A vulnerability management method, system, computer device and storage medium
By receiving user identity information and determining user levels, generating query instructions and using the feature table of the reference code base to locate reference code, the problem of difficulty in querying vulnerabilities is solved by non-professional personnel, and convenient and accurate vulnerability query is achieved.
Patent Information
- Application Number
- CN202210049994.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-01-17
- Publication Date
- 2025-06-10
- Estimated Expiration
- 2042-01-17
AI Technical Summary
In the existing vulnerability library, non-professional personnel encounter difficulties when querying vulnerabilities, and it is difficult to quickly determine which vulnerability the problem belongs to.
By receiving user identity information, determining the user level, and comparing the user level and preset level thresholds, obtaining task targets and architectural parameters, and generating query instructions. Use the feature table of the reference code base to locate reference code, determine the vulnerability type and read the solution.
It realizes convenient query and determination of vulnerability types, improving the convenience and accuracy of non-professional personnel in querying vulnerabilities.
Smart Images

Figure CN114579975B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of vulnerability management, and specifically, to a vulnerability management method, system, computer device, and storage medium. Background Art
[0002] In existing vulnerability libraries, most of the vulnerabilities in the vulnerability library are stored by version numbers or custom names; for some new users or non-professionals, when they need to query what kind of vulnerability a certain problem belongs to, this is very difficult.
[0003] It can be imagined that when we encounter unfamiliar software problems, we often search on search engines. During the search process, our description language is generally very rigid, which is where the difficulty of vulnerability query lies. Because the user doesn't know what kind of vulnerability the problem he encounters is, that's why he queries, but not knowing what kind of vulnerability the problem he encounters is, the query process will be very difficult. How to improve the convenience of non-professionals to query vulnerabilities is the technical problem that the technical solution of the present invention wants to solve. Summary of the Invention
[0004] The purpose of the present invention is to provide a vulnerability management method, system, computer device, and storage medium to solve the problems raised in the above background art.
[0005] To achieve the above purpose, the present invention provides the following technical solutions:
[0006] A vulnerability management method, the method includes:
[0007] Receiving an access request containing user identity information, and determining the user level according to the user identity information;
[0008] Comparing the user level with a preset level threshold, and when the user level reaches the preset level threshold, obtaining the code to be inspected containing the task objective and architecture parameters, and generating a query instruction; wherein, the number of types of the task objective is a finite value, and the architecture parameters are determined by the statements of the code to be inspected;
[0009] Locating a reference code library according to the task objective and the architecture parameters, reading the feature table of the reference code library, and locating the reference code in the reference code library according to the feature table; wherein, the feature table contains input items and output items, and the number of types of the input values in the input items is a finite value; the feature table and the reference code table are in a mapping relationship;
[0010] Determining the vulnerability type according to the reference code, and reading the solution.
[0011] As a further solution of the present invention: The step of receiving an access request containing user identity information and determining the user level according to the user identity information includes:
[0012] Receiving an access request containing user identity information, traversing a preset permission table based on the user identity information, and querying the user level according to the traversal result;
[0013] Obtaining the user location information and determining the risk level according to the location information;
[0014] Correcting the user level according to the risk level.
[0015] As a further solution of the present invention: The step of obtaining the user location information and determining the risk level according to the location information includes:
[0016] Obtaining the location name in the user location information and traversing the access report based on the location name; wherein, the access report includes a location name item and an access times item;
[0017] When the access report contains the location name, reading the access times corresponding to the location name;
[0018] When the access report does not contain the location name, inserting the location name into the access report and assigning the corresponding access times as one;
[0019] Determining the risk level according to the access times corresponding to the location name.
[0020] As a further solution of the present invention: The step of comparing the user level with a preset level threshold, and when the user level reaches the preset level threshold, obtaining the code to be inspected containing the task objective and the architecture parameters and generating a query instruction includes:
[0021] Comparing the user level with a preset level threshold, and when the user level reaches the preset level threshold, obtaining the code to be inspected containing the task objective;
[0022] Traversing the code to be inspected, locating and marking the nested symbols in the code to be inspected according to the preset hierarchical identifier;
[0023] Counting the hierarchical identifiers of the nested symbols and generating architecture parameters according to the counted hierarchical identifiers;
[0024] Generating a query instruction according to the task objective and the architecture parameters.
[0025] As a further solution of the present invention: The steps of locating the reference code library according to the task objective and the architecture parameters, reading the feature table of the reference code library, and locating the reference code in the reference code library according to the feature table include:
[0026] Perform a primary screening of the code library according to the task objective, and perform a secondary screening of the code library after the primary screening according to the architecture parameters to obtain the reference code library;
[0027] Read the feature table in the reference code library, read the input items in the feature table, extract the input values in the input items, and input the input values into the code to be inspected in sequence to obtain the output values;
[0028] Traverse the output items in the feature table according to the output values, and calculate the matching degrees in sequence;
[0029] When the matching degree reaches the matching threshold, obtain the matching position, and extract the reference code according to the matching position based on the mapping relationship between the feature table and the reference code table.
[0030] As a further solution of the present invention: The steps of generating the feature table include:
[0031] Read the information input ends of the reference codes in the reference feature table in sequence, and obtain the data structures of the information input ends;
[0032] Classify the reference codes according to the data structures;
[0033] Obtain the input value ranges of the information input ends in the reference codes after classification, and determine the input values according to the input value ranges;
[0034] Input the input values into each reference code to obtain the output values, and obtain the input-output data pairs according to the input values and the output values;
[0035] Count the input-output data pairs to generate the feature table;
[0036] Wherein, the number of types of the input values is the same as the number of classifications of the reference codes.
[0037] The technical solution of the present invention also provides a vulnerability management system, and the system includes:
[0038] A user level determination module, configured to receive an access request containing user identity information, and determine the user level according to the user identity information;
[0039] A query instruction generation module is configured to compare the user level with a preset level threshold. When the user level reaches the preset level threshold, it acquires the code to be inspected containing the task objective and architecture parameters, and generates a query instruction. Among them, the number of types of the task objective is a finite value, and the architecture parameters are determined by the statements of the code to be inspected.
[0040] A reference code location module is configured to locate the reference code library according to the task objective and the architecture parameters, read the feature table of the reference code library, and locate the reference code in the reference code library according to the feature table. Among them, the feature table contains input items and output items, and the number of types of input values in the input items is a finite value; the feature table and the reference code table have a mapping relationship.
[0041] A solution determination module is configured to determine the vulnerability type according to the reference code and read the solution.
[0042] As a further solution of the present invention: the reference code location module includes:
[0043] A screening unit is configured to perform a first-level screening on the code library according to the task objective, and perform a second-level screening on the code library after the first-level screening according to the architecture parameters to obtain the reference code library.
[0044] A detection unit is configured to read the feature table in the reference code library, read the input items in the feature table, extract the input values in the input items, and input the input values into the code to be inspected in sequence to obtain the output values.
[0045] A matching degree calculation unit is configured to traverse the output items in the feature table according to the output values and calculate the matching degrees in sequence.
[0046] An extraction unit is configured to, when the matching degree reaches the matching threshold, obtain the matching position, and extract the reference code according to the matching position based on the mapping relationship between the feature table and the reference code table.
[0047] The technical solution of the present invention also provides a computer device, which includes one or more processors and one or more memories. At least one program code is stored in the one or more memories. When the program code is loaded and executed by the one or more processors, the vulnerability management method is implemented.
[0048] The technical solution of the present invention also provides a storage medium, in which at least one program code is stored. When the program code is loaded and executed by a processor, the vulnerability management method is implemented.
[0049] Compared with the prior art, the beneficial effects of the present invention are as follows: The present invention establishes index terms according to the input-output relationship. When receiving the code to be detected of the user, it obtains the input-output relationship of the code to be detected, determines the vulnerability type according to the input-output relationship, and the detection process is very convenient and has a very wide range of applications. Brief Description of the Drawings
[0050] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings in the following description are only some embodiments of the present invention.
[0051] Figure 1 Shows the flowchart of the vulnerability management method.
[0052] Figure 2 Shows the first sub-flowchart of the vulnerability management method.
[0053] Figure 3 Shows the second sub-flowchart of the vulnerability management method.
[0054] Figure 4 Shows the third sub-flowchart of the vulnerability management method.
[0055] Figure 5 Shows the fourth sub-flowchart of the vulnerability management method.
[0056] Figure 6 Shows the block diagram of the composition structure of the vulnerability management system.
[0057] Figure 7 Shows the block diagram of the composition structure of the reference code location module in the vulnerability management system. Detailed Embodiments
[0058] In order to make the technical problems, technical solutions and beneficial effects to be solved by the present invention clearer, the following further details the present invention in conjunction with the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.
[0059] Embodiment 1
[0060] Figure 1 Shows the flowchart of the vulnerability management method. In the embodiment of the present invention, a vulnerability management method, the method includes steps S100 to step S400:
[0061] Step S100: Receive an access request containing user identity information, and determine the user level according to the user identity information;
[0062] Step S100 is an identity information verification process, which is a basic function in any service system and aims to simply distinguish users.
[0063] Step S200: Compare the user level with a preset level threshold. When the user level reaches the preset level threshold, obtain the code to be inspected containing the task objective and architecture parameters, and generate a query instruction; where the number of types of the task objective is a finite value, and the architecture parameters are determined by the statements of the code to be inspected.
[0064] Compare the user level with the preset level threshold. If it is a free service, the level threshold can be lowered to adapt to all users. Of course, the users should exclude those in a specific database. In an example of the technical solution of the present invention, the user level of the users in the specific database can be set to a negative value; then obtain the code to be inspected containing the task objective and architecture parameters uploaded by the user, and generate a query instruction.
[0065] Among them, the code to be inspected is actually vulnerability code, and the purpose of the technical solution of the present invention is to query the specific vulnerability type of the code.
[0066] Step S300: Locate the reference code library according to the task objective and the architecture parameters, read the feature table of the reference code library, and locate the reference code in the reference code library according to the feature table; where the feature table contains input items and output items, and the number of types of input values in the input items is a finite value; the feature table and the reference code table are in a mapping relationship.
[0067] Step S300 is the core step of the technical solution of the present invention, and its function is to determine the vulnerability type of the code to be inspected with the help of the reference code library. Specifically, it determines the vulnerability type with the help of the feature table that is in a mapping relationship with the reference code table. Among them, the feature table is set with input items and output items as indexes, and the specific setting process is described in detail in the subsequent content. In the actual application process, there is often only one or a limited number of types of input values.
[0068] Step S400: Determine the vulnerability type according to the reference code and read the solution.
[0069] After determining the reference code in the reference code library, determining the vulnerability type according to the reference code only requires a simple database reading operation to obtain the solution.
[0070] Figure 2 Shows the first sub - process block diagram of the vulnerability management method. The steps of receiving an access request containing user identity information and determining the user level according to the user identity information include steps S101 to S103:
[0071] Step S101: Receive an access request containing user identity information, traverse a preset permission table based on the user identity information, and query the user level according to the traversal result;
[0072] Step S102: Obtain the user location information and determine the risk level according to the location information;
[0073] Step S103: Modify the user level according to the risk level.
[0074] The above content provides a specific user level determination scheme. The user level can be understood as user permissions. On the basis of querying user permissions through the permission table, an additional modification operation is added. The modification process is based on the user's location information. For example, if a person with permissions has an abnormal location, then his level needs to be adjusted to a certain extent. Generally, his permissions will be lowered; as for the extent of the reduction, there is no upper limit, which means that there will be a situation where the permissions of users with abnormal locations are all the lowest and they do not have any access functions.
[0075] Figure 3 The second sub-process block diagram of the vulnerability management method is shown. The steps of obtaining the user location information and determining the risk level according to the location information include steps S1021 to S1024:
[0076] Step S1021: Obtain the location name in the user location information and traverse the access report based on the location name; wherein, the access report includes a location name item and an access times item;
[0077] Step S1022: When the access report contains the location name, read the access times corresponding to the location name;
[0078] Step S1023: When the access report does not contain the location name, insert the location name into the access report and assign the corresponding access times as one;
[0079] Step S1024: Determine the risk level according to the access times corresponding to the location name.
[0080] Steps S1021 to S1024 provide a specific location information processing method. Each time an access occurs, the corresponding location is recorded to generate an access report, and it is determined whether the user logs in to the system at the usual residence according to the access times item in the access report, and then the risk level is determined.
[0081] Figure 4The third sub - process block diagram of the vulnerability management method is shown. The step of comparing the user level with a preset level threshold and, when the user level reaches the preset level threshold, obtaining the code to be inspected containing the task objective and architecture parameters and generating a query instruction includes steps S201 to S204:
[0082] Step S201: Compare the user level with a preset level threshold. When the user level reaches the preset level threshold, obtain the code to be inspected containing the task objective;
[0083] Step S202: Traverse the code to be inspected, locate and mark the nested symbols in the code to be inspected according to a preset hierarchical identifier;
[0084] Step S203: Count the hierarchical identifiers of the nested symbols and generate architecture parameters according to the counted hierarchical identifiers;
[0085] Step S204: Generate a query instruction according to the task objective and the architecture parameters.
[0086] The above content mainly describes the architecture parameters in detail. For a piece of code, no matter which computer language it is written in, it will have some unique features. Among them, the nested structure of the code is one of the features; if the code to be inspected is written in C language, then some parentheses are its nested symbols, and the hierarchical flag can be a number. When the hierarchical flag is a number, for example, when the first left parenthesis is detected, it is recorded as 1, when the second left parenthesis is detected, it is recorded as 2, when the first right parenthesis is detected, it is recorded as 2 according to the second left parenthesis, and when the second right parenthesis is detected, it is recorded as 1. Then the architecture parameter is 1221. Correspondingly, if it is 122221, it means there are two parallel small parentheses in a large parenthesis. This process is actually not difficult to implement. In existing compilation software, there are similar detection functions.
[0087] Among them, the task objective is the objective when the code is designed. When each code is designed, it will have its own problem to solve, and solving the problem is the task objective.
[0088] Figure 5 The fourth sub - process block diagram of the vulnerability management method is shown. The step of locating the reference code library according to the task objective and the architecture parameters, reading the feature table of the reference code library, and locating the reference code in the reference code library according to the feature table includes steps S301 to S304:
[0089] Step S301: Perform a primary screening of the code library according to the task objective, and perform a secondary screening of the code library after the primary screening according to the architecture parameters to obtain the reference code library;
[0090] Step S302: Read the feature table in the reference code library, read the input items in the feature table, extract the input values in the input items, and sequentially input the input values into the code to be inspected to obtain output values;
[0091] Step S303: Traverse the output items in the feature table according to the output values, and sequentially calculate the matching degrees;
[0092] Step S304: When the matching degree reaches the matching threshold, obtain the matching position, and extract the reference code according to the mapping relationship between the feature table and the reference code table based on the matching position.
[0093] Steps S301 to S304 provide a specific code matching solution. First, screen the code library according to the task objective and architecture parameters to obtain a reference code library with fewer elements. Then, extract the feature table of the reference code library, extract the input values of the input items in the feature table, input the input values into the code to be inspected to obtain output values, locate the matching position in the feature table according to the input values and output values, and extract the reference code in the reference code table according to the matching position.
[0094] It can be seen that the core part of the above content is the generation process of the feature table. The generation steps of the feature table include:
[0095] Sequentially read the information input ends of the reference codes in the reference feature table, and obtain the data structures of the information input ends;
[0096] Classify the reference codes according to the data structures;
[0097] Obtain the input value ranges of the information input ends in the classified reference codes, and determine the input values according to the input value ranges;
[0098] Input the input values into each reference code to obtain output values, and obtain input-output data pairs according to the input values and the output values;
[0099] Count the input-output data pairs to generate a feature table;
[0100] Among them, the number of types of the input values is the same as the number of classifications of the reference codes.
[0101] The information input ends in different reference codes may be different. Described in computer language, it means that the data structures of the input values are different. Classify the reference codes according to the data structures. Generally, the data structures are predefined data structures such as integers.
[0102] Then, one or several input values are determined according to different reference codes. The number of these input values is very small. For each reference code, at least one of the input values can match the information input terminal corresponding to the reference code.
[0103] According to the above one or several input values, output values of each reference code are obtained. Eventually, each reference code has its own unique input-output data pair. By counting these input-output data pairs, a feature table is obtained.
[0104] Embodiment 2
[0105] Figure 6 The composition structure block diagram of the vulnerability management system is shown. In an embodiment of the present invention, a vulnerability management system, the system 10 includes:
[0106] A user level determination module 11, configured to receive an access request containing user identity information and determine the user level according to the user identity information;
[0107] A query instruction generation module 12, configured to compare the user level with a preset level threshold. When the user level reaches the preset level threshold, obtain the code to be inspected containing the task target and architecture parameters, and generate a query instruction; wherein, the number of types of the task target is a finite value, and the architecture parameters are determined by the statements of the code to be inspected;
[0108] A reference code location module 13, configured to locate a reference code library according to the task target and the architecture parameters, read the feature table of the reference code library, and locate a reference code in the reference code library according to the feature table; wherein, the feature table contains input items and output items, and the number of types of input values in the input items is a finite value; the feature table and the reference code table are in a mapping relationship;
[0109] A solution determination module 14, configured to determine the vulnerability type according to the reference code and read the solution.
[0110] Figure 7 The composition structure block diagram of the reference code location module in the vulnerability management system is shown. The reference code location module 13 includes:
[0111] A screening unit 131, configured to perform a first-level screening on the code library according to the task target, and perform a second-level screening on the code library after the first-level screening according to the architecture parameters to obtain a reference code library;
[0112] A detection unit 132, configured to read the feature table in the reference code library, read the input items in the feature table, extract the input values in the input items, and input the input values into the code to be inspected in sequence to obtain output values;
[0113] A matching degree calculation unit 133 is configured to traverse output items in the feature table according to the output value, and calculate the matching degree in sequence.
[0114] An extraction unit 134 is configured to, when the matching degree reaches a matching threshold, obtain a matching position, and extract a reference code according to the matching position based on the mapping relationship between the feature table and the reference code table.
[0115] All functions that can be implemented by the vulnerability management method are completed by a computer device. The computer device includes one or more processors and one or more memories. At least one program code is stored in the one or more memories, and the program code is loaded and executed by the one or more processors to implement the functions of the vulnerability management method.
[0116] The processor fetches instructions from the memory one by one, analyzes the instructions, and then completes corresponding operations according to the requirements of the instructions, generating a series of control commands to make each part of the computer act automatically, continuously and coordinately, becoming an organic whole, and realizing the input of the program, the input of data, and the operation and output of results. All arithmetic operations or logical operations generated in this process are completed by the arithmetic unit; the memory includes a read-only memory (ROM), and the read-only memory is used to store computer programs, and a protection device is provided outside the memory.
[0117] Exemplarily, a computer program can be divided into one or more modules. One or more modules are stored in the memory and executed by the processor to complete the present invention. One or more modules can be a series of computer program instruction segments capable of completing specific functions, and the instruction segments are used to describe the execution process of the computer program in the terminal device.
[0118] Those skilled in the art can understand that the description of the above service device is only an example and does not constitute a limitation on the terminal device. It may include more or fewer components than the above description, or combine some components, or different components. For example, it may include input and output devices, network access devices, buses, etc.
[0119] The so-called processor may be a Central Processing Unit (CPU), or it may also be other general-purpose processors, Digital Signal Processors (DSPs), Application Specific Integrated Circuits (ASICs), Field-Programmable Gate Arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The above-mentioned processor is the control center of the above-mentioned terminal device, and connects various parts of the entire user terminal through various interfaces and lines.
[0120] The above-mentioned memory can be used to store computer programs and / or modules. The above-mentioned processor realizes various functions of the above-mentioned terminal device by running or executing the computer programs and / or modules stored in the memory, and by calling the data stored in the memory. The memory mainly includes a program storage area and a data storage area. Among them, the program storage area can store an operating system, application programs required for at least one function (such as an information collection template display function, a product information release function, etc.); the data storage area can store data created according to the use of the berth status display system (such as product information collection templates corresponding to different product types, product information that different product providers need to release, etc.). In addition, the memory may include high-speed random access memory, and may also include non-volatile memory, such as a hard disk, a memory, a plug-in hard disk, a Smart Media Card (SMC), a Secure Digital (SD) card, a Flash Card, at least one magnetic disk storage device, a flash memory device, or other volatile solid-state storage devices.
[0121] If the modules / units integrated in the terminal device are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, to implement all or part of the modules / units in the above-mentioned embodiment system of the present invention, it can also be completed by instructing the relevant hardware through a computer program. The above computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, it can realize the functions of the above-mentioned various system embodiments. Among them, the computer program includes computer program code, and the computer program code can be in the form of source code, object code, executable file or some intermediate form, etc. The computer-readable medium can include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), electrical carrier signal, telecommunication signal, and software distribution medium, etc.
[0122] It should be noted that in this article, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "including a..." does not exclude the existence of additional identical elements in the process, method, article or device including the element.
[0123] The above are only the preferred embodiments of the present invention, and do not limit the patent scope of the present invention accordingly. Any equivalent structure or equivalent process transformation made by using the specification and drawings of the present invention, or directly or indirectly applied in other related technical fields, shall be equally included in the patent protection scope of the present invention.
Claims
1. A vulnerability management method, characterized in that, the method includes: Receiving an access request containing user identity information, and determining the user level according to the user identity information; Comparing the user level with a preset level threshold, and when the user level reaches the preset level threshold, obtaining the code to be inspected containing the task objective and architecture parameters, and generating a query instruction; Among them, the step of generating a query instruction includes: Comparing the user level with a preset level threshold, and when the user level reaches the preset level threshold, obtaining the code to be inspected containing the task objective; Traversing the code to be inspected, locating and marking the nested symbols in the code to be inspected according to the preset hierarchical identifier; Counting the hierarchical identifiers of the nested symbols, and generating architecture parameters according to the counted hierarchical identifiers; Generating a query instruction according to the task objective and the architecture parameters; Among them, the number of types of the task objective is a finite value, and the architecture parameters are determined by the statements of the code to be inspected; Locating the reference code library according to the task objective and the architecture parameters, reading the feature table of the reference code library, and locating the reference code in the reference code library according to the feature table; Among them, the feature table contains input items and output items, and the number of types of input values in the input items is a finite value; The feature table and the reference code table are in a mapping relationship; Determining the vulnerability type according to the reference code, and reading the solution.
2. The vulnerability management method according to claim 1, characterized in that, the step of receiving an access request containing user identity information and determining the user level according to the user identity information includes: Receiving an access request containing user identity information, traversing a preset permission table based on the user identity information, and querying the user level according to the traversal result; Obtaining the user location information, and determining the risk level according to the location information; Correcting the user level according to the risk level.
3. The vulnerability management method according to claim 2, characterized in that, the step of obtaining the user location information and determining the risk level according to the location information includes: Obtaining the location name in the user location information, and traversing the access report based on the location name; Among them, the access report includes a location name item and an access times item; When the access report contains the location name, reading the access times corresponding to the location name; When the access report does not contain the location name, inserting the location name into the access report and assigning the corresponding access times as one; Determining the risk level according to the access times corresponding to the location name.
4. The vulnerability management method according to claim 1, characterized in that, the step of locating the reference code library according to the task objective and the architecture parameters, reading the feature table of the reference code library, and locating the reference code in the reference code library according to the feature table includes: Performing a first-level screening on the code library according to the task objective, and performing a second-level screening on the code library after the first-level screening according to the architecture parameters to obtain the reference code library; Read the feature table in the reference code library, read the input items in the feature table, extract the input values in the input items, and sequentially input the input values into the code to be tested to obtain output values; Traverse the output items in the feature table according to the output values, and calculate the matching degrees sequentially; When the matching degree reaches the matching threshold, obtain the matching position, and extract the reference code according to the matching position based on the mapping relationship between the feature table and the reference code table.
5. The vulnerability management method according to any one of claims 1-4, characterized in that, The generating step of the feature table includes: Sequentially read the information input ends of the reference codes in the reference feature table, and obtain the data structures of the information input ends; Classify the reference codes according to the data structures; Obtain the input value ranges of the information input ends in the classified reference codes, and determine the input values according to the input value ranges; Input the input values into each reference code to obtain output values, and obtain input-output data pairs according to the input values and the output values; Count the input-output data pairs to generate a feature table; Wherein, the number of types of the input values is the same as the number of classifications of the reference codes.
6. A vulnerability management system, characterized in that, The system includes: A user level determination module, configured to receive an access request containing user identity information, and determine the user level according to the user identity information; A query instruction generation module, configured to compare the user level with a preset level threshold, and when the user level reaches the preset level threshold, obtain the code to be tested containing the task objective and the architecture parameters, and generate a query instruction; Wherein, the number of types of the task objectives is a finite value, and the architecture parameters are determined by the statements of the code to be tested; A reference code location module, configured to locate the reference code library according to the task objective and the architecture parameters, read the feature table of the reference code library, and locate the reference code in the reference code library according to the feature table; Wherein, the feature table includes input items and output items, and the number of types of the input values in the input items is a finite value; the feature table and the reference code table have a mapping relationship; A solution determination module, configured to determine the vulnerability type according to the reference code and read the solution.
7. The vulnerability management system according to claim 6, characterized in that, The reference code location module includes: A screening unit, configured to perform a first-level screening on the code library according to the task objective, and perform a second-level screening on the code library after the first-level screening according to the architecture parameters to obtain a reference code library; A detection unit, configured to read the feature table in the reference code library, read the input items in the feature table, extract the input values in the input items, and sequentially input the input values into the code to be tested to obtain output values; A matching degree calculation unit, configured to traverse the output items in the feature table according to the output values, and calculate the matching degrees sequentially; An extraction unit, configured to, when the matching degree reaches the matching threshold, obtain the matching position, and extract the reference code according to the matching position based on the mapping relationship between the feature table and the reference code table.
8. A computer device, characterized in that, The computer device includes one or more processors and one or more memories. At least one program code is stored in the one or more memories. When the program code is loaded and executed by the one or more processors, the vulnerability management method described in any one of claims 1-5 is implemented.
9. A storage medium, characterized in that at least one program code is stored in the storage medium. When the program code is loaded and executed by a processor, the vulnerability management method described in any one of claims 1-5 is implemented.
Citation Information
Patent Citations
Custom plug-in generation method and device, equipment and storage medium
CN108537042A
Industrial Internet of Things abnormal behavior detection method and system
CN113746845A