Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

32 results about "Port scan" patented technology

Asset vulnerability detection method and device, electronic equipment and storage medium

The invention discloses an asset vulnerability detection method and device, electronic equipment and a storage medium, and relates to the technical field of network security, and the method comprises the steps: actively sending a multi-protocol detection packet to scan a target network segment, and obtaining a first asset set; passively monitoring network traffic to extract asset feature information, and obtaining a second asset set to generate an asset list; port scanning tasks of all assets are dispatched to a plurality of scanning nodes in a distributed and parallel mode, dynamic port scanning is carried out according to a descending order of a plurality of key elements in combination with a port scanning optimization model based on risk prediction, and a full-amount port risk map is constructed; the static layer is matched with known vulnerabilities; the dynamic layer identifies suspicious behaviors deviating from a normal behavior baseline through an anomaly detection algorithm, and obtains an asset vulnerability detection result in combination with a cross validation method; according to the invention, the detection requirements of asset full coverage and early threat discovery in a complex network environment are met.
Owner:GUANGDONG ORIENTAL THOUGHT TECH

Cybersecurity Analysis and Protection Using Distributed Systems

Cybersecurity reconnaissance, analysis, and scoring uses distributed, cloud or edge-based pools of computing services to provide sufficient scalability for analysis of IT / OT networks using only publicly available characterizations. An in-memory associative array manages a queue of configuration and vulnerability search tasks through at least one public-facing proxy network which uses configurable search nodes to approach the target network with search tools in a desired manner to control certain aspects of the search in order to obtain the desired results, especially when target network behavior adjusts based on counterparty characteristics. A data packet modifier reveals IP addresses of threat actors behind port scans and subsequently block the threat actors.
Owner:QPX LLC

Method, apparatus, and computer software product for port scan detection

This application relates to port scan detection. A method includes identifying, in network data traffic, a set of source node and destination node (26) pairs, each pair having a given source node, a given destination node, and one or more ports (40) accessed in traffic between the nodes in each pair, and computing, for each pair, a respective baseline indicating a first number of ports accessed on the given destination node by source nodes other than the given source node in the pair during a first time period. For each pair, a respective test score is computed indicating a difference between a second number of ports accessed on the given destination node by the given source node in the pair during a second time period and the baseline, and a preventive action is initiated for the given source node for which the test score for any of the pairs is greater than a threshold.
Owner:PALO ALTO NETWORKS INC

Malicious port scan detection using port profiles

ActiveUS12542789B2Securing communicationSoftware systemDisjoint-set
Methods, apparatus and computer software products implement embodiments of the present invention that include defining, for a given software category, respective, disjoint sets of communication ports that are used by each of a plurality of software systems in the given software category, including at least first and second disjoint sets. A set of port scans are identified in data traffic transmitted between multiple nodes that communicate over a network, each of the port scans including an access, in the data traffic, of a plurality of the communication ports on a given destination node by a given source node during a predefined time period. Upon detecting a port scan by one of the nodes including accesses of at least one of the communication ports in the first set and at least one of the communication ports in the second set, a preventive action is initiated.
Owner:PALO ALTO NETWORKS INC

An intelligent detection method for network abnormal behavior

This invention proposes an intelligent method for detecting abnormal network behavior, including acquiring target network traffic data, constructing a multi-dimensional feature fusion model based on an attention mechanism, and building an abnormal behavior classification model based on deep learning. By automatically allocating attention to different network traffic features through the attention mechanism, it solves the problems of unreasonable feature weight allocation and insufficient feature fusion in traditional methods, significantly improving the detection capability for low-frequency and covert abnormal behaviors and effectively reducing false positive and false negative rates. The classification model employs a hybrid CNN and LSTM structure, taking into account both the local spatial and temporal features of network traffic, and can accurately identify various types of abnormal network behaviors such as DDoS attacks, port scanning, SQL injection, and malicious code propagation, adapting to diverse attack scenarios with high classification accuracy.
Owner:SHIJIAZHUANG ANJIE FUTURE TECHNOLOGY CO LTD

Malicious behavior bypass interception system based on flow analysis and detection

The invention belongs to the technical field of network security protection, and discloses a malicious behavior bypass interception system based on flow analysis and detection, a rule engine quickly matches known attacks based on a dynamic feature library, such as SQL injection, common port scanning, federated learning model combined multi-node cooperative training, and flow time, behavior and content features are combined to realize the flow analysis and detection of malicious behaviors. Unknown threats such as 0day vulnerability variants and low-frequency hidden attacks are accurately captured; in an enterprise mixed service traffic environment, missed judgment of traditional static detection on unknown attacks can be avoided, false alarms caused by data limitation of a single model can be reduced, energy consumption of operation and maintenance personnel for processing invalid alarms is reduced, core assets are prevented from being damaged by novel attacks, and comprehensiveness and reliability of network protection are remarkably improved; a bypass deployment mode is adopted, traffic is obtained through network TAP equipment or traffic mirror images, a service main forwarding link does not need to be intervened, and network delay and single-point failure risks introduced by traditional series deployment are avoided.
Owner:BEIJING LANGU TECHNOLOGY CO LTD

Port scanning detection

This application relates to port scan detection. A method includes identifying, in network data traffic, a set of source node and destination node (26) pairs, each pair having a given source node, a given destination node, and one or more ports (40) accessed in traffic between the nodes in each pair, and computing, for each pair, a respective baseline indicating a first number of ports accessed on the given destination node by source nodes other than the given source node in the pair during a first time period. For each pair, a respective test score is computed indicating a difference between a second number of ports accessed on the given destination node by the given source node in the pair during a second time period and the baseline, and a preventive action is initiated for the given source node for which the test score for any of the pairs is greater than a threshold.
Owner:PALO ALTO NETWORKS INC

Dynamic DAST scanning method and system and readable storage medium

The invention provides a dynamic DAST scanning method and system and a readable storage medium, and belongs to the field of network security and software engineering automation, and the method comprises the steps: automatically triggering a scanning task when a Developops process runs to a sec security node, and obtaining an interface or URL list; the method comprises the following steps of: processing script rendering, event triggering and redirection by adopting a dynamic crawler acquisition entrance which takes Scrapy as a core and is combined with Pyppeteer, and reducing acquisition failure caused by forbidding through strategies such as a proxy pool, a User-Agent, a Referer and session maintenance; after fingerprint identification and port scanning are carried out on the collected URL, tasks are distributed to xray passive scanning and AWVS active scanning by utilizing Celery scheduling; and after field extraction and format unification are carried out on different engine results, the results are written into MongoDB and duplicate removal is carried out, a customized scanning report is generated and returned to a Developops process to serve as sec node output, and therefore automatic safety scanning and early warning repairing are achieved in the development full life cycle.
Owner:UNICLOUD TECH CO LTD

A method and system for port scan detection using server logs

The application discloses a method and system for port scanning detection by using server logs, comprising a feature extraction step and a port scanning detection step; first, access logs on a server cluster are collected, then feature extraction is carried out to construct aggregated records describing access IP behaviors, and finally, whether port scanning occurs is judged by using rules or a clustering method according to the number of positive samples, and meanwhile, the detection result is fed back to an administrator and a positive sample database, so that the accuracy of the method is further improved. The application fully considers the actual needs of operation and maintenance safety audit managers, and has strong implementability and applicability.
Owner:NANJING UNIV

A Port Task Processing Method for a Satellite Telemetry, Tracking and Control System

This invention relates to the field of satellite telemetry and remote control technology, and discloses a port task processing method for a satellite telemetry, tracking, and command (TT&C) system, comprising: Step 1, probing all available network interfaces using a port scanner and establishing a multi-path communication channel including public network, private network, and satellite link; Step 2, collecting packet loss rate, latency, bandwidth, and jitter parameters of each path in the multi-path communication channel in real time, and updating the parameters based on a preset period; Step 3, generating a comprehensive score for each path based on the packet loss rate, latency, bandwidth, and jitter parameters. This invention employs a dynamic scoring and switching technology scheme for multi-path communication channels, achieving the technical effect of automatically selecting the optimal path based on real-time network performance. Compared to existing technologies that rely on fixed paths or manually configured switching thresholds, this solves the problems of high transmission latency, high packet loss rate, and inability to adaptively adjust due to network fluctuations.
Owner:BEIJING CREATUNION INFORMATION TECH CO LTD

Network layer security guarantee method and system for remotely accessing intelligent device with body

The invention discloses a network layer security guarantee method and system for remotely accessing an intelligent device with a body, belongs to the technical field of network security and mobile communication networks, and aims to solve the technical problem of how to prevent security threats of port scanning and brute force cracking and guarantee the security of intelligent applications with the body exposed at a public network end. According to the technical scheme, an SDK plug-in is installed on a user side in advance, the SDK plug-in of the user side is authorized, the authorization content comprises the steps that an application list is accessed, corresponding message identification information is carried when a user accesses a corresponding application on the application list, and a public network server side verifies the message identification information; if yes, allowing the user side to access the corresponding application by the public network server side; and if the verification of the message identification information fails, the public network server rejects the user side to access the corresponding application, and silently discards the application to block the unauthorized access.
Owner:INSPUR COMM TECH CO LTD

Port scanning detection

This application relates to port scan detection. A method includes identifying, in network data traffic, a set of source node and destination node (26) pairs, each pair having a given source node, a given destination node, and one or more ports (40) accessed in traffic between the nodes in each pair, and computing, for each pair, a respective baseline indicating a first number of ports accessed on the given destination node by source nodes other than the given source node in the pair during a first time period. For each pair, a respective test score is computed indicating a difference between a second number of ports accessed on the given destination node by the given source node in the pair during a second time period and the baseline, and a preventive action is initiated for the given source node for which the test score for any of the pairs is greater than a threshold.
Owner:PALO ALTO NETWORKS INC

Farmland RS485 bus intelligent converter based on dynamic error-avoiding port scanning

The utility model discloses a farmland RS485 bus intelligent converter based on dynamic error-avoiding port scanning. The farmland RS485 bus intelligent converter comprises a microprocessor, a port scanning module, a multipath RS485 communication interface, a storage unit, a clock module and a power supply module. The microprocessor is used as a core and is connected with multiple paths of RS485 communication interfaces in a star topology mode, so that parallel communication of multiple devices is realized; the port scanning module detects the state of a communication interface in real time through cooperation of a signal detection unit and a signal control unit, dynamically avoids an offline port, optimizes the polling efficiency and improves the communication rate. The storage unit is used for caching high-speed transmission data and avoiding data loss caused by rate mismatching; the clock module adopts a high-precision crystal oscillator, provides precise time sequence control and ensures data synchronization; the power supply module provides stable power for each component. According to the utility model, through the modular design and the dynamic optimization function, the problems of low polling efficiency, data loss and insufficient system expansibility in the prior art are solved, and the performance of multi-node long-distance high-speed communication is improved.
Owner:WUXI ZHONGKE OPTOELECTRONICS TECH CO LTD

Port scanning method and device, electronic equipment and storage medium

Embodiments of the present application provide a port scanning method and device, electronic equipment and storage medium. The port scanning method comprises: sending a port scanning task request to a scheduling node; receiving task element information and task actual parameters fed back by the scheduling node, wherein the scheduling node has previously constructed an LFSR based on a plurality of scanning targets in scanning information, a plurality of pseudo-random sequences generated by the LFSR have a one-to-one mapping relationship with the plurality of scanning targets, the task element information is used to restore the LFSR, and the task actual parameters include a current state of the LFSR; determining a scanning target set based on the task element information and the task actual parameters, the scanning target set comprising at least one scanning target. Embodiments of the present application can improve the randomness of the distribution of an Internet port scanning task, reduce the risk of scanning behavior being intercepted, and also improve the calculation and transmission efficiency of scanning targets, having the advantage of high execution efficiency of port scanning.
Owner:QI AN XIN TECHNOLOGY GROUP INC +1

System and method for determining readiness for managed runtime application program interface (API) applications via artificial intelligence

Systems, computer program products, and methods are described herein for determining readiness for managed runtime application program interface (API) applications via artificial intelligence. The present disclosure is configured to scan a set of API applications and their associated custom port hosted within a managed runtime environment using a custom port probe embedded within the managed runtime environment, where the custom port probe is operably coupled to a load balancer, where user traffic within the managed runtime environment is processed by the set of API applications and the custom port; initialize a set of components within the custom port for operation; verify readiness of the set of API application and the custom port probe using an artificial intelligence system; and transmit a notification to the load balancer indicating readiness of the set of API applications.
Owner:BANK OF AMERICA CORP

Transmission data security system and method adaptive to switch, and medium

The invention discloses a transmission data security system and method adaptive to a switch, and a medium. A chaotic sequence generation module generates a pseudo-random sequence based on coupled Logistic mapping and Henon mapping; the dynamic port mapping module changes the mapping relation between the physical port and the logic channel in real time according to the chaotic sequence; the chaos driving encryption module maps a chaos sequence into encryption parameters, and dynamically switches among three algorithms of AES-256, SM4 and ChaCha20 and three modes of CBC, CTR and GCM; the port hopping synchronization protocol module establishes a master-slave chaotic synchronization mechanism; the threat detection module detects abnormal behaviors such as port scanning and replay attacks; and the adaptive parameter adjustment module dynamically adjusts the jump period according to the threat level. According to the invention, the data transmission security and the anti-attack capability of the switch are effectively improved.
Owner:SICHUAN ZHIYUAN LIXING TECHNOLOGY CO LTD

An asset feature correlation type intelligent weak password detection and early warning method and system

The application discloses a kind of weak password detection and early warning method and system based on asset feature correlation formula intelligence, method includes: input asset information;Generation asset feature correlation dictionary;Configuration detection task;Select automatic or manual weak password detection task;Scan or identify port;Password collision;Automatic weak password detection report and risk early warning and notification generation;Its efficient asset information management, intelligent password dictionary generation, flexible detection task configuration, diversified detection mode, accurate port scanning identification, automatic report generation and real-time risk early warning and notification etc. together constitute an efficient, accurate and practical weak password detection and early warning system;The application aims at improving network security protection level, ensures asset security.
Owner:XIAN AMAI XINKE TECH CO LTD

Power acquisition system non-inductive migration method based on dynamic port mapping

The invention provides an electric power acquisition system non-inductive migration method based on dynamic port mapping, and belongs to the technical field of electric power acquisition. Twelve asset numbers of an electric energy meter are actively obtained through a transparent transmission module and encrypted and stored, and a concentrator automatically allocates monitoring ports according to the last four asset numbers and establishes a port mapping table; a TCP transparent transmission server is started to realize bidirectional conversion between a carrier frame and a TCP message, an optimal relay path is determined by adopting a carrier relay routing optimization algorithm based on a graph theory minimum spanning tree, time division multiple access time slots are allocated, and a sparse port scanning acceleration algorithm based on compressed sensing is executed to quickly detect a port occupation state. The technical problem that the service interruption time is long due to the fact that the master station needs to reconfigure connection parameters table by table after the communication module of the power acquisition system is replaced is solved.
Owner:QINGDAO EASTSOFT COMM TECH

Autonomous controllable embedded operating system flow monitoring method for power business

The invention relates to an autonomous controllable embedded operating system flow monitoring method for power business. The method comprises the following steps: S1, capturing communication flow data of an industrial protocol in real time; s2, according to the communication flow data, the cloud end detects distributed denial of service attacks, port scanning, illegal instruction injection and data leakage attacks for the power control system in real time by analyzing a space-time interaction mode between devices based on an ST-GAT model; and S3, integrating a lightweight LAKE protocol on intelligent electronic equipment running an autonomous controllable operating system to realize encrypted data transmission, and establishing an end-to-cloud secure communication link in a resource-constrained environment. According to the method, real-time efficient acquisition and end-to-end encryption of the network traffic of the power terminal are realized, and various potential risks and attack behaviors can be intelligently identified through global modeling of network communication behaviors.
Owner:STATE GRID INFORMATION & TELECOMM GRP CO LTD +4

Transmission data security system, method and medium adapted to a switch

The application discloses a transmission data security system, method and medium suitable for a switch, a chaotic sequence generation module generates a pseudo-random sequence based on coupled Logistic mapping and Henon mapping; a dynamic port mapping module changes the mapping relationship between a physical port and a logical channel in real time according to the chaotic sequence; a chaotic driving encryption module maps the chaotic sequence into encryption parameters, and dynamically switches among three algorithms of AES-256, SM4 and ChaCha20 and three modes of CBC, CTR and GCM; a port hopping synchronization protocol module establishes a master-slave chaotic synchronization mechanism; a threat detection module detects abnormal behaviors such as port scanning and replay attacks; and an adaptive parameter adjustment module dynamically adjusts a hopping period according to a threat level. The application effectively improves the security and attack resistance of switch data transmission.
Owner:SICHUAN ZHIYUAN LIXING TECHNOLOGY CO LTD

Method and device for port scanning detection and computer software product

The invention relates to a method and device for port scanning detection and a computer software product. A method includes identifying a set of pairs of source and destination nodes (26) in network data traffic, each pair having a given source node, a given destination node, and one or more ports (40) accessed in traffic between nodes in each pair, and calculating a respective baseline for each pair, the baseline indicates a first number of ports accessed by source nodes other than a given source node in the pair on a given destination node during a first period of time. For each pair, a respective test score is calculated that indicates a difference between a second number of ports accessed by a given source node of the pair on a given destination node during a second period and the baseline, and a preventive action is initiated for a given source node of any of the pairs for which the test score is greater than a threshold.
Owner:PALO ALTO NETWORKS INC

A port scanning detection method, system, electronic device and storage medium

The application discloses a port scanning detection method and system, an electronic device and a storage medium. The method comprises the following steps: loading an eBPF program and creating a first eBPF Map for storing a whitelist; hooking a first eBPF program related to a first kernel function of port listening, dynamically constructing the whitelist during port listening; hooking a second eBPF program related to a second kernel function of network connection establishment, extracting a destination port number and querying the whitelist when receiving a network connection request; if the query is not hit, determining an abnormal scanning event, and collecting connection information and reporting to the user state. The application can detect port scanning behavior in real time and accurately in the kernel state with low performance overhead, and the detection mechanism is difficult to bypass, solving the problems of poor real-time performance, high performance overhead and easy bypassing in the prior art.
Owner:BEIJING BAIGEFEICHI TECH LLC

Methods, devices, equipment, and storage media for monitoring port risks

This disclosure provides a method, apparatus, device, and storage medium for monitoring port risks. The method includes: pushing relevant data of network assets to be monitored onto a task queue in a first database, the relevant data of the network assets including IP addresses; initiating a scan task request to a scanning terminal, the scan task request instructing the scanning terminal to perform a full port scan at the host level against the IP addresses in the task queue to obtain port scan data corresponding to the IP addresses, and returning the port scan data corresponding to the IP addresses; receiving the port scan data corresponding to the IP addresses returned by the scanning terminal; and updating the status information of the port corresponding to the IP addresses based on the port scan data corresponding to the IP addresses. The above method pre-associates the IP addresses of the ports corresponding to the network assets, facilitating in-depth mining of multi-domain network assets bound to the same IP, and monitoring ports based on multi-dimensional parameters, thereby improving the accuracy of monitoring results.
Owner:CHINA CITIC BANK CO LTD

Security system for cyberspace assets

The invention provides a network space asset-oriented security system. The network space asset-oriented security system comprises an asset association analysis module, a port scanning module, a sub-domain name prediction module and a vulnerability analysis module, the asset association analysis module is used for classifying and analyzing network assets; the port scanning module is used for acquiring an open port of a target address and executing service detection on the open port; the sub-domain name prediction module is used for predicting an unknown sub-domain name by fusing statistical modeling of a Markov chain and sequence prediction of deep learning; the vulnerability analysis module is used for performing vulnerability analysis on output results of the three modules according to a preset vulnerability rule base to obtain a vulnerability analysis result; modeling and completely recording path node attributes and link characteristics based on a dynamic attack path tracking technology and a network topological graph theory; a multi-level service fingerprint identification technology and an asset topology positioning technology are fused, a business influence index is generated in combination with risk modeling, and an executable strategy is output.
Owner:WUYI UNIV

System and method for determining readiness for managed runtime application program interface (API) applications via artificial intelligence

Systems, computer program products, and methods are described herein for determining readiness for managed runtime application program interface (API) applications via artificial intelligence. The present disclosure is configured to scan a set of API applications and their associated custom port hosted within a managed runtime environment using a custom port probe embedded within the managed runtime environment, where the custom port probe is operably coupled to a load balancer, where user traffic within the managed runtime environment is processed by the set of API applications and the custom port; initialize a set of components within the custom port for operation; verify readiness of the set of API application and the custom port probe using an artificial intelligence system; and transmit a notification to the load balancer indicating readiness of the set of API applications.
Owner:BANK OF AMERICA CORP

Hot-pluggable HTTP (Hyper Text Transport Protocol) service framework system and method free from port monitoring

PendingCN121833576ATransmissionElectric digital data processingHot swappingHyper text transport protocol
The invention discloses a port-monitoring-free hot-pluggable HTTP (Hyper Text Transport Protocol) service framework system and a port-monitoring-free hot-pluggable HTTP service framework method, which are applied to a service node, and the system comprises a node starting module which is used for initiating an encrypted outbound tunnel to a control plane after the service node is started, so that any new port does not need to be opened; a light HTTP parser is arranged in the parsing module, and the parsing module is used for unpacking the received task frame, mapping the unpacked task frame to a service code to execute service logic and returning a response through the outbound tunnel; the task frame monitors an external entrance in a unified manner through the control plane, and after a request is received, the request is packaged into the task frame, and the task frame is safely issued through an outbound tunnel; the hot plug management module is used for instantly reporting online / offline of a service node through the outbound tunnel, so that the control plane completes rolling upgrading under the condition that a network strategy is not changed; the method has the beneficial effects that any inbound port does not need to be opened, and the vulnerability utilization risk caused by passive port scanning is eliminated.
Owner:SHENZHEN LEAGSOFT TECH

Asset portrait construction method and device based on multi-protocol full-port scanning

The embodiment of the invention provides an asset portrait construction method and device based on multi-protocol full-port scanning, and the method comprises the steps: carrying out the full-port and full-protocol scanning of all IP addresses through a plurality of independent scanning nodes disposed in a network, and obtaining asset information, including an operation system, a service version and a vulnerability state; transmitting a scanning result through an encryption channel; the structured asset information is stored in a relational database, semi-structured or unstructured data is stored in an NoSQL database, and original scanning logs and snapshots are stored in an object storage system; cleaning, standardizing and tagging the asset data, and constructing a fine-grained asset ledger; dynamically updating the asset data, setting a data verification rule, and performing data quality management and verification by using a data quality tool; a unified data access interface is provided, and access and application of various data scenes are supported. Through a systematic technical architecture, the problems of fragmentation and low efficiency in traditional asset management are solved.
Owner:HUANENG INFORMATION TECH CO LTD

Radio frequency front end port control method and device, equipment and storage medium

The invention discloses a radio frequency front-end port control method and device, equipment and a storage medium. Comprising the following steps: determining the number of each sub-port in a radio frequency front end port, and obtaining a frame number and a scanning frame number when an instruction input corresponding to the sub-port number is received; a control mode is determined according to the frame number and the scanning frame number, and the control mode comprises sub-port scanning and sub-port sharing; and determining a buffer command according to the control mode, and performing radio frequency front end port control according to the control mode and the buffer command. The control requirement that a single RFFE bus can support more than 15 devices of protocols can be met. And meanwhile, the requirement that a single RFFE bus controls a plurality of devices of the same model is met. Meanwhile, the design of the devices does not need to be modified, the total number of the devices can be expanded without special limitation, the design cost of the baseband chip RFFE can be reduced, the radio frequency front end can select the devices of the same model, the cost is further reduced, the performance is improved, and the front end control design is simplified.
Owner:MORNINGCORE HLDG CO LTD

Security detection method and device of embedded system and computer equipment

The invention relates to a security detection method and device for an embedded system and computer equipment, and relates to the technical field of security detection. The method comprises the steps of scanning a port of a to-be-detected embedded system in response to a security detection instruction for the to-be-detected embedded system to obtain a port scanning result of the to-be-detected embedded system, and determining system information of the to-be-detected embedded system according to the port scanning result; according to the system information, determining a target security detection strategy corresponding to the embedded system to be detected in a plurality of security detection strategies; and according to the target security detection strategy, performing security detection processing on the to-be-detected embedded system to obtain a security detection result of the to-be-detected embedded system, and generating a security detection report of the to-be-detected embedded system based on the security detection result. By adopting the method, the security detection requirement of the embedded system can be met.
Owner:CHINA ELECTRONICS RELIABILITY AND ENVIRONMENTAL TESTING INSTITUTE ((THE FIFTH INSTITUTE OF ELECTRONICS MINISTRY OF INDUSTRY AND INFORMATION TECHNOLOGY) (CHINA SAIBAO LABORATORY)

Method and device for realizing intelligent penetration test based on deep reinforcement learning, processor and computer readable storage medium thereof

The invention relates to a method for realizing an intelligent penetration test based on deep reinforcement learning, and the method comprises the following steps: learning an automatic penetration path discovery algorithm and a penetration path intelligent planning algorithm under an incomplete information condition on a training server through a machine learning model, and autonomously learning a vulnerability utilization strategy; performing port scanning on a target server by using Nmap, and identifying product features which cannot be directly identified through signatures in combination with a machine learning algorithm; initiating a vulnerability utilization attack to the target server; and executing vulnerability utilization and establishing session connection with the target server. By adopting the method and the device for realizing the intelligent penetration test based on deep reinforcement learning, the processor and the computer readable storage medium, automatic penetration path discovery is realized, manual dependence is reduced, efficiency and expandability are improved, and a penetration path of a large-scale network can be efficiently and automatically planned; according to the multi-thread learning synergy method, the learning process of the intelligent agent is accelerated, and the training and learning efficiency is improved.
Owner:THE THIRD RES INST OF MIN OF PUBLIC SECURITY