A method and system for verifying filtered vulnerability data

By semantic matching and coverage judgment of the filtered vulnerability data, combined with query verification of the predetermined platform, the problems of incomplete vulnerability detection and false positive vulnerability in the existing technology are solved, and accurate vulnerability detection of the target software is achieved.

CN114201758BActive Publication Date: 2025-05-06BEIJING ZHONGKE WEILAN TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111205718.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-10-15
Publication Date
2025-05-06
Estimated Expiration
2041-10-15

AI Technical Summary

Technical Problem

When performing software security detection, the prior art relies on known vulnerability libraries, especially CVE security vulnerability libraries, which leads to incomplete detection of security vulnerabilities in domestic software and false positives.

Method used

A method and system are proposed to verify the filtered vulnerability data, and by extracting the version number information in the CPE information, performing semantic matching or word participle matching, determining whether the version number information matches the vulnerability description information, and determining whether the version number of the target software is covered, and querying the CPE information and vulnerability description information through the predetermined platform to confirm the verification result.

Benefits of technology

It improves the accuracy verification of vulnerability data related to target software, ensures the accuracy of vulnerability detection, reduces the situation of false positive vulnerabilities, and enhances the security vulnerability detection capabilities of domestic software.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114201758B_ABST
    Figure CN114201758B_ABST
Patent Text Reader

Abstract

The present invention discloses a method for verifying filtered vulnerability data, the method comprising: extracting version number information from CPE information of vulnerability data related to target software; judging whether the version number information is consistent with vulnerability description information based on semantic matching or word segmentation matching; if consistent, judging whether the version number information covers the version number of the target software, if so, determining that the vulnerability filtering data has passed the verification; if inconsistent, judging whether the vulnerability description information covers the version number of the target software, if so, determining that the vulnerability filtering data has passed the verification, and updating the CPE information according to the vulnerability description information; if the vulnerability description information does not cover the version number of the target software, querying the CPE information and vulnerability description information of the vulnerability data through a predetermined platform. Through the present invention, the correctness of vulnerability data filtered from multiple data sources can be verified and erroneous data can be corrected.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of software security detection, and in particular to a method and system for verifying filtered vulnerability data. Background Art

[0002] At present, the security detection of target software is mainly based on known vulnerability libraries and public vulnerability information, especially vulnerability detection based on the CVE security vulnerability library. The known vulnerability library is filtered by setting conditions. However, although the CVE security vulnerability library is authoritative, it belongs to a foreign country after all, and there are no records of security vulnerabilities of many domestic software. Even if they are recorded, there are inconsistencies in the software names. When conducting domestic software security testing, many other sources need to be considered. In practice, according to the target software, the vulnerability data related to the target software that is filtered out often contains false positive vulnerabilities. Summary of the invention

[0003] In view of the above problems, the present invention is proposed to provide a technical solution to overcome the above problems or at least partially solve the above problems. Therefore, one aspect of the present invention provides a method for verifying the filtered vulnerability data, the method comprising: verifying the CPE of the vulnerability data related to the target software The information extracts version number information; based on semantic matching or word segmentation matching, determines whether the version number information is consistent with the vulnerability description information; if consistent, determines whether the version number information covers the version number of the target software, and if so, determines that the vulnerability filtering data has passed the verification; if inconsistent, determines whether the vulnerability description information covers the version number of the target software, and if so, determines that the vulnerability filtering data has passed the verification, and updates the CPE information according to the vulnerability description information; if the vulnerability description information does not cover the version number of the target software, queries the CPE information and vulnerability description information of the vulnerability data through a predetermined platform; based on the version number information of the queried CPE information, determines whether the version number of the target software is covered, and if so, determines that the vulnerability filtering data has passed the verification, and updates the vulnerability filtering data; if not, determines whether the queried vulnerability description information covers the version number of the target software, and if so, determines that the vulnerability filtering data has passed the verification, and updates the vulnerability filtering data; if the vulnerability description information does not cover the version number of the target software, determines that the vulnerability filtering data has not passed the verification.

[0004] Optionally, the method further includes: determining whether the queried vulnerability data has a REJECT or RESERVED flag, and if so, determining that the vulnerability filtering data has failed verification.

[0005] Optionally, the semantic matching or word segmentation matching is implemented through regular expressions.

[0006] The present invention also provides a system for verifying the filtered vulnerability data, the system comprising:

[0007] A version number information extraction module is used to extract version number information from vulnerability data CPE information related to the target;

[0008] The vulnerability data self-detection module is used to determine whether the version number information is consistent with the vulnerability description information based on semantic matching or word segmentation matching; the first version number matching module determines whether the version number information covers the version number of the target software if they are consistent, and if they are, it is determined that the vulnerability filtering data has passed the verification; the second version number matching module determines whether the vulnerability description information covers the version number of the target software if they are inconsistent, and if they are, it is determined that the vulnerability filtering data has passed the verification; the vulnerability data update module updates the CPE information according to the vulnerability description information; the vulnerability data query module is used to query the vulnerability through a predetermined platform if the vulnerability description information does not cover the version number of the target software CPE information and vulnerability description information of the data; the first version number matching module determines whether the version number of the target software is covered based on the version number information of the queried CPE information, and if so, determines that the vulnerability filtering data has passed the verification; the vulnerability data updating module updates the vulnerability filtering data according to the queried CPE information; if not, the second version number matching module determines whether the queried vulnerability description information covers the version number of the target software, and if so, determines that the vulnerability filtering data has passed the verification and is updated; the vulnerability data updating module determines that the vulnerability filtering data has not passed the verification if the vulnerability description information does not cover the version number of the target software.

[0009] Optionally, the system also includes: a vulnerability data identification recognition module, which is used to determine whether the queried vulnerability data has a REJECT or RESERVED identification. If so, it is determined that the vulnerability filtering data has not passed the verification and the vulnerability does not exist.

[0010] Optionally, the second version number matching module determines whether the vulnerability description information covers the version number of the target software by means of semantic matching or word segmentation matching.

[0011] Optionally, the second version number matching module determines whether the vulnerability description information covers the version number of the target software through a regular expression.

[0012] The technical solution provided by the present application has at least the following technical effects or advantages: through the present invention, on the one hand, the accuracy of the vulnerability data related to the target software can be verified, and on the other hand, the vulnerabilities expressed by the vulnerability filtering data in the target software can be verified, thereby ensuring the accuracy of vulnerability detection for the target software.

[0013] The above description is only an overview of the technical solution of the present invention. In order to more clearly understand the technical means of the present invention, it can be implemented according to the contents of the specification. In order to make the above technical solution of the present invention and its objectives, features and advantages more obvious and easy to understand, the specific implementation methods of the present invention are listed below. BRIEF DESCRIPTION OF THE DRAWINGS

[0014] Various other advantages and benefits will become apparent to those of ordinary skill in the art by reading the detailed description of the preferred embodiments below. The accompanying drawings are only for the purpose of illustrating the preferred embodiments and are not to be considered as limiting the present invention. Moreover, the same reference symbols are used throughout the accompanying drawings to represent the same components. In the accompanying drawings:

[0015] Figure 1 A flow chart of a vulnerability data filtering method according to the present invention is shown;

[0016] Figure 2 A flow chart of a method for verifying filtered vulnerability data proposed by the present invention is shown. DETAILED DESCRIPTION

[0017] The exemplary embodiments of the present invention will be described in more detail below with reference to the accompanying drawings. Although the exemplary embodiments of the present invention are shown in the accompanying drawings, it should be understood that the present invention can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided in order to enable a more thorough understanding of the present invention and to enable the scope of the present invention to be fully communicated to those skilled in the art.

[0018] Security experts in this field generally learn about the latest discovered vulnerability information through vulnerability database platforms. Currently, the commonly used vulnerability platforms at home and abroad include: the US National Information Security Vulnerability Database NVD, the Global Information Security Vulnerability Fingerprint Database and File Detection Service CVESCAN, the CVE platform, the SECURITYFOCUS platform, the CNVD platform, the CNNVD platform, and the NSFOCUS platform of Green Alliance Technology. These platforms will publish discovered software vulnerabilities on schedule. The above has been explained in detail and will not be repeated here. In addition, various software manufacturers and network companies will also publish discovered software vulnerabilities; when commercial software is upgraded, it will generally publish the vulnerabilities that appeared in the previous version that were fixed by the software upgrade. From the above description, it can be found that the sources of vulnerability public information are wide. When using known vulnerabilities to perform security testing of predetermined software, it is first necessary to filter out vulnerability data related to the target software from the vulnerability data of multiple sources, and then parse and judge what vulnerabilities exist in the target software based on these related vulnerability data.

[0019] CVE is a common name given to widely recognized information security vulnerabilities or weaknesses that have been exposed. Using a common name can help users share data in various independent vulnerability databases and vulnerability assessment tools. Specifically, the CVE official website has detailed information on the vulnerability, including the CPE information of the vulnerability. A CVE vulnerability may include multiple CPE information, and a CPE information may also exist in multiple CVE vulnerabilities. Therefore, there is a correspondence between CPE information and CVE vulnerabilities, and the CPE information can be used to match the corresponding CVE vulnerability. The CPE information contains the name and version information of the corresponding open source component, which can match the open source component with the CVE vulnerability.

[0020] The format of CPE is as follows:

[0021] cpe:2.3:part:vendor:product:version:update:edition:language:sw_edition:target_sw:target_hw:other, where part indicates the target type, and part can be any of a, h, and o. a indicates the application, h indicates the hardware platform, and o indicates the operating system; vendor indicates the manufacturer; product indicates the product name; version indicates the version number; update indicates the update package; edition indicates the version; and language indicates the language item. The following is an example of CPE information. The format of cpe at the beginning is 2.3, 2.3 indicates the cpe using the 2.3 version protocol, o indicates the os operating system, redhat indicates a certain manufacturer, enterprise_linux indicates a certain product of the manufacturer, and 6.0 indicates the version number of the product.

[0022] The detailed description of CVE vulnerabilities provided by the NVD official website includes CPE information (Official Common Platform Enumeration (CPE) Dictionary), such as: cpe:2.3:a:fasterxml:jackson-databind:2.7.8:*:*:*:*:*:*:*; the CVE vulnerabilities of open source components can be obtained by matching CPE information and open source component information. The standard format of CPE information is roughly: cpe:2.3:part:vendor:product:version:update:edition:language:sw_edition:target_sw:tar get_hw:other, where cpe starts with the format; 2.3 means cpe using version 2.3 protocol (now basically all use version 2.3 protocol); part means target type, and the allowed values ​​are a (application), h (hardware platform), o (operating device); vendor means manufacturer; product means the manufacturer's product name; version means the version number of the product; update means update package; edition means version; language means language item. Another example, cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*:*, where cpe starts with the format, 2.3 indicates cpe that uses version 2.3 of the protocol, o indicates the OS operating device, redhat indicates the manufacturer, enterprise_linux indicates the product of this manufacturer, and 6.0 indicates the version number of this product.

[0023] CPE information has a specified format and stores various attribute information of vulnerable software in a standardized manner. The following first presents a method for filtering vulnerability data based on target software, and then presents a process for verifying the accuracy of the filtered vulnerability data.

[0024] One aspect of the present invention provides a vulnerability data filtering method, such as Figure 1 As shown, the method includes:

[0025] Extracting CPE information of vulnerability data; matching the package name of the target software with the original package name in the CPE information;

[0026] If the original package name fails to match, a software package naming matrix is ​​queried based on the original package name to obtain an alias of the original package name. The software package naming matrix will be described in detail later.

[0027] Matching the package name of the target software with the alias in the CPE information;

[0028] If the original package name matches successfully or if the alias matches successfully, matching the version number of the target software with the version number in the CPE information;

[0029] If the alias matching fails, it is determined that the vulnerability data does not affect the target software.

[0030] If the version number matches successfully, the vulnerability data is filtered out as the first priority vulnerability data;

[0031] If the version number fails to match, the vulnerability data is filtered out as the second priority vulnerability data;

[0032] This method can filter vulnerability data from multiple sources according to the target software package and version number list to filter out vulnerabilities related to the target software, including matching package names through the software package name matrix, thereby improving the coverage of the filter and providing a comprehensive data basis for the final security vulnerability analysis results of the target software.

[0033] Since some software is restricted to the operating environment, such as running on Windows operating system, Android system, or Ios system, it can only run on these operating systems, for example; indicating that software running on Windows operating system is unlikely to be able to run on Android operating system or IOS system, then software running on Windows operating system, even if the software package name is the same as that running on Android operating system or IOS system, cannot have the same vulnerability. Some software does not restrict the operating environment, so it may run on different operating systems, or it is not certain which operating system it runs on. In this case, as long as the software package name and version information can match, the same vulnerability may exist. Therefore, the method also includes: determining whether the CPE information contains vulnerability data operating environment information; if it does not contain operating environment information, it is not necessary to match the operating environment information; if it contains operating environment information, it is still necessary to match the operating environment information; if the operating environment information does not match, it is determined that the vulnerability data does not affect the target software. The operating environment information is generally a field containing running with or running on.

[0034] Matching the version number of the target software with the version number in the CPE information includes: inputting the version number of the target software and the version number in the CPE information; determining whether there are characters other than "." in the version number data, and if so, replacing the other characters with "."; using "." to split the version number; and comparing the version numbers bit by bit starting from the front bit.

[0035] Compare the version numbers bit by bit starting from the front bit, including: determine whether there is a letter; if so, convert the number in the current bit to an integer type, and then compare the sizes. The larger number is determined to be a newer version; if the version of the target software is a newer version, it is determined to be a fuzzy vulnerability; if the version of the vulnerability data is a newer version, it is determined to have a vulnerability.

[0036] Corresponding to the above-mentioned vulnerability data filtering method, the present invention also provides a vulnerability data filtering system, which includes: a CPE information extraction module, which is used to extract the CPE information of the vulnerability data; a package name matching module, which is used to match the package name of the target software with the original package name in the CPE information; a version number matching module, which matches the version number of the target software with the version number in the CPE information if the original package name matches successfully; a software package naming matrix query module, which queries the software package naming matrix based on the original package name to obtain the alias of the original package name if the original package name matches fail; the package name matching module is also used to match the package name of the target software with the alias in the CPE information; if the alias matches successfully, the version number matching module matches the version number of the target software with the version number in the CPE information; a vulnerability data filtering module, which filters out the vulnerability data as the first priority vulnerability data if the version number matches successfully; if the version number matches fail, the vulnerability data is filtered out as the second priority vulnerability data; if the alias matches fail, it is determined that the vulnerability data does not affect the target software.

[0037] The system also includes: an operating environment judgment module, which is used to judge whether the CPE information contains vulnerability data operating environment information; if it does not contain the operating environment information, there is no need to match the operating environment information; an environment information matching module, if it contains the operating environment information, is used to match the operating environment information, if the operating environment information does not match, it is determined that the vulnerability data does not affect the target software.

[0038] The version number matching module includes: a version number acquisition submodule, used to input the version number of the target software and the version number in the CPE information; an information processing submodule, used to determine whether there are characters other than "." in the version number data, and if so, replace other characters with "."; use "." to split the version number; and a comparison submodule, used to compare the version number bit by bit starting from the front bit.

[0039] The comparison submodule performs the following steps: determining whether there are letters in the version information; if so, instructing the information processing submodule to convert the current digit into an integer type, and then compare the sizes. The larger number is determined to be a newer version.

[0040] The present invention also provides an information storage medium, which stores a computer program, and the computer program is used to execute the vulnerability data filtering method described above.

[0041] Through the above description, the present invention provides a solution for filtering vulnerability data, so that vulnerability data from multiple sources can be filtered according to the target software package and version number list to filter out vulnerabilities related to the target software, including matching package names through the software package name matrix, thereby improving the coverage of the filter. This technical solution provides a comprehensive data basis for the final security vulnerability analysis results of the target software.

[0042] The software package naming matrix was mentioned above. The following describes how to create a software package naming matrix.

[0043] When collecting vulnerability data, it is necessary to extract the software package information of many different operating systems in real time, including the software package names. However, different operating systems have different ways of naming software packages, which leads to different names. When identifying vulnerabilities, if only the software package names of known vulnerabilities are collected and identified, it is easy to miss software with different names but essentially the same software, which will affect the identification of vulnerabilities.

[0044] This application extracts the upstream source information of the spec files of the software packages of all operating systems. If the upstream sources are the same, it means that the two software packages are essentially the same software package. Based on the upstream source information, the software packages based on the same upstream source are determined, and a mapping relationship is established between the package names of these software packages, which are aliases of each other, and a software package naming matrix is ​​constructed based on these package names. For example, the name of the software package of the openeuler operating system is "python-memcached", while the name of the software package of the opensuse operating system is "memcached". The two software packages have different names, but are compiled from the same upstream source file, but are actually the same software package. Therefore, the software package naming matrix can be constructed by the following method:

[0045] Obtain the open source file information of the known vulnerable software of each operating system; parse the upstream open source component information affected by the vulnerability according to the open source file information; match the above upstream open source component information of each known vulnerable software, and if the match is successful, establish a mapping relationship between the upstream component name and the vulnerable software package name; and form a software package naming matrix based on the mapping relationship.

[0046] In addition to the above method, there is another way to construct the package naming matrix, including:

[0047] According to the CPE information of the known vulnerable software, the name of the upstream open source component in the software package corresponding to the vulnerability is obtained; the names of other software packages developed based on the upstream open source component are obtained in real time according to the upstream open source component name, and a mapping relationship between the upstream component name, the corresponding software package name, and other software package names is established; and a software package naming matrix is ​​formed based on the mapping relationship.

[0048] The above method is mainly used in lunix open source projects. It parses the spec files, control files and other configuration files in the software package. These configuration files record which upstream open source components the software is compiled from. Software compiled based on the same upstream open source components is considered to be essentially the same software and may have the same vulnerabilities.

[0049] This application not only uses the package name of the target software for matching, but also matches through the alias of the target software and the alias of the constructed software with known vulnerabilities, so as to comprehensively detect and filter out vulnerabilities related to the target software, thereby ensuring the comprehensiveness of vulnerability data acquisition.

[0050] Although the vulnerability data related to the target software is filtered out by the above technical means, if the target software is directly considered to have corresponding vulnerabilities based on the vulnerability data and a security alert is issued, the vulnerability identification error may occur. Therefore, the present invention proposes a method for verifying the filtered vulnerability data.

[0051] Next, the present invention attempts to use the impact range information of the vulnerability data to verify the accuracy of the vulnerability data itself and whether it covers the target software. The impact range information of the vulnerability, that is, the affected version range, can be extracted in three ways, one is to extract it directly from the CPE information, the second is to extract it from the vulnerability description information, and the third is to extract it through the repair software information. Using the data characteristics of the vulnerability data itself, that is, it has CPE information and vulnerability description information, the vulnerability data itself is calibrated, and then the impact range information of the vulnerability data (software version range information) is used to match the version information of the target software to determine whether the impact range of the vulnerability data covers the version of the target software, thereby performing the vulnerability data verification process.

[0052] In view of this, one aspect of the present invention is as follows Figure 2As shown, a method for verifying filtered vulnerability data is provided, the method comprising: extracting version number information from CPE information of vulnerability data related to target software; judging whether the version number information is consistent with vulnerability description information based on semantic matching or word segmentation matching; if consistent, judging whether the version number information covers the version number of the target software, and if so, determining that the vulnerability filtering data has passed the verification; if inconsistent, judging whether the vulnerability description information covers the version number of the target software, and if so, determining that the vulnerability filtering data has passed the verification, and updating the CPE information according to the vulnerability description information; if the vulnerability description information If the version number of the target software is not covered by the queried CPE information, the CPE information and vulnerability description information of the vulnerability data are queried through a predetermined platform; based on the version number information of the queried CPE information, it is determined whether the version number of the target software is covered; if so, it is determined that the vulnerability filtering data has passed the verification, and the vulnerability filtering data is updated; if not, it is determined whether the queried vulnerability description information covers the version number of the target software; if so, it is determined that the vulnerability filtering data has passed the verification, and the vulnerability filtering data is updated; if the vulnerability description information does not cover the version number of the target software, it is determined that the vulnerability filtering data has not passed the verification.

[0053] The present invention innovatively verifies the correctness of vulnerability data by matching the version number segment information in the CPE information of the filtered vulnerability data itself with the version number segment information in the vulnerability description information. In addition, the vulnerability description information is prioritized, after all, CPE information is the result of system formatting and is more prone to errors than vulnerability description data. On the other hand, the vulnerability data published on the authoritative platform is fully utilized to supplement and verify the erroneous vulnerability data.

[0054] The method also includes: determining whether the queried vulnerability data has a REJECT or RESERVED mark, and if so, determining that the vulnerability filtering data has not passed the verification. Because some vulnerability data on the CVD platform are temporarily marked as not being vulnerability data or awaiting further verification, and because the vulnerability data is originally collected from multiple aspects, when the vulnerability data mark is verified by the authoritative platform to have a similar mark, the possibility of the target software having a corresponding vulnerability can be ruled out.

[0055] Optionally, the semantic matching or word segmentation matching is implemented through regular expressions.

[0056] The present invention also provides a system for verifying the filtered vulnerability data, the system comprising: a version number information extraction module, used to extract version number information from the vulnerability data CPE information related to the target; a vulnerability data self-detection module, used to determine whether the version number information is consistent with the vulnerability description information based on semantic matching or word segmentation matching; a first version number matching module, if it is consistent, then determine whether the version number information covers the version number of the target software, if it is covered, then determine that the vulnerability filtering data has passed the verification; a second version number matching module, if it is not consistent, then determine whether the vulnerability description information covers the version number of the target software, if it is covered, then determine that the vulnerability filtering data has passed the verification; a vulnerability data update module, used to update the CPE information according to the vulnerability description information; a vulnerability data query module, used to determine whether the If the vulnerability description information does not cover the version number of the target software, the CPE information and vulnerability description information of the vulnerability data are queried through a predetermined platform; the first version number matching module determines whether the version number of the target software is covered based on the version number information of the queried CPE information, and if so, determines that the vulnerability filtering data has passed the verification; the vulnerability data updating module updates the vulnerability filtering data according to the queried CPE information; if not, the second version number matching module determines whether the queried vulnerability description information covers the version number of the target software, and if so, determines that the vulnerability filtering data has passed the verification and is updated; the vulnerability data updating module determines that the vulnerability filtering data has not passed the verification if the vulnerability description information does not cover the version number of the target software.

[0057] Optionally, the system also includes: a vulnerability data identification recognition module, which is used to determine whether the queried vulnerability data has a REJECT or RESERVED identification. If so, it is determined that the vulnerability filtering data has not passed the verification and the vulnerability does not exist.

[0058] Optionally, the second version number matching module determines whether the vulnerability description information covers the version number of the target software by means of semantic matching or word segmentation matching.

[0059] Optionally, the second version number matching module determines whether the vulnerability description information covers the version number of the target software through a regular expression.

[0060] The technical solution provided by the present application has at least the following technical effects or advantages: through the present invention, on the one hand, the accuracy of the vulnerability data related to the target software can be verified, and on the other hand, the vulnerabilities expressed by the vulnerability filtering data in the target software can be verified, thereby ensuring the accuracy of vulnerability detection for the target software.

[0061] In the description provided herein, a large number of specific details are described. However, it is understood that embodiments of the present invention can be practiced without these specific details. In some instances, well-known methods, structures and techniques are not shown in detail so as not to obscure the understanding of this description.

[0062] Similarly, it should be understood that in order to streamline the present invention and aid in understanding one or more of the various inventive aspects, in the above description of exemplary embodiments of the present invention, the various features of the present invention are sometimes grouped together into a single embodiment, figure, or description thereof. However, this disclosed method should not be interpreted as reflecting the following intention: that the claimed invention requires more features than the features explicitly recited in each claim. More specifically, as reflected in the claims below, inventive aspects lie in less than all the features of the individual embodiments disclosed above. Therefore, the claims that follow the specific embodiment are hereby expressly incorporated into the specific embodiment, with each claim itself serving as a separate embodiment of the present invention.

[0063] It should be noted that the above embodiments illustrate the present invention rather than limit the present invention, and those skilled in the art may design alternative embodiments without departing from the scope of the appended claims. In the claims, any reference symbol between brackets shall not be construed as a limitation to the claims.

Claims

1. A method for verifying filtered vulnerability data, characterized in that: The method includes: Based on the CPE information of the vulnerability data related to the target software, extracting the version number information of the CPE information; Determine whether the version number information is consistent with the vulnerability description information based on semantic matching or word segmentation matching; If they match, determining whether the version number information covers the version number of the target software, and if so, determining that the filtered vulnerability data passes the verification; If they do not match, it is determined whether the vulnerability description information covers the version number of the target software. If so, it is determined that the filtered vulnerability data passes the verification, and the CPE information is updated according to the vulnerability description information; If the vulnerability description information does not cover the version number of the target software, querying the CPE information and vulnerability description information of the vulnerability data through a predetermined platform; Based on the version number information of the queried CPE information, determine whether the version number of the target software is overwritten, and if so, determine that the filtered vulnerability data passes the verification, and update the filtered vulnerability data; If not, determining whether the queried vulnerability description information covers the version number of the target software; if so, determining that the filtered vulnerability data passes the verification, and updating the filtered vulnerability data; If the vulnerability description information does not cover the version number of the target software, it is determined that the filtered vulnerability data has failed verification.

2. The method according to claim 1, further characterized in that: The method also includes: determining whether the queried vulnerability data has a REJECT or RESERVED flag, and if so, determining that the filtered vulnerability data has failed verification.

3. The method according to claim 1, further characterized in that: The semantic matching or word segmentation matching is achieved through regular expressions.

4. A system for verifying filtered vulnerability data, characterized in that: The system includes: A version number information extraction module, used to extract version number information of the CPE information based on the CPE information of the vulnerability data related to the target software; A vulnerability data self-detection module, used to determine whether the version number information is consistent with the vulnerability description information based on semantic matching or word segmentation matching; The first version number matching module determines whether the version number information covers the version number of the target software if the information matches, and if so, determines that the filtered vulnerability data passes the verification; The second version number matching module determines whether the vulnerability description information covers the version number of the target software if there is no match, and if so, determines that the filtered vulnerability data passes the verification; A vulnerability data update module, which updates CPE information according to the vulnerability description information; A vulnerability data query module, used to query the CPE information and vulnerability description information of the vulnerability data through a predetermined platform if the vulnerability description information does not cover the version number of the target software; The first version number matching module determines whether the version number of the target software is covered based on the version number information of the queried CPE information, and if so, determines that the filtered vulnerability data passes the verification; the vulnerability data updating module updates the filtered vulnerability data according to the queried CPE information; if not, the second version number matching module determines whether the queried vulnerability description information covers the version number of the target software, and if so, determines that the filtered vulnerability data passes the verification and is updated; The vulnerability data update module determines that the filtered vulnerability data fails verification if the vulnerability description information does not cover the version number of the target software.

5. The system according to claim 4, further characterized in that: The system also includes: a vulnerability data identification module, which is used to determine whether the queried vulnerability data has a REJECT or RESERVED identification. If so, it is determined that the filtered vulnerability data has not passed the verification and the vulnerability does not exist.

6. The system according to claim 4, further characterized in that: The second version number matching module determines whether the vulnerability description information covers the version number of the target software through a semantic matching method or a word segmentation matching method.

7. The system according to claim 4, further characterized in that: The second version number matching module determines whether the vulnerability description information covers the version number of the target software through a regular expression.

Citation Information

Patent Citations

  • Security vulnerability error data correction method based on vulnerability map

    CN110287705A

  • Software vulnerability detection method and device, and storage medium

    CN111797402A