System Vulnerability Handling Task Optimization Method and System
By pre-processing vulnerabilities to be processed, obtaining task tags and time tags, establishing task processing preparation groups, and reasonably allocating vulnerability processing tasks, the problem of unreasonable task allocation in traditional systems is solved and the efficiency of vulnerability processing is improved.
Patent Information
- Application Number
- CN202210049962.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-01-17
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2042-01-17
AI Technical Summary
In traditional system vulnerability handling methods, task allocation is unreasonable, resulting in inefficient vulnerability handling.
By pre-processing vulnerabilities to be processed, obtaining task tags and time tags, establishing a task processing preparation group, and reasonably assigning vulnerability processing tasks to specialists who are good at this type of work for processing.
This improves the efficiency of vulnerability handling, ensures that each vulnerability handling task is reasonably distributed to the appropriate specialist, and improves the overall processing efficiency.
Smart Images

Figure CN114579973B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of vulnerability management, and particularly relates to a method and system for optimizing system vulnerability handling tasks. Background Art
[0002] Nowadays, with the gradual acceleration of enterprise informatization construction, the importance of information systems is self-evident. Among them, vulnerabilities in information systems enable attackers to use these vulnerabilities to invade databases or attack web applications, thereby obtaining some important data and benefits. If there are vulnerabilities, they need to be repaired immediately, otherwise the information system is easily damaged by the network, and even a Trojan horse may be implanted by hackers through the vulnerabilities of the information system, and the consequences will be unimaginable. Currently, in one classification of system vulnerabilities, system vulnerabilities include: memory corruption, logical errors, input validation, design errors, configuration errors, and so on.
[0003] In a specific scenario, after testers discover vulnerabilities, they need to distribute the results of each vulnerability to different vulnerability handling specialists for processing. However, due to unreasonable distribution, such as a vulnerability handling specialist who is good at fixing memory corruption vulnerabilities being randomly assigned to an input validation vulnerability handling task, etc., the efficiency of vulnerability handling is reduced. Summary of the Invention
[0004] The purpose of the present invention is to provide a method and system for optimizing system vulnerability handling tasks, aiming to solve the problem that in the traditional system vulnerability handling method, the task distribution is unreasonable, reducing the efficiency of vulnerability handling.
[0005] To achieve the above purpose, the present invention provides the following technical solutions.
[0006] In a first aspect, in an embodiment provided by the present invention, a method for optimizing system vulnerability handling tasks, the task optimization method includes:
[0007] Obtain the vulnerabilities to be processed, preprocess the vulnerabilities to be processed, and obtain vulnerability handling tasks containing task tags and time tags, where the task tags belong to one of the preset tag libraries;
[0008] Add the vulnerability handling tasks to the task distribution queue for distribution, and establish a task processing preparatory group for all vulnerability handling specialists who are idle before the deadline of the time tag of each vulnerability handling task and match the task tags of the vulnerability handling tasks, and assign the vulnerability handling tasks to a vulnerability handling specialist in the task processing preparatory group for processing.
[0009] As a further limitation of the technical solution of the preferred embodiment of the present invention, the step of preprocessing the vulnerabilities to be processed includes:
[0010] Identify and analyze the vulnerabilities to be processed;
[0011] Extract at least one task tag for the vulnerability to be processed and a time tag corresponding to the latest processing deadline of the task tag.
[0012] As a further limitation of the technical solution of the preferred embodiment of the present invention, before the step of adding the vulnerability handling task to the task assignment queue for assignment, the task optimization method further includes:
[0013] Establish at least one advantage tag for each vulnerability handling specialist, and each advantage tag belongs to one of the preset tag libraries.
[0014] As a further limitation of the technical solution of the preferred embodiment of the present invention, the determination step of being idle before the deadline of the time tag of each vulnerability handling task includes:
[0015] Obtain the idle time period of the vulnerability handling specialist;
[0016] Based on the estimated cycle for the vulnerability handling specialist to process the current vulnerability handling task, determine the effective time period of the vulnerability handling specialist;
[0017] When the deadline of the time tag of the vulnerability handling task is within the effective time period, the current vulnerability handling specialist is idle before the deadline of the time tag of the vulnerability handling task.
[0018] As a further limitation of the technical solution of the preferred embodiment of the present invention, the step of determining the effective time period of the vulnerability handling specialist based on the estimated cycle for the vulnerability handling specialist to process the current vulnerability handling task includes:
[0019] Obtain the estimated cycle for the vulnerability handling specialist to process the current vulnerability handling task;
[0020] According to the start time node t1 of the idle time period T[t1, t2], and based on the estimated cycle P, calculate the effective time period S[t3, t2] of the vulnerability handling specialist, where t3 = t1 + P.
[0021] As a further limitation of the technical solution of the preferred embodiment of the present invention, the determination step of the deadline of the time tag of the vulnerability handling task being within the effective time period includes:
[0022] Obtain the deadline t0 of the time tag of the vulnerability handling task;
[0023] When t0 ∈ S[t3, t2], determine that the deadline of the time tag of the vulnerability handling task is within the effective time period.
[0024] As a further limitation of the technical solution of the preferred embodiment of the present invention, the step of matching the task tags of the vulnerability handling task includes:
[0025] Extract all the advantage tags of the vulnerability handling specialists who meet the idle time;
[0026] When the task tags of the vulnerability handling task are included in all the advantage tags, add the current vulnerability handling specialist to the task processing preparation group.
[0027] As a further limitation of the technical solution of the preferred embodiment of the present invention, the step of assigning the vulnerability handling task to a vulnerability handling specialist in the task processing preparation group for processing includes:
[0028] Calculate the time slack Ts of each vulnerability handling specialist in the task processing preparation group, where Ts = t3 - t2;
[0029] Assign the vulnerability handling task to the vulnerability handling specialist for processing based on the sorting of the time slack Ts of each vulnerability handling specialist in the task processing preparation group.
[0030] As a further limitation of the technical solution of the preferred embodiment of the present invention, the step of assigning the vulnerability handling task to the vulnerability handling specialist for processing based on the sorting of the time slack Ts of each vulnerability handling specialist in the task processing preparation group includes:
[0031] When sorting the time slack Ts of each vulnerability handling specialist in descending order, assign the vulnerability handling task to the vulnerability handling specialist corresponding to the first time slack Ts in the sorting for processing.
[0032] In a second aspect, in another embodiment provided by the present invention, a system vulnerability handling task optimization system, the task optimization system includes:
[0033] A preprocessing unit, which is used to obtain the vulnerability to be processed, preprocess the vulnerability to be processed, and obtain a vulnerability handling task containing task tags and time tags, where the task tags belong to one of the preset tag libraries;
[0034] A task assignment unit, which is used to add the vulnerability handling task to the task assignment queue for assignment, establish a task processing preparation group for all vulnerability handling specialists who are idle before the deadline of the time tag of each vulnerability handling task and match the task tags of the vulnerability handling task, and assign the vulnerability handling task to a vulnerability handling specialist in the task processing preparation group for processing.
[0035] Compared with the prior art, the system vulnerability handling task optimization method provided by the present invention preprocesses the to-be-handled vulnerabilities to obtain vulnerability handling tasks containing task tags and time tags, adds the vulnerability handling tasks to a task assignment queue for assignment, and creates a task handling preparatory group for all vulnerability handling specialists who are idle before the deadline of the time tag of each vulnerability handling task and match the task tags of the vulnerability handling tasks, and assigns the vulnerability handling tasks to a vulnerability handling specialist in the task handling preparatory group for processing, which can reasonably distribute each vulnerability handling task to different vulnerability handling specialists for processing when testers discover vulnerabilities, effectively improving the efficiency of vulnerability handling. BRIEF DESCRIPTION OF THE DRAWINGS
[0036] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings in the following description are only some embodiments of the present invention.
[0037] Figure 1 It is a flowchart for implementing a system vulnerability handling task optimization method of the present invention;
[0038] Figure 2 It is a sub-flowchart of the task optimization method provided by the present invention;
[0039] Figure 3 It is another sub-flowchart of the task optimization method provided by the present invention;
[0040] Figure 4 It is yet another sub-flowchart of the task optimization method provided by the present invention;
[0041] Figure 5 It is still another sub-flowchart of the task optimization method provided by the present invention;
[0042] Figure 6 It is a structural block diagram of a system vulnerability handling task optimization system of the present invention;
[0043] Figure 7 It is a structural block diagram of a computer device provided by the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0044] In order to make the objectives, technical solutions and advantages of the present invention clearer, the following further describes the present invention in detail with reference to the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.
[0045] Currently, in a classification of system vulnerabilities, system vulnerabilities include: memory corruption, logical error, input validation, design error, configuration error, and so on.
[0046] In specific scenarios, after testers discover a vulnerability, they need to distribute the results of each vulnerability to different vulnerability handling specialists for processing. However, due to unreasonable distribution, for example, a vulnerability handling specialist who is good at fixing memory corruption vulnerabilities is randomly assigned to an input validation vulnerability handling task, etc., the efficiency of vulnerability handling is reduced.
[0047] To solve the above problems, the present invention pre-processes the vulnerabilities to be processed to obtain vulnerability processing tasks containing task tags and time tags, adds the vulnerability processing tasks to the task allocation queue for allocation, and establishes a task processing preparatory group for all vulnerability processing specialists who are in idle time before the deadline of the time tag of each vulnerability processing task and match the task tag of the vulnerability processing task, and allocates the vulnerability processing task to a vulnerability processing specialist in the task processing preparatory group for processing. When testers find vulnerabilities, each vulnerability processing task can be reasonably distributed to different vulnerability processing specialists for processing, thereby effectively improving the efficiency of vulnerability processing.
[0048] The specific implementation of the present invention is described in detail below in conjunction with specific embodiments.
[0049] Example 1
[0050] like Figure 1 As shown, in one embodiment provided by the present invention, a system vulnerability processing task optimization method is provided, and the task optimization method includes:
[0051] Step S101: Establish at least one advantage tag for each vulnerability handling specialist, and each advantage tag belongs to one of the preset tag libraries.
[0052] In the specific implementation of step S101 provided in the embodiment of the present invention, each vulnerability handling specialist has a corresponding vulnerability type that he is good at handling, that is, in this embodiment, each vulnerability handling specialist has at least one advantage label, wherein the preset label library includes memory corruption class, logic error class, input verification class, design error class and configuration error class; accordingly, each vulnerability handling specialist has one or more advantage labels; exemplarily, the advantage labels of the current vulnerability handling specialist are memory corruption class and logic error class; or, the advantage label of the current vulnerability handling specialist is only memory corruption class; the advantage label of each vulnerability handling specialist is a combination of one or more labels in the preset label library.
[0053] Furthermore, in an embodiment of the present invention, the task optimization method further includes:
[0054] Step S102: Obtain the vulnerability to be processed, preprocess the vulnerability to be processed, and obtain a vulnerability handling task containing a task tag and a time tag, where the task tag belongs to one of the preset tag libraries;
[0055] In the specific implementation of step S102 provided in the embodiments of the present invention, there are various types of system vulnerabilities. After testers discover a vulnerability, during the preprocessing of the vulnerability to be processed, they first identify and analyze the vulnerability to be processed; that is, identify the type to which the vulnerability to be processed belongs and the time tag of the latest processing deadline. Among them, the vulnerability type can be memory corruption, logical error, input validation, design error, configuration error, etc., and the time tag of the latest processing deadline is a time node. The time node of the time tag can be a preset time node or automatically set according to the processing level of the current vulnerability to be processed. Therefore, in this embodiment, during the preprocessing of the vulnerability to be processed, at least one task tag regarding the vulnerability to be processed and the time tag of the latest processing deadline corresponding to the task tag are extracted.
[0056] Specifically, as Figure 2 shown, in the embodiments of the present invention, the steps of preprocessing the vulnerability to be processed include:
[0057] Step S201: Identify and analyze the vulnerability to be processed;
[0058] Step S202: Extract at least one task tag regarding the vulnerability to be processed and the time tag of the latest processing deadline corresponding to the task tag.
[0059] Furthermore, please continue to refer to Figure 1 In the embodiments of the present invention, the task optimization method further includes:
[0060] Step S103: Add the vulnerability handling task to the task assignment queue for assignment; establish a task processing reserve for all vulnerability handling specialists who are idle before the deadline of the time tag of each vulnerability handling task and whose task tags match the vulnerability handling task; and assign the vulnerability handling task to a vulnerability handling specialist in the task processing reserve group for processing.
[0061] Furthermore, as Figure 3 shown, in the embodiments of the present invention, the judgment step of being idle before the deadline of the time tag of each vulnerability handling task includes:
[0062] Step S301: Obtain the idle time period of the vulnerability handling specialist;
[0063] Step S302: Determine the valid time period of the vulnerability handling specialist based on the estimated period for the current vulnerability handling task by the specialist.
[0064] In the specific implementation of step S302 provided by the present invention, first obtain the estimated period for the current vulnerability handling task by the vulnerability handling specialist; based on the start time node of the idle time period, calculate the valid time period of the vulnerability handling specialist based on the estimated period.
[0065] It further includes:
[0066] Step S303: When the deadline of the time label of the vulnerability handling task is within the valid time period, the current vulnerability handling specialist is in the idle time before the deadline of the time label of the vulnerability handling task.
[0067] In the specific implementation of step S303 provided by the embodiments of the present invention, in the specific implementation where the deadline of the time label of the vulnerability handling task is within the valid time period, obtain the deadline of the time label of the vulnerability handling task; when the deadline falls within the range of the valid time period, determine that the deadline of the time label of the vulnerability handling task is within the valid time period.
[0068] Among them, as Figure 4 shown, in the embodiments of the present invention, the step of determining the valid time period of the vulnerability handling specialist based on the estimated period for the current vulnerability handling task by the specialist includes:
[0069] Step S401: Obtain the estimated period for the current vulnerability handling task by the vulnerability handling specialist;
[0070] Step S402: Based on the start time node t1 of the idle time period T[t1, t2], calculate the valid time period S[t3, t2] of the vulnerability handling specialist based on the estimated period P, where t3 = t1 + P.
[0071] Among them, as Figure 5 shown, in the embodiments of the present invention, the judgment step for the deadline of the time label of the vulnerability handling task to be within the valid time period includes:
[0072] Step S501: Obtain the deadline t0 of the time label of the vulnerability handling task;
[0073] Step S502: When t0 ∈ S[t3, t2], determine that the deadline of the time label of the vulnerability handling task is within the valid time period.
[0074] Further, in the embodiment of the present invention, the step of matching the task tag of the vulnerability handling task includes:
[0075] Extract all the advantage tags of the vulnerability handling specialists who meet the idle time;
[0076] When the task tag of the vulnerability handling task is included in all the advantage tags, add the current vulnerability handling specialist to the task handling preparation group.
[0077] Furthermore, in the embodiment of the present invention, the step of assigning the vulnerability handling task to a vulnerability handling specialist in the task handling preparation group for processing includes:
[0078] Calculate the time slack Ts of each vulnerability handling specialist in the task handling preparation group, where Ts = t3 - t2;
[0079] Assign the vulnerability handling task to the vulnerability handling specialist for processing based on the sorting of the time slack Ts of each vulnerability handling specialist in the task handling preparation group.
[0080] Furthermore, in the embodiment of the present invention, the step of assigning the vulnerability handling task to the vulnerability handling specialist for processing based on the sorting of the time slack Ts of each vulnerability handling specialist in the task handling preparation group includes:
[0081] When sorting the time slack Ts of each vulnerability handling specialist in descending order, assign the vulnerability handling task to the vulnerability handling specialist corresponding to the first time slack Ts in the sorting for processing.
[0082] Correspondingly, in the embodiment of the present invention, when sorting the time slack Ts of each vulnerability handling specialist in ascending order, assign the vulnerability handling task to the vulnerability handling specialist corresponding to the last time slack Ts in the sorting for processing.
[0083] In summary, the system vulnerability handling task optimization method provided by the present invention preprocesses the to-be-processed vulnerabilities to obtain vulnerability handling tasks containing task tags and time tags, adds the vulnerability handling tasks to the task assignment queue for assignment, establishes a task handling preparation group for all vulnerability handling specialists who are idle before the deadline of the time tag of each vulnerability handling task and match the task tag of the vulnerability handling task, and assigns the vulnerability handling task to a vulnerability handling specialist in the task handling preparation group for processing.
[0084] In the embodiment of the present invention, by way of example:
[0085] Advantage tags of vulnerability handling specialist A: memory corruption type, logical error type;
[0086] Advantage tags of Vulnerability Handling Specialist B: Memory corruption, Input validation;
[0087] Advantage tags of Vulnerability Handling Specialist C: Memory corruption, Logical error, Input validation, Design error;
[0088] If the vulnerability task to be processed is: Logical error;
[0089] Then both Vulnerability Handling Specialist A and Vulnerability Handling Specialist C are used as a task processing preparation group; and further judge Vulnerability Handling Specialist A and Vulnerability Handling Specialist C. When the time of Vulnerability Handling Specialist A meets the deadline requirement of the current vulnerability task, prepare to assign the task to Vulnerability Handling Specialist A who meets the time requirement. When Vulnerability Handling Specialist C meets the time requirement, prepare to assign the task to Vulnerability Handling Specialist C who meets the time requirement;
[0090] Furthermore, the vulnerability handling specialist with the most abundant time for processing vulnerability tasks is taken as the most preferred; specifically, when the time of Vulnerability Handling Specialist C is more abundant than that of Vulnerability Handling Specialist A when processing the current vulnerability handling task, the vulnerability handling task is assigned to Vulnerability Handling Specialist C; on the contrary, when the time of Vulnerability Handling Specialist A is more abundant than that of Vulnerability Handling Specialist C when processing the current vulnerability handling task, the vulnerability handling task is assigned to Vulnerability Handling Specialist A.
[0091] In summary, the task optimization method provided by the present invention can reasonably distribute each vulnerability handling task to different vulnerability handling specialists for processing when testers discover vulnerabilities, effectively improving the efficiency of vulnerability handling.
[0092] Embodiment 2
[0093] As Figure 6 shown, in another embodiment provided by the present invention, a system vulnerability handling task optimization system, the task optimization system includes:
[0094] A preprocessing unit 601, which is used to obtain the vulnerability to be processed, preprocess the vulnerability to be processed, and obtain a vulnerability handling task containing a task tag and a time tag, where the task tag belongs to one of the preset tag libraries;
[0095] A task assignment unit 602, which is used to add the vulnerability handling task to the task assignment queue for assignment, establish a task processing preparation group for all vulnerability handling specialists who are idle before the deadline of the time tag of each vulnerability handling task and match the task tag of the vulnerability handling task, and assign the vulnerability handling task to a vulnerability handling specialist in the task processing preparation group for processing.
[0096] Embodiment 3
[0097] As Figure 7 shown, in another preferred embodiment of the present invention, a computer device is further provided. The computer device 700 includes a memory 701 and a processor 702. The memory 701 stores a computer program. When the computer program is executed by the processor 702, the processor 702 is caused to execute the system vulnerability handling task optimization method provided in the above-mentioned Embodiment 1.
[0098] Among them, the system vulnerability handling task optimization method includes: obtaining a vulnerability to be processed, preprocessing the vulnerability to be processed to obtain a vulnerability handling task containing a task tag and a time tag; adding the vulnerability handling task to a task allocation queue for allocation, and establishing a task handling preparation group for all vulnerability handling specialists who are idle before the deadline of the time tag of each vulnerability handling task and match the task tag of the vulnerability handling task, and allocating the vulnerability handling task to a vulnerability handling specialist in the task handling preparation group for processing.
[0099] In addition, the computer device 700 provided in the embodiment of the present invention may further have a communication interface 703 for receiving control instructions.
[0100] Embodiment 4
[0101] In another preferred embodiment of the present invention, a computer-readable storage medium is provided, which stores a computer program. When the computer program is executed by a processor, the processor is caused to execute the system vulnerability handling task optimization method provided in the above-mentioned Embodiment 1.
[0102] Among them, the system vulnerability handling task optimization method includes: obtaining a vulnerability to be processed, preprocessing the vulnerability to be processed to obtain a vulnerability handling task containing a task tag and a time tag; adding the vulnerability handling task to a task allocation queue for allocation, and establishing a task handling preparation group for all vulnerability handling specialists who are idle before the deadline of the time tag of each vulnerability handling task and match the task tag of the vulnerability handling task, and allocating the vulnerability handling task to a vulnerability handling specialist in the task handling preparation group for processing.
[0103] In each embodiment of the present invention, each functional unit may be integrated in a processing unit, or each unit may exist physically alone, or two or more units may be integrated in one unit. The above-mentioned integrated unit may be implemented in the form of hardware, or in the form of a combination of hardware and software functional units.
[0104] In a typical configuration of the present invention, the terminal, the devices of the service network, and the computing device include one or more processors (CPUs), an input / output interface, a network interface, and a memory. The memory may include non-permanent memory in the form of computer-readable media, random access memory (RAM), and / or non-volatile memory such as read-only memory (ROM) or flash memory (flash RAM). The memory is an example of computer-readable media.
[0105] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information by any method or technology. The information can be computer-readable instructions, data structures, program modules, or other data.
[0106] The above embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit it; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements on some or all of the technical features; these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention.
Claims
1. A method for optimizing system vulnerability handling tasks, characterized in that, The task optimization method includes: Obtain the vulnerability to be processed, preprocess the vulnerability to be processed to obtain a vulnerability handling task containing a task tag and a time tag, where the task tag belongs to one of the preset tag libraries; Add the vulnerability handling task to the task assignment queue for assignment. Establish a task handling preparatory group for all vulnerability handling specialists who are idle before the deadline of the time tag of each vulnerability handling task and whose task tags match the vulnerability handling task, and assign the vulnerability handling task to a vulnerability handling specialist in the task handling preparatory group for processing; The determination step of being idle before the deadline of the time tag of each vulnerability handling task includes: Obtain the idle time period of the vulnerability handling specialist; Based on the estimated period for the vulnerability handling specialist to process the current vulnerability handling task, determine the effective time period of the vulnerability handling specialist; When the deadline of the time tag of the vulnerability handling task is within the effective time period, the current vulnerability handling specialist is idle before the deadline of the time tag of the vulnerability handling task; The step of determining the effective time period of the vulnerability handling specialist based on the estimated period for the vulnerability handling specialist to process the current vulnerability handling task includes: Obtain the estimated period for the vulnerability handling specialist to process the current vulnerability handling task; According to the start time node t1 of the idle time period T[t1, t2], and based on the estimated period P, calculate the effective time period S[t3, t2] of the vulnerability handling specialist, where t3 = t1 + P; The determination step of the deadline of the time tag of the vulnerability handling task being within the effective time period includes: Obtain the deadline t0 of the time tag of the vulnerability handling task; When t0 ∈ S[t3, t2], determine that the deadline of the time tag of the vulnerability handling task is within the effective time period; The step of assigning the vulnerability handling task to a vulnerability handling specialist in the task handling preparatory group for processing includes: Calculate the time slack Ts of each vulnerability handling specialist in the task handling preparatory group, where Ts = t3 - t2; Assign the vulnerability handling task to the vulnerability handling specialist for processing based on the sorting of the time slack Ts of each vulnerability handling specialist in the task handling preparatory group.
2. The method for optimizing system vulnerability handling tasks according to claim 1, wherein The step of preprocessing the vulnerability to be processed includes: Identify and analyze the vulnerability to be processed; Extract at least one task tag regarding the vulnerability to be processed and the time tag corresponding to the latest processing deadline of the task tag.
3. The system vulnerability handling task optimization method according to claim 2, characterized in that Before the step of adding the vulnerability handling task to the task assignment queue for assignment, the task optimization method further includes: Establish at least one advantage tag for each vulnerability handling specialist, and each advantage tag belongs to one of the preset tag libraries.
4. The method for optimizing system vulnerability handling tasks according to claim 1, wherein The step of matching the task tag of the vulnerability handling task includes: Extract all the advantage tags of the vulnerability handling specialists who meet the idle time; When the task tag of the vulnerability handling task is included in all the above-mentioned advantage tags, the current vulnerability handling specialist is added to the task handling preparation group.
5. The method for optimizing system vulnerability handling tasks according to claim 1, characterized in that The step of allocating the vulnerability handling task to a vulnerability handling specialist for processing based on the sorting of the time availability Ts of each vulnerability handling specialist in the task handling preparation group includes: When sorting the time availability Ts of each vulnerability handling specialist in descending order, the vulnerability handling task is allocated to the vulnerability handling specialist corresponding to the first time availability Ts in the sorting for processing.
6. A system vulnerability handling task optimization system, characterized in that The task optimization system includes: A preprocessing unit, which is used to obtain the vulnerability to be processed, preprocess the vulnerability to be processed, and obtain a vulnerability handling task containing a task tag and a time tag, where the task tag belongs to one of the preset tag libraries; A task allocation unit, which is used to add the vulnerability handling task to the task allocation queue for allocation, establish a task handling preparation group for all vulnerability handling specialists who are idle before the deadline of the time tag of each vulnerability handling task and match the task tag of the vulnerability handling task, and allocate the vulnerability handling task to a vulnerability handling specialist in the task handling preparation group for processing; the judgment step of being idle before the deadline of the time tag of each vulnerability handling task includes: Obtain the idle time period of the vulnerability handling specialist; Based on the estimated period for the vulnerability handling specialist to process the current vulnerability handling task, determine the effective time period of the vulnerability handling specialist; When the deadline of the time tag of the vulnerability handling task is within the effective time period, the current vulnerability handling specialist is idle before the deadline of the time tag of the vulnerability handling task; The step of determining the effective time period of the vulnerability handling specialist based on the estimated period for the vulnerability handling specialist to process the current vulnerability handling task includes: Obtain the estimated period for the vulnerability handling specialist to process the current vulnerability handling task; According to the start time node t1 of the idle time period T[t1, t2], and based on the estimated period P, calculate the effective time period S[t3, t2] of the vulnerability handling specialist, where t3 = t1 + P; The judgment step of the deadline of the time tag of the vulnerability handling task being within the effective time period includes: Obtain the deadline t0 of the time tag of the vulnerability handling task; When t0 ∈ S[t3, t2], determine that the deadline of the time tag of the vulnerability handling task is within the effective time period; The step of allocating the vulnerability handling task to a vulnerability handling specialist in the task handling preparation group for processing includes: Calculate the time availability Ts of each vulnerability handling specialist in the task handling preparation group, where Ts = t3 - t2; Allocate the vulnerability handling task to a vulnerability handling specialist for processing based on the sorting of the time availability Ts of each vulnerability handling specialist in the task handling preparation group.
Citation Information
Patent Citations
Vulnerability mining model construction method based on swarm intelligence
CN110708279A
Tourism order task allocation method, system, device and storage medium
CN112785208A