Vulnerability rectification method, device, equipment and storage medium
By finding vulnerabilities in network security, calculating and adjusting the rectification time limit of electronic equipment, and combining the characteristic values of asset dimensions, the problem of inaccurate vulnerability rectification time limit in existing technologies is solved, and efficient and reasonable vulnerability rectification is achieved.
Patent Information
- Application Number
- CN202211510799.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-29
- Publication Date
- 2025-10-03
- Estimated Expiration
- 2042-11-29
AI Technical Summary
The existing method for assessing the time limit for rectifying network security vulnerabilities is based solely on the level of hazard, without considering other influencing factors. This results in inaccurate rectification time limits, difficulty in promptly resolving highly hazardous vulnerabilities, and irrational allocation of rectification resources.
By finding vulnerabilities in network security, calculating the candidate time limit of electronic equipment, adjusting the characteristic values of multiple asset dimensions, determining the target time limit, and issuing rectification tasks to ensure that the vulnerability rectification is completed within the target time limit.
The accuracy and real-time performance of vulnerability rectification time limit assessment have been improved, enabling timely and effective risk control under limited labor costs.
Smart Images

Figure CN115883190B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of network security, and in particular relates to a vulnerability rectification method, device, equipment and storage medium. Background Art
[0002] At present, the cybersecurity situation at home and abroad is severe, cyberattack methods are emerging in an endless stream, and various IT assets, such as electronic equipment, are facing increasing cybersecurity threats. Related cybersecurity vulnerabilities are frequently exposed. It is extremely important to promote the rectification of cybersecurity vulnerabilities efficiently and with high quality.
[0003] Currently, traditional methods for assessing the timeframe for remediation of network security vulnerabilities primarily rely on the vulnerability's severity level (classified into three aspects: access path, exploit complexity, and impact), establishing a unified, universal timeframe for remediation of network security vulnerabilities. For example, remediation of extreme and high-risk vulnerabilities is set at 10 working days, while remediation of medium and low-risk vulnerabilities is set at 30 working days. These timeframes often lead to the following problems:
[0004] (1) The rectification time limit determined by only considering the hazard level of the vulnerability without considering other influencing factors cannot accurately meet the needs of remediating each vulnerability.
[0005] (2) Determining the priority of vulnerability rectification based solely on the hazard level makes it difficult to resolve vulnerabilities with high hazard levels in a timely manner, which poses a security risk and also leads to poor allocation of resources for vulnerability rectification. Summary of the Invention
[0006] The present invention provides a vulnerability rectification method, device, equipment and storage medium to solve the problem caused by the simple hazard level classification of vulnerabilities in the existing technology, so as to ensure the accuracy and real-time performance of the vulnerability rectification time limit assessment and achieve timely and effective risk control.
[0007] According to a first aspect of the present invention, a vulnerability rectification method is provided, characterized by comprising:
[0008] Find electronic devices with network security vulnerabilities;
[0009] Calculating a candidate time limit for rectifying the vulnerability for each electronic device according to the hazard level of the vulnerability;
[0010] Calculating characteristic values of each of the electronic devices in multiple asset dimensions;
[0011] Adjusting the candidate time limit for each of the electronic devices according to the plurality of characteristic values to obtain a target time limit for rectifying the vulnerability in each of the electronic devices;
[0012] A vulnerability rectification task is issued to each of the electronic devices, wherein the vulnerability rectification task requires rectification of the vulnerability of each of the electronic devices within the target time limit.
[0013] According to a second aspect of the present invention, a vulnerability rectification device is provided, comprising:
[0014] A search module, used to search for electronic devices with network security vulnerabilities;
[0015] a candidate time limit calculation module, configured to calculate a candidate time limit for rectifying the vulnerability for each electronic device according to the hazard level of the vulnerability;
[0016] a characteristic value calculation module, configured to calculate characteristic values presented by each of the electronic devices in multiple asset dimensions;
[0017] an adjustment module, configured to adjust the candidate time limit for each of the electronic devices according to the plurality of characteristic values to obtain a target time limit for rectifying the vulnerability of each of the electronic devices;
[0018] The issuing module is used to issue a vulnerability rectification task to each of the electronic devices, wherein the vulnerability rectification task requires that the vulnerability of each of the electronic devices be rectified within the target time limit.
[0019] According to another aspect of the present invention, an electronic device is provided, comprising:
[0020] at least one processor; and
[0021] a memory communicatively connected to the at least one processor; wherein,
[0022] The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute a vulnerability rectification method described in any embodiment of the present invention.
[0023] According to another aspect of the present invention, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement a vulnerability rectification method according to any embodiment of the present invention when executed.
[0024] In an embodiment of the present application, a vulnerability rectification method is provided. The method can first search for electronic devices with network security vulnerabilities, and then calculate the candidate time limit for rectifying the vulnerabilities for each electronic device based on the hazard level of the vulnerability. At this time, the determined candidate time limit cannot clearly define the urgency corresponding to each electronic device. The characteristic values presented by each electronic device in multiple asset dimensions can be calculated, and the candidate time limit of each electronic device can be adjusted according to the multiple characteristic values to obtain a target time limit for rectifying the vulnerabilities of each electronic device. A vulnerability rectification task is issued to each electronic device. The vulnerability rectification task requires that the vulnerabilities of each electronic device be rectified within the target time limit. This can effectively improve the accuracy and real-time performance of the rectification time limit assessment for electronic devices with vulnerabilities, and can timely and effectively control risks under limited labor cost conditions.
[0025] It should be understood that the content described in this section is not intended to identify the key or important features of the embodiments of the present invention, nor is it intended to limit the scope of the present invention. Other features of the present invention will become readily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0026] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0027] Figure 1 This is a flow chart of a vulnerability rectification method provided according to the first embodiment of the present invention;
[0028] Figure 2 This is a structural diagram of a vulnerability rectification device provided according to the second embodiment of the present invention;
[0029] Figure 3 The present invention is a schematic structural diagram of an electronic device for implementing a vulnerability rectification method according to an embodiment of the present invention. DETAILED DESCRIPTION
[0030] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of the present invention.
[0031] It should be noted that the terms "first", "second", etc. in the description and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the numbers used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0032] Example 1
[0033] Figure 1 This is a flowchart of a vulnerability rectification method provided in Example 1 of the present disclosure.
[0034] Regarding the current problems facing network security, how to reasonably assess the time limit for rectifying network security vulnerabilities of each type of electronic equipment under limited labor cost conditions is the key to achieving efficient and high-quality rectification of network security vulnerabilities.
[0035] Currently, the timelines for remediating general network security vulnerabilities only consider the vulnerability's severity level, failing to account for differences between vulnerabilities with patches and those without, or for changes in vulnerability remediation timelines during different network security protection periods. Furthermore, the timelines for remediating network security vulnerabilities fail to comprehensively consider factors such as the attack surface, asset type, and frequency of asset use faced by various electronic devices, and fail to prioritize the remediation of vulnerabilities across various electronic devices. This results in a fragmented effort for early stage remediation, leading to ineffective and ineffective remediation efforts.
[0036] The vulnerability rectification method proposed in the embodiment of the present invention can improve the accuracy and real-time performance of the time limit assessment for network security vulnerability rectification of electronic equipment, thereby achieving efficient and high-quality vulnerability rectification.
[0037] The method can be performed by a vulnerability rectification device, and the vulnerability rectification device can be implemented in the form of hardware and / or software.
[0038] like Figure 1 As shown, this embodiment may include the following steps:
[0039] S110, search for electronic devices with network security vulnerabilities.
[0040] In this embodiment, based on a platform with a vulnerability search function, vulnerability scanning and other operations may be performed on electronic devices to determine electronic devices with network security vulnerabilities within a specified range.
[0041] For example, within an enterprise, electronic equipment may include various business systems, network equipment, security equipment, host equipment, office terminals, office peripherals, etc.
[0042] In one embodiment, step S110 includes the following steps:
[0043] S110 - 1 , obtaining vulnerability information released in a designated channel, where the vulnerability information includes first version information of software and / or hardware.
[0044] In this embodiment, the designated channels may include national cybersecurity regulatory agencies, mainstream internet cybersecurity vulnerability disclosure platforms, and the like. These designated channels publish the latest information related to cybersecurity vulnerabilities, i.e., vulnerability information. Specifically, specific software and / or hardware versions, as well as specific vulnerabilities in those versions, can be obtained from these designated channels.
[0045] S110 - 2 , querying the second version information of the software and / or hardware of each electronic device within the specified range.
[0046] In this embodiment, the electronic devices within the specified range may refer to all electronic devices within a certain management range. For example, if a vulnerability is to be rectified in a certain enterprise, the electronic devices within the specified range may be all electronic devices within the enterprise.
[0047] After querying the versions of the software and / or hardware of each electronic device within the specified range, the version information corresponding to the software and / or hardware stored in the specific electronic device can be determined, that is, the second version information is obtained.
[0048] S110-3, if the second version information of a certain electronic device is the same as the first version information, it is determined that there is a vulnerability in the network security of the electronic device.
[0049] In this embodiment, after obtaining the first version information from a designated channel and determining the second version information through searching, the first version information and the second version information can be matched. If the second version information of an electronic device is the same as the first version information, it can be determined that the electronic device has a network security vulnerability and is affected by the vulnerability. All electronic devices within a designated range that have the same network security vulnerability can be screened out.
[0050] S120, calculating a candidate time limit for correcting the vulnerability for each electronic device based on the hazard level of the vulnerability.
[0051] In one embodiment, after the vulnerability is determined, the vulnerability may be classified into different hazard levels, and rectification time limits corresponding to different hazard levels may be determined.
[0052] Different weights can be set based on the impact of the vulnerability on different levels, the length of time since the vulnerability was published, or the specific usage requirements of the specified scope. For example, if the specified scope is a banking enterprise, then vulnerabilities related to transaction processes pose a greater threat to the banking enterprise. In this case, corresponding weights can be set for vulnerabilities related to transaction processes to shorten the rectification timeline.
[0053] Then, the candidate time limits can be calculated based on the rectification time limits corresponding to different hazard levels and the determined weights.
[0054] In one embodiment, step S120 includes the following steps:
[0055] S120-1, query the vulnerability's hazard level.
[0056] In this embodiment, all vulnerabilities can be pre-classified into risk levels, generating vulnerability risk level classification information. After a vulnerability in an electronic device is identified, the pre-generated vulnerability risk level classification information can be queried to determine the risk level corresponding to the vulnerability in the electronic device. Specifically, the risk level can be categorized as extremely risky, high risk, medium risk, and low risk.
[0057] S120-2, mapping the hazard level to the original time limit for correcting the vulnerability of each electronic device configuration, where the original time limit is negatively correlated with the hazard level.
[0058] In this embodiment, different hazard levels correspond to different rectification deadlines. The greater the hazard level, the longer the rectification deadline, i.e., the shorter the deadline. Hazard levels can be mapped to the original time limits for remediating vulnerabilities in each electronic device configuration. For example, for vulnerabilities with a hazard level of extreme or high, the original time limit is 10 working days, while for vulnerabilities with a hazard level of medium or low, the original time limit is 30 working days.
[0059] S120-3, configuring multiple adjustment coefficients for each electronic device under multiple security dimensions.
[0060] In this embodiment, the original time limit for rectifying vulnerabilities mapped by the classification of hazard levels is difficult to accurately match the urgency of rectifying the vulnerabilities, and there is a problem of irrational allocation of rectification efforts. Therefore, different security dimensions can be set for different application scenarios, and multiple adjustment coefficients can be configured for each electronic device under multiple security dimensions to further accurately refine the time limit for rectifying the vulnerabilities to obtain a more reasonable rectification time limit. For example, the security dimension can be whether the current period is a network security protection period, the length of time the vulnerability has been released, the level of vulnerability impact, etc.
[0061] In one embodiment, step S120-3 includes the following steps:
[0062] Query the time since the vulnerability was published;
[0063] Configure an adjustment coefficient for each electronic device according to the duration, and the adjustment coefficient is positively correlated with the duration;
[0064] Query the security level of the network environment where the electronic device is located;
[0065] According to the security level, each electronic device is configured with an adjustment coefficient, and the adjustment coefficient is negatively correlated with the security level;
[0066] Query the level of security impact of vulnerabilities on the software and / or hardware of electronic devices;
[0067] According to the configuration adjustment coefficient of each electronic device at the level, the external access permission at the module level is negatively correlated with the security level.
[0068] In this embodiment, the security dimension may be the length of time the vulnerability has been published, the security level of the network environment in which the electronic device is located, and the level of security impact the vulnerability has on the software and / or hardware of the electronic device.
[0069] The length of time the vulnerability has been published can be queried and determined from the vulnerability information released through the designated channels. An adjustment coefficient is configured for each electronic device according to the length of time, and the adjustment coefficient is positively correlated with the length of time. A1 can be used as an adjustment coefficient for configuring each electronic device according to the length of time. For example, for a vulnerability with a duration of 0 days, a vulnerability with a duration of 1 day, and a vulnerability with a duration of N days, A1 can be set to three coefficients, namely 0.5, 0.7, and 1. A vulnerability of 0 days means a vulnerability for which no official patch has been released, which is extremely harmful. The higher the rectification time limit requirement, the smaller the corresponding adjustment coefficient. In one embodiment, if only the length of time the vulnerability has been published is considered, the rectification time limit for a high-risk vulnerability with a duration of 0 days can be 10 days of the original time limit multiplied by the adjustment coefficient, that is, 10×0.5=5 working days.
[0070] The security level of the network environment in which electronic devices operate can be determined by the time point at which the vulnerability is discovered. Because different network environments process different information, some of which are related to national security, social order, and the public interest, assessments are required at regular intervals, with varying levels of urgency in different assessment time periods. Because more targeted vulnerabilities are present during assessments, posing greater security risks, more rapid remediation is required during the assessment period to ensure information security.
[0071] A2 is an adjustment factor assigned to each electronic device based on its security level, and the adjustment factor is negatively correlated with the security level. For example, security levels can be categorized as special, level one, level two, and during routine network security. A2 can be set to four adjustment factors: 0.7, 0.8, 0.9, and 1, respectively. The higher the level, the higher the adjustment factor. In one embodiment, if only the security level is considered, and the device is currently in the special network security period, the time limit for remediating high-risk vulnerabilities can be the original 10-day deadline multiplied by the adjustment factor, i.e., 10 × 0.7 = 7 working days.
[0072] The levels affected by different vulnerabilities can be divided in advance, and then the level at which the current vulnerability has a security impact on the software and / or hardware of the electronic device can be queried. For example, the different levels can include application level, database level, and operating system level.
[0073] Because the external access permissions for application ports, database ports, and operating system ports have been reduced from wide to narrow, A3 configures an adjustment coefficient for each electronic device layer. External access permissions at the module level are negatively correlated with the security level, and A3 can be set to three coefficients: 0.5, 1, and 2. In one embodiment, if only the affected layer is considered, and the current vulnerability is at the operating system level, then the high-risk vulnerability is considered at the operating system level. The rectification deadline can be the original 10-day deadline multiplied by the adjustment coefficient, i.e., 10 × 2 = 20 working days.
[0074] S120-4: For the same electronic device, the original time limit is multiplied by multiple adjustment coefficients to obtain a candidate time limit for rectifying the vulnerability of the electronic device.
[0075] In one embodiment, after multiple adjustment coefficients are determined based on multiple security dimensions, when determining a candidate time limit for rectifying a vulnerability in an electronic device, the original time limit may be multiplied by the multiple adjustment coefficients.
[0076] The candidate time limit can be determined using the following formula:
[0077] T1=T0×A1×A2×A3
[0078] Among them, T1 is the candidate time limit for rectifying vulnerabilities in electronic equipment, T0 is the original time limit, A1 is the adjustment coefficient configured for each electronic device according to the time length, A2 is the adjustment coefficient configured for each electronic device according to the security level, and A3 is the adjustment coefficient configured for each electronic device according to the level.
[0079] It can be seen that the candidate time limits determined for electronic devices with the same vulnerability are the same.
[0080] S130: Calculate characteristic values of each electronic device in multiple asset dimensions.
[0081] In this embodiment, the rectification time limit may also be comprehensively considered in combination with the asset dimension to determine a more real-time and secure rectification time limit corresponding to each electronic device affected by the vulnerability.
[0082] Specifically, a diagonal matrix may be used to represent the characteristic values presented in multiple asset dimensions.
[0083] In one embodiment, step S130 includes the following steps:
[0084] S130-1, querying asset information of each electronic device in multiple asset dimensions.
[0085] The asset dimensions can be determined in advance. For electronic devices with vulnerabilities, asset information can be queried from the specified range to which the electronic devices belong. For example, when the specified range is within a certain enterprise, for the enterprise, some asset information of the electronic devices in multiple asset dimensions will be recorded, which can be directly queried from the information recorded within the enterprise. In addition, some asset information can also be queried from historical network environment data, such as the number of users, visits, etc.
[0086] In one embodiment, step S130-1 includes:
[0087] Query asset category information, asset exposure information, and asset usage information for each electronic device as asset information;
[0088] Among them, asset category information includes business systems, information infrastructure, terminal equipment, and office peripherals;
[0089] Asset exposure information includes internet applications, first intranet systems that interact with internet applications, second intranet systems accessed across regions, and third intranet systems accessed within a single region.
[0090] The asset usage information includes first usage information, second usage information, third usage information, and fourth usage information; the user level of the first usage information and the user level of the second usage information both belong to the first level, the user level of the third usage information and the user level of the fourth usage information both belong to the second level, and the first level is greater than the second level; the access level of the first usage information and the access level of the third usage information both belong to the third level, the access level of the second usage information and the access level of the fourth usage information both belong to the fourth level, and the third level is greater than the fourth level.
[0091] Specifically, information infrastructure includes network devices, security devices, and host devices. The first usage information can be understood as a large number of users and heavy visits, the second usage information can be understood as a large number of users and a small number of visits, the third usage information can be understood as a small number of users and a large number of visits, and the fourth usage information can be understood as a small number of users and a small number of visits.
[0092] S130-2, mapping asset information into feature values.
[0093] According to the actual application situation, the characteristic value of each information in the asset information can be determined and adjusted. After the asset information of the electronic device with vulnerabilities is determined, mapping is performed to determine the characteristic value corresponding to each asset information.
[0094] In one embodiment, step S130-2 includes:
[0095] Map asset category information, asset exposure information, and asset usage information to asset values respectively;
[0096] Among them, the characteristic value of the business system is smaller than the characteristic value of the information infrastructure, the characteristic value of the information infrastructure is smaller than the characteristic value of the terminal equipment, and the characteristic value of the terminal equipment is smaller than the characteristic value of the office peripheral equipment;
[0097] The characteristic value of the Internet application is smaller than the characteristic value of the first intranet system, the characteristic value of the first intranet system is smaller than the characteristic value of the second intranet system, and the characteristic value of the second intranet system is smaller than the characteristic value of the third intranet system;
[0098] The characteristic value of the first usage information is smaller than the characteristic value of the second usage information, the characteristic value of the second usage information is smaller than the characteristic value of the third usage information, and the characteristic value of the third usage information is smaller than the characteristic value of the fourth usage information.
[0099] Specifically, the characteristic value of the business system, the characteristic value of the terminal device, the characteristic value of the information infrastructure, and the characteristic value of the terminal device can be set to 1, 1.5, 1.8, and 2, respectively.
[0100] The characteristic value of the Internet application, the characteristic value of the first intranet system, the characteristic value of the second intranet system, and the characteristic value of the third intranet system can be set to 0.8, 1, 1.5, and 2, respectively.
[0101] The characteristic value of the first usage information, the characteristic value of the second usage information, the characteristic value of the third usage information, and the characteristic value of the fourth usage information can be set to 1, 1.5, 1.5, and 2, respectively.
[0102] S130-3, for the same asset dimension, write the eigenvalues of each electronic device into the same diagonal matrix.
[0103] In this embodiment, after determining the eigenvalues corresponding to each electronic device under different asset dimensions, the eigenvalues of each electronic device may be written into a diagonal matrix, wherein eigenvalues belonging to the same asset dimension are written into the same diagonal matrix.
[0104] In one embodiment, step S130-3 includes:
[0105] Write the eigenvalues of each electronic device in the asset category information into a diagonal matrix;
[0106] Write the eigenvalues of each electronic device in the asset exposure information into another diagonal matrix;
[0107] The eigenvalues of each electronic device in the asset usage information are written into another diagonal matrix.
[0108] Specifically, a diagonal matrix C = diag{c1, c2, ..., c n} represents the characteristic value in the asset category information corresponding to each electronic device with a vulnerability, where c i Represents the characteristic value in the asset category information corresponding to the electronic device Si. When the characteristic value of the business system, the characteristic value of the terminal device, the characteristic value of the information infrastructure and the characteristic value of the terminal device can be set to 1, 1.5, 1.8 and 2 respectively, then c i ∈{1, 1.5, 1.8, 2}.
[0109] The diagonal matrix E = diag{e1, e2, ..., e n} represents the characteristic value of each electronic device with vulnerabilities in the asset exposure information, where e i Represents the characteristic value in the asset exposure information corresponding to the electronic device Si. When the characteristic value of the Internet application, the characteristic value of the first intranet system, the characteristic value of the second intranet system, and the characteristic value of the third intranet system can be set to 0.8, 1, 1.5, and 2 respectively, then e i ∈{0.8, 1, 1.5, 2}.
[0110] The diagonal matrix U = diag{u1, u2, ..., u n} represents the characteristic value in the asset usage information corresponding to each electronic device with a vulnerability, where u i Represents the characteristic value in the asset usage information corresponding to the electronic device Si. When the characteristic value of the first usage information, the characteristic value of the second usage information, the characteristic value of the third usage information, and the characteristic value of the fourth usage information can be set to 1, 1.5, 1.5, and 2 respectively, then u i ∈{1, 1.5, 1.5, 2}.
[0111] S140 , adjusting the candidate time limit for each electronic device according to the multiple characteristic values to obtain a target time limit for rectifying the vulnerability of each electronic device.
[0112] Since the candidate time limit is determined based on the hazard level, the candidate time limit of each electronic device can be adjusted according to multiple characteristic values to obtain the target time limit for rectifying the vulnerabilities of each electronic device. This takes multiple aspects into consideration and determines a target time limit for rectifying the vulnerabilities of each electronic device that is more real-time and can better ensure safety.
[0113] In one embodiment, step S140 includes the following steps:
[0114] Multiply the candidate time limit for each electronic device with the diagonal matrix corresponding to the asset category information, the diagonal matrix corresponding to the asset exposure information, and the diagonal matrix corresponding to the asset usage information to obtain the target time limit for rectifying the vulnerabilities of each electronic device.
[0115] Specifically, the following formula can be used to determine the target time limit for correcting the vulnerability in each electronic device affected by the vulnerability:
[0116] T n =(T1, T1, ..., T1) 1×n ×C n×n ×E n×n ×U n×n =(T 11 , T 12 ,…,T 1n ) 1×n
[0117] Among them, T n is the target time limit for each electronic device affected by a vulnerability to rectify the vulnerability, T1 is the candidate time limit corresponding to the electronic device with the vulnerability, and T 1i Indicates electronic device S i The corresponding target time limit.
[0118] S150: Issue vulnerability rectification tasks for each electronic device.
[0119] Specifically, after determining the target deadline for each electronic device with a vulnerability, a vulnerability remediation task can be generated and issued to each electronic device. The vulnerability remediation task requires that the vulnerability of each electronic device be remediated within the target deadline.
[0120] An embodiment of the present invention provides a vulnerability rectification method, which can first search for electronic devices with network security vulnerabilities, and then calculate the candidate time limit for rectifying the vulnerabilities for each electronic device based on the hazard level of the vulnerability. At this time, the determined candidate time limit cannot well clarify the corresponding urgency of each electronic device. The characteristic values presented by each electronic device in multiple asset dimensions can be calculated, and the candidate time limit of each electronic device can be adjusted according to the multiple characteristic values to obtain the target time limit for rectifying the vulnerabilities of each electronic device. A vulnerability rectification task is issued to each electronic device. The vulnerability rectification task requires that the vulnerabilities of each electronic device be rectified within the target time limit. The accuracy and real-time performance of the rectification time limit assessment of electronic devices with vulnerabilities can be effectively improved, and risks can be controlled in a timely and effective manner under limited labor cost conditions.
[0121] Example 2
[0122] Figure 2 A schematic diagram of the structure of a device for rectifying a vulnerability is provided, such as Figure 2 As shown, the device includes:
[0123] A search module 210 is used to search for electronic devices with network security vulnerabilities;
[0124] A candidate time limit calculation module 220 is configured to calculate a candidate time limit for rectifying the vulnerability for each electronic device based on the hazard level of the vulnerability;
[0125] A feature value calculation module 230 is configured to calculate the feature values of each electronic device in multiple asset dimensions;
[0126] An adjustment module 240 is configured to adjust the candidate time limit for each of the electronic devices according to the plurality of characteristic values to obtain a target time limit for rectifying the vulnerability of each of the electronic devices;
[0127] The issuing module 250 is configured to issue a vulnerability rectification task to each of the electronic devices, wherein the vulnerability rectification task requires that the vulnerability of each of the electronic devices be rectified within the target time limit.
[0128] In one embodiment, the search module 210 includes the following submodules:
[0129] A vulnerability information acquisition submodule is used to acquire vulnerability information published in a designated channel, wherein the vulnerability information includes first version information of software and / or hardware;
[0130] A second version information query submodule, configured to query the second version information of the software and / or hardware of each electronic device within a specified range;
[0131] The execution submodule is configured to determine that a network security vulnerability exists in a certain electronic device when the second version information of the electronic device is the same as the first version information.
[0132] In one embodiment, the candidate time limit calculation module 220 includes the following submodules:
[0133] The hazard level query submodule is used to query the hazard level of the vulnerability;
[0134] A first mapping submodule is configured to map the hazard level to an original time limit for configuring each electronic device to rectify the vulnerability, wherein the original time limit is negatively correlated with the hazard level;
[0135] An adjustment coefficient configuration submodule, configured to configure multiple adjustment coefficients for each of the electronic devices under multiple security dimensions respectively;
[0136] The candidate time limit determination submodule is configured to multiply the original time limit by a plurality of the adjustment coefficients for the same electronic device to obtain a candidate time limit for rectifying the vulnerability in the electronic device.
[0137] In one embodiment, the adjustment coefficient configuration submodule is specifically configured to:
[0138] Query how long the vulnerability has been published;
[0139] configuring an adjustment coefficient for each of the electronic devices according to the duration, wherein the adjustment coefficient is positively correlated with the duration;
[0140] Querying the security level of the network environment in which the electronic device is located;
[0141] configuring an adjustment coefficient for each electronic device according to the security level, wherein the adjustment coefficient is negatively correlated with the security level;
[0142] Querying the level of security impact of the vulnerability on the software and / or hardware of the electronic device;
[0143] An adjustment coefficient is configured for each electronic device according to the layer, and the external access authority at the module level is negatively correlated with the security level.
[0144] In one embodiment, the eigenvalue calculation module 230 includes the following submodules:
[0145] An asset information query submodule, configured to query asset information of each electronic device in multiple asset dimensions;
[0146] A second mapping submodule, configured to map the asset information into a characteristic value;
[0147] The eigenvalue writing submodule is used to write the eigenvalues of the electronic devices into the same diagonal matrix for the same asset dimension.
[0148] In one embodiment,
[0149] The asset information query submodule is specifically used to:
[0150] querying asset category information, asset exposure information, and asset usage information for each of the electronic devices as asset information;
[0151] The asset category information includes business systems, information infrastructure, terminal equipment, and office peripherals;
[0152] The asset exposure information includes internet applications, a first intranet system that interacts with internet applications, a second intranet system that is accessed across regions, and a third intranet system that is accessed within a single region;
[0153] The asset usage information includes first usage information, second usage information, third usage information, and fourth usage information; the user level of the first usage information and the user level of the second usage information both belong to the first level, the user level of the third usage information and the user level of the fourth usage information both belong to the second level, and the first level is greater than the second level; the access level of the first usage information and the access level of the third usage information both belong to the third level, the access level of the second usage information and the access level of the fourth usage information both belong to the fourth level, and the third level is greater than the fourth level;
[0154] The second mapping submodule is specifically configured to:
[0155] Mapping the asset category information, the asset exposure information, and the asset usage information to asset values respectively;
[0156] The characteristic value of the business system is smaller than the characteristic value of the information infrastructure, the characteristic value of the information infrastructure is smaller than the characteristic value of the terminal device, and the characteristic value of the terminal device is smaller than the characteristic value of the office peripheral device;
[0157] The characteristic value of the Internet application is smaller than the characteristic value of the first intranet system, the characteristic value of the first intranet system is smaller than the characteristic value of the second intranet system, and the characteristic value of the second intranet system is smaller than the characteristic value of the third intranet system;
[0158] The characteristic value of the first usage information is smaller than the characteristic value of the second usage information, the characteristic value of the second usage information is smaller than the characteristic value of the third usage information, and the characteristic value of the third usage information is smaller than the characteristic value of the fourth usage information;
[0159] The writing characteristic value submodule is specifically used for:
[0160] Writing the characteristic values of each electronic device in the asset category information into a diagonal matrix;
[0161] Writing the eigenvalues of each electronic device in the asset exposure information into another diagonal matrix;
[0162] The eigenvalues of each electronic device in the asset usage information are written into another diagonal matrix.
[0163] In one embodiment, the adjustment module 240 is specifically configured to:
[0164] Multiply the candidate time limit of each electronic device with the diagonal matrix corresponding to the asset category information, the diagonal matrix corresponding to the asset exposure information, and the diagonal matrix corresponding to the asset usage information to obtain the target time limit for rectifying the vulnerability of each electronic device.
[0165] The vulnerability rectification device provided in the embodiment of the present invention can implement the vulnerability rectification method provided in the first embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the execution method.
[0166] Example 3
[0167] Figure 3 A schematic diagram of the structure of an electronic device 10 that can be used to implement an embodiment of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processing, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or claimed herein.
[0168] like Figure 3 As shown, the electronic device 10 includes at least one processor 11, and a memory connected to the at least one processor 11, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc., wherein the memory stores a computer program that can be executed by the at least one processor, and the processor 11 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 to the random access memory (RAM) 13. Various programs and data required for the operation of the electronic device 10 can also be stored in the RAM 13. The processor 11, ROM 12 and RAM 13 are connected to each other via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.
[0169] Multiple components in the electronic device 10 are connected to the I / O interface 15, including an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a magnetic disk, an optical disk, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.
[0170] Processor 11 can be any general-purpose and / or specialized processing component with processing and computing capabilities. Some examples of processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various specialized artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, digital signal processors (DSPs), and any other suitable processor, controller, microcontroller, etc. Processor 11 executes the various methods and processes described above, such as a vulnerability remediation method.
[0171] In some embodiments, a vulnerability rectification method may be implemented as a computer program, which is tangibly contained in a computer-readable storage medium, such as a storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed on the electronic device 10 via the ROM 12 and / or the communication unit 19. When the computer program is loaded into the RAM 13 and executed by the processor 11, one or more steps of the vulnerability rectification method described above may be performed. Alternatively, in other embodiments, the processor 11 may be configured to execute a vulnerability rectification method in any other appropriate manner (e.g., by means of firmware).
[0172] Various embodiments of the systems and techniques described herein can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), system-on-chip systems (SOCs), programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include being implemented in one or more computer programs that are executable and / or interpreted on a programmable system that includes at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.
[0173] Computer programs for implementing the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the computer program is executed by the processor, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The computer program may be executed entirely on the machine, partially on the machine, as a stand-alone software package, partially on the machine and partially on a remote machine, or entirely on a remote machine or server.
[0174] In the context of the present invention, computer-readable storage media can be tangible media that can contain or store a computer program for use with an instruction execution system, device or equipment or used in combination with an instruction execution system, device or equipment. Computer-readable storage media can include but are not limited to electronic, magnetic, optical, electromagnetic, infrared or semiconductor systems, devices or equipment, or any suitable combination of the foregoing. Alternatively, computer-readable storage media can be machine-readable signal media. More specific examples of machine-readable storage media can include electrical connections based on one or more lines, portable computer disks, hard disks, random access memories (RAM), read-only memories (ROM), erasable programmable read-only memories (EPROM or flash memory), optical fibers, portable compact disk read-only memories (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0175] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user can provide input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).
[0176] The systems and techniques described herein can be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer with a graphical user interface or web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.
[0177] A computing system may include clients and servers. The clients and servers are typically remote from each other and typically interact via a communication network. This client-server relationship arises through computer programs running on the respective computers, creating a client-server relationship. The server may be a cloud server, also known as a cloud computing server or cloud host. This server is a hosting product within the cloud computing service ecosystem that addresses the management difficulties and limited scalability of traditional physical hosting and VPS services.
[0178] It should be understood that the various forms of the processes shown above can be used to reorder, add, or delete steps. For example, the steps described in the present invention can be performed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of the present invention can be achieved. This is not limited herein.
[0179] The above specific embodiments do not limit the scope of protection of the present invention. Those skilled in the art will appreciate that various modifications, combinations, sub-combinations, and substitutions may be made based on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention are intended to be included within the scope of protection of the present invention.
Claims
1. A method for rectifying a vulnerability, characterized in that: include: Find electronic devices with network security vulnerabilities; Calculating a candidate time limit for rectifying the vulnerability for each electronic device according to the hazard level of the vulnerability; Calculating characteristic values of each of the electronic devices in multiple asset dimensions; Adjusting the candidate time limit for each of the electronic devices according to the plurality of characteristic values to obtain a target time limit for rectifying the vulnerability in each of the electronic devices; issuing vulnerability rectification tasks for each of the electronic devices, wherein the vulnerability rectification tasks require rectification of the vulnerability of each of the electronic devices within the target time limit; The calculating of the characteristic values of each electronic device in multiple asset dimensions includes: querying asset category information, asset exposure information, and asset usage information for each of the electronic devices as asset information; Asset category information includes business systems, information infrastructure, terminal equipment, and office peripherals; asset exposure information includes internet applications, first intranet systems that interact with internet applications, second intranet systems accessed across regions, and third intranet systems accessed within a single region; Mapping the asset category information, the asset exposure information, and the asset usage information to characteristic values respectively; For the same asset dimension, the characteristic values of the electronic devices are written into the same diagonal matrix.
2. The method according to claim 1, characterized in that The step of searching for electronic devices with network security vulnerabilities includes: Obtain vulnerability information published in a designated channel, the vulnerability information including first version information of software and / or hardware; Query the second version information of the software and / or hardware of each electronic device within a specified range; If the second version information of a certain electronic device is the same as the first version information, it is determined that the electronic device has a network security vulnerability.
3. The method according to claim 1, characterized in that The calculating of a candidate time limit for rectifying the vulnerability for each electronic device according to the hazard level of the vulnerability includes: Query the severity level of the vulnerability; Mapping the hazard level to an original time limit for configuring each electronic device to rectify the vulnerability, wherein the original time limit is negatively correlated with the hazard level; configuring a plurality of adjustment coefficients for each of the electronic devices under a plurality of security dimensions respectively; For the same electronic device, the original time limit is multiplied by a plurality of the adjustment coefficients to obtain a candidate time limit for rectifying the vulnerability in the electronic device.
4. The method according to claim 3, characterized in that The configuring multiple adjustment coefficients for each of the electronic devices under multiple security dimensions includes: Query how long the vulnerability has been published; configuring an adjustment coefficient for each of the electronic devices according to the duration, wherein the adjustment coefficient is positively correlated with the duration; Querying the security level of the network environment in which the electronic device is located; configuring an adjustment coefficient for each electronic device according to the security level, wherein the adjustment coefficient is negatively correlated with the security level; Querying the level of security impact of the vulnerability on the software and / or hardware of the electronic device; An adjustment coefficient is configured for each electronic device according to the layer, and the external access authority at the module level is negatively correlated with the security level.
5. The method according to claim 1, wherein The querying of asset information of each electronic device in multiple asset dimensions further includes: The asset usage information includes first usage information, second usage information, third usage information, and fourth usage information; the user level of the first usage information and the user level of the second usage information both belong to the first level, the user level of the third usage information and the user level of the fourth usage information both belong to the second level, and the first level is greater than the second level; the access level of the first usage information and the access level of the third usage information both belong to the third level, the access level of the second usage information and the access level of the fourth usage information both belong to the fourth level, and the third level is greater than the fourth level; Mapping the asset information into characteristic values further includes: The characteristic value of the business system is smaller than the characteristic value of the information infrastructure, the characteristic value of the information infrastructure is smaller than the characteristic value of the terminal device, and the characteristic value of the terminal device is smaller than the characteristic value of the office peripheral device; The characteristic value of the Internet application is smaller than the characteristic value of the first intranet system, the characteristic value of the first intranet system is smaller than the characteristic value of the second intranet system, and the characteristic value of the second intranet system is smaller than the characteristic value of the third intranet system; The characteristic value of the first usage information is smaller than the characteristic value of the second usage information, the characteristic value of the second usage information is smaller than the characteristic value of the third usage information, and the characteristic value of the third usage information is smaller than the characteristic value of the fourth usage information; For the same asset dimension, writing the eigenvalues of the electronic devices into the same diagonal matrix includes: Writing the characteristic values of each electronic device in the asset category information into a diagonal matrix; Writing the eigenvalues of each electronic device in the asset exposure information into another diagonal matrix; The eigenvalues of each electronic device in the asset usage information are written into another diagonal matrix.
6. The method according to claim 5, characterized in that The step of adjusting the candidate time limit for each electronic device according to the plurality of characteristic values to obtain a target time limit for rectifying the vulnerability of each electronic device includes: Multiply the candidate time limit of each electronic device with the diagonal matrix corresponding to the asset category information, the diagonal matrix corresponding to the asset exposure information, and the diagonal matrix corresponding to the asset usage information to obtain the target time limit for rectifying the vulnerability of each electronic device.
7. A device for rectifying a vulnerability, characterized in that: include: A search module, used to search for electronic devices with network security vulnerabilities; a candidate time limit calculation module, configured to calculate a candidate time limit for rectifying the vulnerability for each electronic device according to the hazard level of the vulnerability; a characteristic value calculation module, configured to calculate characteristic values presented by each of the electronic devices in multiple asset dimensions; an adjustment module, configured to adjust the candidate time limit for each of the electronic devices according to the plurality of characteristic values to obtain a target time limit for rectifying the vulnerability of each of the electronic devices; a publishing module, configured to publish a vulnerability rectification task to each of the electronic devices, wherein the vulnerability rectification task requires rectification of the vulnerability of each of the electronic devices within the target time limit; The eigenvalue calculation module includes the following submodules: An asset information query submodule, configured to query asset information of each electronic device in multiple asset dimensions; A second mapping submodule, configured to map the asset information into a characteristic value; a writing eigenvalue submodule, configured to write the eigenvalues of the electronic devices into the same diagonal matrix for the same asset dimension; The asset information query submodule is specifically used to: querying asset category information, asset exposure information, and asset usage information for each of the electronic devices as asset information; The asset category information includes business systems, information infrastructure, terminal equipment, and office peripherals; The asset exposure information includes internet applications, a first intranet system that interacts with internet applications, a second intranet system that is accessed across regions, and a third intranet system that is accessed within a single region; The second mapping submodule is specifically configured to: The asset category information, the asset exposure information, and the asset usage information are mapped to feature values respectively.
8. An electronic device, characterized in that: The electronic device comprises: At least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can perform a vulnerability rectification method according to any one of claims 1 to 6.
9. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement a vulnerability rectification method according to any one of claims 1 to 6 when executed.
Citation Information
Patent Citations
Vulnerability processing method and device, equipment and readable storage medium
CN113886840A
Vulnerability priority processing method based on deep reinforcement learning
CN115396156A