Vulnerability Intelligence Analysis Method and System

Through the HMM model word segmentation and professional vocabulary weighted processing methods, the problem of unclear types of vulnerability intelligence in the existing technology is solved, and the high accuracy of vulnerability intelligence analysis is achieved.

CN114462473BActive Publication Date: 2025-06-27SIWEI CHUANGZHI (BEIJING) TECH DEV CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111574464.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-21
Publication Date
2025-06-27
Estimated Expiration
2041-12-21

AI Technical Summary

Technical Problem

The prior art is difficult to intuitively and accurately reflect the types to which the vulnerability information belongs.

Method used

The HMM model is used to segment the vulnerability information, and the scores of professional vocabulary are weighted through a pre-constructed professional vocabulary library to generate a collection of vulnerability information types, and then determine the final type of vulnerability information.

Benefits of technology

It realizes intuitive and accurate reflection of vulnerability intelligence types, and improves the accuracy of vulnerability intelligence analysis.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114462473B_ABST
    Figure CN114462473B_ABST
Patent Text Reader

Abstract

The vulnerability intelligence analysis method and system provided by the embodiments of the present invention relate to the technical field of data analysis and processing. By using the HMM model, the vulnerability intelligence is segmented and the word frequency is counted. Then, the scores of the professional vocabulary in the vulnerability intelligence are weighted through a manually constructed professional vocabulary library to distinguish professional vocabulary from general vocabulary. According to the scores of the professional vocabulary, the scores of each type of vulnerability intelligence are determined. According to the scores of each type of vulnerability intelligence, the type of vulnerability intelligence is determined, which can intuitively and accurately reflect the type of vulnerability intelligence.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data analysis and processing, and particularly to a vulnerability intelligence analysis method and system. Background Art

[0002] On the Internet, there are usually a large number of vulnerability intelligence regarding vulnerability analysis, introduction, etc. However, many pieces of vulnerability intelligence cannot intuitively reflect the category to which the vulnerability intelligence belongs, that is, what the main content of the vulnerability intelligence is, or the category of the reflected vulnerability intelligence is not accurate. Summary of the Invention

[0003] Embodiments of the present invention provide a vulnerability intelligence analysis method and system to solve the defect in the prior art that the category to which the vulnerability intelligence belongs cannot be intuitively and accurately reflected.

[0004] To achieve the above object, the vulnerability intelligence analysis method and system provided by the embodiments of the present invention include the following technical solutions:

[0005] In a first aspect, the vulnerability intelligence analysis method provided by the embodiments of the present invention includes the following steps:

[0006] S101, obtain corresponding vulnerability intelligence according to a pre-created vulnerability intelligence category library.

[0007] S102, use the HMM model to segment the vulnerability intelligence to obtain a plurality of words, and generate a first word set.

[0008] S103, perform denoising processing on the first word set to generate a second word set and count the word frequencies of each word in the second word set.

[0009] S104, determine the initial scores of each word in the second word set according to the word frequencies to obtain a first score set.

[0010] S105, extract the professional words in the second word set according to a pre-constructed professional word library to generate a first professional word set.

[0011] S106, perform weighted processing on the initial scores of each professional word in the first professional word set respectively to obtain a second score set.

[0012] S107, extract the words with scores in the top set number according to the second score set to obtain a third word set.

[0013] S108, extract the professional words in the third word set to generate a second professional word set.

[0014] S109. Obtain the types of vulnerability intelligence corresponding to each professional term in the second set of professional terms according to the pre-created association relationship between professional terms and vulnerability intelligence, and generate a set of vulnerability intelligence types.

[0015] S1010. Score each type of vulnerability intelligence in the set of vulnerability intelligence types according to the second scores of each professional term in the second set of professional terms, and obtain the scores of each type of vulnerability intelligence.

[0016] S1011. According to the scores of each type of vulnerability intelligence, determine the final type of the vulnerability intelligence as the type of vulnerability intelligence with the highest score.

[0017] As a preferred embodiment of the first aspect, after the above step S1010, the method further includes:

[0018] Respectively use the sum of the second scores of each professional term associated with each type of vulnerability intelligence in the set of vulnerability intelligence types as the score of the corresponding type of vulnerability intelligence, and obtain a third set of scores;

[0019] According to the third set of scores, determine whether the score of the first set of preset types of vulnerability intelligence in the set of vulnerability intelligence types meets the set threshold. If so, perform a secondary score on the scores of the second set of preset types of vulnerability intelligence in the set of vulnerability intelligence types.

[0020] As a preferred embodiment of the first aspect, the vulnerability intelligence type library includes "vulnerability analysis", "vulnerability reproduction", "vulnerability exploitation", and "vulnerability repair".

[0021] As a preferred embodiment of the first aspect, the association relationship between the professional terms and the vulnerability intelligence is determined manually.

[0022] In the second aspect, the vulnerability intelligence analysis system provided by the embodiment of the present invention includes the following modules:

[0023] An acquisition module, configured to obtain corresponding vulnerability intelligence according to a pre-created vulnerability intelligence type library;

[0024] A word segmentation module, configured to use the HMM model to segment the vulnerability intelligence, obtain multiple words, and generate a first set of words;

[0025] A statistics module, configured to perform denoising processing on the first set of words, generate a second set of words, and count the word frequencies of each word in the second set of words;

[0026] A calculation module, configured to calculate the initial scores of each word in the second set of words according to the word frequencies, and obtain a first set of scores;

[0027] An extraction module, configured to extract professional terms from the second vocabulary set according to a pre-constructed professional vocabulary library, and generate a first set of professional terms;

[0028] A weighting module, configured to perform weighting processing on the initial scores of each professional term in the first set of professional terms respectively to obtain a second set of scores;

[0029] The extraction module is further configured to extract terms with scores in the top preset number according to the second set of scores to obtain a third vocabulary set;

[0030] The extraction module is further configured to extract professional terms from the third vocabulary set to generate a second set of professional terms;

[0031] A generation module is further configured to obtain the types of vulnerability intelligence corresponding to each professional term in the second set of professional terms according to the pre-created association relationship between professional terms and vulnerability intelligence, and generate a set of vulnerability intelligence types;

[0032] A scoring module is further configured to score each type of vulnerability intelligence in the set of vulnerability intelligence types according to the second scores of each professional term in the second set of professional terms to obtain the scores of each type of vulnerability intelligence;

[0033] A determination module is further configured to use the type of vulnerability intelligence with the highest score as the final type of the vulnerability intelligence according to the scores of each type of vulnerability intelligence.

[0034] In a third aspect, an embodiment of the present invention provides a computer-readable storage medium, where the storage medium stores a computer program, and the computer program is used to execute the method described in the first aspect above.

[0035] In a fourth aspect, an embodiment of the present invention provides an electronic device, where the electronic device includes:

[0036] A processor;

[0037] A memory for storing executable instructions of the processor;

[0038] The processor is configured to read the executable instructions from the memory and execute the instructions to implement the method described in the first aspect above.

[0039] The vulnerability intelligence analysis method and system provided by the embodiments of the present invention have the following beneficial effects:

[0040] Using the HMM model, the vulnerability intelligence is segmented and the word frequencies are counted. Then, through a professionally constructed vocabulary library, the scores of the professional vocabulary in the vulnerability intelligence are weighted to distinguish professional vocabulary from general vocabulary. Based on the scores of the professional vocabulary, the scores of each type of vulnerability intelligence are determined, and based on the scores of each type of vulnerability intelligence, the type of vulnerability intelligence is determined, which can intuitively and accurately reflect the type of vulnerability intelligence. BRIEF DESCRIPTION OF THE DRAWINGS

[0041] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0042] Figure 1 It is a schematic flowchart of the vulnerability intelligence analysis method provided by the embodiment of the present invention.

[0043] Figure 2 It is a schematic structural diagram of the vulnerability intelligence analysis system provided by the embodiment of the present invention.

[0044] Figure 3 It is a schematic structural diagram of the electronic device provided by the embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0045] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts fall within the scope of protection of the present invention.

[0046] Embodiment 1

[0047] As Figure 1 shown, the vulnerability intelligence analysis method provided by the embodiment of the present invention includes the following steps:

[0048] S101, obtaining corresponding vulnerability intelligence according to a pre-created vulnerability intelligence type library.

[0049] Optionally, the vulnerability intelligence type library includes "vulnerability analysis", "vulnerability reproduction", "vulnerability exploitation", and "vulnerability repair".

[0050] Specifically, the vulnerability intelligence named "vulnerability analysis" includes the content of the causes of vulnerability formation, the vulnerability intelligence named "vulnerability reproduction" includes the content of how to reproduce the vulnerability trigger process, the vulnerability intelligence named "vulnerability exploitation" includes the content of how to use vulnerabilities to achieve certain purposes, and the vulnerability intelligence named "vulnerability repair" includes the content of vulnerability repair measures, patch download, emergency handling, etc.

[0051] Among them, this vulnerability intelligence category library is constructed through data collection and collation of manual annotation (using the method of knowledge crowdsourcing to let cybersecurity researchers sort out and collect vulnerability names) and semi-structured data sources (mainly referring to data collection from open-source vulnerability intelligence platforms).

[0052] S102, using the Hidden Markov Model (HMM) model, segment the vulnerability intelligence to obtain multiple words and generate the first word set.

[0053] Among them, the HMM model uses the Viterbi algorithm to dynamically adjust the parameters of the HMM model, enabling the HMM model to recognize out-of-vocabulary words. Among them, out-of-vocabulary words are words that are not included in the segmentation word list but must be segmented, including various proper nouns (personal names, place names, company names, etc.), abbreviations, newly added words, and so on.

[0054] S103, perform denoising processing on the first word set to generate the second word set and count the word frequencies of each word in the second word set.

[0055] Specifically, the denoising process includes filtering out stop words in the first word set and so on.

[0056] S104, according to the word frequency, determine the initial scores of each word in the second word set to obtain the first score set.

[0057] Specifically, every time a word appears in the vulnerability intelligence, the initial score is increased by 1 point.

[0058] S105, according to the pre-constructed professional vocabulary library, extract the professional words in the second word set to generate the first professional word set.

[0059] Specifically, professional words are professional words in the field of cybersecurity, such as "environment setup", "Heartbleed", "Dirty Cow", "Cross-Site Request", "XXE", etc.

[0060] S106, perform weighted processing on the initial scores of each professional word in the first professional word set to obtain the second score set.

[0061] Specifically, multiply the first score of each professional term in the first set of professional terms by 5 to obtain the second score (i.e., the final score) of each professional term, so as to distinguish professional terms from common terms.

[0062] S107. According to the second set of scores, extract the terms with the top set number of scores to obtain the third set of terms.

[0063] Specifically, extract the terms with the top ten scores to form the third set of terms.

[0064] S108. Extract the professional terms from the third set of terms to generate the second set of professional terms.

[0065] S109. According to the pre-created association relationship between professional terms and vulnerability information, obtain the types of vulnerability information corresponding to each professional term in the second set of professional terms, and generate a set of vulnerability information types.

[0066] Among them, the association relationship between professional terms and vulnerability information is created manually. For example, if the professional term "environment setup" is a process of the vulnerability information type "vulnerability reproduction", then it is determined that the term "environment setup" has an association relationship with the vulnerability information type "vulnerability reproduction".

[0067] S1010. According to the second scores of each professional term in the second set of professional terms, score each type of vulnerability information in the set of vulnerability information types to obtain the scores of each type of vulnerability information.

[0068] Specifically, for example, the professional terms "exp" and "poc" are both terms associated with the vulnerability information type "vulnerability exploitation", then the sum of the second scores of the professional terms "exp" and "poc" is used as the score of the vulnerability information type "vulnerability exploitation".

[0069] Optionally, after step S1010, the vulnerability information analysis method provided by the embodiments of the present invention further includes:

[0070] Respectively, take the sum of the second scores of each professional term associated with each type of vulnerability information in the set of vulnerability information types as the score of the corresponding type of vulnerability information to obtain the third set of scores;

[0071] According to the third set of scores, determine whether the score of the first set type of vulnerability information in the set of vulnerability information types meets the set threshold. If so, perform a secondary score on the score of the second set type of vulnerability information in the set of vulnerability information types.

[0072] Specifically, through the analysis of vulnerability intelligence by the K-mean clustering model and manual work, it is found that there are correlations among different types of vulnerability intelligence. For example, when the type of a piece of vulnerability intelligence contains the process of "vulnerability analysis" or "vulnerability reproduction", the type of this vulnerability intelligence must contain "vulnerability exploitation". After testing, when the score of the type "vulnerability reproduction" or "vulnerability exploitation" exceeds 8, the score of the type "vulnerability analysis" is also adjusted to 8 to obtain the final score. For example, the type of vulnerability intelligence contains both "vulnerability reproduction" and "vulnerability exploitation", but since the process of vulnerability analysis does not trigger keywords and the vulnerability intelligence of the type "vulnerability analysis" is not detected, resulting in a score of 0 for "vulnerability analysis" after the first scoring. However, since the scores of "vulnerability reproduction" and "vulnerability exploitation" both exceed 8, the score of the type "vulnerability analysis" is adjusted to 8, improving the accuracy of vulnerability intelligence analysis.

[0073] S1011. According to the scores of each type of vulnerability intelligence, take the type of vulnerability intelligence with the highest score as the final type of the vulnerability intelligence.

[0074] Embodiment 2

[0075] As Figure 2 shown, the vulnerability intelligence analysis system provided by the embodiment of the present invention includes the following modules:

[0076] An acquisition module, configured to acquire corresponding vulnerability intelligence according to a pre-created vulnerability intelligence type library;

[0077] A word segmentation module, configured to segment the vulnerability intelligence by using the HMM model to obtain multiple words and generate a first word set;

[0078] A statistics module, configured to perform denoising processing on the first word set to generate a second word set and count the word frequencies of each word in the second word set;

[0079] A calculation module, configured to calculate the initial scores of each word in the second word set according to the word frequencies to obtain a first score set;

[0080] An extraction module, configured to extract professional words from the second word set according to a pre-constructed professional word library to generate a first professional word set;

[0081] A weighting module, configured to perform weighting processing on the initial scores of each professional word in the first professional word set to obtain a second score set;

[0082] The extraction module is further configured to extract the words with the top set number of scores according to the second score set to obtain a third word set;

[0083] The extraction module is further configured to extract the professional terms in the third vocabulary set to generate a second professional vocabulary set;

[0084] The generation module is further configured to obtain the types of vulnerability intelligence corresponding to the professional terms in the second professional vocabulary set according to the pre-created association relationship between professional terms and vulnerability intelligence, and generate a vulnerability intelligence type set;

[0085] The scoring module is further configured to score each type of vulnerability intelligence in the vulnerability intelligence type set according to the second scores of the professional terms in the second professional vocabulary set to obtain the scores of each type of vulnerability intelligence;

[0086] The determination module is further configured to use the type of vulnerability intelligence with the highest score as the final type of the vulnerability intelligence according to the scores of each type of vulnerability intelligence.

[0087] Embodiment 3

[0088] Figure 3 is the structure of an electronic device provided by an exemplary embodiment of the present invention. As Figure 3 shown, the electronic device can be any one or both of the first device and the second device, or a stand-alone device independent of them, and the stand-alone device can communicate with the first device and the second device to receive the input signals collected from them. Figure 3 The block diagram of an electronic device according to an embodiment of the present disclosure is illustrated. As Figure 3 shown, the electronic device includes one or more processors 401 and a memory 402.

[0089] The processor 401 can be a central processing unit (CPU) or other forms of processing units with penetration data processing capabilities and / or instruction execution capabilities, and can control other components in the electronic device to perform desired functions.

[0090] The memory 402 may include one or more computer program products, and the computer program products may include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. The volatile memory may include, for example, random access memory (RAM) and / or cache memory, etc. The non-volatile memory may include, for example, read-only memory (ROM), hard disk, flash memory, etc. One or more computer program instructions may be stored on the computer-readable storage media, and the processor 401 may run the program instructions to implement the method of information mining on the historical change records of the software programs of the various disclosed embodiments described above and / or other desired functions. In one example, the electronic device may further include: an input device 403 and an output device 404, and these components are interconnected through a bus system and / or other forms of connection mechanisms (not shown).

[0091] In addition, the input device 403 may further include, for example, a keyboard, a mouse, and so on.

[0092] The output device 404 may output various information to the outside. The output device 404 may include, for example, a display, a speaker, a printer, and a communication network and its connected remote output devices, and so on.

[0093] Of course, for simplicity, Figure 3 only some of the components related to the present disclosure in the electronic device are shown, and components such as buses, input / output interfaces, and so on are omitted. In addition, according to specific application scenarios, the electronic device may further include any other appropriate components.

[0094] Embodiment 4

[0095] In addition to the above methods and devices, an embodiment of the present disclosure may also be a computer program product, which includes computer program instructions, and when the computer program instructions are run by a processor, the processor is caused to execute the steps in the method of infiltrating data annotation, encapsulation, and acquisition according to various embodiments of the present disclosure described in the "Exemplary Method" section above of this specification.

[0096] The computer program product may be written in any combination of one or more programming languages for programming code to perform the operations of the embodiments of the present disclosure. The programming languages include object-oriented programming languages, such as Java, C++, etc., and also include conventional procedural programming languages, such as the "C" language or similar programming languages. The program code may be executed entirely on the user computing device, partially on the user device, executed as an independent software package, partially on the user computing device and partially on a remote computing device, or entirely on a remote computing device or server.

[0097] In addition, an embodiment of the present disclosure may also be a computer-readable storage medium having computer program instructions stored thereon, and when the computer program instructions are run by a processor, the processor is caused to execute the steps in the penetration data annotation, encapsulation, and acquisition methods according to various embodiments of the present disclosure described in the above "Exemplary Method" section of this specification.

[0098] The computer-readable storage medium may adopt any combination of one or more readable media. The readable media may be a readable signal medium or a readable storage medium. The readable storage medium may include, for example, but is not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples (a non-exhaustive list) of the readable storage medium include: an electrical connection having one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.

[0099] The basic principles of the present disclosure have been described above in conjunction with specific embodiments. However, it should be noted that the advantages, benefits, effects, etc. mentioned in the present disclosure are only examples and not limitations, and it cannot be considered that these advantages, benefits, effects, etc. are essential for each embodiment of the present disclosure. In addition, the above-described specific details are only for the purpose of illustration and facilitating understanding, rather than limitations, and the above details do not limit the present disclosure to necessarily adopt the above specific details for implementation.

[0100] Each embodiment in this specification is described in a progressive manner, and the key point of each embodiment is to illustrate the differences from other embodiments. The same or similar parts among the embodiments can be referred to each other. For system embodiments, since they basically correspond to method embodiments, they are described relatively simply, and the relevant parts can refer to the partial description of the method embodiments.

[0101] The block diagrams of the devices, apparatuses, equipment, and systems involved in the present disclosure are only exemplary examples and do not intend to require or imply that they must be connected, arranged, and configured in the manner shown in the block diagrams. As those skilled in the art will recognize, these devices, apparatuses, equipment, and systems can be connected, arranged, and configured in any manner. Words such as "including", "comprising", "having", etc. are open-ended words, meaning "including but not limited to", and can be used interchangeably with each other. The words "or" and "and" used herein refer to the word "and / or" and can be used interchangeably with each other, unless the context clearly indicates otherwise. The word "such as" used herein refers to the phrase "such as but not limited to" and can be used interchangeably with each other.

[0102] The methods and apparatuses of the present disclosure may be implemented in many ways. For example, the methods and apparatuses of the present disclosure may be implemented by software, hardware, firmware, or any combination of software, hardware, and firmware. The above order of the steps for the methods is for illustration only, and the steps of the methods of the present disclosure are not limited to the specific order described above, unless otherwise specifically stated. In addition, in some embodiments, the present disclosure may also be implemented as a program recorded in a recording medium, and these programs include machine-readable instructions for implementing the methods according to the present disclosure. Therefore, the present disclosure also covers a recording medium storing a program for executing the methods according to the present disclosure.

[0103] It should also be noted that in the apparatuses, devices, and methods of the present disclosure, each component or each step can be decomposed and / or recombined. These decompositions and / or recombinations should be regarded as equivalent solutions of the present disclosure. The above description of the disclosed aspects is provided to enable any person skilled in the art to make or use the present disclosure. Various modifications to these aspects are very obvious to those skilled in the art, and the general principles defined herein can be applied to other aspects without departing from the scope of the present disclosure. Therefore, the present disclosure is not intended to be limited to the aspects shown herein, but to the widest scope consistent with the principles and novel features disclosed herein.

[0104] The above description has been given for purposes of illustration and description. In addition, this description is not intended to limit the embodiments of the present disclosure to the forms disclosed herein. Although several example aspects and embodiments have been discussed above, those skilled in the art will recognize certain variations, modifications, alterations, additions, and sub-combinations thereof.

[0105] It can be understood that the relevant features in the above methods and apparatuses can be referred to each other. In addition, the "first", "second", etc. in the above embodiments are used to distinguish each embodiment, and do not represent the advantages and disadvantages of each embodiment.

[0106] The above are only the embodiments of the present application and are not used to limit the present application. For those skilled in the art, the present application may have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the scope of the claims of the present application.

[0107] It should be noted that the above embodiments do not limit the present invention in any form. Any technical solutions obtained by means of equivalent replacement or equivalent transformation shall fall within the protection scope of the present invention.

Claims

1. A vulnerability intelligence analysis method, characterized in that, It includes the following steps: S101, obtain corresponding vulnerability intelligence according to the pre-created vulnerability intelligence category library; S102, use the HMM model to segment the vulnerability intelligence, obtain multiple words, and generate a first word set; S103, perform denoising processing on the first word set, generate a second word set and count the word frequencies of each word in the second word set; S104, determine the initial scores of each word in the second word set according to the word frequencies, and obtain a first score set; S105, extract the professional words in the second word set according to the pre-constructed professional word library, and generate a first professional word set; S106, perform weighted processing on the initial scores of each professional word in the first professional word set respectively, and obtain a second score set; S107, extract the words with scores in the top set number according to the second score set, and obtain a third word set; S108, extract the professional words in the third word set, and generate a second professional word set; S109, obtain the vulnerability intelligence categories corresponding to each professional word in the second professional word set according to the pre-created association relationship between professional words and vulnerability intelligence, and generate a vulnerability intelligence category set; S1010, score each vulnerability intelligence category in the vulnerability intelligence category set according to the second scores of each professional word in the second professional word set, and obtain the scores of each vulnerability intelligence category; S1011, according to the scores of each vulnerability intelligence category, take the vulnerability intelligence category with the highest score as the final category of the vulnerability intelligence.

2. The vulnerability intelligence analysis method according to claim 1, wherein After the above step S1010, the method further includes: Respectively take the sum of the second scores of each professional word associated with each vulnerability intelligence category in the vulnerability intelligence category set as the score of the corresponding vulnerability intelligence category, and obtain a third score set; According to the third score set, judge whether the score of the first set vulnerability intelligence category in the vulnerability intelligence category set meets the set threshold. If so, perform secondary scoring on the scores of the second set vulnerability intelligence category in the vulnerability intelligence category set.

3. The vulnerability intelligence analysis method according to claim 1, wherein The vulnerability intelligence category library includes "vulnerability analysis", "vulnerability reproduction", "vulnerability exploitation" and "vulnerability repair".

4. The vulnerability intelligence analysis method according to claim 1, wherein The association relationship between the professional words and the vulnerability intelligence is determined manually.

5. A vulnerability intelligence analysis system, characterized in that, It includes the following modules: An acquisition module, configured to obtain corresponding vulnerability intelligence according to the pre-created vulnerability intelligence category library; A word segmentation module, configured to use the HMM model to segment the vulnerability intelligence, obtain multiple words, and generate a first word set; A statistics module, configured to perform denoising processing on the first word set, generate a second word set and count the word frequencies of each word in the second word set; A calculation module, configured to calculate the initial scores of each word in the second word set according to the word frequencies, and obtain a first score set; An extraction module, configured to extract the professional words in the second word set according to the pre-constructed professional word library, and generate a first professional word set; A weighting module, configured to perform weighting processing on the initial scores of each professional vocabulary in the first set of professional vocabularies respectively to obtain a second set of scores; The extraction module is further configured to extract the vocabularies with scores in the top preset number according to the second set of scores to obtain a third set of vocabularies; The extraction module is further configured to extract the professional vocabularies in the third set of vocabularies to generate a second set of professional vocabularies; A generation module, configured to obtain the types of vulnerability intelligence corresponding to each professional vocabulary in the second set of professional vocabularies according to the pre-created association relationship between professional vocabularies and vulnerability intelligence, and generate a set of vulnerability intelligence types; A scoring module, configured to score each type of vulnerability intelligence in the set of vulnerability intelligence types according to the second scores of each professional vocabulary in the second set of professional vocabularies to obtain the scores of each type of vulnerability intelligence; A determination module is further configured to use the type of vulnerability intelligence with the highest score as the final type of the vulnerability intelligence according to the scores of each type of vulnerability intelligence; 6. A computer-readable storage medium, characterized in that, The storage medium stores a computer program, and the computer program is used to execute the method described in claim 1 or 2 above; 7. An electronic device, characterized in that, The electronic device includes: A processor; A memory for storing executable instructions of the processor; The processor is configured to read the executable instructions from the memory and execute the instructions to implement the method described in claim 1 or 2 above.

Citation Information

Patent Citations

  • Vulnerability manufacturer name matching method

    CN113468315A

  • Network public opinion analysis method and apparatus, and computer-readable storage medium

    WO2019227710A1