A vulnerability early warning method and device, electronic equipment and storage medium
By collecting and monitoring vulnerability information in the CVE database and utilizing the CVE numbering mechanism, we have achieved early warning before vulnerabilities are officially disclosed, solving the problem of delayed vulnerability warning information in existing technologies and realizing the effect of early detection of vulnerability existence.
Patent Information
- Application Number
- CN202111409975.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-11-25
- Publication Date
- 2025-11-21
- Estimated Expiration
- 2041-11-25
AI Technical Summary
Existing vulnerability warning technologies suffer from information lag, failing to detect the existence of vulnerabilities before their official public release, resulting in a lack of timely protection during periods of high vulnerability exploitation.
By collecting vulnerability information from the CVE database of common vulnerability disclosures, filtering to obtain target vulnerability information, and monitoring it, changes in vulnerability types are detected, and early warnings are issued based on the changes. The CVE vulnerability numbering allocation mechanism is used to detect the existence of vulnerabilities in advance.
It enables early detection of vulnerabilities before their official public release, effectively providing advance warnings, reducing the risk during peak vulnerability exploitation periods, and helping enterprises to protect themselves in advance.
Smart Images

Figure CN114218579B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The embodiment of the application relates to the technical field of enterprise network security vulnerability early warning, and particularly relates to a vulnerability early warning method and device, an electronic device and a storage medium. BACKGROUND
[0002] In recent years, network security incidents occur frequently, and the number of vulnerabilities of network products is also increasing. Current vulnerability early warning technologies are based on major vulnerability databases, such as NVD, CNVD, CNNVD and the like. The early warning vulnerabilities are all publicly disclosed vulnerabilities, but actual vulnerabilities may have been exploited for several days or even longer. Newly submitted vulnerabilities need to be audited by the official, and the detailed information of the vulnerability will be disclosed after entering the formal publication process. Therefore, the high incidence period of vulnerability exploitation may have been missed when the early warning is issued, resulting in the lag of vulnerability early warning publication. Moreover, the official audit time is very unstable, and each step in the audit process may further lengthen the vulnerability early warning time. Therefore, how to solve the lag of vulnerability early warning information is a technical problem to be solved by the technical personnel in the field. SUMMARY
[0003] The embodiment of the application provides a vulnerability early warning method and device, an electronic device and a storage medium, so that the existence of the vulnerability can be perceived in advance before the vulnerability is formally disclosed.
[0004] In a first aspect, the embodiment of the application provides a vulnerability early warning method, comprising:
[0005] Collecting vulnerability information in a common vulnerability disclosure CVE database, and filtering the vulnerability information to obtain target vulnerability information;
[0006] Monitoring the target vulnerability information to detect the vulnerability type change of the target vulnerability information;
[0007] According to the vulnerability type change of the target vulnerability information, the target vulnerability information is early warned.
[0008] In a second aspect, the embodiment of the application further provides a vulnerability early warning device, comprising:
[0009] A target vulnerability information acquisition module is configured to collect vulnerability information in a common vulnerability disclosure CVE database, and filter the vulnerability information to obtain target vulnerability information;
[0010] A vulnerability type change determination module is configured to monitor the target vulnerability information to detect the vulnerability type change of the target vulnerability information;
[0011] A target vulnerability information early warning module is configured to early warn the target vulnerability information according to the vulnerability type change of the target vulnerability information.
[0012] In a third aspect, an electronic device is provided, and the electronic device includes:
[0013] one or more processors;
[0014] a memory device storing one or more programs;
[0015] When the one or more programs are executed by the one or more processors, the one or more processors implement the vulnerability early warning method according to any of the embodiments of the present application.
[0016] In a fourth aspect, a computer readable storage medium is provided, and the computer readable storage medium stores a computer program, and the computer program is executed by a processor to implement the vulnerability early warning method according to any of the embodiments of the present application.
[0017] The embodiments of the present application provide a vulnerability early warning method, device, electronic device and storage medium. The vulnerability information in a common vulnerability and exposure (CVE) database is collected, and the target vulnerability information is obtained by filtering the vulnerability information. The target vulnerability information is monitored to detect the vulnerability type change of the target vulnerability information. The target vulnerability information is early warned according to the vulnerability type change of the target vulnerability information. The technical solution of the embodiments of the present application solves the problem of lag of vulnerability early warning information in the prior art, uses the mechanism of CVE vulnerability number allocation, and can perceive the existence of the vulnerability in advance before the vulnerability is officially published, and can effectively early warn the vulnerability information. BRIEF DESCRIPTION OF DRAWINGS
[0018] Other characteristics, objects and advantages of the present application will become more apparent from the following detailed description of the non-restrictive embodiments, made with reference to the attached drawings. The drawings are merely intended to illustrate the preferred embodiments, and are not considered as limiting the present application. Moreover, the same reference numerals are used throughout the drawings to denote the same components. In the drawings:
[0019] Figure 1A is a flowchart of a vulnerability early warning method provided by the first embodiment of the present application;
[0020] Figure 1B is a flowchart of another vulnerability early warning method provided by the first embodiment of the present application;
[0021] Figure 2A is a flowchart of a vulnerability early warning method provided by the second embodiment of the present application;
[0022] Figure 2B is a flowchart of a vulnerability early warning method provided by the second embodiment of the present application;
[0023] Figure 3 is a structural schematic view of a vulnerability early warning device provided by embodiment three of the present application;
[0024] Figure 4 is a structural schematic view of an electronic device provided by embodiment four of the present application. DETAILED DESCRIPTION
[0025] The application will be further described below in conjunction with the drawings and embodiments. It can be understood that the specific embodiments described herein are only used to explain the present application, but not to limit the present application. In addition, it should be noted that, for the convenience of description, only the parts related to the present application are shown in the drawings, but not all the structures.
[0026] Before discussing the example embodiments in more detail, it should be mentioned that some of the example embodiments are described as processes or methods depicted as flowcharts. Although the flowcharts depict the operations (or steps) as sequential processes, many of the operations (or steps) can be performed in parallel, concurrently, or simultaneously. In addition, the order of the operations can be rearranged. The processes can be terminated when their operations are completed, but can also have additional steps not included in the figures. The processes can correspond to methods, functions, routines, subroutines, subprograms, etc.
[0027] Embodiment one
[0028] Figure 1A is a flowchart of a vulnerability early warning method provided by embodiment one of the present application. The embodiment can be applicable to the case of early warning of vulnerabilities. The method of the embodiment can be performed by a vulnerability early warning device, which can be realized in the form of hardware and / or software. The device can be configured in a vulnerability early warning server. The method specifically includes the following steps:
[0029] Github is the most popular open source software code hosting platform at present, in addition to providing the most basic code repository hosting and basic WEB management interface, it also provides project management functions such as subscription, discussion group, online text editing. At present, its registered users have exceeded 3.5 million, and the number of versions hosted is also very large. Among them, there are well-known open source components such as tomcat and FASTXML, etc. The vulnerability repair, code change, etc. of the project contained therein are all open to anyone to access, and the use of this information may advance the early warning time of the vulnerability.
[0030] The data of the existing vulnerability early warning system is mostly based on the public vulnerability library mentioned above. The vulnerability monitoring engine uses the official public API interface to obtain vulnerability data at regular intervals, and triggers the issuance of a vulnerability warning when a new vulnerability is discovered. Enterprises receive vulnerability warnings, analyze the vulnerability information, determine the impact of the vulnerability on the enterprise's network security, and respond to network security emergencies.
[0031] The above is the process of the existing technology for emergency response. It can be seen that the existing technology is based on public vulnerabilities for early warning, but actual vulnerabilities may have been exploited for several days or even longer. Therefore, the present application provides a vulnerability early warning method.
[0032] S110, collecting vulnerability information in the Common Vulnerabilities and Exposures (CVE) database, and filtering the vulnerability information to obtain target vulnerability information.
[0033] The Common Vulnerabilities and Exposures (CVE) can refer to a widely recognized name for information security vulnerabilities or exposed weaknesses. Using a common name can help users share data in various vulnerability databases and vulnerability assessment tools, making CVE a "keyword" for security information sharing. For example, a vulnerability in a vulnerability report can be quickly found in any other CVE-compatible database by searching for the CVE name, and the corresponding patch information can be found to solve the security problem.
[0034] Vulnerability information can refer to defects in the specific implementation of hardware, software, and protocols or system security policies, which can allow attackers to access or damage systems without authorization. For example, defects in the logical design of application software or operating system software or errors made during writing. This defect or error can be exploited by criminals or computer hackers to attack or control the entire computer by planting Trojans and viruses, etc., thereby stealing important data and information from the computer, or even destroying the entire system. The vulnerability information includes but is not limited to disclosed vulnerability information, rejected vulnerability information, reserved vulnerability information, and controversial vulnerability information. The vulnerability information is filtered to obtain reserved vulnerability information and controversial vulnerability information.
[0035] S120, monitoring the target vulnerability information to detect changes in the vulnerability type of the target vulnerability information.
[0036] The monitoring can refer to supervising and detecting the target vulnerability information, such as setting a monitoring frequency according to the creation time of the reserved vulnerability information in the CVE official, monitoring the reserved vulnerability information, and monitoring whether the vulnerability type of the reserved vulnerability information changes.
[0037] The vulnerability type includes, but is not limited to, disclosed vulnerability information, rejected vulnerability information, controversial vulnerability information and reserved vulnerability information. When the type of vulnerability information becomes disclosed or rejected, the vulnerability information is recorded, and it is warned that the vulnerability state has been changed, and the target vulnerability information is no longer monitored. If the type of vulnerability information is controversial vulnerability information, the vulnerability information of the target vulnerability information is extracted, and it is judged again whether the target vulnerability information is associated assets. If the type of vulnerability information is still reserved vulnerability information, the target vulnerability information is warned in advance. The dynamic adjustment of the monitoring frequency can be that the monitoring frequency is dynamically adjusted according to the creation time of the reserved vulnerability information. For example, the monitoring frequency is set to once a day when the reserved vulnerability information is monitored for the first time, and the monitoring frequency is dynamically adjusted to once a week when the reserved vulnerability information is monitored for the second time, so as to prevent resource waste.
[0038] S130, according to the change of the type of the target vulnerability information, the target vulnerability information is warned in advance.
[0039] The advance warning can be that the target vulnerability information is monitored according to the set monitoring frequency, and when the keyword of the vulnerability information is found in the monitoring channel, it is warned that suspicious information is found, and the target vulnerability information is judged. For example, if the type of vulnerability information is reserved vulnerability information, the monitoring frequency is dynamically adjusted according to the creation time of the reserved vulnerability information. It is checked whether the keyword of the reserved vulnerability information is found in the monitoring channel. If the keyword of the reserved vulnerability information is found, it is warned that suspicious information is found, the reserved vulnerability information is judged, and the advance warning of the vulnerability information is realized. If the keyword of the reserved vulnerability information is not found, the monitoring frequency is dynamically adjusted according to the creation time of the reserved vulnerability information, and the reserved vulnerability information is monitored again. The warning includes, but is not limited to, warning by email. The judgment can be that the expert fills in the judgment information of the reserved vulnerability information in the displayed pop-up window.
[0040] In an optional scheme of the embodiment of the application, Figure 1B is a flow chart of another vulnerability advance warning method provided by the embodiment of the application, as shown in Figure 1BAs shown, the vulnerability information is collected and filtered, it is judged whether the vulnerability information is in a reserved state, if the vulnerability information is in the reserved state, a monitoring task is created according to the creation time of the vulnerability information, the monitoring frequency is set and the monitoring is started; if the vulnerability information is not in the reserved state, it is judged whether the vulnerability information is in a controversial state, if the vulnerability information is in the controversial state, the vulnerability information is extracted and it is judged whether it is associated with assets; if the vulnerability information is neither in the reserved state nor in the controversial state, the monitoring of the vulnerability information is stopped, and the waste of resources is reduced. The vulnerability information in the controversial state and the vulnerability information in the reserved state are monitored, it is judged whether the vulnerability state changes, if the vulnerability information is adjusted to be disclosed or rejected, it is alarmed that the vulnerability state has been changed, and the monitoring of the vulnerability information is stopped; if the vulnerability information is adjusted to be in the controversial state, the vulnerability information is extracted, and it is judged again whether the vulnerability information is associated with assets; if the type of the vulnerability information is still the reserved vulnerability information, the vulnerability information is monitored at a frequency, it is checked whether a keyword is found in the monitoring channel, if the keyword is found, an email alarm is sent that suspicious information has been found, and a judgment is made; if the keyword is not found, the monitoring frequency of the vulnerability information is dynamically adjusted according to the creation time. The advanced warning of the vulnerability information is realized.
[0041] The embodiment of the present application provides a vulnerability advanced warning method, which collects vulnerability information in a common vulnerability disclosure CVE database, filters the vulnerability information to obtain target vulnerability information, monitors the target vulnerability information, detects the vulnerability type change of the target vulnerability information, and performs advanced warning on the target vulnerability information according to the vulnerability type change of the target vulnerability information. Through the technical scheme of the embodiment of the present application, the problem that the existing vulnerability warning technology publishes vulnerability warning information with a lag is solved, the mechanism of CVE vulnerability number allocation is used, and the existence of the vulnerability can be perceived in advance before the vulnerability is officially published, so that the advanced warning of the vulnerability information can be effectively realized.
[0042] Embodiment two
[0043] Figure 2A It is a flowchart of a vulnerability advanced warning method provided by the embodiment two of the present application. The embodiment of the present application further optimizes the foregoing embodiment on the basis of the foregoing embodiment, and can be combined with each optional scheme in one or more of the foregoing embodiments. As shown in the figure, Figure 2A The vulnerability advanced warning method provided in the embodiment of the present application can include the following steps:
[0044] S210, collect the keywords of the associated asset information, limit the monitoring range of the vulnerability warning.
[0045] The monitoring range of the vulnerability early warning is limited according to the keywords of the collected associated asset information, for example, the keywords of the collected associated asset information include the enterprise name, the vulnerability information of the related enterprise is monitored, and the monitoring range of the vulnerability early warning is limited.
[0046] Optionally, the vulnerability type, the influence range and the threat level of the early warning are determined according to the repair scheme and the change of the code mentioned in the audit vulnerability repair log.
[0047] According to the keywords of the collected associated asset information, the monitoring range of the vulnerability early warning is limited; and according to the repair scheme and the change of the code mentioned in the vulnerability repair log, the submission and repair of the vulnerability can be found in advance, and the vulnerability type, the influence range and the threat level are determined.
[0048] S220, collecting the vulnerability information in the common vulnerability and exposure CVE database, and filtering the vulnerability information to obtain target vulnerability information.
[0049] The vulnerability information in the CVE database is collected, and the vulnerability type of the vulnerability information is filtered and classified.
[0050] Optionally, the reserved vulnerability information and the controversial vulnerability information are obtained according to the filtering of the vulnerability type of the vulnerability information.
[0051] If the controversial vulnerability information is associated assets, the controversial vulnerability information and the reserved vulnerability information are taken as target vulnerability information.
[0052] If the controversial vulnerability information is not associated assets, the reserved vulnerability information is taken as target vulnerability information.
[0053] The associated asset represents whether the vulnerability information is the vulnerability information published by the enterprise.
[0054] According to the filtering of the vulnerability type of the vulnerability information, if the vulnerability type is REJECT, this type of vulnerability is an invalid vulnerability rejected by CVE, and the reason for the rejection is usually described in the CVE entry comment, and the original description of the vulnerability is also retained. This type of vulnerability does not need to be concerned, and a small part of the vulnerability will be submitted again, and after the re-submission, it will still be collected. The published vulnerability does not need special attention, and the monitoring ability of the ordinary vulnerability early warning system can monitor it. It can be used as an auxiliary module of the early warning, and used to confirm the early warning result.
[0055] The embodiment of the application collects public vulnerability information by using the API interface disclosed by CVE, mainly uses the vulnerability CVE ID without disclosed detailed information, and combines the search API provided by the public code repository Github. Using the CVE ID as a keyword, the submission notes, problems and branch merging requests of the open source component code repository are monitored, and the submission and repair of the vulnerability are found in advance, so that the effect of vulnerability early warning is achieved.
[0056] S230, monitoring the target vulnerability information, detecting the vulnerability type change of the target vulnerability information.
[0057] Among them, only when the vulnerability type is reserved (RESERVED) or disputed (DISPUTED), the monitoring task will be added to the queue, and the monitoring engine will execute the tasks in the queue in turn. If the vulnerability type is changed to other forms, the monitoring engine will report to the management platform, and whether to monitor is verified by manual.
[0058] Optionally, the creation time of the reserved vulnerability information is obtained, the monitoring frequency is set to monitor the reserved vulnerability information, and the publication channel of the reserved vulnerability information is monitored.
[0059] The publication channel of the disputed vulnerability information is obtained, and the publication channel of the disputed vulnerability information is monitored.
[0060] According to the monitoring result of the set frequency and the publication channel monitoring result, the vulnerability type change of the target vulnerability information is determined.
[0061] The raw materials of the monitoring task mainly come from two directions, which are the monitored CVEID information and the asset information. Because some vulnerabilities are in the audit stage and do not disclose any information, the CVE in the reserved state does not have related product information, so this kind of vulnerability will monitor all product publication channels, and also monitor the state of the ID in the CVE database, so as to avoid the monitoring failure caused by the insufficient monitoring channel of the product not involved in the associated assets or the CVE not mentioned in the repair log, which may cause the task to end. For the vulnerability in the disputed state, the owned asset is determined according to the asset keyword, and the monitoring range does not cover all assets. Among them, the monitoring task includes but is not limited to CVEID, CVE state, monitoring keyword, monitoring frequency mode, monitoring frequency, task first start time, asset name, monitoring URL address, authorization mode, authorization address, authorization key and asset keyword.
[0062] The vulnerability state is RESERVED, and such vulnerability only indicates that MITRE and CNA members have received the vulnerability, and the quality or authenticity of the vulnerability is unverified, and such vulnerability is the focus. However, different monitoring frequencies are set according to different creation time. A small number of vulnerabilities may be in the RESERVED state for a long time due to verification difficulties and other reasons, and the monitoring frequency needs to be dynamically adjusted at this time to prevent resource waste.
[0063] The vulnerability state is DISPUTED, and the disputed vulnerability is because the CVE entry cannot work as expected or there is a dispute for some reason. At this time, the description information of the CVE will also be partially disclosed, and such vulnerability state is only a temporary state, which may be rejected or marked as a valid vulnerability. Since the information of the vulnerability has been disclosed, only the release channel of the product needs to be monitored for such vulnerability to save resources.
[0064] S240, according to the change of the type of the target vulnerability information, the target vulnerability information is pre-warned.
[0065] Optionally, if the target vulnerability information state is adjusted to be disclosed or rejected, the identification information of the target vulnerability information is recorded, and it is warned that the target vulnerability information state has been changed;
[0066] If the target vulnerability information state is adjusted to be a controversial vulnerability information, the vulnerability information of the controversial vulnerability information is extracted and it is judged whether it is a related asset;
[0067] If the target vulnerability information state is still a reserved vulnerability information, the target vulnerability information is pre-warned.
[0068] Before each task monitoring, the latest state of the current CVE is inquired, and it is viewed whether it is modified. Only when the latest state is RESERVED or DISPUTED, the monitoring task is added to the queue, and the tasks in the queue are executed in turn. If the state is changed to other forms, it is reported to the management platform, and whether to monitor is verified by manual. If the target vulnerability information state is still a reserved vulnerability information, the target vulnerability information is pre-warned.
[0069] Optionally, the target vulnerability information is monitored according to the set frequency, and it is judged whether the keyword is found in the monitoring channel;
[0070] If the keyword is not found in the monitoring channel, the monitoring frequency is dynamically adjusted according to the creation time of the target vulnerability information;
[0071] If a keyword is found in the monitoring channel, an alarm is given to find suspicious vulnerability information, the target vulnerability information is judged, and early warning of the target vulnerability information is performed.
[0072] Once the monitoring engine finds that the repair log mentions a security repair or a CVE ID, it will immediately report to the management platform, which will notify the relevant security experts, who will audit the type and harm of the vulnerability, and if there is a possibility, a POC can be written to verify it. For security fixes that do not explicitly mention CVE, security experts can manually audit whether they cover this CVE.
[0073] The embodiment of the application provides a vulnerability early warning method, which realizes the limitation of the monitoring range of vulnerability warning according to the keywords of the collected associated asset information; according to the repair scheme and the change of the code mentioned in the vulnerability repair log, the submission and repair of the vulnerability can be found in advance, and the type, influence range and threat level of the vulnerability can be determined; the vulnerability information in the common vulnerability disclosure CVE database is collected, and the target vulnerability information is obtained by filtering the vulnerability information; the target vulnerability information is monitored, and the change of the vulnerability type of the target vulnerability information is detected; according to the change of the vulnerability type of the target vulnerability information, the target vulnerability information is early warned. Through the technical scheme of the embodiment of the application, the vulnerability CVE ID without detailed information is used, and the search API provided by the public code repository Github is combined. Using the CVE ID as the keyword, the submission notes, problems and branch merging requests of the open source component code repository are monitored, the submission and repair of the vulnerability are found in advance, the existence of the vulnerability can be perceived in advance before the vulnerability is officially published, so that the effect of vulnerability early warning is achieved.
[0074] In an optional scheme of the embodiment of the application, Figure 2B is a flowchart for early warning of reserved vulnerability information provided by the second embodiment of the application, as Figure 2B The management platform is the centralized scheduling center of the whole system, responsible for managing the work between multiple modules in the system. The personnel are mainly divided into two categories. One is the developer or the automatic asset sorting system, which is used to collect the keywords of asset information, which is the basic information for subsequent judgment of whether to collect vulnerabilities, and mainly limits the monitoring range of vulnerability warning. The other type of personnel is for security experts, who manually audit the repair scheme and the change of the code mentioned in the vulnerability repair log to determine the type of the vulnerability for early warning, and judge the influence range and threat level of the published vulnerability.
[0075] In addition, the management platform will also connect three engine systems, including the collection engine, the analysis engine and the monitoring engine.
[0076] The collection engine is mainly used to collect vulnerability information in the CVE database. However, unlike the common vulnerability warning system on the market, the common vulnerability warning system focuses on vulnerabilities that have been officially published. The officially published vulnerabilities will describe which product the CVE belongs to and which type of vulnerability. The engine mainly focuses on vulnerabilities in the RESERVED state. Since these vulnerabilities are still under review, the authenticity and impact of the vulnerabilities have not been assessed. Therefore, there is no mention of the product involved, the type of vulnerability, and the degree of harm in the information of such vulnerabilities. The collection engine will perform crawling according to the asset keywords stored in the management platform and transmit the data to the analysis engine. In addition, the management platform is also responsible for controlling the collection frequency and task triggering of the collection engine.
[0077] The analysis engine filters the vulnerabilities and retains the vulnerabilities in the RESERVED state. The analysis engine also obtains the official release channel of the product and the URL address of the release channel according to the asset keywords. The analysis engine also needs to filter the vulnerability creation date. For CVEIDs with a long creation time but no updated vulnerability status, such vulnerabilities may be long-unreviewed vulnerabilities, and it is likely that the vulnerability is difficult to reproduce or the manufacturer has not responded for a long time. Such vulnerabilities do not need to use too many resources to monitor.
[0078] The monitoring engine is responsible for executing the monitoring tasks submitted by the analysis engine. Since the tasks are not usually executed immediately, the monitoring engine also has a task queue, which can be managed through the management platform. For example, viewing the number of task executions, modifying the frequency of task execution, or immediately executing the task. The return result of the task execution will also be reported to the management platform.
[0079] The management center maintains an asset list to record the products and components that the system is concerned about. The list is usually created by project personnel or security experts. Subsequent monitoring addresses and authorization information need to be maintained by security personnel in the long term. The entry of the monitoring address is related to the effect of rectifying product vulnerability monitoring. In addition, as the target website updates or is rebranded, this place also needs to be maintained. Therefore, the monitoring engine also needs to have a security monitoring mechanism to notify the administrator for maintenance when crawling abnormalities are found.
[0080] The present application can monitor products to achieve the mechanism of early awareness of security vulnerabilities before MITRE officially discloses the vulnerabilities. Through observation and trial, the present application can advance the warning of some vulnerabilities by 1-3 days or even longer. However, these days are the peak period of vulnerability exploitation. Early warning can help enterprises to perceive vulnerabilities and take precautions in advance.
[0081] Embodiment Three
[0082] Figure 3is a structural schematic diagram of a vulnerability early warning device provided by embodiment three of the present application. The device comprises: a target vulnerability information acquisition module 310, a vulnerability type change condition determination module 320, and a target vulnerability information early warning module 330. Among them:
[0083] The target vulnerability information acquisition module 310 is configured to collect vulnerability information in the Common Vulnerabilities and Exposures (CVE) database, and filter the vulnerability information to obtain target vulnerability information.
[0084] The vulnerability type change condition determination module 320 is configured to monitor the target vulnerability information, and detect the vulnerability type change condition of the target vulnerability information.
[0085] The target vulnerability information early warning module 330 is configured to perform early warning on the target vulnerability information according to the vulnerability type change condition of the target vulnerability information.
[0086] On the basis of the above-mentioned embodiments, optionally, the target vulnerability information acquisition module 310 comprises:
[0087] The vulnerability information is filtered according to the vulnerability type to obtain reserved vulnerability information and controversial vulnerability information.
[0088] If the controversial vulnerability information is associated assets, the controversial vulnerability information and the reserved vulnerability information are taken as target vulnerability information.
[0089] If the controversial vulnerability information is not associated assets, the reserved vulnerability information is taken as target vulnerability information.
[0090] Among them, the associated assets represent whether the vulnerability information is vulnerability information published by the company.
[0091] On the basis of the above-mentioned embodiments, optionally, the vulnerability type change condition determination module 320 comprises:
[0092] The creation time of the reserved vulnerability information is obtained, the reserved vulnerability information is monitored at a set monitoring frequency, and the publication channel of the reserved vulnerability information is monitored.
[0093] The publication channel of the controversial vulnerability information is obtained, and the publication channel of the controversial vulnerability information is monitored.
[0094] According to the set frequency monitoring result and the publication channel monitoring result, the vulnerability type change condition of the target vulnerability information is determined.
[0095] On the basis of the above-mentioned embodiments, optionally, the target vulnerability information early warning module 330 comprises:
[0096] If the target vulnerability information state is adjusted to be public or rejected, the identification information of the target vulnerability information is recorded, and it is warned that the target vulnerability information state has been changed;
[0097] If the target vulnerability information state is adjusted to be controversial vulnerability information, the vulnerability information of the controversial vulnerability information is extracted, and it is judged whether it is associated assets;
[0098] If the target vulnerability information state is still reserved vulnerability information, the target vulnerability information is warned in advance.
[0099] On the basis of the above-mentioned embodiments, if the target vulnerability information state is still reserved vulnerability information, the target vulnerability information is warned in advance, which includes:
[0100] According to the set frequency, the target vulnerability information is monitored in frequency, and it is judged whether the keywords are found in the monitoring channel;
[0101] If the keywords are not found in the monitoring channel, the monitoring frequency is dynamically adjusted according to the target vulnerability information creation time;
[0102] If the keywords are found in the monitoring channel, it is warned that suspicious vulnerability information is found, the target vulnerability information is judged, and the target vulnerability information is warned in advance.
[0103] On the basis of the above-mentioned embodiments, before collecting the vulnerability information in the common vulnerability disclosure CVE database and filtering the target vulnerability information, it further includes:
[0104] The keywords of the associated asset information are collected, and the monitoring range of vulnerability warning is limited;
[0105] According to the repair scheme and the change of the code mentioned in the audit vulnerability repair log, the vulnerability type, the influence range and the threat level of this time are determined.
[0106] The above-mentioned device can execute the vulnerability early warning method provided by any embodiment of the application, has the corresponding function modules and beneficial effects for executing the vulnerability early warning method.
[0107] Embodiment four
[0108] Figure 4 It is a structural schematic diagram of an electronic device provided by the fourth embodiment of the application. The fourth embodiment of the application provides an electronic device, and the interactive device for vulnerability early warning provided by the fourth embodiment of the application can be integrated in the electronic device. Figure 4As shown, this embodiment provides an electronic device 400, which includes: one or more processors 420; and a storage device 410 for storing one or more programs. When the one or more programs are executed by the one or more processors 420, the one or more processors 420 implement the vulnerability early warning method provided in this application embodiment. The method includes:
[0109] Collect vulnerability information from the Common Vulnerability Disclosure (CVE) database and filter the vulnerability information to obtain target vulnerability information;
[0110] The target vulnerability information is monitored to detect changes in the vulnerability type.
[0111] Based on changes in the vulnerability type of the target vulnerability information, an early warning is issued for the target vulnerability information. Of course, those skilled in the art will understand that the processor 420 also implements the technical solution of the vulnerability early warning method provided in any embodiment of this application.
[0112] Figure 4 The electronic device 400 shown is merely an example and should not impose any limitations on the functionality and scope of use of the embodiments of this application.
[0113] like Figure 4 As shown, the electronic device 400 includes a processor 420, a storage device 410, an input device 430, and an output device 440; the number of processors 420 in the electronic device can be one or more. Figure 4 Taking a processor 420 as an example; the processor 420, storage device 410, input device 430, and output device 440 in the electronic device can be connected via a bus or other means. Figure 4 For example, China and Israel are connected via bus 450.
[0114] Storage device 410, as a computer-readable storage medium, can be used to store software programs, computer-executable programs, and module units, such as the program instructions corresponding to the vulnerability early warning method in the embodiments of this application.
[0115] The storage 410 can include a program storage area that can store an operating system and applications required for at least one function, and a data storage area that can store data created according to use of the terminal, etc. In addition, the storage 410 can include a high-speed random access memory, and can further include a non-volatile memory such as at least one of a magnetic disk storage device, a flash memory device, or other non-volatile solid state memory device. In some examples, the storage 410 can further include a memory disposed remotely with respect to the processor 420, and these remote memories can be connected through a network. Examples of the network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0116] The input device 430 can be used to receive inputted numbers, character information, or voice information, and to generate key signal inputs related to user settings and function controls of the electronic device. The output device 440 can include a display screen, a speaker, etc. of the electronic device.
[0117] The electronic device provided by the embodiments of the present application can achieve the technical effect of being able to perceive the existence of a vulnerability in advance before the vulnerability is officially published, and to give an early warning of the vulnerability information.
[0118] Embodiment Five
[0119] The embodiment five of the present application further provides a storage medium containing computer executable instructions, which, when executed by a computer processor, are used to execute a vulnerability early warning method, the method comprising:
[0120] Collecting vulnerability information in a common vulnerability disclosure CVE database, and filtering the vulnerability information to obtain target vulnerability information;
[0121] Monitoring the target vulnerability information, and detecting a vulnerability type change of the target vulnerability information;
[0122] According to the vulnerability type change of the target vulnerability information, giving an early warning of the target vulnerability information.
[0123] The computer storage medium of the embodiments of the present application can adopt any combination of one or more computer readable media. The computer readable medium can be a computer readable signal medium or a computer readable storage medium. The computer readable storage medium may, for example, be, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or apparatus, or any combination thereof. More specific examples (a non-exhaustive list) of the computer readable storage medium include an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read only memory (ROM), an erasable programmable read only memory (EPROM), a flash memory, an optical fiber, a portable CD-ROM, an optical storage device, a magnetic storage device, or any suitable combination of the above. The computer readable storage medium can be any tangible medium containing or storing a program that can be used by or in connection with an instruction execution system, apparatus or device.
[0124] The computer readable signal medium can include a data signal propagated in baseband or propagated as a carrier wave in a propagated data signal, in which the computer readable program code is contained. Such propagated data signal can take a variety of forms, including but not limited to electro-magnetic, optical or any suitable combination thereof. The computer readable signal medium can also be any computer readable medium that is not a storage medium and that can communicate, propagate or transport program for use by or in connection with an instruction execution system, apparatus or device.
[0125] The program code contained on the computer readable medium can be transmitted using any suitable medium, including but not limited to wireless, wire line, optical fiber cable, radio frequency (RF), or any suitable combination thereof.
[0126] Computer program code for carrying out operations of the present application can be written in any combination of one or more programming languages, including an object oriented programming language such as Java, Smalltalk, C++ or the like, and conventional procedural programming languages, such as the "C" programming language or similar programming languages. The program code can execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer or entirely on the remote computer or server. In the latter scenario, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection can be made to an external computer (for example, through the Internet using an Internet Service Provider).
[0127] In the description of the specification, the description of the terms "one embodiment", "some embodiments", "an example", "a specific example", or "some examples" etc. means that the specific features, structures, materials or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present application. In the specification, the illustrative description of the above terms does not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described can be combined in any appropriate manner in one or more embodiments or examples.
[0128] Note that the above only describes the preferred embodiments of the present application and the applied technical principles. Those skilled in the art will understand that the present application is not limited to the specific embodiments described herein, and that various obvious changes, readjustments and substitutions can be made by those skilled in the art without departing from the scope of the present application. Therefore, although the present application has been described in more detail through the above embodiments, the present application is not limited to the above embodiments, and can include more other equivalent embodiments without departing from the concept of the present application, and the scope of the present application is determined by the scope of the appended claims.
Claims
1. A vulnerability early warning method, characterized by, The method comprises: Collecting vulnerability information in a common vulnerability and exposure (CVE) database, and filtering the vulnerability information to obtain target vulnerability information; Monitoring the target vulnerability information to detect changes in the vulnerability type of the target vulnerability information; Performing early warning on the target vulnerability information according to the changes in the vulnerability type of the target vulnerability information; The monitoring of the target vulnerability information to detect changes in the vulnerability type of the target vulnerability information comprises: Obtaining the creation time of reserved vulnerability information, setting a monitoring frequency to monitor the reserved vulnerability information, and monitoring the publication channel of the reserved vulnerability information; obtaining the publication channel of controversial vulnerability information, monitoring the publication channel of the controversial vulnerability information; determining the changes in the vulnerability type of the target vulnerability information according to the monitoring results and the publication channel monitoring results at a set frequency; The early warning on the target vulnerability information according to the changes in the vulnerability type of the target vulnerability information comprises: If the status of the target vulnerability information is adjusted to be public or rejected, the identification information of the target vulnerability information is recorded, and it is warned that the status of the target vulnerability information has been changed; if the status of the target vulnerability information is adjusted to be controversial vulnerability information, the vulnerability information of the controversial vulnerability information is extracted and it is judged whether it is associated assets; if the status of the target vulnerability information is still reserved vulnerability information, early warning is performed on the target vulnerability information; If the status of the target vulnerability information is still reserved vulnerability information, early warning is performed on the target vulnerability information, which comprises: According to the target vulnerability information creation time, the monitoring frequency is dynamically adjusted; if the monitoring channel finds the keyword, it is warned that suspicious vulnerability information is found, the target vulnerability information is judged, and early warning is performed on the target vulnerability information.
2. The method of claim 1, wherein, The collection of vulnerability information in a common vulnerability and exposure (CVE) database, and the filtering of the vulnerability information to obtain target vulnerability information comprises: According to the vulnerability type of the vulnerability information, reserved vulnerability information and controversial vulnerability information are obtained; If the controversial vulnerability information is associated assets, the controversial vulnerability information and the reserved vulnerability information are taken as target vulnerability information; If the controversial vulnerability information is not associated assets, the reserved vulnerability information is taken as target vulnerability information; The associated assets represent whether the vulnerability information is vulnerability information published by the enterprise.
3. The method of claim 1, wherein, Before collecting vulnerability information in a common vulnerability and exposure (CVE) database, and filtering the vulnerability information to obtain target vulnerability information, it further comprises: Collecting the keywords of associated asset information to limit the monitoring range of vulnerability warning; According to the changes of the repair scheme and the code mentioned in the audit vulnerability repair log before and after, the vulnerability type, the influence range and the threat level of this early warning are determined.
4. A vulnerability early warning device, characterized by, The device comprises: The target vulnerability information acquisition module is configured to collect vulnerability information in a common vulnerability and exposure (CVE) database and filter the vulnerability information to obtain target vulnerability information. The vulnerability type change determination module is configured to monitor the target vulnerability information and detect a vulnerability type change of the target vulnerability information. The target vulnerability information early warning module is configured to perform early warning on the target vulnerability information according to the vulnerability type change of the target vulnerability information. The vulnerability type change determination module is configured to: obtain a creation time of reserved vulnerability information, set a monitoring frequency to monitor the reserved vulnerability information, and monitor a publication channel of the reserved vulnerability information; obtain a publication channel of controversial vulnerability information, monitor the publication channel of the controversial vulnerability information; and determine the vulnerability type change of the target vulnerability information according to a set frequency monitoring result and a publication channel monitoring result. The target vulnerability information early warning module is configured to: if the target vulnerability information state is adjusted to be public or rejected, record identification information of the target vulnerability information, and alarm that the target vulnerability information state has been changed; if the target vulnerability information state is adjusted to be controversial vulnerability information, extract vulnerability information of the controversial vulnerability information and determine whether the vulnerability information is associated assets; and if the target vulnerability information state is still reserved vulnerability information, perform early warning on the target vulnerability information. The target vulnerability information early warning module is further configured to: monitor the target vulnerability information according to a set frequency, and determine whether a keyword is found in a monitoring channel; if the keyword is not found in the monitoring channel, dynamically adjust a monitoring frequency according to a creation time of the target vulnerability information; and if the keyword is found in the monitoring channel, alarm that suspicious vulnerability information is found, analyze the target vulnerability information, and perform early warning on the target vulnerability information.
5. The apparatus of claim 4, wherein, The target vulnerability information acquisition module includes: filter the vulnerability information according to a vulnerability type to obtain reserved vulnerability information and controversial vulnerability information; if the controversial vulnerability information is associated assets, the controversial vulnerability information and the reserved vulnerability information are taken as target vulnerability information; if the controversial vulnerability information is not associated assets, the reserved vulnerability information is taken as target vulnerability information. The associated assets represent whether the vulnerability information is vulnerability information published by the enterprise.
6. A computer device comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, The processor executes the program to implement the vulnerability early warning method in any one of claims 1-3.
7. A storage medium containing computer-executable instructions, wherein: The computer executable instructions are executed by the computer processor to implement the vulnerability early warning method in any one of claims 1-3.