A method and system for constructing a software package naming matrix

By building a software package naming matrix, the problem of incomplete vulnerability detection caused by different software names on different operating systems is solved, the accuracy of vulnerability identification is improved, and the accuracy of vulnerability identification is continuously improved through the continuous improvement of the matrix.

CN114168960BActive Publication Date: 2025-05-30BEIJING ZHONGKE WEILAN TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111204316.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-10-15
Publication Date
2025-05-30
Estimated Expiration
2041-10-15

AI Technical Summary

Technical Problem

In vulnerability management, the same software has different names on different operating systems, resulting in incomplete vulnerability detection.

Method used

By obtaining the open source file information of all software in each operating system, the upstream source information is parsed. If the software of different operating systems has the same upstream source, a mapping relationship between their names is established to form a software package naming matrix, which is used to match the alias of the software to be tested and match the vulnerability database.

Benefits of technology

It improves the accuracy of software security detection, ensures the comprehensiveness of vulnerability identification, and continuously improves the accuracy of vulnerability identification through the continuously improved software package naming matrix.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114168960B_ABST
    Figure CN114168960B_ABST
Patent Text Reader

Abstract

The present invention discloses a method for constructing a software package naming matrix. The method includes: obtaining the open-source file information of all software for each operating system; parsing out the upstream source information of all software according to the open-source file information; if software with different names in different operating systems has the same upstream source, it is considered that the different names correspond to the same software, establishing a mapping relationship between different names of the same software, and forming a software package naming matrix based on the mapping relationship; performing name matching on the software to be tested based on the software package naming matrix to obtain an alias of the software to be tested, and matching the alias with the vulnerability information in the known vulnerability database to make up for the problem that security vulnerabilities cannot be identified based on the package name of the software.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical fields of host and network security, and particularly to a method and system for constructing a software package naming matrix. Background Art

[0002] Vulnerability management generally involves scanning each machine to obtain vulnerability scan results, identifying the vulnerability scan results to discover vulnerabilities, and providing corresponding repair methods. Generally speaking, the vulnerability repair priority is determined according to the importance of network nodes and external threat events. As the number of networked machines such as virtual machines, servers, and hosts increases, the number of discovered vulnerabilities also increases. The danger levels of vulnerabilities are different, the importance of each machine and the impact of external events are also different, and the processing order and repair strategies for vulnerability handling are also different, thus developing vulnerability management technology. Vulnerability management technology has been applied in host security management systems, threat intrusion detection, and network security comprehensive management, etc.

[0003] In vulnerability management, especially when detecting vulnerabilities in various software of different operating systems, since in many cases, the same software has different names in different operations, and the vulnerability data publicly available in the vulnerability database does not cover all different names of a software, there is often an incomplete vulnerability detection situation. Summary of the Invention

[0004] In view of the above problems, the present invention is proposed to provide a technical solution that overcomes or at least partially solves the above problems. Therefore, in one aspect of the present invention, a method for constructing a software package naming matrix is provided, and the method includes:

[0005] Obtain the open source file information of all software of each operating system;

[0006] Parse out the upstream source information of all software according to the open source file information;

[0007] If different names of software in different operating systems have the same upstream source, it is considered that the different names correspond to the same software;

[0008] Establish a mapping relationship between different names of the same software, and form a software package naming matrix based on the mapping relationship;

[0009] Perform name matching on the software to be tested based on the software package naming matrix to obtain an alias of the software to be tested; match the alias with the vulnerability information in the known vulnerability database to perform vulnerability identification.

[0010] Parse out the upstream source information in the corresponding software package according to the spec file information in the software.

[0011] Optionally, according to the control file information of the software, the upstream source information in the corresponding software package is parsed out.

[0012] Optionally, based on the software package naming matrix, name matching of the software to be tested is performed to obtain an alias of the software to be tested, including: querying in the software package naming matrix using the software name of the software to be tested to obtain the alias corresponding to the name.

[0013] Optionally, the method further includes:

[0014] Obtain the package name of the software to be tested;

[0015] According to the package name, match the software to be tested with the known information in the vulnerability database. If the match is unsuccessful, then find its alias through the package naming matrix, and then match based on the alias with the vulnerability information in the known vulnerability database for vulnerability identification.

[0016] The present invention also provides a software package naming matrix construction system, which includes:

[0017] An open source file acquisition module, used to acquire the open source file information of all software of each operating system;

[0018] An upstream source information parsing module, which parses out the upstream source information of all software according to the open source file information;

[0019] A software package naming matrix construction module. If software with different names in different operating systems has the same upstream source, it is considered that the different names correspond to the same software, and a mapping relationship between different names of the same software is established, and a software package naming matrix is formed based on the mapping relationship;

[0020] A package name expansion module, used to perform name matching of the software to be tested based on the software package naming matrix to obtain an alias of the software to be tested;

[0021] A vulnerability identification module, used to match based on the alias with the vulnerability information in the known vulnerability database for vulnerability identification.

[0022] Optionally, the upstream source information parsing module parses out the upstream source information of all software according to the spec file information of the known vulnerability software.

[0023] Optionally, the upstream source information parsing module parses out the upstream source information of all software according to the control file information of the known vulnerability software.

[0024] Optionally, the package name expansion module searches in the software package naming matrix using the software name of the software to be tested to obtain the alias corresponding to the software name.

[0025] Optionally, the vulnerability identification module is further configured to match the software to be tested with the known information in the vulnerability database according to the package name of the software to be tested; if the match fails, the package name extension module finds its alias through the package naming matrix, and the vulnerability identification module then matches based on the alias with the vulnerability information in the known vulnerability database to perform vulnerability identification.

[0026] The technical solution provided by this application has at least the following technical effects or advantages: The present invention innovatively discovers that software developed based on the same upstream source basically has the same vulnerabilities. Based on this discovery and understanding, the present invention parses the upstream source information of the software package, obtains the software package names with different package names in each operating system based on the same upstream source, and establishes the mapping relationship of the software package names to construct a software package naming matrix. Based on this software package naming matrix, the alias of the package name of the software to be detected is obtained, and it is matched with the software information in the known vulnerability database to determine whether there are vulnerabilities in the software to be detected, improving the accuracy of software security detection. Moreover, as the vulnerability identification system is used, the software package naming matrix continuously self-improves, making the vulnerability identification accuracy continuously improve.

[0027] The above description is only an overview of the technical solution of the present invention. In order to be able to understand the technical means of the present invention more clearly, it can be implemented according to the content of the specification. And in order to make the above technical solution, its purpose, features and advantages of the present invention more obvious and understandable, the following specific embodiments of the present invention are specifically given. Brief Description of the Drawings

[0028] By reading the detailed description of the preferred embodiments below, various other advantages and benefits will become clear to those of ordinary skill in the art. The drawings are only for the purpose of showing the preferred embodiments and are not considered to be a limitation of the present invention. And throughout the drawings, the same reference numerals are used to represent the same components. In the drawings:

[0029] Figure 1 Shows the flowchart of a method for identifying vulnerabilities based on a software package naming matrix according to an embodiment provided by the present invention;

[0030] Figure 2 Shows the flowchart of a method for identifying vulnerabilities based on a software package naming matrix according to another embodiment provided by the present invention. Detailed Embodiments

[0031] The exemplary embodiments of the present invention will be described in more detail below with reference to the drawings. Although the exemplary embodiments of the present invention are shown in the drawings, it should be understood that the present invention can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided so that the present invention can be more thoroughly understood and the scope of the present invention can be completely conveyed to those skilled in the art.

[0032] In this application, when collecting information about vulnerabilities, it is necessary to extract the package information of many different operating systems in real time, including the names of the packages. However, the naming methods of packages in different operating systems are different, resulting in different names. For example, a main file type on the Windows operating system is a WPA file regarded as an ACT Word Processing Document format, and on other operating systems, the format has other names, such as wifi and protected sice. When constructing a knowledge graph, a node represents a software information. When collecting and identifying vulnerability data, if only collecting and identifying based on the package names of known vulnerabilities, it is very easy to regard software with different names but the same essence as different nodes, which will affect the identification of vulnerabilities. The present invention aims to solve this technical problem. Many software is developed based on open-source software, and software developed based on the same upstream open-source components (upstream sources) is basically the same software. In this application, by extracting the information of the upstream sources of the spec files of the software packages of all operating systems, if the upstream sources are the same, it indicates that these two software packages are essentially the same software package. Based on the information of the upstream sources, determine the software packages based on the same upstream sources, establish a mapping relationship between the package names of these software packages, and they are aliases of each other. Based on these package names, construct a software package naming matrix. For example, the name of the software package of the openEuler operating system is "python-memcached", while the name of the software package of the openSUSE operating system is "memcached". The two software package names are different, but they are compiled from the same upstream source file and are actually the same software package.

[0033] One aspect of the present invention provides a method for constructing a software package naming matrix, as Figure 1 shown, the method includes:

[0034] S1. Obtain the open-source file information of all software of each operating system;

[0035] S2. Parse out the upstream source information of all software according to the open-source file information;

[0036] S3. If different names of software in different operating systems have the same upstream source, it is considered that the different names correspond to the same software;

[0037] S4. Establish a mapping relationship between different names of the same software, and form a software package naming matrix based on the mapping relationship;

[0038] S5. Perform name matching on the software to be tested based on the software package naming matrix to obtain the alias of the software to be tested;

[0039] S6. Match the alias with the vulnerability information in the known vulnerability database to identify vulnerabilities.

[0040] The above method can be mainly used for the lunix open-source project. By parsing configuration files such as spec files and control files in the software package, these configuration files record which open-source components from upstream are used to compile the software. Software compiled based on the same upstream open-source components (upstream sources) is considered substantially the same software and may have the same vulnerabilities.

[0041] The full name of CPE is Common Platform Enumeration, which means Common Platform Enumeration Item. It is a unified naming specification for IT products, including systems, platforms, upstream components, and software packages, etc. The common format is as follows:

[0042] cpe: / ::::::

[0043] Among them, part represents the target type, and the allowed values are a (application), h (hardware platform), o (operating system); vendor represents the vendor; product represents the product name; version represents the version number; update represents the update package; edition represents the version; language represents the language item. Through the CPE file, the upstream component information (upstream source information) of the open-source software can be obtained.

[0044] This method tracks the upstream name of the software package and the software package names corresponding to other Linux distributions in real time, and establishes a mapping relationship between the software names developed based on the same upstream open-source components to form a matrix. This matrix can be used to associate the components affected by the vulnerability. According to the information in the CPE of the vulnerability, it can be found whether the relevant Linux distribution has this vulnerability. If there is a vulnerability, the software affected by the vulnerability in the corresponding Linux distribution is associated. Thus, the software package name matching of different Linux vendors is carried out by constructing a software package naming matrix.

[0045] As a specific implementation, to detect whether an application software A has vulnerabilities, this application software A is developed based on an open-source program, and the vulnerability library has no record of the vulnerabilities existing in this application software A. First, scan the predetermined files of this application software A to obtain the software name of this software, and match the software name with the software information in the known vulnerability library. If the match is successful, it is determined that the software has vulnerabilities. If the match is not successful, then match according to the software name in the software package naming matrix. If the match is successful, the corresponding alias of this application software is determined. Use this alias to further match in the known vulnerability library. If the match is successful, it is determined that the software has vulnerabilities. If the match is not successful, it is considered that the software has no vulnerabilities.

[0046] In the software package naming matrix, each software is an entity, and the entity has related attributes. The entity and related attributes form an AI, and the relationships between entities form a knowledge structure that can be used for operations. The software package naming matrix, as a software knowledge graph, can be used to expand software package names and perform reasoning operations using the attribute relationships between software because it contains rich information.

[0047] As a configuration file for software packages, the SPEC file includes the name of the software package, the actual version number of the software, the release serial number, the software licensing method, the name of the upstream source component, and the source code package. Information about the upstream components (upstream source information) of the software can be obtained by parsing the SPEC file.

[0048] As a specific implementation, according to the SPEC file information of known vulnerable software, the upstream open-source component information (upstream source information) in the corresponding software package is parsed.

[0049] As another specific implementation, the upstream open-source component information (upstream source information) in the corresponding software package can also be parsed according to the control file information of known vulnerable software.

[0050] Based on the software package naming matrix, the security of software is identified to determine whether there are vulnerabilities in the software, including: matching the software name of the software to be tested in the software package naming matrix. If the match is successful, the alias of the software to be tested is determined according to the match result.

[0051] In the case where the software naming matrix fails to match the name of the software to be tested, the method further includes:

[0052] S1’ Obtain the open-source file information of the software to be tested;

[0053] S2’ Parse the upstream open-source component information according to the open-source file information;

[0054] S3’ Match the upstream open-source component information with the relevant information of known vulnerable software in the vulnerability library;

[0055] S4’ If a match is found, it is determined that the software to be tested has a vulnerability corresponding to the matched software.

[0056] Through this process, the software package naming matrix is updated and supplemented based on the results of upstream open-source component matching, thereby further improving the software package naming matrix. In fact, as new software continuously appears, the software package naming matrix is constantly updated and improved.

[0057] The present invention also provides a software package naming matrix construction system, which includes:

[0058] An open-source file acquisition module for acquiring open-source file information of all software for each operating system;

[0059] An upstream source information parsing module for parsing all software's upstream source information according to the open-source file information;

[0060] A software package naming matrix construction module, if different software with different names on different operating systems has the same upstream source, it is considered that the different names correspond to the same software, and a mapping relationship between different names of the same software is established, and a software package naming matrix is formed based on the mapping relationship;

[0061] A package name extension module for matching the name of the software to be tested based on the software package naming matrix to obtain an alias of the software to be tested;

[0062] A vulnerability identification module for matching the alias with the vulnerability information in the known vulnerability database to identify vulnerabilities.

[0063] As a specific implementation, the upstream source information parsing module parses all software's upstream source information according to the spec file information of the software with known vulnerabilities.

[0064] As another specific implementation, the upstream source information parsing module parses all software's upstream source information according to the control file information of the software with known vulnerabilities.

[0065] The package name extension module searches in the software package naming matrix using the software name of the software to be tested to obtain the alias corresponding to the software name.

[0066] The vulnerability identification module is also used to match the software to be tested with the known information in the vulnerability library according to the package name of the software to be tested; if the match is unsuccessful, the package name extension module finds its alias through the package naming matrix, and the vulnerability identification module then matches the alias with the vulnerability information in the known vulnerability database to identify vulnerabilities.

[0067] The technical solution provided by this application has at least the following technical effects or advantages: The present invention innovatively discovers that software developed based on the same upstream source basically has the same vulnerabilities. Based on this discovery and understanding, the present invention parses the upstream source information of software packages, obtains the names of software packages with different package names in each operating system based on the same upstream source, and establishes the mapping relationship of the names of these software packages to construct a software package naming matrix. Based on this software package naming matrix, the aliases of the package names of the software to be detected are obtained, and the aliases are matched with the software information in the known vulnerability library to determine whether there are vulnerabilities in the software to be detected, improving the accuracy of software security detection. Moreover, as the vulnerability identification system is used, the software package naming matrix continuously improves itself, making the vulnerability identification accuracy continuously improve.

[0068] The present invention is applicable to the security identification of software developed based on open-source software code, can achieve centralized identification of multiple devices in a short time, and is applicable to being set in the cloud, network link nodes, server backgrounds, etc.

[0069] In the specification provided here, a large number of specific details are described. However, it can be understood that the embodiments of the present invention can be practiced without these specific details. In some instances, well-known methods, structures, and technologies are not shown in detail so as not to obscure the understanding of this specification.

[0070] Similarly, it should be understood that, in order to streamline the present invention and help understand one or more of the various aspects of the invention, in the above description of the exemplary embodiments of the present invention, the various features of the present invention are sometimes grouped together into a single embodiment, figure, or description thereof. However, the disclosed method should not be construed as reflecting the intention that the claimed invention requires more features than are expressly recited in each claim. Rather, as reflected in the following claims, the aspects of the invention lie in less than all the features of the single foregoing disclosed embodiment. Thus, the claims following the detailed description are hereby expressly incorporated into the detailed description, where each claim stands on its own as a separate embodiment of the present invention.

[0071] It should be noted that the above embodiments illustrate the present invention rather than limit the present invention, and those skilled in the art can design alternative embodiments without departing from the scope of the appended claims. In the claims, any reference signs placed between parentheses shall not be construed as limiting the claim.

Claims

1. A method for constructing a software package naming matrix, characterized in that, the method includes: Obtain the open-source file information of all software for each operating system; Parse out the upstream source information of all software according to the open-source file information; If different software with different names on different operating systems have the same upstream source information, it is considered that the different names correspond to the same software; Establish a mapping relationship between different names of the same software, and form a software package naming matrix based on the mapping relationship; Perform name matching on the software to be tested based on the software package naming matrix to obtain an alias of the software to be tested; Match the alias with the vulnerability information in the known vulnerability database to perform vulnerability identification; The upstream source information is upstream open-source component information, and the upstream source information in the corresponding software package is parsed according to the spec file information or control file information in the software.

2. The method according to claim 1, further characterized in that, Performing name matching on the software to be tested based on the software package naming matrix to obtain an alias of the software to be tested, including: querying in the software package naming matrix using the software name of the software to be tested to obtain the alias corresponding to the name.

3. The method according to claim 1, further characterized in that, the method further includes: Obtain the package name of the software to be tested; According to the package name, match the software to be tested with the known information in the vulnerability library. If the match is unsuccessful, find its alias through the package naming matrix, and then match the alias with the vulnerability information in the known vulnerability database to perform vulnerability identification.

4. A software package naming matrix construction system, characterized in that, the system includes: An open-source file acquisition module for obtaining the open-source file information of all software for each operating system; An upstream source information parsing module for parsing out the upstream source information of all software according to the open-source file information; A software package naming matrix construction module. If different software with different names on different operating systems have the same upstream source information, it is considered that the different names correspond to the same software, and a mapping relationship between different names of the same software is established, and a software package naming matrix is formed based on the mapping relationship; A package name expansion module for performing name matching on the software to be tested based on the software package naming matrix to obtain an alias of the software to be tested; A vulnerability identification module for matching the alias with the vulnerability information in the known vulnerability database to perform vulnerability identification; The upstream source information is upstream open-source component information, and the upstream source information in the corresponding software package is parsed according to the spec file information or control file information in the software.

5. The system according to claim 4, further characterized in that, The package name expansion module searches in the software package naming matrix using the software name of the software to be tested to obtain the alias corresponding to the software name.

6. The system according to claim 4, further characterized in that, The vulnerability identification module is also used to match the software to be tested with the known information in the vulnerability database according to the package name of the software to be tested; if the match is unsuccessful, the package name extension module finds its alias through the package naming matrix, and then the vulnerability identification module matches based on the alias with the vulnerability information in the known vulnerability database to identify vulnerabilities.

Citation Information

Patent Citations

  • On-line detecting method, device and server for software

    CN104700029A

  • Method for uniformly naming malicious codes based on file fingerprint and system thereof

    CN104778406A