Mandatory vulnerability update method, mandatory vulnerability scanning method, and related device
By inputting the specific details of mandatory vulnerabilities into the vulnerability scanner, and using big data analytics to automatically identify mandatory vulnerabilities in information systems, this technology solves the problems of inefficiency and errors caused by manual identification in existing technologies, and achieves accurate location and efficient updating of mandatory vulnerabilities.
Patent Information
- Application Number
- CN202211570852.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-08
- Publication Date
- 2025-10-21
- Estimated Expiration
- 2042-12-08
AI Technical Summary
Existing network vulnerability scanners require manual identification of mandatory vulnerabilities, resulting in low efficiency and error-proneness in system security operations and maintenance, and an inability to accurately identify mandatory vulnerabilities in information systems.
By matching vulnerability matching rules with historical network traffic data, essential vulnerabilities with a high probability of being exploited are screened out and updated to the vulnerability scanner. Big data analysis technology is used to automatically identify essential vulnerabilities.
It enables precise location and automatic updating of mandatory vulnerabilities, improves system security operation and maintenance efficiency, and reduces manual intervention and identification errors.
Smart Images

Figure CN116055102B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of network vulnerability scanning, and in particular to a mandatory vulnerability updating method, a mandatory vulnerability scanning method, and related equipment. Background Art
[0002] With the continuous advancement of science and technology, information technology is becoming increasingly ubiquitous, and various types of information systems are becoming more and more numerous. This has led to a growing vulnerability to cyberattacks and a growing number of exploitable network vulnerabilities in these systems. However, it's worth noting that each network vulnerability has its own degree of difficulty to exploit. Existing network vulnerability scanners often require manual identification by network security experts to determine which network vulnerabilities are mandatory and must be fixed, impacting system security. The entire mandatory vulnerability identification process is often affected by the level of network security experts, resulting in low efficiency in system security operations and maintenance, and the risk of misidentifying mandatory vulnerabilities. Summary of the Invention
[0003] In view of this, the purpose of this application is to provide a mandatory vulnerability updating method and device, a mandatory vulnerability scanning method and device, a computer device and a readable storage medium, which can use big data analysis technology to automatically enter the specific vulnerability conditions of mandatory vulnerabilities existing in today's network into the vulnerability scanner, so that operation and maintenance personnel can directly use the corresponding vulnerability scanner to effectively identify which specific mandatory vulnerabilities exist in the information system, so as to improve the system security operation and maintenance efficiency and achieve the precise positioning effect of mandatory vulnerabilities.
[0004] In order to achieve the above objectives, the technical solutions adopted in the embodiments of the present application are as follows:
[0005] In a first aspect, the present application provides a method for updating a mandatory vulnerability, the method comprising:
[0006] Obtain vulnerability matching rules for multiple network vulnerabilities to be identified;
[0007] Call the content distribution network platform to obtain historical network traffic data within the target time period;
[0008] Perform vulnerability matching on the historical network traffic data using the obtained multiple vulnerability matching rules to obtain vulnerability matching results of the historical network traffic data for each of the multiple vulnerability matching rules;
[0009] Filtering, based on the vulnerability matching results of each of the plurality of vulnerability matching rules, a plurality of target required vulnerabilities with a high probability of being exploited from the plurality of network vulnerabilities to be identified;
[0010] The vulnerability information of the screened target mandatory vulnerabilities is updated to the target vulnerability scanner.
[0011] In an optional embodiment, when the vulnerability matching result is represented by the number of vulnerability occurrences corresponding to the to-be-identified network vulnerability in the historical network traffic data, the step of screening out a plurality of target mandatory vulnerabilities having a high probability of being exploited from the plurality of to-be-identified network vulnerabilities based on the vulnerability matching results of each of the plurality of vulnerability matching rules includes:
[0012] Arrange the number of occurrences of each of the plurality of network vulnerabilities to be identified in the historical network traffic data in descending order to obtain a corresponding occurrence ranking result;
[0013] Extracting, from the plurality of network vulnerabilities to be identified according to a preset number of vulnerabilities, a plurality of target network vulnerabilities that are ranked highest in the occurrence ranking result;
[0014] Each extracted target network vulnerability is treated as a target required vulnerability.
[0015] In an optional embodiment, when the vulnerability matching result is represented by the number of vulnerability users corresponding to the to-be-identified network vulnerability in the historical network traffic data, the step of screening out a plurality of target mandatory vulnerabilities with a high probability of being exploited from the plurality of to-be-identified network vulnerabilities based on the vulnerability matching results of each of the plurality of vulnerability matching rules includes:
[0016] Arrange the number of vulnerability users of each of the multiple to-be-identified network vulnerabilities at the historical network traffic data in descending order to obtain a corresponding usage ranking result;
[0017] Extracting, from the plurality of network vulnerabilities to be identified, a plurality of target network vulnerabilities that are ranked highest in the usage count ranking result according to a preset number of vulnerabilities;
[0018] Each extracted target network vulnerability is treated as a target required vulnerability.
[0019] In an optional embodiment, when the vulnerability matching result is represented by a vulnerability threat level of the corresponding to-be-identified network vulnerability when it existed in the historical network traffic data, the step of screening out a plurality of target mandatory vulnerabilities with a high probability of being exploited from the plurality of to-be-identified network vulnerabilities based on the vulnerability matching results of each of the plurality of vulnerability matching rules includes:
[0020] Filtering out a plurality of network vulnerabilities to be extracted from the plurality of network vulnerabilities to be identified, which exist in the historical network traffic data;
[0021] Arrange the vulnerability threat levels of the plurality of network vulnerabilities to be extracted in descending order to obtain corresponding threat level ranking results;
[0022] Extracting a preset number of target network vulnerabilities from the plurality of network vulnerabilities to be extracted, and extracting a plurality of target network vulnerabilities that are ranked highest in the threat level ranking result;
[0023] Each extracted target network vulnerability is treated as a target required vulnerability.
[0024] In a second aspect, the present application provides a mandatory vulnerability scanning method, the method comprising:
[0025] Obtain vulnerability information of each of a plurality of target mandatory vulnerabilities recorded by a target vulnerability scanner, wherein the target vulnerability scanner updates the mandatory vulnerabilities using the mandatory vulnerability updating method described in any one of the aforementioned implementations;
[0026] For each target mandatory vulnerability, the target vulnerability scanner is called according to the vulnerability information of the target mandatory vulnerability to perform network vulnerability detection on the target information system.
[0027] In an optional embodiment, the step of calling the target vulnerability scanner to perform network vulnerability detection on the target information system according to the vulnerability information of the target mandatory vulnerability includes:
[0028] According to the vulnerability information of the target required vulnerability, determining the system part to be detected corresponding to the target required vulnerability in the target information system;
[0029] Calling the target vulnerability scanner to perform vulnerability feature matching on the part of the system to be detected according to the vulnerability matching rules of the target required vulnerability;
[0030] When the vulnerability feature matching is successful, it is determined that the target information system has the target required vulnerability.
[0031] In a third aspect, the present application provides a mandatory vulnerability update device, the device comprising:
[0032] A matching rule acquisition module is used to obtain vulnerability matching rules for each of multiple network vulnerabilities to be identified;
[0033] A historical traffic acquisition module is used to call the content distribution network platform to obtain historical network traffic data within a target time period;
[0034] a vulnerability rule matching module, configured to perform vulnerability matching on the historical network traffic data using the obtained plurality of vulnerability matching rules, and obtain vulnerability matching results of the historical network traffic data using the respective plurality of vulnerability matching rules;
[0035] A required vulnerability screening module, configured to screen out a plurality of target required vulnerabilities with a high probability of being exploited from the plurality of network vulnerabilities to be identified based on the vulnerability matching results of each of the plurality of vulnerability matching rules;
[0036] The mandatory vulnerability recording module is used to update the vulnerability information of the multiple screened target mandatory vulnerabilities to the target vulnerability scanner.
[0037] In a fourth aspect, the present application provides a mandatory vulnerability scanning device, the device comprising:
[0038] a vulnerability information acquisition module, configured to acquire vulnerability information of each of a plurality of target mandatory vulnerabilities recorded by a target vulnerability scanner, wherein the target vulnerability scanner updates the mandatory vulnerabilities using the mandatory vulnerability update method described in any one of the aforementioned embodiments;
[0039] The compulsory vulnerability detection module is used to call the target vulnerability scanner to perform network vulnerability detection on the target information system according to the vulnerability information of each target compulsory vulnerability.
[0040] In a fifth aspect, the present application provides a computer device comprising a processor and a memory, wherein the memory stores a computer program that can be executed by the processor, and the processor can execute the computer program to implement the mandatory vulnerability update method described in any one of the aforementioned embodiments, or to implement the mandatory vulnerability scanning method described in any one of the aforementioned embodiments.
[0041] In a sixth aspect, the present application provides a readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, it implements the required vulnerability update method described in any one of the aforementioned embodiments, or implements the required vulnerability scanning method described in any one of the aforementioned embodiments.
[0042] In this case, the beneficial effects of the embodiments of the present application may include the following:
[0043] This application obtains vulnerability matching rules for multiple network vulnerabilities to be identified, calls a content distribution network platform to obtain historical network traffic data within a target time period, and then performs vulnerability matching on the multiple vulnerability matching rules obtained with the historical network traffic data respectively. Based on the vulnerability matching results of the multiple vulnerability matching rules at the historical network traffic data, multiple target mandatory vulnerabilities with a higher probability of being exploited are screened out from the multiple network vulnerabilities to be identified. Finally, the vulnerability information of the screened multiple target mandatory vulnerabilities is updated to the target vulnerability scanner, and the specific vulnerability status of the mandatory vulnerabilities existing in the current network is automatically entered into the vulnerability scanner by using big data analysis technology, so that operation and maintenance personnel can directly use the corresponding vulnerability scanner to effectively identify which mandatory vulnerabilities exist in the information system, thereby effectively improving the system security operation and maintenance efficiency and achieving the precise positioning effect of mandatory vulnerabilities.
[0044] In order to make the above-mentioned objects, features and advantages of the present application more obvious and easy to understand, preferred embodiments are given below and described in detail with reference to the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0045] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following is a brief introduction to the drawings required for use in the embodiments. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other relevant drawings can be obtained based on these drawings without creative work.
[0046] Figure 1 A schematic diagram of the composition of a computer device provided in an embodiment of the present application;
[0047] Figure 2 A flowchart of a method for updating mandatory vulnerabilities provided in an embodiment of the present application;
[0048] Figure 3 A flowchart of a required vulnerability scanning method provided in an embodiment of the present application;
[0049] Figure 4 A schematic diagram of the composition of a mandatory vulnerability update device provided in an embodiment of the present application;
[0050] Figure 5 A schematic diagram of the composition of the required vulnerability scanning device provided in an embodiment of the present application.
[0051] Icons: 10-Computer equipment; 11-Memory; 12-Processor; 13-Communication unit; 100-Required vulnerability update device; 110-Matching rule acquisition module; 120-Historical traffic acquisition module; 130-Vulnerability rule matching module; 140-Required vulnerability screening module; 150-Required vulnerability recording module; 200-Required vulnerability scanning device; 210-Vulnerability information acquisition module; 220-Required vulnerability detection module. DETAILED DESCRIPTION
[0052] To make the objectives, technical solutions, and advantages of the embodiments of the present application more clear, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the accompanying drawings of the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Generally, the components of the embodiments of the present application described and shown in the drawings herein can be arranged and designed in various different configurations.
[0053] Therefore, the following detailed description of the embodiments of the present application provided in the accompanying drawings is not intended to limit the scope of the present application for protection, but merely represents selected embodiments of the present application. All other embodiments obtained by persons of ordinary skill in the art based on the embodiments in the present application without creative work are within the scope of protection of the present application.
[0054] It should be noted that similar reference numerals and letters denote similar items in the following drawings, and therefore, once an item is defined in one drawing, it does not need to be further defined or explained in subsequent drawings.
[0055] In the description of the present application, it should be understood that relational terms such as the terms "first" and "second" are merely used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply the existence of any such actual relationship or order between these entities or operations. Moreover, the terms "comprise", "include" or any other variants thereof are intended to cover non-exclusive inclusion, so that the process, method, article or equipment comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or also include elements inherent to such process, method, article or equipment. In the absence of further restrictions, the elements defined by the statement "comprise a ..." do not exclude the presence of other identical elements in the process, method, article or equipment comprising the elements. For those of ordinary skill in the art, the specific meanings of the above terms in the present application can be understood according to the specific circumstances.
[0056] The following describes some embodiments of the present application in detail with reference to the accompanying drawings. In the absence of conflict, the following embodiments and features in the embodiments may be combined with each other.
[0057] Please refer to Figure 1 , Figure 1 : is a schematic diagram of the composition of the computer device 10 provided in an embodiment of the present application. In the embodiment of the present application, the computer device 10 can be connected to at least one vulnerability scanner to automatically identify multiple mandatory vulnerabilities with a high probability of being exploited in the current network using big data analysis technology, and input the specific vulnerability status of the mandatory vulnerabilities existing in the current network into the connected vulnerability scanner, so that operation and maintenance personnel can directly use the corresponding vulnerability scanner to effectively identify which mandatory vulnerabilities exist in the information system, thereby effectively improving the efficiency of system security operation and maintenance, and achieving the precise positioning effect of mandatory vulnerabilities. Among them, the computer device 10 can be, but is not limited to, a personal computer, a laptop computer, a tablet computer, a server, etc.
[0058] In the embodiment of the present application, the computer device 10 may include a memory 11, a processor 12, and a communication unit 13. The memory 11, the processor 12, and the communication unit 13 are electrically connected to each other directly or indirectly to achieve data transmission or interaction. For example, the memory 11, the processor 12, and the communication unit 13 may be electrically connected to each other via one or more communication buses or signal lines.
[0059] In the embodiment of the present application, the memory 11 may be, but is not limited to, a random access memory (RAM), a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), etc. The memory 11 is used to store a computer program, and the processor 12 may execute the computer program accordingly after receiving an execution instruction.
[0060] In this embodiment, the processor 12 can be an integrated circuit chip with signal processing capabilities. The processor 12 can be a general-purpose processor, including at least one of a central processing unit (CPU), a graphics processing unit (GPU), a network processor (NP), a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, and discrete hardware components. The general-purpose processor can be a microprocessor or any conventional processor, etc., which can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application.
[0061] In this embodiment, the communication unit 13 is used to establish a communication connection between the computer device 10 and other electronic devices through a network, and to send and receive data through the network, wherein the network includes a wired communication network and a wireless communication network. For example, the computer device 10 can communicate with a server operating a content delivery network (CDN) platform through the communication unit 13 to obtain historical network traffic data of the current network within a preset time period through the CDN platform, wherein the preset time period can be the time period of the day at which the traffic data is obtained, or it can be a time period of at least one day before the time point at which the traffic data is obtained. The specific distribution of the preset time periods can be configured differently by the user of the computer device 10 according to needs.
[0062] Optionally, in an embodiment of the present application, the computer device 10 may further include a mandatory vulnerability update device 100, and the mandatory vulnerability update device 100 may include at least one software function module that can be stored in the memory 11 in the form of software or firmware or solidified in the operating system of the computer device 10. The processor 12 can be used to execute the executable modules stored in the memory 11, such as the software function modules and computer programs included in the mandatory vulnerability update device 100. The computer device 10 can automatically enter the specific vulnerability status of the mandatory vulnerabilities existing in the current network into the vulnerability scanner using big data analysis technology through the mandatory vulnerability update device 100, so as to achieve the automatic update effect of the mandatory vulnerability status for the vulnerability scanner, so that the operation and maintenance personnel can directly use the corresponding vulnerability scanner to effectively identify which mandatory vulnerabilities exist in the information system, thereby improving the system security operation and maintenance efficiency and achieving the precise positioning effect of the mandatory vulnerabilities.
[0063] Optionally, in an embodiment of the present application, the computer device 10 may further include a mandatory vulnerability scanning device 200, and the mandatory vulnerability scanning device 200 may include at least one software function module that can be stored in the memory 11 in the form of software or firmware or solidified in the operating system of the computer device 10. The processor 12 may be used to execute the executable modules stored in the memory 11, such as the software function modules and computer programs included in the mandatory vulnerability scanning device 200. The computer device 10 may call a vulnerability scanner with mandatory vulnerability status entered through the mandatory vulnerability scanning device 200 to preferentially locate and identify possible mandatory vulnerabilities in the information system, so as to improve the efficiency of system security operation and maintenance, and achieve the precise positioning effect of mandatory vulnerabilities.
[0064] It is understandable that Figure 1 The block diagram shown is only a schematic diagram of the composition of the computer device 10. The computer device 10 may also include Figure 1 More or fewer components than shown, or with Figure 1 Different configurations shown. Figure 1 Each component shown in the figure can be implemented by hardware, software or a combination thereof.
[0065] In the present application, to ensure that the computer device 10 can automatically input the specific vulnerability status of the mandatory vulnerabilities existing in the current network into the vulnerability scanner using big data analysis technology, so as to achieve the automatic update effect of the mandatory vulnerability status for the vulnerability scanner, so that operation and maintenance personnel can directly use the corresponding vulnerability scanner to effectively identify which mandatory vulnerabilities exist in the information system, thereby improving the efficiency of system security operation and maintenance, and achieving the precise positioning effect of mandatory vulnerabilities, the embodiment of the present application provides a mandatory vulnerability update method to achieve the aforementioned purpose. The mandatory vulnerability update method provided by the present application is described in detail below.
[0066] Please refer to Figure 2 , Figure 2 3 is a flow chart of a method for updating mandatory vulnerabilities provided in an embodiment of the present application. In an embodiment of the present application, the method for updating mandatory vulnerabilities may include steps S310 to S350.
[0067] Step S310: Obtain vulnerability matching rules for each of a plurality of network vulnerabilities to be identified.
[0068] In this embodiment, the network vulnerability to be identified is a network vulnerability that needs to be tested to see if it is a required vulnerability. Each vulnerability matching rule corresponds to a network vulnerability to be identified. The vulnerability matching rule can be composed of the vulnerability name, vulnerability threat level (e.g., high, medium, low), and vulnerability location rules. Taking the Apache Log4j2 remote code execution vulnerability as an example, the vulnerability name in the vulnerability matching rule of this network vulnerability is "CVE-2021-44228", the vulnerability threat level is "high", and the vulnerability location rule is "url~ / "(?i)(\$|\%24)(\{|\%7b).*j.*n.*d.*i.*(\:|\%3a)" / user_agent~ / "(?i)(\$|\%24)(\{|\%7b).*j.*n.*d.*i.*(\:|\%3a)" / referer~ / "(?i)(\$|\%24)(\{|\%7b).*j.*n.*d.*i.*(\:|\%3a)" / ".
[0069] Step S320: Call the content distribution network platform to obtain historical network traffic data within the target time period.
[0070] In one implementation of this embodiment, the target time period may be a time period of the day before the current traffic data acquisition time point. The computer device 10 may control the content distribution network platform to collect historical network traffic data of the entire Internet within the target time period by sending a traffic data acquisition request to the server operating the content distribution network platform.
[0071] In step S330 , vulnerability matching is performed on the obtained multiple vulnerability matching rules and the historical network traffic data respectively, to obtain vulnerability matching results of the multiple vulnerability matching rules in the historical network traffic data.
[0072] In this embodiment, the computer device 10 can perform vulnerability matching on each vulnerability matching rule of a plurality of network vulnerabilities to be identified with the acquired historical network traffic data to determine the specific number of occurrences, the specific number of users (for example, the total number of IP addresses using the vulnerability), and the specific vulnerability threat level of one or several network vulnerabilities to be identified in the historical network traffic data, thereby obtaining vulnerability matching results of each of the plurality of vulnerability matching rules in the historical network traffic data, wherein the vulnerability matching result can be represented by any one of the matching results of the number of vulnerability occurrences, the number of users of the vulnerability, and the vulnerability threat level.
[0073] Step S340 , based on the vulnerability matching results of the plurality of vulnerability matching rules, a plurality of target mandatory vulnerabilities with a high probability of being exploited are screened out from the plurality of network vulnerabilities to be identified.
[0074] In this embodiment, after obtaining the vulnerability matching results of multiple vulnerability matching rules for the historical network traffic data, the computer device 10 can sort the multiple network vulnerabilities to be identified according to the vulnerability matching results of each vulnerability matching rule according to the vulnerability exploitation probability, so as to screen out the top-ranked multiple network vulnerabilities from the multiple network vulnerabilities to be identified as the multiple target required vulnerabilities with a higher probability of exploitation existing in the current network.
[0075] Optionally, when the vulnerability matching result of each vulnerability matching rule is represented by the number of vulnerability occurrences of the corresponding to-be-identified network vulnerability in the historical network traffic data, the step of screening out a plurality of target required vulnerabilities with a high probability of being exploited from the plurality of to-be-identified network vulnerabilities based on the vulnerability matching results of each of the plurality of vulnerability matching rules may include:
[0076] Arrange the number of occurrences of each of the plurality of network vulnerabilities to be identified in the historical network traffic data in descending order to obtain a corresponding occurrence ranking result;
[0077] Extracting, from the plurality of network vulnerabilities to be identified according to a preset number of vulnerabilities, a plurality of target network vulnerabilities that are ranked highest in the occurrence ranking result;
[0078] Each extracted target network vulnerability is treated as a target required vulnerability.
[0079] Thus, the present application can select multiple network vulnerabilities that are frequently exploited from the current network by executing the first specific step process included in step S340 above, as multiple target mandatory vulnerabilities with a high probability of being exploited in the current network. The preset number of vulnerabilities can be 20, 10, or 15, and the specific value of the preset number of vulnerabilities can be configured by the user of the computer device 10 based on the required accuracy of mandatory vulnerability identification. The smaller the preset number of vulnerabilities, the higher the accuracy of the mandatory vulnerability identification.
[0080] Optionally, when the vulnerability matching result of each vulnerability matching rule is represented by the number of vulnerability users corresponding to the to-be-identified network vulnerability in the historical network traffic data, the step of screening out a plurality of target required vulnerabilities with a high probability of being exploited from the plurality of to-be-identified network vulnerabilities based on the vulnerability matching results of each of the plurality of vulnerability matching rules may include:
[0081] Arrange the number of vulnerability users of each of the multiple to-be-identified network vulnerabilities at the historical network traffic data in descending order to obtain a corresponding usage ranking result;
[0082] Extracting, from the plurality of network vulnerabilities to be identified, a plurality of target network vulnerabilities that are ranked highest in the usage count ranking result according to a preset number of vulnerabilities;
[0083] Each extracted target network vulnerability is treated as a target required vulnerability.
[0084] Therefore, the present application can select multiple network vulnerabilities with a large number of users from the current network as multiple target required vulnerabilities with a high probability of being exploited in the current network by executing the second specific step process included in the above step S340.
[0085] Optionally, when the vulnerability matching result of each vulnerability matching rule is represented by the vulnerability threat level of the corresponding to-be-identified network vulnerability when it existed in the historical network traffic data, the step of screening out a plurality of target mandatory vulnerabilities with a high probability of being exploited from the plurality of to-be-identified network vulnerabilities based on the vulnerability matching results of each of the plurality of vulnerability matching rules may include:
[0086] Filtering out a plurality of network vulnerabilities to be extracted from the plurality of network vulnerabilities to be identified, which exist in the historical network traffic data;
[0087] Arrange the vulnerability threat levels of the plurality of network vulnerabilities to be extracted in descending order to obtain corresponding threat level ranking results;
[0088] Extracting a preset number of target network vulnerabilities from the plurality of network vulnerabilities to be extracted, and extracting a plurality of target network vulnerabilities that are ranked highest in the threat level ranking result;
[0089] Each extracted target network vulnerability is treated as a target required vulnerability.
[0090] Therefore, the present application can select multiple network vulnerabilities that actually exist and have a high threat level from the current network by executing the third specific step process included in the above step S340, as multiple target mandatory vulnerabilities that have a high probability of being exploited in the current network.
[0091] Step S350: updating vulnerability information of the screened multiple target mandatory vulnerabilities to the target vulnerability scanner.
[0092] In this embodiment, the vulnerability information of the target mandatory vulnerability may include a vulnerability name corresponding to the target mandatory vulnerability and a vulnerability matching rule corresponding to the target mandatory vulnerability.
[0093] Therefore, the present application can automatically enter the specific vulnerability status of the mandatory vulnerabilities existing in the current network into the vulnerability scanner by executing the above steps S310 to S350, using big data analysis technology, so as to achieve the automatic update effect of the mandatory vulnerability status for the vulnerability scanner, so that the operation and maintenance personnel can directly use the corresponding vulnerability scanner to effectively identify which specific mandatory vulnerabilities exist in the information system, thereby improving the system security operation and maintenance efficiency and achieving the precise positioning effect of the mandatory vulnerabilities.
[0094] In this application, to ensure that the computer device 10 can call a vulnerability scanner that has recorded mandatory vulnerability status to prioritize the location and identification of possible mandatory vulnerabilities in the information system, thereby improving the efficiency of system security operation and maintenance and achieving the precise location of mandatory vulnerabilities, an embodiment of this application provides a mandatory vulnerability scanning method to achieve the aforementioned purpose. The mandatory vulnerability scanning method provided in this application is described in detail below.
[0095] Please refer to Figure 3 , Figure 3 4 is a flow chart of a required vulnerability scanning method provided by an embodiment of the present application. In the embodiment of the present application, the required vulnerability scanning method may include steps S410 to S420.
[0096] Step S410: obtaining vulnerability information of each of a plurality of target mandatory vulnerabilities recorded by the target vulnerability scanner.
[0097] In this embodiment, the target vulnerability scanner uses any of the above-mentioned mandatory vulnerability update methods to update the mandatory vulnerabilities. The vulnerability information of each target mandatory vulnerability recorded by the target vulnerability scanner may include the vulnerability name and vulnerability matching rule of the corresponding target mandatory vulnerability.
[0098] Step S420 : For each target mandatory vulnerability, a target vulnerability scanner is called according to the vulnerability information of the target mandatory vulnerability to perform network vulnerability detection on the target information system.
[0099] In this embodiment, the target information system is the information system that currently requires vulnerability detection. The computer device 10 can call the target vulnerability scanner to prioritize the location and identification of mandatory vulnerabilities that may exist in the target information system, thereby improving the efficiency of system security operation and maintenance and achieving accurate location of mandatory vulnerabilities.
[0100] Optionally, for each target mandatory vulnerability recorded by the target vulnerability scanner, the step of calling the target vulnerability scanner to perform network vulnerability detection on the target information system according to the vulnerability information of the target mandatory vulnerability may include:
[0101] According to the vulnerability information of the target required vulnerability, determining the system part to be detected corresponding to the target required vulnerability in the target information system;
[0102] Calling the target vulnerability scanner to perform vulnerability feature matching on the part of the system to be detected according to the vulnerability matching rules of the target required vulnerability;
[0103] When the vulnerability feature matching is successful, it is determined that the target information system has the target required vulnerability.
[0104] Therefore, the present application can achieve the effect of automatic detection of required vulnerabilities of the target information system by executing the specific step process of the above-mentioned step S420.
[0105] This application can execute the above steps S410 to S420 to call the vulnerability scanner that has entered the mandatory vulnerability status to prioritize the location and identification of possible mandatory vulnerabilities in the information system, so as to improve the system security operation and maintenance efficiency and achieve the precise location of mandatory vulnerabilities.
[0106] In this application, to ensure that the computer device 10 can effectively execute the aforementioned mandatory vulnerability update method, this application implements the aforementioned functions by dividing the mandatory vulnerability update device 100 stored in the computer device 10 into functional modules. The specific components of the mandatory vulnerability update device 100 provided in this application and applied to the aforementioned computer device 10 are described below.
[0107] Please refer to Figure 4 , Figure 4 1 is a schematic diagram of the components of the mandatory vulnerability update device 100 provided in an embodiment of the present application. In this embodiment of the present application, the mandatory vulnerability update device 100 may include a matching rule acquisition module 110, a historical traffic acquisition module 120, a vulnerability rule matching module 130, a mandatory vulnerability screening module 140, and a mandatory vulnerability recording module 150.
[0108] The matching rule acquisition module 110 is configured to acquire vulnerability matching rules for each of a plurality of network vulnerabilities to be identified.
[0109] The historical traffic acquisition module 120 is used to call the content distribution network platform to obtain historical network traffic data within a target time period.
[0110] The vulnerability rule matching module 130 is used to perform vulnerability matching on the obtained multiple vulnerability matching rules and the historical network traffic data respectively, and obtain vulnerability matching results of the multiple vulnerability matching rules in the historical network traffic data.
[0111] The mandatory vulnerability screening module 140 is configured to screen out a plurality of target mandatory vulnerabilities with a high probability of being exploited from a plurality of network vulnerabilities to be identified based on the vulnerability matching results of the plurality of vulnerability matching rules.
[0112] The mandatory vulnerability recording module 150 is used to update the vulnerability information of the screened multiple target mandatory vulnerabilities to the target vulnerability scanner.
[0113] It should be noted that the basic principles and technical effects of the mandatory vulnerability update device 100 provided in the embodiment of the present application are the same as those of the aforementioned mandatory vulnerability update method. For the sake of brevity, any parts not mentioned in this embodiment can be referred to the description of the aforementioned mandatory vulnerability update method.
[0114] In this application, to ensure that the computer device 10 can effectively execute the aforementioned mandatory vulnerability scanning method, this application implements the aforementioned functions by dividing the mandatory vulnerability scanning device 200 stored in the computer device 10 into functional modules. The specific components of the mandatory vulnerability scanning device 200 provided in this application and applied to the aforementioned computer device 10 are described below.
[0115] Please refer to Figure 5 , Figure 5 FIG. 2 is a schematic diagram of the components of a mandatory vulnerability scanning device 200 provided in an embodiment of the present application. In the embodiment of the present application, the mandatory vulnerability scanning device 200 may include a vulnerability information acquisition module 210 and a mandatory vulnerability detection module 220 .
[0116] The vulnerability information acquisition module 210 is configured to acquire vulnerability information of each of a plurality of target mandatory vulnerabilities recorded by a target vulnerability scanner, wherein the target vulnerability scanner updates the mandatory vulnerabilities using any of the mandatory vulnerability update methods described above.
[0117] The mandatory vulnerability detection module 220 is used to call a target vulnerability scanner to perform network vulnerability detection on a target information system according to vulnerability information of each target mandatory vulnerability.
[0118] It should be noted that the basic principles and technical effects of the mandatory vulnerability scanning device 200 provided in the embodiment of the present application are the same as those of the aforementioned mandatory vulnerability scanning method. For the sake of brevity, any parts not mentioned in this embodiment can be referred to the description of the aforementioned mandatory vulnerability scanning method.
[0119] In the embodiments provided in this application, it should be understood that the disclosed devices and methods can also be implemented in other ways. The device embodiments described above are merely schematic. For example, the flowcharts and block diagrams in the accompanying drawings show the possible architectures, functions and operations of the devices, methods and computer program products according to the embodiments of the present application. In this regard, each box in the flowchart or block diagram can represent a module, a program segment or a part of the code, and the module, program segment or a part of the code contains one or more executable instructions for implementing the specified logical functions. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in an order different from that marked in the accompanying drawings. For example, two consecutive boxes can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, and the combination of boxes in the block diagram and / or flowchart, can be implemented using a dedicated hardware-based system that performs the specified function or action, or can be implemented using a combination of dedicated hardware and computer instructions.
[0120] In addition, the functional modules in each embodiment of the present application can be integrated together to form an independent part, or each module can exist separately, or two or more modules can be integrated to form an independent part. If the various functions provided by the present application are implemented in the form of software functional modules and sold or used as independent products, they can be stored in a storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art or the part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a readable storage medium, including several instructions for making a computer device (which can be a personal computer, a server, or a network device, etc.) perform all or part of the steps of the method described in each embodiment of the present application. The aforementioned readable storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
[0121] In summary, in the mandatory vulnerability updating method and device, mandatory vulnerability scanning method and device, computer equipment and readable storage medium provided in the embodiments of the present application, the present application obtains the vulnerability matching rules of each of the multiple network vulnerabilities to be identified, and calls the content distribution network platform to obtain the historical network traffic data within the target time period, and then performs vulnerability matching on the multiple vulnerability matching rules obtained with the historical network traffic data respectively, and based on the vulnerability matching results of each of the multiple vulnerability matching rules at the historical network traffic data, screens out multiple target mandatory vulnerabilities with a higher probability of being exploited from the multiple network vulnerabilities to be identified, and finally updates the vulnerability information of the multiple target mandatory vulnerabilities screened out to the target vulnerability scanner, so as to use big data analysis technology to automatically enter the specific vulnerability status of the mandatory vulnerabilities existing in the current network into the vulnerability scanner, so that the operation and maintenance personnel can directly use the corresponding vulnerability scanner to effectively identify which specific mandatory vulnerabilities exist in the information system, thereby effectively improving the system security operation and maintenance efficiency and achieving the precise positioning effect of the mandatory vulnerabilities.
[0122] The above are merely various embodiments of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.
Claims
1. A method for updating a required vulnerability, characterized in that: The method comprises: Obtain vulnerability matching rules for multiple network vulnerabilities to be identified; Call the content distribution network platform to obtain historical network traffic data within the target time period; Perform vulnerability matching on the historical network traffic data using the obtained multiple vulnerability matching rules to obtain vulnerability matching results for the historical network traffic data for each of the multiple vulnerability matching rules, wherein the vulnerability matching results are represented by any one of the following matching results: the number of vulnerability occurrences, the number of people using the vulnerability, and the vulnerability threat level corresponding to the network vulnerability to be identified in the historical network traffic data; According to the vulnerability matching results of each of the plurality of vulnerability matching rules, a plurality of target mandatory vulnerabilities with a high probability of being exploited are screened from the plurality of network vulnerabilities to be identified, wherein the mandatory vulnerabilities are network vulnerabilities that must be repaired and affect system security; The vulnerability information of the screened target mandatory vulnerabilities is updated to the target vulnerability scanner.
2. The method according to claim 1, characterized in that When the vulnerability matching result is represented by the number of vulnerability occurrences corresponding to the to-be-identified network vulnerability in the historical network traffic data, the step of screening out a plurality of target required vulnerabilities having a high probability of being exploited from the plurality of to-be-identified network vulnerabilities according to the vulnerability matching results of each of the plurality of vulnerability matching rules comprises: Arrange the number of occurrences of each of the plurality of network vulnerabilities to be identified in the historical network traffic data in descending order to obtain a corresponding occurrence ranking result; Extracting, from the plurality of network vulnerabilities to be identified according to a preset number of vulnerabilities, a plurality of target network vulnerabilities that are ranked highest in the occurrence ranking result; Each extracted target network vulnerability is treated as a target required vulnerability.
3. The method according to claim 1, characterized in that When the vulnerability matching result is represented by the number of vulnerability users corresponding to the network vulnerability to be identified in the historical network traffic data, the step of screening out a plurality of target required vulnerabilities with a high probability of being exploited from the plurality of network vulnerabilities to be identified based on the vulnerability matching results of each of the plurality of vulnerability matching rules includes: Arrange the number of vulnerability users of each of the multiple to-be-identified network vulnerabilities at the historical network traffic data in descending order to obtain a corresponding usage ranking result; Extracting, from the plurality of network vulnerabilities to be identified, a plurality of target network vulnerabilities that are ranked highest in the usage count ranking result according to a preset number of vulnerabilities; Each extracted target network vulnerability is treated as a target required vulnerability.
4. The method according to claim 1, wherein When the vulnerability matching result is represented by a vulnerability threat level corresponding to the to-be-identified network vulnerability when it existed in the historical network traffic data, the step of screening out a plurality of target mandatory vulnerabilities having a high probability of being exploited from the plurality of to-be-identified network vulnerabilities according to the vulnerability matching results of each of the plurality of vulnerability matching rules includes: Filtering out a plurality of network vulnerabilities to be extracted from the plurality of network vulnerabilities to be identified, which exist in the historical network traffic data; Arrange the vulnerability threat levels of the plurality of network vulnerabilities to be extracted in descending order to obtain corresponding threat level ranking results; Extracting, from the plurality of network vulnerabilities to be extracted, a plurality of target network vulnerabilities that are ranked highest in the threat level ranking result according to a preset number; Each extracted target network vulnerability is treated as a target required vulnerability.
5. A required vulnerability scanning method, characterized in that: The method comprises: Obtain vulnerability information of each of a plurality of target mandatory vulnerabilities recorded by a target vulnerability scanner, wherein the target vulnerability scanner updates the mandatory vulnerabilities using the mandatory vulnerability updating method according to any one of claims 1 to 4; For each target mandatory vulnerability, the target vulnerability scanner is called according to the vulnerability information of the target mandatory vulnerability to perform network vulnerability detection on the target information system.
6. The method according to claim 5, characterized in that The step of calling the target vulnerability scanner to perform network vulnerability detection on the target information system according to the vulnerability information of the target required vulnerability includes: According to the vulnerability information of the target required vulnerability, determining the system part to be detected corresponding to the target required vulnerability in the target information system; Calling the target vulnerability scanner to perform vulnerability feature matching on the part of the system to be detected according to the vulnerability matching rules of the target required vulnerability; When the vulnerability feature matching is successful, it is determined that the target information system has the target required vulnerability.
7. A mandatory vulnerability update device, characterized in that: The device comprises: A matching rule acquisition module is used to obtain vulnerability matching rules for each of multiple network vulnerabilities to be identified; A historical traffic acquisition module is used to call the content distribution network platform to obtain historical network traffic data within a target time period; a vulnerability rule matching module, configured to perform vulnerability matching on the historical network traffic data using the obtained plurality of vulnerability matching rules, thereby obtaining vulnerability matching results for each of the plurality of vulnerability matching rules in the historical network traffic data, wherein the vulnerability matching results are represented by any one of the following matching results: the number of occurrences of the vulnerability in the historical network traffic data, the number of users of the vulnerability, and the vulnerability threat level corresponding to the network vulnerability to be identified; a mandatory vulnerability screening module, configured to screen, based on the vulnerability matching results of each of the plurality of vulnerability matching rules, a plurality of target mandatory vulnerabilities with a high probability of being exploited from the plurality of network vulnerabilities to be identified, wherein mandatory vulnerabilities are network vulnerabilities that must be repaired and that affect system security; The mandatory vulnerability recording module is used to update the vulnerability information of the multiple screened target mandatory vulnerabilities to the target vulnerability scanner.
8. A required vulnerability scanning device, characterized in that: The device comprises: a vulnerability information acquisition module, configured to acquire vulnerability information of each of a plurality of target mandatory vulnerabilities recorded by a target vulnerability scanner, wherein the target vulnerability scanner updates the mandatory vulnerabilities using the mandatory vulnerability update method according to any one of claims 1 to 4; The compulsory vulnerability detection module is used to call the target vulnerability scanner to perform network vulnerability detection on the target information system according to the vulnerability information of each target compulsory vulnerability.
9. A computer device, characterized in that: It includes a processor and a memory, the memory stores a computer program that can be executed by the processor, and the processor can execute the computer program to implement the mandatory vulnerability update method described in any one of claims 1-4, or implement the mandatory vulnerability scanning method described in any one of claims 5-6.
10. A readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, it implements the mandatory vulnerability updating method described in any one of claims 1-4, or implements the mandatory vulnerability scanning method described in any one of claims 5-6.
Citation Information
Patent Citations
Vulnerability display method and device
CN114969764A