A crowdsourcing collaborative sharing anti-disclosure system and method for undisclosed vulnerabilities
By adopting a anti-leakage system with dynamic token management, blockchain storage, internal leakage prevention and trust distinction modules in the group intelligence collaborative sharing environment, the problem of undisclosed vulnerability leakage is solved, and the secure sharing and leakage traceability of undisclosed vulnerability information is realized, reducing the risk of system downtime and information leakage.
Patent Information
- Application Number
- CN202210230968.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-03-10
- Publication Date
- 2025-06-17
- Estimated Expiration
- 2042-03-10
AI Technical Summary
It is difficult for existing technology to effectively prevent the leakage of undisclosed vulnerabilities, especially in the collective intelligence collaborative sharing environment. The lack of effective mitigation measures will lead to undisclosed vulnerabilities being easily exploited by attackers, causing system downtime or information leakage.
A group intelligence collaborative sharing anti-leakage system is adopted, including a dynamic token management module, a blockchain-assisted continuous log storage module, an internal leakage prevention module with single-step traceability, and a trust-based security collaborator distinction module. Through these modules, secure sharing and leakage traceability of undisclosed vulnerability information is realized.
Effectively resist malicious leakage, trace the leaker, prevent further dissemination of leaked information, ensure that the undisclosed vulnerable information flows under the principle of least permissions, and reduce the risk of system downtime and information leakage.
Smart Images

Figure CN115118422B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of network security, and particularly relates to a crowdsourcing collaborative sharing anti-disclosure system and method for undisclosed vulnerabilities. Background Art
[0002] In recent years, emerging threats in the cyber space have shown more complex and concealed characteristics, and their highly lethal attack methods endanger the interests of individuals, organizations and even governments. Security defense means relying on the single emergency response ability of victims are a drop in the bucket, while the emergence of threat information sharing and interaction mechanisms provides new ideas for network security emergency response. As one of the most intractable emerging threats, undisclosed vulnerabilities have become exploitable tools favored by attackers due to the lack of effective mitigation measures. Large-scale attacks triggered by undisclosed vulnerabilities emerge in an endless stream, such as APT attacks, phishing attacks, ransomware attacks, supply chain attacks, etc., seriously endangering system operation and even causing key information leakage.
[0003] In particular, as the real economy, which is the lifeblood of the national economy, the manufacturing industry is actively responding to the call for digital industrial upgrading. To achieve digital transformation, a large number of intelligent devices are connected to the original industrial system to provide real-time perception data for the decision-making center to achieve intelligent production. However, due to the lack of necessary security protection for most of the widely distributed intelligent devices, potential undisclosed vulnerabilities are easily discovered and exploited by attackers.
[0004] Inviting external security workers to participate has become a more popular collaborative emergency response mode. By integrating crowdsourcing resources to help organizations judge the security threats they face, and accordingly formulate proactive defense plans, maximizing the value of vulnerability information, reducing information collection costs and improving the information silo problem, thereby improving the overall security response ability. To achieve a virtuous cycle of crowdsourcing collaborative sharing of undisclosed vulnerabilities, it is necessary to ensure that all crowdsourcing collaborators are honest. However, in practice, this premise often cannot be effectively guaranteed, and the leakage of undisclosed vulnerability information caused by any dishonest behavior is likely to lead to large-scale malicious exploitation of undisclosed vulnerabilities. More seriously, due to the lack of effective mitigation measures, the exploitation of undisclosed vulnerabilities will cause long-term system downtime or information leakage.
[0005] Currently, the following main problems exist in this field:
[0006] When information systems respond to undisclosed vulnerabilities, they will face some technical problems, such as:
[0007] 1) Due to the lack of effective mitigation measures, undisclosed vulnerabilities are often fatal to private network scenarios with closed-loop ecosystems such as industrial control, power, medical, and finance. Once large-scale exploitation occurs, it will lead to the leakage of enterprise privacy information and the long-term suspension of system services.
[0008] 2) Existing work only provides some guiding principles for the coordinated disclosure of undisclosed vulnerabilities, and there is no specific coordinated sharing model for undisclosed vulnerabilities. The effect of coordinated sharing of undisclosed vulnerabilities may be difficult to guarantee.
[0009] 3) Due to the lack of effective mitigation measures for undisclosed vulnerabilities, any leakage of undisclosed vulnerabilities caused by dishonest collaborators will lead to the failure of the entire coordinated sharing process.
[0010] In view of this, it is necessary to adopt an information sharing model for undisclosed vulnerabilities with anti-leakage effects to actively promote the flow of undisclosed vulnerabilities and reduce security threats as soon as possible. Summary of the Invention
[0011] To overcome the deficiencies of the above-mentioned prior art, the purpose of the present invention is to provide a crowdsourcing collaborative sharing anti-leakage system and method for undisclosed vulnerabilities, which has the characteristics of resisting malicious leakage behavior and tracing the leaker.
[0012] To achieve the above purpose, the technical solution adopted by the present invention is: a crowdsourcing collaborative sharing anti-leakage system for undisclosed vulnerabilities, including a dynamic token management module, a blockchain-assisted continuous log storage module, an internal leakage prevention module with single-step tracing, and a trusted security collaborator differentiation module;
[0013] The dynamic token management module serves as an implicit access credential and tracing evidence for collaborators. The dynamic token management module can be generally divided into two stages: token generation and token update;
[0014] The blockchain-assisted continuous log storage module includes a block body and a block header. Different from the traditional blockchain structure, in addition to the forward hash, timestamp, Merkle root, and block ID, the following new block elements are integrated into the block header:
[0015] SC i : The identity identifier of the security collaborators participating in the crowdsourcing collaborative sharing. The security collaborators are enthusiastic about requesting access to undisclosed vulnerability information to help the compromised system quickly formulate mitigation measures;
[0016] Tr i : The trust value of the security collaborator;
[0017] In the block header, Tr i can be quickly retrieved by a trusted authorization agency;
[0018] Vul meta : The meta-information of the undisclosed vulnerability, used to record the key information that has not been disclosed;
[0019] In the block body, the log data of the security collaborator is hashed to generate a Merkle tree;
[0020] R[i]: Request record of the security collaborator accessing the undisclosed vulnerability;
[0021] F false : Flag indicating whether to release false information for the purpose of entrapping conspirators.
[0022] The described internal leakage prevention module prevents the security collaborator from leaking the undisclosed vulnerability information of the request. The undisclosed vulnerability is immediately destroyed when leaving the predetermined access environment, and has a benign logic bomb code with self-triggering logic preleak , the benign logic bomb code preleak Consists of a trigger module and a payload responsible for making a response; the trigger condition is designed to detect the difference between the access environments of honest and dishonest security collaborators; once the trigger condition is met, the payload will immediately trigger to destroy the undisclosed vulnerability information in the leakage environment.
[0023] The described token generation and token update specifically include the following steps:
[0024] Step 1, for each security collaborator, the trusted authorization agency generates a token through a hash function access , each access token token generated by the trusted authorization agency access Will be stored on the blockchain;
[0025] Step 2, when a security collaborator requests access to an undisclosed vulnerability, the trusted authorization agency retrieves the corresponding historical access token token of the security collaborator on the blockchain access , if it hits, the access token token access Is associated with the security collaborator, and a new access token is generated at the end of the access. The subsequent update of the access token token access Is stored on the blockchain. If the hit is unsuccessful, the newly generated access token token access Will be associated with the security collaborator and stored on the blockchain;
[0026] Step 3, when the trusted authorization agency receives an access request, the access token token access Is recycled by the trusted authorization agency. At this time, the trusted authorization agency generates a traceable token token according to the target access environment mac current And the recycled access token token access And embeds it into the undisclosed vulnerability information requested to be accessed; the traceable token token tracing Is generated in the following way: token tracing Generated by: tokentracin ←H(mac current ||token access ), and at the same time, the trusted authorization agency will generate a new access token token access , and store it on the blockchain.
[0027] The continuous log data of the security collaborator contains the following elements:
[0028] (sec i(old) ,lek i(old) ): is the historical trust data of the security collaborator, which is used to evaluate the trust value of the security collaborator before accessing the undisclosed vulnerability;
[0029] (sec i(new) ,lek i(new) ): is the current trust data of the security collaborator, which is used to update the trust value of the security collaborator after accessing the undisclosed vulnerability information.
[0030] The benign logic bomb code preleak specifically includes: a self-check module and a self-destruction module.
[0031] For the self-check module mentioned above, once the undisclosed vulnerability information enters the access environment of the security collaborator, the benign logic bomb code preleak will extract the current access environment of the security collaborator, that is, the MAC address and the access token token access to calculate the verification value V c , and the verification value V c can be calculated as: V c ←token tracing ==H(token access ,mac current );
[0032] For the self-destruction module mentioned above, if the verification value V c = 0, the leakage behavior has not occurred, and the undisclosed vulnerability information has not left the predetermined access environment, and the payload will continue to be in a dormant state; if the verification value V c = 1, the leakage behavior may have occurred, and the undisclosed vulnerability information has left the predetermined access environment; in this case, the payload will be immediately activated to destroy the undisclosed vulnerability; at the same time, the self-destruction module will actively send encrypted feedback information to the trusted authorization agency, e f = {token access ,vul j ,SC i ,mac current ,tp}.
[0033] The described trust-based secure collaborator differentiation module evaluates the trust value of a secure collaborator based on their historical behavior. Using the trust value, honest and dishonest collaborators can be distinguished. For semi-honest collaborators, their trustworthiness is judged based on whether they have conspirators, and different collaborators will be granted different access rights to undisclosed vulnerabilities.
[0034] For the described secure collaborators, during the sharing process of undisclosed vulnerability information, the behavior patterns of secure collaborators can be generalized into two types: always maintaining confidentiality and leaking undisclosed vulnerabilities. Using the trust mechanism, if a secure collaborator frequently leaks undisclosed vulnerability information, they will obtain a lower trust value.
[0035] For the described behavior patterns, to quantify these behavior patterns, first count the number of times a secure collaborator maintains confidentiality and the number of leakage behaviors; sec i and leak i represent the number of times of maintaining confidentiality and leakage behaviors respectively. Considering that the trust value should be mapped to the range [0, 1], the trust value BT of the secure collaborator i can be evaluated as:
[0036]
[0037] And introduce a penalty factor to make the trust value of the secure collaborator respond significantly to leakage behaviors. The introduced penalty factor can be calculated as:
[0038]
[0039] In the formula, sec i and leak i represent the number of times of maintaining confidentiality and leaking undisclosed vulnerability information respectively. The exponential operation with base e can quickly make the penalty factor P i decay.
[0040] The final trust value Tr of the collaborator i can be evaluated as:
[0041]
[0042] In the formula, BT i is the basic trust value of the secure collaborator SC i , sec i and leak i represent the number of times of maintaining confidentiality and leaking undisclosed vulnerability information respectively. The exponential operation part with base e is the penalty factor P i ,
[0043] Secure collaborators are based on different trust thresholds (σ h , σ l) are classified as honest, semi - honest and dishonest.
[0044] The described trust threshold (σ h , σ l ), and its classification rule is:
[0045] R1, for Tr i ≥σ h , the request of the secure collaborator for the undisclosed vulnerability will be accepted by the trusted authorization agency. In this case, the secure collaborator is considered honest;
[0046] R2, for Tr i <σ l , the request of the secure collaborator for the undisclosed vulnerability will be rejected by the trusted authorization center. In this case, the secure collaborator is considered dishonest;
[0047] R3, for σ l ≤Tr i <σ h , in this case, it is difficult to classify the secure collaborator as honest or dishonest, and is considered semi - honest waiting for further detection;
[0048] To further evaluate the semi - honest secure collaborator, according to whether it has conspirators, μ i is defined as the number of conspirators owned by the secure collaborator. If μ i = 0, it means it has no conspirators, and the secure collaborator can be temporarily considered honest. If μ i ≥1, then the secure collaborator may have a considerable number of conspirators and is thus rejected from joining the candidate sharing process;
[0049] If the secure collaborator is determined to be semi - honest, when the conspirator entrapment releases false undisclosed vulnerability information when the suspected secure collaborator requests access to the undisclosed vulnerability again, and ensures that the embedded benign logic bomb code preleak will not damage the leaked information. According to the information fed back to the trusted authorization center each time the benign logic bomb code preleak is triggered, judge whether there is a possibility of secondary leakage. Once the conspirator is entrapped, the suspected secure collaborator will be regarded as dishonest.
[0050] The described crowdsourcing collaborative sharing anti - leakage system for undisclosed vulnerabilities further includes a trusted authorization agency and secure collaborators.
[0051] A crowdsourcing collaborative sharing anti - leakage method for undisclosed vulnerabilities includes the following steps:
[0052] Step 1, when the crowdsourcing collaborative sharing anti - leakage system is initialized, each secure collaborator SC participating in the collaborative sharing iOne needs to present their identity credentials to a trusted authorization agency first. The trusted authorization agency grants corresponding access permissions to the Secure Collaborator (SC) based on whether the SC i is in the collaboration pool. The trusted authorization agency generates an access token i for each verified Secure Collaborator (SC). i The Secure Collaborator (SC) access cannot obtain any information about the access token i . The generated access token access will be securely stored on the blockchain; access
[0053] Step 2: When a Secure Collaborator (SC) i initiates a sharing request to the trusted authorization agency, the trusted authorization agency retrieves the SC's i token access from the blockchain. If a hit occurs, the access token access is associated with the Secure Collaborator (SC) i , and the request response of the Secure Collaborator (SC) i is returned. If no hit occurs, a new access token access is generated and forms a continuous access log storage chain with the SC's i historical access tokens access .
[0054] Step 3: When the trusted authorization agency receives an access request from a Secure Collaborator (SC) i , the access token access will be immediately recycled. The trusted authorization agency generates a traceable token current based on the target access environment mac access and the recycled access token tracing , and embeds it into the undisclosed vulnerability information being requested for access. The traceable token tracing is generated in the following way: token tracing ←H(mac current ||token access ). Meanwhile, the trusted authorization agency stores the newly generated traceable token tracing on the blockchain;
[0055] Step 4: When a suspicious Secure Collaborator (SC) i accesses the undisclosed vulnerability information in a permitted access environment, the benign logic bomb code preleak Still in the dormant state, the trusted authorization agency will generate corresponding suspicious security collaborators SC i Historical access records. Once the suspicious security collaborator SC i The access environment is different from the permitted access environment, and the benign logic bomb code in the single-step internal leakage prevention module preleak Will be immediately activated, run the self-destruction module to destroy the undisclosed vulnerability information. When destroying the leaked undisclosed vulnerability information, the feedback information will also be immediately sent to the trusted authorization agency. The feedback information exists in encrypted form, e f ={token access ,vul j ,SC i ,mac current ,tp} contains the leakage location and the identity information of the leaker;
[0056] Step 5, after receiving the feedback information from the leaker, the trusted authorization agency will immediately impose a penalty on the trust value of the target leaker and reject any sharing requests from the target leaker. For the suspicious security collaborator SC i in the middle of the trust range, when the suspicious security collaborator SC i sends a sharing request again, the trusted authorization agency returns false undisclosed vulnerability information. Once the suspicious security collaborator SC i leaks the false information to any third party, the suspicious security collaborator SC i will be considered dishonest by the trusted authorization agency and will be refused continued service.
[0057] The beneficial effects of the present invention are:
[0058] The difference between the anti-leakage method for collaborative sharing of undisclosed vulnerability groups in the present invention and the prior art lies in:
[0059] 1) The present invention designs an anti-leakage method for collaborative sharing of undisclosed vulnerability information, which can not only effectively trace the information leaker, but also prevent the further spread of the leaked information.
[0060] 2) The present invention designs a dynamic token with a complete life cycle. This dynamic token, as an implicit access credential for security collaborators to participate in sharing, is only held by the system and is embedded into the undisclosed vulnerability information by the system as evidence for tracing the leaker.
[0061] 3) The present invention designs a blockchain-assisted continuous log storage method. By virtue of the anti-tampering feature of the blockchain, it stores the initial dynamic token and its subsequent updates, the access records of collaborators, and the meta-information Vul meta of the undisclosed vulnerability, achieving transparent information sharing.
[0062] 4) The present invention provides an internal leakage prevention method with single-step traceability characteristics. This method is based on the design concept of a benign logic bomb, compares the dynamic token generated based on access environment information with the dynamic token embedded in the undisclosed vulnerability information, and selects whether to trigger the logic bomb to destroy the undisclosed vulnerability information.
[0063] 5) The present invention introduces a trust mechanism to distinguish different collaborator identities according to the historical behaviors of the collaborators. For semi-honest collaborators who are difficult to judge, false undisclosed vulnerability information is released to trap their potential accomplices.
[0064] The advantages of the present invention are as follows:
[0065] 1) The present invention provides a crowdsourcing collaboration paradigm for undisclosed vulnerabilities with anti-leakage characteristics.
[0066] 2) In the present invention, by introducing a dynamic token with a complete life cycle, it is ensured that the access of secure collaborators to undisclosed vulnerabilities is always under system control, and at the same time, as a hidden trace clue, it is embedded in the undisclosed vulnerabilities to ensure the traceability reliability of the leakers.
[0067] 3) The present invention designs an internal leakage prevention method with single-step traceability characteristics. By introducing a self-triggering benign logic bomb code preleak , the single-step internal leakage prevention method can quickly respond to abnormal access environments, and while reliably tracing the leakers, it realizes the end destruction of the leaked information.
[0068] 4) The present invention utilizes blockchain to assist in realizing continuous access log storage, designs a block structure to record access information, trust data, and dynamic token records, and ensures the security of the key data for the normal operation of the system.
[0069] 5) The present invention evaluates the trustworthiness of collaborators according to the historical behavior patterns of secure collaborators, and divides the roles of secure collaborators according to the degree of trust. For secure collaborators with medium trust levels, false undisclosed vulnerability information is released to induce them to perform unauthorized behaviors, and further trap the conspirators of the secure collaborators.
[0070] The application features of the present invention:
[0071] Through research and analysis of a large number of relevant domestic and foreign literatures, there are few studies on the sharing method of undisclosed vulnerability information with anti-disclosure characteristics, and most of them exist in the form of policies. Although policy guidelines provide guidance for collaborative disclosure of vulnerabilities, the premise for the correct implementation of these policies is to assume that all collaborators are honest. For the situation of undisclosed vulnerability information leakage caused by malicious collaborators, policy guidelines cannot provide any effective preventive measures. In addition, in complex application scenarios, the collaborative sharing of undisclosed vulnerabilities often involves the interests of multiple parties, and vulnerability disclosure policies cannot provide guidance for multi-party collaborative sharing.
[0072] The present invention provides a good environment with anti-disclosure characteristics for collaborative sharing of undisclosed vulnerabilities by using dynamic tokens and the single-step traceability leakage method. As a typical application in a private network environment, the industrial Internet of Things involves a large number of terminal devices. The limited security defense capabilities of terminal devices have become an advantage for attackers. By exploiting undisclosed vulnerabilities on vulnerable terminals, a large number of terminal devices will become accomplices for attackers to launch attacks. Through the use of crowdsourcing collaborative sharing of undisclosed vulnerabilities, a large number of authorized collaborators can access undisclosed vulnerabilities to help victims actively develop mitigation measures and quickly establish a defense system. The present invention can be applied to multiple private network scenarios, such as energy, logistics, manufacturing, and transportation. Taking the manufacturing industry of the industrial Internet of Things as an example, once the target manufacturer reports a new undisclosed vulnerability in the collaborative sharing process, it can select multiple security collaborators to join the collaborative sharing mitigation. The trusted authorization center will assign tokens access to each security collaborator joining the collaborative environment and store them on the blockchain. Without implicit access credentials, security collaborators will have no permission to access undisclosed vulnerability information. Security collaborators with access credentials can access the target undisclosed vulnerability information only under the condition of high trust, enabling the undisclosed vulnerability information to flow only under the principle of least privilege and avoiding leakage problems caused by dishonest security collaborators in advance.
[0073] Among them, the meta-information of undisclosed vulnerabilities and access records related to security collaborators are also stored on the blockchain, making the records of collaborative access to undisclosed vulnerabilities have the characteristics of being tamper-proof. After the access request is accepted by the authorization center, the traceable token tracing and code preleak will be embedded in the undisclosed vulnerability information in a concealed form. Once the undisclosed vulnerability information leaves the target access environment, code preleak will immediately activate its destructive payload to destroy the undisclosed vulnerability information and actively report the traceable evidence, the traceable token tracing , thereby preventing the leakage of undisclosed vulnerability information at the end and avoiding large-scale damage to the target manufacturer caused by the leakage of undisclosed vulnerability information. After formulating effective mitigation measures, the target manufacturer can decide whether to disclose the undisclosed vulnerability information.
[0074] In summary, the leakage prevention solution designed by the present invention has good flexibility and robustness, which is conducive to establishing a collaborative sharing environment for undisclosed vulnerability information with anti-leakage characteristics and promoting the collaborative mitigation of the harm caused by undisclosed vulnerabilities. BRIEF DESCRIPTION OF THE DRAWINGS
[0075] Figure 1 It is a schematic block diagram of the principle of the anti-leakage system for crowdsourced collaborative sharing of undisclosed vulnerability groups of the present invention.
[0076] Figure 2 It is a flow chart of the complete life cycle of the dynamic token of the present invention.
[0077] Figure 3 It is a schematic diagram of the block structure of the continuous log storage of the present invention.
[0078] Figure 4 It is the Code of the present invention preleak Functional structure diagram.
[0079] Figure 5 It is a flow chart of the method of the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0080] The present invention will be further described in detail below with reference to specific embodiments and the accompanying drawings.
[0081] The present invention uses a dynamic token to propose a crowdsourced collaborative sharing anti-leakage method for undisclosed vulnerabilities to suppress the leakage behavior of undisclosed vulnerabilities until mitigation measures are available; the implementation of the crowdsourced collaborative sharing anti-leakage method for undisclosed vulnerabilities includes four collaborative modules: dynamic token management, blockchain-assisted continuous log storage, internal leakage prevention with single-step traceability, and trusted-based secure collaborator differentiation.
[0082] Figure 1 It depicts the overall architecture of the crowdsourced collaborative sharing anti-leakage method for undisclosed vulnerabilities, which involves the following entities:
[0083] Trusted Authority (TA): The trusted authority is responsible for processing access requests from collaborators, generating and updating dynamic tokens, and evaluating the trust values of collaborators.
[0084] Security Coordinator (SC): A security worker invited to join the sharing process, who has the right to access the undisclosed vulnerability information in the sharing process and contributes their professional skills to help the victim formulate mitigation measures as soon as possible. The collaborative workers can be described as three types: 1) honest collaborative workers who will not act without authorization; 2) suspicious security collaborative workers who have the opportunity to conduct unauthorized acts; 3) dishonest collaborative workers who often disclose undisclosed vulnerability information.
[0085] Undisclosed vulnerability information: The undisclosed vulnerability information reported by the discoverer will actively flow among authorized collaborative workers, and the collaborative workers contribute their professional skills to help the compromised system quickly establish targeted defense methods.
[0086] · Dynamic token management module
[0087] Introduce a dynamic token management module as the implicit access credential and traceability evidence for collaborative workers. The dynamic token management can be generally divided into two stages: token generation and token update process.
[0088] Token generation: When a collaborative worker submits a new undisclosed vulnerability, each internal collaborative worker participating in the sharing will be granted a corresponding access token, which is called the access token token access , and this access token is only held by a trusted authorization agency and cannot be obtained outside the system. The trusted authorization center generates the access token token through a hash function access . It is obtained through the following calculation method: token access ←H(SC i ||vul meta ||tp||nonce), where vul meta is the original information of the undisclosed vulnerability, tp is the timestamp for generating this token, and nonce is a one-time random number. Even if a security collaborative worker obtains the access permission to participate in collaborative sharing, a security collaborative worker without holding the access token token access still has no right to access the undisclosed vulnerability information. The specific steps for generating and updating the token are as follows:
[0089] Step 1. For each security collaborative worker, the trusted authorization center generates an access token token through a hash function access , and each access token token access generated by the system will be stored on the blockchain.
[0090] Step 2. When a security collaborative worker requests access to an undisclosed vulnerability, the system will retrieve the corresponding historical access token token of the security collaborative worker on the blockchainaccess ; If a hit occurs, the newly generated access token access is associated with the security collaborator and a new access token is generated at the end of the access. The subsequent updates of the access token access are stored on the blockchain; if the hit is not successful, the newly generated access token access is associated with the security collaborator and stored on the blockchain;
[0091] Step 3, when the trusted authorization agency receives an access request, the access token access will be recycled by the system. At this time, the trusted authorization agency generates a traceable token current based on the target access environment mac access and the recycled access token tracing , and embeds it into the undisclosed vulnerability information requested for access; the traceable token tracing is generated in the following way: token tracin ←H(mac current ||token access ). Meanwhile, the trusted authorization agency generates a new access token access and stores it on the blockchain.
[0092] To avoid malicious inference of the access token access , a one-time fresh random number is introduced to make the access token access dynamic. At the end of the security collaborator's access to the undisclosed vulnerability, the access token access will be updated; the update calculation is as follows: token access ←H(SC i ||vul meta ||tp||nonce’); in this scheme, the traceable token tracing will be embedded into the requested undisclosed vulnerability information in a concealed manner as evidence to trace the leaker.
[0093] · Blockchain-assisted continuous log storage module
[0094] To prevent attackers from tampering with the generated dynamic token, access records, and the trusted data of the security collaborator, the continuous behavior records of the security collaborator composed of these information should be securely stored on the blockchain. In the blockchain, the block structure in the blockchain-assisted continuous log storage module is as Figure 3 shown:
[0095] The block header is slightly different from the traditional blockchain structure, in addition to the forward hash, timestamp, Merkle root, and block ID. Some new block elements are integrated into the block header:
[0096] SC i : The identity identifier of the security collaborator, who is keen on requesting access to undisclosed vulnerability information to help the compromised system quickly formulate mitigation measures.
[0097] Tr i : The trust value of the security collaborator. In the block header, Tr i can be quickly retrieved by a trusted authorization agency.
[0098] Vul meta : Undisclosed vulnerability meta-information, used to record key undisclosed information.
[0099] In the block body, the log data of the security collaborator generates a Merkle tree after hashing. In addition to token access and token tracing , the continuous log data of the security collaborator contains the following elements:
[0100] (sec i(old) ,lek i(old) ): The historical trust data of the security collaborator, used to evaluate the trust value of the security collaborator before accessing the undisclosed vulnerability.
[0101] (sec i(new) ,lek i(new) ): The current trust data of the security collaborator, used to update the trust value of the security collaborator after accessing the undisclosed vulnerability information.
[0102] R[i]: The request record of the security collaborator accessing the undisclosed vulnerability.
[0103] F false : The flag indicating whether to release false information for the purpose of trapping conspirators.
[0104] · Single-step traceable internal leakage prevention
[0105] To prevent the security collaborator from leaking the requested undisclosed vulnerability information, the undisclosed vulnerability is immediately destroyed when it leaves the predetermined access environment; therefore, a benign logic bomb with self-triggering logic is designed, called code preleak , code preleak consists of a trigger module and a payload responsible for making a response; the trigger condition is designed to detect the difference between the access environments of honest and dishonest security collaborators; once the trigger condition is met, the payload will immediately trigger to destroy the undisclosed vulnerability information in the leakage environment. Such asFigure 4 As shown is the code preleak function structure diagram.
[0106] Self-check module: Once the undisclosed vulnerability information enters the access environment of the security collaborator, the code preleak will extract the current access environment of the security collaborator, that is, the MAC address and the token access to calculate the verification value V c , the verification value V c can be calculated as: V c ←token tracing ==H(token access , mac current )?
[0107] Self-destruction module: If the verification value V c = 0, the leakage behavior has not occurred, the undisclosed vulnerability information has not left the predetermined access environment, and the protection payload will continue to be in a dormant state. If the verification value V c = 1, the leakage behavior may have occurred, and the undisclosed vulnerability information has left the predetermined access environment. In this case, the protection payload will be immediately activated to destroy the undisclosed vulnerability. At the same time, the self-destruction module will actively send encrypted feedback information to the trusted authorization center, e f = {token access , vul j , SC i , mac current , tp}
[0108] · Trust-based security collaborator partitioning
[0109] Evaluate the trust value of the security collaborator based on its historical behavior, and use the trust value to achieve the partitioning of honest collaborators and dishonest collaborators; for semi-honest collaborators, judge their trustworthiness according to whether they have conspirators, and different collaborators will obtain different access rights to the undisclosed vulnerabilities.
[0110] During the sharing process of undisclosed vulnerability information, the behavior patterns of security collaborators can be generalized into two types: always maintaining confidentiality and leaking undisclosed vulnerabilities; using the trust mechanism, if a security collaborator often leaks undisclosed vulnerability information, he will obtain a lower trust value.
[0111] To quantify these behavior patterns, first count the number of times of the behavior of maintaining confidentiality and the leakage behavior of the security collaborator; taking SC i as an example, sec i and leak i represent the number of times of maintaining confidentiality and the leakage behavior. Considering that the trust value should be mapped to the range of [0, 1], the trust value of the security collaborator BT iCan be evaluated as:
[0112]
[0113] And introduce a penalty factor P i So that the trust value BT of the security collaborator i Responds significantly to the leakage behavior. The introduced penalty factor P i Can be calculated as:
[0114]
[0115] The final trust value Tr of the security collaborator i Can be evaluated as:
[0116]
[0117] Security collaborators are classified as honest, semi - honest, and dishonest based on different trust thresholds (σ h , σ l ). The specific classification rules are as follows:
[0118] R1. For Tr i ≥σ h , the request of the security collaborator for undisclosed vulnerabilities will be accepted by the trusted authorization center. In this case, the security collaborator is considered honest;
[0119] R2. For Tr i <σ l , the request of the security collaborator for undisclosed vulnerabilities will be rejected by the trusted authorization center. In this case, the security collaborator is considered dishonest;
[0120] R3. For σ l ≤Tr i <σ h , in this case, it is difficult to classify the security collaborator as honest or dishonest and is considered semi - honest waiting for further detection;
[0121] To further evaluate semi - honest security collaborators, according to whether they have conspirators, define μ i As the number of conspirators owned by the security collaborator. If μ i = 0, it means it has no conspirators and the security collaborator can be temporarily considered honest. If μ i ≥1, then the security collaborator may have a considerable number of conspirators and is therefore rejected from joining the candidate sharing process;
[0122] If the secure collaborator is determined to be semi - honest, the conspirator trap will release false undisclosed vulnerability information when the secure collaborator requests access to the undisclosed vulnerability again, and ensure that the embedded benign logic bomb code preleak will not damage the leaked information. According to the information fed back to the trusted authorization center each time the benign logic bomb code preleak is triggered, judge whether there is a possibility of secondary leakage. Once the conspirator is trapped, the secure collaborator will be regarded as dishonest.
[0123] A crowdsourcing collaborative sharing anti - leakage method for undisclosed vulnerabilities, characterized by including the following steps:
[0124] Step 1, when initializing the crowdsourcing collaborative sharing anti - leakage system, each secure collaborator SC i first presents its identity credentials to the trusted authorization agency. The trusted authorization agency grants the secure collaborator SC i corresponding access rights according to whether the secure collaborator SC i is in the collaboration pool. The trusted authorization agency generates an access token token i for each verified secure collaborator SC access . The secure collaborator SC i cannot obtain any information about the access token token access . The generated access token token access will be securely stored on the blockchain;
[0125] Step 2, when a secure collaborator SC i initiates a sharing request to the trusted authorization agency, the trusted authorization agency will retrieve the access token token i of the secure collaborator SC access from the blockchain. If it hits, the access token token access will be associated with the secure collaborator SC i , and the request response of the secure collaborator SC i will be returned. If it does not hit, a new access token token access will be generated and form a continuous access log storage chain with the historical access token token i of the secure collaborator SC access ;
[0126] Step 3, when the trusted authorization agency receives the access request of the secure collaborator SC i , the access token token access is recycled. The trusted authorization agency determines according to the target access environment mac current and the recycled access token token accessGenerate a traceable token tracing and embed it into the undisclosed vulnerability information requested for access; the traceable token tracing is generated in the following way: token tracing ←H(mac current ||token access ). Meanwhile, the trusted authorization agency will generate a new traceable token tracing and store it on the blockchain;
[0127] Step 4, when a suspicious security collaborator SC i accesses the undisclosed vulnerability information in a licensed access environment, the benign logic bomb code preleak in the internal leakage prevention module is still in a dormant state. The trusted authorization agency generates a corresponding historical access record of the suspicious security collaborator SC i . Once the access environment of the suspicious security collaborator SC i differs from the licensed access environment, the benign logic bomb code preleak in the single-step internal leakage prevention module is activated to run the self-destruction module to destroy the undisclosed vulnerability information. When destroying the leaked undisclosed vulnerability information, feedback information is also sent to the trusted authorization agency. The feedback information exists in an encrypted form, e f ={token access , vul j , SC i , mac current , tp} containing the leakage location and the identity information of the leaker;
[0128] Step 5, after receiving the feedback information from the leaker, the trusted authorization agency imposes a penalty on the trust value of the target leaker and rejects any sharing requests from the target leaker. For a suspicious security collaborator SC i in the middle of the trust range, when the suspicious security collaborator SC i sends a sharing request again, the trusted authorization agency returns false undisclosed vulnerability information. Once the suspicious security collaborator SC i leaks the false information to any third party, the suspicious security collaborator SC i will be recognized as dishonest by the trusted authorization agency and will be refused continued service.
Claims
1. An intelligent collaborative sharing anti-disclosure system for undisclosed vulnerabilities, characterized in that including dynamic token management module, blockchain-assisted continuous log storage module, internal leakage prevention module with single-step traceability, trust-based secure collaborator differentiation module; The dynamic token management module serves as the implicit access credential and traceability evidence for collaborative workers, where the dynamic token management module is divided into two phases: token generation and token update; The blockchain-assisted continuous log storage module includes a block body and a block header. Different from the traditional blockchain structure, in addition to the forward hash, timestamp, Merkle root, and block ID, the following new block elements are integrated into the block header: SC i : Identity identifier of the security collaborator participating in crowdsourced collaborative sharing. The security collaborator requests access to undisclosed vulnerability information to help the compromised system quickly develop mitigation measures, where the parameter i represents the i number of the th security collaborator; Tr i : Trust value of the security collaborator; In the block header, Tr i can be quickly retrieved by a trusted authorization agency; Vul meta : Un-disclosed vulnerability meta information, used to record un-disclosed key information; In the block body, the log data of the security collaborators is hashed to generate a Merkle tree; R[i]: Request record of the security collaborator accessing the undisclosed vulnerability; F false : Whether to release a false information identifier for the purpose of entrapping conspirators; The internal leakage prevention module prevents the security collaborator from leaking the undisclosed vulnerability information of the request. The undisclosed vulnerability is immediately destroyed when leaving the predetermined access environment, and has a benign logic bomb with self-triggering logic code preleak , the benign logic bomb code preleak consists of a trigger module and a payload responsible for making a response; the trigger condition is designed to detect the difference between the access environments of honest and dishonest security collaborators; Once the triggering condition is met, the payload will immediately trigger to destroy the undisclosed vulnerability information in the leakage environment; The trust-based security collaborator discrimination module evaluates the trust value of the security collaborator based on their historical behavior, uses the trust value to divide honest and dishonest collaborators, and for semi-honest collaborators, judges their credibility according to whether they have conspirators. Different collaborators will obtain different access rights to the undisclosed vulnerability.
2. The intelligent collaborative sharing anti-disclosure system for undisclosed vulnerabilities according to claim 1, characterized in that The said token generating and token updating, specifically including the following steps: Step 1, for each security collaborator, the trusted authorization agency generates an access token through a hash function token access , and each access token generated by the trusted authorization agency token access will be stored on the blockchain; Step 2, when a security collaborator requests access to an undisclosed vulnerability, the trusted authorization agency retrieves the corresponding historical access token of the security collaborator on the blockchain token access , if a hit occurs, the access token token access is associated with the security collaborator and a new access token is generated at the end of the access token access , the subsequent updates of the access token token access are stored on the blockchain. If the hit is unsuccessful, the newly generated access token token access will be associated with the security collaborator and stored on the blockchain; Step 3, when the trusted authorization agency receives an access request, the access token token access is recycled. At this time, the trusted authorization agency generates a traceable token mac current according to the target access environment and the recycled access token token access and embeds it into the undisclosed vulnerability information requested to be accessed; the traceable token token tracing is generated in the following way: token tracing ← token tracing ← H ( mac current || token access ). At the same time, the trusted authorization agency generates a new access token token access and stores it on the blockchain.
3. The intelligent collaborative sharing anti-disclosure system for undisclosed vulnerabilities according to claim 1, characterized in that The continuous log data of the security collaborator includes the following elements: ( sec i(old) ,lek i(old) ): It is the historical trust data of the security collaborator's confidentiality and leakage behavior, which is used to evaluate the trust value of the security collaborator before accessing the undisclosed vulnerability. Among them, the parameter i represents the i number of the security collaborator; ( sec i(new) ,lek i(new) ): It is the current trust data of the security collaborator's confidentiality and leakage behavior, and is used to update the trust value of the security collaborator after accessing the undisclosed vulnerability information. Among them, the parameter i represents the i th security collaborator number.
4. The intelligent collaborative sharing anti-disclosure system for undisclosed vulnerabilities according to claim 1, characterized in that The described benign logic bomb code preleak Specifically, it includes: a self-check module and a self-destruction module.
5. The intelligent collaborative sharing anti-disclosure system for undisclosed vulnerabilities according to claim 4, characterized in that The self-check module, once un-disclosed vulnerability information enters the access environment of the security collaborator, a benign logic bomb code preleak will extract the current access environment of the security collaborator, i.e., the MAC address and the access token token access for calculating a check value V c , the check value V c is calculated as: V c ← token tracing ==H(token access ,mac current ) ; The self-destruction module, if the verification value V c = 0, the leakage behavior has not occurred, the undisclosed vulnerability information has not left the predetermined access environment, and the protection payload will continue to be in a dormant state; if the verification value V c = 1, the leakage behavior may have occurred, and the undisclosed vulnerability information has left the predetermined access environment; in this case, the protection payload will be immediately activated to destroy the undisclosed vulnerability; at the same time, the self-destruction module will actively send encrypted feedback information to the trusted authorization agency, e f = { token access , vul j , SC i , mac current , tp}, where tp is the timestamp for generating the feedback information.
6. The intelligent collaborative sharing anti-disclosure system for undisclosed vulnerabilities according to claim 1, characterized in that During the sharing process of the undisclosed vulnerability information, the behavior patterns of the security collaborator are generalized into two types: always maintaining confidentiality and leaking the undisclosed vulnerability; Using the trust mechanism, if a security collaborator often leaks the undisclosed vulnerability information, he will obtain a lower trust value.
7. The intelligent collaborative sharing anti-disclosure system for undisclosed vulnerabilities according to claim 6, characterized in that The behavior pattern is a quantitative behavior pattern. First, count the number of times the security collaborator maintains confidentiality and leaks; sec i and leak i represent the number of times of maintaining confidentiality and disclosure behavior respectively, where the parameter i indicates i the number of the BT i th security collaborator. Considering that the trust value should be mapped to the range of [0, 1], the basic trust value of the security collaborator ; And introduce a penalty factor P i So that the trust value of the security collaborator makes a significant response to the leakage behavior, the introduced penalty factor P i Can be calculated as: ; In the formula, sec i and leak i represent the number of times of maintaining confidentiality and acts of disclosure respectively. The exponential operation with base e can quickly make the penalty factor P i decay. Final collaborator trust value Tr i Can be evaluated as: ; Wherein, BT i is the basic trust value of the security collaborator SC i , sec i and leak i represent the number of times of maintaining confidentiality and leakage behavior, and the exponential operation part with e as the base is the penalty factor P i , Secure Collaborator SC i Based on different trust thresholds ( σ h , σ l ), they are classified as honest, semi - honest and dishonest.
8. A crowdsourcing collaborative sharing anti-disclosure system for undisclosed vulnerabilities according to claim 7, characterized in that, The trust threshold ( σ h , σ l ), and its discrimination rule is: R1, for Tr i ≥ σ h , requests from security collaborators for undisclosed vulnerabilities will be accepted by the trusted authorization agency, and in this case, the security collaborators are considered honest; R2, for Tr i < σ l , the request of the security collaborator for an undisclosed vulnerability will be rejected by the trusted authorization center, and in this case, the security collaborator is considered dishonest; R3, for σ l ≤ Tr i < σ h , in this case, it is difficult for the security collaborator to be classified as honest or dishonest and is considered semi - honest waiting for further detection; To further evaluate semi - honest secure collaborators, according to whether they have colluders, define μ i as the number of colluders that a secure collaborator has. If μ i = 0, it means that it has no colluders, and the secure collaborator can be temporarily considered honest. If μ i ≥ 1, then the secure collaborator may have a considerable number of colluders and is therefore rejected from joining the candidate sharing process; If the security collaborator is determined to be semi - honest, the conspirator entrapment will release false undisclosed vulnerability information when the security collaborator requests access to the undisclosed vulnerability again, and ensure that the embedded benign logic bomb code preleak will not damage the leaked information; according to the information fed back to the trusted authorization agency each time the benign logic bomb code preleak is triggered, judge whether there is a possibility of secondary leakage. Once the conspirator is entrapped, the security collaborator will be regarded as dishonest.
9. A crowdsourcing collaborative sharing anti-disclosure method for undisclosed vulnerabilities of the crowdsourcing collaborative sharing anti-disclosure system for undisclosed vulnerabilities according to claim 1, characterized in that, Including the following steps: Step 1, when the crowdsourcing collaborative sharing anti-disclosure system is initialized, each security collaborator participating in the collaborative sharing SC i first presents his identity credential to the trusted authorization agency. The trusted authorization agency grants the security collaborator SC i corresponding access rights according to whether the security collaborator is in the collaboration pool. The trusted authorization agency generates an access token for each verified SC i one, SC i and the generated access token token access , SC i no information about the access token can be obtained. The generated access token token access will be securely stored on the blockchain; token access Step 2, when a security collaborator SC i initiates a sharing request to the trusted authorization agency, the trusted authorization agency will retrieve the access token of the security collaborator from the blockchain SC i . If a hit occurs, the access token token access will be associated with the security collaborator token access , and the request response SC i will be returned. If no hit occurs, a new access token SC i will be generated and form a continuous access log storage chain with the historical access tokens token access of the security collaborator SC i ; token access Step 3, when the trusted authorization agency receives SC i the access request, the access token token access is recycled. The trusted authorization agency generates a traceable token mac current based on the target access environment token access and the recycled access token token tracing and embeds it into the undisclosed vulnerability information requested to be accessed. The traceable token token tracing is generated in the following way: token tracing ← H ( mac current || token access ) At the same time, the trusted authorization agency stores the newly generated traceable token token tracing on the blockchain; Step 4, when a suspected security collaborator SC i accesses the undisclosed vulnerability information in a permitted access environment, the benign logic bomb in the internal leakage prevention module code preleak remains dormant, and the trusted authorization agency generates the corresponding suspected security collaborator SC i historical access records. Once the suspected security collaborator SC i has an access environment different from the permitted access environment, the benign logic bomb in the single-step internal leakage prevention module code preleak is activated, runs the self-destruction module to destroy the undisclosed vulnerability information. When destroying the leaked undisclosed vulnerability information, feedback information is also sent to the trusted authorization agency, and the feedback information exists in an encrypted form, e f ={ token access , vul j , SC i , mac current , tp} contains the leakage location and the identity information of the leaker; Step 5, after receiving the feedback information from the leaker, the trusted authorization agency imposes a penalty on the trust value of the target leaker and rejects any sharing requests from the target leaker. For the suspicious security collaborators in the middle of the trust range SC i , when the trusted authorization agency SC i receives a sharing request again from the suspicious security collaborator, it returns false undisclosed vulnerability information. Once the suspicious security collaborator SC i leaks the false information to any third party, the suspicious security collaborator SC i will be recognized as dishonest by the trusted authorization agency and be refused continued service.
Citation Information
Patent Citations
Methods and systems for executing programs in secure environments
CN110392888A
Authority authentication control method based on HTTP protocol and storage medium
CN113645247A