Information security-based vulnerability management and control method and system
By using an information security-based vulnerability management system, which employs security vulnerability scanning and management modules to scan and manage network vulnerabilities, distinguishes between high-risk and low-risk vulnerabilities, and provides security patch upgrades, the system solves the problem of insufficient timely response from manual monitoring and improves network security.
Patent Information
- Application Number
- CN202210929126.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-08-03
- Publication Date
- 2025-11-21
- Estimated Expiration
- 2042-08-03
AI Technical Summary
Current cybersecurity vulnerability management relies on manual monitoring, which cannot respond in a timely manner, leading to frequent security incidents.
An information security-based vulnerability management system is adopted, including a security vulnerability scanning module and a security management module. Through scanning, policy management and security patch upgrades, it distinguishes between high-risk and low-risk vulnerabilities and provides corresponding security patch upgrade packages.
It enables timely identification and management of network security vulnerabilities, improves network security, and reduces the occurrence of security incidents.
Smart Images

Figure CN115484055B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of security vulnerability management technology, and in particular to a vulnerability management method and system based on information security. Background Technology
[0002] With the rapid development of my country's internet, network security vulnerabilities have also become more prominent. Currently, network security vulnerability management is generally achieved through manual monitoring of configuration data. This method is highly susceptible to human factors and cannot respond in a timely manner, thus leading to security incidents where vulnerabilities infiltrate the network.
[0003] In the prior art, Chinese invention patent application number CN114785691A discloses a network security management and control method, including a management terminal sending a configuration collection request to a switching terminal and receiving current configuration data sent by the switching terminal, wherein the current configuration data is obtained by the switching terminal in response to the configuration collection request; the management terminal obtains the historical configuration data of the previous configuration data and compares the current configuration data with the historical configuration data to obtain a comparison result; the management terminal generates an anomaly report based on the comparison result. This application also provides a network security management and control device, a computer device, and a storage medium. This application compares the current configuration data with historical configuration data to determine whether the current network configuration has changed, and then obtains the network configuration change information based on the obtained mobility report, so as to maintain network security in a timely manner and effectively ensure network security.
[0004] A comparison between the present invention and the prior art reveals that the technical solution of the present invention can effectively manage security vulnerabilities in networks and has high practicality. Summary of the Invention
[0005] Therefore, the purpose of this invention is to provide a vulnerability management method and system based on information security, so as to at least solve the above problems.
[0006] The first aspect of this invention proposes a vulnerability management method based on information security, and the technical solution adopted is as follows:
[0007] A vulnerability management method based on information security is applied to an information security vulnerability management system. The system includes a server, a security vulnerability scanning module, and a security management module. The security vulnerability scanning module is used to scan for security vulnerabilities, and the security management module is used to manage and control the security vulnerabilities. The method includes the following steps:
[0008] S1. When the security vulnerability scanning module detects a security vulnerability, the server distinguishes between web-based and host-based security vulnerabilities.
[0009] S2. The security management module adopts the first strategy and the second strategy for security vulnerabilities of Web and host types, respectively.
[0010] S3. If the security vulnerability scanning module can still detect security vulnerabilities after the security management module has adopted the first and second strategies, then the security management module will adopt the third strategy.
[0011] S4. The server marks security vulnerabilities that the security management module uses a third strategy for;
[0012] S5. The server transfers the marked security vulnerabilities to the security vulnerability training model for security simulation training.
[0013] S6. The server distinguishes between high-risk and low-risk levels based on the security simulation training results of the security vulnerability training model, and provides suggestions on matching security patch upgrade packages for high-risk and low-risk levels.
[0014] Furthermore, in step S1, the specific steps for differentiating the web types of security vulnerabilities for the server are as follows:
[0015] The type of web security vulnerability is determined by capturing security logs from the network via the server and identifying any SQL injection, cross-site scripting, cross-site request forgery, or weak password attacks.
[0016] The specific methods for differentiating host types of security vulnerabilities in servers are as follows:
[0017] The type of host security vulnerability is determined by capturing network security logs from the server and identifying any weak passwords or exposed ports.
[0018] Furthermore, in step S2, the security management module adopts the first strategy specifically for web-type security vulnerabilities:
[0019] The security control module locks the IP address of any input terminal that is vulnerable to SQL injection, cross-site scripting, cross-site request forgery, or weak password attacks, and performs CAPTCHA verification. If the input terminal cannot obtain the CAPTCHA, the security control module restricts the input from that terminal.
[0020] The security management module adopts a second strategy for security vulnerabilities of host types, specifically as follows:
[0021] The security control module restricts input thresholds and closes high-risk ports based on the presence of any weak password or exposed port.
[0022] Furthermore, in step S3, the security control module adopts a third strategy, specifically as follows:
[0023] The security management module shuts down the external network connection and requires internal network security verification when enabling the internal network.
[0024] Furthermore, in step S4, the server marks the security vulnerabilities for which the security management module adopts the third strategy as follows:
[0025] The server uses a monitor to mark security vulnerabilities of the third-party security strategy and generates a detection report to issue security warnings for intrusions caused by the third-party security vulnerabilities.
[0026] Furthermore, in step S5, the server transfers the marked security vulnerabilities to the security vulnerability training model for security simulation training, specifically as follows:
[0027] The server transfers the marked security vulnerabilities to a security vulnerability training model within a closed internal network for security simulation and records the network impact caused by the marked security vulnerabilities.
[0028] Furthermore, in step S6, the server distinguishes between high-risk and low-risk levels based on the security simulation training results of the security vulnerability training model, and provides suggestions for matching high-risk and low-risk security patch upgrade packages, specifically as follows:
[0029] The server classifies the presence of security issues into high-risk and low-risk levels based on the network impact results of security vulnerabilities trained by the security vulnerability training model in a closed intranet environment. The high-risk level is defined as: causing irreversible damage to the server and affecting other servers.
[0030] The low-risk level is defined as follows: the impact on the server is controllable and will not endanger other servers;
[0031] The server provides recommendations on the combination of security patch upgrade packages for both high-risk and low-risk security vulnerabilities.
[0032] A second aspect of the present invention provides a vulnerability management system based on information security, the system comprising a server, a security vulnerability scanning module, and a security management module, wherein the security vulnerability scanning module is used to scan for security vulnerabilities, and the security management module is used to manage the security vulnerabilities.
[0033] Compared with the prior art, the beneficial effects of the present invention are:
[0034] This invention provides a vulnerability management method based on information security. First, a security vulnerability scanning module scans out security vulnerabilities, and a security management module manages these vulnerabilities through policy control. Finally, a server provides security patch upgrade packages to upgrade the security vulnerabilities. This invention can manage security vulnerabilities in the network and has high practicality. Attached Figure Description
[0035] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only preferred embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0036] Figure 1 This is a schematic diagram of the overall process of a vulnerability management method based on information security provided in an embodiment of the present invention. Detailed Implementation
[0037] The principles and features of the present invention are described below with reference to the accompanying drawings. The listed embodiments are only used to explain the present invention and are not intended to limit the scope of the present invention.
[0038] Reference Figure 1 This embodiment provides a vulnerability management method based on information security. The method is applied to an information security vulnerability management system, which includes a server, a security vulnerability scanning module, and a security management module. The security vulnerability scanning module is used to scan for security vulnerabilities, and the security management module is used to manage and control the security vulnerabilities. The method includes the following steps:
[0039] S1. When the security vulnerability scanning module detects a security vulnerability, the server distinguishes between web-based and host-based security vulnerabilities.
[0040] S2. The security management module adopts the first strategy and the second strategy for security vulnerabilities of Web and host types, respectively.
[0041] S3. If the security vulnerability scanning module can still detect security vulnerabilities after the security management module has adopted the first and second strategies, then the security management module will adopt the third strategy.
[0042] S4. The server marks security vulnerabilities that the security management module uses a third strategy for;
[0043] S5. The server transfers the marked security vulnerabilities to the security vulnerability training model for security simulation training.
[0044] S6. The server distinguishes between high-risk and low-risk levels based on the security simulation training results of the security vulnerability training model, and provides suggestions on matching security patch upgrade packages for high-risk and low-risk levels.
[0045] For example, in order to prevent malicious intrusions launched by criminals against the network, this method first scans for security vulnerabilities through a security vulnerability scanning module, then classifies the security vulnerabilities by type through a server, then manages the security vulnerabilities through a security control module, and finally recommends high-risk and low-risk security patch upgrade packages through a server.
[0046] In step S1, the specific steps for differentiating the web types of security vulnerabilities for the server are as follows:
[0047] The type of web security vulnerability is determined by capturing security logs from the network via the server and identifying any SQL injection, cross-site scripting, cross-site request forgery, or weak password attacks.
[0048] The specific methods for differentiating host types of security vulnerabilities in servers are as follows:
[0049] The type of host security vulnerability is determined by capturing network security logs from the server and identifying any weak passwords or exposed ports.
[0050] For example, by prioritizing the prevention of SQL injection, cross-site scripting, cross-site request forgery, and weak password attacks among web security vulnerability types, as well as weak passwords and port exposure among host security vulnerability types, security vulnerabilities can be effectively identified, and the network can be securely protected.
[0051] In step S2, the security management module adopts the first strategy for web-type security vulnerabilities, specifically as follows:
[0052] The security control module locks the IP address of any input terminal that is vulnerable to SQL injection, cross-site scripting, cross-site request forgery, or weak password attacks, and performs CAPTCHA verification. If the input terminal cannot obtain the CAPTCHA, the security control module restricts the input from that terminal.
[0053] For example, if any SQL injection, cross-site scripting, cross-site request forgery, or weak password attack exists at the input end, the security control module will lock the source of the input IP and perform a verification code check. The verification code can be a regular image / text verification or a mobile SMS verification. The above methods can effectively prevent web-type security vulnerabilities.
[0054] The security management module adopts a second strategy for security vulnerabilities of host types, specifically as follows:
[0055] The security control module restricts input thresholds and closes high-risk ports based on the presence of any weak password or exposed port.
[0056] For example, when a weak password occurs, the number of times it can be entered can be limited at the input end, i.e., an input threshold, which is set by the system staff; when a port is exposed, some high-risk ports, such as port 455, can be closed.
[0057] In step S3, the security control module adopts the third strategy as follows:
[0058] The security management module shuts down the external network connection and requires internal network security verification when enabling the internal network.
[0059] For example, when the security vulnerability scanning module fails to identify common web and host type security vulnerabilities, the vulnerability has already threatened network security. In order to protect network security, the security management module shuts down the external network connection and requires internal network security verification when enabling the internal network. In particular, internal network verification means using the internal network terminal for network communication.
[0060] In step S4, the server marks the security vulnerabilities for which the security management module adopts the third strategy as follows:
[0061] The server uses a monitor to mark security vulnerabilities of the third-party security strategy and generates a detection report to issue security warnings for intrusions caused by the third-party security vulnerabilities.
[0062] For example, in order to improve network security, security vulnerabilities of third-party strategies can be marked on the server so that the vulnerabilities can be discovered and the corresponding network security patch packages can be studied for effective interception.
[0063] In step S5, the server transfers the marked security vulnerabilities to the security vulnerability training model for security simulation training, specifically as follows:
[0064] The server transfers the marked security vulnerabilities to a security vulnerability training model within a closed internal network for security simulation and records the network impact caused by the marked security vulnerabilities.
[0065] For example, by transferring the marked security vulnerabilities to a closed internal network, the server can effectively prevent them from intruding into other networks. The network impact caused by the marked security vulnerabilities can be recorded so that system staff can take corresponding measures.
[0066] In step S6, the server distinguishes between high-risk and low-risk levels based on the security simulation training results of the security vulnerability training model, and provides suggestions for matching high-risk and low-risk security patch upgrade packages as follows:
[0067] The server classifies the presence of security issues into high-risk and low-risk levels based on the network impact results of security vulnerabilities trained by the security vulnerability training model in a closed intranet environment. The high-risk level is defined as: causing irreversible damage to the server and affecting other servers.
[0068] The low-risk level is defined as follows: the impact on the server is controllable and will not endanger other servers;
[0069] The server provides recommendations on the combination of security patch upgrade packages for both high-risk and low-risk security vulnerabilities.
[0070] Another embodiment of the present invention proposes a vulnerability management system based on information security. The system includes a server, a security vulnerability scanning module, and a security management module. The security vulnerability scanning module is used to scan for security vulnerabilities, and the security management module is used to manage the security vulnerabilities.
[0071] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
Claims
1. A vulnerability management method based on information security, characterized in that, The method is applied to an information security vulnerability management system. The system includes a server, a security vulnerability scanning module, and a security management module. The security vulnerability scanning module is used to scan for security vulnerabilities, and the security management module is used to manage and control the security vulnerabilities. The method includes the following steps: S1. When the security vulnerability scanning module detects a security vulnerability, the server distinguishes between web-based and host-based security vulnerabilities. S2. The security management module adopts the first strategy and the second strategy for security vulnerabilities of Web and host types, respectively. S3. If the security vulnerability scanning module can still detect security vulnerabilities after the security management module has adopted the first and second strategies, then the security management module will adopt the third strategy. S4. The server marks security vulnerabilities that the security management module uses a third strategy for; S5. The server transfers the marked security vulnerabilities to the security vulnerability training model for security simulation training. S6. The server distinguishes between high-risk and low-risk levels based on the security simulation training results of the security vulnerability training model, and provides suggestions on matching security patch upgrade packages for high-risk and low-risk levels. In step S1, the specific steps for differentiating the web types of security vulnerabilities for the server are as follows: The type of web security vulnerability is determined by capturing security logs from the network via the server and identifying any SQL injection, cross-site scripting, cross-site request forgery, or weak password attacks. The specific methods for differentiating host types of security vulnerabilities in servers are as follows: The type of host security vulnerability is determined by capturing network security logs from the server and identifying any weak passwords or exposed ports. In step S2, the security management module adopts the first strategy for web-type security vulnerabilities, specifically as follows: The security control module locks the IP address of any input terminal that is vulnerable to SQL injection, cross-site scripting, cross-site request forgery, or weak password attacks, and performs CAPTCHA verification. If the input terminal cannot obtain the CAPTCHA, the security control module restricts the input from that terminal. The security management module adopts a second strategy for security vulnerabilities of host types, specifically as follows: The security control module restricts input thresholds and closes high-risk ports based on the existence of any weak password or exposed port. In step S3, the security control module adopts the third strategy as follows: The security management module shuts down the external network connection and requires internal network security verification when enabling the internal network.
2. The vulnerability management method based on information security according to claim 1, characterized in that, In step S4, the server marks the security vulnerabilities for which the security management module adopts the third strategy as follows: The server uses a monitor to mark security vulnerabilities of the third-party security strategy and generates a detection report to issue security warnings for intrusions caused by the third-party security vulnerabilities.
3. The vulnerability management method based on information security according to claim 1, characterized in that, In step S5, the server transfers the marked security vulnerabilities to the security vulnerability training model for security simulation training, specifically as follows: The server transfers the marked security vulnerabilities to a security vulnerability training model within a closed internal network for security simulation and records the network impact caused by the marked security vulnerabilities.
4. The vulnerability management method based on information security according to claim 3, characterized in that, In step S6, the server distinguishes between high-risk and low-risk levels based on the security simulation training results of the security vulnerability training model, and provides suggestions for matching high-risk and low-risk security patch upgrade packages as follows: The server classifies the presence of security issues into high-risk and low-risk levels based on the network impact results of security vulnerabilities trained by the security vulnerability training model in a closed intranet environment. The high-risk level is defined as: causing irreversible damage to the server and affecting other servers. The low-risk level is defined as follows: the impact on the server is controllable and will not endanger other servers; The server provides recommendations on the combination of security patch upgrade packages for both high-risk and low-risk security vulnerabilities.
5. A vulnerability management system based on information security, characterized in that, The system is used to perform the method described in any one of claims 1-4. The system includes a server, a security vulnerability scanning module, and a security management module. The security vulnerability scanning module is used to scan for security vulnerabilities, and the security management module is used to manage the security vulnerabilities.
Citation Information
Patent Citations
Network security control method and device, computer equipment and storage medium
CN114785691A
Security analysis and assessment platform for information system and control system of smart substation
CN106230780A
System and method for enabling remote registry service security audits
US20110185431A1