved in the present disclosure and the core principles of security risk identification are introduced and explained.

[0021] Elastic Compute Service (ECS) is a cloud computing service that allows users to rent virtual servers in the cloud to run applications and process data.

[0022] In the field of information security and risk management, assets usually refer to the information assets of an organization, including hardware, software, data, documents, services, etc. These assets are crucial to the organization's operations, decision-making, and competitiveness, so they need to be properly protected and managed. For example, assets can be ECS, Virtual Private Cloud (VPC), subnet, network card, Server Load Balancer (SLB), Network Address Translation (NAT), virtual IP, container, Elastic IP (EIP), etc.

[0023] Assets can be divided into core assets and non-core assets according to business attributes. Among them, core assets are a group of assets that need to be protected and are the assets that attackers ultimately want to obtain or destroy. Core assets are assets that meet preset conditions, which can be assets with core labels or can be classified by humans. Core assets include but are not limited to data assets, device assets, and operating systems that need to be protected. Non-core assets refer to assets that are less important to the organization. They may have some impact on daily operations, but even if they are damaged or lost, they will not cause serious or long-term impact on the organization.

[0024] Public exposure usually refers to the fact that certain devices, services, or data are not properly protected or hidden on public networks, making them vulnerable to unauthorized access or attacks. In the field of network security, this is usually a serious problem because it can lead to risks such as the leakage of sensitive information, the intrusion of systems, or the tampering of data.

[0025] In the field of network security, lateral movement is the process by which an attacker exploits vulnerabilities or misconfigurations to move from one infected system or network node to another, expanding the scope of the attack or gaining access to more sensitive information. This movement can be achieved through trust relationships within an internal network, the use of known credentials, or the exploitation of other system vulnerabilities. Once the attacker successfully performs lateral movement, they can pose a greater threat to the entire network, including data breaches, system crashes, or business disruptions.

[0026] A web shell is a script or program that executes commands through a scripting language on a web server, typically used for remote management of web servers. It allows users to execute system commands through a web interface, just like operating directly on the server's command line.

[0027] Cloud Security Posture Management (CSPM) is a strategy and technology focused on improving the security performance of cloud environments. The goal of CSPM is to ensure that cloud resource configurations comply with security standards, detect and fix security vulnerabilities in a timely manner, and continuously monitor the security status of cloud resources.

[0028] Cloud Identity and Event Management (CIEM) is a cloud security solution that focuses on managing identity and cloud permissions through the principle of least privilege.

[0029] Distributed Denial of Service (DDoS) is a common network attack method. Attackers control or exploit a large number of computers or network devices to send a large number of useless requests or data packets to the target server, consuming its bandwidth, CPU and memory resources, so that it cannot handle normal requests or provide normal services.

[0030] A bastion host, also known as an operation and maintenance security audit system, is a specific network environment that uses various technical means to monitor and record the operation of network servers, network devices, security devices, databases and other devices by operation and maintenance personnel, in order to centralize alarm, timely processing and audit responsibility.

[0031] Log4j is an open source project of the Apache Foundation, providing a powerful log management tool for Java. It aims to set log recording behavior at runtime through configuration files, allowing flexible control of log output format, output destination (such as console, file, GUI component, etc.), and log level.

[0032] Git is an open-source, distributed version control system used to track changes in files within a project. It allows developers to record every update and modification of file content and can manage multiple versions of project history.

[0033] One-Liner Shell refers to a very short script code that can be embedded in a web page or uploaded to a server through other means. This code, although short, is powerful and allows attackers to execute remote commands or gain control over the server. It is usually contained in a single line of code, hence the name "one-liner".

[0034] A prefix list is a collection of rules used to match destination network segment addresses or next-hop addresses in routing information. Prefix lists typically include prefixes (i.e., IP addresses) and mask length ranges, which are used to filter routing information published and received by routing protocols. Specifically, prefix lists can be used to specify which networks are reachable and which are not, thereby controlling the propagation of routing information. A prefix list has two main parameters: prefix and prefix length (or subnet mask). The prefix is the specified route prefix (network segment), while the prefix length specifies the length of the subnet mask.

[0035] The core principles of security risk identification are as follows. As shown in FIG. 1, attackers usually have two entry points to compromise core assets: one entry point is public network exposure, which belongs to the network layer entry. Through public network exposure, the core assets can be reached on the network path, for example, by attacking non-core assets to move horizontally to the core assets. The other entry point is secret leakage.

[0036] As shown in FIG. 1, attackers can attack core assets through public network exposure. If non-core assets (such as cloud resources shown in FIG. 1, such as ECS, containers, etc.) are bound with EIP, attackers can obtain access to the above assets through the following attack means, and reach the core assets through unreasonable network configuration, expanded permissions, horizontal movement, etc.:

[0037] (a1) Exploitable network vulnerabilities: attack through exploitable network vulnerabilities, such as log4j vulnerabilities;

[0038] (a2) Exploitable Web Shell / malware: attackers upload Web Shell through web applications or make users deploy malware through malicious images, etc.

[0039] (a3) Attackers attack non-core assets through attacks such as one-liner shell;

[0040] (a4) Attackers attack non-core assets through brute force attacks and weak passwords (i.e., weak passwords).

[0041] When the non-core asset is deployed with resource code of plaintext access key (AK), secret key (SK), database password, etc., the attacker can further expand the attack to obtain access to the core asset, i.e., through unreasonable network configuration to reach the core asset, as shown in Fig. 1, through CSPM to reach the core asset. When the non-core asset can access the relational database service (RDS), MongoDB, and other database resources, the attacker can further do brute force and expand the permission to obtain the core data (i.e., reach the core asset), as shown in Fig. 1, through CIEM to reach the core asset. After attacking the non-core asset, the attacker can also move horizontally from the attacked non-core asset to the core asset.

[0042] As shown in Fig. 1, the attacker can also attack the core asset from the identity permission, i.e., attack the core asset through secret leakage, which has the following several ways:

[0043] (b1) If some core assets are not set with authorized access (i.e., anonymous access), the attacker can easily obtain core data, i.e., reach the core asset;

[0044] (b2) If AK is leaked, such as the developer embedding AK or SK in plaintext into the code and uploading to Git, the core asset is easily attacked by the attacker;

[0045] (b3) When an internal user steals core confidential data with his own permission, resulting in data leakage (i.e., abnormal user shown in Fig. 1);

[0046] (b4) If the attacker obtains a certain cloud identity, due to the abnormality of CSPM, the attacker can obtain more cloud resources, i.e., through secret leakage, through permission amplification to reach the core asset (i.e., through CSPM to reach the core asset shown in Fig. 1).

[0047] Embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although certain embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms, and should not be interpreted as being limited to the embodiments set forth herein, but rather these embodiments are provided to more thoroughly and completely understand the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are for exemplary purposes only and are not intended to limit the scope of protection of the present disclosure.

[0048] It should be understood that each step recited in the method embodiments of the present disclosure can be performed in different orders and / or in parallel. In addition, the method embodiments can include additional steps and / or omit performing the steps shown. The scope of the present disclosure is not limited in this respect.

[0049] The term "comprising" and variations thereof as used herein are used inclusively, i.e., "comprising, but not limited to." The term "based on" means "based, at least in part, on." The term "one embodiment" means "at least one embodiment." The term "another embodiment" means "at least one additional embodiment." The term "some embodiments" means "at least some embodiments." Related definitions are given below in the description of the various terms.

[0050] It should be noted that the terms "first", "second", and the like in the present disclosure are merely used to distinguish different devices, modules or units, and do not imply the order or interdependence of the functions performed by these devices, modules or units.

[0051] It should be noted that the terms "one", "multiple" in the present disclosure are illustrative and not restrictive, and those skilled in the art should understand that "one or more" should be understood unless otherwise explicitly indicated in the context.

[0052] The names of the messages or information exchanged between the devices in the embodiments of the present disclosure are merely for illustrative purposes, and are not intended to limit the scope of the messages or information.

[0053] It can be understood that, before using the technical solutions disclosed in the embodiments of the present disclosure, the type, use range, use scenario, etc. of the personal information involved in the present disclosure should be informed to the user and the authorization of the user should be obtained in a proper manner according to relevant laws and regulations.

[0054] For example, in response to receiving an active request of a user, a prompt information is sent to the user to explicitly prompt the user that the operation requested to be performed will require obtaining and using personal information of the user. Thus, the user can voluntarily choose whether to provide personal information to the software or hardware such as electronic device, application program, server or storage medium, etc. performing the operation of the technical solutions of the present disclosure according to the prompt information.

[0055] As an optional but non-limiting implementation manner, in response to receiving an active request of a user, the manner of sending a prompt information to the user may, for example, be a pop-up window manner, in which the prompt information can be presented in the form of text. In addition, the pop-up window can also carry a selection control for the user to select "agree" or "disagree" to provide personal information to the electronic device.

[0056] It can be understood that the above notification and user authorization process is only illustrative and does not limit the implementation of the present disclosure, and other methods that meet relevant laws and regulations can also be applied to the implementation of the present disclosure.

[0057] At the same time, it can be understood that the data involved in the technical solution (including but not limited to the data itself, the acquisition or use of the data) should comply with the requirements of relevant laws and regulations and relevant provisions.

[0058] FIG. 2 is a flowchart illustrating a network security risk identification method according to an exemplary embodiment. As shown in FIG. 2, the network security risk identification method can include the following S101 and S102.

[0059] In S101, a target network topology graph based on a target object is acquired.

[0060] In the present disclosure, the target object can be an object pre-set by the user, or can be determined based on a security risk identification request initiated by the user. The security risk identification request is used to indicate identification of a security risk related to the target object, and the security risk identification request can include the target object. The target network topology graph is used to represent the relationship between the target object and its related assets. The target object can include one of an asset, an identity, and a resource. The identity entity can be divided into five types, namely a user, a user group, a role, a service, and an identity provider (IDP). The resource includes a database, and the asset can include at least one of a virtual private cloud (VPC), a subnet, a network card, an elastic computing service, and a container.

[0061] In S102, based on the business attribute and the security characteristic of the asset in the target network topology graph, attack link analysis is performed on the target network topology graph to identify a security risk in the target network topology graph.

[0062] In the present disclosure, the business attribute of the asset is used to represent whether the corresponding asset is a core asset, and the security characteristic of the asset can include the horizontal movement of the asset, public network exposure, and the like. By using the network topology graph, the risk and the business attribute and the security characteristic of the asset in the network topology graph are combined, and attack link analysis is performed based on the perspective of an attacker.

[0063] In the technical solution, the target network topology graph based on the target object is acquired, and then, based on the business attributes and security characteristics of the assets in the target network topology graph, attack link analysis is performed on the target network topology graph to identify security risks in the target network topology graph. In this way, the network topology graph can be used to combine the risks with the business attributes and security characteristics of the assets in the network topology graph, and attack link analysis can be performed based on the attacker's perspective, so that key risks can be more accurately identified, the number of business repair risks can be reduced, the risks that can cause the most asset loss can be focused on, the continuity of key business processes can be ensured, and business interruption caused by security problems can be reduced. In addition, through automatic attack link analysis, potential security threats can be quickly identified, so that rapid response and repair can be performed, and the impact of security events on business can be reduced. Furthermore, only the target network topology graph related to the target object can be generated, rather than the network topology graph of the entire business system, so that multi-layer topology effect can be achieved with less storage space, key risk identification can be targeted, and through the target network topology graph, the risk repair personnel can clearly see the asset loss caused by not repairing, which increases the repair motivation of the risk repair personnel.

[0064] The specific implementation of acquiring the target network topology graph based on the target object in S101 will be described in detail below.

[0065] Specifically, when acquiring the target network topology graph based on the target object, it can be detected whether a network topology graph based on the target object has been generated within a preset time period before the current time. If a network topology graph based on the target object has been generated within the preset time period before the current time, the generated network topology is directly used as the target network topology graph. If a network topology graph based on the target object has not been generated within the preset time period before the current time, different topology graph generation methods can be used to generate the target network topology graph according to different types of target objects.

[0066] In an embodiment, the target object is an asset, and specifically, the target asset. In this case, the target network topology graph representing the relationship between the target asset and other related assets can be generated according to the connection relationship between the assets and the mapping relationship between the elastic public IP and the assets.

[0067] In the present disclosure, the connection relationship between assets and assets can include a relationship between different VPCs, a relationship between subnets and subnets, a relationship between a subnet and an asset or IP within a VPC to which the subnet belongs, a relationship between a bastion host and an ECS, a relationship between an EIP and a cloud wall, a relationship between a Web Application Firewall (WAF) and a service group, a limiting relationship between a WAF and the Internet, and the like. Among them, the limiting relationship between the WAF and the Internet mainly reflects the prevention of web application attacks by the WAF and the limitation on the access port.

[0068] In another embodiment, the target object is a resource or an identity, which can specifically include a target resource or a target identity. In this case, a target network topology graph based on the target object can be generated through steps (c1) to (c4) as follows:

[0069] Step (c1): Obtain a permission topology graph based on the target object, wherein the permission topology graph is used to represent the relationship between the identity and the resource.

[0070] In an embodiment, the target object is a target resource. In this case, the identity corresponding to the target resource can be obtained according to the pre-established correspondence relationship between the identity and the resource (used to represent the resources that can be accessed by different identities). Then, the connection relationship between the target resource and the identity corresponding thereto is represented by a topology graph, that is, a permission topology graph based on the target resource is obtained.

[0071] In another embodiment, the target object is a target identity. In this case, the resource corresponding to the target identity can be obtained according to the pre-established correspondence relationship between the identity and the resource. Then, the connection relationship between the target identity and the resource corresponding thereto is represented by a topology graph, that is, a permission topology graph based on the target identity is obtained.

[0072] The attributes of the connection relationship between the resource and the identity can include read-only, read-write, management, privilege (for example, including all permissions such as read-write and management), and the like.

[0073] Step (c2): Determine the related assets of the resource in the permission topology graph based on the pre-constructed correspondence relationship between the assets and the resources.

[0074] In the present disclosure, each resource is usually configured with a white list, and only the assets in the white list can access the corresponding resource. The correspondence relationship between the assets and the resources can be constructed according to the white list corresponding to each resource.

[0075] Step (c3): Obtain a tenth network topology graph based on the related assets.

[0076] In the present disclosure, if a network topology map based on the related asset has been generated within a preset time period before the current time, the generated network topology is directly taken as the tenth network topology map; if a network topology map based on the related asset has not been generated within a preset time period before the current time, the tenth network topology map based on the related asset can be generated according to the connection relationship between assets and assets and the mapping relationship between the elastic public network IP and the asset.

[0077] Step (c4): adding the tenth network topology map to the permission topology map to obtain a target network topology map based on the target object.

[0078] The target network topology map based on the target identity or the target resource not only contains the relationship between the identity and the resource, but also contains the relationship between the resource and the asset, so that the identity and the asset can be associated, and more security risks can be mined from the secret leakage as an attack entry.

[0079] The construction method of the connection relationship between assets will be described in detail below. Specifically, the following steps (d1) to (d3) can be used to achieve the connection relationship between assets.

[0080] Step (d1): collecting assets in the business system.

[0081] In the present disclosure, the assets in the business system can be queried based on the asset identifier (for example, ID), and the association relationship between the asset and the asset identifier can be established.

[0082] Step (d2): relationship processing of the collected assets.

[0083] In the present disclosure, the relationship processing can specifically include: for each VPC in the business system, constructing the corresponding relationship between the VPC identifier, the asset identifier and the IP segment of the asset; constructing the mapping relationship between the EIP and the asset; constructing the corresponding relationship between the NAT and the ECS, constructing the corresponding relationship between the SLB and the ECS; associating the Access Control List (ACL) with the subnet, and abstracting the ACL into a unified structure permission; associating the policy of the cloud wall (i.e. the permission list of the cloud wall) with the asset bound by the cloud wall, and abstracting the policy of the cloud wall into a unified structure permission; abstracting the policy of the security group (i.e. the permission list of the security group) into a unified structure permission.

[0084] The permission generally refers to a data structure or object model that encapsulates the rules and attributes of access control. The structure can include various elements such as operations (allow / deny), protocol types (such as TCP, UDP, ICMP), port ranges, address information (including any of source IP address, destination IP address, network segment), etc. The policies of the cloud wall are divided into two categories: one is the cloud wall policy based on EIP, and the other is the cloud wall policy across VPC.

[0085] Step (d3): based on the processing result of the asset, the connection relationship between the above-mentioned assets and assets is constructed.

[0086] In the disclosure, the relationship between different VPCs, the relationship between subnets, and the relationship between subnets and assets or IPs in the VPC to which the subnets belong can be constructed by traversing the routing table in the business system. Specifically, the following methods can be used:

[0087] First, for each routing table in the business system, find the VPC and subnet to which the routing table belongs according to the identifier of the VPC and the identifier of the subnet to which the routing table belongs; then, associate the routing table with the VPC and subnet to which it belongs, and traverse the routing entries in the routing table, wherein the routing entries are classified and processed according to the next hop type, and the routing entries are (destination IP address, next hop type, next hop identifier).

[0088] Specifically, if the destination IP address in the current routing entry is 100.64.0.0 / 10, it is ignored, i.e. no relationship association operation is performed; if the destination IP address in the current routing entry is the default gateway (e.g. 0.0.0.0 / 0), the next hop asset is obtained according to the next hop identifier in the routing entry, a one-way connection relationship between the VPC to which the routing table belongs and the next hop asset is established, and the next hop asset is marked as "gateway"; if the destination IP address in the current routing entry is neither 100.64.0.0 / 10 nor the default gateway, the relationship is constructed according to the next hop type in the current routing entry.

[0089] Among them, the relationship can be constructed according to the next hop type in the current routing entry by the following methods:

[0090] If the next hop type in the current routing entry is InnerSubnet, the first target asset identifier corresponding to the destination IP address in the current routing entry is determined according to the correspondence between the VPC identifier, the asset identifier and the IP segment of the asset constructed in step (d2) above, and the first target asset (specifically, a target subnet) corresponding to the first target asset identifier is determined according to the association between the asset and the asset identifier constructed in step (d1) above. Then, a one-way connection relationship between the subnet to which the routing table belongs and the target subnet is established, and the connection relationship is marked as "VPC-in connection".

[0091] If the next hop type in the current routing entry is a prefix list, an IP prefix object (i.e., a target prefix list) corresponding to the next hop identifier (i.e., a prefix list identifier) is obtained. Then, the first target IP segment matching the IP prefix object and the second target asset identifier corresponding to the first target IP segment are determined according to the correspondence between the VPC identifier, the asset identifier and the IP segment of the asset constructed in step (d2) above. Next, the second target asset corresponding to the second target asset identifier is determined according to the association between the asset and the asset identifier constructed in step (d1) above, and a connection relationship between the subnet to which the routing table belongs and the second target asset is established.

[0092] If the next hop type in the current routing entry is any one of a cloud server, an auxiliary network card, a NAT gateway, a high-availability virtual IP and an IPv6 gateway, the second target IP segment consistent with the destination IP address in the current routing entry and the third target asset identifier corresponding to the second target IP segment are determined according to the correspondence between the VPC identifier, the asset identifier and the IP segment of the asset constructed in step (d2) above, and the third target asset corresponding to the third target asset identifier is determined according to the association between the asset and the asset identifier constructed in step (d1) above. Then, a one-way connection relationship between the subnet to which the routing table belongs and the third target asset is established, and the connection relationship is marked as "VPC-in connection". If there is no IP segment consistent with the destination IP address in the correspondence between the VPC identifier, the asset identifier and the IP segment of the asset, and the destination IP address is a subset of an IP segment (hereinafter referred to as a third target IP segment) in the correspondence, the fourth target asset identifier corresponding to the third target IP segment is determined according to the correspondence, and the fourth target asset corresponding to the fourth target asset identifier is determined according to the association between the asset and the asset identifier constructed in step (d1) above. Then, a one-way connection relationship between the subnet to which the routing table belongs and the fourth target asset is established, and the connection relationship is marked as "limited connection", and the destination IP address is attached to the relationship.

[0093] If the next hop type in the current routing entry is any one of a cloud enterprise network, a VPN gateway, a transit router, and a dedicated line, a connection asset corresponding to the next hop identifier in the current routing entry is acquired, and according to the connection asset, a peer asset is found. Then, a one-way relationship between the VPC to which the routing table belongs and the peer asset is established, and the connection relationship is marked as "inter-VPC connection".

[0094] In order to facilitate the user to correct the relationship in time when there is a problem, after the above relationship is established, the routing table identifier and the current routing entry identifier can be attached to the relationship as the source of establishing the relationship.

[0095] The specific construction manner of the above relationship between the WAF and the service group, and the restriction relationship between the WAF and the Internet will be described in detail below. Specifically, in the case where the user enables the WAF: if the WAF is an SLB WAF, a relationship between the SLB and the WAF is established, and if the WAF is a Canonical Name (CNAME) WAF, a public network provided by the WAF is acquired, a relationship between the EIP of the public network and the WAF is established, and a list of backend server IPs bound to the WAF is acquired, and the IP list is converted into an asset, and a relationship between the WAF and the converted asset is established.

[0096] In addition, the asset instance of the cloud wall enabled can be acquired, and then a bidirectional relationship between the asset instance and the cloud wall is established, so as to realize the relationship construction between the EIP and the cloud wall. Moreover, in the case where the ECS enables the bastion host, a relationship between the ECS and the bastion host is established.

[0097] The specific implementation of generating the target network topology graph representing the relationship between the target asset and other related assets according to the connection relationship between the assets and the mapping relationship between the elastic public network IP and the asset will be described in detail below. Specifically, the target asset can include at least one VPC. Wherein, when generating the topology graph between VPCs, the target asset can include one or more VPCs; when generating the topology graph between subnets in a VPC, the target asset includes one VPC, and the target network topology graph is used to represent the connection relationship between the subnets in the one VPC. At this time, the target network topology graph can be generated through steps 1-6 shown in FIG. 3:

[0098] Step 1, taking the first node in the target sequence as the current node.

[0099] Wherein, when generating the topology graph between VPCs, the target sequence is composed of the above at least one VPC, and when generating the topology graph between subnets in a VPC, the target asset includes one VPC, and the target sequence is composed of the subnets in the one VPC.

[0100] Step 2, judging whether the current node exists in the first network topology graph.

[0101] In the present disclosure, the first network topology graph is initially empty. If the current node exists in the first network topology graph, it indicates that the asset directly related to the current node has been added to the first network topology graph. At this time, the current node can be ignored, and the next node of the current node in the target sequence is considered, that is, the following step 3 is directly executed. If the current node does not exist in the first network topology graph, the asset directly related to the current node is considered to be added to the first network topology graph, that is, the following step 4 is executed, and then step 3 is executed.

[0102] Step 3, judging whether the current node has a next node.

[0103] If the current node has a next node, the following step 5 is executed. If the current node does not have a next node, it indicates that all the related relationships have been added to the first network topology graph. At this time, the first network topology graph is completed, and the latest first network topology graph is determined as the target network topology graph, that is, the following step 6 is executed.

[0104] Step 4, according to the connection relationship between the assets and the mapping relationship between the elastic public network IP and the assets, the asset and the elastic public network IP related to the current node are added to the first network topology graph.

[0105] Step 5, the next node of the current node in the target sequence is taken as the current node, and the above step 2 is returned.

[0106] Step 6, the first network topology graph is determined as the target network topology graph.

[0107] The specific implementation of step 4 in the above will be described in detail. Specifically, steps 21-28 in FIG. 4 can be used to achieve the implementation.

[0108] Step 21, the current node is added to the target node set.

[0109] The target node set is initially empty.

[0110] In step 22, the target connection relationship related to the current node is determined according to the connection relationship between the assets.

[0111] In the present disclosure, the target connection relationship is used to represent the relationship between the current node and the asset of the same type.

[0112] In an embodiment, the current node is a VPC, and the asset of the same type as the current node is also a VPC, and the target connection relationship is used to represent the relationship between the current VPC and the VPCs associated with the current VPC.

[0113] In another embodiment, the current node is a subnet, and the asset of the same type as the current node is also a subnet, and the target connection relationship is used to represent the relationship between the current subnet and the subnets associated with the current subnet, wherein the subnets associated with the current subnet belong to the same VPC.

[0114] Step 23, add the target connection relationship to the first network topology graph.

[0115] Step 24, if there is an elastic public IP corresponding to the current node in the mapping relationship between the elastic public IP and the asset, add the corresponding relationship between the corresponding elastic public IP and the current node to the first network topology graph.

[0116] In order to directly know whether the asset is exposed to the public network when identifying security risks, the elastic public IP corresponding to the current node can be added to the first network topology graph.

[0117] Step 27, determine whether the new node based on the current node in the first network topology graph is empty.

[0118] In the present disclosure, the new node based on the current node refers to the node added after the target connection relationship related to the current node is added to the first network topology graph, wherein the new node does not include the elastic public IP.

[0119] If the new node based on the current node in the first network topology graph is not empty, step 25 is executed; if the new node based on the current node in the first network topology graph is empty, step 28 is executed.

[0120] Step 26, for each new node in the target node set, the new node is taken as the current node.

[0121] Step 25, remove the current node from the target node set and add the new node to the target node set.

[0122] After removing the current node from the target node set and adding the new node to the target node set, step 26 can be executed, and then step 22 is returned to add the connection relationship related to the new node to the first network topology graph.

[0123] In step 28, it is determined whether the new node of each node in the target node set is empty.

[0124] When the new nodes based on the current node are not empty in the first network topology graph, the new nodes based on the current node can be one or more. At this time, the association relationship related to each new node can be added to the first network topology graph respectively, that is, each new node is taken as a current node, and the association relationship related to each current node is added to the first network topology graph respectively. Then, for each new node, if the new nodes based on the new node are not empty, the association relationship related to the new nodes based on the new node is added to the first network topology graph. This cycle continues until the new nodes based on the last batch of new nodes (that is, one or more current nodes) are all empty, that is, until the new nodes based on each node in the target node set are all empty. At this time, it is indicated that the direct association relationship and the indirect association relationship related to the current node have been added to the first network topology graph. The next node of the current node in the target sequence can be considered, that is, step 3 is executed. If the new nodes based on each node in the target node set are not all empty, it is continued to monitor whether the new nodes based on each node in the target node set are all empty, that is, step 28 is returned to continue to be executed.

[0125] For example, the target sequence is VPC1, VPC3, VPC6. At this time, the target network topology graph can be constructed through steps (e1) to (e6):

[0126] Step (e1): VPC1 is taken as a current node. At this time, the first network topology graph is empty, that is, VPC1 does not exist in the first network topology graph.

[0127] Step (e2): the current node VPC1 is added to the target node set. At this time, the target node set is {VPC1}.

[0128] Step (e3): according to the connection relationship between the assets, the target connection relationship related to VPC1 includes the connection relationship between VPC1 and VPC2 and the connection relationship between VPC1 and VPC3. The target connection relationship is added to the first network topology graph to obtain the first network topology graph shown in FIG. 5A.

[0129] Step (e4): the elastic public IP corresponding to VPC1 in the mapping relationship is EIP1. The corresponding relationship between EIP1 and VPC1 is added to the first network topology graph shown in FIG. 5A to obtain the first network topology graph shown in FIG. 5B.

[0130] Step (e5): At this time, the new node based on VPC1 includes VPC2 and VPC3, the current node VPC1 is removed from the target node set "{VPC1}", and VPC2 and VPC3 are added to the target node set, at this time, the target node set is {VPC2, VPC3}, and then VPC2 and VPC3 are taken as the current node respectively to add their related target connection relationships to the first network topology graph shown in FIG. 5B; for VPC2, the target connection relationship related to VPC2 determined according to the connection relationship between assets includes the connection relationship between VPC1 and VPC2, after adding it to the first network topology graph shown in FIG. 5B, the obtained topology graph does not change, that is, the new node based on VPC2 is empty, at this time, the condition that the new node based on each node in the target node set is empty is not met, and it is continued to detect whether the condition that the new node based on each node in the target node set is empty is met; for VPC3, the target connection relationship related to VPC3 determined according to the connection relationship between assets includes the connection relationship between VPC3 and VPC1 and the connection relationship between VPC3 and VPC4, after adding it to the first network topology graph shown in FIG. 5B, the first network topology graph shown in FIG. 5C is obtained, and there is no EIP corresponding to VPC3 in the mapping relationship, so that the EIP adding operation is not needed.

[0131] Step (e6): At this time, the new node based on VPC3 includes VPC4, the current node VPC3 is removed from the target node set "{VPC2, VPC3}", and VPC4 is added to the target node set, at this time, the target node set is {VPC2, VPC4}, and then VPC4 can be taken as the current node, the target connection relationship related to VPC4 determined according to the connection relationship between assets includes the connection relationship between VPC4 and VPC3, after adding it to the first network topology graph shown in FIG. 5C, the obtained topology graph does not change, that is, the new node based on VPC4 is empty; at this time, the condition that the new node based on each node in the target node set is empty is met, VPC3 in the target sequence can be taken as the current node, the first network topology graph shown in FIG. 5C already contains VPC3, therefore, VPC6 in the target sequence can be taken as the current node, for VPC6 as the current node, the current node VPC6 is added to the target node set, at this time, the target node set is {VPC2, VPC4, VPC6}, the target connection relationship related to VPC6 determined according to the connection relationship between assets includes the connection relationship between VPC6 and VPC7, after adding it to the first network topology graph shown in FIG. 5C, the first network topology graph shown in FIG. 5D is obtained.

[0132] Step (e7): If there is no EIP corresponding to VPC6 in the mapping relationship, no EIP addition operation is needed, at this time, the new node based on VPC6 includes VPC7, then, the current node VPC6 is removed from the target node set "{VPC2, VPC4, VPC6}", and VPC7 is added to the target node set, at this time, the target node set is {VPC2, VPC4, VPC6}, VPC7 can be taken as the current node, the target connection relationship related to VPC7 determined according to the connection relationship between assets includes the connection relationship between VPC7 and VPC6, after adding the connection relationship to the first network topology graph shown in FIG. 5D, the obtained topology graph does not change, that is, the new node based on VPC7 is empty, at this time, the condition that the new node based on each node in the target node set is empty is met, then, the next node of VPC6 in the target sequence is determined to be empty, therefore, the first network topology graph shown in FIG. 5D can be determined as the target network topology graph.

[0133] In order to ensure the real-time accuracy of the target network topology graph, when there is a cloud wall between the target connection relationships, the network topology graph after adding the target connection relationship is modified by using the strategy of the cloud wall. Specifically, before step 24, the assets and elastic public IP related to the current node are added to the first network topology graph according to the connection relationship between the assets and the assets, and the mapping relationship between the elastic public IP and the assets, and the method further comprises:

[0134] If the target connection relationship is a cross-VPC relationship, and there is a cloud wall between the target connection relationships, the first network topology graph is modified based on the permission list of the cloud wall.

[0135] At this time, step 24 can include: if there is an elastic public IP corresponding to the current node in the mapping relationship between the elastic public IP and the assets, the corresponding relationship between the corresponding elastic public IP and the current node is added to the first network topology graph obtained after modification.

[0136] The cloud wall can include the firewall (FW) shown in FIG. 1, and the first network topology graph can also be modified based on the secure sockets layer (SSL), network traffic analysis (NTA), etc.

[0137] The specific implementation of modifying the first network topology graph based on the permission list of the cloud wall will be described in detail below. Specifically, steps (f1) to (f5) can be used to achieve the following:

[0138] Step (f1): The permission list of the cloud wall is sorted according to priority from low to high to obtain a first permission list.

[0139] Step (f2): The permission rules with the same priority in the first permission list are arranged according to the order of operation as rejection and operation as permission to obtain a second permission list.

[0140] In the present disclosure, the policy of the cloud wall is a permission list composed of permission rules, wherein the permission rule is abstracted as a permission structure, which includes elements such as operation (allow / reject), address information (IP address or IP segment), etc.

[0141] Step (f3): The first target node to be processed is determined according to the type of address information in the current permission rule by traversing the second permission list.

[0142] In the present disclosure, the current permission rule is the permission rule currently traversed in the second permission list. Specifically, if the address information in the current permission rule is the default gateway, the VPC to which the cloud wall belongs existing between the target connection relationship is determined as the first target node; if the address information in the current permission rule is the security group, the address information is determined as the first target node, that is, the security group is determined as the first target node; if the address information in the current permission rule is the IP address or IP prefix, the first target node is determined according to the address information and the corresponding relationship between the VPC identifier, asset identifier and IP segment of the asset pre-constructed.

[0143] Step (f4): When the operation in the current permission rule is acceptance, the connection relationship between the current node and the first target node is added to the first network topology graph according to the direction information in the current permission rule.

[0144] In the present disclosure, the direction information is out or in. When the direction information is in, the connection relationship between the current node and the first target node is from the first target node to the current node, indicating that the first target node can access the current node; when the direction information is out, the connection relationship between the current node and the first target node is from the current node to the first target node, indicating that the current node can access the first target node.

[0145] Step (f5): When the operation in the current permission rule is rejection, at least according to the type of address information in the current permission rule, a target processing strategy for the first target node is determined and executed, wherein the target processing strategy is one of the following: removing the first target node from the first network topology graph, and modifying the relationship between the current node and the first target node to limited connection.

[0146] The following detailed description is made with respect to the above determining the first target node according to the address information, and the correspondence between the VPC identifier, the asset identifier, and the IP segment of the asset.

[0147] Specifically, if the fourth target IP segment consistent with the address information exists in the correspondence between the VPC identifier, the asset identifier, and the IP segment of the asset, the asset represented by the asset identifier corresponding to the fourth target IP segment in the correspondence is determined as the first target node; if the fourth target IP segment consistent with the address information does not exist in the correspondence between the VPC identifier, the asset identifier, and the IP segment of the asset, and the address information is a subset of an IP segment (hereinafter referred to as a fifth target IP segment) in the correspondence, the asset represented by the asset identifier corresponding to the fifth target IP segment in the correspondence is determined as the first target node, and the connection relationship between the current node and the first target node is limited connection; if the fourth target IP segment consistent with the address information does not exist in the correspondence between the VPC identifier, the asset identifier, and the IP segment of the asset, and an IP segment (hereinafter referred to as a sixth target IP segment) in the correspondence is a subset of the address information, the address information is split to obtain the sixth target IP segment and other IP segments, the asset represented by the asset identifier corresponding to the sixth target IP segment in the correspondence is determined as the first target node, and the assets corresponding to the other IP segments (if no corresponding asset is found, the IP segment is used to represent) are also determined as the first target node; if none of the above conditions is met, the address information is determined as the first target node.

[0148] The following detailed description is made with respect to the above determining the first target node according to the address information, and the correspondence between the VPC identifier, the asset identifier, and the IP segment of the asset.

[0149] Specifically, when the address information in the current permission rule is a default gateway or a security group, the target processing strategy is determined as removing the first target node from the first network topology graph.

[0150] In the case that the address information in the current permission rule is an IP address or an IP prefix: if there is a fourth target IP segment consistent with the address information in the correspondence between the VPC identifier, the asset identifier, and the IP segment of the asset, or if there is no fourth target IP segment consistent with the address information in the correspondence, and the address information is a subset of an IP segment in the correspondence, it is determined that the target processing strategy is to remove the first target node from the first network topology graph; if there is no fourth target IP segment consistent with the address information in the correspondence between the VPC identifier, the asset identifier, and the IP segment of the asset, and an IP segment in the correspondence is a subset of the address information, the relationship between the current node and the first target node is modified to a limited connection.

[0151] In order to ensure the real-time accuracy of the target network topology graph, after the elastic public IP corresponding to the current node is added to the first network topology graph, if the elastic public IP corresponding to the current node is turned on cloud wall, the network topology graph after the elastic public IP corresponding to the current node is added is modified by using the strategy of the cloud wall. Specifically, in the case of generating the topology graph between the subnets in the VPC, before step 27, the target network topology graph is generated according to the connection relationship between the assets and the mapping relationship between the elastic public IP and the assets, which further includes:

[0152] If the elastic public IP corresponding to the current node is turned on cloud wall, the first network topology graph is modified according to the permission list of the cloud wall turned on by the elastic public IP corresponding to the current node.

[0153] At this time, step 27 includes: determining whether the newly added node based on the current node in the first network topology graph after modification is empty. That is, if the newly added node based on the current node in the first network topology graph after modification is not empty, the current node is removed from the target node set, and the newly added node is added to the target node set.

[0154] Among them, the first network topology graph can be modified according to the permission list of the cloud wall turned on by the elastic public IP corresponding to the current node in a manner similar to steps (f1) to (f5), and the difference is that if the address information in the current permission rule is the default gateway, the Internet node (abstract node) is determined as the first target node, rather than the VPC to which the cloud wall belongs existing between the target connection relationship is determined as the first target node.

[0155] In addition, the tenth network topology graph based on the related asset can be generated according to the connection relationship between the assets and the mapping relationship between the elastic public IP and the asset in a manner similar to the generation of the target network topology graph according to the connection relationship between the assets and the mapping relationship between the elastic public IP and the asset, and the disclosure will not be repeated.

[0156] In order to improve the accuracy of the target network topology graph, in the case of generating the topology graph between the subnets in the VPC, the access control list bound by each subnet in the target network topology graph can be used to correct the target network topology graph. Specifically, as shown in FIG. 6, before S102, the network security risk identification method can further include S103 and S104.

[0157] In S103, the target network topology graph is corrected according to the access control list bound by each subnet in the target network topology graph, and a second network topology graph is obtained.

[0158] In S104, if there is an elastic public network IP connected to both a subnet and a VPC to which the subnet belongs in the second network topology graph, the connection relationship between the elastic public network IP and the VPC is removed, and a third network topology graph is obtained.

[0159] In the present disclosure, if there is an elastic public network IP connected to both a subnet and a VPC to which the subnet belongs in the second network topology graph, in order to avoid relationship redundancy, only the connection relationship between the EIP and the subnet can be retained, that is, the connection relationship between the EIP and the VPC to which the subnet belongs needs to be deleted.

[0160] At this time, S102 can perform attack link analysis on the third network topology graph based on the business attributes and security characteristics of the assets in the third network topology graph.

[0161] The specific implementation of S103 will be described in detail below. Specifically, the following steps (g1) to (g5) can be used to achieve the above-mentioned S103:

[0162] Step (g1): For each subnet in the target network topology graph, the access control list of the subnet is sorted in order of priority from low to high to obtain a first access control list.

[0163] Step (g2): The permission rules with the same priority in the first access control list are arranged in the order of operation as rejection and operation as permission, and a second access control list is obtained.

[0164] Step (g3): Traverse the second access control list, and determine the second target node to be processed according to the type of address information in the current access control rule.

[0165] In the present disclosure, the current access control rule is an access control rule currently traversed in the second access control list. In addition, the second target node to be processed can be determined according to the type of the address information in the current access control rule in a manner similar to that in step (f3) described above, that is, according to the type of the address information in the current access control rule, the first target node to be processed is determined. The only difference is that if the address information in the current access control rule is the default gateway, the other subnets in the VPC to which the subnets belong, and the VPC to which the subnets belong are determined as the second target node.

[0166] Step (g4): When the operation in the current access control rule is accept, the connection relationship between the current node and the second target node is added to the target network topology graph according to the direction information in the current access control rule.

[0167] In the present disclosure, the direction information is out or in. When the direction information is in, the connection relationship between the current node and the second target node is from the second target node to the current node, indicating that the second target node can access the current node; when the direction information is out, the connection relationship between the current node and the second target node is from the current node to the second target node, indicating that the current node can access the second target node.

[0168] Step (g5): When the operation in the current access control rule is reject, the target processing strategy for the second target node is determined and executed according to at least the type of the address information in the current access control rule.

[0169] In the present disclosure, the target processing strategy for the second target node is one of the following: removing the second target node from the target network topology graph, and modifying the relationship between the current node and the second target node to limited connection.

[0170] In addition, the target processing strategy for the second target node can be determined according to at least the type of the address information in the current access control rule in a manner similar to that in step (f5) described above, that is, the target processing strategy for the first target node is determined according to at least the type of the address information in the current permission rule, and the present disclosure will not be described again.

[0171] In order to more accurately identify key risks, after the topology graph between the subnets in the VPC is constructed, it can be associated with the upper topology of the VPC. Specifically, when the topology graph between the subnets in the VPC is generated, the target object includes a VPC, as shown in FIG. 7, before the above S102, the above method can further include the following S105 and S106.

[0172] In S105, a fourth network topology graph based on the VPC is obtained.

[0173] In the present disclosure, the fourth network topology graph is used to represent the topology relationship between VPCs. Wherein, the fourth network topology graph based on the one VPC can be obtained in a similar manner as the S101 obtaining the target network topology graph based on the target object, and the present disclosure will not be repeated.

[0174] In S106, the fourth network topology graph is added to the target network topology graph to obtain a fifth network topology graph.

[0175] At this time, the S102 described above can perform attack link analysis on the fifth network topology graph based on the business attributes and security characteristics of the assets in the fifth network topology graph.

[0176] In addition to constructing the topology graph between VPCs or the topology graph between subnets in a VPC, a network card-based topology graph can also be constructed. Specifically, the target asset includes a network card, at this time, the target network topology graph representing the relationship between the target asset and other related assets can be generated according to the connection relationship between assets and assets, and the mapping relationship between the elastic public IP and the asset, through the following steps (h1) to (h3).

[0177] Step (h1): According to the mapping relationship between the elastic public IP and the asset, determine the elastic public IP corresponding to the network card.

[0178] Step (h2): Based on the network card and its corresponding elastic public IP, generate a sixth network topology graph.

[0179] Step (h3): According to the permission list of the security group associated with the network card, modify the sixth network topology graph to obtain the target network topology graph representing the relationship between the target asset and other related assets.

[0180] Specifically, the permission list of the security group associated with the network card can be sorted according to the priority from low to high to obtain a third permission list; then, the permission rules with the same priority in the third permission list are arranged according to the order of the operation as rejection and the operation as permission to obtain a fourth permission list; next, the fourth permission list is traversed, and according to the type of the address information in the current permission rule, a third target node to be processed is determined; when the operation in the current permission rule is acceptance, according to the direction information in the current permission rule, the connection relationship between the current node and the third target node is added to the sixth network topology graph to obtain a seventh network topology graph; when the operation in the current permission rule is rejection, at least according to the type of the address information in the current permission rule, a target processing strategy for the third target node is determined and executed, wherein the target processing strategy for the third target node is one of the following: removing the third target node from the sixth network topology graph, and modifying the relationship between the current node and the third target node to limited connection.

[0181] Wherein, the third target node to be processed can be determined according to the type of the address information in the current permission rule in a manner similar to that in step (f3) above, that is, according to the type of the address information in the current permission rule, the first target node to be processed is determined. The only difference is that if the address information in the current permission rule is the default gateway, the security group associated with the network card and the subnet where the network card is located are determined as the third target node.

[0182] In addition, the target processing strategy for the third target node can be determined at least according to the type of the address information in the current permission rule in a manner similar to that in step (f5) above, that is, at least according to the type of the address information in the current permission rule, the target processing strategy for the first target node is determined. The disclosure will not be repeated here.

[0183] In order to more accurately identify key risks, after constructing the network card-based topology graph, it can be associated with the subnet in the VPC where the network card is located. Specifically, when generating the network card-based topology graph, the target object includes the network card, and before step S102, the network security risk identification method can further include the following two steps:

[0184] Obtain a seventh network topology graph based on the VPC where the network card is located, wherein the seventh network topology graph is used to represent the topology relationship between the subnets in the VPC;

[0185] If there is an elastic public IP connected to both the network card and the subnet to which the network card belongs in the seventh network topology graph, remove the connection relationship between the elastic public IP and the subnet to which the network card belongs, and obtain an eighth network topology graph;

[0186] At this time, step S102 can perform attack link analysis on the eighth network topology graph based on the business attributes and security characteristics of the assets in the eighth network topology graph.

[0187] In the present disclosure, when there is an elastic public IP connected to both the network card and the subnet to which the network card belongs in the seventh network topology graph, in order to avoid relationship redundancy, only the connection relationship between the EIP and the network card can be retained, that is, the connection relationship between the EIP and the subnet to which the network card belongs needs to be deleted.

[0188] In addition to constructing the topology graph between VPCs, the topology graph between subnets in a VPC, and the network card-based topology graph, a ECS or container-based topology graph can also be constructed. At this time, according to the connection relationship between assets and assets, and the mapping relationship between elastic public IP and assets, a target network topology graph representing the relationship between the target asset and other related assets can be generated through the following two steps:

[0189] First, determine the target network card bound to the elastic computing service or the container;

[0190] Then, a ninth network topology graph based on the target network card is acquired as the target network topology graph.

[0191] In the present disclosure, the ninth network topology graph based on the target network card can be acquired in a similar manner as the acquisition of the target network topology graph based on the network card, and the present disclosure will not be repeated.

[0192] The following describes a specific implementation of the attack link analysis on the target network topology graph based on the business attributes and security characteristics of the assets in the target network topology graph in S102.

[0193] In an implementation, the target object includes a target asset, and at this time, a risk asset with public network exposure in the target network topology graph can be identified first, wherein an asset in the target network topology graph that has a direct connection relationship with an EIP can be determined as the risk asset with public network exposure; if the risk asset does not belong to a core asset and the risk asset satisfies any one of the first preset conditions, it is determined whether the risk asset can move horizontally to the core asset; if the risk asset can move horizontally to the core asset, the risk asset is determined as a security risk; and if the risk asset cannot move horizontally to the core asset, it is indicated that the risk asset does not belong to the security risk.

[0194] If the risk asset does not belong to the core asset and the risk asset satisfies any one of the second preset conditions, the risk asset is determined as the security risk.

[0195] If the risk asset belongs to the core asset and the risk asset satisfies any one of the third preset conditions, the risk asset is determined as the security risk.

[0196] In the present disclosure, the first preset conditions can include any one of a high-risk exploitable vulnerability, a malicious file / Web Shell, a weak password, a brute force attack, a dictionary attack, and a remote login.

[0197] For example, if there is a public network exposed VM / container in the target network topology graph, and the public network exposed VM / container has a high-risk exploitable vulnerability and can move laterally to the core asset, the public network exposed VM / container is determined as a security risk; if there is a public network exposed VM / container in the target network topology graph, and the public network exposed VM / container has a malicious file / Web Shell and can move laterally to the core asset, the public network exposed VM / container is determined as a security risk; if there is a public network exposed VM / container in the target network topology graph, and the public network exposed VM / container has a weak password, brute force cracking, dictionary attack, remote login, etc., and can move laterally to the core asset, the public network exposed VM / container is determined as a security risk; if there is a public network exposed VM / container in the target network topology graph, and the public network exposed VM / container has suspicious port listening and can move laterally to the core asset, the public network exposed VM / container is determined as a security risk.

[0198] The second preset condition can include that the resource code of the risk asset contains an access credential, and the access permission corresponding to the access credential can access the core asset; the risk asset has an access key call, and the access key involves the core asset.

[0199] For example, if there is a public network exposed VM / container in the target network topology graph, and the resource code of the public network exposed VM / container contains AK plaintext or SK plaintext, and the access permission corresponding to the AK plaintext or SK plaintext can access the core asset, the public network exposed VM / container is determined as a security risk; if there is a public network exposed VM / container in the target network topology graph, and there is an access key call, and the access key involves the core asset, the public network exposed VM / container is determined as a security risk.

[0200] In addition, if the VM / container has an alarm of the host and can move laterally to the core asset, the VM / container is determined as a security risk.

[0201] The third preset condition can include any one of a high-risk exploitable vulnerability or a high-risk vulnerability, a malicious file / Web Shell, a weak password, brute force cracking, dictionary attack, remote login, and suspicious port listening.

[0202] In another implementation, the target object includes a target resource or a target identity, at this time, the target network topology graph can be analyzed based on the business attribute and security characteristics of the asset in the target network topology graph and the secret leakage of the identity in the target network topology graph to identify the security risk in the target network topology graph.

[0203] Specifically, in a similar manner as in the above embodiments, the target network topology graph can be analyzed based on the business attributes and security characteristics of the assets in the target network topology graph to identify key nodes in the target network topology graph; meanwhile, based on the secret leakage, the security risks in the target network topology graph can be further identified.

[0204] In this regard, the security risks in the target network topology graph can be identified based on the secret leakage in the following manner:

[0205] If the core asset has a public network opening (the CSPM influence range is public network access, and the asset is a core asset), and has a CSM risk of excessive authority influence range, the core asset is determined as a security risk.

[0206] If the leaked AK can access the core asset, the leaked AK is determined as a security risk.

[0207] If an account with a secret leakage risk (for example, anonymous access, weak password, unauthorized access, and all CSPM risks with an influence range of secret leakage) can access the core asset, the account with abnormal behavior is determined as a security risk.

[0208] If the account with abnormal behavior can access the core asset, the account with abnormal behavior is determined as a security risk.

[0209] If there is an identity entity that can access the core asset, the identity entity is determined as a security risk.

[0210] In addition, the above method can further include the following steps:

[0211] In response to receiving a security risk identification request, a target object is determined based on the security risk identification request, wherein the security risk identification request includes the target object.

[0212] FIG. 8 is a block diagram of a network security risk identification apparatus according to an exemplary embodiment. As shown in FIG. 8, the apparatus 700 includes:

[0213] A first acquisition module 701 is configured to acquire a target network topology graph based on a target object, wherein the target network topology graph is used to represent the relationship between the target object and its related assets.

[0214] A link analysis module 702 is configured to analyze the target network topology graph based on the business attributes and security characteristics of the assets in the target network topology graph to identify security risks in the target network topology graph.

[0215] In the technical solution, a target network topology graph based on a target object is obtained, and then, based on the business attributes and security characteristics of assets in the target network topology graph, attack link analysis is performed on the target network topology graph to identify security risks in the target network topology graph. In this way, the network topology graph can be used to combine the risks and the business attributes and security characteristics of assets in the network topology graph, and attack link analysis can be performed based on the perspective of an attacker, so that key risks can be more accurately identified, the number of business repair risks can be reduced, the risks that can cause the most asset loss can be focused on, the continuity of key business processes can be ensured, and business interruption caused by security problems can be reduced. In addition, through automatic attack link analysis, potential security threats can be quickly identified, so that rapid response and repair can be performed, and the impact of security events on business can be reduced. Furthermore, only a target network topology graph related to a target object can be generated, rather than a network topology graph of the entire business system, so that multi-layer topology effects can be achieved using less storage space, key risk identification can be targeted, and through the target network topology graph, risk repair personnel can clearly see the asset loss caused by not repairing, which increases the repair motivation of the risk repair personnel.

[0216] Optionally, the target object includes one of an asset, an identity, and a resource.

[0217] Optionally, the resource includes a database.

[0218] The asset includes at least one of a virtual private cloud (VPC), a subnet, a network card, elastic computing service, and a container.

[0219] Optionally, the business attribute is used to represent whether the corresponding asset is a core asset, and the security characteristic includes public network exposure and horizontal movement, where the core asset is an asset that meets a preset condition.

[0220] Optionally, the target object includes a target asset.

[0221] The first obtaining module 701 is configured to generate the target network topology graph representing the relationship between the target asset and other related assets according to the connection relationship between assets and the mapping relationship between an elastic public network IP and assets.

[0222] Optionally, the target asset includes at least one virtual private cloud (VPC).

[0223] The first obtaining module 701 includes:

[0224] a first determining sub-module, configured to take a first node in a target sequence as a current node, wherein the target sequence is constituted by the at least one VPC when a topology graph between VPCs is generated, and the target sequence is constituted by subnets in one VPC when a topology graph between subnets in a VPC is generated;

[0225] a first adding sub-module, configured to determine whether the current node exists in a first network topology graph, if not, add assets and elastic public network IP related to the current node into the first network topology graph according to a connection relationship between assets and assets and a mapping relationship between the elastic public network IP and the assets, and then trigger a second determining sub-module to run, if yes, directly trigger the second determining sub-module to run, wherein the first network topology graph is initially empty;

[0226] a second determining sub-module, configured to determine whether the current node has a next node, if yes, take the next node of the current node in the target sequence as the current node, and trigger the first adding sub-module to run, if not, determine the first network topology graph as the target network topology graph.

[0227] Optionally, the first adding sub-module comprises:

[0228] a second adding sub-module, configured to add the current node into a target node set, wherein the target node set is initially empty;

[0229] a third determining sub-module, configured to determine a target connection relationship related to the current node according to the connection relationship between assets and assets, wherein the target connection relationship is used to represent a relationship between the current node and assets of the same type as the current node;

[0230] a third adding sub-module, configured to add the target connection relationship into the first network topology graph;

[0231] a fourth adding sub-module, configured to add a corresponding relationship between the corresponding elastic public network IP and the current node into the first network topology graph if the corresponding elastic public network IP corresponding to the current node exists in the mapping relationship between the elastic public network IP and the assets;

[0232] a fifth adding sub-module, configured to remove the current node from the target node set and add a new node based on the current node in the first network topology graph into the target node set if the new node is not empty, wherein the new node does not include an elastic public network IP;

[0233] The triggering submodule is configured to, for each of the added nodes in the target node set, take the added node as a current node, and trigger the third determining submodule until each of the added nodes in the target node set is empty.

[0234] Optionally, the first joining submodule further includes:

[0235] The first correcting submodule is configured to, before the fourth joining submodule performs the step of adding the corresponding relationship between the corresponding elastic public network IP and the current node to the first network topology graph, if the target connection relationship is a cross-VPC relationship and there is a cloud wall between the target connection relationship, correct the first network topology graph based on a permission list of the cloud wall.

[0236] The fourth joining submodule is configured to, if there is a corresponding elastic public network IP corresponding to the current node in the mapping relationship between the elastic public network IP and the asset, add the corresponding relationship between the corresponding elastic public network IP and the current node to the first network topology graph obtained after correction.

[0237] Optionally, the first correcting submodule includes:

[0238] The first sorting submodule is configured to sort the permission list of the cloud wall according to priorities from low to high to obtain a first permission list.

[0239] The second sorting submodule is configured to arrange permission rules with the same priority in the first permission list according to the order of operation as rejection and operation as permission to obtain a second permission list.

[0240] The traversing submodule is configured to traverse the second permission list, and determine a first target node to be processed according to the type of address information in a current permission rule, wherein the current permission rule is a permission rule currently traversed in the second permission list.

[0241] The sixth joining submodule is configured to, when the operation in the current permission rule is acceptance, add a connection relationship between the current node and the first target node to the first network topology graph according to the direction information in the current permission rule.

[0242] The execution submodule is configured to, when the operation in the current permission rule is rejection, determine and execute a target processing strategy for the first target node according to at least the type of the address information, wherein the target processing strategy is one of the following: removing the first target node from the first network topology graph, and modifying the relationship between the current node and the first target node to limited connection.

[0243] Optionally, the traversal submodule comprises:

[0244] The fourth determination submodule is configured to, if the address information in the current permission rule is a default gateway, determine the VPC to which the cloud wall belongs as the first target node.

[0245] The fifth determination submodule is configured to, if the address information is a security group, determine the address information as the first target node.

[0246] The sixth determination submodule is configured to, if the address information is an IP address or an IP prefix, determine the first target node according to the address information and a pre-constructed correspondence relationship between VPC identifiers, asset identifiers and IP segments of assets.

[0247] Optionally, in the case of generating a topology graph between subnets in a VPC, the first adding submodule further comprises:

[0248] The second correction submodule is configured to, before the step of, if the newly added node based on the current node in the first network topology graph is not empty, removing the current node from the target node set and adding the newly added node to the target node set, if the corresponding elastic public IP of the current node enables a cloud wall, correct the first network topology graph according to a permission list of the cloud wall enabled by the corresponding elastic public IP.

[0249] The fifth adding submodule is configured to, if the newly added node based on the current node in the first network topology graph after correction is not empty, remove the current node from the target node set and add the newly added node to the target node set.

[0250] Optionally, in the case of generating a topology graph between subnets in a VPC, the device 700 further comprises:

[0251] The correction module is configured to, before the attack link analysis of the target network topology graph by the link analysis module 702 based on the business attributes and security characteristics of assets in the target network topology graph, correct the target network topology graph according to the access control lists bound by each subnet in the target network topology graph, to obtain a second network topology graph.

[0252] The first removing module is configured to remove a connection relationship between a simultaneously connected elastic public IP and a VPC to which a subnet belongs if the simultaneously connected elastic public IP exists in the second network topology graph and is connected to the subnet and the VPC to which the subnet belongs, to obtain a third network topology graph.

[0253] The link analysis module 702 is configured to perform attack link analysis on the third network topology graph based on the business attributes and security characteristics of the assets in the third network topology graph.

[0254] Optionally, when the topology graph between the subnets in the VPC is generated, the target object includes one VPC.

[0255] The apparatus 700 further includes:

[0256] The second obtaining module is configured to obtain a fourth network topology graph based on the one VPC before the link analysis module 702 performs attack link analysis on the target network topology graph based on the business attributes and security characteristics of the assets in the target network topology graph, where the fourth network topology graph is used to represent the topology relationship between the VPCs.

[0257] The joining module is configured to join the fourth network topology graph to the target network topology graph to obtain a fifth network topology graph.

[0258] The link analysis module 702 is configured to perform attack link analysis on the fifth network topology graph based on the business attributes and security characteristics of the assets in the fifth network topology graph.

[0259] Optionally, the target asset includes a network card.

[0260] The first obtaining module 701 includes:

[0261] The seventh determining submodule is configured to determine an elastic public IP corresponding to the network card according to the mapping relationship between the elastic public IP and the asset.

[0262] The generating submodule is configured to generate a sixth network topology graph based on the network card and the elastic public IP corresponding to the network card.

[0263] The third correcting submodule is configured to correct the sixth network topology graph according to the permission list of the security group associated with the network card to obtain the target network topology graph representing the relationship between the target asset and other related assets.

[0264] Optionally, the target object includes a network card.

[0265] The apparatus 700 further includes:

[0266] The third obtaining module is configured to, before the link analysis module 702 performs attack link analysis on the target network topology graph based on the business attributes and the security characteristics of assets in the target network topology graph, obtain a seventh network topology graph based on a VPC in which the network card is located, where the seventh network topology graph is used to represent a topology relationship between subnets in the VPC.

[0267] The second removing module is configured to, if there is an elastic public network IP that is simultaneously connected to the network card and a subnet to which the network card belongs in the seventh network topology graph, remove a connection relationship between the simultaneously connected elastic public network IP and the subnet to which the network card belongs, to obtain an eighth network topology graph.

[0268] The link analysis module 702 is configured to perform attack link analysis on the eighth network topology graph based on the business attributes and the security characteristics of assets in the eighth network topology graph.

[0269] Optionally, the target asset includes an elastic computing service or a container.

[0270] The first obtaining module 701 includes:

[0271] An eighth determining submodule is configured to determine a target network card bound to the elastic computing service or the container.

[0272] A first obtaining submodule is configured to obtain a ninth network topology graph based on the target network card as the target network topology graph.

[0273] Optionally, the target object includes a target asset.

[0274] The business attribute is used to represent whether a corresponding asset belongs to a core asset, and the security characteristic includes public network exposure and horizontal movement.

[0275] The link analysis module 702 includes:

[0276] An identifying submodule is configured to identify a risk asset that has public network exposure in the target network topology graph.

[0277] A ninth determining submodule is configured to determine whether the risk asset can move horizontally to the core asset if the risk asset does not belong to the core asset and the risk asset satisfies any one of first preset conditions.

[0278] A tenth determining submodule is configured to determine the risk asset as a security risk if the risk asset can move horizontally to the core asset.

[0279] Optionally, the link analysis module 702 further includes:

[0280] The eleventh determination sub-module is configured to determine the risk asset as a security risk if the risk asset does not belong to the core asset and the risk asset satisfies any one of the second preset conditions.

[0281] The second preset conditions include that:

[0282] The risk asset contains an access credential in a resource code of the risk asset, and an access permission corresponding to the access credential can access the core asset.

[0283] The risk asset has an access key call, and the access key is related to the core asset.

[0284] Optionally, the link analysis module 702 further includes:

[0285] The risk asset is determined as a security risk if the risk asset belongs to the core asset and the risk asset satisfies any one of the third preset conditions.

[0286] Optionally, the target object includes a target resource or a target identity.

[0287] The first acquisition module 701 includes:

[0288] The second acquisition sub-module is configured to acquire a permission topology graph based on the target object, wherein the permission topology graph is used to represent the relationship between identities and resources.

[0289] The twelfth determination sub-module is configured to determine a related asset of a resource in the permission topology graph based on a pre-constructed corresponding relationship between assets and resources.

[0290] The third acquisition sub-module is configured to acquire a tenth network topology graph based on the related asset.

[0291] The sixth joining sub-module is configured to join the tenth network topology graph into the permission topology graph to obtain the target network topology graph.

[0292] Optionally, the link analysis module 702 is configured to perform attack link analysis on the target network topology graph based on a business attribute and a security characteristic of an asset in the target network topology graph and a secret leakage of an identity in the target network topology graph.

[0293] In addition, the present disclosure also provides a computer readable medium having a computer program stored thereon, and the computer program is executed by a processing device to implement the steps of the above network security risk identification method provided by the present disclosure.

[0294] In addition, the present disclosure also provides a computer readable medium having a computer program stored thereon, and the computer program is executed by a processing device to implement the steps of the above network security risk identification method provided by the present disclosure.

[0295] Reference is now made to FIG. 9, which shows a structural diagram of an electronic device (terminal device or server) 600 suitable for implementing embodiments of the present disclosure. The terminal device in embodiments of the present disclosure can include, but is not limited to, a mobile terminal such as a mobile phone, a notebook computer, a digital broadcast receiver, a PDA (Personal Digital Assistant), a PAD (Tablet Personal Computer), a PMP (Portable Multimedia Player), a car terminal (e.g., a car navigation terminal), and the like, as well as a stationary terminal such as a digital TV, a desktop computer, and the like. The electronic device shown in FIG. 9 is merely an example and should not impose any limitation on the functions and use range of embodiments of the present disclosure.

[0296] As shown in FIG. 9, the electronic device 600 can include a processing device (e.g., a central processor, a graphic processor, etc.) 601, which can perform various appropriate actions and processes according to programs stored in a read-only memory (ROM) 602 or loaded into a random access memory (RAM) 603 from a storage device 608. In the RAM 603, various programs and data required for the operation of the electronic device 600 are also stored. The processing device 601, the ROM 602, and the RAM 603 are connected to each other through a bus 604. An input / output (I / O) interface 605 is also connected to the bus 604.

[0297] Generally, the following devices can be connected to the I / O interface 605: an input device 606 including, for example, a touch screen, a touch pad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, and the like; an output device 607 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, and the like; a storage device 608 including, for example, a magnetic tape, a hard disk, and the like; and a communication device 609. The communication device 609 can allow the electronic device 600 to communicate with other devices wirelessly or via wires to exchange data. Although FIG. 9 shows the electronic device 600 having various devices, it should be understood that all of the shown devices are not required to be implemented or possessed. More or fewer devices can be alternatively implemented or possessed.

[0298] In particular, according to embodiments of the present disclosure, the processes described above with reference to the flowcharts can be implemented as a computer software program. For example, embodiments of the present disclosure include a computer program product including a computer program carried on a non-transitory computer readable medium, the computer program containing program code for executing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network through the communication device 609, or installed from the storage device 608, or installed from the ROM 602. When the computer program is executed by the processing device 601, the above-described functions defined in the methods of embodiments of the present disclosure are performed.

[0299] It should be noted that the computer-readable medium described above can be a computer-readable signal medium or a computer-readable storage medium or any combination thereof. The computer-readable storage medium can be, for example, but not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus or device, or any suitable combination of the above. More specific examples of the computer-readable storage medium can include, but are not limited to, an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present disclosure, the computer-readable storage medium can be any tangible medium that contains or stores a program used by or in connection with an instruction execution system, apparatus or device. In the present disclosure, the computer-readable signal medium can include a data signal propagated in baseband or propagated as a carrier wave in a propagated data signal, in which the computer-readable program code is contained. Such a propagated data signal can take many forms, including but not limited to, an electromagnetic signal, an optical signal, or any suitable combination of the above. The computer-readable signal medium can also be any computer-readable medium that can send, propagate or transfer the program for use by or in connection with the instruction execution system, apparatus or device. The program code contained in the computer-readable medium can be transmitted by any suitable medium, including but not limited to, wire, cable, RF (radio frequency), etc., or any suitable combination of the above.

[0300] In some embodiments, the client, server, or both can communicate using any current known or future developed network protocol, such as HTTP (HyperText Transfer Protocol), and can be interconnected with any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include local area networks ("LAN"), wide area networks ("WAN"), the Internet, and peer-to-peer networks (e.g., ad hoc peer-to-peer networks), as well as any current known or future developed networks.

[0301] The computer-readable medium described above can be included in the electronic device described above; or can exist separately from the electronic device, and is not assembled into the electronic device.

[0302] The computer readable medium described above carries one or more programs, when the one or more programs are executed by the electronic device, cause the electronic device to: acquire a target network topology graph based on a target object, wherein the target network topology graph is used to represent a relationship between the target object and its related assets; and perform attack link analysis on the target network topology graph based on a business attribute and a security characteristic of an asset in the target network topology graph, to identify a security risk in the target network topology graph.

[0303] Computer program code for carrying out operations of the present disclosure can be written in any one or more of a variety of programming languages or combinations thereof, including an object oriented programming language such as Java, Smalltalk, C++, or a conventional procedural programming language such as the "C" programming language or similar programming languages. The program code can execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer, or entirely on the remote computer or server. In the latter scenario, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection can be made to an external computer (for example, through the Internet using an Internet Service Provider).

[0304] The flow diagrams and the block diagrams in the drawings are illustrations of architectures, functionalities, and operations of possible implementations of systems, methods, and computer program products according to various embodiments of present disclosure. In this regard, each block in the flow diagrams or block diagrams can represent a module, a segment, or a portion of code, which comprises one or more executable instructions for implementing the specified logical functions. It should also be noted that in some alternative implementations, the functions noted in the blocks can occur out of the order noted in the figures. For example, two blocks shown in succession may, in fact, be executed substantially concurrently or the blocks may sometimes be executed in the reverse order, depending upon the functionality involved. It will also be noted that each block of the block diagrams and / or flow diagrams, and combinations thereof, can be implemented by special purpose hardware-based systems that perform the specified functions or operations, or combinations of special purpose hardware and computer instructions.

[0305] The modules described in the embodiments of the present disclosure can be implemented by software, or by hardware. In some cases, the name of a module does not constitute a limitation on the module itself. For example, a first obtaining module can also be described as an "obtaining a target network topology graph based on a target object module".

[0306] The functionality described herein above can be performed, at least in part, by one or more hardware logic components. For example, and without limitation, an example type of hardware logic components that can be used include Field-programmable Gate Arrays (FPGAs), Application-specific Integrated Circuits (ASICs), Application-specific Standard Products (ASSPs), System-on-a-chip systems (SOCs), Complex Programmable Logic Devices (CPLDs), etc.

[0307] In the context of the present disclosure, a machine-readable medium can be a tangible medium that contains or stores a program for use by or in connection with an instruction execution system, apparatus, or device. The machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of the machine-readable storage medium will include one or more lines of electrical connections, portable computer disks, hard disk drives, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or Flash memory), optical fibers, portable compact disc read-only memories (CD-ROMs), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.

[0308] According to one or more embodiments of the present disclosure, example 1 provides a network security risk identification method, comprising: obtaining a target network topology graph based on a target object, wherein the target network topology graph is used to represent the relationship between the target object and its related assets; based on the business attribute and security characteristic of the asset in the target network topology graph, performing attack link analysis on the target network topology graph to identify the security risk in the target network topology graph.

[0309] According to one or more embodiments of the present disclosure, example 2 provides the method of example 1, wherein the target object comprises one of an asset, an identity, and a resource; wherein the resource comprises a database; and wherein the asset comprises at least one of a virtual private cloud (VPC), a subnet, a network card, an elastic computing service, and a container.

[0310] According to one or more embodiments of the present disclosure, example 3 provides the method of example 1, wherein the business attribute is used to represent whether the corresponding asset belongs to a core asset, and the security characteristic comprises public network exposure and horizontal movement, wherein the core asset is an asset that meets a preset condition.

[0311] According to one or more embodiments of the present disclosure, example 4 provides the method of example 1, wherein the target object comprises a target asset; and the obtaining the target network topology graph based on the target object comprises: generating the target network topology graph representing relationships between the target asset and other related assets according to connection relationships between assets and assets and mapping relationships between elastic public network IPs and assets.

[0312] According to one or more embodiments of the present disclosure, example 5 provides the method of example 4, wherein the target asset comprises at least one virtual private cloud (VPC); and the generating the target network topology graph according to the connection relationships between assets and assets and the mapping relationships between elastic public network IPs and assets comprises: the generating the target network topology graph representing relationships between the target asset and other related assets according to the connection relationships between assets and assets and the mapping relationships between elastic public network IPs and assets comprises: step 1, taking a first node in a target sequence as a current node, wherein the target sequence is composed of the at least one VPC when generating an inter-VPC topology graph, and the target asset comprises a VPC when generating an intra-VPC topology graph, and the target sequence is composed of subnets in the VPC; step 2, determining whether the current node exists in a first network topology graph, if not, adding assets and elastic public network IPs related to the current node to the first network topology graph according to the connection relationships between assets and assets and the mapping relationships between elastic public network IPs and assets, and then performing step 3, if yes, directly performing step 3, wherein the first network topology graph is initially empty; and step 3, determining whether the current node has a next node, if yes, taking a next node of the current node in the target sequence as the current node and returning to step 2, if not, determining the first network topology graph as the target network topology graph.

[0313] According to one or more embodiments of the present disclosure, example 6 provides the method of example 5, wherein the adding the asset and the elastic public network IP related to the current node into the first network topology graph according to the connection relationship between the asset and the asset and the mapping relationship between the elastic public network IP and the asset comprises: step 21, adding the current node into a target node set, wherein the target node set is initially empty; step 22, determining a target connection relationship related to the current node according to the connection relationship between the asset and the asset, wherein the target connection relationship is used to represent the relationship between the current node and its same-type asset; step 23, adding the target connection relationship into the first network topology graph; step 24, if there is an elastic public network IP corresponding to the current node in the mapping relationship between the elastic public network IP and the asset, then adding the corresponding relationship between the corresponding elastic public network IP and the current node into the first network topology graph; step 25, if the newly added node based on the current node in the first network topology graph is not empty, then removing the current node from the target node set and adding the newly added node into the target node set, wherein the newly added node does not include an elastic public network IP; step 26, for each newly added node in the target node set, taking the newly added node as the current node and repeating the steps 22-26 until each node in the target node set has no newly added node.

[0314] According to one or more embodiments of the present disclosure, example 7 provides the method of example 6, wherein before the step of adding the corresponding relationship between the corresponding elastic public network IP and the current node into the first network topology graph if there is an elastic public network IP corresponding to the current node in the mapping relationship between the elastic public network IP and the asset, the adding the asset and the elastic public network IP related to the current node into the first network topology graph according to the connection relationship between the asset and the asset and the mapping relationship between the elastic public network IP and the asset further comprises: if the target connection relationship is a cross-VPC relationship and there is a cloud wall between the target connection relationships, then modifying the first network topology graph based on the permission list of the cloud wall; and wherein the step of adding the corresponding relationship between the corresponding elastic public network IP and the current node into the first network topology graph if there is an elastic public network IP corresponding to the current node in the mapping relationship between the elastic public network IP and the asset comprises: if there is an elastic public network IP corresponding to the current node in the mapping relationship between the elastic public network IP and the asset, then adding the corresponding relationship between the corresponding elastic public network IP and the current node into the first network topology graph obtained after the modification.

[0315] According to one or more embodiments of the present disclosure, example 8 provides the method of example 7, wherein the modifying the first network topology graph based on the permission list of the cloud wall comprises: sorting the permission list of the cloud wall according to priority from low to high to obtain a first permission list; arranging permission rules with the same priority in the first permission list according to the order of operation as rejection and operation as permission to obtain a second permission list; traversing the second permission list, and determining a first target node to be processed according to the type of address information in a current permission rule, wherein the current permission rule is a permission rule currently traversed in the second permission list; when the operation in the current permission rule is acceptance, adding a connection relationship between the current node and the first target node in the first network topology graph according to the direction information in the current permission rule; when the operation in the current permission rule is rejection, determining and executing a target processing strategy for the first target node according to at least the type of address information, wherein the target processing strategy is one of the following: removing the first target node from the first network topology graph, and modifying the relationship between the current node and the first target node to limited connection.

[0316] According to one or more embodiments of the present disclosure, example 9 provides the method of example 8, wherein the determining the first target node to be processed according to the type of address information in the current permission rule comprises: if the address information in the current permission rule is a default gateway, determining the VPC to which the cloud wall belongs as the first target node; if the address information is a security group, determining the address information as the first target node; and if the address information is an IP address or an IP prefix, determining the first target node according to the address information, and a pre-constructed correspondence relationship between VPC identifiers, asset identifiers, and IP segments of assets.

[0317] According to one or more embodiments of the present disclosure, example 10 provides the method of example 6, in the case of generating a topology graph between subnets in a VPC, before the step of removing the current node from the target node set and adding the new node based on the current node in the first network topology graph to the target node set if the new node is not empty, and adding the assets and elastic public IP related to the current node to the first network topology graph according to the connection relationship between the assets and the assets, and the mapping relationship between the elastic public IP and the assets, further comprising: if the elastic public IP corresponding to the current node is turned on cloud wall, then according to the permission list of the cloud wall opened by the corresponding elastic public IP, the first network topology graph is corrected; if the new node based on the current node in the first network topology graph is not empty, then remove the current node from the target node set and add the new node to the target node set, including: if the new node based on the current node in the first network topology graph after correction is not empty, then remove the current node from the target node set and add the new node to the target node set.

[0318] According to one or more embodiments of the present disclosure, example 11 provides the method of example 1, in the case of generating a topology graph between subnets in a VPC, before the step of performing attack link analysis on the target network topology graph based on the business attributes and security characteristics of the assets in the target network topology graph, the method further comprises: correcting the target network topology graph according to the access control list bound by each subnet in the target network topology graph to obtain a second network topology graph; if there is an elastic public IP connected to a subnet and the VPC to which the subnet belongs in the second network topology graph, remove the connection relationship between the simultaneously connected elastic public IP and the VPC to which the subnet belongs, and obtain a third network topology graph; the step of performing attack link analysis on the target network topology graph based on the business attributes and security characteristics of the assets in the target network topology graph, including: performing attack link analysis on the third network topology graph based on the business attributes and security characteristics of the assets in the third network topology graph.

[0319] According to one or more embodiments of the present disclosure, example 12 provides the method of example 1, when generating the topology graph between subnets in the VPC, the target object includes one VPC; before the step of performing attack link analysis on the target network topology graph based on the business attributes and security characteristics of the assets in the target network topology graph, the method further comprises: obtaining a fourth network topology graph based on the one VPC, wherein the fourth network topology graph is used to represent the topology relationship between VPCs; adding the fourth network topology graph to the target network topology graph to obtain a fifth network topology graph; and performing attack link analysis on the target network topology graph based on the business attributes and security characteristics of the assets in the target network topology graph comprises: performing attack link analysis on the fifth network topology graph based on the business attributes and security characteristics of the assets in the fifth network topology graph.

[0320] According to one or more embodiments of the present disclosure, example 13 provides the method of example 4, the target asset includes a network card; and the step of generating the target network topology graph representing the relationship between the target asset and other related assets according to the connection relationship between assets and assets and the mapping relationship between the elastic public IP and the assets comprises: determining the elastic public IP corresponding to the network card according to the mapping relationship between the elastic public IP and the assets; generating a sixth network topology graph based on the network card and the elastic public IP corresponding to the network card; and correcting the sixth network topology graph according to the permission list of the security group associated with the network card to obtain the target network topology graph representing the relationship between the target asset and other related assets.

[0321] According to one or more embodiments of the present disclosure, example 14 provides the method of example 1, the target object includes a network card; before the step of performing attack link analysis on the target network topology graph based on the business attributes and security characteristics of the assets in the target network topology graph, the method further comprises: obtaining a seventh network topology graph based on the VPC in which the network card is located, wherein the seventh network topology graph is used to represent the topology relationship between subnets in the VPC; if there is an elastic public IP simultaneously connected with the network card and the subnet to which the network card belongs in the seventh network topology graph, removing the connection relationship between the simultaneously connected elastic public IP and the subnet to which the network card belongs to obtain an eighth network topology graph; and the step of performing attack link analysis on the target network topology graph based on the business attributes and security characteristics of the assets in the target network topology graph comprises: performing attack link analysis on the eighth network topology graph based on the business attributes and security characteristics of the assets in the eighth network topology graph.

[0322] According to one or more embodiments of the present disclosure, example 15 provides the method of example 4, wherein the target asset comprises an elastic computing service or a container; and the generating the target network topology graph representing the relationship between the target asset and other related assets according to the connection relationship between assets and the mapping relationship between the elastic public network IP and the assets comprises: determining a target network card bound by the elastic computing service or the container; and obtaining a ninth network topology graph based on the target network card as the target network topology graph. According to one or more embodiments of the present disclosure, example 16 provides the method of example 1, wherein the target object comprises a target asset; the business attribute is used to represent whether the corresponding asset belongs to a core asset, and the security feature comprises public network exposure and horizontal movement; and the performing attack link analysis on the target network topology graph based on the business attribute and the security feature of the asset in the target network topology graph to identify a security risk in the target network topology graph comprises: identifying a risk asset with public network exposure in the target network topology graph; and determining whether the risk asset can move horizontally to the core asset if the risk asset does not belong to the core asset and satisfies any one of the first preset conditions; and determining the risk asset as a security risk if the risk asset can move horizontally to the core asset.

[0323] According to one or more embodiments of the present disclosure, example 17 provides the method of example 16, wherein the performing attack link analysis on the target network topology graph based on the business attribute and the security feature of the asset in the target network topology graph to identify a security risk in the target network topology graph further comprises: determining the risk asset as a security risk if the risk asset does not belong to the core asset and satisfies any one of the second preset conditions; and wherein the second preset conditions comprise: the resource code of the risk asset contains access credentials, and the access permissions corresponding to the access credentials can access the core asset; and the risk asset has access key calls, and the access key involves the core asset.

[0324] According to one or more embodiments of the present disclosure, example 18 provides the method of example 16, wherein the performing attack link analysis on the target network topology graph based on the business attribute and the security feature of the asset in the target network topology graph to identify a security risk in the target network topology graph further comprises: determining the risk asset as a security risk if the risk asset belongs to the core asset and satisfies any one of the third preset conditions.

[0325] According to one or more embodiments of the present disclosure, example 19 provides the method of example 1, the target object includes a target resource or a target identity; the obtaining the target network topology graph based on the target object includes: obtaining a permission topology graph based on the target object, wherein the permission topology graph is used to represent the relationship between the identity and the resource; determining a related asset of the resource in the permission topology graph based on a pre-constructed corresponding relationship between the asset and the resource; obtaining a tenth network topology graph based on the related asset; and adding the tenth network topology graph to the permission topology graph to obtain the target network topology graph.

[0326] According to one or more embodiments of the present disclosure, example 20 provides the method of example 19, the attack link analysis on the target network topology graph based on the business attribute and the security characteristic of the asset in the target network topology graph includes: performing attack link analysis on the target network topology graph based on the business attribute and the security characteristic of the asset in the target network topology graph, and a secret leakage of the identity in the target network topology graph.

[0327] According to one or more embodiments of the present disclosure, example 21 provides the method of example 1, in response to receiving a security risk identification request, determining the target object based on the security risk identification request, wherein the security risk identification request includes the target object.

[0328] According to one or more embodiments of the present disclosure, example 22 provides a network security risk identification device, comprising: a first obtaining module configured to obtain a target network topology graph based on a target object, wherein the target network topology graph is used to represent the relationship between the target object and its related asset; and a link analysis module configured to perform attack link analysis on the target network topology graph based on the business attribute and the security characteristic of the asset in the target network topology graph, to identify the security risk in the target network topology graph.

[0329] According to one or more embodiments of the present disclosure, example 23 provides a computer readable medium having a computer program stored thereon, the computer program being executed by a processing device to implement the steps of the method of any one of examples 1-21.

[0330] According to one or more embodiments of the present disclosure, example 24 provides an electronic device, comprising:

[0331] a storage device having a computer program stored thereon; and a processing device configured to execute the computer program in the storage device to implement the steps of the method of any one of examples 1-21.

[0332] According to one or more embodiments of the present disclosure, example 25 provides a computer program product including a computer program that, when executed by a processor, implements the steps of the method of any one of examples 1-21.

[0333] The above description is merely exemplary of the disclosure and the application made use of the principles of the technology. It is to be understood that the disclosure is not limited in scope to the particular embodiments described herein, which are intended as examples only, and that the application is applicable to other like embodiments and / or implementations not expressly described herein. Numerous modifications, as would be apparent to one skilled in this art, can be made on the embodiments described without departing from the scope of the disclosure and such modifications are intended to fall within the scope of the appended claims. It is contemplated that, in these respects, that which is included in the present disclosure in a broad sense, and that is also encompassed within the concept and scope of the application.

[0334] Moreover, while operations may be depicted in the drawings in a particular, chronological order, this should not be understood as a requirement that such operations be performed in the particular order shown, or in sequential order, or that all illustrated operations be performed, to achieve desirable results. In certain circumstances, multitasking and parallel processing can be advantageous. Likewise, while several specific implementation details have been discussed, such details are not to be construed as limiting the scope of this disclosure. Certain features that are described in the context of separate embodiments can also be implemented in combination in a single embodiment. Conversely, various features that are described in the context of a single embodiment can also be implemented in subcombination, or as separate embodiments, absent the features of the single embodiment. Embodiments described herein can be implemented in hardware, software, firmware, or any combination thereof.

[0335] Although the subject matter has been described in language specific to structural features and / or methodological acts, it is to be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or acts described above. Rather, the specific features and acts described above are disclosed as example forms of implementing the claims. With respect to the devices in the above-described embodiments, the specific manner in which the various modules perform operations has been described in detail in the embodiments relating to the method, and will not be described in detail here.

Claims

1. A method for identifying cybersecurity risks, comprising: Obtain a target network topology map based on the target object, wherein the target network topology map is used to characterize the relationship between the target object and its related assets; Based on the business attributes and security characteristics of the assets in the target network topology, attack link analysis is performed on the target network topology to identify security risks in the target network topology.

2. The method according to claim 1, wherein, The target object includes one of the following: assets, identity, and resources; The resources mentioned include databases; The assets include at least one of Virtual Private Cloud (VPC), subnets, network interface cards (NICs), elastic computing services, and containers.

3. The method according to claim 1 or 2, wherein, The business attributes are used to characterize whether the corresponding asset belongs to the core asset, and the security characteristics include public network exposure and lateral movement. The core asset is an asset that meets preset conditions.

4. The method according to any one of claims 1-3, wherein, The target object includes the target asset; The process of obtaining the target network topology map based on the target object includes: Based on the connections between assets and the mapping between elastic public IPs and assets, a target network topology diagram representing the relationship between the target asset and other related assets is generated.

5. The method according to claim 4, wherein, The target assets include at least one Virtual Private Cloud (VPC); The step of generating the target network topology map, representing the relationship between the target asset and other related assets, based on the connection relationships between assets and the mapping relationship between elastic public IPs and assets, includes: Step 1: Take the first node in the target sequence as the current node. When generating the topology map between VPCs, the target sequence is composed of at least one VPC. When generating the topology map between subnets in a VPC, the target asset includes a VPC, and the target sequence is composed of subnets in that VPC. Step 2: Determine whether the current node exists in the first network topology graph. If not, add the assets and elastic public IPs related to the current node to the first network topology graph according to the connection relationship between assets and the mapping relationship between elastic public IPs and assets, and then execute Step 3. If yes, execute Step 3 directly. The first network topology graph is initially empty. Step 3: Determine whether the current node has a next node. If yes, take the next node of the current node in the target sequence as the current node and return to step 2. If no, determine the first network topology as the target network topology.

6. The method according to claim 5, wherein, The step of adding assets and elastic public IPs related to the current node to the first network topology graph based on the connection relationships between assets and the mapping relationship between elastic public IPs and assets includes: Step 21: Add the current node to the target node set, wherein the target node set is initially empty; Step 22: Based on the connection relationships between the assets, determine the target connection relationships related to the current node, wherein the target connection relationships are used to characterize the relationship between the current node and its similar assets; Step 23: Add the target connection relationship to the first network topology graph; Step 24: If there is an elastic public IP corresponding to the current node in the mapping relationship between the elastic public IP and the asset, then add the corresponding elastic public IP and the current node to the first network topology graph. Step 25: If the newly added node based on the current node in the first network topology graph is not empty, then remove the current node from the target node set and add the newly added node to the target node set, wherein the newly added node does not include elastic public IPs; Step 26: For each newly added node in the target node set, take the newly added node as the current node, and repeat steps 22 to 26 until all newly added nodes in the target node set are empty.

7. The method according to claim 6, wherein, Before the step of adding the mapping relationship between the elastic public IP and the asset to the first network topology graph if there is an elastic public IP corresponding to the current node in the mapping relationship between the elastic public IP and the asset, the step of adding the assets and elastic public IPs related to the current node to the first network topology graph according to the connection relationship between assets and the mapping relationship between elastic public IPs and assets further includes: If the target connection relationship is a cross-VPC relationship and there is a cloud firewall between the target connection relationships, then the first network topology map is modified based on the permission list of the cloud firewall; If the mapping relationship between the elastic public IP and the asset contains an elastic public IP corresponding to the current node, then the mapping relationship between the corresponding elastic public IP and the current node is added to the first network topology graph, including: If there is an elastic public IP address corresponding to the current node in the mapping relationship between the elastic public IP address and the asset, then the mapping relationship between the corresponding elastic public IP address and the current node is added to the first network topology obtained after correction.

8. The method according to claim 7, wherein, The permission list based on the cloud wall is used to modify the first network topology map, including: Sort the permission list of the cloud wall from low to high priority to obtain the first permission list; Arrange the permission rules with the same priority in the first permission list in the order of operation being denied and operation being allowed to obtain the second permission list; Traverse the second permission list and determine the first target node to be processed based on the type of address information in the current permission rule, wherein the current permission rule is the permission rule currently traversed in the second permission list; When the operation in the current permission rule is to accept, the connection relationship between the current node and the first target node is added to the first network topology graph according to the direction information in the current permission rule; When the operation in the current permission rule is denial, at least based on the type of the address information, a target processing strategy for the first target node is determined and executed, wherein the target processing strategy is one of the following: removing the first target node from the first network topology graph, or modifying the relationship between the current node and the first target node to a limited connection.

9. The method according to claim 8, wherein, The step of determining the first target node to be processed based on the type of address information in the current permission rules includes: If the address information in the current permission rule is the default gateway, then the VPC to which the cloud wall belongs is determined as the first target node; If the address information is a security group, then the address information is determined to be the first target node; If the address information is an IP address or an IP prefix, then the first target node is determined based on the address information and the pre-built correspondence between VPC identifiers, asset identifiers, and asset IP segments.

10. The method according to claim 6, wherein, In generating a topology map between subnets in a VPC, before the step of removing the current node from the target node set and adding the new node to the target node set if the newly added node based on the current node in the first network topology map is not empty, the step of adding assets and elastic public IPs related to the current node to the first network topology map according to the connection relationship between assets and the mapping relationship between elastic public IPs and assets further includes: If the Elastic Public IP corresponding to the current node has a cloud firewall enabled, the first network topology map is modified according to the permission list of the cloud firewall enabled by the corresponding Elastic Public IP. If the newly added node based on the current node in the first network topology graph is not empty, then removing the current node from the target node set and adding the newly added node to the target node set includes: If the newly added node based on the current node in the first network topology graph obtained after correction is not empty, then the current node is removed from the target node set, and the newly added node is added to the target node set.

11. The method according to claim 1, wherein, In the case of generating a topology map between subnets in a VPC, before the step of performing attack link analysis on the target network topology map based on the service attributes and security characteristics of assets in the target network topology map, the method further includes: Based on the access control lists bound to each subnet in the target network topology diagram, the target network topology diagram is modified to obtain a second network topology diagram; If there is an Elastic Public IP address that is simultaneously connected to a subnet and the VPC to which the subnet belongs in the second network topology diagram, then remove the connection relationship between the simultaneously connected Elastic Public IP address and the VPC to which the subnet belongs, and obtain the third network topology diagram. The attack link analysis of the target network topology based on the business attributes and security characteristics of the assets in the target network topology includes: Based on the business attributes and security characteristics of the assets in the third network topology, attack link analysis is performed on the third network topology.

12. The method according to claim 1, wherein, When generating the topology map between subnets in a VPC, the target object includes a VPC; Before the step of performing attack link analysis on the target network topology map based on the business attributes and security characteristics of assets in the target network topology map, the method further includes: Obtain a fourth network topology map based on the VPC, wherein the fourth network topology map is used to characterize the topological relationships between VPCs; The fourth network topology graph is added to the target network topology graph to obtain the fifth network topology graph; The attack link analysis of the target network topology based on the business attributes and security characteristics of the assets in the target network topology includes: Based on the business attributes and security characteristics of the assets in the fifth network topology diagram, attack link analysis is performed on the fifth network topology diagram.

13. The method according to claim 4, wherein, The target assets include network interface cards (NICs); The step of generating the target network topology map, representing the relationship between the target asset and other related assets, based on the connection relationships between assets and the mapping relationship between elastic public IPs and assets, includes: Based on the mapping relationship between the elastic public IP and the assets, determine the elastic public IP corresponding to the network card; Based on the network interface card and its corresponding elastic public IP, a sixth network topology diagram is generated; Based on the permission list of the security group associated with the network interface card, the sixth network topology map is modified to obtain the target network topology map representing the relationship between the target asset and other related assets.

14. The method according to claim 1, wherein, The target object includes a network interface card (NIC); Before the step of performing attack link analysis on the target network topology map based on the business attributes and security characteristics of assets in the target network topology map, the method further includes: Obtain a seventh network topology map based on the VPC where the network interface card is located, wherein the seventh network topology map is used to characterize the topological relationships between subnets in the VPC; If there is an Elastic Public IP address that is simultaneously connected to the network card and the subnet to which the network card belongs in the seventh network topology diagram, then remove the connection relationship between the simultaneously connected Elastic Public IP address and the subnet to which the network card belongs, and obtain the eighth network topology diagram. The attack link analysis of the target network topology based on the business attributes and security characteristics of the assets in the target network topology includes: Based on the business attributes and security characteristics of the assets in the eighth network topology diagram, attack link analysis is performed on the eighth network topology diagram.

15. The method according to claim 4, wherein, The target assets include elastic computing services or containers; The step of generating the target network topology map, representing the relationship between the target asset and other related assets, based on the connection relationships between assets and the mapping relationship between elastic public IPs and assets, includes: Determine the target network interface card (NIC) to which the elastic computing service or the container is bound; Obtain a ninth network topology map based on the target network interface card, and use it as the target network topology map.

16. The method according to claim 1, wherein, The target object includes the target asset; The business attributes are used to characterize whether the corresponding asset belongs to the core asset, and the security features include public network exposure and lateral movement. The method of analyzing attack links in the target network topology based on the business attributes and security characteristics of assets in the target network topology to identify security risks in the target network topology includes: Identify risky assets exposed to the public network in the target network topology graph; If the risky asset is not a core asset and the risky asset meets any of the first preset conditions, then it is determined whether the risky asset can be moved laterally to the core asset. If the risky asset can be moved laterally to the core asset, then the risky asset is identified as a security risk.

17. The method according to claim 16, wherein, The method of analyzing attack links in the target network topology based on the business attributes and security characteristics of assets in the target network topology to identify security risks in the target network topology also includes: If the risky asset is not a core asset and the risky asset meets any of the second preset conditions, then the risky asset is identified as a security risk. The second preset condition includes: The resource code of the risk asset contains access credentials, and the access permissions corresponding to the access credentials can access the core asset. The risky assets have access key calls, and the access key involves the core assets.

18. The method according to claim 16, wherein, The method of analyzing attack links in the target network topology based on the business attributes and security characteristics of assets in the target network topology to identify security risks in the target network topology also includes: If the risky asset is a core asset and meets any of the third preset conditions, then the risky asset is identified as a security risk.

19. The method according to claim 1, wherein, The target object includes target resources or target identity; The process of obtaining the target network topology map based on the target object includes: Obtain a permission topology graph based on the target object, wherein the permission topology graph is used to represent the relationship between identity and resources; Based on the pre-built correspondence between assets and resources, determine the assets related to the resources in the permission topology diagram; Obtain the tenth network topology map based on the aforementioned related assets; The tenth network topology map is added to the permission topology map to obtain the target network topology map.

20. The method according to claim 19, wherein, The attack link analysis of the target network topology based on the business attributes and security characteristics of the assets in the target network topology includes: Based on the business attributes and security characteristics of the assets in the target network topology diagram, as well as the secret leakage of identities in the target network topology diagram, attack link analysis is performed on the target network topology diagram.

21. The method according to any one of claims 1-20, further comprising: In response to receiving a security risk identification request, the target object is determined based on the security risk identification request, wherein the security risk identification request includes the target object.

22. A network security risk identification device, comprising: The first acquisition module is configured to acquire a target network topology map based on the target object, wherein the target network topology map is used to characterize the relationship between the target object and its related assets; The link analysis module is configured to perform attack link analysis on the target network topology based on the business attributes and security characteristics of the assets in the target network topology to identify security risks in the target network topology.

23. A computer-readable medium having a computer program stored thereon, wherein, When the computer program is executed by the processing device, it implements the steps of the method according to any one of claims 1-21.

24. An electronic device, comprising: A storage device on which computer programs are stored; A processing device is configured to execute the computer program in the storage device to implement the steps of the method according to any one of claims 1-21.

25. A computer program product comprising a computer program, wherein, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1-21.

Citation Information

Patent Citations

  • Business data security risk identification method and system

    CN109977680A

  • Asset vulnerability assessment method, device and equipment, medium and product

    CN116049832A

  • Network attack response method and device, computer equipment and storage medium

    CN116723052A

  • Equipment security management method and system based on topology network

    CN116886341A

  • Network security protection system and method aiming at full-dimension attack and medium

    CN117640263A

Cited By

  • Honey array driven network security situation awareness method and system

    CN122027363A