A vulnerability risk reachability analysis method, electronic device and storage medium
By combining vulnerability scanning analysis with reachability analysis of call paths and triggering conditions, the problem of unreachable vulnerability detection in existing technologies has been solved, enabling accurate assessment and efficient management of vulnerability risks.
Patent Information
- Application Number
- CN202511180051.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-22
- Publication Date
- 2025-11-21
- Estimated Expiration
- 2045-08-22
AI Technical Summary
Existing vulnerability detection technologies detect a large number of unreachable vulnerabilities in large-scale code, making it difficult for programmers to identify the vulnerabilities that truly need to be fixed, and blindly fixing them wastes resources.
By obtaining an initial risk assessment value through vulnerability scanning and analysis, and combining it with the reachability analysis of call paths and triggering conditions, the reachability analysis weight of the vulnerability is determined, and the actual risk of the vulnerability is accurately assessed.
It improves the reliability of vulnerability risk assessment, can more accurately reflect the true risk level of vulnerabilities, provides a reliable basis for security decisions, optimizes resource allocation, and improves vulnerability management efficiency.
Smart Images

Figure CN120671151B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of data analysis, in particular to a vulnerability risk reachability analysis method, an electronic device and a storage medium. BACKGROUND
[0002] In today's digital era, with the widespread application of various software systems and the rapid development of network technology, software security problems are increasingly prominent. In the software development process, in order to realize rich functions, it often relies on numerous components, and these components may have vulnerabilities, which pose a potential security threat to software systems. Therefore, vulnerability detection and risk assessment of software have become a key link to ensure software security.
[0003] At present, common vulnerability detection technologies such as software component analysis technology can identify and count the open source component dependency relationship in the software, and then discover security vulnerabilities hidden in the dependency. However, there are obvious defects. In the context of a large amount of code, a large number of code vulnerabilities will be detected, but most of the detected vulnerabilities are actually unreachable. The main reason is that the dependent components with known vulnerabilities are detected, which may not be loaded in the actual running process of the software. Even if the dependent components with known vulnerabilities are loaded, the software may not execute to the code location where the vulnerability is located, or the corresponding vulnerability function may not be called in the actual running time. Even if the software can execute to the code location where the vulnerability is located in the dependent component, or the vulnerability function is called, the harmful parameters that can trigger the vulnerability may not be passed into the code location where the vulnerability is located.
[0004] A large number of unreachable vulnerabilities will make it difficult for programmers to determine the vulnerabilities that need to be repaired, and repairing all detected vulnerabilities will waste a lot of human resources, and repairing unreachable vulnerabilities will have no actual effect.
[0005] Therefore, how to analyze the reachability of vulnerabilities to correct the vulnerability risk evaluation, improve the reliability of the vulnerability risk evaluation, and thus reduce the cost of code maintenance has become a problem to be solved. SUMMARY
[0006] In view of the above technical problems, the technical solution adopted by the present application is a vulnerability risk reachability analysis method, which comprises the following steps:
[0007] S1, performing vulnerability scanning analysis on the target code to obtain M target vulnerabilities, entry information corresponding to the M target vulnerabilities respectively, and initial risk evaluation values corresponding to the M target vulnerabilities respectively, wherein M is a positive integer.
[0008] S2, for any target vulnerability, determine the call path between the target vulnerability and the entry information corresponding to the target vulnerability, the call path including N call sub-paths, wherein N is a non-negative integer.
[0009] S3, according to the call path, the security protection information corresponding to the N call sub-paths respectively, determine the path reachability analysis value corresponding to the target vulnerability.
[0010] S4, according to the K trigger conditions corresponding to the target vulnerability, determine the condition reachability analysis value corresponding to the target vulnerability, wherein K is a positive integer.
[0011] S5, according to the path reachability analysis value and the condition reachability analysis value corresponding to the target vulnerability, determine the reachability analysis weight corresponding to the target vulnerability.
[0012] S6, according to the initial risk evaluation value and the reachability analysis weight corresponding to the target vulnerability, determine the target risk evaluation value corresponding to the target vulnerability.
[0013] The application also provides a non-transitory computer readable storage medium, the non-transitory computer readable storage medium stores at least one instruction or at least one program, the at least one instruction or the at least one program is loaded and executed by the processor to realize the vulnerability risk reachability analysis method.
[0014] The application also provides an electronic device, including a processor and the above-mentioned non-transitory computer readable storage medium.
[0015] The application has at least the following beneficial effects: by performing vulnerability scanning analysis on the target code, obtaining the initial risk evaluation value of the vulnerability, and combining the path reachability analysis value and the condition reachability analysis value to determine the reachability analysis weight, finally obtaining the target risk evaluation, fully considering the actual possibility of vulnerability exploitation, compared with the traditional risk assessment based on inherent harm, can more accurately reflect the real risk degree of vulnerability, and provide more reliable basis for security decision, the target risk evaluation value can provide reference for resource allocation, facilitate to prioritize high-risk vulnerabilities in the vulnerability repair process, avoid blind repair of vulnerabilities, and greatly improve the efficiency of vulnerability management. BRIEF DESCRIPTION OF DRAWINGS
[0016] In order to more clearly illustrate the technical solutions in the embodiments of the application, the drawings needed in the embodiment description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the application, and other drawings can be obtained by those skilled in the art without creative labor.
[0017] Figure 1A flow chart of a vulnerability risk reachability analysis method provided for the first embodiment of the present application. DETAILED DESCRIPTION
[0018] The technical solutions in the embodiments of the present application will be clearly and completely described in connection with the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by a person skilled in the art without creative work fall within the protection scope of the present application.
[0019] It should be noted that the terms "first", "second" and the like in the specification and claims of the present application and the above-described drawings are used to distinguish similar objects, and do not necessarily indicate a specific order or a chronological sequence. It can be understood that the above-described terms for distinguishing similar objects can be interchanged under appropriate circumstances, so that the present application can also be implemented in other embodiments in addition to the above-described illustrated embodiments or described embodiments. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, system, product or server including a series of steps or units does not necessarily have to include only those steps or units clearly listed, but can include other steps or units not clearly listed or inherent to the process, method, product or device.
[0020] Embodiment one
[0021] The first embodiment provides a vulnerability risk reachability analysis method, which comprises the following steps, as shown in Figure 1
[0022] S1, performing vulnerability scanning analysis on target code to obtain M target vulnerabilities, entry information corresponding to the M target vulnerabilities respectively, and initial risk evaluation values corresponding to the M target vulnerabilities respectively.
[0023] Wherein, M is a positive integer, the entry information can be a trigger function, a parameter position, etc., the vulnerability scanning analysis can be implemented by using a software component analysis technology to obtain the M target vulnerabilities, the entry information corresponding to the M target vulnerabilities respectively, and the initial risk evaluation values corresponding to the M target vulnerabilities respectively, and the software component analysis technology and the common vulnerability scoring system (CVSS score) are all prior art, which will not be described here.
[0024] Specifically, the initial risk evaluation values corresponding to the M target vulnerabilities are all normalized by comparison with a theoretical maximum initial risk evaluation value.
[0025] S2, for any target vulnerability, determine the call path between the target vulnerability and the entry information corresponding to the target vulnerability, the call path including N call sub-paths.
[0026] Wherein, N is a non-negative integer, and the call path refers to a complete call link from a vulnerability entry of the target vulnerability to a vulnerability trigger point of the target vulnerability.
[0027] The call sub-path can correspond to a functional module, that is, the call path is split into N call sub-paths according to the functional module, for example, the call sub-path can correspond to the functional modules of front end to gateway, gateway to business logic layer, business logic layer to database, etc.
[0028] Specifically, the implementer can obtain the call path through program slicing, control flow graph, call relationship graph, etc., when the target code is relatively complex, an automatic analysis tool can also be used to automatically analyze the call path, and the automatic analysis tool can use Ghidra tool, etc.
[0029] S3, according to the call path, the security protection information corresponding to the N call sub-paths, determine the path accessibility analysis value corresponding to the target vulnerability.
[0030] Wherein, the path accessibility analysis value can represent the difficulty of triggering the vulnerability by external attack, the easier the external attack triggers the vulnerability, the larger the path accessibility analysis value.
[0031] In a specific embodiment, S3 includes the following steps:
[0032] S31, if N=0, determine the path accessibility analysis value corresponding to the target vulnerability as a first preset value.
[0033] S32, if N≠0, according to the call path, the security protection information corresponding to the N call sub-paths, determine the path accessibility analysis value corresponding to the target vulnerability.
[0034] Wherein, when N=0, it means that there is no call path, and the target vulnerability is completely unreachable, so the path accessibility analysis value corresponding to the target vulnerability can be directly determined as the first preset value, in this embodiment, the value range of the path accessibility analysis value is [0, 1], and the first preset value is set to 0.
[0035] In a specific embodiment, the security protection information at least includes input filtering rules.
[0036] Wherein, the input filtering rules can include type checking, format checking, length checking, content checking, range checking, etc.
[0037] In an embodiment, the security protection information can further include a permission verification rule, and the permission verification rule can include an identity authentication rule, a data permission rule, an operation frequency rule, and the like.
[0038] In an embodiment, S32 includes the following steps:
[0039] S321, if N≠0, mapping the number N of the calling sub-paths contained in the calling path into a first impact weight by using a first mapping function.
[0040] S322, for the security protection information corresponding to any calling sub-path, obtaining the basic input data meeting the input filtering rule corresponding to the calling sub-path.
[0041] S323, initializing the iteration number Q=1.
[0042] S324, randomly generating noise data, and determining intermediate input data according to the noise data and the basic input data.
[0043] S325, inputting the intermediate input data into the trained generation model to obtain updated input data, and determining an update loss according to the basic input data, the updated input data, and a passing identifier of the updated input data to the input filtering rule.
[0044] S326, fixing the parameters of the trained generation model according to the update loss, updating the intermediate input data until the update loss converges, obtaining temporary input data, and updating Q=Q+1.
[0045] S327, returning to step S324 until Q=L+1, and obtaining L temporary input data, wherein L is a positive integer.
[0046] S328, determining the security protection coefficient corresponding to the calling sub-path according to the L temporary input data.
[0047] S329, determining a reference protection coefficient according to the security protection coefficients corresponding to the N calling sub-paths respectively, and taking the product of the first impact weight and the reference protection coefficient as the path reachability analysis value corresponding to the target vulnerability.
[0048] wherein the first mapping function can be represented as f1(N)=e -w×N wherein w is the first mapping weight, in the embodiment, w can be set to 0.4, and the implementer can adjust the value of w according to the actual situation, and w should be greater than 0 and less than 1.
[0049] The basic input data is data that can pass the input filtering rule, the noise data is randomly generated, and the noise data and the basic input data are obtained in a superposition manner.
[0050] The generation model can adopt an encoder-decoder architecture, for example, a U-Net network model, a variational autoencoder, etc. The generation model can be trained by using a data reconstruction task.
[0051] In an embodiment, the noise data can not be directly superimposed on the basic input data, but can be superimposed on the feature vector extracted by the encoder from the basic input data.
[0052] Specifically, according to the basic input data, the update input data, and the pass identifier of the update input data on the input filtering rule, the update loss can be determined, which can be calculated by the difference between the basic input data and the update input data to obtain a difference calculation result d, when the update input data can pass the input filtering rule, the pass identifier a is set to 0, and when the update input data cannot pass the input filtering rule, the pass identifier a is set to 1, and the update loss can be represented as L = b x (e a -1) + c x e -d , b is a first loss coefficient, c is a second loss coefficient, b and c satisfy b > c, in this embodiment, b is set to 100, and c is set to 10.
[0053] When a = 0, the update input data can pass the input filtering rule, at this time, the loss term b x (e a -1) is 0, when a = 1, the update input data cannot pass the input filtering rule, at this time, the loss term b x (e a -1) is much larger than 0, therefore, the loss term b x (e a -1) is used to supervise the intermediate input data to obtain the update input data that can pass the input filtering rule through the update.
[0054] Since the generation model aims to generate update input data that is different from the basic input data and can pass the input filtering rule, in order to simulate the input data of external attacks, the larger the difference calculation result d is, the smaller the loss term c x e -d , and the loss term c x e -d is used to supervise the difference between the basic input data and the update input data to be large enough.
[0055] The constraint b > c is set, and in general cases, b should be at least one order of magnitude larger than c to ensure that the update input data can pass the input filtering rule during the update. It can be known that if the input filtering rule only allows the basic input data to pass, the update input data will eventually be the same as the basic input data, so as to maximize the reduction of the update loss.
[0056] By analyzing each temporary input data obtained through multiple iterations, the difficulty of external attacks through the input data is represented, and the security protection coefficient corresponding to the calling sub-path is determined.
[0057] The security protection coefficients corresponding to the N calling sub-paths are calculated by mean value to obtain a reference protection coefficient.
[0058] In an embodiment, when the security protection information further includes a permission verification rule, the implementer can quantize the permission verification rule according to the strictness of the permission verification rule to obtain a permission verification coefficient. The more strict the permission verification rule is, the closer the permission verification coefficient is to 0. The more relaxed the permission verification rule is, the closer the permission verification coefficient is to 1. In this embodiment, the product of the first influence weight, the reference protection coefficient, and the permission verification coefficient is taken as the path reachability analysis value corresponding to the target vulnerability.
[0059] In a specific embodiment, S328 includes the following steps:
[0060] S3281, performing deduplication processing on the L temporary input data to obtain P target input data, where P is a positive integer.
[0061] S3282, mapping P to the security protection coefficient corresponding to the calling sub-path by using a second mapping function.
[0062] Wherein each target input data is different from each other, and the second mapping function can be represented as f2(P)=2 / (e -r×P +1)-1, and r is a second mapping weight. In this embodiment, r can be set to 0.2. The implementer can adjust the value of r according to the actual situation. r should be greater than 0 and less than 1.
[0063] Specifically, the smaller P is, the more reliable the security protection of the calling sub-path is, and the smaller the corresponding security protection coefficient is.
[0064] S4, determining a condition reachability analysis value corresponding to the target vulnerability according to the K trigger conditions corresponding to the target vulnerability.
[0065] Wherein K is a positive integer, the trigger condition can include a configuration condition, a timing condition, etc., and the condition reachability analysis value can represent the difficulty of triggering the target vulnerability. The easier the target vulnerability is triggered, the larger the condition reachability analysis value is.
[0066] In a specific embodiment, S4 includes the following steps:
[0067] S41, mapping K by using a third mapping function to obtain a mapping result.
[0068] S42, taking the mapping result as the condition reachability analysis value corresponding to the target vulnerability.
[0069] Wherein the third mapping function can be represented as f3(K)=e -t×KWherein, t is the third mapping weight, in this embodiment, t can be set as 0.8, and the implementer can adjust the value of t according to the actual situation.
[0070] In a specific embodiment, the implementer can also quantitatively represent the satisfaction difficulty evaluation value of each trigger condition based on prior information, the value range of the satisfaction difficulty evaluation value is [0, 1], the greater the satisfaction difficulty evaluation value, the easier the corresponding trigger condition is satisfied, and the minimum value of the satisfaction difficulty evaluation value of each trigger condition is multiplied by the mapping result to obtain the condition reachability analysis value corresponding to the target vulnerability.
[0071] S5, determining the reachability analysis weight corresponding to the target vulnerability according to the path reachability analysis value and the condition reachability analysis value corresponding to the target vulnerability.
[0072] Wherein, the reachability analysis weight can represent the difficulty of the target vulnerability being attacked by external attacks, the greater the reachability analysis weight, the easier the target vulnerability is attacked by external attacks.
[0073] In a specific embodiment, S5 includes the following steps:
[0074] S51, multiplying the path reachability analysis value and the condition reachability analysis value corresponding to the target vulnerability to obtain a first multiplication result.
[0075] S52, taking the first multiplication result as the reachability analysis weight corresponding to the target vulnerability.
[0076] Wherein, the value range of the path reachability analysis value and the condition reachability analysis value is [0, 1], so the value range of the reachability analysis weight is also [0, 1].
[0077] S6, determining the target risk evaluation value corresponding to the target vulnerability according to the initial risk evaluation value and the reachability analysis weight corresponding to the target vulnerability.
[0078] Wherein, the target risk evaluation value can represent the risk degree of the target vulnerability, the greater the target risk evaluation value, the greater the risk degree of the target vulnerability.
[0079] Specifically, the implementer can sort the target risk evaluation values of each target vulnerability to determine high-risk vulnerabilities and reasonably allocate resources.
[0080] In an embodiment, the implementer can also set a risk evaluation value threshold, and perform risk warning on the target vulnerability whose target risk evaluation value is greater than the risk evaluation value threshold.
[0081] In a specific embodiment, S6 includes the following steps:
[0082] S61, the initial risk evaluation value corresponding to the target vulnerability and the reachability analysis weight are multiplied to obtain a second multiplication result.
[0083] S62, the second multiplication result is taken as the target risk evaluation value corresponding to the target vulnerability.
[0084] The value range of the initial risk evaluation value and the reachability analysis weight is [0, 1], and therefore the value range of the target risk evaluation value is also [0, 1].
[0085] The initial risk evaluation value of the vulnerability is obtained by scanning and analyzing the target code, the reachability analysis weight is determined by combining the path reachability analysis value and the conditional reachability analysis value, and finally the target risk evaluation is obtained. The actual possibility of vulnerability exploitation is fully considered, compared with the traditional risk assessment based on inherent harm, the real risk degree of the vulnerability can be more accurately reflected, a more reliable basis for security decision is provided, the target risk evaluation value can provide a reference for resource allocation, and high-risk vulnerabilities can be preferentially processed in the vulnerability repair process, blind repair of vulnerabilities is avoided, and the efficiency of vulnerability management is greatly improved.
[0086] Embodiment two
[0087] The embodiment two of the present application provides a non-transitory computer readable storage medium which can be arranged in an electronic device to save at least one instruction or at least one program related to a method in the method embodiment, and the at least one instruction or the at least one program is loaded and executed by the processor to realize the vulnerability risk reachability analysis method provided in the above embodiment.
[0088] Embodiment three
[0089] The embodiment three of the present application provides an electronic device, which comprises a processor and the non-transitory computer readable storage medium in the embodiment two of the present application.
[0090] The above is only a preferred embodiment of the present application, and does not limit the present application in any form. Although the present application has been disclosed as above, it is not intended to limit the present application. Any skilled person in the art can make some changes or modifications to the above disclosed technical content without departing from the scope of the technical solution of the present application, and any simple modification, equivalent change and modification of the above embodiment according to the technical essence of the present application are still within the scope of the technical solution of the present application.
Claims
1. A method of vulnerability risk reachability analysis, the method comprising: The method comprises the following steps: S1, performing vulnerability scanning analysis on target code to obtain M target vulnerabilities, entry information corresponding to the M target vulnerabilities respectively, and initial risk evaluation values corresponding to the M target vulnerabilities respectively, wherein M is a positive integer; S2, for any target vulnerability, determining a call path between the target vulnerability and the entry information corresponding to the target vulnerability, the call path comprising N call sub-paths, wherein N is a non-negative integer; S3, determining a path reachability analysis value corresponding to the target vulnerability according to the call path, security protection information corresponding to the N call sub-paths respectively, wherein the security protection information at least comprises an input filtering rule, and if N≠0, determining the path reachability analysis value corresponding to the target vulnerability according to the call path and the security protection information corresponding to the N call sub-paths comprises the following steps: S321, mapping the number N of call sub-paths contained in the call path into a first influence weight through a first mapping function; S322, for the security protection information corresponding to any call sub-path, obtaining basic input data meeting the input filtering rule corresponding to the call sub-path; S323, initializing iteration times Q=1; S324, randomly generating noise data, and determining intermediate input data according to the noise data and the basic input data; S325, inputting the intermediate input data into a trained generation model to obtain updated input data, and determining an update loss according to the basic input data, the updated input data, and a passing identifier of the updated input data to the input filtering rule; S326, fixing parameters of the trained generation model according to the update loss, updating the intermediate input data until the update loss converges, obtaining temporary input data, and updating Q=Q+1; S327, returning to step S324 until Q=L+1, obtaining L temporary input data, wherein L is a positive integer; S328, determining a security protection coefficient corresponding to the call sub-path according to the L temporary input data; S329, determining a reference protection coefficient according to the security protection coefficients corresponding to the N call sub-paths, and taking the product of the first influence weight and the reference protection coefficient as the path reachability analysis value corresponding to the target vulnerability; S4, determining a condition reachability analysis value corresponding to the target vulnerability according to K trigger conditions corresponding to the target vulnerability, wherein K is a positive integer; S5, determining a reachability analysis weight corresponding to the target vulnerability according to the path reachability analysis value and the condition reachability analysis value corresponding to the target vulnerability; S6, determining a target risk evaluation value corresponding to the target vulnerability according to the initial risk evaluation value and the reachability analysis weight corresponding to the target vulnerability.
2. The method of vulnerability risk reachability analysis of claim 1, wherein, S3 comprises the following steps: S31, if N=0, determining the path reachability analysis value corresponding to the target vulnerability as a first preset value.
3. The method of vulnerability risk reachability analysis of claim 1, wherein, S328 comprises the following steps: S3281, performing deduplication processing on the L temporary input data to obtain P target input data, wherein P is a positive integer; S3282, mapping P into a security protection coefficient corresponding to the calling sub-path through a second mapping function.
4. The method of vulnerability risk reachability analysis of claim 1, wherein, S4 includes the following steps: S41, mapping K through a third mapping function to obtain a mapping result; S42, taking the mapping result as a conditional reachability analysis value corresponding to the target vulnerability.
5. The method of vulnerability risk reachability analysis of claim 4, wherein, S5 includes the following steps: S51, multiplying the path reachability analysis value and the conditional reachability analysis value corresponding to the target vulnerability to obtain a first multiplication result; S52, taking the first multiplication result as a reachability analysis weight corresponding to the target vulnerability.
6. The method of vulnerability risk reachability analysis of claim 1, wherein, S6 includes the following steps: S61, multiplying the initial risk evaluation value and the reachability analysis weight corresponding to the target vulnerability to obtain a second multiplication result; S62, taking the second multiplication result as a target risk evaluation value corresponding to the target vulnerability. 7.A non-transitory computer-readable storage medium having stored therein at least one instruction or at least one piece of program, characterized in that, The at least one instruction or the at least one program is loaded and executed by the processor to implement the method for vulnerability risk reachability analysis according to any one of claims 1-6.
8. An electronic device, comprising: The processor and the non-transitory computer readable storage medium described in claim 7.
Citation Information
Patent Citations
Vulnerability assessment method and device, electronic equipment and storage medium
CN119357976A