Network security event vulnerability detection method and system

Through the combination of real-time vulnerability scanning and historical survival cycle data, the probability of remaining survival time of the vulnerability is calculated, and the microservice call chain topology is used to analyze the impact of vulnerability, the problem of vulnerability assessment bias in the existing technology is solved, and the time sensitivity evaluation and accurate analysis of vulnerability risks are achieved.

CN120090851AInactive Publication Date: 2025-06-03GUANGZHOU BORIDA TECH CO LTD
View PDF 0 Cites 3 Cited by

Patent Information

Application Number
CN202510261823.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-06
Publication Date
2025-06-03
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Existing network security incident vulnerability detection methods have vulnerability exploitability prediction bias in dynamic environments, and cannot track fast replacement of container instances and real-time changes in service dependencies in real time, resulting in the risk of deviation of vulnerability assessment results from the real risk.

Method used

Through real-time vulnerability scanning combined with historical survival cycle data, the logical model is trained, and the remaining survival time probability of the vulnerability is calculated, and the microservice call chain topology is used to analyze the location of the vulnerable component, and the location contribution weight is calculated based on path contribution analysis and downstream dependency ratio, the actual attack surface impact coefficient of the vulnerability is derived, and the time sensitivity assessment of vulnerability risk is realized.

Benefits of technology

Break through the limitations of traditional static vulnerability scanning that cannot measure the vulnerability life cycle, realize time-sensitive assessment of vulnerability risks, reduce resource waste caused by expired vulnerability false positives, improve the accuracy of vulnerability risk analysis, and ensure that vulnerability risk assessment is synchronized with operating status.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120090851A_ABST
    Figure CN120090851A_ABST
Patent Text Reader

Abstract

The invention discloses a network security event vulnerability detection method and system, particularly relates to the field of network security event detection, and is used for solving the problems of vulnerability life cycle evaluation and dynamic risk quantification in a containerized environment. According to the method, the defect of traditional static scanning in vulnerability life cycle measurement is overcome, vulnerability risk time-sensitive evaluation is realized, and resource waste caused by misinformation of expired vulnerabilities is reduced. Analyzing a vulnerability component position by using micro-service call chain topology, calculating a position contribution weight in combination with path contribution and a downstream dependency ratio, deducing an actual attack surface influence coefficient in linkage with a vulnerability survival time probability, accurately depicting a vulnerability propagation potential and an influence range, calculating a container instance level dynamic risk score, and calculating a vulnerability level dynamic risk score; the asset list and the risk score are updated in real time after the container capacity expansion and contraction event is triggered, and it is ensured that the evaluation result is synchronous with the actual operation state.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security event detection, and more specifically, to a method and system for detecting network security event vulnerabilities. Background Art

[0002] In a cloud-native architecture, business systems achieve dynamic scaling through containerization technologies (such as Docker) and service orchestration platforms (such as Kubernetes), and the instance lifecycle may be as short as seconds. At the same time, the traffic management mechanism of the service mesh (such as Istio) enables service dependencies to change in real time. For example, a microservice instance is automatically replaced due to load balancing, or the replica set is temporarily expanded due to failover.

[0003] Existing network security event vulnerability detection methods have deviations in predicting the exploitability of vulnerabilities in a dynamic environment due to relying on static asset snapshots and periodic scanning mechanisms. The specific manifestations are as follows: When container instances are quickly replaced, the vulnerability scan results are seriously out of touch with the real-time asset status. For example, a destroyed high-risk instance is still marked as having a vulnerability, while a newly generated instance is missed due to not being included in the scan scope in time, ultimately leading to the system misjudging the actual survival status of the vulnerability and the impact scope of the attack surface, and the threat assessment result deviating from the real risk. To solve the above problems, a technical solution is provided. Summary of the Invention

[0004] To overcome the above-mentioned defects of the prior art, embodiments of the present invention provide a method and system for detecting network security event vulnerabilities. By combining real-time vulnerability scanning with historical survival cycle data to train a logic model and calculating the probability of the remaining survival time of the vulnerability, it breaks through the limitation of traditional static vulnerability scanning that cannot measure the vulnerability lifecycle, realizes the time sensitivity assessment of vulnerability risks, and reduces the waste of resources caused by false alarms of expired vulnerabilities. Using the microservice call chain topology to analyze the location of the vulnerable components, and combining path contribution analysis with downstream dependency ratio to calculate the location contribution weight, and linking with the vulnerability survival time probability to deduce the actual attack surface impact coefficient of the vulnerability, accurately depicting the propagation potential and impact scope of the vulnerability, avoiding the impact assessment deviation caused by simply relying on the CVSS score, and improving the accuracy of vulnerability risk analysis. By non-linearly integrating the CVSS base score, attack surface impact coefficient, and survival time probability of the vulnerability, calculating the dynamic risk score at the container instance level, making the risk assessment more in line with the actual impact of the vulnerability in the running environment, avoiding score distortion caused by linear accumulation, and adjusting the asset inventory and risk score in real time after the container scaling event is triggered to ensure that the vulnerability risk assessment is synchronized with the running state, so as to solve the problems raised in the above background art.

[0005] To achieve the above object, the present invention provides the following technical solutions:

[0006] A method for detecting vulnerabilities in network security events, comprising the steps:

[0007] S1. Based on real-time traffic data to analyze the interaction relationship between instances, combined with the metadata of the orchestration engine to construct a dynamic asset topology, and generate a real-time asset inventory;

[0008] S2. Relying on the information of surviving container instances in the real-time asset inventory, perform vulnerability scanning and match with the vulnerability database, and use historical survival cycle data to train a logical function model to output the probability value of the remaining survival time of each vulnerability;

[0009] S3. According to the probability value of the vulnerability survival time, analyze the microservice call chain dependency relationship in the service mesh, and combine the position contribution weight and survival time probability of the vulnerability-affected component in the call chain to calculate the actual attack surface impact coefficient of the vulnerability in the dynamic environment;

[0010] S4. Use the attack surface impact coefficient to fuse the basic CVSS score of the vulnerability and the probability value of the vulnerability survival time to generate a dynamic risk score by instance dimension, and trigger an update of the real-time asset inventory and a linked update of the risk score when a container scaling event is detected.

[0011] In a preferred embodiment, step S1 includes the following contents:

[0012] Parse the communication records of the real-time traffic data of the service mesh, extract the network addresses and port mappings of the container instances; obtain the unique instance identifier, creation timestamp and survival status from the metadata of the orchestration engine; count the number of valid communications within a predetermined time window, and calculate the interaction intensity between instances through inverse normalization and exponential decay processing, so as to construct a dynamic asset topology of container instance nodes and interaction intensity edge weights, and generate a real-time asset inventory including network information, time stamps and interaction data.

[0013] In a preferred embodiment, step S2 includes the following contents:

[0014] According to the information of surviving container instances in the real-time asset inventory, perform vulnerability scanning on the target instance and match it with the vulnerability database, extract the first detection time of each vulnerability, calculate the existing time of the vulnerability, and at the same time extract the historical survival cycle data of the corresponding instance, and count the median survival cycle of the corresponding instance as the benchmark duration of the container life cycle.

[0015] In a preferred embodiment, step S2 further includes the following contents:

[0016] Use a logical function to model the probability of the remaining survival time of the vulnerability, use the deviation between the existing time of the vulnerability and the median survival cycle as the input, construct an exponential decay form of the calculation model, and finally output the probability of the remaining survival time of the vulnerability and establish the corresponding relationship between the vulnerability information and the instance identifier.

[0017] In a preferred embodiment, step S3 includes the following contents:

[0018] According to the remaining survival time probability of the vulnerability and the surviving container instance information in the real-time asset list, the microservice call chain dependency is obtained from the service grid analysis to build a call chain dependency graph, where each node is a microservice component and each directed edge is a call relationship.

[0019] In a preferred embodiment, step S3 further includes the following contents:

[0020] For components with vulnerabilities in container instances, identify all call paths from the entry node to the corresponding component, count the number of path hops, and use the path hop count plus one as the denominator and the natural logarithm of the path hop count plus two as the multiplier to calculate the single contribution value of each path, and add them up to form an aggregated path contribution value; at the same time, count the ratio of the number of downstream nodes of the vulnerable component to the total number of nodes in the call chain as the downstream dependency ratio, and the product of the two is the position contribution weight, which is then multiplied by the probability of the remaining survival time of the vulnerability to determine the actual attack surface impact coefficient of the vulnerability.

[0021] In a preferred embodiment, step S4 includes the following contents:

[0022] Based on the actual attack surface impact coefficient of the vulnerability and the probability of the remaining survival time of the vulnerability, and combined with the CVSS basic score of the vulnerability extracted from the vulnerability database, a dynamic risk scoring model for container instances is constructed. For each vulnerability detected in each container instance, the risk factors of all vulnerabilities in the container instance are accumulated to obtain the dynamic risk score of the container instance.

[0023] In a preferred embodiment, step S4 includes the following contents:

[0024] Container expansion and contraction events trigger real-time asset inventory updates and linked updates to risk scores, ensuring that risk assessments are synchronized with the dynamic state of the operating environment.

[0025] A network security incident vulnerability detection system, comprising: a panoramic topology module, a remaining life calculation module, an attack surface quantification module and a risk quantification module;

[0026] The panoramic topology module analyzes the interaction between instances based on the real-time traffic data of the service grid, builds a dynamic asset topology and generates a real-time asset list based on the metadata of the orchestration engine. Its output includes the network attributes, creation timestamp and survival status of the container instance.

[0027] The remaining life estimation module relies on the real-time asset list output by the panoramic topology module to perform vulnerability scanning on the surviving instances and match them with the vulnerability database. It also uses the historical survival cycle data to train the logic function model, thereby outputting the remaining survival time probability value of each vulnerability.

[0028] Based on the vulnerability survival time probability value output by the remaining life measurement module, the attack surface quantification module parses the dependency relationship of the microservice call chain in the service mesh, and calculates the actual attack surface impact coefficient of the vulnerability in the dynamic environment by combining the position contribution weight of the vulnerability-affected component in the call chain.

[0029] The risk quantification module then uses the attack surface impact coefficient output by the attack surface quantification module, integrates the CVSS base score of the vulnerability and the vulnerability survival time probability value output by the remaining life measurement module, generates a dynamic risk score at the container instance level through a non-linear fusion model, and updates the real-time asset inventory and risk score when the container scaling event is triggered.

[0030] The technical effects and advantages of a network security event vulnerability detection method and system of the present invention:

[0031] The present invention combines real-time vulnerability scanning with historical survival cycle data to train a logic model, calculates the probability of the remaining survival time of the vulnerability, breaks through the limitation that traditional static vulnerability scanning cannot measure the vulnerability life cycle, realizes the time sensitivity assessment of vulnerability risk, and reduces the waste of resources caused by false alarms of expired vulnerabilities. By parsing the location of the vulnerability-affected component using the microservice call chain topology, combining path contribution analysis with downstream dependency ratio to calculate the location contribution weight, and jointly deriving the actual attack surface impact coefficient of the vulnerability with the vulnerability survival time probability, accurately depicts the propagation potential and influence range of the vulnerability, avoids the influence assessment deviation caused by simply relying on the CVSS score, and improves the accuracy of vulnerability risk analysis. By non-linearly integrating the CVSS base score, attack surface impact coefficient and survival time probability of the vulnerability, calculates the dynamic risk score at the container instance level, makes the risk assessment more in line with the actual impact of the vulnerability in the running environment, avoids the score distortion caused by linear accumulation, and adjusts the asset inventory and risk score in real time after the container scaling event is triggered, ensures that the vulnerability risk assessment is synchronized with the running state, overcomes the lag of traditional methods in the dynamic container environment, and improves the accuracy of vulnerability priority ranking and repair decision-making. Brief Description of the Drawings

[0032] Figure 1 It is a schematic flow chart of a network security event vulnerability detection method of the present invention.

[0033] Figure 2 It is a schematic structural diagram of a network security event vulnerability detection system of the present invention. Detailed Embodiments

[0034] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0035] Embodiment 1: Figure 1 A network security event vulnerability detection method of the present invention is provided, including:

[0036] S1. Based on the real-time traffic data, analyze the interaction relationship between instances, combine with the metadata of the orchestration engine to construct a dynamic asset topology, and generate a real-time asset inventory.

[0037] S2. Relying on the information of the surviving container instances in the real-time asset inventory, perform vulnerability scanning and match with the vulnerability database, and use the historical survival cycle data to train a logical function model, and output the probability value of the remaining survival time of each vulnerability.

[0038] S3. According to the probability value of the vulnerability survival time, analyze the microservice call chain dependency relationship in the service mesh, and combine the position contribution weight and the survival time probability of the vulnerability-affected component in the call chain to calculate the actual attack surface impact coefficient of the vulnerability in the dynamic environment.

[0039] S4. Using the attack surface impact coefficient, fuse the CVSS basic score of the vulnerability and the probability value of the vulnerability survival time to generate a dynamic risk score by instance dimension, and trigger an update of the real-time asset inventory and a linked update of the risk score when a container scaling event is detected.

[0040] In a containerized environment, the high dynamicity of the microservice architecture results in a short life cycle of instances, frequent creation, destruction, and scaling events of instances. Traditional static asset management methods are difficult to adapt to the rapidly changing operating state, difficult to accurately depict the current surviving instances and their associated relationships, and thus affect the accuracy of subsequent vulnerability detection. The service mesh provides full-scale traffic monitoring data, and the container orchestration engine maintains the deployment information of instances. Combining the two can form a real-time dynamic asset view to provide complete, accurate, and traceable instance information, enabling vulnerability detection and risk assessment to be carried out based on the real operating environment rather than relying on lagging static information.

[0041] Step S1 includes the following contents:

[0042] Obtain real-time traffic data from the service mesh, extract all communication traffic records, and parse the network addresses and port information of the source and target. Synchronously extract the unique identifier, creation timestamp, and current survival status of all surviving container instances from the metadata of the orchestration engine, and establish the association between the container instance and its basic network information.

[0043] A service mesh is an infrastructure layer specifically designed to manage the communication and data transmission between services in a distributed microservices environment. By deploying lightweight agents beside each service, common network functions such as load balancing, fault recovery, security authentication, traffic control, and monitoring between services are separated from the business logic and centrally managed by a unified control plane, enabling automated service discovery, traffic scheduling, and access control, thereby enhancing the stability, security, and observability of the system and ensuring efficient and reliable communication between nodes in the microservices architecture.

[0044] For all communication traffic records, based on the network address and port information of the source and target, establish the connection relationship between container instances. Traverse all communication traffic records, count the number of interactions between each pair of container instances, form a traffic interaction matrix between instances, and each matrix element represents the interaction intensity between the corresponding instance pair. Combine the metadata of the orchestration engine, match the instance pairs in the interaction matrix with the surviving container instances, eliminate the associated data of terminated instances, and only retain the interaction information of current surviving instances.

[0045] Build a dynamic asset topology based on the interaction matrix, use the surviving container instances as topology nodes, and set weights for the connections between nodes according to the interaction intensity. Utilize the instance identifier, creation timestamp, and survival status in the metadata, combined with the network address, port information, and topology structure, to generate a real-time asset inventory. Each record item in the real-time asset inventory includes the instance unique identifier, creation timestamp, current survival status, network address, port mapping, and topology association information.

[0046] Among them, the interaction intensity is calculated based on communication traffic records. Each communication traffic record includes the source instance, target instance, and communication timestamp. First, filter out the communication records between surviving container instances. For each pair of surviving instances, count the number of valid communications within a set time window. Define the interaction intensity as the communication frequency per unit time, and use a time decay function to adjust the historical communication contribution. The calculation method is as follows: For instance A and instance B, in the set of communication records within the time window, sort them in ascending order of the timestamp, calculate the time interval between adjacent communications, and perform inverse normalization processing on the time interval. The sum of all normalized values is the basic interaction value. To enhance the temporal characteristics, introduce an exponential decay factor to assign lower weights to communications with longer time intervals. After setting the decay coefficient, adjust the basic interaction value to obtain the final interaction intensity. This value can be used to describe the real-time interaction situation between instances and serve as the weight value of the connection edge in the dynamic asset topology. The calculation of the interaction intensity ensures that the dynamic asset topology can accurately reflect the real-time interaction relationship between instances and provides data support for subsequent vulnerability propagation path and attack surface assessment.

[0047] By combining service mesh traffic data with container orchestration engine metadata, a real-time asset inventory and a dynamic asset topology are constructed, enabling the accurate identification of live instances and the dynamic characterization of their associated structures. This ensures that vulnerability detection is based on the current running state, avoiding deviations in vulnerability detection results caused by lagging asset information, and providing high-timeliness basic data support for subsequent vulnerability analysis and dynamic risk assessment based on the instance life cycle.

[0048] Based on the information of live container instances in the real-time asset inventory, vulnerability data is accurately obtained by matching vulnerability scans with a vulnerability database. Then, combined with the median survival cycle parameter and the logical function model obtained by training with the historical survival cycle data of container instances, a probability output of the remaining survival time of the vulnerability is formed, providing data support for subsequent analysis of microservice call chain dependencies and calculation of dynamic attack surface impact coefficients.

[0049] Step S2 includes the following content:

[0050] Based on the real-time asset inventory generated in step S1, container instances in the live state are strictly selected from it, and a vulnerability scan operation is performed on each container instance. During the scan, the vulnerability information existing in the container instance is detected and recorded, and the information content includes the unique identifier of the vulnerability, the vulnerability detection time, and related vulnerability attributes. Subsequently, the scan results are compared with the pre-constructed vulnerability database one by one to achieve accurate matching and standardization of vulnerability information and obtain detailed vulnerability description data. The survival time data set of container instances is sorted out using the historical survival cycle data of container instances, and the median survival cycle of container instances is calculated, represented by the symbol T M indicating the typical duration of the container life cycle; for each vulnerability, its first detection time is extracted, and the difference between the current moment and the vulnerability detection time is used as the duration of the vulnerability existence, represented by the symbol A v indicating. A logical function is used to predict the probability of the remaining survival time of the vulnerability, and its calculation formula is:

[0051]

[0052] where P represents the probability of the remaining survival time of the vulnerability, and K is a balance factor reflecting the sensitivity of the prediction function, determined by fitting historical data; the calculated probability value is established in correspondence with the container instance and vulnerability information to form an output data set containing the unique identifier of the container instance, detailed vulnerability information, and the probability value of the remaining survival time of the vulnerability. This data set provides an accurate quantitative basis for subsequent calculation of the actual attack surface impact coefficient of the vulnerability and dynamic risk scoring.

[0053] Accurately scan and standardize the matching of vulnerability information for container instances. At the same time, use historical lifecycle data to train a logical function model to obtain the remaining survival time probability value of each vulnerability, and construct an output dataset that is connected to the unique identifier of the container instance and the detailed attributes of the vulnerability, providing an accurate probability quantification basis for vulnerability risk assessment in a dynamic environment.

[0054] Based on the remaining survival time probability of the vulnerability obtained in step S2, the real-time asset inventory information, and the microservice call chain dependency relationship resolved through the service mesh, clarify each call path, the number of path hops, and the downstream dependency distribution where the vulnerable component is located in the container instance. By calculating the contribution value of each call path and quantifying the proportion of the vulnerable component in the downstream dependent nodes in the call chain, a location contribution weight is formed, providing comprehensive and accurate data support for calculating the actual attack surface impact coefficient later.

[0055] Step S3 includes the following content:

[0056] Based on the remaining survival time probability of the vulnerability output in step S2 and the information of the surviving container instances in the real-time asset inventory, obtain the microservice call chain dependency relationship from the service mesh resolution, and construct a call chain dependency graph with microservice components as nodes and directed call relationships as edges. For the components with vulnerabilities in the container instance, identify all call paths from the entry node (node without incoming edges) to the vulnerable component, and count the number of hops of each call path; for each call path, use the number of hops of the call path plus one as the denominator and the natural logarithm of the number of hops of the call path plus two as the multiplier to calculate the single-path contribution value, reflecting that the impact decreases as the path gets longer but the multi-path effect is reflected; accumulate the single-path contribution values of each call path to form an aggregated path contribution value, fully demonstrating the comprehensive situation of the vulnerable component depending on multiple paths. At the same time, count the number of downstream nodes of the vulnerable component in the call chain dependency graph and calculate the downstream dependency ratio, that is, the ratio of the number of downstream nodes to the total number of nodes in the call chain, to quantify the propagation effect of the vulnerable component in the dependency network. The location contribution weight is determined by the product of the aggregated path contribution value and the downstream dependency ratio, which not only reflects the contribution attenuation of the vulnerable component in all call paths but also reflects the importance of its propagation risk in the dependency network. Use the remaining survival time probability of the vulnerability output in step S2 and the calculated location contribution weight for multiplication operation to determine the actual attack surface impact coefficient of the vulnerability; the output dataset includes the unique identifier of the container instance, the unique identifier of the vulnerability, the remaining survival time probability of the vulnerability, the location contribution weight, and the finally calculated attack surface impact coefficient, providing an accurate quantification basis for generating a dynamic risk score at the container instance dimension by fusing the basic CVSS score of the vulnerability later.

[0057] The actual attack surface impact coefficient is a comprehensive quantitative index based on the probability of the remaining vulnerability survival time and the position contribution weight of the vulnerability in the microservice call chain, aiming to objectively measure the potential ability of the vulnerability to spread risks in the containerized environment. A higher coefficient value indicates that the vulnerability not only has a higher probability of persistent existence, but also is located at key nodes or multiple entry paths in the call chain, thus triggering a wider range of risk diffusion in the microservice dependency network; conversely, a lower value reflects that the vulnerability exists for a shorter time or its location has limited impact on the overall system. This index combines real-time asset data with the call chain topology structure to provide accurate and traceable data support for dynamic risk scoring, which helps to reasonably prioritize vulnerability repairs and formulate targeted protection measures.

[0058] The calculation result of the actual attack surface impact coefficient combines the persistent risk of the vulnerability's existence with the importance of the vulnerability component's position in the call chain, objectively reflecting the potential of the vulnerability to spread risks in the container instance. The output data set clearly shows the impact strength of each vulnerability in the call chain structure, providing a clear and traceable quantitative basis for generating a dynamic risk score by fusing the CVSS base score of the vulnerability.

[0059] Based on the actual attack surface impact coefficient of the vulnerability calculated in step S3 and the probability of the remaining vulnerability survival time obtained in step S2, combined with the CVSS base score of the vulnerability in the vulnerability database, a risk assessment model for container instances is constructed to comprehensively quantify the impact of each vulnerability in different dimensions, so as to reflect the survival trend, propagation ability and influence scope of the vulnerability in the microservice architecture. At the same time, due to the dynamic life cycle characteristics of container instances, the number of instances in the running environment may change due to reasons such as business load adjustment, resource scheduling strategy or container failure recovery. Therefore, when scaling events occur, the asset inventory needs to be updated in real time, and the risk at the instance level needs to be re-evaluated to ensure that the vulnerability risk assessment is synchronized with the actual running environment, providing an accurate basis for subsequent security protection and priority repair strategies.

[0060] Step S4 includes the following contents:

[0061] Based on the actual attack surface impact coefficient of the vulnerability output in step S3 and the probability of the remaining vulnerability survival time output in step S2, combined with the CVSS base score of the vulnerability extracted from the vulnerability database, a dynamic risk scoring model for container instances is constructed. For each vulnerability detected in each container instance, the following non-linear fusion formula is used to calculate the comprehensive risk factor:

[0062]

[0063] Among them, B v represents the CVSS base score of the vulnerability, and the natural logarithm function is used to achieve non-linear smoothing of the score; I vis the impact coefficient of the actual attack surface of the vulnerability, which is transformed into a cube root and then amplified nonlinearly through an exponential function; P v is the probability of the remaining survival time of the vulnerability, and the risk saturation effect is reflected by square root and exponential decay. All vulnerability risk factors in the container instance are accumulated to obtain the dynamic risk score of the container instance, which is expressed as:

[0064]

[0065] V(CI) represents the set of all detected vulnerabilities in the container instance. Container expansion and contraction events trigger real-time asset inventory updates and linked updates to risk scores, ensuring that risk assessment is synchronized with the dynamic state of the operating environment.

[0066] Container scaling events refer to the process in which the container orchestration engine dynamically adjusts the number of container instances in a containerized microservice environment based on real-time load demand, resource utilization, and system maintenance requirements. This includes horizontal scaling (adding new container instances to cope with traffic surges and improve system carrying capacity) and horizontal scaling (reducing container instances to reduce resource consumption and optimize system performance). It also covers container instance replacements caused by fault recovery, version updates, or resource scheduling optimization, thereby ensuring real-time matching of the operating environment with business needs and security protection measures.

[0067] Container scaling events are triggered by the container orchestration engine, which monitors changes in the status of container instances in real time. After detecting the addition or termination of an instance, the real-time asset list is updated according to the specific information in the scaling event. The updated content includes the instance's IP address, port mapping, creation timestamp, and survival status. The updated real-time asset list will serve as the basic data input for subsequent vulnerability scanning, probability calculation of the remaining survival time of vulnerabilities, and resolution of microservice call chain dependencies. It will automatically trigger scanning and comparison of vulnerability data of newly added instances, and recalculate the impact coefficient of the actual attack surface of the vulnerability. Finally, the nonlinear fusion model is used to regenerate the dynamic risk score of the container instance dimension, thereby ensuring that the risk score remains consistent with changes in the container environment in real time.

[0068] By integrating the vulnerability CVSS basic score, the vulnerability's actual attack surface impact coefficient, and the probability of the vulnerability's remaining survival time, a nonlinear calculation model is used to generate a dynamic risk score for the container instance dimension, which can effectively quantify the actual risk level of the vulnerability in the current environment. When container scaling events occur, the asset list and risk score are adjusted in real time to ensure that the assessment results always reflect the latest operating status, thereby improving the accuracy and response speed of vulnerability management and providing a more timely quantitative basis for vulnerability repair decisions.

[0069] Based on the real-time traffic analysis of the service grid and the integration of the orchestration engine metadata, a dynamic asset list containing the network information, creation timestamp and survival status of the container instance is constructed to accurately capture the surviving instances, improve the vulnerability detection coverage and avoid misjudgment of the destroyed instances. Through real-time vulnerability scanning combined with historical survival cycle data to train the logical model, the probability of the remaining survival time of the vulnerability is calculated, breaking through the limitation of traditional static vulnerability scanning that cannot measure the vulnerability life cycle, realizing the time sensitivity assessment of vulnerability risks, and reducing the waste of resources caused by expired vulnerability false alarms. The location of the vulnerability-affected component is analyzed by using the microservice call chain topology, and the location contribution weight is calculated by combining the path contribution analysis and the downstream dependency ratio. The actual attack surface impact coefficient of the vulnerability is derived in conjunction with the vulnerability survival time probability, accurately depicting the propagation potential and impact range of the vulnerability, avoiding the impact assessment bias caused by relying solely on CVSS scores, and improving the accuracy of vulnerability risk analysis. By nonlinearly integrating the vulnerability CVSS basic score, attack surface impact coefficient and survival time probability, the dynamic risk score at the container instance level is calculated to make the risk assessment more consistent with the actual impact of the vulnerability in the operating environment and avoid the score distortion caused by linear accumulation. After the container expansion and reduction event is triggered, the asset list and risk score are adjusted in real time to ensure that the vulnerability risk assessment is synchronized with the operating status, overcome the lag of traditional methods in dynamic container environments, and improve the accuracy of vulnerability priority sorting and repair decisions.

[0070] Embodiment 2: Figure 2 The present invention provides a network security event vulnerability detection system, comprising:

[0071] Panoramic topology module, remaining life calculation module, attack surface quantification module and risk quantification module;

[0072] The panoramic topology module analyzes the interaction between instances based on the real-time traffic data of the service grid, builds a dynamic asset topology and generates a real-time asset list based on the metadata of the orchestration engine. Its output includes the network attributes, creation timestamp and survival status of the container instance.

[0073] The remaining life estimation module relies on the real-time asset list output by the panoramic topology module to perform vulnerability scanning on the surviving instances and match them with the vulnerability database. It also uses the historical survival cycle data to train the logic function model, thereby outputting the remaining survival time probability value of each vulnerability.

[0074] The attack surface quantification module is based on the vulnerability survival time probability value output by the remaining life measurement module. It also analyzes the dependency relationship of the microservice call chain in the service grid and calculates the actual attack surface impact coefficient of the vulnerability in a dynamic environment by combining the position contribution weight of the vulnerability-affecting component in the call chain.

[0075] The risk quantification module utilizes the attack surface impact coefficient output by the attack surface quantification module, integrates the CVSS base score of the vulnerability and the probability value of the vulnerability survival time output by the remaining life calculation module, generates a dynamic risk score at the container instance level through a non-linear fusion model, and updates the real-time asset inventory and risk score when the container scaling event is triggered.

[0076] The above formulas are all dimensionless and take their numerical values for calculation. The formulas are obtained by collecting a large amount of data for software simulation to get a formula closest to the real situation. The preset parameters in the formulas are set by those skilled in the art according to the actual situation.

[0077] It should be noted that the system of the present invention can be deployed on the device itself to achieve embedded applications, or can also run on a PC or other terminals with a user interface, so as to meet various hardware environments and usage requirements.

[0078] Only some exemplary embodiments of the present invention have been described by way of illustration above. Undoubtedly, for those of ordinary skill in the art, without departing from the spirit and scope of the present invention, the described embodiments can be modified in various different ways. Therefore, the above drawings and descriptions are illustrative in nature and should not be construed as limiting the protection scope of the claims of the present invention.

[0079] It should be noted that in this article, if there are relational terms such as first and second, they are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "including one..." does not exclude the existence of another identical element in the process, method, article or device including the element.

[0080] The above is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present application can easily think of changes or substitutions, which should all be covered within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the protection scope of the claims.

Claims

1. A network security event vulnerability detection method, characterized in that: Includes steps: S1. Analyze the interaction relationship between instances based on real-time traffic data, build dynamic asset topology based on orchestration engine metadata, and generate a real-time asset list; S2. Based on the surviving container instance information in the real-time asset list, perform vulnerability scanning and match with the vulnerability database, and use the historical survival cycle data to train the logic function model to output the remaining survival time probability value of each vulnerability; S3. According to the vulnerability survival time probability value, analyze the microservice call chain dependency in the service grid, combine the position contribution weight and survival time probability of the vulnerability-affected component in the call chain, and calculate the actual attack surface impact coefficient of the vulnerability in a dynamic environment; S4. Using the attack surface impact coefficient, the vulnerability CVSS basic score and the vulnerability survival time probability value are integrated to generate a dynamic risk score based on the instance dimension. When a container expansion or reduction event is detected, the real-time asset list is updated and the risk score is updated in conjunction.

2. A network security event vulnerability detection method according to claim 1, characterized in that: Step S1 includes the following contents: The service grid uses real-time traffic data to parse communication records and extract the network address and port mapping of the container instance. The orchestration engine metadata obtains the instance unique identifier, creation timestamp, and survival status. The number of effective communications within the predetermined time window is counted, and the interaction intensity between instances is calculated through inverse normalization and exponential decay processing. This constructs a dynamic asset topology of container instance nodes and interaction intensity edge weights, and generates a real-time asset list containing network information, time stamps, and interaction data.

3. A network security event vulnerability detection method according to claim 2, characterized in that: Step S2 includes the following contents: Based on the surviving container instance information in the real-time asset list, vulnerability scanning is performed on the target instance and matched with the vulnerability database. The first detection time of each vulnerability is extracted, and the existence time of the vulnerability is calculated. At the same time, the historical survival cycle data of the corresponding instance is extracted, and the median survival cycle of the corresponding instance is calculated, which is used as the benchmark duration of the container life cycle.

4. A network security event vulnerability detection method according to claim 3, characterized in that: Step S2 also includes the following contents: A logical function is used to model the probability of the remaining survival time of the vulnerability. The deviation between the existing time of the vulnerability and the median survival period is taken as input, and a calculation model in the form of exponential decay is constructed. Finally, the probability of the remaining survival time of the vulnerability is output and the correspondence between the vulnerability information and the instance identifier is established.

5. A network security event vulnerability detection method according to claim 4, characterized in that: Step S3 includes the following contents: According to the remaining survival time probability of the vulnerability and the surviving container instance information in the real-time asset list, the microservice call chain dependency is obtained from the service grid analysis to build a call chain dependency graph, where each node is a microservice component and each directed edge is a call relationship.

6. A network security event vulnerability detection method according to claim 5, characterized in that: Step S3 also includes the following: For components with vulnerabilities in container instances, identify all call paths from the entry node to the corresponding component, count the number of path hops, and use the path hop count plus one as the denominator and the natural logarithm of the path hop count plus two as the multiplier to calculate the single contribution value of each path, and add them up to form an aggregated path contribution value; at the same time, count the ratio of the number of downstream nodes of the vulnerable component to the total number of nodes in the call chain as the downstream dependency ratio, and the product of the two is the position contribution weight, which is then multiplied by the probability of the remaining survival time of the vulnerability to determine the actual attack surface impact coefficient of the vulnerability.

7. A network security event vulnerability detection method according to claim 6, characterized in that: Step S4 includes the following contents: Based on the actual attack surface impact coefficient of the vulnerability and the probability of the remaining survival time of the vulnerability, and combined with the CVSS basic score of the vulnerability extracted from the vulnerability database, a dynamic risk scoring model for container instances is constructed. For each vulnerability detected in each container instance, the risk factors of all vulnerabilities in the container instance are accumulated to obtain the dynamic risk score of the container instance.

8. A network security event vulnerability detection method according to claim 7, characterized in that: Step S4 includes the following contents: Container expansion and contraction events trigger real-time asset inventory updates and linked updates to risk scores, ensuring that risk assessments are synchronized with the dynamic state of the operating environment.

9. A network security event vulnerability detection system, used to implement a network security event vulnerability detection method according to any one of claims 1 to 8, characterized in that: include: Panoramic topology module, remaining life calculation module, attack surface quantification module and risk quantification module; The panoramic topology module analyzes the interaction between instances based on the real-time traffic data of the service grid, builds a dynamic asset topology and generates a real-time asset list based on the metadata of the orchestration engine. Its output includes the network attributes, creation timestamp and survival status of the container instance. The remaining life estimation module relies on the real-time asset list output by the panoramic topology module to perform vulnerability scanning on the surviving instances and match them with the vulnerability database. It also uses the historical survival cycle data to train the logic function model, thereby outputting the remaining survival time probability value of each vulnerability. The attack surface quantification module is based on the vulnerability survival time probability value output by the remaining life measurement module. It also analyzes the dependency relationship of the microservice call chain in the service grid and calculates the actual attack surface impact coefficient of the vulnerability in a dynamic environment by combining the position contribution weight of the vulnerability-affecting component in the call chain. The risk quantification module uses the attack surface impact coefficient output by the attack surface quantification module, integrates the vulnerability CVSS basic score and the vulnerability survival time probability value output by the remaining life measurement module, and generates a dynamic risk score at the container instance level through a nonlinear fusion model. It also realizes real-time asset inventory and risk score updates when container expansion and contraction events are triggered.

Citation Information

Cited By

  • Network security monitoring method and system based on dynamic vulnerability verification

    CN120389908A

  • A network security monitoring method and system based on dynamic vulnerability verification

    CN120389908B

  • A vulnerability life cycle sla management and intelligent repair suggestion method

    CN122513208A