The invention discloses an internet asset
exposure information checking method. The method comprises the following steps: S1, confirming known clue information; s2, obtaining
a domain name and an Ip
list of an enterprise through an association
algorithm; s3, detecting the
domain name and the IP obtained in the S2 by using an asset detection tool; and S4, analyzing ports, protocols and component applications of asset opening. The enterprise
domain name and Ip
list are obtained through association algorithms such as certificates, sub-
domain name blasting, flow analysis, ICP information, domain name registration information, enterprise names, app, WeChat applets and the like, then the domain names and the IPs are detected by using an asset detection tool, open ports, protocols and component applications of assets are analyzed, comprehensive
exposure surface investigation is carried out on enterprise internet assets. The method can converge the
attack surface, reduce the attacked risk, improve the
internal management of an enterprise, reduce the notification of a supervised unit, and lay a foundation for the subsequent
safety risk assessment and monitoring.