A software vulnerability identification method and system based on software package naming matrix

Through the method based on the software package naming matrix, the CPE information of vulnerability data and the package name of the software to be detected is solved, and the problem of insufficient display of vulnerability information in the existing technology is not rich enough and lacking universality, and more accurate and comprehensive filtering and analysis of vulnerability data is achieved.

CN114201759BActive Publication Date: 2025-05-23BEIJING ZHONGKE WEILAN TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111205719.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-10-15
Publication Date
2025-05-23
Estimated Expiration
2041-10-15

AI Technical Summary

Technical Problem

When the prior art conducts target software security detection based on known vulnerability databases and public information, there are problems such as insufficient display of vulnerability information, insufficient visualization effect, and lack of universality.

Method used

Using a method based on the software package naming matrix, the package name of the software to be detected is matched with the package name in the CPE information by extracting the CPE data. If the match fails, the package naming matrix is ​​queried to obtain the alias for matching, and the version number is matched to filter out the relevant vulnerability data.

Benefits of technology

Improves the coverage of vulnerability data filtering, provides a comprehensive data base to support the security vulnerability analysis of target software, and enhances the accuracy and comprehensiveness of detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114201759B_ABST
    Figure CN114201759B_ABST
Patent Text Reader

Abstract

The present invention discloses a software vulnerability identification method based on a software package naming matrix, extracting CPE information of vulnerability data; matching the package name of the software to be detected with the original package name in the CPE information; if the original package name fails to match, querying the software package naming matrix based on the original package name to obtain the alias of the original package name, and matching the package name of the software to be detected with the alias in the CPE information; if the original package name or the alias matches successfully, matching the version number of the software to be detected with the version number in the CPE information; if the version number matches successfully, filtering out the vulnerability data as the first priority vulnerability data; if the version number matches failed, filtering out the vulnerability data as the second priority vulnerability data; if the alias matches failed, judging that the vulnerability data does not affect the software to be detected. The coverage of the filter is improved, and a comprehensive data basis is provided for the final security vulnerability analysis result of the software to be detected.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of equipment and network operation security technology, and in particular to a software vulnerability identification method and system based on a software package naming matrix, and an information storage medium. Background Art

[0002] How to perform security testing on target software based on known vulnerability databases and public vulnerability information has always been an area of ​​effort in the industry. In order to improve the quality of answers returned by search engines and the efficiency of user queries, Google proposed the concept of knowledge graph in 2012. Knowledge graph is based on data sets, forms a relationship network between data through analysis and processing, and displays it through visualization. It is essentially a structured network with rich semantic relationships. In recent years, with the rapid development of artificial intelligence, knowledge graphs have also made great progress and produced many excellent results. At present, Minzhe Guo et al. proposed an ontology-based method to model the CVE security vulnerability database (Guo M, Wang J A. An ontology-based approach to model common vulnerabilities and exposures in information security [C] / / ASEE Southest Section Conference. 2009.). With the help of concepts, axioms and basic attributes in the ontology, complex relationships between individuals, between individuals and concepts, and between concepts are discovered. This solution is currently mainly used to display vulnerability information, and there are problems such as insufficient visualization effect and insufficient query convenience. Tao Yaodong et al. proposed an in-depth study of the knowledge base of industrial Internet security vulnerabilities (Tao Yaodong, Jia Xintong, Wu Yunkun. A research method for industrial Internet security vulnerabilities based on knowledge graph [J]. Information Technology and Network Security, 2020, 39(01): 6-13+18.), which mined the correlation between vulnerabilities-products, events-vulnerabilities and events-products, and analyzed them, achieving certain results. However, the main disadvantage of this solution is that it only targets industrial Internet vulnerabilities and is not universal. Summary of the invention

[0003] In view of the above problems, the present invention is proposed to provide a technical solution to overcome the above problems or at least partially solve the above problems. Therefore, one aspect of the present invention provides a method for identifying software vulnerabilities based on a software package naming matrix, the method comprising: extracting CPE information of vulnerability data; matching the original package name of the software to be detected with the package name in the CPE information; if the original package name matches successfully, matching the version number of the software to be tested with the version number in the CPE information; if the original package name matches unsuccessfully, querying the software package naming matrix based on the original package name to obtain an alias of the original package name, and matching the obtained alias with the package name in the CPE information; if the alias matches successfully, matching the version number of the software to be tested with the version number in the CPE information; if the version number matches successfully, filtering out the vulnerability data as the first priority vulnerability data; if the version number matches unsuccessfully, filtering out the vulnerability data as the second priority vulnerability data; if the alias matches unsuccessfully, judging that the vulnerability data does not affect the software to be tested.

[0004] Optionally, the method also includes: determining whether the CPE information contains vulnerability data operating environment information; if it does not contain operating environment information, there is no need to match the operating environment information; if it contains operating environment information, it is still necessary to match the operating environment information; if the operating environment information does not match, it is determined that the vulnerability data does not affect the software under test.

[0005] Optionally, the method further includes: the operating environment information is a field including running with or running on.

[0006] Optionally, the version number of the software to be tested is matched with the version number in the CPE information, including: inputting the version number of the software to be tested and the version number in the CPE information; determining whether there are characters other than "." in the version number data, and if so, replacing the other characters with "."; using "." to split the version number; and comparing the version numbers bit by bit starting from the front bit.

[0007] Optionally, the version numbers are compared bit by bit starting from the front bit, including: determining whether there is a letter, if so, separating the number in the current bit from the letter, and converting the letter to an integer type, and then comparing the sizes; for numbers, directly compare the sizes, and determine the larger value as the newer version.

[0008] If the version of the software to be tested is a newer version, it is judged as a fuzzy vulnerability; if the version of the vulnerability data is a newer version, it is judged that a vulnerability exists.

[0009] The present invention also provides a software vulnerability identification system based on a software package naming matrix, the system comprising: a CPE information extraction module, used to extract CPE information of vulnerability data; a package name matching module, used to match the original package name of the software to be detected with the package name in the CPE information; a version number matching module, if the original package name matches successfully, then matches the version number of the software to be tested with the version number in the CPE information; a software package naming matrix query module, if the original package name matches fail, then queries the software package naming matrix based on the original package name to obtain an alias of the original package name; the package name matching module is also used to match the alias with the package name in the CPE information; if the alias matches successfully, then the version number matching module matches the version number of the software to be tested with the version number in the CPE information; a vulnerability data filtering module, if the version number matches successfully, then filters out the vulnerability data as the first priority vulnerability data; if the version number matches fail, then filters out the vulnerability data as the second priority vulnerability data; if the alias matches fail, then determines that the vulnerability data does not affect the software to be tested.

[0010] Optionally, the system also includes: an operating environment judgment module, used to judge whether the CPE information contains vulnerability data operating environment information; if it does not contain the operating environment information, there is no need to match the operating environment information; an environment information matching module, if it contains the operating environment information, is used to match the operating environment information; if the operating environment information does not match, it is determined that the vulnerability data does not affect the software under test.

[0011] Optionally, the version number matching module includes: a version number acquisition submodule, used to input the version number of the software to be tested and the version number in the CPE information; an information processing submodule, used to determine whether there are characters other than "." in the version number data, and if so, replace other characters with "."; use "." to split the version number; and a comparison submodule, used to compare the version number bit by bit starting from the front bit.

[0012] Optionally, the comparison submodule performs the following steps: determining whether there are letters in the version information; if so, separating the current digit from the letter, converting the letter into an integer type, and then comparing the sizes; for numbers, directly comparing the sizes, and determining the one with the larger value as the newer version;

[0013] The present invention also provides an information storage medium storing a computer program, wherein the computer program is used to execute the software vulnerability identification method based on the software package naming matrix described above.

[0014] The technical solution provided by the present application has at least the following technical effects or advantages: the present invention provides a solution that enables vulnerability data from multiple sources to be filtered according to a list of target software packages and version numbers to filter out vulnerabilities related to the target software, including matching package names through a software package name matrix, thereby improving the coverage of the filter. The technical solution provides a comprehensive data basis for the final security vulnerability analysis results of the target software.

[0015] The above description is only an overview of the technical solution of the present invention. In order to more clearly understand the technical means of the present invention, it can be implemented according to the contents of the specification. In order to make the above technical solution of the present invention and its objectives, features and advantages more obvious and easy to understand, the specific implementation methods of the present invention are listed below. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] Various other advantages and benefits will become apparent to those of ordinary skill in the art by reading the detailed description of the preferred embodiments below. The accompanying drawings are only for the purpose of illustrating the preferred embodiments and are not to be considered as limiting the present invention. Moreover, the same reference symbols are used throughout the accompanying drawings to represent the same components. In the accompanying drawings:

[0017] Figure 1 A flowchart of a software vulnerability identification method based on a software package naming matrix proposed by the present invention is shown;

[0018] Figure 2 A flowchart of matching operating environment information in a software vulnerability identification method based on a software package naming matrix is ​​shown;

[0019] Figure 3 The specific process of matching version information is shown;

[0020] Figure 4 A flow chart of a software vulnerability identification method based on confidence identification provided by the present invention is shown;

[0021] Figure 5 The diagram shows the confidence levels set in the software vulnerability identification method proposed in the present invention. DETAILED DESCRIPTION

[0022] The exemplary embodiments of the present invention will be described in more detail below with reference to the accompanying drawings. Although the exemplary embodiments of the present invention are shown in the accompanying drawings, it should be understood that the present invention can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided in order to enable a more thorough understanding of the present invention and to enable the scope of the present invention to be fully communicated to those skilled in the art.

[0023] Security experts in this field generally learn about the latest discovered vulnerability information through vulnerability database platforms. Currently, the commonly used vulnerability platforms at home and abroad include: the US National Information Security Vulnerability Database NVD, the Global Information Security Vulnerability Fingerprint Database and File Detection Service CVESCAN, the CVE platform, the SECURITYFOCUS platform, the CNVD platform, the CNNVD platform, and the NSFOCUS platform of Green Alliance Technology. These platforms will publish discovered software vulnerabilities on schedule. The above has been explained in detail and will not be repeated here. In addition, various software manufacturers and network companies will also publish discovered software vulnerabilities; when commercial software is upgraded, it will generally publish the vulnerabilities that appeared in the previous version that were fixed by the software upgrade. From the above description, it can be found that the sources of vulnerability public information are wide. When using known vulnerabilities to perform security testing of predetermined software, it is first necessary to filter out the vulnerability data related to the predetermined software from the vulnerability data of multiple sources, and then parse and judge what vulnerabilities exist in the predetermined software based on these related vulnerability data.

[0024] CVE is a common name given to widely recognized information security vulnerabilities or weaknesses that have been exposed. Using a common name can help users share data in various independent vulnerability databases and vulnerability assessment tools. Specifically, the CVE official website has detailed information on the vulnerability, including the CPE information of the vulnerability. A CVE vulnerability may include multiple CPE information, and a CPE information may also exist in multiple CVE vulnerabilities. Therefore, there is a correspondence between CPE information and CVE vulnerabilities, and the CPE information can be used to match the corresponding CVE vulnerability. The CPE information contains the name and version information of the corresponding open source component, which can match the open source component with the CVE vulnerability.

[0025] The format of CPE is as follows:

[0026] cpe:2.3:part:vendor:product:version:update:edition:language:sw_edition:target_sw:target_hw:other, where part indicates the target type, and part can be any of a, h, and o. a indicates the application, h indicates the hardware platform, and o indicates the operating system; vendor indicates the manufacturer; product indicates the product name; version indicates the version number; update indicates the update package; edition indicates the version; and language indicates the language item. The following is an example of CPE information. The format of cpe at the beginning is 2.3, 2.3 indicates the cpe using the 2.3 version protocol, o indicates the os operating system, redhat indicates a certain manufacturer, enterprise_linux indicates a certain product of the manufacturer, and 6.0 indicates the version number of the product.

[0027] The detailed description of CVE vulnerabilities provided by the NVD official website includes CPE information (Official CommonPlatform Enumeration (CPE) Dictionary), such as: cpe:2.3:a:fasterxml:jackson-databind:2.7.8:*:*:*:*:*:*:*:*; the CVE vulnerabilities of open source components can be obtained by matching CPE information and open source component information. The standard format of CPE information is roughly as follows: cpe:2.3:part:vendor:product:version:update:edition:language:sw_edition:target_sw:target_hw:other, where the format begins with cpe; 2.3 indicates CPE that uses version 2.3 of the protocol (basically all of them use version 2.3 of the protocol now); part indicates the target type, and the allowed values ​​are a (application), h (hardware platform), and o (operating device). The open source component analyzed in this invention belongs to an application, that is, part is a; vendor indicates the manufacturer; product indicates the manufacturer's product name; version indicates the version number of the product; update indicates the update package; edition indicates the version; and language indicates the language item. Another example is cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*:*, where cpe starts with the format, 2.3 indicates cpe that uses version 2.3 of the protocol, o indicates the OS operating device, redhat indicates the manufacturer, enterprise_linux indicates the product of this manufacturer, and 6.0 indicates the version number of this product.

[0028] One aspect of the present invention provides a method for identifying software vulnerabilities based on a software package naming matrix, such as Figure 1 As shown, the method includes:

[0029] a) extracting CPE information of vulnerability data; matching the original package name of the software to be detected with the package name in the CPE information;

[0030] b) if the original package name fails to match, querying the software package naming matrix based on the original package name to obtain an alias of the original package name;

[0031] c) matching the alias with the package name in the CPE information;

[0032] d) If the original package name matches successfully or the alias matches successfully, the version number of the software to be tested is matched with the version number in the CPE information;

[0033] e) If the version number matches successfully, the vulnerability data is filtered out as the first priority vulnerability data;

[0034] f) If the version number fails to match, the vulnerability data is filtered out as the second priority vulnerability data;

[0035] g) If the alias matching fails, it is determined that the vulnerability data does not affect the software under test.

[0036] This method can filter vulnerability data from multiple sources according to the target software package and version number list to filter out vulnerabilities related to the target software, including matching package names through the software package name matrix to improve the coverage of the filter. This technical solution provides a comprehensive data foundation for the final security vulnerability analysis results of the target software.

[0037] Since some software is restricted to the operating environment, such as running on Windows operating system, Android system, or Ios system, it can only run on these operating systems, for example; indicating that software running on Windows operating system is unlikely to be able to run on Android operating system or IOS system, then software running on Windows operating system, even if the software package name is the same as that running on Android operating system or IOS system, is unlikely to have the same vulnerability. Some software does not restrict the operating environment, so it may run on different operating systems, or it is not certain which operating system it runs on. In this case, as long as the software package name and version information can match, the same vulnerability may exist. Therefore, the method also includes: determining whether the CPE information contains vulnerability data operating environment information; if it does not contain operating environment information, it is not necessary to match the operating environment information; if it contains operating environment information, it is still necessary to match the operating environment information; if the operating environment information does not match, it is determined that the vulnerability data does not affect the software to be tested. The operating environment information is a field containing running with or running on.

[0038] The version number of the software to be tested is matched with the version number in the CPE information, including: inputting the version number of the software to be tested and the version number in the CPE information; determining whether there are characters other than "." in the version number data, and if so, replacing the other characters with "."; using "." to split the version number; and comparing the version numbers bit by bit starting from the front bit.

[0039] Compare the version numbers bit by bit starting from the front bit, including: determine whether there is a letter; if so, separate the number and letter of the current bit, convert the letter to an integer type, and then compare the sizes; for numbers, directly compare the sizes, and determine the larger value as the newer version; if the version of the software to be tested is a newer version, it is determined to be a fuzzy vulnerability; if the version of the vulnerability data is a newer version, it is determined to have a vulnerability.

[0040] The present invention also provides a software vulnerability identification system based on a software package naming matrix, the system comprising: a CPE information extraction module, used to extract CPE information of vulnerability data; a package name matching module, used to match the package name of the software to be detected with the original package name in the CPE information; a version number matching module, if the original package name matches successfully, then matches the version number of the software to be tested with the version number in the CPE information; a software package naming matrix query module, if the original package name matches fail, then queries the software package naming matrix based on the original package name to obtain the alias of the original package name; the package name matching module is also used to match the package name of the software to be detected with the alias in the CPE information; if the alias matches successfully, then the version number matching module matches the version number of the software to be tested with the version number in the CPE information; a vulnerability data filtering module, if the version number matches successfully, then filters out the vulnerability data as the first priority vulnerability data; if the version number matches fail, then filters out the vulnerability data as the second priority vulnerability data; if the alias matches fail, then determines that the vulnerability data does not affect the software to be tested.

[0041] The system also includes: an operating environment judgment module, which is used to judge whether the CPE information contains vulnerability data operating environment information; if it does not contain the operating environment information, there is no need to match the operating environment information; an environment information matching module, if it contains the operating environment information, is used to match the operating environment information, if the operating environment information does not match, it is determined that the vulnerability data does not affect the software to be tested.

[0042] The version number matching module includes: a version number acquisition submodule, used to input the version number of the software to be tested and the version number in the CPE information; an information processing submodule, used to determine whether there are characters other than "." in the version number data, and if so, replace other characters with "."; use "." to split the version number; and a comparison submodule, used to compare the version number bit by bit starting from the front bit.

[0043] The comparison submodule performs the following steps: determining whether there are letters in the version information; if so, separating the current digit from the letter, converting the letter into an integer type, and then comparing the sizes; for numbers, directly comparing the sizes, and determining the larger value as the newer version.

[0044] The present invention also provides an information storage medium storing a computer program, wherein the computer program is used to execute the software vulnerability identification method based on the software package naming matrix described above.

[0045] Through the above description, the present invention provides a solution, which enables vulnerability data from multiple sources to be filtered according to the target software package and version number list to filter out vulnerabilities related to the target software, including matching package names through the software package name matrix, thereby improving the coverage of the filter. This technical solution provides a comprehensive data basis for the final security vulnerability analysis results of the target software.

[0046] The second priority vulnerability data can be pushed as fuzzy matching vulnerability data. Vulnerability data that can match the package name or alias and version number are considered to be very relevant to the software to be detected.

[0047] Although the vulnerability data that is very relevant to the software to be detected is filtered out, if the vulnerability detection analysis is directly based on these vulnerability data, identification errors or vulnerability detection omissions often occur. In addition, due to the multi-source nature of vulnerability data, the accuracy of software vulnerability detection results needs to be further improved while taking into account comprehensiveness.

[0048] Another aspect of the present invention provides a method for identifying the confidence level of the above-filtered vulnerability data, such as Figure 4As shown, the method includes: collecting known software vulnerability information from multiple predetermined links, the known software vulnerability information including CPE information, vulnerability description information, and open source software release information; extracting the package name and version information of the software to be tested; matching the package name and version information with the CPE information respectively; if the match with the CPE information is successful, identifying the source of the vulnerability data corresponding to the CPE information as the first confidence level, and determining that the software to be tested has the vulnerability corresponding to the CPE information; if the match with the CPE information is unsuccessful, matching the package name and version information with the vulnerability description data respectively; if the match with the vulnerability description data is successful, identifying the source of the vulnerability data corresponding to the vulnerability description data as the second confidence level, and determining that the software to be tested has the vulnerability corresponding to the CPE information There is a vulnerability corresponding to the vulnerability description data; if the match with the vulnerability description data is unsuccessful, the package name and version information are matched with the open source software release information respectively; if the package name is successfully matched with the open source software release information, and the version number is less than the repair version number, the source of the vulnerability data corresponding to the open source software release information is identified as the third confidence level, and it is judged that the software to be tested has a first possibility of a vulnerability corresponding to the open source software release information; if the package name is successfully matched with the CPE information and the vulnerability description data, but the version number is unsuccessful, the source of the vulnerability data corresponding to the CPE information and the vulnerability description data is identified as the fourth confidence level, and it is judged that the software to be tested has a second possibility of a vulnerability corresponding to the CPE information and the vulnerability description data.

[0049] The method adds a confidence field to the filtered vulnerability data by matching the vulnerability information source and the package name, thereby determining whether the vulnerability data is an exact match or a fuzzy match. The first confidence level and the second confidence level may belong to an exact match, while the third confidence level and the fourth confidence level may belong to a fuzzy match.

[0050] However, when collecting vulnerability data, it is necessary to extract the software package information of many different operating systems in real time, including the software package names. However, different operating systems have different ways of naming software packages, which leads to different names. When identifying vulnerabilities, if only the software package names of known vulnerabilities are collected and identified, it is easy to miss software with different names but essentially the same, which will affect the identification of vulnerabilities.

[0051] This application extracts the upstream source information of the spec files of the software packages of all operating systems. If the upstream sources are the same, it means that the two software packages are essentially the same software package. Based on the upstream source information, the software packages based on the same upstream source are determined, and a mapping relationship is established between the package names of these software packages, which are aliases to each other, and a software package naming matrix is ​​constructed based on these package names. For example, the name of the software package of the openeuler operating system is "python-memcached", while the name of the software package of the opensuse operating system is "memcached". The two software packages have different names, but are compiled from the same upstream source file, but are actually the same software package.

[0052] One aspect of the present invention provides a vulnerability identification method based on a software package naming matrix, such as Figure 4 As shown, the method includes:

[0053] S1. Obtain open source file information of known vulnerability software for each operating system;

[0054] S2. parse the upstream open source component information affected by the vulnerability according to the open source file information;

[0055] S3. Match the upstream open source component information of each known vulnerable software. If the match is successful, a mapping relationship between the upstream component name and the vulnerable software package name is established;

[0056] S4. Forming a software package naming matrix based on the mapping relationship;

[0057] S5. Perform security identification of the software to be tested based on the software package naming matrix to identify whether the software has vulnerabilities.

[0058] As another implementation process, the vulnerability identification method based on the software package naming matrix proposed in the present invention is as follows: Figure 5 As shown, the method may include:

[0059] S1'. According to the CPE information of the known vulnerable software, obtain the name of the upstream open source component in the software package corresponding to the vulnerability;

[0060] S2 'real-time acquisition of other software package names based on the upstream open source component name developed based on the upstream open source component, and establish the upstream component name, the corresponding software package name, other software package names mapping relationship between;

[0061] S3 'based on the mapping relationship to form a software package naming matrix;

[0062] S4'. Match the software names of the software to be detected based on the software package naming matrix to identify vulnerabilities.

[0063] The above method is mainly used in lunix open source projects. It parses the spec files, control files and other configuration files in the software package. These configuration files record which upstream open source components the software is compiled from. Software compiled based on the same upstream open source components is considered to be essentially the same software and may have the same vulnerabilities.

[0064] This application not only uses the package name of the software to be tested for matching, but also uses the alias of the software to be tested and the alias of the constructed software with known vulnerabilities to match, so as to comprehensively detect possible vulnerabilities in the software to be tested, thereby ensuring the comprehensiveness of vulnerability detection.

[0065] If the package name fails to match the CPE information, the package name is retrieved through the software package naming matrix to obtain an alias corresponding to the package name; the alias is matched with the CPE information, and if the match is successful, the version information is matched with the CPE information, and if the version information matches successfully, the data source corresponding to the CPE information is identified as the fifth confidence level, and it is determined that the software under test has a vulnerability corresponding to the CPE information, and the fifth confidence level is lower than the first confidence level. The fifth confidence level is slightly lower than the first confidence level and may belong to the category of exact matching.

[0066] If the package name fails to match the vulnerability description data, the package name is retrieved through the software package naming matrix to obtain an alias corresponding to the package name; the alias is matched with the vulnerability description data, and if the match is successful, the version information is matched with the vulnerability description data, and if the version information matches successfully, the data source corresponding to the vulnerability description data is identified as the sixth confidence level, and it is determined that the software under test has a vulnerability corresponding to the vulnerability description data, and the sixth confidence level is lower than the second confidence level. The sixth confidence level is slightly lower than the second confidence level and may belong to the category of exact matching.

[0067] If the package name fails to match the open source software release information, the package name is retrieved through the software package naming matrix to obtain an alias corresponding to the package name; the alias is matched with the open source software release information, and if the match is successful, the version information is matched with the open source software release information, and if the version information matches successfully, the data source corresponding to the open source software release information is identified as the seventh confidence level, and the third possibility that the software to be tested has a vulnerability corresponding to the open source software release information is determined, the seventh confidence level is lower than the third confidence level, and the third possibility is lower than the second possibility.

[0068] As a specific implementation method, Figure 5As shown, the package name and version information are matched with the CPE information, vulnerability description data, and open source software release information respectively, including: first matching the package name with the CPE information, vulnerability description data, and open source software release information, and after the match is successful, matching the version information with the CPE information, vulnerability description data, and open source software release information.

[0069] The present invention sets confidence levels for different vulnerability data sources through data matched by package names, thereby determining the accuracy of vulnerability detection results and achieving comprehensiveness of vulnerability detection, while providing a basis for subsequent vulnerability repair strategies.

[0070] In the description provided herein, a large number of specific details are described. However, it is understood that embodiments of the present invention can be practiced without these specific details. In some instances, well-known methods, structures and techniques are not shown in detail so as not to obscure the understanding of this description.

[0071] Similarly, it should be understood that in order to streamline the present invention and aid in understanding one or more of the various inventive aspects, in the above description of exemplary embodiments of the present invention, the various features of the present invention are sometimes grouped together into a single embodiment, figure, or description thereof. However, this disclosed method should not be interpreted as reflecting the following intention: that the claimed invention requires more features than the features explicitly recited in each claim. More specifically, as reflected in the claims below, inventive aspects lie in less than all the features of the individual embodiments disclosed above. Therefore, the claims that follow the specific embodiment are hereby expressly incorporated into the specific embodiment, with each claim itself serving as a separate embodiment of the present invention.

[0072] It should be noted that the above embodiments illustrate the present invention rather than limit the present invention, and those skilled in the art may design alternative embodiments without departing from the scope of the appended claims. In the claims, any reference symbol between brackets shall not be construed as a limitation to the claims.

Claims

1. A software vulnerability identification method based on software package naming matrix, It is characterized in that The method includes: extracting CPE information of vulnerability data; Matching the original package name of the software to be detected with the package name in the CPE information; If the original package name matches successfully, the version number of the software to be tested is matched with the version number in the CPE information; If the original package name fails to match, query the software package naming matrix based on the original package name to obtain an alias of the original package name, and match the alias with the package name in the CPE information; if the alias matches successfully, match the version number of the software to be tested with the version number in the CPE information; If the version number matches successfully, the vulnerability data is filtered out as the first priority vulnerability data; If the version number fails to match, the vulnerability data is filtered out as the second priority vulnerability data; If the alias matching fails, it is determined that the vulnerability data does not affect the software under test; The software packages based on the same upstream source are determined based on the information of the upstream source, a mapping relationship is established between the package names of the software packages, which are aliases to each other, and the software package naming matrix is ​​constructed based on the package names.

2. The software vulnerability identification method based on the software package naming matrix according to claim 1, Its characteristics are also that The method further includes: Determining whether the CPE information includes vulnerability data operating environment information; If the operating environment information is not included, there is no need to match the operating environment information; If the operating environment information is included, the operating environment information needs to be matched; If the operating environment information does not match, it is determined that the vulnerability data does not affect the software under test.

3. The software vulnerability identification method based on the software package naming matrix according to claim 2, Its characteristics are also that The operating environment information is a field including running with or running on.

4. The software vulnerability identification method based on the software package naming matrix according to claim 1, Its characteristics are also that The version number of the software to be tested is matched with the version number in the CPE information, including: Enter the version number of the software to be tested and the version number in the CPE information; Determine whether the version number data contains characters other than ".", if so, replace other characters with "."; Use "." to separate the version number; Compare version numbers bit by bit starting from the first bit.

5. The software vulnerability identification method based on the software package naming matrix according to claim 4, Its characteristics are also that Compare the version numbers bit by bit starting from the first bit, including: Determine whether there is a letter; If it exists, separate the current digit and letter, convert the letter to integer type, and then compare the sizes. For numbers, compare the sizes directly and determine the larger value as the newer version. If the version of the software to be tested is a newer version, it is judged as a fuzzy vulnerability; If the version of the vulnerability data is a newer version, it is determined that a vulnerability exists.

6. A software vulnerability identification system based on software package naming matrix, It is characterized in that The system includes: CPE information extraction module, used to extract CPE information of vulnerability data; A package name matching module, used to match the original package name of the software to be detected with the package name in the CPE information; A version number matching module, which matches the version number of the software to be tested with the version number in the CPE information if the original package name matches successfully; A software package naming matrix query module, if the original package name fails to match, then the software package naming matrix is ​​queried based on the original package name to obtain the alias of the original package name; the package name matching module is also used to match the alias with the package name in the CPE information; if the alias matches successfully, the version number matching module matches the version number of the software to be tested with the version number in the CPE information; a vulnerability data filtering module, if the version number matches successfully, then the vulnerability data is filtered out as the first priority vulnerability data; if the version number matches fail, then the vulnerability data is filtered out as the second priority vulnerability data; if the alias matches fail, then it is determined that the vulnerability data does not affect the software to be tested; The software packages based on the same upstream source are determined based on the information of the upstream source, a mapping relationship is established between the package names of the software packages, which are aliases to each other, and the software package naming matrix is ​​constructed based on the package names.

7. The software vulnerability identification system based on software package naming matrix according to claim 6, Its characteristics are also that The system also includes: An operating environment judgment module, used to judge whether the CPE information contains vulnerability data operating environment information; if it does not contain operating environment information, there is no need to match the operating environment information; The environment information matching module is used to match the operating environment information if the operating environment information is included. If the operating environment information does not match, it is determined that the vulnerability data does not affect the software under test.

8. The software vulnerability identification system based on software package naming matrix according to claim 6, Its characteristics are also that The version number matching module includes: A version number acquisition submodule, used to input the version number of the software to be tested and the version number in the CPE information; The information processing submodule is used to determine whether the version number data contains characters other than ". ". If so, replace the other characters with ". " and use ". " to split the version number; The comparison submodule is used to compare the version numbers bit by bit starting from the first bit.

9. The software vulnerability identification system based on software package naming matrix according to claim 8, Its characteristics are also that The comparison submodule performs the following steps: determining whether there are letters in the version information; If it exists, the information processing submodule is instructed to convert the letter of the current position into an integer type, and then compare the sizes. The one with the larger value is determined to be a newer version.

10. An information storage medium storing a computer program, wherein the computer program is used to execute the software vulnerability identification method based on the software package naming matrix according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Method and device for detecting integrated or customized open source project bugs in software

    CN106446691A

  • Security hole online finding method based on multi-mode matching

    CN107273751A