Vulnerability repair verification method, device, equipment and readable storage medium
Through automated verification methods, the system automatically determines the vulnerability repair status, solving the problem of low efficiency of manual verification and achieving efficient and timely vulnerability repair verification.
Patent Information
- Application Number
- CN202310343374.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-03-31
- Publication Date
- 2025-09-30
- Estimated Expiration
- 2043-03-31
AI Technical Summary
In the existing technology, the verification process of Web security vulnerability repair is time-consuming, and manual verification is inefficient, and vulnerability rollback cannot be discovered in a timely manner.
An automated method is used to automatically determine the vulnerability repair status through the system, and the existence or non-existence of the vulnerability is verified using the request packet and return packet. The scheduled verification task is configured to realize automated vulnerability repair status verification.
It reduces the verification tasks of vulnerability verifiers, improves verification efficiency, timely discovers possible vulnerability rollbacks, and ensures the accuracy and timeliness of vulnerability repairs.
Smart Images

Figure CN116319042B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of vulnerability repair technology, and in particular to a vulnerability repair verification method, apparatus, device, and readable storage medium. Background Art
[0002] Currently, the industry typically manually verifies the status of web security vulnerability fixes after they've been released. This verification process requires personnel to complete a full user login, crawl relevant interfaces / URLs, construct attack request packets, verify the contents of the returned packets, and ultimately determine whether the fix is successful. Manual verification of vulnerability fixes is time-consuming, resulting in inefficient verification. Furthermore, if the vulnerability fix verifier happens to be without a computer or tools, they may not be able to perform the verification. Furthermore, some security vulnerabilities can reappear due to system changes or code rollbacks, potentially preventing them from detecting them in time. Summary of the Invention
[0003] The purpose of the present invention is to provide a vulnerability repair verification method, device, equipment and readable storage medium to improve the above-mentioned problems.
[0004] In order to achieve the above objectives, the embodiments of the present application provide the following technical solutions:
[0005] On the one hand, an embodiment of the present application provides a vulnerability repair verification method, the method comprising:
[0006] Obtaining a first request packet sent by a vulnerability verification person, and sending a first return packet to the vulnerability verification person, wherein the first return packet is used to trigger the vulnerability verification person to determine whether a vulnerability exists based on the first request packet and the first return packet, and obtain a result of vulnerability existence or vulnerability non-existence, wherein the result of vulnerability existence is used to trigger maintenance of vulnerability verification rules in the vulnerability verification server, and obtain the maintained vulnerability verification rules;
[0007] Receive a second request packet sent by the vulnerability verification server, and send a second return packet to the vulnerability verification server, the second return packet is used to trigger the vulnerability verification server to verify the vulnerability repair status according to the second return packet and the maintained vulnerability verification rules to obtain a first verification result.
[0008] Optionally, the result of the vulnerability existence is used to trigger maintenance of vulnerability verification rules in the vulnerability verification server, and the maintained vulnerability verification rules are obtained, including:
[0009] When the vulnerability verification personnel obtains the result that the vulnerability exists, the vulnerability verification personnel is triggered to send a third request packet to the test environment server. The third request packet is used to trigger the test environment server to send a third return packet to the vulnerability verification personnel. The third return packet is used to trigger the vulnerability verification personnel to maintain the vulnerability verification rules in the vulnerability verification server to obtain the maintained vulnerability verification rules.
[0010] Optionally, the third return packet is used to trigger the vulnerability verification personnel to maintain the vulnerability verification rules in the vulnerability verification server to obtain the maintained vulnerability verification rules, including:
[0011] After the vulnerability verifier receives the third return package, the vulnerability verifier is triggered to mark the key fields of vulnerability repair according to the first return package and the third return package to obtain the key fields of vulnerability repair; and use the key fields of vulnerability repair to maintain the vulnerability verification rules in the vulnerability verification server to obtain the maintained vulnerability verification rules.
[0012] Optionally, the receiving of a second request packet sent by the vulnerability verification server and the sending of a second return packet to the vulnerability verification server, wherein the second return packet is used to trigger the vulnerability verification server to verify the vulnerability repair status according to the second return packet and the maintained vulnerability verification rule, and after obtaining the first verification result, further includes:
[0013] When the vulnerability verification server obtains the first verification result, the vulnerability verification personnel is triggered to configure a timed verification task for the vulnerability verification server; the timed verification task is used to trigger the vulnerability verification server to automatically send a fourth request packet to the production environment server at a specified time node, and the fourth request is used to trigger the production environment server to send a fourth return packet to the vulnerability verification server, and the fourth return packet is used to trigger the vulnerability verification server to verify the vulnerability repair status according to the fourth return packet and the maintained vulnerability verification rules to obtain a second verification result.
[0014] Optionally, the receiving of a third request packet sent by the vulnerability verification server and the sending of a third return packet to the vulnerability verification server, wherein the third return packet is used to trigger the vulnerability verification server to verify the vulnerability repair status according to the third return packet and the maintained vulnerability verification rule, and after obtaining the first verification result, further comprising:
[0015] When the vulnerability verification server obtains the first verification result, it triggers the vulnerability verification server to generate different prompt information according to the first verification result, and sends the prompt information to the vulnerability verification personnel. The prompt information is used to trigger the vulnerability verification personnel to perform corresponding processing according to the prompt information.
[0016] Optionally, before the vulnerability existence result is used to trigger maintenance of vulnerability verification rules in the vulnerability verification server, the method further includes:
[0017] When the vulnerability verification personnel obtains the result that the vulnerability exists, the vulnerability verification personnel is triggered to determine whether a login account and password are required to maintain the vulnerability verification rules in the vulnerability verification server, and obtains a result that a login account and password are required or a result that a login account and password are not required. The result that a login account and password are required is used to trigger the vulnerability verification personnel to configure the login account and password for the vulnerability verification server.
[0018] In a second aspect, an embodiment of the present application provides a device for verifying vulnerability repair status, which includes an acquisition module and a receiving module.
[0019] The acquisition module is used to acquire a first request packet sent by a vulnerability verification person and send a first return packet to the vulnerability verification person, wherein the first return packet is used to trigger the vulnerability verification person to determine whether a vulnerability exists based on the first request packet and the first return packet, and obtain a result of vulnerability existence or vulnerability non-existence, and the result of vulnerability existence is used to trigger maintenance of vulnerability verification rules in the vulnerability verification server to obtain the maintained vulnerability verification rules;
[0020] The receiving module is used to receive a second request packet sent by the vulnerability verification server and send a second return packet to the vulnerability verification server. The second return packet is used to trigger the vulnerability verification server to verify the vulnerability repair status according to the second return packet and the maintained vulnerability verification rules to obtain a first verification result.
[0021] Optionally, the acquisition module includes:
[0022] The first trigger unit is used to trigger the vulnerability verifier to send a third request packet to the test environment server when the vulnerability verifier obtains the result that the vulnerability exists. The third request packet is used to trigger the test environment server to send a third return packet to the vulnerability verifier. The third return packet is used to trigger the vulnerability verifier to maintain the vulnerability verification rules in the vulnerability verification server to obtain the maintained vulnerability verification rules.
[0023] Optionally, the first triggering unit includes:
[0024] The triggering sub-unit is used to trigger the vulnerability verifier to mark the key fields of vulnerability repair according to the first return package and the third return package after the vulnerability verifier receives the third return package, so as to obtain the key fields of vulnerability repair; and use the key fields of vulnerability repair to maintain the vulnerability verification rules in the vulnerability verification server to obtain the maintained vulnerability verification rules.
[0025] Optionally, the device further includes:
[0026] The first trigger module is used to trigger the vulnerability verification personnel to configure a timed verification task for the vulnerability verification server when the vulnerability verification server obtains the first verification result; the timed verification task is used to trigger the vulnerability verification server to automatically send a fourth request packet to the production environment server at a specified time node, and the fourth request is used to trigger the production environment server to send a fourth return packet to the vulnerability verification server, and the fourth return packet is used to trigger the vulnerability verification server to verify the vulnerability repair status according to the fourth return packet and the vulnerability verification rules after maintenance to obtain a second verification result.
[0027] Optionally, the device further includes:
[0028] The second trigger module is used to trigger the vulnerability verification server to generate different prompt information according to the first verification result when the vulnerability verification server obtains the first verification result, and send the prompt information to the vulnerability verification personnel. The prompt information is used to trigger the vulnerability verification personnel to perform corresponding processing according to the prompt information.
[0029] Optionally, the acquisition module includes:
[0030] The second triggering unit is used to trigger the vulnerability verification personnel to determine whether a login account and password are required to maintain the vulnerability verification rules in the vulnerability verification server when the vulnerability verification personnel obtains the result that the vulnerability exists, and obtain a result that a login account and password are required or a result that a login account and password are not required. The result that a login account and password are required is used to trigger the vulnerability verification personnel to configure the login account and password for the vulnerability verification server.
[0031] In a third aspect, embodiments of the present application provide a vulnerability repair verification device, comprising a memory and a processor. The memory is configured to store a computer program; the processor is configured to implement the steps of the vulnerability repair verification method described above when executing the computer program.
[0032] In a fourth aspect, an embodiment of the present application provides a readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the above-mentioned vulnerability repair verification method are implemented.
[0033] The beneficial effects of the present invention are:
[0034] The present invention adopts an automatic verification method, in which the system automatically determines the vulnerability repair status, which can reduce the verification tasks of vulnerability verifiers, and can regularly check the repair results through scheduled tasks to promptly discover possible vulnerability rollbacks.
[0035] Other features and advantages of the present invention will be described in the following description, and in part will become apparent from the description, or understood by practicing the embodiments of the present invention. The purposes and other advantages of the present invention can be realized and obtained by the structures particularly pointed out in the written description, claims, and drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0036] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the embodiments. It should be understood that the following drawings only illustrate certain embodiments of the present invention and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other relevant drawings can be obtained based on these drawings without paying any creative work.
[0037] Figure 1 1 is a flow chart of a vulnerability repair verification method according to an embodiment of the present invention;
[0038] Figure 2 Schematic diagram of the structure of the vulnerability repair verification device according to an embodiment of the present invention;
[0039] Figure 3 Schematic diagram of the structure of the vulnerability repair verification device described in an embodiment of the present invention. DETAILED DESCRIPTION
[0040] In order to make the purpose, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. The components of the embodiments of the present invention generally described and shown in the drawings herein can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present invention provided in the drawings is not intended to limit the scope of the claimed invention, but merely represents selected embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention.
[0041] It should be noted that similar reference numerals or letters represent similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined or explained in subsequent drawings. At the same time, in the description of the present invention, the terms "first", "second", etc. are only used to distinguish the description and should not be understood as indicating or implying relative importance.
[0042] Example 1
[0043] like Figure 1 As shown, this embodiment provides a vulnerability repair verification method, which includes step S1 and step S2.
[0044] Step S1: Obtain a first request packet sent by a vulnerability verification person, and send a first return packet to the vulnerability verification person, wherein the first return packet is used to trigger the vulnerability verification person to determine whether a vulnerability exists based on the first request packet and the first return packet, and obtain a result of vulnerability existence or vulnerability non-existence. The result of vulnerability existence is used to trigger maintenance of vulnerability verification rules in the vulnerability verification server, and obtain the maintained vulnerability verification rules;
[0045] Step S2: Receive a second request packet sent by the vulnerability verification server, and send a second return packet to the vulnerability verification server. The second return packet is used to trigger the vulnerability verification server to verify the vulnerability repair status according to the second return packet and the maintained vulnerability verification rules to obtain the first verification result.
[0046] This embodiment adopts an automatic verification method, and the system automatically determines the vulnerability repair status, which can reduce the verification tasks of vulnerability verifiers and regularly check the repair results through scheduled tasks to promptly discover possible vulnerability rollbacks.
[0047] In a specific embodiment of the present disclosure, the step S1 may further include step S11.
[0048] Step S11: When the vulnerability verification personnel obtains the result that the vulnerability exists, the vulnerability verification personnel is triggered to send a third request packet to the test environment server. The third request packet is used to trigger the test environment server to send a third return packet to the vulnerability verification personnel. The third return packet is used to trigger the vulnerability verification personnel to maintain the vulnerability verification rules in the vulnerability verification server to obtain the maintained vulnerability verification rules.
[0049] In this embodiment, the vulnerability verification rules are maintained to obtain the maintained vulnerability verification rules, which can improve the accuracy of the vulnerability verification results.
[0050] In a specific embodiment of the present disclosure, the step S1 may further include step S12.
[0051] Step S12: When the vulnerability verification personnel obtains the result that the vulnerability exists, the vulnerability verification personnel is triggered to determine whether a login account and password are required to maintain the vulnerability verification rules in the vulnerability verification server, and obtains a result that a login account and password are required or a result that a login account and password are not required. The result that a login account and password are required is used to trigger the vulnerability verification personnel to configure the login account and password for the vulnerability verification server.
[0052] In this embodiment, two methods are provided. One method requires an account and password to maintain the vulnerability verification rules in the vulnerability verification server, and the other method does not. By adopting this method, the applicability of the system can be improved and the operation can be more user-friendly.
[0053] In a specific embodiment of the present disclosure, the step S11 may further include step S111.
[0054] Step S111: After the vulnerability verifier receives the third return package, the vulnerability verifier is triggered to mark the key fields of vulnerability repair according to the first return package and the third return package to obtain the key fields of vulnerability repair; and the key fields of vulnerability repair are used to maintain the vulnerability verification rules in the vulnerability verification server to obtain the maintained vulnerability verification rules.
[0055] In a specific embodiment of the present disclosure, step S3 may be further included after step S2.
[0056] Step S3: When the vulnerability verification server obtains the first verification result, the vulnerability verification personnel is triggered to configure a timed verification task for the vulnerability verification server; the timed verification task is used to trigger the vulnerability verification server to automatically send a fourth request packet to the production environment server at a specified time node, and the fourth request is used to trigger the production environment server to send a fourth return packet to the vulnerability verification server, and the fourth return packet is used to trigger the vulnerability verification server to verify the vulnerability repair status according to the fourth return packet and the vulnerability verification rules after maintenance to obtain a second verification result.
[0057] In this embodiment, by setting a scheduled verification task, the repair results can be regularly checked through the scheduled task, and possible vulnerability rollback situations can be discovered in a timely manner.
[0058] In a specific embodiment of the present disclosure, step S4 may be further included after step S2.
[0059] Step S4: When the vulnerability verification server obtains the first verification result, it triggers the vulnerability verification server to generate different prompt information according to the first verification result, and sends the prompt information to the vulnerability verification personnel. The prompt information is used to trigger the vulnerability verification personnel to perform corresponding processing according to the prompt information.
[0060] In this embodiment, the verification result can be sent by email or text message. By sending the verification result to the vulnerability verification personnel, the vulnerability verification personnel can obtain the vulnerability repair status in a timely manner, thereby facilitating the deployment of subsequent work.
[0061] Example 2
[0062] This embodiment provides a vulnerability repair verification method, which includes:
[0063] Step S1: The vulnerability verification personnel sends a first request packet to the production environment server;
[0064] Step S2: The production environment server receives the first request packet and sends a first return packet to the vulnerability verification personnel;
[0065] Step S3: The vulnerability verification personnel determines whether a vulnerability exists based on the contents of the first request packet and the first return packet;
[0066] Step S4: If the vulnerability exists, the vulnerability verification personnel sends a second request packet to the test environment server;
[0067] Step S5: The test environment server receives the second request packet and sends a second return packet to the vulnerability verifier;
[0068] Step S6: The vulnerability verification personnel marks the key fields for determining vulnerability repair based on the difference between the first return package and the second return package, maintains the vulnerability verification rules on the vulnerability verification server, and obtains the maintained vulnerability verification rules. If a login account and password are required when maintaining the vulnerability verification rules on the vulnerability verification server, the vulnerability verification personnel configures the login account and password for the vulnerability verification server.
[0069] Step S7: The vulnerability verification server sends a third request packet to the production environment server;
[0070] Step S8: The production environment server receives the third request packet and sends a third return packet to the vulnerability verification server;
[0071] Step S9: The vulnerability verification server determines the vulnerability repair status based on the third return package and the vulnerability verification rules after maintenance, and pushes the vulnerability repair status to the vulnerability verification personnel in real time via email or other means;
[0072] Step S10: The vulnerability verification personnel configures information of a scheduled verification task on the vulnerability verification server;
[0073] Step S11: The vulnerability verification server automatically sends a fourth request packet to the production environment server at the time specified by the scheduled verification task;
[0074] Step S12: The production environment server receives the fourth request packet and sends a fourth return packet to the vulnerability verification server;
[0075] Step S13: The vulnerability verification server re-determines the vulnerability repair status based on the fourth return package and the maintained vulnerability verification rules, and pushes the newly obtained vulnerability repair status to the vulnerability verification personnel in real time again via email or other means.
[0076] This embodiment adopts an automatic verification method. The vulnerability verifier only needs to provide a vulnerability verification request and create vulnerability verification rules. The system will automatically determine the vulnerability repair status, which can reduce the verification tasks of the vulnerability verifier. The system can also regularly check the repair results through scheduled tasks to promptly discover possible vulnerability rollbacks.
[0077] Example 3
[0078] like Figure 2 As shown, this embodiment provides a vulnerability repair status verification device, which includes an acquisition module 701 and a receiving module 702.
[0079] The acquisition module 701 is used to obtain a first request packet sent by a vulnerability verification person and send a first return packet to the vulnerability verification person. The first return packet is used to trigger the vulnerability verification person to determine whether a vulnerability exists based on the first request packet and the first return packet, and obtain a result of vulnerability existence or vulnerability non-existence. The result of vulnerability existence is used to trigger maintenance of vulnerability verification rules in the vulnerability verification server to obtain the maintained vulnerability verification rules;
[0080] The receiving module 702 is used to receive a second request packet sent by the vulnerability verification server and send a second return packet to the vulnerability verification server. The second return packet is used to trigger the vulnerability verification server to verify the vulnerability repair status according to the second return packet and the maintained vulnerability verification rules to obtain a first verification result.
[0081] This device adopts an automatic verification method, and the system automatically determines the vulnerability repair status, which can reduce the verification tasks of vulnerability verifiers. It can also regularly check the repair results through scheduled tasks and promptly discover possible vulnerability rollbacks.
[0082] In a specific implementation of the present disclosure, the acquisition module 701 includes a first triggering unit 7011 .
[0083] The first trigger unit 7011 is used to trigger the vulnerability verifier to send a third request packet to the test environment server when the vulnerability verifier obtains the result that the vulnerability exists. The third request packet is used to trigger the test environment server to send a third return packet to the vulnerability verifier. The third return packet is used to trigger the vulnerability verifier to maintain the vulnerability verification rules in the vulnerability verification server to obtain the maintained vulnerability verification rules.
[0084] In a specific implementation of the present disclosure, the acquisition module 701 includes a second triggering unit 7012 .
[0085] The second trigger unit 7012 is used to trigger the vulnerability verification personnel to determine whether a login account and password are required to maintain the vulnerability verification rules in the vulnerability verification server when the vulnerability verification personnel obtains the result that the vulnerability exists, and obtain a result that a login account and password are required or a result that a login account and password are not required. The result that a login account and password are required is used to trigger the vulnerability verification personnel to configure the login account and password for the vulnerability verification server.
[0086] In a specific embodiment of the present disclosure, the first triggering unit 7011 includes a triggering subunit 70111 .
[0087] The trigger sub-unit 70111 is used to trigger the vulnerability verifier to mark the key fields of vulnerability repair according to the first return package and the third return package after the vulnerability verifier receives the third return package, so as to obtain the key fields of vulnerability repair; and use the key fields of vulnerability repair to maintain the vulnerability verification rules in the vulnerability verification server to obtain the maintained vulnerability verification rules.
[0088] In a specific implementation of the present disclosure, the apparatus further includes a first trigger module 703 .
[0089] The first trigger module 703 is used to trigger the vulnerability verification personnel to configure a timed verification task for the vulnerability verification server when the vulnerability verification server obtains the first verification result; the timed verification task is used to trigger the vulnerability verification server to automatically send a fourth request packet to the production environment server at a specified time node, and the fourth request is used to trigger the production environment server to send a fourth return packet to the vulnerability verification server, and the fourth return packet is used to trigger the vulnerability verification server to verify the vulnerability repair status according to the fourth return packet and the vulnerability verification rules after maintenance to obtain a second verification result.
[0090] In a specific embodiment of the present disclosure, the apparatus further includes a second trigger module 704 .
[0091] The second trigger module 704 is used to trigger the vulnerability verification server to generate different prompt information according to the first verification result when the vulnerability verification server obtains the first verification result, and send the prompt information to the vulnerability verification personnel. The prompt information is used to trigger the vulnerability verification personnel to perform corresponding processing according to the prompt information.
[0092] It should be noted that, regarding the apparatus in the above embodiment, the specific manner in which each module performs operations has been described in detail in the embodiment of the method, and will not be elaborated on here.
[0093] Example 4
[0094] Corresponding to the above method embodiment, the embodiment of the present disclosure further provides a vulnerability repair situation verification device. The vulnerability repair situation verification device described below and the vulnerability repair situation verification method described above can refer to each other.
[0095] Figure 3 FIG. 8 is a block diagram of a vulnerability repair verification device 800 according to an exemplary embodiment. Figure 3As shown, the vulnerability repair verification device 800 may include: a processor 801 and a memory 802. The vulnerability repair verification device 800 may also include one or more of a multimedia component 803, an input / output (I / O) interface 804, and a communication component 805.
[0096] The processor 801 is used to control the overall operation of the vulnerability repair verification device 800 to complete all or part of the steps in the vulnerability repair verification method described above. The memory 802 is used to store various types of data to support the operation of the vulnerability repair verification device 800. This data may include, for example, instructions for any application or method operating on the vulnerability repair verification device 800, as well as application-related data such as contact data, sent and received messages, pictures, audio, video, etc. The memory 802 can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk or optical disk. The multimedia component 803 may include a screen and an audio component. The screen may be, for example, a touch screen, and the audio component is used to output and / or input audio signals. For example, the audio component may include a microphone for receiving external audio signals. The received audio signal may be further stored in the memory 802 or transmitted via the communication component 805. The audio component also includes at least one speaker for outputting audio signals. The I / O interface 804 provides an interface between the processor 801 and other interface modules, which may be a keyboard, a mouse, buttons, etc. These buttons may be virtual buttons or physical buttons. The communication component 805 is used for wired or wireless communication between the vulnerability repair verification device 800 and other devices. Wireless communication, such as Wi-Fi, Bluetooth, Near Field Communication (NFC), 2G, 3G or 4G, or a combination of one or more of them, so the corresponding communication component 805 may include: a Wi-Fi module, a Bluetooth module, an NFC module.
[0097] In an exemplary embodiment, the vulnerability repair verification device 800 can be implemented by one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors, or other electronic components to perform the above-mentioned vulnerability repair verification method.
[0098] In another exemplary embodiment, a computer-readable storage medium including program instructions is also provided. When executed by a processor, the program instructions implement the steps of the vulnerability remediation verification method described above. For example, the computer-readable storage medium may be the aforementioned memory 802 including the program instructions. The program instructions may be executed by the processor 801 of the vulnerability remediation verification device 800 to perform the vulnerability remediation verification method described above.
[0099] Example 5
[0100] Corresponding to the above method embodiment, the embodiment of the present disclosure further provides a readable storage medium. The readable storage medium described below and the vulnerability repair verification method described above can refer to each other.
[0101] A readable storage medium stores a computer program, which, when executed by a processor, implements the steps of the vulnerability repair verification method of the above method embodiment.
[0102] The readable storage medium may specifically be any readable storage medium that can store program code, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.
[0103] The foregoing description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. Those skilled in the art will readily appreciate that various modifications and variations of the present invention are possible. Any modifications, equivalent substitutions, or improvements made within the spirit and principles of the present invention are intended to be within the scope of protection of the present invention.
Claims
1. A vulnerability repair verification method, characterized in that: This method is applied to production environment servers and includes: Obtaining a first request packet sent by a vulnerability verification person, and sending a first return packet to the vulnerability verification person, wherein the first return packet is used to trigger the vulnerability verification person to determine whether a vulnerability exists based on the first request packet and the first return packet, and obtain a result of vulnerability existence or vulnerability non-existence, wherein the result of vulnerability existence is used to trigger maintenance of vulnerability verification rules in the vulnerability verification server, and obtain the maintained vulnerability verification rules; receiving a second request packet sent by the vulnerability verification server, and sending a second return packet to the vulnerability verification server, wherein the second return packet is used to trigger the vulnerability verification server to verify the vulnerability repair status according to the second return packet and the maintained vulnerability verification rules to obtain a first verification result; The result of the vulnerability existence is used to trigger maintenance of the vulnerability verification rules in the vulnerability verification server, and the maintained vulnerability verification rules are obtained, including: When the vulnerability verifier obtains the result that the vulnerability exists, the vulnerability verifier is triggered to send a third request packet to the test environment server, and the third request packet is used to trigger the test environment server to send a third return packet to the vulnerability verifier, and the third return packet is used to trigger the vulnerability verifier to maintain the vulnerability verification rules in the vulnerability verification server to obtain the maintained vulnerability verification rules; The third return packet is used to trigger the vulnerability verification personnel to maintain the vulnerability verification rules in the vulnerability verification server, and obtain the maintained vulnerability verification rules, including: After the vulnerability verifier receives the third return package, the vulnerability verifier is triggered to mark the key fields of vulnerability repair according to the first return package and the third return package to obtain the key fields of vulnerability repair; and use the key fields of vulnerability repair to maintain the vulnerability verification rules in the vulnerability verification server to obtain the maintained vulnerability verification rules.
2. The vulnerability repair verification method according to claim 1, characterized in that: The method further comprises: receiving a second request packet sent by the vulnerability verification server, and sending a second return packet to the vulnerability verification server, wherein the second return packet is used to trigger the vulnerability verification server to verify the vulnerability repair status according to the second return packet and the maintained vulnerability verification rule, and obtaining a first verification result, further comprising: When the vulnerability verification server obtains the first verification result, the vulnerability verification personnel is triggered to configure a timed verification task for the vulnerability verification server; the timed verification task is used to trigger the vulnerability verification server to automatically send a fourth request packet to the production environment server at a specified time node, and the fourth request is used to trigger the production environment server to send a fourth return packet to the vulnerability verification server, and the fourth return packet is used to trigger the vulnerability verification server to verify the vulnerability repair status according to the fourth return packet and the vulnerability verification rules after maintenance to obtain a second verification result.
3. The vulnerability repair verification method according to claim 1, characterized in that: The receiving of the third request packet sent by the vulnerability verification server and the sending of a third return packet to the vulnerability verification server, wherein the third return packet is used to trigger the vulnerability verification server to verify the vulnerability repair status according to the third return packet and the maintained vulnerability verification rule, and after obtaining the first verification result, further comprising: When the vulnerability verification server obtains the first verification result, it triggers the vulnerability verification server to generate different prompt information according to the first verification result, and sends the prompt information to the vulnerability verification personnel. The prompt information is used to trigger the vulnerability verification personnel to perform corresponding processing according to the prompt information.
4. The vulnerability repair verification method according to claim 1, characterized in that: Before the vulnerability existence result is used to trigger the maintenance of the vulnerability verification rules in the vulnerability verification server, the following steps are also included: When the vulnerability verification personnel obtains the result that the vulnerability exists, the vulnerability verification personnel is triggered to determine whether a login account and password are required to maintain the vulnerability verification rules in the vulnerability verification server, and obtains a result that a login account and password are required or a result that a login account and password are not required. The result that a login account and password are required is used to trigger the vulnerability verification personnel to configure the login account and password for the vulnerability verification server.
5. A production environment server, characterized in that: include: an acquisition module, configured to acquire a first request packet sent by a vulnerability verification person, and to send a first return packet to the vulnerability verification person, wherein the first return packet is used to trigger the vulnerability verification person to determine whether a vulnerability exists based on the first request packet and the first return packet, and obtain a result of vulnerability existence or vulnerability non-existence, wherein the result of vulnerability existence is used to trigger maintenance of vulnerability verification rules in the vulnerability verification server, and obtain the maintained vulnerability verification rules; a receiving module, configured to receive a second request packet sent by the vulnerability verification server, and send a second return packet to the vulnerability verification server, wherein the second return packet is used to trigger the vulnerability verification server to verify the vulnerability repair status according to the second return packet and the maintained vulnerability verification rules, and obtain a first verification result; The acquisition module includes: a first triggering unit configured to trigger the vulnerability verifier to send a third request packet to the test environment server when the vulnerability verifier obtains a result that the vulnerability exists, wherein the third request packet is used to trigger the test environment server to send a third return packet to the vulnerability verifier, and the third return packet is used to trigger the vulnerability verifier to maintain the vulnerability verification rules in the vulnerability verification server to obtain the maintained vulnerability verification rules; The first triggering unit includes: The triggering sub-unit is used to trigger the vulnerability verifier to mark the key fields of vulnerability repair according to the first return package and the third return package after the vulnerability verifier receives the third return package, so as to obtain the key fields of vulnerability repair; and use the key fields of vulnerability repair to maintain the vulnerability verification rules in the vulnerability verification server to obtain the maintained vulnerability verification rules.
6. The production environment server according to claim 5, characterized in that: The server further includes: The first trigger module is used to trigger the vulnerability verification personnel to configure a timed verification task for the vulnerability verification server when the vulnerability verification server obtains the first verification result; the timed verification task is used to trigger the vulnerability verification server to automatically send a fourth request packet to the production environment server at a specified time node, and the fourth request is used to trigger the production environment server to send a fourth return packet to the vulnerability verification server, and the fourth return packet is used to trigger the vulnerability verification server to verify the vulnerability repair status according to the fourth return packet and the vulnerability verification rules after maintenance to obtain a second verification result.
7. The production environment server according to claim 5, characterized in that: The server further includes: The second trigger module is used to trigger the vulnerability verification server to generate different prompt information according to the first verification result when the vulnerability verification server obtains the first verification result, and send the prompt information to the vulnerability verification personnel. The prompt information is used to trigger the vulnerability verification personnel to perform corresponding processing according to the prompt information.
8. The production environment server according to claim 5, characterized in that: The acquisition module includes: The second trigger unit is used to trigger the vulnerability verifier to determine whether a login account and password are required to maintain the vulnerability verification rules in the vulnerability verification server when the vulnerability verifier obtains the result that the vulnerability exists, and obtain a result that a login account and password are required or a result that a login account and password are not required. The result that a login account and password are required is used to trigger the vulnerability verifier to configure the login account and password for the vulnerability verification server.
9. Production environment server, characterized by, include: memory for storing computer programs; A processor, configured to implement the steps of the vulnerability repair verification method according to any one of claims 1 to 4 when executing the computer program.
10. A readable storage medium, characterized in that: The readable storage medium stores a computer program, which, when executed by a processor, implements the steps of the vulnerability repair verification method according to any one of claims 1 to 4.