Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

170 results about "Vulnerability scanning" patented technology

Vulnerability scanning is an inspection of the potential points of exploit on a computer or network to identify security holes. A vulnerability scan detects and classifies system weaknesses in computers, networks and communications equipment and predicts the effectiveness of countermeasures.

Notebook software vulnerability scanning method and system based on security policy

The invention relates to a notebook software vulnerability scanning method based on a security policy. According to the method, firstly, a security policy library of a target notebook is obtained, and the security policy library comprises access control rules, data operation limiting conditions and vulnerability detection reference requirements for different software types; collecting software running data of the target notebook computer, wherein the software running data comprises current running process information, file system operation records, network connection states and software configuration parameters; performing matching analysis on the software operation data and the security policy library to generate a preliminary scanning result; evaluating the risk level of the software vulnerability according to the preliminary scanning result; and finally, based on the risk level and the repair guide terms in the security policy library, generating software vulnerability repair guide information. Therefore, notebook software vulnerabilities can be scanned comprehensively and accurately, and effective repair guidance is provided.
Owner:SHENZHEN ZHUO CHUANG INTELLIGENT TECH CO LTD

Information system security evaluation method and device, electronic equipment and storage medium

PendingCN121030748APlatform integrity maintainanceKnowledge representationAttackInformation systems security
The embodiment of the invention provides an information system security evaluation method and device, electronic equipment and a storage medium, and the method comprises the steps: obtaining an evaluation index model corresponding to a security evaluation request, and obtaining a simulation system corresponding to a target information system; performing vulnerability scanning on the simulation system based on the scanning missing tool and the MDATA knowledge base to obtain a corresponding first scanning result and a corresponding second scanning result, and performing scanning result fusion analysis based on the MDATA knowledge base to obtain a system risk assessment result of the simulation system; obtaining an optimized attack strategy based on the system risk assessment result and the MDATA knowledge base, and obtaining an optimized defense strategy based on the system risk assessment result and the expert knowledge base; the attack and defense test is performed on the simulation system based on the optimized attack strategy and the optimized defense strategy to obtain the attack and defense test result, and the security evaluation result of the target information system is obtained based on the evaluation index model and the attack and defense test result, so that the accuracy of evaluating the information system is improved.
Owner:PENG CHENG LAB

Adaptive scanning concurrent number adjusting method under microgrid isolation

The invention relates to the technical field of intelligent power grid network security, in particular to an adaptive scanning concurrency number adjusting method under micro-grid isolation, which comprises the following steps: S1, respectively deploying load monitoring nodes in a control area, a non-control area and a management information area, collecting service load and network state data of each area in real time through the load monitoring node; and S2, based on the collected service load and network state data, constructing a concurrent number calculation formula, and through dynamic concurrent adjustment driven by the real-time load, the vulnerability scanning efficiency is ensured, and the service operation of each region of the micro-grid is prevented from being interfered.
Owner:GUIZHOU POWER GRID CO LTD

Network attack path automatic generation and defense strategy optimization method, system and device and medium

The invention discloses a network attack path automatic generation and defense strategy optimization method, system and device and a medium, and relates to the technical field of network security, and the method comprises the steps: constructing a topology mapping model, obtaining a network architecture, an asset list and a dependency relationship, constructing a visual topology chart, building a vulnerability association analysis model, and combining a vulnerability scanning result. The method comprises the steps of obtaining a vulnerability knowledge graph, optimizing a path calculation process based on the vulnerability knowledge graph, establishing a path derivation model, generating an attack chain by applying a path derivation algorithm, optimizing defense logic, formulating an optimization step model, and establishing a real-time simulation feedback model based on the generated attack chain. And performing simulation implementation on the defense strategy through a multi-level simulation training scheme, and dynamically optimizing the defense strategy according to feedback data. According to the method, the crossing from passive protection to active prediction and from single-point defense to global optimization is realized, and the accuracy and adaptive capacity of network defense are remarkably improved.
Owner:GUIZHOU POWER GRID CO LTD

Centralized Vulnerability Security Scanning And Distributed Detection

Techniques for a centralized vulnerability security scanning and distributed detection system are disclosed. Some techniques set forth a set of operations including receiving, in a first cloud environment of a cloud system, image scan results from a second cloud environment of the cloud system, receiving container identity data from a particular deployed container of a set of deployed containers in the first cloud environment, based on a comparison between the image scan results and the container identity data, determining that the particular deployed container of the set of deployed containers is running a vulnerable software product, and generating, for presentation on a graphic user interface (GUI), information associated with the vulnerable software product. The image scan results correspond to a vulnerability scan of a plurality of software products running in the set of deployed containers.
Owner:ORACLE INT CORP

System and method for analyzing artificial intelligence utilization and associated risks

A code sensor system is provided, configured for execution by one or more processors, for cataloging and analyzing code repositories containing Artificial Intelligence (“AI”) and associating risks and vulnerabilities to the code repositories, the system comprising: a Detect AI module configured to identify code repositories that may contain AI; a Deep Scan module configured to generate an AI Bill-of-Materials (“BOM”) from the code repositories, the AI BOM including a plurality of categories including technologies, models and datasets; a Vulnerability Scan module configured to generate an interactive assessment of the risks and vulnerabilities associated with the AI BOM by cross-referencing content of the AI BOM with Open-Source Resources and a Threat Intelligence Database; a Code Sensor Platform configured to control the operation of the Detect AI module, the Deep Scan module and the Vulnerability Scan module; and a User Interface configured to display the risks and vulnerabilities to a user.
Owner:CRANIUM AI INC

Agentless Workload Vulnerability Scanning

Systems and methods provide agentless security assessment for workloads and cloud posture control across multi-cloud environments. Discovery modules are configured with collection intervals to ingest posture control data including assets, identities, configurations, activities, network flows, and build-time artifacts. A multi-cloud configuration inventory maintains current and historical states and produces misconfiguration and identity-activity findings. For workload vulnerability evaluation, an external snapshot manager obtains point-in-time root-disk state without installing an in-workload agent. A file system data processor derives operating system and package metadata, and a detector matches the metadata against a vulnerability feed refreshed on a recurring basis to identify vulnerabilities. Identified vulnerabilities are correlated with misconfiguration and activity findings to generate prioritized risk exposures. Results are stored per workload and presented through graphical user interfaces that display risk levels, timelines, alerts, and guided remediation, enabling continuous, low-overhead security coverage for cloud workloads and configurations.
Owner:ZSCALER INC

Web application vulnerability automatic scanning method based on security agent

The invention discloses a Web application vulnerability automatic scanning method based on a security agent. The method comprises the following steps that S0, security knowledge is collected, and a penetration tool is combined with a large model to construct the security agent; s1, a user inputs a vulnerability scanning task into the security agent; s2, the security agent disassembles the vulnerability scanning task, generates a tool as required, and calls the tool; s3, vulnerability scanning and blasting are executed in sequence based on the disassembled tasks; s4, processing the data after vulnerability scanning and blasting, and performing information extraction; and S5, aggregating the extracted information as structured data, analyzing the structured data and generating a visual report. According to the method, a large model is adopted to understand task requirements, task steps are intelligently disassembled, corresponding safety tools are dynamically called, and end-to-end automatic vulnerability scanning is achieved.
Owner:CHANGCHUN QIMING INFORMATION INTEGRATION SERVICES CO LTD +1

Vulnerability processing method, electronic equipment and storage medium

The invention provides a vulnerability processing method, electronic equipment and a storage medium, and relates to the technical field of data security transmission, and the method comprises the following steps: carrying out vulnerability scanning on a data center platform, obtaining a vulnerability information list of the data center platform, determining a preset associated parameter list of the data center platform influenced by vulnerabilities, a plurality of optimization parameter values are generated for each preset associated parameter in the preset associated parameter list, so that a combination list of all the optimization parameter values is obtained, and the security risk value of the data center platform under each combination is determined based on the combination list of the optimization parameter values. And the data center platform is optimized by using the combination corresponding to the minimum security risk value, and the vulnerability influence is reduced by optimizing the preset associated parameters.
Owner:ZHEJIANG BIG DATA TRADING CENT CO LTD +1

Vulnerability scanning method and device based on template cluster and storage medium

The invention discloses a vulnerability scanning method and device based on a template cluster and a storage medium, and the method comprises the steps: responding to a vulnerability scanning request initiated by a user, and determining a scanning target of the vulnerability scanning request; loading at least one YAML classification template adapted to the scanning target to form a template cluster; performing global request merging and path optimization based on the address information of the scanning target and the request specification of each YAML classification template in the template cluster to obtain a detection request set; sending a detection request set to the scanning target, and receiving a response data set returned by the scanning target based on the detection request set; extracting a response matching rule of each YAML classification template in the template cluster, and performing matching analysis on the response data set through the response matching rule; and generating a vulnerability detection report according to a matching analysis result. According to the method, through template rule packaging and global intelligent optimization, scanning request magnitude reduction and efficient resource utilization are realized, and the detection efficiency and accuracy are remarkably improved.
Owner:SHENZHEN SHIXI TECH CO LTD

Penetration testing method and system based on multi-source data association and risk aggregation

PendingCN121814444ASecuring communicationRisk quantificationCritical information infrastructure
The invention provides a penetration testing method and system based on multi-source data association and risk aggregation, and the method comprises the steps: firstly carrying out the automatic collection and normalization processing of heterogeneous security data from penetration testing, source code detection, vulnerability scanning and the like, and breaking an information island; and intelligent association and attack path discovery are carried out on discrete vulnerabilities based on an attack chain model, and a dynamic risk quantification model fusing a business influence weight and attack path complexity is innovatively introduced to carry out comprehensive risk assessment. According to the technical scheme, the problems of data splitting, single analysis dimension and disjunction between risk assessment and services of a traditional scheme are effectively solved, accurate identification and quantitative grading of composite attack chain risks are finally achieved, the safety analysis operation efficiency is remarkably improved, expert knowledge is solidified in the system, and the safety analysis efficiency is improved. And a visual and reliable data support is provided for safety investment decision-making of key information infrastructure industries such as power generation and the like.
Owner:XIAN THERMAL POWER RES INST CO LTD +1

An intelligent method for verifying vulnerability scanning of power information system

The present application relates to a kind of electric power information system vulnerability scanning verification intelligent method.The present application is formed by the key technologies such as electric power information network Web system asset identification and vulnerability intelligent detection, and forms the intelligent, non-destructive electric power information network Web system asset identification and vulnerability intelligent detection technology system, comprehensively improves the deep level vulnerability mining of electric power information network Web system and the accurate identification ability of attack, makes the supplement for the research of company network security field in scientific research, technology and equipment etc.Aspects of research.From the angle of attack research, it will promote the research and development of related security technology and product in the field of electric power.
Owner:STATE GRID FUJIAN ELECTRIC POWER CO LTD +2

Contextual vulnerability management

Techniques are described for providing a software-based platform for context-based vulnerability management of information technology (IT) environments. In some examples, a vulnerability management application collects vulnerability scan data, from potentially many different scanning agents, as well as vulnerability information from other third-party sources. The vulnerability management application also accesses asset and activity data associated with an IT environment. The vulnerability management application can provide a user interface contextualizing vulnerabilities, based on the contextual asset or activity data, allowing for user-configured or automated vulnerability risk adjustments to impact the management and remediation of vulnerabilities for the IT environment.
Owner:CISCO TECHNOLOGY INC

Linkage banning method and device for network security threats, computer equipment, storage medium and program product

The invention relates to a linkage forbidding method and device for network security threats, equipment, a storage medium and a program product, and relates to the technical field of network security. According to the invention, the efficiency and accuracy of network security protection can be improved. The method comprises the following steps: carrying out multi-dimensional monitoring on a target network and collecting multi-source monitoring data; performing feature extraction on the multi-source monitoring data to obtain a traffic feature corresponding to the network traffic data, a log feature corresponding to the system log information, a user behavior feature corresponding to the user behavior data and a potential security vulnerability corresponding to the vulnerability scanning information; according to the flow characteristics, the log characteristics, the user behavior characteristics and the potential security vulnerabilities, performing threat analysis through a machine learning algorithm to identify potential network security threats, and determining threat levels of the network security threats by adopting an analytic hierarchy process; and formulating a forbidding strategy according to the network security threat and the threat level, and executing the forbidding strategy for the network security threat.
Owner:SHUOHUANG RAILWAY DEV +1

A black box web vulnerability scanning entry collection method and device

The application discloses a black box Web vulnerability scanning entry collection method and device, and relates to the technical field of network security. The method comprises the following steps: identifying all the interactive elements in a Web page by traversing a DOM tree; obtaining events bound to each interactive element; performing simulation operation on the events bound to each interactive element; judging whether a new Web page generated in response to the simulation operation reaches a stable state; if yes, traversing an updated DOM sub-tree, locating newly added interactive elements in the current Web page, and performing deduplication processing on the newly added interactive elements; repeatedly performing the above steps on the new Web page until a maximum recursion depth is reached or the Web page no longer generates new interactive elements. The application improves the authenticity and comprehensiveness of Web application request collection, thereby improving the detection rate of black box Web vulnerabilities.
Owner:BEIJING CHAITIN TECH CO LTD +1

Method, device and equipment for training vulnerability scanning strategy matching model

Embodiments of the present application provide a vulnerability scanning strategy matching model training method, device and equipment, and relate to the technical field of network security. The method comprises: obtaining vulnerability scanning records of network devices uploaded by a vulnerability scanning device, including: attribute information of the network devices, vulnerability scanning strategy parameters adopted by the vulnerability scanning device for scanning the network devices, and corresponding vulnerability scanning results; determining vulnerability scanning strategy target parameters corresponding to the network devices according to the vulnerability scanning strategy parameters and the corresponding vulnerability scanning results; generating device attribute samples according to the attribute information, and generating corresponding labels according to the corresponding vulnerability scanning strategy target parameters; generating a training set according to the samples and the labels; training a preset vulnerability scanning strategy matching model using the training set to obtain a model with strong matching capability, and then quickly matching vulnerability scanning strategy parameters corresponding to a network device to be scanned, i.e. a vulnerability scanning strategy, based on the model.
Owner:BEIJING RUIHESOFT CO LTD

Vulnerability scanning and attack detection methods, model training methods and devices

This application provides a vulnerability scanning attack detection method, model training method, and apparatus. The method includes: acquiring access logs and extracting key field information from the access logs; generating feature vectors based on the key field information; inputting the feature vectors into a vulnerability scanning attack detection model to obtain the analysis results output by the vulnerability scanning attack detection model; wherein, the vulnerability scanning attack detection model is obtained by pre-generating corresponding training feature vectors based on training logs, and training the model using the training feature vectors and labels used to characterize whether the training source IP address corresponding to the training logs exhibits vulnerability scanning attack behavior; the analysis results are used to characterize whether the behavior corresponding to the access logs is a vulnerability scanning attack behavior. This application improves the accuracy of vulnerability scanning attack behavior identification by analyzing the feature vectors of access logs using a machine learning model.
Owner:QI-ANXIN LEGENDSEC INFORMATION TECH (BEIJING) INC +1

Method for securely deploying a software framework on a machine learning (ML) platform and a system thereof

The present disclosure provides a method for deploying the software framework on the ML Platform in a secure manner. In particular, the present disclosure provides a method for securely deploying the ML models or the algorithms into the system by providing a multi-level scanning procedure. In an embodiment, the disclosed method performs multiple vulnerability scans on the ML model or the algorithm at multiple stages to check for malware and ensure that only models / algorithms that pass the security checks are imported into the system. If the security scan detects vulnerabilities at any stage then the files are placed in a quarantined zone and the import process is terminated. Thereby protecting the system and making it cyber-secure.
Owner:HONEYWELL INTERNATIONAL INC

Method for vulnerability scanning and an arrangement for vulnerablity scanning

An arrangement and a method for vulnerability scanning in a network, the network comprising at least one host, such as an endpoint and / or a server. The method comprises collecting host specific information relating to resources of hosts in the network by detecting and / or analyzing processes executing at the hosts and / or network traffic at the hosts, the resources of the hosts relating to at least one of the following: processes being executed at the hosts, ports used by the hosts, protocols used by the hosts. The method further comprises building and / or updating a database comprising information relating to the hosts and resources of the hosts based at least in part of the collected host specific information and performing a vulnerability scan of the network by scanning the resources of the hosts at least in part based on the built database for the hosts.
Owner:F SECURE CORP

Network vulnerability scanning system, method, electronic device and storage medium

Embodiments of the present application provide a network vulnerability scanning system, method, electronic device and storage medium, the scanning system at least includes at least one local CPE located in the user intranet, cloud CPE located in the cloud and at least two scanners in communication connection with the cloud CPE, the cloud CPE is configured with a virtual network interface for network vulnerability scanning, the local CPE is configured with a network identifier for accessing the virtual network interface, and the vulnerability scanning tunnel for network vulnerability scanning is constructed between the local CPE and the cloud CPE through the cooperation between the network identifier and the virtual network interface.
Owner:CHINA TELECOM CORP LTD

Trans-translation-unit code vulnerability scanning method, device and equipment and medium

The embodiment of the invention provides a cross-translation-unit code vulnerability scanning method and device, equipment and a medium, and the method comprises the following steps: carrying out static inspection on a target translation unit by using an abstract syntax tree, and extracting an external dependency relationship of the target translation unit based on a source code; on the basis of the extracted external dependency relationship, generating a dependency chain of the translation unit, deleting a circular reference in the dependency chain, and generating a dependency tree; according to the dependency tree, context information related to the target translation unit is loaded, and the context information comprises declarations, method signatures, function signatures, class definitions, macro definitions and namespace information; and assembling the loaded context information into a target translation unit, generating an assembled target translation unit, and executing a vulnerability detection tool to perform static vulnerability analysis on the assembled target translation unit. The efficiency and accuracy of cross-translation unit vulnerability analysis are improved through an incremental mode of loading the dependent content as required.
Owner:BEIHANG UNIV

A method for implementing island network vulnerability scanning based on Metasploit technology

ActiveCN117040815BComputer networkAttack
The application discloses a method for realizing island network vulnerability scanning based on Metasploit technology, which comprises the following steps: setting an intermediate machine with traffic relay function in the island network; connecting to the intermediate machine from an external network and building a Metasploit environment on the intermediate machine; penetrating the intermediate machine by using modular components and related attack technology in the Metasploit and obtaining the access right to the internal island network; scanning the host and running service in the island network by using the vulnerability scanning module in the Metasploit and transmitting the scanning result back to the intermediate machine. The method can discover and repair the possible security vulnerability in the island network, can comprehensively and deeply scan the island network, can flexibly scan the vulnerability and manage the security of the island network from the external network, and can transmit the scanning result back to the intermediate machine in real time to deal with the possible security threat in time.
Owner:YUNNAN POWER GRID CO LTD

Industrial control system network vulnerability scanning preprocessing method and system

The invention belongs to the technical field of industrial control network vulnerability scanning, and relates to an industrial control system network vulnerability scanning preprocessing method and system. Determining a system scanning boundary according to the network configuration information and the real-time flow data of the industrial control system, and obtaining a survival IP address list, an open port list and a scanning tolerance degree based on the system scanning boundary; obtaining a scanning task workload and scanning load intensity based on the survival IP address list, the open port list and the scanning tolerance degree, and generating a scanning task based on the scanning task workload and the scanning load intensity; and carrying out network vulnerability scanning according to the scanning task and obtaining an unverified vulnerability list, obtaining a vulnerability set according to the unverified vulnerability list and the threat score, and verifying the vulnerability set by utilizing POC. Invalid scanning and over-scanning can be avoided, the scanning range can be narrowed according to the characteristics of the industrial control system, and a reasonable scanning load is generated, so that the scanning time is effectively shortened. The false alarm rate of vulnerability detection can be reduced.
Owner:XIAN THERMAL POWER RES INST CO LTD

Part packaging method and system based on function decoupling technology

The invention relates to a function decoupling technology-based part packaging method and system. The method comprises the following steps of 1, inputting an authorization and application patent text; 2, function decoupling and minimum part division are carried out; step 3, intelligent vulnerability scanning; step 4, carrying out standardized packaging on the parts; 5, performing transaction matching and dynamic assembly; according to the method, the authorized patent text is disassembled into minimum functional parts, and functions, interfaces and technical parameters of the authorized patent text are described in a standardized manner, so that patent technology modularization and transactability are realized, and the conversion efficiency of technical achievements is improved; functional decoupling and part packaging are applied to the patent transaction field for the first time, the limitation of traditional transaction is broken through, sleeping patents can enter the transaction market again through part disassembly, the conversion rate of technical achievements is improved, part purchasing among enterprises according to needs is supported, and industrial chain technology integration is accelerated.
Owner:CHENGDU PATZHILIHU DIGITAL TECHNOLOGY CO LTD

Method, device and storage medium for vulnerability scanning without compilation

This invention discloses a compilation-independent vulnerability scanning method, apparatus, and storage medium, comprising: acquiring file information containing source code; determining the language type of the source code; parsing the source code according to the language type to obtain data model information corresponding to the source code; scanning the data model information; and outputting the vulnerability scanning results of the file information. In practical applications, when vulnerability scanning of source code is required, it can perform corresponding parsing according to different language types of different source codes to obtain data model information in a unified format, and then perform vulnerability feature matching scanning on the unified format data model information to accurately obtain vulnerability scanning results. This solves the problem that SAST products can complete analysis and scanning of different languages ​​on the same platform, no longer relying on language-specific compilers, improving versatility without needing to consider the integrity of the project code.
Owner:SECZONE TECH CO LTD

Network security equipment vulnerability scanning method and device and electronic equipment

The invention discloses a network security equipment vulnerability scanning method and device and electronic equipment, and particularly relates to the technical field of Internet of Things security, the method comprises the steps of forming a basic data set by collecting data such as equipment moving states, obtaining a target equipment preliminary screening and final list through threshold comparison and the like, obtaining a port abnormity judgment result through port detection and the like, and finally, generating a vulnerability detection key information set in combination with multi-aspect information. According to the network security equipment vulnerability scanning method and device and the electronic equipment, through multi-dimensional data acquisition and integration, the equipment moving state, the signal intensity and the environment interference data are integrated into the structured data set, a standardized data basis is provided for subsequent analysis, the problem of single data acquisition in the prior art is solved, and the data acquisition efficiency is improved. And a comprehensive data support is laid for vulnerability scanning.
Owner:GUANGDONG BITEBAO TECHNOLOGY CO LTD

Method and device for starting vulnerability scanning instruction, electronic equipment and storage medium

Embodiments of the present application provide a vulnerability scanning instruction starting method and device, electronic equipment and storage medium. The method comprises: if a starting instruction of vulnerability scanning is received, a pre-probing instruction is sent to an IP address range corresponding to a system, wherein the pre-probing instruction carries a first identifier; receiving probing information fed back by the pre-probing instruction, if the probing information indicates that the pre-probing instruction exists abnormal forwarding, determining a forwarding node corresponding to the abnormal forwarding, and adding the forwarding node to a white list, wherein the forwarding nodes in the white list are prohibited from forwarding instructions carrying the first identifier and instructions carrying a second identifier; determining a target IP address corresponding to each forwarding node in the white list, and sending a vulnerability scanning instruction to the remaining IP addresses in the IP address range except the target IP address to respond to the starting instruction, wherein the vulnerability scanning instruction carries the second identifier.
Owner:AGRICULTURAL BANK OF CHINA

Container vulnerability detection method and device, equipment and medium

The invention discloses a container vulnerability detection method and device, equipment and a medium, which are used for carrying out container vulnerability detection with low performance overhead and low invasiveness. According to the method, when a container detection instruction is received, identification information, carried in the container detection instruction, of a target container is identified, a set probe is injected into the target container based on the identification information, software information related to the target container in the running process is collected based on the probe, and the target container is detected according to the collected software information. The software information is matched with the pre-constructed vulnerability database to determine whether the container has the vulnerability, so that an agent does not need to be installed in the container, no root file system is mounted, the target container is completely not invaded, container vulnerability scanning with low performance overhead and low invasiveness can be realized, and the vulnerability scanning efficiency is improved. The software information obtained based on the probe reflects the software really loaded and executed in the actual running process of the container, false alarm can be avoided by conducting vulnerability detection based on the software information, and the vulnerability detection accuracy is improved.
Owner:CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1

Vulnerability scanning identification method and system for cybersecurity testing

This invention discloses a vulnerability scanning and identification method and system for information security compliance testing, relating to the field of information security technology. The vulnerability scanning and identification system for information security compliance testing includes an information security compliance testing identification module and an information security compliance testing adjustment module. This invention solves the problem of confusion between traditional test traffic and normal business traffic by embedding an information security compliance testing coloring mark containing a unique identifier in the protocol header of the information security compliance testing end; combined with the continuous monitoring of TCP sequence numbers and the verification mechanism of acknowledgment messages on the information security compliance testing monitoring end, it can accurately distinguish between valid test requests and network noise or packet loss; by establishing a full-cycle context coloring state, it realizes full lifecycle monitoring of test requests from entry point to key nodes and then to the return result.

Method for realizing software bill of material creation management and software component analysis function based on block chain alliance chain and micro-service architecture

The invention discloses a method for realizing software bill of material creation management and software component analysis functions based on a block chain alliance chain and a micro-service architecture, and the method comprises the steps: S1, tool construction: constructing each micro-service business and an alliance chain multi-channel network required by a tool, and deploying an intelligent contract on the alliance chain; s2, user authentication is carried out, the user is managed, and a software component analysis platform / block chain access control problem is perfected; s3, generation and distribution of a software bill of material: for storage of the software bill of material, in combination with the block chain in the previous step, performing storage in a manner of "under-chain storage and on-chain indexing" so as to protect core data from being tampered while relieving the storage pressure of the block chain; and S4, license compliance and security vulnerability scanning: on the basis of the software material list, comparing existing vulnerability information and license information according to a specific scanning strategy for a certain software project, evaluating the vulnerability risk of the software project and checking the license violation condition of the software project, and finally forming a visual report.
Owner:NANJING KUANGJI INFORMATION TECH CO LTD +1