Cloud security product identification method and apparatus, and computer device, readable storage medium and program product

By acquiring and filtering a list of cloud security products and using network information for detection and processing, the problem of identifying and managing cloud security products on the cloud platform has been solved, and support for cloud security governance and vulnerability verification has been achieved.

WO2026114108A1PCT designated stage Publication Date: 2026-06-04CHINA TELECOM CLOUD TECH CO LTD

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
CHINA TELECOM CLOUD TECH CO LTD
Filing Date
2025-11-21
Publication Date
2026-06-04

AI Technical Summary

Technical Problem

Due to the diverse range of cloud security products offered by cloud service providers, OEMs, and cloud security vendors, existing technologies struggle to effectively identify and manage cloud security products on cloud platforms, impacting cloud security governance and vulnerability verification.

Method used

By obtaining a list of candidate cloud security products, filtering products associated with the target cloud platform, using network information for detection and processing, identifying target cloud security products that meet preset conditions, and storing relevant information.

Benefits of technology

It enables accurate identification and management of cloud security products on cloud platforms, supports cloud security governance and vulnerability verification, and promptly discovers and addresses vulnerabilities in shadow assets and OEM vendors.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025136572_04062026_PF_FP_ABST
    Figure CN2025136572_04062026_PF_FP_ABST
Patent Text Reader

Abstract

The present application relates to a cloud security product identification method and apparatus, and a computer device, a computer-readable storage medium and a computer program product. The method comprises: acquiring a list of candidate cloud security products, and acquiring product information and network information of each candidate cloud security product in the list of candidate cloud security products; on the basis of the product information and the network information of each candidate cloud security product, screening the list of candidate cloud security products to obtain cloud security products associated with a target cloud platform; on the basis of the network information of the cloud security products, performing detection processing on the cloud security products to obtain detection results, and determining a target cloud security product, the detection result of which meets a preset condition; and storing information of the target cloud security product, wherein the information at least includes the product information and the network information. By means of the method, cloud security products can be identified, thereby providing powerful support for cloud security governance and vulnerability verification.
Need to check novelty before this filing date? Find Prior Art

Description

Cloud security product identification methods, devices, computer equipment, readable storage media, and program products

[0001] Related applications

[0002] This application claims priority to Chinese patent application filed on November 27, 2024, with application number 202411714119.5, entitled "Cloud Security Product Identification Method, Apparatus, Computer Equipment, Readable Storage Medium and Program Product", the entire contents of which are incorporated herein by reference. Technical Field

[0003] This application relates to the field of computer technology, and in particular to a cloud security product identification method, apparatus, computer equipment, computer-readable storage medium, and computer program product. Background Technology

[0004] As enterprises and organizations increasingly rely on cloud platforms to host their critical business applications and data, cloud security has gradually become a core topic in the field of information security. Cloud security products, as the main line of defense protecting cloud platforms from malicious attacks, play a crucial role in protecting the security of business data and applications hosted on cloud platforms.

[0005] Identifying cloud security products is crucial for cloud security governance and vulnerability verification. Given the diverse range of cloud security products offered by cloud service providers, OEMs (Original Equipment Manufacturers), and cloud security vendors, a robust method for identifying cloud security products is urgently needed to provide strong support for cloud security governance and vulnerability verification. Summary of the Invention

[0006] Therefore, it is necessary to provide a cloud security product identification method, apparatus, computer equipment, computer-readable storage medium, and computer program product that can identify cloud security products in order to address the above-mentioned technical problems.

[0007] Firstly, this application provides a method for identifying cloud security products, the method comprising:

[0008] Obtain a list of candidate cloud security products, and obtain the product information and network information of each candidate cloud security product in the list;

[0009] Based on the product information and network information of each candidate cloud security product, cloud security products associated with the target cloud platform are selected from the list of candidate cloud security products.

[0010] Based on the network information of the cloud security product, the cloud security product is detected and processed to obtain the detection results, and the target cloud security product whose detection results meet the preset conditions is determined.

[0011] The information of the target cloud security product is stored, and the information includes at least product information and network information.

[0012] In one embodiment, obtaining the candidate cloud security product list includes:

[0013] Obtain the first cloud security product currently offered by the cloud security product provider, and add the first cloud security product to the candidate cloud security product list; and / or,

[0014] Search for a second cloud security product using a web space search engine, and add the found second cloud security product to the candidate cloud security product list; wherein, the cloud security product provider includes at least one or more of cloud service providers, OEM manufacturers, and cloud security product manufacturers.

[0015] In one embodiment, obtaining the product information and network information of each candidate cloud security product in the candidate cloud security product list includes:

[0016] Based on pre-stored configuration information, obtain product information for each candidate cloud security product in the candidate cloud security product list; and,

[0017] For each candidate cloud security product in the candidate cloud security product list, obtain the network search syntax corresponding to the candidate cloud security product, and search for the network information of the candidate cloud security product through a network space search engine and the network search syntax.

[0018] In one embodiment, the product information of the candidate cloud security product includes at least the product type, and the product type includes at least one or more of the following: self-developed type, OEM type, and third-party type.

[0019] The network information of the candidate cloud security products includes at least one or more of the following: IP address, port number, and ASN.

[0020] In one embodiment, the step of filtering cloud security products associated with the target cloud platform from the candidate cloud security product list based on the product information and network information of each candidate cloud security product includes:

[0021] If the product type is self-developed, the candidate cloud security product will be identified as the cloud security product associated with the target cloud platform.

[0022] In the case of OEM type, candidate cloud security products whose network information meets the first screening condition are identified as cloud security products associated with the target cloud platform; wherein, the first screening condition includes at least one of the following: the IP address belongs to the IP asset library of the cloud service provider, the IP address or ASN belongs to the ASN of the cloud service provider, and the product features corresponding to the cloud service provider are included.

[0023] In the case of a third-party product, candidate cloud security products whose network information meets the second screening criteria are identified as cloud security products associated with the target cloud platform; wherein, the second screening criteria include at least one of the following: the IP address belongs to the IP asset library of the cloud service provider, and the IP address or ASN belongs to the ASN of the cloud service provider.

[0024] In one embodiment, the step of detecting the cloud security product based on its network information, obtaining detection results, and determining target cloud security products whose detection results meet preset conditions includes:

[0025] Based on the network information of the cloud security product, construct the detection data packet of the cloud security product;

[0026] Based on the probe data packet, the cloud security product is probed and processed to obtain the probe results. The cloud security product that is found to be alive and providing security services is identified as the target cloud security product.

[0027] Secondly, this application provides a cloud security product identification device, the device comprising:

[0028] The acquisition module is used to acquire a list of candidate cloud security products and acquire product information and network information of each candidate cloud security product in the list of candidate cloud security products;

[0029] The filtering module is used to filter cloud security products associated with the target cloud platform from the list of candidate cloud security products based on the product information and network information of each candidate cloud security product.

[0030] The determination module is used to perform detection processing on the cloud security product based on the network information of the cloud security product, obtain the detection result, and determine the target cloud security product whose detection result meets the preset conditions.

[0031] The storage module is used to store information about the target cloud security product, which includes at least product information and network information.

[0032] In one embodiment, the acquisition module is specifically used for:

[0033] Obtain the first cloud security product currently offered by the cloud security product provider, and add the first cloud security product to the candidate cloud security product list; and / or,

[0034] Search for a second cloud security product using a web space search engine, and add the found second cloud security product to the candidate cloud security product list; wherein, the cloud security product provider includes at least one or more of cloud service providers, OEM manufacturers, and cloud security product manufacturers.

[0035] In one embodiment, the acquisition module is specifically used for:

[0036] Based on pre-stored configuration information, obtain product information for each candidate cloud security product in the candidate cloud security product list; and,

[0037] For each candidate cloud security product in the candidate cloud security product list, obtain the network search syntax corresponding to the candidate cloud security product, and search for the network information of the candidate cloud security product through a network space search engine and the network search syntax.

[0038] In one embodiment, the product information of the candidate cloud security product includes at least the product type, and the product type includes at least one or more of the following: self-developed type, OEM type, and third-party type.

[0039] The network information of the candidate cloud security products includes at least one or more of the following: IP address, port number, and ASN.

[0040] In one embodiment, the filtering module is specifically used for:

[0041] If the product type is self-developed, the candidate cloud security product will be identified as the cloud security product associated with the target cloud platform.

[0042] In the case of OEM type, candidate cloud security products whose network information meets the first screening condition are identified as cloud security products associated with the target cloud platform; wherein, the first screening condition includes at least one of the following: the IP address belongs to the IP asset library of the cloud service provider, the IP address or ASN belongs to the ASN of the cloud service provider, and the product features corresponding to the cloud service provider are included.

[0043] In the case of a third-party product, candidate cloud security products whose network information meets the second screening criteria are identified as cloud security products associated with the target cloud platform; wherein, the second screening criteria include at least one of the following: the IP address belongs to the IP asset library of the cloud service provider, and the IP address or ASN belongs to the ASN of the cloud service provider.

[0044] In one embodiment, the determining module is specifically used for:

[0045] Based on the network information of the cloud security product, construct the detection data packet of the cloud security product;

[0046] Based on the probe data packet, the cloud security product is probed and processed to obtain the probe results. The cloud security product that is found to be alive and providing security services is identified as the target cloud security product.

[0047] Thirdly, this application provides a computer device including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps of the method described in any one of the first aspects.

[0048] Fourthly, this application provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the method described in any one of the first aspects.

[0049] Fifthly, this application provides a computer program product, including a computer program that, when executed by a processor, implements the steps of the method described in any one of the first aspects.

[0050] The aforementioned cloud security product identification method, apparatus, computer equipment, computer-readable storage medium, and computer program product. First, the cloud security management device acquires a list of candidate cloud security products, and obtains the product information and network information of each candidate cloud security product in the list. Then, based on the product information and network information of each candidate cloud security product, the cloud security management device filters cloud security products associated with the target cloud platform from the candidate cloud security product list. Based on the network information of the cloud security products, it performs detection processing on the cloud security products, obtains the detection results, and determines the target cloud security products whose detection results meet preset conditions. Finally, the cloud security management device stores the information of the target cloud security products, which includes at least product information and network information. In this way, the cloud security management device can identify cloud security products in the cloud platform, providing strong support for cloud security governance and vulnerability verification. Attached Figure Description

[0051] To more clearly illustrate the technical solutions in the embodiments of this application or related technologies, the drawings used in the description of the embodiments of this application or related technologies will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.

[0052] Figure 1 is a schematic diagram of an application scenario in one embodiment;

[0053] Figure 2 is a flowchart illustrating a cloud security product identification method in one embodiment;

[0054] Figure 3 is a flowchart illustrating a cloud security product identification method in one embodiment;

[0055] Figure 4 is a flowchart illustrating a cloud security product identification method in one embodiment;

[0056] Figure 5 is a flowchart illustrating a cloud security product identification method in one embodiment;

[0057] Figure 6 is a flowchart illustrating a cloud security product identification method in one embodiment;

[0058] Figure 7 is a flowchart illustrating an example of a cloud security product identification method in one embodiment;

[0059] Figure 8 is a structural block diagram of a cloud security product identification device in one embodiment;

[0060] Figure 9 is an internal structure diagram of a computer device in one embodiment. Detailed Implementation

[0061] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0062] As enterprises and organizations increasingly rely on cloud platforms to host their critical business applications and data, cloud security has gradually become a core topic in the field of information security. Cloud security products, as the main line of defense protecting cloud platforms from malicious attacks, play a crucial role in protecting the security of business data and applications hosted on cloud platforms.

[0063] Identifying cloud security products is crucial for cloud security governance and vulnerability verification. Given the wide variety of cloud security products offered by cloud service providers, OEMs, and cloud security vendors, a robust method for identifying cloud security products is urgently needed to provide strong support for cloud security governance and vulnerability verification.

[0064] This application provides a cloud security product identification method, which can be applied to cloud security management devices in a cloud platform. Figure 1 is a schematic diagram of an application scenario in one embodiment. As shown in Figure 1, the cloud platform includes a cloud security management device 110 and a cloud security product 120. The cloud security management device 110 and the cloud security product 120 are connected via a network device. The cloud security management device 110 is used to identify, manage, and perform vulnerability verification on the cloud security product 120 in the cloud platform.

[0065] The cloud security product identification method provided in this application embodiment can be applied to the following application scenarios: (1) Understanding the distribution of cloud security products, statistically analyzing information such as product category, geographical location distribution, and port distribution of cloud security products, and understanding the deployment scale of cloud security products. (2) Identification and governance of shadow assets. For the IP of a surviving cloud security product, if the IP of the cloud security product is not in the IP asset database of the cloud service provider, then the cloud security product belongs to the category of shadow assets, which can promote internal governance of shadow assets. (3) Vulnerability verification and handling. When a cloud security product has a vulnerability, the IP address and port number of the cloud security product can be queried from the database. Then, the IP address and port number of the cloud security product with the vulnerability are handled to prevent problems before they occur and promote tenants to handle the vulnerability before attackers discover it. (4) Vulnerability handling of OEM-type cloud security products. The product information of cloud security products records the information of cloud OEM manufacturers. When the cloud security product of an OEM manufacturer has a vulnerability, the IP address and port number of the cloud security product can be queried from the database. Then, the IP address and port number of the cloud security product with the vulnerability are handled to prevent problems before they occur.

[0066] The cloud security product identification method provided in this application will be described in detail below with reference to specific implementation methods. As shown in Figure 2, the method includes the following steps:

[0067] Step 201: Obtain the candidate cloud security product list, and obtain the product information and network information of each candidate cloud security product in the candidate cloud security product list.

[0068] In one implementation, since cloud security products deployed on the cloud platform can be provided by cloud service providers, OEMs, and cloud security vendors, and these cloud security products are diverse, the cloud security management device can first obtain a candidate cloud security product list to accurately and comprehensively identify the cloud security products deployed on the cloud platform. This candidate cloud security product list comprises all cloud security products that can be deployed on the cloud platform (including cloud security products deployed on the cloud platform that provide security services, cloud security products deployed on the cloud platform that do not provide security services, cloud security products not deployed on the cloud platform, etc.).

[0069] After obtaining the candidate cloud security product list, the cloud security management device can further obtain the product information and network information of each candidate cloud security product in the list. The product information of a candidate cloud security product may include at least one or more of the following: product name (product_name), vendor name (vendor), OEM vendor name (oem_vendor), and product type (type). The product type may include at least one or more of the following: self-developed type, OEM type, and third-party type; cloud security products provided by cloud service providers are classified as self-developed type, cloud security products provided by OEM vendors are classified as OEM type, and cloud security products provided by cloud security vendors are classified as third-party type. The network information of a candidate cloud security product may include at least one or more of the following: IP address, country, latitude and longitude, port number, and ASN (Autonomous System Number).

[0070] Step 202: Based on the product information and network information of each candidate cloud security product, filter the cloud security products associated with the target cloud platform from the candidate cloud security product list.

[0071] In one implementation, since the candidate cloud security product list includes all cloud security products that can be deployed on the cloud platform, the cloud security management device needs to filter out the cloud security products associated with the target cloud platform from the candidate cloud security product list. Based on this, after obtaining the product information and network information of each candidate cloud security product, the cloud security management device can further filter out the cloud security products associated with the target cloud platform from the candidate cloud security product list based on the product information and network information of each candidate cloud security product. Here, the target cloud platform is a cloud platform provided by a cloud service provider, and the cloud security products associated with the target cloud platform are cloud security products deployed on the target cloud platform that provide security services.

[0072] Step 203: Based on the network information of the cloud security product, perform detection processing on the cloud security product, obtain the detection results, and determine the target cloud security product whose detection results meet the preset conditions.

[0073] In one implementation, since the liveness status of cloud security products deployed on a cloud platform may change over time, and the security services deployed on those products may also change, the cloud security management device, after filtering out cloud security products associated with the target cloud platform, can perform detection processing on these products based on their network information to obtain detection results. Then, the cloud security management device can further determine target cloud security products whose detection results meet preset conditions. These target cloud security products are those whose liveness status on the cloud platform is live, and whose deployed security services have not changed.

[0074] Step 204: Store the information of the target cloud security product. This information must include at least product information and network information.

[0075] In one implementation, after identifying a target cloud security product, the cloud security management device can store information about the target cloud security product. This information includes at least product information and network information.

[0076] The cloud security management device can store information about the target cloud security product in a database. The database can be MySQL, Elasticsearch, etc., and this embodiment is not limited to any particular database.

[0077] In an exemplary embodiment, as shown in Figure 3, the process by which the cloud security management device obtains a list of candidate cloud security products is as follows:

[0078] Step 301: Obtain the first cloud security product currently offered by the cloud security product provider and add it to the candidate cloud security product list. The cloud security product provider includes at least one or more of the following: cloud service providers, OEMs, and cloud security product vendors.

[0079] In one implementation, since the cloud security products deployed on the cloud platform can be provided by cloud security product providers (such as cloud service providers, OEMs, cloud security vendors, etc.), the cloud security management device can directly obtain the cloud security products currently offered or publicly available by the cloud security product provider, i.e., the first cloud security product. Then, the cloud security management device can add the obtained first cloud security product to the candidate cloud security product list.

[0080] In one example, a cloud security management device can use a web crawler to obtain the first cloud security product currently offered or publicly available by a cloud security product provider from its official website.

[0081] Step 302: Search for a second cloud security product using a web space search engine, and add the found second cloud security product to the candidate cloud security product list.

[0082] In one implementation, since the cloud security products deployed on the cloud platform may also include cloud security products whose providers have discontinued them but which are still used by cloud tenants—i.e., second cloud security products—the cloud security management device can also search for second cloud security products using a cyberspace search engine and add the found second cloud security products to the candidate cloud security product list to compensate for any omissions in the process of obtaining the candidate cloud security product list in step 301.

[0083] Specifically, cloud security management devices can use a web search engine to search for second cloud security products based on a pre-built product search syntax. For example, using the product search syntax "cert=A.cn", the web search engine can search for cloud security products whose certificate information includes the main website of cloud security vendor A. Technical personnel can pre-determine the product search syntax for all cloud security products in the web search engine. Since different versions of cloud security products may correspond to different product search syntaxes, one cloud security product may correspond to multiple product search syntaxes.

[0084] The search syntax for cloud security products in cyberspace search engines can be divided into two categories. The first category includes cloud security products already identified by the search engine. For example, the search syntax for a VPN (Virtual Private Network) product from cloud security vendor B could be "product=B-SSL-VPN". The second category includes cloud security products not identified by the search engine, or identified but not accurately. The search syntax for these products can be constructed by technical personnel based on specific circumstances. For example, the search syntax for a webpage anti-tampering system from cloud security vendor C could be "title=B Webpage Anti-tampering System".

[0085] It should be noted that cloud security management devices can determine the product type of each candidate cloud security product included in the candidate cloud security product list during the process of obtaining the candidate cloud security product list.

[0086] In an exemplary embodiment, as shown in Figure 4, the process by which the cloud security management device obtains product information and network information of each candidate cloud security product from the candidate cloud security product list is as follows:

[0087] Step 401: Based on the pre-stored configuration information, obtain the product information of each candidate cloud security product in the candidate cloud security product list.

[0088] In one implementation, the cloud security management device can obtain product information for each candidate cloud security product from a list of candidate cloud security products based on pre-stored configuration information. The configuration information includes product information for each candidate cloud security product; the product information for a candidate cloud security product may include at least one or more of the following: product name (product_name), vendor name (vendor), OEM vendor name (oem_vendor), and product type (type); the product type may include at least one or more of the following: self-developed type, OEM type, and third-party type; the product type of cloud security products provided by cloud service providers is self-developed type, the product type of cloud security products provided by OEM vendors is OEM type, and the product type of cloud security products provided by cloud security vendors is third-party type.

[0089] Step 402: For each candidate cloud security product in the candidate cloud security product list, obtain the corresponding network search syntax for the candidate cloud security product, and search for network information of the candidate cloud security product through the network space search engine and network search syntax.

[0090] In one implementation, due to the wide range of IP addresses and the uncertain ports opened by cloud security products after deployment, it is impossible to scan only specific ports. Therefore, building a platform for scanning all IP addresses and ports is not cost-effective. Furthermore, considering that attackers typically use existing, mature web search engines to obtain the IP addresses and port numbers of cloud security products before launching attacks, cloud security management devices can use mainstream web search engines to search for network information of candidate cloud security products.

[0091] For each candidate cloud security product in the candidate cloud security product list, the cloud security management device can obtain the corresponding network search syntax. This network search syntax is used to search for the candidate cloud security product's network information. Then, based on this network search syntax, the cloud security management device can use a cyberspace search engine to search for the candidate cloud security product's network information updated within a preset time period. For example, in the first search, to avoid omissions, the preset time period should be as long as possible; the cyberspace search engine can search for the candidate cloud security product's network information within the past two years. After the first search, to avoid data redundancy, in subsequent searches, the cyberspace search engine can only search for the candidate cloud security product's network information from the last search time to the current time.

[0092] To facilitate automated processing, cyberspace search engines typically provide APIs (Application Programming Interfaces). Correspondingly, cloud security management devices can obtain network information for various candidate cloud security products through these APIs. This network information can include at least one or more of the following: IP address, country, latitude and longitude, port number, and ASN. Cloud security management devices can select or exclude network information as needed, but it must at least include IP address, port number, and ASN.

[0093] It should be noted that after the cloud security management device obtains the product information and network information of each candidate cloud security product, it can store them in a database. The database can be MySQL, Elasticsearch, etc., and this embodiment does not limit the choice. Taking JSON format as an example, the data structure for storing the product information and network information of candidate cloud security products in the database is as follows:

[0094] "product_name":"Product Name"

[0095] "vendor": "vendor name"

[0096] "oem_vendor":"OEM manufacturer name"

[0097] "type":"Self-developed / OEM / Third-party"

[0098] "search_time": "Search time"

[0099] "data":"Network Information"

[0100] In one exemplary embodiment, the cloud security management device uses different methods to select candidate cloud security products for different product types. As shown in Figure 5, the cloud security management device selects cloud security products associated with the target cloud platform from the candidate cloud security product list based on the product and network information of each candidate cloud security product.

[0101] Step 501: If the product type is self-developed, the candidate cloud security product is determined to be the cloud security product associated with the target cloud platform.

[0102] In one implementation, since the self-developed candidate cloud security product is a cloud security product developed by the cloud service provider and will not be deployed on any cloud platform other than the target cloud platform, the cloud security management device can directly identify the candidate cloud security product as the cloud security product associated with the target cloud platform when the product type of the candidate cloud security product is self-developed.

[0103] Step 502: If the product type is OEM, candidate cloud security products whose network information meets the first screening criteria are identified as cloud security products associated with the target cloud platform. The first screening criteria include at least one of the following: the IP address belongs to the cloud service provider's IP asset library; the IP address or ASN belongs to the cloud service provider's ASN; and the product features include those corresponding to the cloud service provider.

[0104] In one implementation, OEM refers to companies that manufacture cloud security products for other companies. These cloud security products are packaged by cloud service providers according to their own choices and branded under their own names on the final product.

[0105] For OEM-type cloud security products, multiple cloud service providers typically OEM the same product. However, web search syntax is generally generic and cannot distinguish which OEM-type candidate cloud security products belong to which cloud service providers. Therefore, the network information of OEM-type candidate cloud security products obtained by the cloud security management device may include network information of candidate cloud security products that are not OEMed by cloud service providers. Based on this, the cloud security management device can preset a first screening condition based on OEM-type candidate cloud security products. Then, when the candidate cloud security product is of OEM type, the candidate cloud security products whose network information meets the first screening condition are identified as cloud security products associated with the target cloud platform. The first screening condition can primarily include at least one of the following:

[0106] The first type: The IP address belongs to the cloud service provider's IP asset database. When building a security operations platform, cloud service providers establish an IP asset database to record the IP addresses they own. While the existence of shadow assets (usually referring to cloud security products not under the control of the cloud security management device) is unavoidable, it can still be used to screen OEM-type candidate cloud security products. The cloud security management device can search for IPs in the network information of candidate cloud security products obtained through a cyberspace search engine. If a match is found in the IP asset database, it indicates that the OEM-type candidate cloud security product belongs to that cloud service provider.

[0107] The second type includes product features corresponding to the cloud service provider. OEMs can typically customize production and design according to the specifications of cloud service providers, and their cloud security products usually contain product features of the cloud service provider. Generally, OEM-type cloud security products will contain some product features of the cloud service provider. Based on this, cloud security management devices can identify candidate cloud security products containing product features corresponding to the cloud service provider as cloud security products associated with the target cloud platform.

[0108] For example, consider a cloud service provider's firewall, which is OEM'd from a different OEM manufacturer. This OEM manufacturer stores the cloud service provider's name in the `static / localize / oem.js` path of the cloud security product. The data stored in this path is shown below. The `COPYRIGHT_CN` field stores the cloud service provider's name. Therefore, for this cloud firewall, the cloud security management device can retrieve the content from the `static / localize / oem.js` path and then determine if the `COPYRIGHT_CN` field matches the cloud service provider's name. If the `COPYRIGHT_CN` field matches the cloud service provider's name, the cloud security management device can determine that the cloud firewall is a cloud security product associated with the target cloud platform.

[0109] var OEM_CN = "Next Generation Firewall"

[0110] var OEM_EN = "NGFW"

[0111] var COPYRIGHT_CN = " © 2023 ** Co., Ltd. All rights reserved.

[0112] var COPYRIGHT_EN = " 2023 **Corporation Ltd.

[0113] var LOGIN_TITLE_CN = "Please log in to the next-generation firewall"

[0114] var LOGIN_TITLE_EN="Please Login NGFW"

[0115] var INDEX_TITLE_CN = "Next-Generation Firewall"

[0116] var INDEX_TITLE_EN = "NGFW"

[0117] var DASH_PIE_COLOR = "#3ec289:#686868" / / Color of the homepage ring chart and the color of the remaining part

[0118] var AUTH_CN = "Authenticated Login"

[0119] var AUTH_EN="Authentication Login"

[0120] It should be noted that cloud security management devices can compare the product characteristics of cloud security products before and after OEM testing, and even analyze the product characteristics of other cloud service provider OEMs. If similar characteristics exist, this method can be used to screen and identify the cloud security product that is truly associated with the target cloud platform.

[0121] The third type: The IP address or ASN belongs to the cloud service provider's ASN. Generally, cloud service providers also have their own unique ASNs. If the IP address or ASN in the network information of the OEM-type candidate cloud security product belongs to the cloud service provider's ASN, it means that the OEM-type candidate cloud security product is a cloud security product of the cloud server provider, and the cloud security management device can identify the OEM-type candidate cloud security product as a cloud security product associated with the target cloud platform.

[0122] Step 503: If the product type is third-party, candidate cloud security products whose network information meets the second screening criteria are identified as cloud security products associated with the target cloud platform. The second screening criteria include at least one of the following: the IP address belongs to the cloud service provider's IP asset library, and the IP address or ASN belongs to the cloud service provider's ASN.

[0123] In one implementation, for cloud security products from third-party cloud security vendors, a cyberspace search engine, based on web search syntax, will search for all cloud security products exposed on the internet by that vendor. Therefore, the cloud security management device can preset a second filtering condition based on candidate cloud security products of the third-party type. Then, when the candidate cloud security product type is third-party, the candidate cloud security products whose network information meets the second filtering condition are identified as cloud security products associated with the target cloud platform. The filtering method is similar to that for OEM-type cloud security products, and can be performed using an IP asset database and ASN. Since third-party cloud security products do not contain cloud service provider product characteristics, filtering methods that include cloud service provider-related product characteristics are not suitable for third-party candidate cloud security products. Therefore, the second filtering condition includes at least one of the following: the IP address belongs to the cloud service provider's IP asset database, and the IP address or ASN belongs to the cloud service provider's ASN.

[0124] In an exemplary embodiment, as shown in Figure 6, the cloud security management device detects and processes cloud security products based on their network information, obtains detection results, and determines the target cloud security product whose detection results meet preset conditions. The process is as follows:

[0125] Step 601: Based on the network information of the cloud security product, construct the probe data packet of the cloud security product.

[0126] In one implementation, since the liveness status of cloud security products deployed on a cloud platform may change over time, and the security services deployed on those products may also change, the network information of cloud security products obtained through a cyberspace search engine does not reflect their latest status. It only indicates that a cloud security product is deployed on a specific IP address and port number at the time of the search. Therefore, cloud security management devices can also probe cloud security products based on their network information.

[0127] Since the network information of cloud security products obtained through cyberspace search engines already includes IP addresses, port numbers, and the security services running on them, cloud security management devices can construct probe data packets for cloud security products based on this network information.

[0128] Step 602: Based on the probe data packet, probe the cloud security product to obtain the probe result, and identify the cloud security product that is alive and provides security services as the target cloud security product.

[0129] In one implementation, the cloud security management device constructs a probe data packet for the cloud security product based on its network information. This packet is then sent to the corresponding IP address and port number. The device can then make a judgment based on the probe results. If the connection times out or the probe result is not the original security service, it indicates that the IP address and port number have changed and are no longer relevant to the cloud security product, and can be filtered out. If the device verifies the product is alive and the security service is consistent, it is also necessary to determine whether the probe result contains the characteristic information of the cloud security product. If not, it should also be filtered out. By probing the IP address and port number and verifying the rules, the cloud security management device can identify a target cloud security product based on an open IP address and port, matching services, and matching product characteristics.

[0130] It should be noted that the cloud security management device can store the detection results in a database. The database can be MySQL, Elasticsearch, etc., and this embodiment of the application is not limited to any particular database.

[0131] Taking JSON format as an example, the data structure for storing the probe results in the database is as follows:

[0132] "scan_time":"scan time",

[0133] "is_alive": "Survival status, True / False"

[0134] "is_security_product": Whether the security rule has been matched, True / False

[0135] Furthermore, as time goes on, cloud service providers will deploy more cloud security products on their cloud platforms, and may also introduce new cloud security products. Therefore, cloud security management devices can continuously update the data, with the update cycle determined based on actual needs.

[0136] As shown in Figure 7, this application embodiment provides an example of a cloud security product identification method, including the following steps:

[0137] Step 701: Obtain the first cloud security product currently offered by the cloud security product provider and add it to the candidate cloud security product list. The cloud security product provider includes at least one or more of the following: cloud service providers, OEMs, and cloud security product vendors.

[0138] Step 702: Search for a second cloud security product using a web space search engine, and add the found second cloud security product to the candidate cloud security product list.

[0139] Step 703: Based on the pre-stored configuration information, obtain the product information of each candidate cloud security product in the candidate cloud security product list.

[0140] Step 704: For each candidate cloud security product in the candidate cloud security product list, obtain the corresponding network search syntax for the candidate cloud security product, and search for network information of the candidate cloud security product through the network space search engine and network search syntax.

[0141] Step 705a: If the product type is self-developed, the candidate cloud security product is determined to be the cloud security product associated with the target cloud platform.

[0142] Step 705b: If the product type is OEM, candidate cloud security products whose network information meets the first screening criteria are identified as cloud security products associated with the target cloud platform. The first screening criteria include at least one of the following: the IP address belongs to the cloud service provider's IP asset library; the IP address or ASN belongs to the cloud service provider's ASN; and the product features include those corresponding to the cloud service provider.

[0143] Step 705c: If the product type is third-party, candidate cloud security products whose network information meets the second screening criteria are identified as cloud security products associated with the target cloud platform. The second screening criteria include at least one of the following: the IP address belongs to the cloud service provider's IP asset library, and the IP address or ASN belongs to the cloud service provider's ASN.

[0144] Step 706: Based on the network information of the cloud security product, construct the probe data packet of the cloud security product.

[0145] Step 707: Based on the probe data packet, probe the cloud security product to obtain the probe result, and identify the cloud security product that is alive and provides security services as the target cloud security product.

[0146] Step 708: Store the information of the target cloud security product. This information must include at least product information and network information.

[0147] In this embodiment, the cloud security management device first obtains a list of candidate cloud security products, and then obtains the product information and network information of each candidate cloud security product in the list. Next, based on the product and network information of each candidate cloud security product, the cloud security management device filters cloud security products associated with the target cloud platform from the candidate cloud security product list. Based on the network information of the cloud security products, it performs detection processing on the cloud security products, obtains the detection results, and determines the target cloud security products whose detection results meet preset conditions. Finally, the cloud security management device stores the information of the target cloud security products, which includes at least product information and network information. In this way, firstly, the cloud security management device can comprehensively identify self-developed, OEM, and third-party cloud security products. Secondly, the cloud security management device obtains cloud security product data based on a cyberspace search engine, eliminating the need to build its own full IP address and full port number scanning platform, and aligns with the attacker's perspective, enabling timely detection of problems with cloud security products and promoting remediation. Thirdly, the cloud security management device ensures the accuracy of cloud security product data by filtering, probing, and verifying rules on the data obtained from the cyberspace search engine. Fourthly, cloud security management devices can identify shadow assets of cloud service providers. Fifthly, cloud security management devices record information about OEM manufacturers, so when vulnerabilities appear in the cloud security products of OEM manufacturers, they can also promptly verify and address vulnerabilities in the cloud security products of cloud service providers that are of the OEM type.

[0148] It should be understood that although the steps in the flowcharts of the above embodiments are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the above embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages of other steps.

[0149] Based on the same inventive concept, this application also provides a cloud security product identification device for implementing the cloud security product identification method described above. The solution provided by this device is similar to the solution described in the above method; therefore, the specific limitations in one or more cloud security product identification device embodiments provided below can be found in the limitations of the cloud security product identification method described above, and will not be repeated here.

[0150] In an exemplary embodiment, as shown in FIG8, a cloud security product identification device is provided, the device comprising: an acquisition module 810, a filtering module 820, a determination module 830, and a storage module 840; wherein,

[0151] The acquisition module 810 is used to acquire a list of candidate cloud security products and acquire product information and network information of each candidate cloud security product in the list of candidate cloud security products;

[0152] The filtering module 820 is used to filter cloud security products associated with the target cloud platform from the list of candidate cloud security products based on the product information and network information of each candidate cloud security product.

[0153] The determination module 830 is used to perform detection processing on the cloud security product based on the network information of the cloud security product, obtain the detection result, and determine the target cloud security product whose detection result meets the preset conditions.

[0154] The storage module 840 is used to store information about the target cloud security product, which includes at least product information and network information.

[0155] In one embodiment, the acquisition module 810 is specifically used for:

[0156] Obtain the first cloud security product currently offered by the cloud security product provider, and add the first cloud security product to the candidate cloud security product list; and / or,

[0157] Search for a second cloud security product using a web space search engine, and add the found second cloud security product to the candidate cloud security product list; wherein, the cloud security product provider includes at least one or more of cloud service providers, OEM manufacturers, and cloud security product manufacturers.

[0158] In one embodiment, the acquisition module 810 is specifically used for:

[0159] Based on pre-stored configuration information, obtain product information for each candidate cloud security product in the candidate cloud security product list; and,

[0160] For each candidate cloud security product in the candidate cloud security product list, obtain the network search syntax corresponding to the candidate cloud security product, and search for the network information of the candidate cloud security product through a network space search engine and the network search syntax.

[0161] In one embodiment, the product information of the candidate cloud security product includes at least the product type, and the product type includes at least one or more of the following: self-developed type, OEM type, and third-party type.

[0162] The network information of the candidate cloud security products includes at least one or more of the following: IP address, port number, and ASN.

[0163] In one embodiment, the filtering module 820 is specifically used for:

[0164] If the product type is self-developed, the candidate cloud security product will be identified as the cloud security product associated with the target cloud platform.

[0165] In the case of OEM type, candidate cloud security products whose network information meets the first screening condition are identified as cloud security products associated with the target cloud platform; wherein, the first screening condition includes at least one of the following: the IP address belongs to the IP asset library of the cloud service provider, the IP address or ASN belongs to the ASN of the cloud service provider, and the product features corresponding to the cloud service provider are included.

[0166] In the case of a third-party product, candidate cloud security products whose network information meets the second screening criteria are identified as cloud security products associated with the target cloud platform; wherein, the second screening criteria include at least one of the following: the IP address belongs to the IP asset library of the cloud service provider, and the IP address or ASN belongs to the ASN of the cloud service provider.

[0167] In one embodiment, the determining module 830 is specifically used for:

[0168] Based on the network information of the cloud security product, construct the detection data packet of the cloud security product;

[0169] Based on the probe data packet, the cloud security product is probed and processed to obtain the probe results. The cloud security product that is found to be alive and providing security services is identified as the target cloud security product.

[0170] Each module in the aforementioned cloud security product identification device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in a computer device, or stored in the memory of a computer device as software, so that the processor can call and execute the corresponding operations of each module.

[0171] In an exemplary embodiment, a computer device is provided, which may be a terminal, and its internal structure diagram is shown in Figure 9. The computer device includes a processor, memory, input / output interface, communication interface, display unit, and input device. The processor, memory, and input / output interface are connected via a system bus, and the communication interface, display unit, and input device are also connected to the system bus via the input / output interface. The processor of the computer device provides computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and internal memory. The non-volatile storage medium stores an operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage medium. The input / output interface of the computer device is used for exchanging information between the processor and external devices. The communication interface of the computer device is used for wired or wireless communication with external terminals; wireless communication can be achieved through Wi-Fi, mobile cellular networks, Near Field Communication (NFC), or other technologies. When the computer program is executed by the processor, it implements a cloud security product identification method. The display unit of the computer device is used to form a visually visible image and may be a display screen, a projection device, or a virtual reality imaging device. The display screen can be an LCD screen or an e-ink screen. The input device of the computer device can be a touch layer covering the display screen, or buttons, trackballs, or touchpads set on the casing of the computer device, or external keyboards, touchpads, or mice, etc.

[0172] Those skilled in the art will understand that the structure shown in Figure 9 is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or may combine certain components, or may have different component arrangements.

[0173] In one exemplary embodiment, a computer device is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps of the cloud security product identification method described above.

[0174] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon, which, when executed by a processor, implements the steps of the cloud security product identification method described above.

[0175] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, implements the steps of the cloud security product identification method described above.

[0176] It should be noted that the user information (including but not limited to user device identifiers, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of the relevant data must comply with relevant regulations.

[0177] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, artificial intelligence (AI) processors, etc., and are not limited to these.

[0178] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this application.

[0179] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this patent application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.

Claims

1. A method for identifying cloud security products, wherein, The method includes: Obtain a list of candidate cloud security products, and obtain the product information and network information of each candidate cloud security product in the list; Based on the product information and network information of each candidate cloud security product, cloud security products associated with the target cloud platform are selected from the list of candidate cloud security products. Based on the network information of the cloud security product, the cloud security product is detected and processed to obtain the detection results, and the target cloud security product whose detection results meet the preset conditions is determined. The information of the target cloud security product is stored, and the information includes at least product information and network information.

2. The method according to claim 1, wherein, The process of obtaining the candidate cloud security product list includes: Obtain the first cloud security product currently offered by the cloud security product provider, and add the first cloud security product to the candidate cloud security product list; and / or, The system uses a web space search engine to search for second cloud security products and adds the found second cloud security products to the candidate cloud security product list; wherein, the cloud security product providers include at least one or more of cloud service providers, original equipment manufacturers (OEMs) and cloud security product manufacturers.

3. The method according to claim 1, wherein, The step of obtaining the product information and network information of each candidate cloud security product in the candidate cloud security product list includes: Based on pre-stored configuration information, obtain product information for each candidate cloud security product in the candidate cloud security product list; and, For each candidate cloud security product in the candidate cloud security product list, obtain the network search syntax corresponding to the candidate cloud security product, and search for the network information of the candidate cloud security product through a network space search engine and the network search syntax.

4. The method according to claim 1, wherein, The product information of the candidate cloud security products includes at least the product type, which includes at least one or more of the following: self-developed type, OEM type, and third-party type. The network information of the candidate cloud security products includes at least one or more of the following: Internet Protocol (IP) address, port number, and Autonomous System Number (ASN).

5. The method according to claim 4, wherein, Based on the product information and network information of each candidate cloud security product, the cloud security products associated with the target cloud platform are filtered from the candidate cloud security product list, including: If the product type is self-developed, the candidate cloud security product will be identified as the cloud security product associated with the target cloud platform. In the case of OEM type, candidate cloud security products whose network information meets the first screening condition are identified as cloud security products associated with the target cloud platform; wherein, the first screening condition includes at least one of the following: the IP address belongs to the IP asset library of the cloud service provider, the IP address or ASN belongs to the ASN of the cloud service provider, and the product features corresponding to the cloud service provider are included. In the case of a third-party product, candidate cloud security products whose network information meets the second screening criteria are identified as cloud security products associated with the target cloud platform; wherein, the second screening criteria include at least one of the following: the IP address belongs to the IP asset library of the cloud service provider, and the IP address or ASN belongs to the ASN of the cloud service provider.

6. The method according to claim 1, wherein, The process of detecting and processing the cloud security product based on its network information, obtaining detection results, and determining target cloud security products whose detection results meet preset conditions includes: Based on the network information of the cloud security product, construct the detection data packet of the cloud security product; Based on the probe data packet, the cloud security product is probed and processed to obtain the probe results. The cloud security product that is found to be alive and providing security services is identified as the target cloud security product.

7. A cloud security product identification device, wherein, The device includes: The acquisition module is used to acquire a list of candidate cloud security products and acquire product information and network information of each candidate cloud security product in the list of candidate cloud security products; The filtering module is used to filter cloud security products associated with the target cloud platform from the list of candidate cloud security products based on the product information and network information of each candidate cloud security product. The determination module is used to perform detection processing on the cloud security product based on the network information of the cloud security product, obtain the detection result, and determine the target cloud security product whose detection result meets the preset conditions. The storage module is used to store information about the target cloud security product, which includes at least product information and network information.

8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein... When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 6.

9. A computer-readable storage medium having a computer program stored thereon, wherein, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 6.

10. A computer program product comprising a computer program, wherein, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 6.