Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

59 results about "Open port" patented technology

In security parlance, the term open port is used to mean a TCP or UDP port number that is configured to accept packets. In contrast, a port which rejects connections or ignores all packets directed at it is called a closed port.

Techniques for detecting exploitation of manufacturing device vulnerabilities

A system and method for determining device attributes using a classifier hierarchy. The method includes determining exploitation conditions for a manufacturing device based on a first set of device attributes of the manufacturing device and a second set of device attributes indicated in a vulnerabilities database; analyzing behavior and configuration of the manufacturing device to detect an exploitable vulnerability for the manufacturing device, wherein the exploitable vulnerability is a behavior or configuration of the manufacturing device which meets the exploitation conditions; and performing mitigation actions based on the exploitable vulnerability. The vulnerabilities database further indicates known exploits for the second set of device attributes. Analyzing the behavior and configuration of the manufacturing device includes identifying that a port is open and querying a vulnerability scanner for identifying information of the open port, wherein the currently exploitable vulnerability is detected based further on the identifying information of the open port.
Owner:ARMIS SECURITY LTD

Dynamic detection method and device for network assets

The invention discloses a dynamic detection method and device for network assets, and belongs to the technical field of network security management. The method comprises the steps of performing initialization analysis and environment matching processing on a detection instruction received by a system, and determining a task scanning object of a to-be-scanned asset; performing first dynamic detection on assets to be scanned according to the task scanning object to obtain port opening information of all survival assets; performing second dynamic identification on all survival assets according to the task scanning object and the port open information to obtain structured data of an open port; and performing fusion correction on the structured data according to a preset fingerprint database, and establishing a complete asset model of the to-be-scanned asset according to a correction result. According to the invention, the detection efficiency of network assets can be improved and complete detection information can be obtained.
Owner:BEIJING CHANGYANG TECH CO LTD

Equipment identification method and device, equipment and medium

The invention relates to the technical field of Internet of Things, and provides an equipment identification method and device, equipment and a medium, which can start a probe to asynchronously initiate an address resolution protocol broadcast request for a target authorized network segment in a sectional manner to generate an active equipment list, and can avoid congestion, thereby accurately detecting active equipment. Performing port detection on each device in the active device list, performing multi-protocol verification on an open port according to a port-protocol adaptive matching mechanism, and performing organization unique identifier analysis on a media access control address of each device in the active device list; the problem of missing detection caused by single protocol broadcasting and port change and the problem of false alarm caused by only organizing unique identifier analysis are solved; and calculating a confidence score of each device according to the fusion features to generate an identification result of each device, so that device identification can be accurately carried out step by step by integrating multi-dimensional factors, and the false alarm rate is effectively reduced.
Owner:PRIMFORCE TECHNOLOGIES LTD

High flowrate flushing for open port sampling probe

In a sampling system for mass spectrometry, a method and apparatus are set forth for high flow-rate flushing and sample delivery via a sampling probe (10). The sampling system includes a sampling probe (10) having a first fluid conduit (40) with an inlet, a second fluid conduit (42) with an outlet, and a sampling port fluidly connecting the first fluid conduit (40) and second fluid conduit (42). A fluid source (50) is attached to the inlet and a vacuum source (60) is attached to the outlet for causing fluid to flow through the first fluid conduit (40) past the sampling port and exit through the second fluid conduit (42). A cap (90) is provided for selectively closing and opening the sampling port. When the cap is removed, thus when the sampling port is open, sample may be introduced into, and captured by fluid flowing through the sampling port. When the cap is in place, thus when the sampling port is closed, a flushing fluid is supplied for flushing the sampling probe (10).
Owner:DH TECH DEVMENT PTE

System and method for detecting apache HTTP server path traversal vulnerability

The present application provides a system and a method for detecting an Apache HTTP Server path traversal vulnerability. The method comprises: inputting a target IP address list into a scanning module, and probing the network reachability of each IP address in the target IP address list; if there is a network-reachable IP address, probing all ports of the IP address, and recording open port numbers; identifying services running on the open ports and performing service classification; if a service is classified as an Apache service, initiating a Curl request command to an icons directory path of the Apache service; if the Curl request succeeds and an / etc / passwd file is read, parsing the / etc / passwd file and extracting users of a host under test; performing detection on the users of the host to obtain an Apache HTTP Server path traversal vulnerability; and generating a detection report for the host on the basis of the Apache HTTP Server path traversal vulnerability.
Owner:XIAN THERMAL POWER RES INST CO LTD

Automated method parameter configuration for differential mobility spectrometry separations

Systems and methods are disclosed for automated method parameter configuration for differential mobility separations. As non-limiting examples, various aspects of this disclosure provide receiving a sample in an open port interface; transferring the sample to an ionization source; ionizing the transferred sample; introducing the ionized sample into a mass spectrometer; mass analyzing the ionized sample to produce an initial mass analysis result; determining a peak width of the initial mass analysis result; and determining a dwell time for subsequent measurements based on the determined peak width, a pre-defined number of data points across subsequent mass analysis peak widths, and a number of different analytes to be assessed for the sample. The sample may be diluted and transferred to the ionization source by a sample introduction apparatus selected from a group including an acoustic droplet ejector (ADE), a pneumatic ejector, a piezoelectric ejector, and a hydraulic ejector.
Owner:DH TECH DEVMENT PTE

Detection system and method for harbor image registry registration vulnerabilities

The present application provides a detection system and method for Harbor image registry registration vulnerabilities. The method comprises: inputting a target IP address list to a scanning module, and detecting network reachability of each IP address in the target IP address list; if there is a network-reachable IP address, detecting all ports of the IP address, and recording the number of an open port; by identifying a service running under the open port, classifying the service; if the service is classified as a Web service of a Harbor image registry, determining whether an api users path under the service can be accessed; if the access succeeds, using a registration module to initiate a post request for the api users path and register an administrator account; when the post request has been implemented and a new administrator account has been successfully created by a Harbor image registry server, a parsing module pulling an image file of the image registry and parsing and detecting the image file; and a detection report module integrating detected vulnerabilities to generate a detection report of Harbor image registry registration vulnerabilities.
Owner:XIAN THERMAL POWER RES INST CO LTD

Method and system for probing components based on gRPC communication

The application discloses a method and system for detecting components based on gRPC communication, and relates to the technical field of communication information management; a client gRPC sending module sends a request to obtain return information to judge the availability of a detected component, a server gRPC receiving module receives the request, obtains client information and a component name to be detected according to the request, obtains open ports of the corresponding component and ping request return values of the open ports from a server data storage module according to the component name, knows whether the component is available according to the ping request return values, organizes return information and sends the return information to the client gRPC sending module, a server self-checking module sends a ping request to the open ports of each component in real time and obtains ping request return values, and the component, the corresponding open ports of the component and the corresponding ping request return values are written into the server data storage module.
Owner:上海沄熹科技有限公司

Extended use of second LED for calibration

The present invention relates to a method for operating a spectrometer device (126) for obtaining at least one item of spectral information on at least one object (128), wherein the method comprises the following step: 5. obtaining the item of spectral information on the object (128) by evaluating the item of object measurement information and the item of open port measurement information, wherein at least one of: the item of object measurement correction information and the item of open port measurement correction information are further evaluated when obtaining the item of spectral information in order to compensate for at least one deviating measurement condition during the generation of the item of object measurement information and the item of open port measurement information.
Owner:TRINAMIX GMBH

Acoustic control and characterization of sampling interface

Disclosed are methods and systems that can detect, monitor, adjust, and optimize fluid dynamic conditions within a sampling system comprising a transport capillary (e.g., an open port interface). The methods and systems detect an acoustic signal within the sampling system and, based on characteristics of the detected acoustic signal, adjust flow rate conditions of the liquid and / or airflow in the sampling system. Also provided are automated control and feedback systems (e.g., automated feedback adjustments made to an inlet pump flow rate, nebulizer gas flow rate, or both) that adjust, tune, and maintain flow conditions within a transport line based on a detected acoustic signal.
Owner:DH TECH DEVMENT PTE

Crystal head wire harness waterproof rapid installation connector

The utility model discloses a waterproof rapid installation connector for a crystal head wire harness, and relates to the technical field of electronic components. Comprising an RJ45 waterproof connector, one end of the RJ45 waterproof connector is provided with a rear cover body, the other end of the RJ45 waterproof connector is provided with a main body rubber core, and a crystal head wire harness body penetrates through the main body rubber core. According to the utility model, the mounting hole is larger than the maximum size of the crystal head body, so that the crystal head body is convenient to directly pass through and mount without finding a non-mounted wire end to pass through, and the problem that the assembled crystal is difficult to mount is effectively solved. The wire sealing body is provided with the opening, and is directly sleeved on the wire harness body through the opening, and the wire sealing body is of a dovetail opening structure; the problem of falling caused by large opening after winding is solved, the reliability of the waterproof capability of the connector is improved, the waterproof protection capability is improved through the arrangement of the rubber core waterproof Rib body and the wire sealing body Rib structure, meanwhile, the interference area with a wire harness body is reduced, and installation is more convenient.
Owner:苏州鲁益电子科技有限公司

Industrial control system network vulnerability scanning preprocessing method and system

The invention belongs to the technical field of industrial control network vulnerability scanning, and relates to an industrial control system network vulnerability scanning preprocessing method and system. Determining a system scanning boundary according to the network configuration information and the real-time flow data of the industrial control system, and obtaining a survival IP address list, an open port list and a scanning tolerance degree based on the system scanning boundary; obtaining a scanning task workload and scanning load intensity based on the survival IP address list, the open port list and the scanning tolerance degree, and generating a scanning task based on the scanning task workload and the scanning load intensity; and carrying out network vulnerability scanning according to the scanning task and obtaining an unverified vulnerability list, obtaining a vulnerability set according to the unverified vulnerability list and the threat score, and verifying the vulnerability set by utilizing POC. Invalid scanning and over-scanning can be avoided, the scanning range can be narrowed according to the characteristics of the industrial control system, and a reasonable scanning load is generated, so that the scanning time is effectively shortened. The false alarm rate of vulnerability detection can be reduced.
Owner:XIAN THERMAL POWER RES INST CO LTD

Network connection safety automatic start-stop control method and device, computer equipment, medium and product

The invention relates to a network connection security automatic start-stop control method and device, computer equipment, a medium and a product. The method comprises the steps that network equipment receives a first start-stop time strategy issued by a strategy management platform, and sends a start instruction to a fan control unit to instruct the fan control unit to open a to-be-opened port under the condition that the current moment is a start moment, so that operation and maintenance personnel remotely access the fan control unit through the to-be-opened port, and the operation and maintenance personnel remotely access the fan control unit through the to-be-opened port. And under the condition that the current moment is a stop moment, sending a stop instruction to the fan control unit to indicate the fan control unit to close the to-be-opened port so as to stop the process that the operation and maintenance personnel remotely access the fan control unit through the to-be-opened port, and feeding back a session termination notification to the strategy management platform, and the policy management platform is indicated to send a session termination notification to the operation and maintenance personnel. By adopting the method, the network security can be improved.
Owner:HUARUN ELECTRICITY FENGNENG SHANTOU CHAONAN CO LTD

Proactive inspection technique for improved classification

Systems, methods, and related technologies for a proactive inspection system for improved classification of devices are described. A device is discovered on a network that has a first open port number. A filename is obtained based on a likelihood that the filename is being used as a name for file content, in association with the first open port number. The file content is obtained from the device with the first open port number and the filename. The device is classified with the file content.
Owner:FORESCOUT TECHNOLOGIES INC

Port electronic greenhouse meteorological big data monitoring and joint operation method and system

The invention relates to the technical field of intelligent environmental protection of port bulk cargo storage yards, in particular to a meteorological big data monitoring and joint operation method and system for a port electronic greenhouse, and the method comprises the following steps: collecting multi-source data in an open port storage yard electronic greenhouse, constructing a multi-source data resource pool, and storing the multi-source data resource pool in a database; constructing a dynamic dust diffusion prediction model, and predicting dust concentration distribution in combination with the correction factor; setting a multi-equipment cooperative control rule, calculating a risk score, and controlling dust falling equipment in combination with current and predicted dust concentration distribution to realize dust falling; and monitoring the dust falling effect in real time so as to adjust the control parameters of the dust falling equipment, and regularly performing incremental training on the dynamic dust diffusion prediction model. According to multi-source information such as meteorological data, the dust diffusion trend can be pre-judged in advance, cooperative control over dust falling equipment can be achieved, control parameters can be adjusted according to the dust falling effect, control unbalance can be relieved, and the requirement for intelligent dust control of a port is met.
Owner:ACAD OF NATURAL SCI ENVIRONMENTAL TECH DEV (TIANJIN) CO LTD +1

Terminal identification method and device

The invention provides a terminal identification method and device, and the method comprises the steps: obtaining the open port information of a plurality of terminals, carrying out the clustering of the plurality of terminals according to the open port information of each terminal, and recognizing at least one cluster to which the plurality of terminals belong according to a clustering result, the terminals included in each of the at least one cluster belong to the same type. Therefore, in consideration of the fact that the terminal usually needs to open a specific port to be in butt joint with a server corresponding to the terminal and different types of terminals need to open different specific ports, the terminal to be identified is clustered by opening the port information of the terminal to be identified and taking the port information as the basis, so that the terminal to be identified can be identified. The open port information of the terminals belonging to the same cluster in the clustering result is similar, and the terminals belonging to the same cluster belong to the same type with a large probability, so that the effective and accurate identification of the terminals is realized, and the identification rate of the terminals can be ensured under the scene that various types of terminals emerge endlessly.
Owner:HUAWEI TECH CO LTD

Power electronic equipment

Power electronic equipment comprises a power box body internally provided with a heating device, a heat dissipation box body fixed to one side of the power box body, and a two-phase flow heat dissipation device vertically arranged in the heat dissipation box body. The power box body is provided with a first side plate, the upper portion of the first side plate is provided with an inner concave portion, one side of the heat dissipation box body is provided with an opening, the opening side of the heat dissipation box body is attached to the outer side of the first side plate, the two-phase flow radiator comprises an evaporator, a condenser and a connecting cavity connecting the evaporator and the condenser, and the evaporator is attached to the outer surface of the lower portion of the first side plate. The condenser is located above the evaporator and arranged in the inner concave part, an air inlet is formed in the lower portion of the heat dissipation box body, and an air outlet is formed in the upper portion of the heat dissipation box body. The power electronic equipment is high in heat dissipation efficiency, compact in structure and capable of adapting to various installation angles and installation directions in the range from the vertical direction to the horizontal direction, and the application flexibility and scene adaptability of the power electronic equipment are improved.
Owner:SHENZHEN HOPEWIND ELECTRIC CO LTD

Screening device for battery recycling

The utility model provides a screening device for battery recovery, which relates to the technical field of battery recovery and comprises an obliquely arranged screening frame and a screen arranged at an open port of the screening frame, a driving part for generating vibration is arranged outside the screening frame, and a liquid guide part is arranged on the inner wall of the screening frame and below the screen. The inclined plate is installed along the inclined side wall of the screening frame, the separating screen is installed above the bottom end of the inclined plate, the end of the separating screen is attached to the inclined face of the inclined plate, the separating screen forms another branch relative to the inclined plate, and the mesh number of the separating screen is smaller than that of the screen cloth. Crushed materials and an electrolyte are separated through the screen, the crushed materials falling to the inclined plate through the screen move downwards along with the electrolyte through vibration, the crushed materials and the electrolyte can be vibrated and separated through the separation screen, the electrolyte is guided and collected through the arc-shaped plate, the crushed materials of different sizes are collected through the screen and the separation screen, and the crushed materials and the electrolyte can be subjected to follow-up machining and recycling after being collected. And the electrolyte is prevented from being mixed with crushed aggregates.
Owner:安徽巡鹰再生资源利用有限公司

Multi-pass multi-control safety dosing device

The application discloses a multi-path multi-control safe medicine administration device. The device comprises a flow channel valve, the flow channel valve comprises a multi-path multi-functional control valve, the multi-path multi-functional control valve comprises a valve seat, a valve core, a valve sleeve body connected to the valve seat, and corresponding flow control devices, the valve core comprises a valve body sealing part and corresponding channel on-off parts, the flow control devices comprise valve flow devices and control devices, the valve flow devices comprise a flow guide chamber arranged on a corresponding side wall of the valve seat and a channel hole connected to corresponding channels of the multi-path multi-functional control valve and the flow guide chamber, the corresponding channel on-off parts of the valve core are arranged between the flow guide chamber and the channel hole, and the control devices comprise a touch body corresponding to the valve core and arranged at an open port of the valve sleeve body. The multi-path multi-control safe medicine administration device has simple and reasonable structure, stable and reliable operation, and is safer and cleaner.
Owner:JIANGXI KELUN MEDICAL EQUIP MFG CO LTD

A port opening method, device, apparatus and storage medium

Embodiments of the present application relate to the technical field of cloud computing, in particular to a port opening method and device, equipment and storage medium, aiming to improve the port opening efficiency. The method comprises: a service software receives a global configuration file, wherein the global configuration file includes a network address corresponding to the service software and a port blacklist, all ports in the network address are open ports; the service software sends a forwarding rule corresponding to the global configuration file to a kernel; the service software receives domain name port information corresponding to an added port; the kernel verifies an access request for the added port according to the forwarding rule; the kernel sends the access request to the service software if the verification is passed; and the service software returns a corresponding response message if the access request meets the domain name port information.
Owner:CHINA TELECOM CLOUD TECH CO LTD

Network equipment detection method and device, program product, medium and electronic equipment

The invention provides a network equipment detection method and device, a program product, a medium and electronic equipment. The method comprises the following steps: acquiring port state information of to-be-detected network equipment, and determining a port scanning strategy according to the port state information; according to the port scanning strategy, scanning the network equipment, and determining open port information and port service information in the network equipment; and performing port detection on the network equipment according to the open port information and the port service information in the network equipment, and determining whether a risk exists in the network equipment or not. The method comprises the following steps: determining a port scanning strategy exclusive to network equipment according to port state information of the network equipment, scanning the network equipment according to the determined port scanning strategy, determining open port information and port service information in the network equipment, and finally detecting the open port in the network equipment to determine the security of the network equipment. And the detection efficiency of the network equipment is improved.
Owner:HANGZHOU DPTECH TECH

Network security protection method and system

The invention provides a network security protection method and system, and belongs to the technical field of network security, and the method comprises the steps: firstly, obtaining all open ports of a server, obtaining feature data of each open port, the feature data comprising a port number, a protocol, a service name and a corresponding process, and then, carrying out the protection of all the open ports; the risk level of the open ports is determined through a neural network based on the feature data of each open port, the open ports are divided into a first group and a second group based on the risk levels, the risk levels of the open ports belonging to the first group are higher than the risk levels of the open ports belonging to the second group, and finally, the risk levels of the open ports belonging to the second group are lower than the risk levels of the open ports belonging to the second group. And performing differentiated management on the open ports belonging to the first group and the open ports belonging to the second group. According to the network security protection system provided by the embodiment of the invention and the network security protection method provided by the embodiment of the invention, the security is ensured, the resource allocation is optimized, and the unnecessary monitoring overhead is reduced.
Owner:JIANGSU ZHOUQI DIGITAL TECH CO LTD

Detection system and method for springboot actuator vulnerabilities

PCT designated stageWO2026065620A1Securing communicationOpen portPathPing
The present application provides a detection method for SpringBoot Actuator vulnerabilities, comprising: inputting a target IP address list to a scanning module, and detecting the network reachability of each IP address in the IP address list; if any IP address is reachable in a network, detecting all ports of the IP address, and recording open port numbers; performing service classification by identifying services running on open ports; if a service is classified to as a SpringBoot Web-type service, determining whether an Actuator path of the service is accessible; if the access is successful, using a crawler module to crawl a Web page under the Actuator path; if the crawled content contains a Heapdump binary file, downloading the Heapdump file to a local computer; parsing the downloaded Heapdump file by means of a parsing module to extract sensitive information from the file; and a detection report module generating a SpringBoot Actuator vulnerability detection report on the basis of the extracted sensitive information.
Owner:XIAN THERMAL POWER RES INST CO LTD

Method of calibrating a spectral sensing device

ActiveUS12699005B2Open portOptical property
Disclosed herein is a method of calibrating a spectral sensing device. The spectral sensing device includes:a. at least one detector element;b. at least one wavelength-selective element;c. at least one light source:d. at least one sample interface;e. at least one first optical path; andf. at least one second optical path.The method includes:I. illuminating the detector element via the at least one first optical path;II. illuminating the detector element via the at least one second optical path with no sample applied to the sample interface;III. illuminating the detector element via the at least one second optical path with at least one calibration sample applied to the sample interface; andIV. determining at least one item of calibration information by using the first detector signal, the open port detector signal and the calibration detector signal.Further disclosed herein are a method of determining at least one calibrated optical property of at least one sample, a spectral sensing device and computer programs and computer-readable storage media for performing the methods.
Owner:TRINAMIX GMBH

Combination of two LEDs and open port calibration

A method of calibrating a sensing device (110) is disclosed. The method comprises: I. illuminating the at least one detector element (112) via at least one first light path (128) to obtain at least one first detector signal, where the first light path (128) is configured to allow light emitted from the at least one light source (124) to propagate to the detector element (112) without passing through the at least one sample interface (126); iI. Illuminating the detector element (112) via at least one second optical path (130) without applying the sample onto the sample interface (126) to obtain at least one open port detector signal, where the second optical path (130) is configured to allow light emitted from the light source (124) to propagate to the detector element (112) by at least one pass through the sample interface (126); and III. Determining at least one piece of operational calibration information by using the first detector signal, the open port detector signal and at least one piece of factory calibration information, where the factory calibration information comprises a predefined relationship between the open port detector signal and a reference signal of the second optical path (130).
Owner:TRINAMIX GMBH

Policy-based K8s NodePort service exposure control method

The invention provides a strategy-based K8s NodePort service exposure control method, which comprises the following steps of: grouping nodes in a cluster according to a preset node label strategy, and configuring a port range allowed to be used and a corresponding namespace for each node group; when a NodePort service is created in a specified namespace, determining a node set and a port range which should be exposed by the service based on a binding relationship between the namespace and a node group and the node group selected by a tenant; according to the determined node set and port range, dynamically configuring and opening a NodePort port on the corresponding node to realize policy-based exposure of the service; and monitoring changes of node group configuration, a port range or a namespace binding relationship in real time, and dynamically updating the exposed node and port configuration of the created NodePort service when the changes are detected. According to the method, the attack surface exposed by the service can be effectively reduced, and the port resource utilization rate and the isolation control capability in a multi-tenant environment are enhanced through node grouping and a port range multiplexing mechanism.
Owner:JINAN INSPUR DATA TECH CO LTD

Recoil valve

The utility model discloses a recoil valve, which belongs to the related technical field of valves, and comprises a valve body, a diaphragm and a guide rod which are arranged in the valve body, and a third interface connected to the axial direction of the valve body, the interior of the valve body is hollow and is provided with a plurality of open ports (including a first port and a second port); the first port and the second port are formed in the two axial sides of the valve body respectively. The diaphragm is arranged in the cavity and is hermetically connected with the corresponding inner wall in the cavity to form a control cavity; one end of the guide rod extends into the control cavity and is fixedly connected with the diaphragm, the other end of the guide rod extends into the third port in the axial direction of the valve body, the guide rod can move in the axial direction of the third port along with the deformation process of the diaphragm, and the other end of the guide rod is connected with a plugging structure. And synchronous cooperative operation of multiple valves does not need to be considered, maintenance is easy and convenient, and the method is suitable for internet remote control.
Owner:SHIJIAZHUANG HIT FLUID TECHNOLOGY CO LTD

A microservice calling method

The present invention discloses a microservice calling method, which realizes microservice registration and microservice access proxy through a service registration proxy. The service registration proxy receives microservice connections and saves microservice related information in a service routing table. The service registration proxy can propagate change information of the service routing table to adjacent service registration proxies. The service proxy is used for microservices in a local service domain to call microservices in other service domains for external access. At the same time, it can also proxy microservices in other service domains to request access to microservices registered in the local service domain, thereby solving the complexity of mutual calling of microservices in different networks. In addition, the microservice itself does not need to open a port. The service registration proxy opens a port to receive the registration of the microservice, establishes a long link, realizes two-way communication, improves security, and can avoid high RTT and TIME_WAIT problems caused by frequent creation and disconnection.
Owner:CHANGSHA FUGLEN INFORMATION TECH CO LTD

Information system asset risk assessment method and device and medium

The invention provides an information system asset risk assessment method and device and a medium, and relates to the technical field of computers. The method comprises the following steps: acquiring multi-dimensional risk assessment information of information system assets, wherein the multi-dimensional risk assessment information comprises open port information and component protection information; obtaining the risk value of each dimension of the information system asset according to the risk assessment information of each dimension, including obtaining the asset exposure risk value according to the open port information and obtaining the component protection risk value according to the component protection information; and obtaining a comprehensive risk score of the information system assets according to the multi-dimensional risk value, and carrying out risk early warning on the information system assets according to the comprehensive risk score. According to the method, two dimensions of the asset exposure degree and the asset protection condition are introduced into asset risk calculation, risk quantification is realized from a two-way perspective of risk exposure and protection offset, and the reliability of asset risk assessment is improved.
Owner:CHINA UNITED NETWORK COMM GRP CO LTD

Session establishment method and device, electronic device and readable storage medium

The present invention provides a session establishment method and apparatus, an electronic device, and a readable storage medium, relating to the field of communications technology. The method includes: performing security authentication on a UDP message sent by a user terminal; if the UDP message passes security authentication, establishing a return route based on the UDP message; and conducting a session with the user terminal based on the return route. Therefore, the present invention can address the related art issue of open server ports being susceptible to intrusion and penetration, resulting in risks of data leakage and program corruption.
Owner:CHINA TELECOM CORP LTD