A method for assessing security risks of vulnerabilities

By acquiring software feature information from the operating system of video devices and combining it with vulnerability feature information to conduct vulnerability security risk assessment, the problem of incomplete vulnerability scanning in existing technologies is solved, and a more accurate assessment of the scope and severity of vulnerability impact is achieved.

CN114943080BActive Publication Date: 2025-12-12BEIJING LEADSEC TECH +2
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202110825355.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-07-21
Publication Date
2025-12-12
Estimated Expiration
2041-07-21

AI Technical Summary

Technical Problem

In existing technologies, when vulnerability scanners perform security assessments of video devices on an IP address basis, there is a problem of incomplete vulnerability scanning, leading to inaccurate assessment results.

Method used

By acquiring the characteristic information of the target vulnerability software in the operating system, and combining the software's characteristic information with the pre-acquired vulnerability characteristic information, the security risk of the vulnerability is assessed, including the software's importance level, usage rate, and severity level. The weight of the characteristic information is dynamically adjusted to improve the accuracy of the assessment results.

Benefits of technology

It improves the comprehensiveness and accuracy of vulnerability assessment, enabling a more accurate determination of the scope and severity of the vulnerability's impact.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114943080B_ABST
    Figure CN114943080B_ABST
Patent Text Reader

Abstract

The embodiment of the application discloses a method for evaluating security risks of vulnerabilities. The method comprises the following steps: obtaining software with a target vulnerability when the target vulnerability is evaluated; obtaining characteristic information of the software in the process of running in an operating system; and evaluating security risks of the vulnerability according to the characteristic information of the software and pre-acquired characteristic information of the vulnerability.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] Embodiments of the present application relate to the field of information security, and in particular to a method for evaluating security risks of a vulnerability. BACKGROUND

[0002] Video devices are used more and more widely in the environment of wisdom empowerment, such as smart city, smart factory, smart transportation, etc. Video network security is also becoming more and more important, and effective evaluation of the security of video private network has become an important research field. In the prior art, the security of the video network is mainly evaluated by using a vulnerability scanner.

[0003] In the related art, the vulnerability scanner takes IP addresses as units to perform port discovery on video devices and identify services started by the video devices, and determines whether the related devices have security vulnerabilities by sending data packets to the identified services. The above-mentioned method has the problem of incomplete vulnerability scanning. SUMMARY

[0004] To solve any of the above technical problems, embodiments of the present application provide a method for evaluating security risks of a vulnerability.

[0005] To achieve the purposes of the embodiments of the present application, the embodiments of the present application provide a method for evaluating security risks of a vulnerability, comprising:

[0006] When evaluating a target vulnerability, a software having the target vulnerability is obtained;

[0007] Characteristic information of the software in a running process in an operating system is obtained;

[0008] According to the characteristic information of the software and pre-obtained characteristic information of the vulnerability, the security risks of the vulnerability are evaluated.

[0009] A storage medium having a computer program stored therein, wherein the computer program is configured to execute the method described above when running.

[0010] An electronic device comprising a memory and a processor, wherein the memory has a computer program stored therein, and the processor is configured to execute the computer program to perform the method described above.

[0011] The technical solution provided by the embodiments of the present application, when evaluating a target vulnerability, a software having the target vulnerability is obtained, characteristic information of the software in a running process in an operating system is obtained, and according to the characteristic information of the software and pre-obtained characteristic information of the vulnerability, the security risks of the vulnerability are evaluated. By combining the characteristic information of the software having the target vulnerability for security evaluation, the comprehensiveness of the evaluation risks can be effectively improved, and the accuracy of the evaluation results can be improved.

[0012] Other features and advantages of the present embodiments will be set forth in the description that follows, and in part will be apparent from the description, or can be learned by practice of the present embodiments. The purposes and other advantages of the present embodiments will be realized and attained by the structure particularly pointed out in the description and claims of the present embodiments. BRIEF DESCRIPTION OF DRAWINGS

[0013] The accompanying drawings are included to provide a further understanding of the present embodiments and are incorporated in and constitute a part of this specification, illustrate embodiments of the present embodiments and serve to explain the principles of the present embodiments, but are not intended to limit the present embodiments.

[0014] Figure 1 A flowchart of the method for evaluating security risks of vulnerabilities provided by the present embodiments. DETAILED DESCRIPTION

[0015] In order to make the purposes, technical solutions and advantages of the present embodiments clearer, the following will describe the embodiments of the present embodiments in detail with reference to the drawings. It should be noted that, in the case of no conflict, the embodiments in the present embodiments and the features in the embodiments can be combined with each other at will.

[0016] The security evaluation by the vulnerability scanner in the prior art is based on a single attribute, the related attributes of security vulnerabilities are not associated, the real threat of the vulnerability cannot be evaluated, and there is the problem of inaccurate evaluation results.

[0017] Figure 1 A flowchart of the method for evaluating security risks of vulnerabilities provided by the present embodiments. As shown in Figure 1 The method comprises the following steps.

[0018] In step 101, when evaluating a target vulnerability, a software in which the target vulnerability exists is acquired.

[0019] In an exemplary embodiment, a vulnerability can be uniquely identified by a number.

[0020] The vulnerability selected externally is taken as a target vulnerability, and security evaluation of a single vulnerability is realized.

[0021] When it is determined to evaluate the security risks of a vulnerability, not only the attribute information of the vulnerability itself is acquired, but also the attribute information of the software in which the vulnerability exists is combined for evaluation.

[0022] In step 102, feature information of the software in the running process of an operating system is acquired.

[0023] The characteristic information of the software is used to indicate the application frequency and application range of the software, so as to facilitate determination of the influence range and severity of the vulnerability according to the characteristic information of the software.

[0024] In step 103, the security risk of the vulnerability is evaluated according to the characteristic information of the software and the characteristic information of the vulnerability obtained in advance.

[0025] In an example embodiment, the security risk of the vulnerability can be evaluated according to the characteristic information of the vulnerability, and the influence range of the vulnerability can be further determined according to the influence range of the software associated with the vulnerability by means of the characteristic information of the software, so as to more accurately evaluate the security risk of the vulnerability.

[0026] The method provided by the embodiment of the application can obtain the software associated with the target vulnerability, obtain the characteristic information of the software in the running process of the operating system, and evaluate the security risk of the vulnerability according to the characteristic information of the software and the characteristic information of the vulnerability obtained in advance. By combining the characteristic information of the software associated with the target vulnerability for security evaluation, the comprehensiveness of the evaluation risk can be effectively improved, and the accuracy of the evaluation result can be improved.

[0027] The method provided by the embodiment of the application will be described below.

[0028] In an example embodiment, the characteristic information of the software includes at least one of the importance level information of the software in the operating system, the usage rate, and the hazard level.

[0029] The CPE (Common Product Enumeration) information of the vulnerability is used to determine the product library affected by the vulnerability, and the corresponding relationship between the product and the manufacturer is established based on the product in the product library, the corresponding manufacturer library is established, the corresponding relationship between the product and the specific industry is established, and the industry library of the related product is established.

[0030] The characteristic information of the software can be determined based on the statistical results in the product library, the manufacturer library and the industry library, so as to ensure the comprehensiveness of the determination of the characteristic information of the software.

[0031] In an example embodiment, the hazard level is determined according to the geographic location of the terminal running the software.

[0032] The IP address of the terminal installed with the software can be determined based on the statistical results in the product library, the manufacturer library and the industry library, the corresponding relationship between the IP address and the specific product is established, the IP library of the product is constructed, the geographic location library of the IP address is established by associating the IP address with the region, and the geographic location library of the IP address is established.

[0033] According to the terminal installed with the software, the geographical region of the software installation can be determined, thereby determining the influence region of the vulnerability and the hazard level information.

[0034] In an example embodiment, the characteristic information of the vulnerability includes at least one of POC (Proof of Concept), EXP (Exploit), malicious code, vulnerability patch, product with the vulnerability, and vulnerability source.

[0035] In an example embodiment, the security risk of the vulnerability is evaluated according to the characteristic information of the software and the characteristic information of the vulnerability obtained in advance, including:

[0036] The security risk of each characteristic information of the software and the vulnerability is evaluated respectively, and a score result of each characteristic information is obtained.

[0037] The score result of each characteristic information and the weight of each characteristic information set in advance are used to calculate the score result of all characteristic information, and the security risk information of the vulnerability is obtained.

[0038] Taking the weight shown in Table 1 as an example, after obtaining the score result of each characteristic, the score result of each characteristic information is multiplied by the respective weight, and the multiplication result of each characteristic information is accumulated, and the score result of all characteristic information can be obtained.

[0039]

[0040]

[0041] Table 1

[0042] In Table 1, the weight of each characteristic information can be determined according to the importance of each characteristic information itself, and the setting of the above weight can be set according to experience.

[0043] In an example embodiment, the weight of each characteristic information is obtained by the following method, including:

[0044] Obtain the score parameter required for evaluating each characteristic information;

[0045] Periodically detect the change information of each score parameter of each characteristic information, and set the weight of the characteristic information according to the change information of each score parameter.

[0046] The evaluation parameters used to evaluate the feature information are patch source, patch execution timeliness, and patch security. When the values of the evaluation parameters change, the importance of the evaluation parameters is affected. Therefore, the weight of the feature information is automatically adjusted by obtaining the change information of the evaluation parameters.

[0047] In an example embodiment, the weight of each feature information is obtained by including the following steps:

[0048] Periodically obtaining importance level information of each weight;

[0049] According to the result obtained by the periodic obtaining operation, determine the change information of the importance level of each weight;

[0050] According to the change information of the importance level of each weight, set the weight of each feature information.

[0051] If the importance level of a feature information in the result of the periodic obtaining operation is increased, the weight of the feature information is increased; otherwise, if the importance level of a feature information in the result of the periodic obtaining operation is decreased, the weight of the feature information is decreased.

[0052] For example, the importance level of the weight shown in Table 2. In Table 2, the greater the value of the importance level, the higher the importance of the weight; otherwise, the lower the value of the importance level, the lower the importance of the weight.

[0053] Serial number Feature information Weight Importance level 1 Vulnerability POC 3 1.5 2 Vulnerability EXP 2 2 3 Vulnerability used by malicious code 1 0.5 4 Vulnerability patch 2 1 5 Affected product range 2 1.5 6 Vulnerability source 2 2 7 Importance degree 2 2 8 Usage rate 3 1 9 Harm level 2 1

[0054] Table 2

[0055] By dynamically adjusting the weight of the feature information, it is ensured that the set weight conforms to the actual operation of the current vulnerability, and the accuracy of the evaluation result is ensured.

[0056] In an example embodiment, the periodic obtaining of the importance level information of each weight includes:

[0057] Periodically obtaining the score result of each feature information;

[0058] Determine the change information of the score result of the same feature information in the adjacent period;

[0059] According to the change information of the score result of the same feature information, determine the importance level information of each weight.

[0060] By determining the change information of the score results of the same feature information in adjacent periods, a plurality of feature information whose score results have obvious changes can be determined, according to two change directions of positive increasing and negative decreasing, the values recorded in the change information are sorted in descending order, and the first n feature information in each change direction is obtained, and the weight of the first n feature information in each change direction is adjusted, where n is an integer greater than or equal to 1.

[0061] The adjustment range can be determined according to the values recorded in the change information. The adjustment percentage of the weight corresponding to different ranges of the values can be recorded in advance, and the actual adjustment percentage of the weight is determined according to the corresponding relationship.

[0062] A storage medium, the storage medium has a computer program stored therein, wherein the computer program is configured to execute the method described above when running.

[0063] An electronic device, comprising a memory and a processor, the memory has a computer program stored therein, and the processor is configured to execute the computer program to execute the method described above.

[0064] Those of ordinary skill in the art will realize and understand that all or some of the steps in the methods disclosed above and the functional modules / units in the systems and devices can be implemented as software, firmware, hardware, and appropriate combinations thereof. In hardware implementation, the division between the functional modules / units mentioned in the above description does not necessarily correspond to the division of physical components; for example, one physical component can have multiple functions, or one function or step can be performed by several physical components in cooperation. Some or all of the components can be implemented as software executed by a processor, such as a digital signal processor or a microprocessor, or as hardware, or as an integrated circuit, such as an application-specific integrated circuit. Such software can be distributed on computer-readable media, which can include computer storage media (or non-transitory media) and communication media (or transitory media). As is well known to those of ordinary skill in the art, the term computer storage media includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storage of information such as computer readable instructions, data structures, program modules or other data. Computer storage media includes, but is not limited to, RAM, ROM, EEPROM, flash memory or other memory technology, CD-ROM, digital versatile disks (DVD) or other optical disk storage, magnetic cassettes, magnetic tapes, magnetic disk storage or other magnetic storage devices, or any other medium which can be used to store the desired information and which can be accessed by a computer. Furthermore, it is common and well understood by those of ordinary skill in the art that communication media typically embodies computer readable instructions, data structures, program modules or other data in a modulated data signal such as a carrier wave or other transport mechanism and can include any information delivery media.

Claims

1. A method of assessing security risk of a vulnerability, characterized by, The application relates to a method for evaluating a target vulnerability, and a computer device and a storage medium. In the evaluation of the target vulnerability, software in which the target vulnerability exists is acquired; Characteristic information of the software in the process of running in an operating system is acquired; According to the characteristic information of the software and the characteristic information of the vulnerability acquired in advance, the security risk of the vulnerability is evaluated; The evaluation of the security risk of the vulnerability according to the characteristic information of the software and the characteristic information of the vulnerability acquired in advance comprises: The security risk of each characteristic information in the characteristic information of the software and the characteristic information of the vulnerability is evaluated respectively to obtain a scoring result of each characteristic information; The scoring result of each characteristic information and the weight of each characteristic information set in advance are used to calculate the scoring result of all the characteristic information, and the security risk information of the vulnerability is obtained; The determination of the weight adjusted in each period comprises: The scoring result of each characteristic information is acquired periodically; The change information of the scoring result of the same characteristic information in adjacent periods is determined; According to the two change directions of positive increase and reverse decrease, the values recorded in the change information are sorted in descending order, the first n characteristic information in each change direction is obtained, and the weight of the first n characteristic information in each change direction is adjusted, wherein n is an integer greater than or equal to 1.

2. The method of claim 1, wherein, The characteristic information of the software comprises at least one of importance level information, usage rate and damage level of the software in the operating system.

3. The method of claim 2, wherein, The damage level is determined according to the geographical position of a terminal running the software.

4. The method of claim 1, wherein, The characteristic information of the vulnerability comprises at least one of a technical verification POC, a vulnerability exploitation EXP, malicious code, a vulnerability patch, a product in which the vulnerability exists and a vulnerability source.

5. A storage medium, characterized by The storage medium stores a computer program, wherein the computer program is set to execute the method in any one of claims 1 to 4 when running. 6.An electronic device comprising a memory and a processor, the electronic device comprising: The storage medium stores a computer program, wherein the computer program is set to execute the method in any one of claims 1 to 4 when running.

Citation Information

Patent Citations

  • Software running security measurement and estimation method based on network environment

    CN102799822A