Vulnerability risk level determination method, related system and computer storage medium

By obtaining and analyzing the information to be tested at the kernel layer and inputting it into the vulnerability risk model to evaluate the compilation vulnerability and operation vulnerability, the problem of difficulty in effectively detecting and evaluating the kernel layer vulnerability risks in the existing technology is solved, and a more accurate and comprehensive vulnerability risk assessment is achieved.

CN120162786APending Publication Date: 2025-06-17WUHAN ANTIY MOBILE SECURITY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311726085.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-14
Publication Date
2025-06-17

AI Technical Summary

Technical Problem

The risk of kernel-level vulnerabilities is difficult to effectively detect and evaluate the prior art, especially when possible vulnerabilities are not fully considered during compilation and runtime.

Method used

By obtaining the target kernel layer's test information, including basic information, configuration information and code, and inputting it into the trained vulnerability risk model, we can determine the compilation vulnerability and operation vulnerability, and then evaluate the vulnerability risk level.

Benefits of technology

This method can more comprehensively evaluate the risk of kernel-level vulnerabilities, combining compile-time and run-time vulnerability detection to reduce false positive rates and improve detection accuracy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120162786A_ABST
    Figure CN120162786A_ABST
Patent Text Reader

Abstract

The invention discloses a kernel vulnerability detection method, a related system and a computer storage medium. The method can comprise the steps of obtaining to-be-detected information of a target kernel layer; inputting the to-be-tested information of the target kernel layer into a vulnerability risk model to obtain a compiling vulnerability and a running vulnerability of the target kernel layer; and determining a vulnerability risk level of the target kernel layer based on the compiling vulnerability of the target kernel layer and the operation vulnerability of the target kernel layer. Therefore, the method adopts a mode of inputting the to-be-tested information of the target kernel layer into the vulnerability risk model to firstly determine the compiling vulnerability and the running vulnerability of the target kernel layer, and then determines the vulnerability risk level of the target kernel layer through the compiling vulnerability of the target kernel layer and the running vulnerability of the target kernel layer. Vulnerabilities generated during compiling and vulnerabilities generated during running are fully considered, so that the two methods can mutually compensate for the limitation of self detection, and the false alarm rate is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technology, and in particular, to a method for determining vulnerability risk levels, related systems, and computer media. Background Art

[0002] The kernel layer is the core of the operating system, responsible for managing the system's processes, memory, device drivers, files, and network systems, etc., and determining the performance and stability of the system. When a kernel vulnerability appears in the kernel layer, an attacker can access or damage the system through the vulnerability without authorization, resulting in problems such as data loss or tampering, and user privacy leakage. Therefore, in order to prevent the malicious exploitation of kernel layer vulnerabilities, it is usually necessary to detect kernel layer vulnerabilities irregularly so that developers can repair them in time. Summary of the Invention

[0003] Embodiments of this application provide a method for determining vulnerability risk levels, related systems, and computer storage media.

[0004] In a first aspect, embodiments of this application provide a method for determining vulnerability risk levels, the method including:

[0005] Obtain the information to be tested of the target kernel layer; wherein, the information to be tested includes: the basic information of the target kernel layer, the configuration information of the target kernel layer, and the code of the target kernel layer;

[0006] Input the information to be tested of the target kernel layer into a vulnerability risk model to obtain the compilation vulnerabilities and running vulnerabilities of the target kernel layer; wherein, the vulnerability risk model is trained based on the information of multiple kernel layers with known vulnerability risk information; the information of the kernel layer with known vulnerability risk information includes: the basic information of the kernel layer, the configuration information of the kernel layer, and the code of the kernel layer; the compilation vulnerabilities of the target kernel layer are determined based on the code of the target kernel layer and the basic information of the target kernel layer, and the running vulnerabilities of the target kernel layer are determined based on the code of the target kernel layer and the configuration information of the target kernel layer;

[0007] Based on the compilation vulnerabilities and running vulnerabilities of the target kernel layer, determine the vulnerability risk level of the target kernel layer.

[0008] In a second aspect, embodiments of this application provide a device for determining vulnerability risk levels, the device including:

[0009] An obtaining module, configured to obtain the information to be tested of the target kernel layer; wherein, the information to be tested includes: the basic information of the target kernel layer, the configuration information of the target kernel layer, and the code of the target kernel layer;

[0010] An obtaining module is configured to input the information to be measured of the target kernel layer into a vulnerability risk model to obtain compilation vulnerabilities and running vulnerabilities of the target kernel layer. The vulnerability risk model is trained based on information of kernel layers of multiple known vulnerability risk information. The information of the kernel layer of the known vulnerability risk information includes: basic information of the kernel layer, configuration information of the kernel layer, and code of the kernel layer. The compilation vulnerabilities of the target kernel layer are determined based on the code of the target kernel layer and the basic information of the target kernel layer, and the running vulnerabilities of the target kernel layer are determined based on the code of the target kernel layer and the configuration information of the target kernel layer.

[0011] A determining module is configured to determine a vulnerability risk level of the target kernel layer based on the compilation vulnerabilities and the running vulnerabilities of the target kernel layer.

[0012] In a third aspect, an embodiment of the present application provides a computer storage medium storing multiple instructions adapted to be loaded and executed by a processor to perform the above method steps.

[0013] In a fourth aspect, an embodiment of the present application provides a terminal, which may include: a processor and a memory;

[0014] The memory stores a computer program adapted to be loaded and executed by the processor to perform the above method steps.

[0015] The beneficial effects brought by the technical solutions provided by some embodiments of the present application at least include:

[0016] The present application adopts a method of inputting the information to be measured of the target kernel layer into a vulnerability risk model to first determine compilation vulnerabilities and running vulnerabilities of the target kernel layer, and then determine the vulnerability risk level of the target kernel layer through the compilation vulnerabilities and the running vulnerabilities of the target kernel layer, so as to fully consider vulnerabilities generated during compilation and vulnerabilities generated during operation, enabling the two methods to make up for the limitations of their own detections and reducing the false alarm rate. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] To more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required in the embodiments. Obviously, the drawings in the following description are only some embodiments of the present application, and those of ordinary skill in the art can obtain other drawings without creative efforts based on these drawings.

[0018] Figure 1 It is an application scenario diagram of a kernel vulnerability detection system provided by an embodiment of the present application;

[0019] Figure 2Schematic flow chart of a kernel vulnerability detection method provided by an embodiment of the present application;

[0020] Figure 3 Schematic flow chart of another kernel vulnerability detection method provided by an embodiment of the present application;

[0021] Figure 4 Schematic structural diagram of a kernel vulnerability detection device provided by an embodiment of the present application;

[0022] Figure 5 Schematic structural diagram of a terminal provided by an embodiment of the present application. Detailed implementation manners

[0023] When the following description refers to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The implementation manners described in the following exemplary embodiments do not represent all implementation manners consistent with the present application. On the contrary, they are merely examples of systems and methods consistent with some aspects of the present application as detailed in the appended claims.

[0024] In the description of the present application, it should be understood that the terms "first", "second", etc. are only used for descriptive purposes and cannot be construed as indicating or implying relative importance. For those of ordinary skill in the art, the specific meanings of the above terms in the present application can be understood according to specific circumstances. In addition, in the description of the present application, unless otherwise specified, "a plurality of" means two or more. "And / or" describes the association relationship of associated objects and indicates that three relationships may exist. For example, A and / or B may represent: A exists alone, A and B exist simultaneously, and B exists alone. The character " / " generally represents an "or" relationship between the associated objects before and after.

[0025] Figure 1 Exemplarily shows a schematic diagram of each internal level of a terminal. Among them, the internal level structure of the terminal from bottom to top is: hardware layer - kernel layer - command parsing layer - user layer.

[0026] Specifically, the hardware layer may include hardware devices such as a Central Processing Unit (CPU), memory, network card, and disk. The kernel layer refers to a system software that provides functions such as a hardware abstraction layer, disk and file system control, and multitasking. It is part of the software that provides secure access to the computer hardware for numerous application programs. This access is limited, and the kernel layer determines when a program operates on a certain part of the hardware and for how long. Directly operating on the hardware in the hardware layer is very complex, so the kernel layer provides a simple and unified interface between application software and the hardware, making programming easier. The command parsing layer parses the commands input by the user into the terminal and calls the corresponding programs in the kernel layer to execute the commands input by the user in the terminal. For example, the Shell command interpreter can parse the commands into instructions that the kernel layer can recognize, and then the kernel layer executes the commands, and finally the terminal displays the results of the command execution to the user. The user layer is used to display user-operable software such as application programs and receive the operation instructions of the user.

[0027] In the related art, for kernel vulnerability detection methods, one is to detect kernel vulnerabilities through the static characteristics of the kernel layer. However, this method is easily bypassed, resulting in inaccurate detection and being unable to defend against unknown threats. The other is to detect kernel vulnerabilities by detecting the behavior of hackers obtaining the highest privileges of the system (such as administrator privileges) through privilege escalation when invading the system to gain control of the operating system. However, if hackers do not escalate privileges when invading the system, it is very difficult to detect kernel vulnerabilities.

[0028] Next, in combination with Figure 1 the application scenario diagram of the kernel vulnerability detection system introduced below, the kernel vulnerability detection method provided by the embodiments of the present application will be introduced.

[0029] In one embodiment, Figure 2 as shown, a flowchart of a kernel vulnerability detection method is provided. As Figure 2 shown, the kernel vulnerability detection method may include the following steps:

[0030] S201, obtain the information to be tested of the target kernel layer.

[0031] Among them, the information to be tested may include: the basic information of the target kernel layer, the configuration information of the target kernel layer, and the code of the target kernel layer.

[0032] Specifically, the basic information in the embodiments of the present application may include: kernel version information, release date, manufacturer, etc. The configuration information may include: encryption algorithm, permission settings, network configuration, running environment information, etc. Among them, the running environment may include: hardware environment and other software environments, etc.

[0033] S202. Input the information to be tested of the target kernel layer into the vulnerability risk model to obtain compilation vulnerabilities and running vulnerabilities of the target kernel layer.

[0034] Among them, the vulnerability risk model is trained based on the information of the kernel layers of multiple known vulnerability risk information; the information of the kernel layers of the known vulnerability risk information includes: the basic information of the kernel layer, the configuration information of the kernel layer, and the code of the kernel layer; the compilation vulnerabilities of the target kernel layer are determined based on the code of the target kernel layer and the basic information of the target kernel layer, and the running vulnerabilities of the target kernel layer are determined based on the code of the target kernel layer and the configuration information of the target kernel layer.

[0035] Specifically, the embodiments of the present application can obtain the information of the kernel layers of multiple known vulnerability risk values; based on the information of the kernel layers of multiple known vulnerability risk values, train the pre-established initial vulnerability risk model to obtain the vulnerability risk model. Among them, the information of the kernel layer can include: basic information and configuration information.

[0036] It can be understood that different versions of the kernel may correspond to different security features and known version vulnerabilities. The relevant settings of some configuration information of the kernel layer may make the kernel layer more vulnerable to attacks. For example, enabling insecure features or services, and the applied patches may fix some vulnerabilities, but may also introduce new vulnerabilities.

[0037] Possibly, the known vulnerability information of the kernel layer in the embodiments of the present application can include: known vulnerability lists, etc.

[0038] Possibly, the embodiments of the present application can also include other metric information, such as code quality metrics, historical security records, community activity levels, etc.

[0039] It can be understood that the embodiments of the present application can encode and combine the above-mentioned basic information of the kernel layer, configuration information of the kernel layer, and code of the kernel layer in various ways to obtain predicted vulnerability information, and then compare the predicted vulnerability information with the known vulnerability information to train the vulnerability risk model.

[0040] It can be understood that the compilation vulnerabilities in the embodiments of the present application indicate the vulnerabilities that may occur during the encoding of the code of the target kernel layer.

[0041] Possibly, the embodiments of the present application can determine compilation vulnerabilities through static methods. For example, by analyzing the source code of the kernel to obtain the static information of the kernel, identifying code patterns or insecure programming practices that may have vulnerabilities, and detecting vulnerabilities based on the presence or absence of static features involved in the vulnerability patch files. The advantage of the static analysis method is that the analysis and implementation are simple and it can comprehensively detect the kernel code.

[0042] Possibly, the embodiments of the present application may also use other decision models such as decision trees and neural networks to establish a vulnerability risk model.

[0043] It can be understood that the running vulnerabilities in the embodiments of the present application refer to the vulnerabilities that may occur during the running of the target kernel layer code. Since the kernel layer usually involves complex interactions of multiple threads or multiple processes during operation, it may be difficult to accurately identify the risks generated during its operation only by analyzing the code.

[0044] Specifically, the embodiments of the present application may determine the running vulnerabilities through dynamic methods. For example, monitor and analyze the kernel behavior during the running of the kernel layer to detect vulnerabilities. The advantage of the dynamic method is that it can detect vulnerabilities and abnormal behaviors in real time during the kernel operation, can quickly discover and respond to security issues, and since the dynamic method is based on the actual running behavior of the kernel for analysis, it can provide more accurate vulnerability detection results and reduce the possibility of false positives and false negatives.

[0045] S203. Determine the vulnerability risk level of the target kernel layer based on the compilation vulnerabilities and running vulnerabilities of the target kernel layer.

[0046] Specifically, the compilation vulnerabilities in the embodiments of the present application may include any one or more of the following: null pointer reference, kernel privilege escalation, insecure system call, misuse of application programming interface, insecure driver call, hard-coded sensitivity, hard-coded credential vulnerability, use of deprecated kernel application programming interface. The running vulnerabilities may include any one or more of the following: insecure system call, buffer overflow, integer overflow, kernel memory leak, information leak, hardware-level vulnerability, double free, race condition, deadlock, resource exhaustion.

[0047] Specifically, privilege escalation means allowing a low-privilege user or process to obtain elevated privileges. Memory leakage may lead to the leakage of sensitive information or the exhaustion of system resources. Buffer overflow may cause the system to crash or enable remote code execution. Race condition may allow unauthorized operations such as file access or data modification. Information leakage may disclose sensitive system or user data. Hardware-level vulnerabilities refer to vulnerabilities existing in computer hardware such as the CPU, graphics processing unit (GPU), chipset, etc. These vulnerabilities may allow attack behaviors to bypass software security mechanisms. For example, the "Meltdown" and "Spectre" vulnerabilities are security flaws at the hardware level, which use the specifications of modern processors to execute functions to access sensitive data of the system. Information leakage refers to vulnerabilities at the kernel level, which may lead to unauthorized access or leakage of sensitive data (such as user information, system configuration, passwords, etc.). Since double free may affect memory areas that have been reallocated for other purposes, double free may cause memory corruption. In addition, sometimes attackers can also use the double free vulnerability to corrupt the memory management data structure of the program, and then execute arbitrary code or escalate privileges. Deadlock is usually caused by the competition for resources among multiple processes, which hinders the normal operation of the program and makes these processes never complete.

[0048] It can be understood that attacks using hardware-level vulnerabilities are usually more complex than software-level attacks, but they often provide deeper system access privileges, and there is a certain interaction between kernel vulnerabilities and hardware-level vulnerabilities. For example, some hardware-level vulnerabilities (such as Spectre) may require kernel-level vulnerabilities to achieve the actual leakage of data. Hardware-level vulnerabilities may exacerbate the severity of information leakage at the kernel level. If the hardware cannot reliably isolate the memory spaces of different processes, then even if the kernel is properly designed, the risk of information leakage may increase, and attackers may use such vulnerabilities to obtain key information and further escalate the attack, such as obtaining higher system privileges or executing remote code.

[0049] Furthermore, the embodiments of the present application can adopt the following processing measures for different vulnerability risk levels of the target kernel layer:

[0050] 1. Lower risk level:

[0051] Monitoring and recording: For low-risk vulnerabilities, it is recommended to implement system monitoring and event recording to detect and respond in a timely manner when there is an attempt to exploit the vulnerability.

[0052] 2. Medium risk level:

[0053] Remediation plan: Medium-risk vulnerabilities should be included in the vulnerability remediation plan to ensure that they are repaired within a reasonable time frame.

[0054] Update the kernel: It may be necessary to update or upgrade the kernel version to include relevant security fixes.

[0055] 3. Higher risk level:

[0056] Prioritize patching: High-risk vulnerabilities should be patched first to reduce the threat of potential attacks.

[0057] Emergency Updates: Kernel updates may need to be released urgently to include critical security fixes.

[0058] Emergency response: For high-risk vulnerabilities, additional emergency response measures should be considered, such as deactivating affected services or taking emergency security measures to minimize potential risks.

[0059] 4. Extremely high risk level:

[0060] Immediately deactivate services: For extremely high risk vulnerabilities, it may be necessary to immediately deactivate the affected services to prevent the attack.

[0061] Investigation and tracing: For situations where an attack has occurred, detailed investigation and tracing are required to understand the impact of the attack and how the vulnerability was exploited.

[0062] Comprehensive repair: Extremely high-risk vulnerabilities must be repaired immediately to ensure the security of the system.

[0063] When implementing vulnerability management and emergency response strategies, they should be formulated based on the severity of the vulnerability, the impact of the vulnerability, business needs, and organizational policies. At the same time, organizations should establish vulnerability management and emergency response plans to ensure that vulnerabilities are handled in a timely manner to maintain the security of the system.

[0064] Therefore, the present application adopts a method of inputting the information to be tested of the target kernel layer into the vulnerability risk model to first determine the compilation vulnerabilities and operation vulnerabilities of the target kernel layer, and then determines the vulnerability risk level of the target kernel layer through the compilation vulnerabilities of the target kernel layer and the operation vulnerabilities of the target kernel layer, so as to fully consider the vulnerabilities generated during compilation and the vulnerabilities generated during runtime, so that the two methods can compensate for each other's own detection limitations and reduce the false alarm rate.

[0065] In some embodiments, Figure 3 The following is a flow chart showing a method for determining a vulnerability risk level according to an embodiment of the present application. Figure 3 As shown, the vulnerability risk level determination method may at least include the following steps:

[0066] S301, extracting features from basic information of the kernel layer to obtain basic feature information of the kernel layer; extracting features from configuration information of the kernel layer to obtain configuration feature information of the kernel layer.

[0067] Possibly, embodiments of the present application may normalize values such as the kernel version number and release date in the basic information, and one-hot encoding can be used to determine classification features for information such as the manufacturer and encryption algorithm.

[0068] Specifically, one-hot encoding is mainly used to convert discrete features into continuous features so that machine learning algorithms can better process them. One-hot encoding maps the values of each discrete feature to a binary vector, where only one element is 1 and the rest are 0, and the position of this element represents the position of the value among all values. For example, there are multiple manufacturers stored in the vulnerability risk model: Manufacturer A, Manufacturer B, Manufacturer C, etc. If the manufacturer at the kernel layer is Manufacturer A, then the element corresponding to Manufacturer A is 1, and the elements corresponding to other manufacturers are 0.

[0069] S302: Obtain the static loss value of the kernel layer based on the code of the kernel layer and the basic feature information of the kernel layer; obtain the dynamic loss value of the kernel layer based on the code of the kernel layer and the configuration feature information of the kernel layer.

[0070] Specifically, embodiments of the present application can determine the test compilation vulnerabilities of the kernel layer based on the code of the kernel layer and the basic feature information of the kernel layer; determine the static loss value of the kernel layer based on the test compilation vulnerabilities of the kernel layer and the known compilation vulnerabilities of the kernel layer; determine the test running vulnerabilities of the kernel layer from the code of the kernel layer and the configuration feature information of the kernel layer; determine the dynamic loss value of the kernel layer based on the test running vulnerabilities of the kernel layer and the known running vulnerabilities of the kernel layer.

[0071] Input the code of the kernel layer and the basic feature information of the kernel layer into the first detection module to obtain the test compilation vulnerabilities of the kernel layer. Input the code of the kernel layer and the configuration feature information of the kernel layer into the second detection module to obtain the test running vulnerabilities of the kernel layer.

[0072] Among them, the first detection module includes any one or more of the following detections: module dependency analysis, symbol table analysis, static data flow analysis, detection based on pattern matching. The second detection module is used to detect the code of the kernel layer based on at least one test case; the test case is used to simulate the attack behavior of the user layer and / or the server.

[0073] Specifically, the embodiments of the present application can analyze the dependency relationships between modules in the kernel layer through module dependency analysis, and can detect malicious behaviors of hidden modules or illegally loaded modules in the kernel layer. Symbol table analysis can identify illegal code in the kernel based on known legitimate kernel functions and their related code features. This technology can detect malicious functions with deceptive naming methods in the kernel. Static data flow analysis: When performing static analysis on the code in the kernel layer, this technology tracks the sources and destinations of sensitive variables (such as system call parameters, process identification IDs, etc.) to facilitate the discovery and prevention of attacks against these sensitive variables. Pattern matching detection can design corresponding detection rules according to known attack behavior patterns, and then scan the kernel-mode code and user-mode code during the system operation process to discover and prevent similar attacks. It can detect attack behaviors that match them.

[0074] Possibly, the second detection module in the embodiments of the present application can use the Proof of Concept (PoC) method to determine the running vulnerabilities in the kernel layer by writing a special test case to simulate the attack process. It triggers the vulnerabilities in the kernel by constructing specific input data or input sequences and records relevant information to verify whether there are vulnerabilities in the kernel. Specifically, it is necessary to first determine the type of vulnerability to be detected, and it is necessary to clarify the kernel version, patch level, configuration options, etc. Then, according to the vulnerability type and attack scenario, select appropriate test cases. Then write the PoC code for symbol test requirements for testing to generate vulnerability construction parameters and corresponding attack codes. If experimental verification is carried out in a controlled environment, it is necessary to continuously modify and improve the PoC to ensure that it can successfully trigger the vulnerability. If the PoC successfully triggers the vulnerability, the attacker can further use this vulnerability to elevate privileges, execute code, etc. At the same time, it is also necessary to record the exploitation and reproduction process for subsequent security analysis and report writing.

[0075] It can be understood that because the PoC method is based on the construction method of actual vulnerabilities, it can detect more malicious behaviors, thereby improving the detection accuracy and comprehensiveness.

[0076] In addition, the embodiments of the present application can also determine the running vulnerabilities in the kernel layer by combining the PoC method and the system call method. The system call method can detect whether there are abnormalities in the parameters and return values of system calls based on monitoring the behavior of system calls. In kernel layer vulnerability detection, by monitoring the usage of system calls and judging whether there are kernel layer vulnerabilities according to the defined rules or trust models. The system call method can also detect some low-level malicious attacks, such as attacks based on buffer overflows, etc. Use the PoC method to simulate the running process of the kernel layer and use the system call method for detection during the running process. The system call monitor will record all syscall calls and their parameters, check whether the parameters are abnormal, and analyze whether the return results are normal. If there are abnormalities, it means that there are vulnerabilities in the kernel.

[0077] Possibly, by gradually changing the parameters of the attack code or adding more attack scenarios, the PoC method and the system call method can be run again to gradually verify whether other kernel layer vulnerabilities can be exposed.

[0078] S303, based on the static loss value of the kernel layer and the dynamic loss value of the kernel layer, train the initial vulnerability risk model to obtain the vulnerability risk model.

[0079] Possibly, the embodiments of the present application can perform processing on possible text data (for example, known vulnerability information) using the bag-of-words model or the common weighting technique of information retrieval and text mining (Term Frequency-Inverse Document Frequency, TF-IDF), and train and verify the vulnerability risk model through the random forest algorithm.

[0080] It can be understood that the evaluation of vulnerability risk levels is a complex process, and the initial vulnerability risk model needs to be trained according to the following multiple factors:

[0081] 1. The type of vulnerability: Vulnerability types such as privilege escalation and hardware-level vulnerabilities are more likely to lead to serious security consequences. However, this does not mean that every such vulnerability will be classified as a high-risk vulnerability.

[0082] 2. The context of the vulnerability: including the importance of the software component where the vulnerability is located, the degree to which the vulnerability is easily exploited, the potential scope of influence, etc.

[0083] 3. The exploitability of the vulnerability: Even seemingly serious vulnerabilities may have a relatively low actual risk if they are difficult to exploit (for example, specific conditions or advanced skills are required).

[0084] 4. The potential impact of the vulnerability: including different impact dimensions such as data leakage, service interruption, and acquisition of system control rights. Some seemingly minor vulnerabilities may have a major impact in specific situations.

[0085] Therefore, during the training of the initial vulnerability risk model, the model should be trained based on the above factors. In addition, different types of vulnerabilities may have different risk levels in different application environments. For example, for a system with high security requirements, any vulnerability that may lead to information leakage may be regarded as a high risk. While for a system with less strict security requirements, the same vulnerability may only be regarded as medium or low risk.

[0086] Furthermore, the embodiments of the present application can determine the loss value of the initial vulnerability risk model based on the static loss value of the kernel layer and the dynamic loss value of the kernel layer; when the loss value of the initial vulnerability risk model is greater than the loss threshold, after adjusting the model parameters of the initial vulnerability risk model, the step of S302 is executed again until the loss value of the initial vulnerability risk model is less than or equal to the loss threshold, and the vulnerability risk model is obtained.

[0087] It can be understood that the loss value of the initial vulnerability risk model, that is, the total loss value, is that the static loss value and the dynamic loss value can be combined by a certain method (such as weighted average or maximum value, etc.) to obtain a comprehensive loss value.

[0088] Possibly, the embodiments of the present application can calculate the loss value of the initial vulnerability risk model in the following way:

[0089] Calculate the static loss value: Static loss value = f(test compilation vulnerability, known compilation vulnerability);

[0090] Calculate the dynamic loss value: Dynamic loss value = f(test running vulnerability, known test vulnerability);

[0091] Loss value of the initial vulnerability risk model = g(static loss value, dynamic loss value).

[0092] Wherein, f and g are functions for calculating the loss value, which may include algorithms such as weighting, normalization, and non-linear transformation.

[0093] Possibly, the embodiments of the present application also include some index information that can be used to help train the initial vulnerability risk model to obtain a more accurate vulnerability risk model.

[0094] Specifically, the index information in the embodiments of the present application may include: code quality indexes that can affect software security, such as: code complexity, coding standards followed, proportion of duplicate code, code coverage, etc. Historical security records, including: the number of vulnerabilities found in historical versions, repair speed, severity of vulnerabilities, etc. Community activity, such as the activity of developers, feedback and participation of the community, frequency of regular updates and maintenance, etc.

[0095] It is understandable that an active community usually means that the software will be updated in a timely manner, and vulnerabilities can be quickly discovered and fixed. Effective communication and collaboration among community members also contribute to improving the overall security of the software. On the contrary, projects lacking an active community may lead to vulnerabilities remaining undetected or unfixed for a long time, increasing security risks.

[0096] S304. Obtain the information to be tested for the target kernel layer.

[0097] Specifically, S304 is the same as S201, and details are not repeated here.

[0098] S305. Input the information to be tested for the target kernel layer into the vulnerability risk model to obtain compilation vulnerabilities and running vulnerabilities of the target kernel layer.

[0099] Specifically, S305 is the same as S202, and details are not repeated here.

[0100] S306. Determine the vulnerability risk level of the target kernel layer based on the compilation vulnerabilities and running vulnerabilities of the target kernel layer.

[0101] Specifically, S306 is the same as S203, and details are not repeated here.

[0102] It should be noted that when the kernel vulnerability detection system provided in the above embodiments executes the kernel vulnerability detection method, only the above division of each functional module is used for illustration. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above. In addition, the kernel vulnerability detection system provided in the above embodiments and the embodiments of the kernel vulnerability detection method belong to the same concept. The implementation process is detailed in the method embodiments and will not be repeated here.

[0103] The serial numbers of the above embodiments of the present application are only for description and do not represent the advantages and disadvantages of the embodiments.

[0104] Figure 4 It is a schematic structural diagram of a vulnerability risk level determination device provided by an exemplary embodiment of the present application. The vulnerability risk level determination device can be set in devices such as servers and execute the information push method in any of the above embodiments of the present application. As Figure 4 shown, the information push device may include:

[0105] An acquisition module 41, configured to acquire the information to be tested for the target kernel layer; wherein, the information to be tested includes: the basic information of the target kernel layer, the configuration information of the target kernel layer, and the code of the target kernel layer;

[0106] An obtaining module 42 is configured to input the information to be measured of the target kernel layer into a vulnerability risk model, so as to obtain compilation vulnerabilities and running vulnerabilities of the target kernel layer. The vulnerability risk model is trained based on the information of the kernel layers of multiple known vulnerability risk information. The information of the kernel layers of the known vulnerability risk information includes: the basic information of the kernel layer, the configuration information of the kernel layer, and the code of the kernel layer. The compilation vulnerabilities of the target kernel layer are determined based on the code of the target kernel layer and the basic information of the target kernel layer, and the running vulnerabilities of the target kernel layer are determined based on the code of the target kernel layer and the configuration information of the target kernel layer.

[0107] A determining module 43 is configured to determine the vulnerability risk level of the target kernel layer based on the compilation vulnerabilities and the running vulnerabilities of the target kernel layer.

[0108] Therefore, the present application adopts a method of inputting the information to be measured of the target kernel layer into the vulnerability risk model to first determine the compilation vulnerabilities and running vulnerabilities of the target kernel layer, and then determine the vulnerability risk level of the target kernel layer through the compilation vulnerabilities and running vulnerabilities of the target kernel layer, so as to fully consider the vulnerabilities generated during compilation and the vulnerabilities generated during running, enabling the two methods to compensate for the limitations of their own detections and reducing the false positive rate.

[0109] In some embodiments, before the obtaining module 42, the apparatus includes:

[0110] A kernel layer information obtaining module is configured to obtain the information of the kernel layers of multiple known vulnerability risk values.

[0111] A vulnerability risk model obtaining module is configured to train a pre-established initial vulnerability risk model based on the information of the kernel layers of multiple known vulnerability risk values to obtain the vulnerability risk model.

[0112] In some embodiments, the basic information of the kernel layer includes any one or more of the following: kernel version information, release date, manufacturer; the configuration information of the kernel layer includes any one or more of the following: encryption algorithm, permission setting, network configuration, patch information, running environment information.

[0113] The vulnerability risk model obtaining module is specifically configured to:

[0114] Extract features from the basic information of the kernel layer to obtain the basic feature information of the kernel layer.

[0115] Extract features from the configuration information of the kernel layer to obtain the configuration feature information of the kernel layer.

[0116] Obtain the static loss value of the kernel layer based on the code of the kernel layer and the basic feature information of the kernel layer;

[0117] Obtain the dynamic loss value of the kernel layer based on the code of the kernel layer and the configuration feature information of the kernel layer;

[0118] Train the initial vulnerability risk model based on the static loss value of the kernel layer and the dynamic loss value of the kernel layer to obtain the vulnerability risk model.

[0119] In some embodiments, the known vulnerability information of the kernel layer includes: the known compilation vulnerabilities of the kernel layer and the known running vulnerabilities of the kernel layer;

[0120] The module for obtaining the vulnerability risk model is specifically configured to:

[0121] Determine the test compilation vulnerabilities of the kernel layer based on the code of the kernel layer and the basic feature information of the kernel layer;

[0122] Determine the static loss value of the kernel layer based on the test compilation vulnerabilities of the kernel layer and the known compilation vulnerabilities of the kernel layer;

[0123] The module for obtaining the vulnerability risk model is specifically configured to:

[0124] Determine the test running vulnerabilities of the kernel layer by using the code of the kernel layer and the configuration feature information of the kernel layer;

[0125] Determine the dynamic loss value of the kernel layer based on the test running vulnerabilities of the kernel layer and the known running vulnerabilities of the kernel layer.

[0126] In some embodiments, the module for obtaining the vulnerability risk model is specifically configured to:

[0127] Determine the loss value of the initial vulnerability risk model based on the static loss value of the kernel layer and the dynamic loss value of the kernel layer;

[0128] In the case where the loss value of the initial vulnerability risk model is greater than the loss threshold, after adjusting the model parameters of the initial vulnerability risk model, execute again the steps of obtaining the static loss value of the kernel layer based on the code of the kernel layer and the basic feature information of the kernel layer, and obtaining the dynamic loss value of the kernel layer based on the code of the kernel layer and the configuration feature information of the kernel layer, until the loss value of the initial vulnerability risk model is less than or equal to the loss threshold, to obtain the vulnerability risk model.

[0129] In some embodiments, the initial vulnerability risk model includes: a first detection module and a second detection module;

[0130] The vulnerability risk model obtaining module is specifically configured to:

[0131] Input the code of the kernel layer and the basic feature information of the kernel layer into the first detection module to obtain the test compilation vulnerabilities of the kernel layer; wherein, the first detection module includes any one or more of the following detections: module dependency analysis, symbol table analysis, static data flow analysis, detection based on pattern matching;

[0132] The vulnerability risk model obtaining module is specifically configured to:

[0133] Input the code of the kernel layer and the configuration feature information of the kernel layer into the second detection module to obtain the test running vulnerabilities of the kernel layer; wherein, the second detection module is used to detect the code of the kernel layer based on at least one test case; the test case is used to simulate the attack behaviors of the user layer and / or the server.

[0134] In some embodiments, the compilation vulnerabilities include any one or more of the following: null pointer reference, kernel state permission error, insecure system call, misuse of application programming interface, insecure driver call, hard-coded sensitive information, hard-coded credentials, use of deprecated kernel application programming interface;

[0135] The running vulnerabilities include any one or more of the following: insecure system call, buffer overflow, integer overflow, kernel memory leak, double free, race condition, deadlock, resource exhaustion.

[0136] Please refer to Figure 5 , which provides a schematic structural diagram of a terminal for an embodiment of the present application. As Figure 5 shown, the terminal 50 may include: at least one processor 51, at least one network interface 54, a user interface 53, a memory 55, and at least one communication bus 52.

[0137] Among them, the communication bus 52 is used to realize the connection and communication between these components.

[0138] Among them, the user interface 53 may include a display screen (Display), a camera (Camera), and optionally the user interface 53 may further include a standard wired interface and a wireless interface.

[0139] Among them, the network interface 54 may optionally include a standard wired interface and a wireless interface (such as a WI-FI interface).

[0140] Among them, the processor 51 may include one or more processing cores. The processor 51 is connected to various parts within the entire terminal 50 through various interfaces and circuits. By running or executing instructions, programs, code sets, or instruction sets stored in the memory 55, and by calling the data stored in the memory 55, it performs various functions of the terminal 50 and processes data. Optionally, the processor 51 may be implemented in at least one hardware form of digital signal processing (DSP), field-programmable gate array (FPGA), or programmable logic array (PLA). The processor 51 may integrate a combination of one or more of a central processing unit (CPU), a graphics processing unit (GPU), and a modem, etc. Among them, the CPU mainly processes the operating system, user interface, application programs, etc.; the GPU is responsible for rendering and drawing the content to be displayed on the display screen; the modem is used to process wireless communications. It can be understood that the above-mentioned modem may not be integrated into the processor 51 and may be implemented separately by a single chip.

[0141] Among them, the memory 55 may include random access memory (RAM) and may also include read-only memory. Optionally, the memory 55 includes a non-transitory computer-readable storage medium. The memory 55 can be used to store instructions, programs, code, code sets, or instruction sets. The memory 55 may include a program storage area and a data storage area. Among them, the program storage area may store instructions for implementing the operating system, instructions for at least one function (such as touch function, sound playback function, image playback function, etc.), instructions for implementing the above-mentioned various method embodiments, etc.; the data storage area may store the data involved in the above-mentioned various method embodiments. Optionally, the memory 55 may also be at least one storage system located far from the aforementioned processor 51. As Figure 5 shown, the memory 55, as a computer storage medium, may include an operating system, a network communication module, a user interface module, and a kernel vulnerability detection application program.

[0142] In Figure 5In the terminal 50 shown, the user interface 53 is mainly used to provide an interface for the user to input and obtain the data input by the user; and the processor 51 can be used to call the kernel vulnerability detection application program stored in the memory 55 and specifically perform the following operations:

[0143] Obtain the information to be tested of the target kernel layer; wherein, the information to be tested includes: the basic information of the target kernel layer, the configuration information of the target kernel layer, and the code of the target kernel layer;

[0144] Input the information to be tested of the target kernel layer into the vulnerability risk model to obtain the compilation vulnerability and running vulnerability of the target kernel layer; wherein, the vulnerability risk model is trained based on the information of multiple kernel layers with known vulnerability risk information; the information of the kernel layer with known vulnerability risk information includes: the basic information of the kernel layer, the configuration information of the kernel layer, and the code of the kernel layer; the compilation vulnerability of the target kernel layer is determined based on the code of the target kernel layer and the basic information of the target kernel layer, and the running vulnerability of the target kernel layer is determined based on the code of the target kernel layer and the configuration information of the target kernel layer;

[0145] Based on the compilation vulnerability of the target kernel layer and the running vulnerability of the target kernel layer, determine the vulnerability risk level of the target kernel layer.

[0146] In some embodiments, before the processor 51 executes the operation of inputting the information to be tested of the target kernel layer into the vulnerability risk model to obtain the vulnerability risk value of the target kernel layer, it also executes:

[0147] Obtain the information of multiple kernel layers with known vulnerability risk values;

[0148] Based on the information of multiple kernel layers with known vulnerability risk values, train the pre-established initial vulnerability risk model to obtain the vulnerability risk model.

[0149] In some embodiments, the basic information of the kernel layer includes any one or more of the following: kernel version information, release date, manufacturer; the configuration information of the kernel layer includes any one or more of the following: encryption algorithm, permission setting, network configuration, patch information, running environment information;

[0150] When the processor 51 executes the operation of training the pre-established initial vulnerability risk model based on the information of multiple kernel layers with known vulnerability risk values to obtain the vulnerability risk model, it specifically executes: extract features from the basic information of the kernel layer to obtain the basic feature information of the kernel layer;

[0151] Extract the configuration information of the kernel layer to obtain the configuration feature information of the kernel layer;

[0152] Based on the code of the kernel layer and the basic feature information of the kernel layer, obtain the static loss value of the kernel layer;

[0153] Based on the code of the kernel layer and the configuration feature information of the kernel layer, obtain the dynamic loss value of the kernel layer;

[0154] Based on the static loss value of the kernel layer and the dynamic loss value of the kernel layer, train the initial vulnerability risk model to obtain the vulnerability risk model.

[0155] In some embodiments, the known vulnerability information of the kernel layer includes: the known compilation vulnerabilities of the kernel layer and the known running vulnerabilities of the kernel layer;

[0156] When the processor 51 executes obtaining the static loss value of the kernel layer based on the code of the kernel layer and the basic feature information of the kernel layer, it specifically executes:

[0157] Use the code of the kernel layer and the basic feature information of the kernel layer to determine the test compilation vulnerabilities of the kernel layer;

[0158] Based on the test compilation vulnerabilities of the kernel layer and the known compilation vulnerabilities of the kernel layer, determine the static loss value of the kernel layer;

[0159] When the processor 51 executes obtaining the dynamic loss value of the kernel layer based on the code of the kernel layer and the configuration feature information of the kernel layer, it specifically executes:

[0160] Use the code of the kernel layer and the configuration feature information of the kernel layer to determine the test running vulnerabilities of the kernel layer;

[0161] Based on the test running vulnerabilities of the kernel layer and the known running vulnerabilities of the kernel layer, determine the dynamic loss value of the kernel layer.

[0162] In some embodiments, when the processor 51 executes training the initial vulnerability risk model based on the static loss value of the kernel layer and the dynamic loss value of the kernel layer to obtain the vulnerability risk model, it specifically executes:

[0163] Based on the static loss value of the kernel layer and the dynamic loss value of the kernel layer, determine the loss value of the initial vulnerability risk model;

[0164] In the case where the loss value of the initial vulnerability risk model is greater than the loss threshold, after adjusting the model parameters of the initial vulnerability risk model, the steps of obtaining the static loss value of the kernel layer based on the code of the kernel layer and the basic feature information of the kernel layer, and obtaining the dynamic loss value of the kernel layer based on the code of the kernel layer and the configuration feature information of the kernel layer are executed again until the loss value of the initial vulnerability risk model is less than or equal to the loss threshold, thereby obtaining the vulnerability risk model.

[0165] In some embodiments, the initial vulnerability risk model includes: a first detection module and a second detection module;

[0166] When the processor 51 determines the test compilation vulnerability of the kernel layer by executing the code of the kernel layer and the basic feature information of the kernel layer, it specifically executes:

[0167] Input the code of the kernel layer and the basic feature information of the kernel layer into the first detection module to obtain the test compilation vulnerability of the kernel layer; wherein, the first detection module includes any one or more of the following detections: module dependency analysis, symbol table analysis, static data flow analysis, detection based on pattern matching;

[0168] When the processor 51 determines the test running vulnerability of the kernel layer by executing the code of the kernel layer and the configuration feature information of the kernel layer, it specifically executes:

[0169] Input the code of the kernel layer and the configuration feature information of the kernel layer into the second detection module to obtain the test running vulnerability of the kernel layer; wherein, the second detection module is used to detect the code of the kernel layer based on at least one test case; the test case is used to simulate the attack behaviors of the user layer and / or the server.

[0170] In some embodiments, the compilation vulnerability includes any one or more of the following: null pointer reference, kernel state permission error, insecure system call, application programming interface misuse, insecure driver call, hard-coded sensitive information, hard-coded credentials, use of deprecated kernel application programming interfaces;

[0171] The running vulnerability includes any one or more of the following: insecure system call, buffer overflow, integer overflow, kernel memory leak, double free, race condition, deadlock, resource exhaustion.

[0172] The embodiment of the present application further provides a computer-readable storage medium, in which instructions are stored, and when they run on a computer or a processor, the computer or the processor is enabled to execute the above Figure 2One or more steps in the illustrated embodiments. If each component module of the above kernel vulnerability detection system is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in the computer-readable storage medium.

[0173] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable systems. The computer instructions can be stored in a computer-readable storage medium or transmitted through the computer-readable storage medium. The computer instructions can be transmitted from a website, computer, server, or data center to another website, computer, server, or data center by wire (such as coaxial cable, optical fiber, Digital Subscriber Line (DSL)) or wirelessly (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that the computer can access or a data storage device such as a server or data center that includes one or more integrated available media. The available medium can be a magnetic medium (such as a floppy disk, hard disk, magnetic tape), an optical medium (such as a Digital Versatile Disc (DVD)), or a semiconductor medium (such as a Solid State Disk (SSD)), etc.

[0174] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The program can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above methods. The aforementioned storage medium includes various media that can store program codes such as a Read Only Memory (ROM), a Random Access Memory (RAM), a magnetic disk, or an optical disc. Without conflict, the technical features in this embodiment and the implementation solutions can be combined arbitrarily.

[0175] The above-described embodiments are merely described as preferred implementation manners of the present application and do not limit the scope of the present application. Without departing from the design spirit of the present application, various deformations and improvements made by those of ordinary skill in the art to the technical solutions of the present application shall fall within the protection scope determined by the claims of the present application.

Claims

1. A method for determining the vulnerability risk level, characterized in that, The method includes: Obtaining the information to be tested of the target kernel layer; wherein, the information to be tested includes: the basic information of the target kernel layer, the configuration information of the target kernel layer, and the code of the target kernel layer; Inputting the information to be tested of the target kernel layer into a vulnerability risk model to obtain the compilation vulnerabilities and running vulnerabilities of the target kernel layer; wherein, the vulnerability risk model is trained based on the information of multiple kernel layers with known vulnerability risk information; the information of the kernel layer with known vulnerability risk information includes: the basic information of the kernel layer, the configuration information of the kernel layer, and the code of the kernel layer; the compilation vulnerabilities of the target kernel layer are determined based on the code of the target kernel layer and the basic information of the target kernel layer, and the running vulnerabilities of the target kernel layer are determined based on the code of the target kernel layer and the configuration information of the target kernel layer; Determining the vulnerability risk level of the target kernel layer based on the compilation vulnerabilities and running vulnerabilities of the target kernel layer.

2. The method according to claim 1, characterized in that, Before the step of inputting the information to be tested of the target kernel layer into a vulnerability risk model to obtain the compilation vulnerabilities and running vulnerabilities of the target kernel layer, the method includes: Obtaining the information of multiple kernel layers with known vulnerability risk values; Training a pre-established initial vulnerability risk model based on the information of multiple kernel layers with known vulnerability risk values to obtain the vulnerability risk model.

3. The method according to claim 2, characterized in that, The basic information of the kernel layer includes any one or more of the following: kernel version information, release date, manufacturer; the configuration information of the kernel layer includes any one or more of the following: encryption algorithm, permission setting, network configuration, patch information, running environment information; The step of training a pre-established initial vulnerability risk model based on the information of multiple kernel layers with known vulnerability risk values to obtain the vulnerability risk model includes: Performing feature extraction on the basic information of the kernel layer to obtain the basic feature information of the kernel layer; Performing feature extraction on the configuration information of the kernel layer to obtain the configuration feature information of the kernel layer; Based on the code of the kernel layer and the basic feature information of the kernel layer, obtaining the static loss value of the kernel layer; Based on the code of the kernel layer and the configuration feature information of the kernel layer, obtaining the dynamic loss value of the kernel layer; Training the initial vulnerability risk model based on the static loss value and dynamic loss value of the kernel layer to obtain the vulnerability risk model.

4. The method according to claim 3, characterized in that, The known vulnerability information of the kernel layer includes: the known compilation vulnerabilities of the kernel layer and the known running vulnerabilities of the kernel layer; The step of obtaining the static loss value of the kernel layer based on the code of the kernel layer and the basic feature information of the kernel layer includes: Based on the code of the kernel layer and the basic feature information of the kernel layer, determining the test compilation vulnerabilities of the kernel layer; Based on the test compilation vulnerabilities of the kernel layer and the known compilation vulnerabilities of the kernel layer, determining the static loss value of the kernel layer; The step of obtaining the dynamic loss value of the kernel layer based on the code of the kernel layer and the configuration feature information of the kernel layer includes: Determine the test - running vulnerabilities of the kernel layer based on the code of the kernel layer and the configuration feature information of the kernel layer; Determine the dynamic loss value of the kernel layer based on the test - running vulnerabilities of the kernel layer and the known running vulnerabilities of the kernel layer.

5. The method according to claim 4, characterized in that, Training the initial vulnerability risk model based on the static loss value of the kernel layer and the dynamic loss value of the kernel layer to obtain the vulnerability risk model, including: Determine the loss value of the initial vulnerability risk model based on the static loss value of the kernel layer and the dynamic loss value of the kernel layer; When the loss value of the initial vulnerability risk model is greater than the loss threshold, after adjusting the model parameters of the initial vulnerability risk model, execute again the steps of obtaining the static loss value of the kernel layer based on the code of the kernel layer and the basic feature information of the kernel layer, and obtaining the dynamic loss value of the kernel layer based on the code of the kernel layer and the configuration feature information of the kernel layer, until the loss value of the initial vulnerability risk model is less than or equal to the loss threshold, to obtain the vulnerability risk model.

6. The method according to claim 5, characterized in that, The initial vulnerability risk model includes: a first detection module and a second detection module; Determine the test - compilation vulnerabilities of the kernel layer based on the code of the kernel layer and the basic feature information of the kernel layer, including: Input the code of the kernel layer and the basic feature information of the kernel layer into the first detection module to obtain the test - compilation vulnerabilities of the kernel layer; where the first detection module includes any one or more of the following detections: module - dependency analysis, symbol - table analysis, static data - flow analysis, detection based on pattern matching; Determine the test - running vulnerabilities of the kernel layer by using the code of the kernel layer and the configuration feature information of the kernel layer, including: Input the code of the kernel layer and the configuration feature information of the kernel layer into the second detection module to obtain the test - running vulnerabilities of the kernel layer; where the second detection module is used to detect the code of the kernel layer based on at least one test case; the test case is used to simulate the attack behaviors of the user layer and / or the server.

7. The method according to claim 1, characterized in that, The compilation vulnerabilities include any one or more of the following: null - pointer reference, kernel - state permission error, unsafe system call, misuse of application - programming interface, unsafe driver call, hard - coded sensitive information, hard - coded credentials, use of deprecated kernel application - programming interface; The running vulnerabilities include any one or more of the following: unsafe system call, buffer overflow, integer overflow, kernel memory leak, double free, race condition, deadlock, resource exhaustion.

8. A device for determining the vulnerability risk level, characterized in that, The device includes: An acquisition module, configured to acquire the information to be tested of the target kernel layer; where the information to be tested includes: the basic information of the target kernel layer, the configuration information of the target kernel layer, and the code of the target kernel layer; A obtaining module, configured to input the information to be measured of the target kernel layer into a vulnerability risk model, so as to obtain the compilation vulnerabilities and running vulnerabilities of the target kernel layer; wherein, the vulnerability risk model is trained based on the information of the kernel layers of multiple known vulnerability risk information; the information of the kernel layers of the known vulnerability risk information includes: the basic information of the kernel layer, the configuration information of the kernel layer, and the code of the kernel layer; the compilation vulnerabilities of the target kernel layer are determined based on the code of the target kernel layer and the basic information of the target kernel layer, and the running vulnerabilities of the target kernel layer are determined based on the code of the target kernel layer and the configuration information of the target kernel layer; A determining module, configured to determine the vulnerability risk level of the target kernel layer based on the compilation vulnerabilities of the target kernel layer and the running vulnerabilities of the target kernel layer.

9. A computer storage medium, characterized in that, The computer storage medium stores multiple instructions, and the instructions are suitable for being loaded and executed by a processor to perform the method steps of any one of claims 1-7.

10. A terminal, characterized in that, Comprising: A processor and a memory; wherein, the memory stores a computer program, and the computer program is suitable for being loaded and executed by a processor to perform the method steps of any one of claims 1-7.