A method and system based on determining the impact scope of software vulnerabilities
By storing and analyzing the relationship between known vulnerabilities and basic files, we can determine whether there are vulnerabilities in software compiled from different open source software versions, and solve the problem of difficulty in detecting software based on Linux core files in the existing technology, and achieve the completion of the scope of the vulnerability impact and the improvement of network security detection.
Patent Information
- Application Number
- CN202111205715.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-10-15
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2041-10-15
AI Technical Summary
It is difficult to determine whether software developed based on Linux core files has vulnerabilities, especially because the same core files may have different file names and some core files are not identified, which makes vulnerability detection difficult.
By storing known vulnerabilities, related basic files and their associated path relationships, obtain different open source software versions containing these basic files, and determine whether the software compiled from these open source software has known vulnerabilities, and build a vulnerability map for vulnerability detection.
It achieves the completion of the impact range of software vulnerabilities, can predict software products that are actually affected by known vulnerabilities but are not recorded by the vulnerability library, and improves network security detection capabilities.
Smart Images

Figure CN114139160B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a method and system for determining the impact range of a software vulnerability, and a software vulnerability detection method and system. Background Art
[0002] The Linux kernel implements many important architectural properties. At a higher or lower level, the kernel is divided into multiple subsystems. Linux can also be viewed as a monolith because it integrates all basic services into the kernel. Linux is very portable for its size and complexity. Linux can be compiled to run on a large number of processors and platforms with different architectural constraints and requirements.
[0003] Due to the open source, convenience, and high performance of Linux, there are many software compiled based on the Linux core. The security of software is of great importance to every user, enterprise, and country. Therefore, some countries develop and operate vulnerability libraries to publicize the discovered vulnerabilities on a regular basis. When enterprises find that the software they operate has vulnerabilities, they will perform security upgrades on the software, and users will also use security monitoring software to detect vulnerabilities in the installed software. However, after the software developed based on the Linux core files is compiled, the same core files may have different file names, and some core files are not marked, resulting in that even if some Linux core files are publicized to have vulnerabilities, there is no way to know that some software developed based on them has vulnerabilities. Summary of the invention
[0004] In view of the above problems, the present invention is proposed to provide a technical solution to overcome the above problems or at least partially solve the above problems. Therefore, one aspect of the present invention provides a method for determining the impact scope of a software vulnerability, the method comprising:
[0005] storing an association path relationship between a known vulnerability, a first software having the known vulnerability, a first open source software based on the first software, and a basic file causing the known vulnerability, wherein the first open source software contains the basic file;
[0006] Storing the mapping relationship between known vulnerabilities and the basic files;
[0007] According to the basic file, obtaining a second open source software including the basic file,
[0008] Obtaining second software compiled based on the second open source software, and determining whether the second software has the known vulnerability;
[0009] The associated path relationship among the known vulnerability, the second software, the second open source software, and the basic file is stored.
[0010] Optionally, a vulnerability map is constructed based on the stored relationship.
[0011] Optionally, the first open source software and the second open source software include different Linux kernel versions.
[0012] The present invention also provides a software vulnerability detection method, which is characterized in that the vulnerability map constructed above is used to perform vulnerability detection on the software to be tested.
[0013] The present invention also provides a system for determining the impact range of a software vulnerability, the system comprising:
[0014] A first storage unit is used to store an association path relationship between a known vulnerability, a first software having the known vulnerability, a first open source software based on the first software, and a basic file causing the known vulnerability, wherein the open source software contains the basic file;
[0015] The second storage unit stores a mapping relationship between known vulnerabilities and the basic files;
[0016] an open source software analysis module, configured to obtain, according to the basic file, a second open source software including the basic file,
[0017] an application software analysis module, configured to obtain second software compiled based on the second open source software, and determine whether the second software has the known vulnerability;
[0018] The third storage unit is used to store the associated path relationship between the known vulnerability, the second software, the second open source software, and the basic file.
[0019] Optionally, the system further includes a vulnerability map component unit, which is used to construct a vulnerability map according to the relationship stored in the first storage unit, the second storage unit, and the third storage unit.
[0020] Optionally, the first open source software and the second open source software include different Linux kernel versions.
[0021] The present invention also provides a software vulnerability detection system, which also includes a vulnerability detection unit for performing vulnerability detection on the software to be tested using the vulnerability map constructed above.
[0022] The technical solution provided by the present application has at least the following technical effects or advantages: using multi-dimensional information related to vulnerabilities to deduce and predict software products that are actually affected by known vulnerabilities but are not recorded in the vulnerability library.
[0023] The above description is only an overview of the technical solution of the present invention. In order to more clearly understand the technical means of the present invention, it can be implemented according to the contents of the specification. In order to make the above technical solution of the present invention and its objectives, features and advantages more obvious and easy to understand, the specific implementation methods of the present invention are listed below. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] Various other advantages and benefits will become apparent to those of ordinary skill in the art by reading the detailed description of the preferred embodiments below. The accompanying drawings are only for the purpose of illustrating the preferred embodiments and are not to be considered as limiting the present invention. Moreover, the same reference symbols are used throughout the accompanying drawings to represent the same components. In the accompanying drawings:
[0025] Figure 1 The process of the method for determining the impact scope of a software vulnerability provided by the present invention is shown;
[0026] Figure 2 It shows the known and determined association path relationships stored by the present invention;
[0027] Figure 3 A vulnerability map of a specific implementation is shown. DETAILED DESCRIPTION
[0028] The exemplary embodiments of the present invention will be described in more detail below with reference to the accompanying drawings. Although the exemplary embodiments of the present invention are shown in the accompanying drawings, it should be understood that the present invention can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided in order to enable a more thorough understanding of the present invention and to enable the scope of the present invention to be fully communicated to those skilled in the art.
[0029] The Linux kernel is mainly composed of five subsystems: process scheduling, memory management, virtual file system, network interface, and inter-process communication. Among them, process scheduling (SCHED) controls the process's access to the CPU. When the next process needs to be selected, the scheduler selects the most worthy process to run; memory management (MM) allows multiple processes to safely share the main memory area; the virtual file system (Virtual File System, VFS) hides the specific details of various hardware and provides a unified interface for all devices. VFS provides up to dozens of different file systems; the network interface (NET) provides access to various network standards and support for various network hardware; inter-process communication (IPC) supports various communication mechanisms between processes.
[0030] With the development of Linux, new versions are constantly generated. Generally, the version number of Linux consists of three parts: the first part represents the main version number of the kernel, which is changed only when there are structural changes; the second part represents the minor version number of the kernel, which is changed only when new functions are added; the third part represents the revision number of the kernel, which represents the number of patch packages or the number of modifications of the minor version, the number of compilations (or builds). Although Linux has different versions, they all include five basic files, and many times, they include many identical basic files. If a basic file has a vulnerability, it is very likely that the software developed based on the Linux version that includes this basic file is affected by the vulnerability. Based on this discovery, the present invention deeply explores the associations based on the basic files with vulnerabilities, and intends to propose a method and system for completing the scope of vulnerability impact.
[0031] One aspect of the present invention provides a method for determining the impact scope of a software vulnerability, such as Figure 1 As shown, the method includes:
[0032] S1. storing the association path relationship between a known vulnerability, a first software having the known vulnerability, a first open source software based on the first software, and a basic file causing the known vulnerability, wherein the open source software contains the basic file;
[0033] S2. Store the mapping relationship between known vulnerabilities and the basic files;
[0034] S3. According to the basic file, obtaining a second open source software including the basic file;
[0035] S4. Obtaining a second software compiled based on the second open source software, and determining whether the second software has the known vulnerability;
[0036] S5. Storing the associated path relationship between the known vulnerability, the second software, the second open source software, and the basic file.
[0037] Through the above method, the vulnerability impact range can be supplemented, which can largely solve the problem of missing a large number of vulnerability impact ranges in the current vulnerability database, such as Figure 2 As shown, the present invention mines a known first association path stored in a first storage unit, a second association path stored in a second storage unit, and analyzes and determines a third association path, that is, discovers or identifies that the second software has the known vulnerability.
[0038] The first open source software and the second open source software include different Linux kernel versions. For the convenience of description, the present invention selects the Linux kernel open source core component for description, and the present invention is not limited to the Linux open source system.
[0039] As a specific implementation method, Figure 3 As shown in the figure, the three different versions of Linux_kernel, Linux Kernel 2.6, Linux Kernel 2.6.18, and Linux Kernel 2.6.32, are all based on the basic file mm / gup.c. The vulnerability database has recorded that the basic file mm / gup.c has the vulnerability CVE-2016-5195. At the same time, both versions of the application software Redhat Enterprise Linux 5 and Redhat Enterprise Linux 6 have vulnerabilities. This is because Redhat Enterprise Linux 5 is compiled based on Linux Kernel 2.6.18, and Redhat Enterprise Linux 6 is compiled based on Linux Kernel 2.6.32. The present application has found through analysis of Google Android 1.1 that Google Android 1.1 is compiled or developed based on Linux Kernel 2.6. At the same time, through analysis of Linux Kernel 2.6, it has been found that it is built on the basic file mm / gup.c with a vulnerability. Although there is no record in the Google Android 1.1 software package reflecting the information of the basic file mm / gup.c, and neither the network security news information, the CVD vulnerability platform nor other vulnerability information sources have disclosed the vulnerability CVE-2016-5195 related to the basic file in Google and Android, the present application provides the vulnerability CVE-2016-5195 in Google Android 1.1 after discovering this connection.
[0040] Through the description of the above specific implementation methods, the present application aims to discover invisible vulnerabilities, thereby ensuring network security. In the present invention, a path mining method is provided, that is, based on the discovered fact that two operating systems of RedHat have vulnerabilities due to vulnerabilities in basic files, some hidden and difficult to identify vulnerabilities are discovered. For example, the gup.c file exists in the Google operating system, but the Google system does not describe the gup.c file, but only records that it is developed based on the Lunix_kernal 2.6 version file. The gop.c file has a vulnerability, a vulnerability with a known CVE number, which affects two versions of Redhat's operating system. The upstream of the two versions of Redhat's operating system is two revised versions of LinuxKernel 2.6. By analyzing that Lunix_kernal 2.6 is the same as the two revised versions of Linux Kernel 2.6, it is built on the gup.c file, and it can be determined that the known vulnerability affects the Google operating system. The present invention constructs a vulnerability map by obtaining the relationship between the basic files and vulnerabilities of open source components, and the association between the upstream source open source components and the basic files as the development basis (open source component file structure relationship). Based on the vulnerability map, it can be determined that the Google operating system has the CVE number vulnerability.
[0041] On the other hand, the present invention can construct a vulnerability map based on the above-mentioned stored relationship, that is, the vulnerability map includes known software affected by the vulnerability, the vulnerability comes from a basic file mm / gup.c, all Linux_kernel versions built on the basic file, and the software developed and compiled based on all the Linux_kernel versions are affected by the vulnerability.
[0042] The present invention also provides a software vulnerability detection method, which uses the vulnerability map constructed above to perform vulnerability detection on the software to be tested, that is, by matching the software to be tested with software developed and compiled based on all the Linux_kernel versions, it is determined whether the software to be tested is affected by the vulnerability.
[0043] The present invention also provides a system for determining the impact range of a software vulnerability, the system comprising:
[0044] A first storage unit is used to store an association path relationship between a known vulnerability, a first software having the known vulnerability, a first open source software based on the first software, and a basic file causing the known vulnerability, wherein the open source software contains the basic file;
[0045] The second storage unit stores a mapping relationship between known vulnerabilities and the basic files;
[0046] an open source software analysis module, configured to obtain, according to the basic file, a second open source software including the basic file,
[0047] an application software analysis module, configured to obtain second software compiled based on the second open source software, and determine whether the second software has the known vulnerability;
[0048] The third storage unit is used to store the associated path relationship between the known vulnerability, the second software, the second open source software, and the basic file.
[0049] The system also includes a vulnerability map component unit, which is used to construct a vulnerability map according to the relationship stored in the first storage unit, the second storage unit, and the third storage unit.
[0050] The first open source software and the second open source software include different Linux kernel versions.
[0051] The present invention also provides a software vulnerability detection system, which also includes a vulnerability detection unit for performing vulnerability detection on the software to be tested using the vulnerability map constructed above.
[0052] The technical solution provided by the present application has at least the following technical effects or advantages: using multi-dimensional information related to vulnerabilities to deduce and predict software products that are actually affected by known vulnerabilities but are not recorded in the vulnerability library.
[0053] In the description provided herein, a large number of specific details are described. However, it is understood that embodiments of the present invention can be practiced without these specific details. In some instances, well-known methods, structures and techniques are not shown in detail so as not to obscure the understanding of this description.
[0054] Similarly, it should be understood that in order to streamline the present invention and aid in understanding one or more of the various inventive aspects, in the above description of exemplary embodiments of the present invention, the various features of the present invention are sometimes grouped together into a single embodiment, figure, or description thereof. However, this disclosed method should not be interpreted as reflecting the following intention: that the claimed invention requires more features than the features explicitly recited in each claim. More specifically, as reflected in the claims below, inventive aspects lie in less than all the features of the individual embodiments disclosed above. Therefore, the claims that follow the specific embodiment are hereby expressly incorporated into the specific embodiment, with each claim itself serving as a separate embodiment of the present invention.
[0055] It should be noted that the above embodiments illustrate the present invention rather than limit the present invention, and those skilled in the art may design alternative embodiments without departing from the scope of the appended claims. In the claims, any reference symbol between brackets shall not be construed as a limitation to the claims.
Claims
1. A method based on determining the scope of impact of software vulnerabilities, It is characterized in that The method includes: storing an association path relationship between a known vulnerability, a first software having the known vulnerability, a first open source software based on the first software, and a basic file causing the known vulnerability, wherein the first open source software contains the basic file; Storing the mapping relationship between known vulnerabilities and the basic files; According to the basic file, obtaining a second open source software including the basic file, Obtaining second software compiled based on the second open source software, and determining whether the second software has the known vulnerability; Storing the associated path relationship between the known vulnerability, the second software, the second open source software, and the basic file; The method also includes: constructing a vulnerability map based on the stored relationships, wherein the relationships include: an associated path relationship between a known vulnerability, a first software having the known vulnerability, a first open source software on which the first software is based, and a basic file causing the known vulnerability, a mapping relationship between the known vulnerability and the basic file, and an associated path relationship between a known vulnerability, a second software, a second open source software, and a basic file.
2. The method according to claim 1, Its characteristics are also that The first open source software and the second open source software are different Linux kernel versions.
3. A software vulnerability detection method, It is characterized in that The vulnerability map constructed by claim 1 is used to perform vulnerability detection on the software to be tested.
4. A system based on determining the scope of impact of software vulnerabilities, It is characterized in that The system includes: A first storage unit is used to store an association path relationship between a known vulnerability, a first software having the known vulnerability, a first open source software based on the first software, and a basic file causing the known vulnerability, wherein the first open source software contains the basic file; A second storage unit is used to store a mapping relationship between known vulnerabilities and the basic files; an open source software analysis module, configured to obtain, according to the basic file, a second open source software including the basic file, an application software analysis module, configured to obtain second software compiled based on the second open source software, and determine whether the second software has the known vulnerability; A third storage unit is used to store the associated path relationship between the known vulnerability, the second software, the second open source software, and the basic file; The system also includes a vulnerability map component unit, which is used to construct a vulnerability map according to the relationship stored in the first storage unit, the second storage unit, and the third storage unit; wherein the relationship includes: the associated path relationship between a known vulnerability, a first software having the known vulnerability, a first open source software based on the first software, and a basic file causing the known vulnerability, a mapping relationship between the known vulnerability and the basic file, and an associated path relationship between the known vulnerability, the second software, the second open source software, and the basic file.
5. The system according to claim 4, Its characteristics are also that The first open source software and the second open source software are different Linux kernel versions.
6. A software vulnerability detection system, It is characterized in that The system includes a vulnerability detection unit, which is used to perform vulnerability detection on the software to be tested using the vulnerability map constructed according to claim 4.