A vulnerability assessment method and device for virtual resources, a storage medium and an electronic device

By performing basic and secondary ratings of virtual resources, and combining time factors, environmental factors, and virtual resource factors, the problem that CVSS vulnerability scoring cannot reflect the impact of the real environment is solved, thus achieving more accurate vulnerability assessment and open-source software risk management.

CN116961945BActive Publication Date: 2026-04-07ZTE CORP
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-04-18
Publication Date
2026-04-07

AI Technical Summary

Technical Problem

The existing CVSS vulnerability scoring system cannot objectively reflect the impact of vulnerabilities on the real environment, especially the actual risks of open source software under different operating systems, and cannot accurately assess the risks.

Method used

By obtaining basic vulnerability information of virtual resources, a basic score is determined, and a secondary score is determined by combining vulnerability time factors, environmental factors, and virtual resource factors, resulting in a more accurate vulnerability assessment result.

Benefits of technology

It improved the accuracy of vulnerability assessment, mitigated the risk of attacks on the open-source software supply chain, and enhanced the efficiency of open-source governance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116961945B_ABST
    Figure CN116961945B_ABST
Patent Text Reader

Abstract

The embodiment of the application provides a virtual resource vulnerability assessment method and device, a storage medium and an electronic device, the method comprises the following steps: obtaining the basic information of the vulnerability of the virtual resource, and performing basic score grading on the virtual resource according to the basic information of the vulnerability, to obtain a basic score; determining the vulnerability time factor score, the vulnerability environment factor score and the virtual asset factor score of the virtual resource according to the basic information of the vulnerability respectively; performing secondary vulnerability grading on the virtual asset according to the basic score, the vulnerability time factor score, the vulnerability environment factor score and the virtual asset factor score, to obtain a secondary grading result; and generating a vulnerability assessment result of the virtual resource according to the secondary grading result, which can solve the problem that the CVSS vulnerability score cannot objectively reflect the influence of the vulnerability on the real environment in the related art, and through the secondary vulnerability grading on the basic score, the final vulnerability assessment result is obtained, the risk of open source software supply chain attack is alleviated, and the efficiency of open source governance is improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] Embodiments of the present application relate to the field of communication, in particular to a vulnerability assessment method and device for virtual resources, a storage medium and an electronic device. BACKGROUND

[0002] The Common Vulnerability Scoring System (CVSS) is an open framework for communicating the characteristics and severity of software vulnerabilities. CVSS is composed of three groups of metrics: Base, Temporal, and Environmental. The Base group represents the intrinsic quality of the vulnerability that remains constant over time and across user environments, the Temporal group reflects the characteristics of the vulnerability that change over time, and the Environmental group represents the user-specific environment of the vulnerability characteristics. The base metrics produce a score ranging from 0 to 10, which can then be modified by scoring the temporal and environmental metrics.

[0003] The original CVSS score only contains the Base score, and lacks real impact analysis of the actual situation of the asset where the vulnerability is located, for example: CVE-2015-5652 is an escalation vulnerability of Python versions before 3.5.0, which can only be exploited in a Windows environment, but the Python version containing the vulnerability is deployed on a Linux server, which is actually not at risk. The environmental factor option of CVSS cannot fully cover the threat surface, such as the probability of actual environmental attack events and the use of components containing vulnerabilities. And CVSS does not consider the importance of assets, and cannot accurately assess the risk.

[0004] In view of the problem that the CVSS vulnerability score in the related art cannot objectively reflect the impact of the vulnerability on the real environment, no solution has been proposed. SUMMARY

[0005] Embodiments of the present application provide a vulnerability assessment method and device for virtual resources, a storage medium and an electronic device to at least solve the problem that the CVSS vulnerability score in the related art cannot objectively reflect the impact of the vulnerability on the real environment.

[0006] According to an embodiment of the present application, a vulnerability assessment method for virtual resources is provided, the method comprising:

[0007] obtaining vulnerability basic information of a virtual resource, and performing basic score grading on the virtual resource according to the vulnerability basic information to obtain a basic score;

[0008] determining a vulnerability temporal factor score, a vulnerability environmental factor score and a virtual resource factor score of the virtual resource according to the vulnerability basic information, respectively;

[0009] secondary vulnerability rating of the virtual resource according to the base score, the vulnerability time factor score, the vulnerability environment factor score and the virtual resource factor score, to obtain a secondary rating result;

[0010] generating a vulnerability evaluation result of the virtual resource according to the secondary rating result.

[0011] In an embodiment, the method further comprises:

[0012] obtaining project version information and component version information of the open source component in which the virtual resource is located;

[0013] determining that corresponding vulnerability information does not exist in a vulnerability information library according to the project version information and the component version information, wherein the vulnerability information library stores vulnerability information of the open source component corresponding to component versions and project versions.

[0014] In an embodiment, the method further comprises:

[0015] obtaining a vulnerability evaluation result of the vulnerability information of the open source component from the vulnerability information library, when it is determined that corresponding vulnerability information exists in the vulnerability information library according to the project version and the component version;

[0016] determining the vulnerability evaluation result of the vulnerability information of the open source component as the vulnerability evaluation result of the virtual resource.

[0017] In an embodiment, obtaining vulnerability base information of the virtual resource comprises:

[0018] obtaining asset base information of the open source component in which the virtual resource is located;

[0019] obtaining the vulnerability base information of the virtual resource according to the project version information of the open source component in which the virtual resource is located and the asset base information.

[0020] In an embodiment, determining the vulnerability time factor score, the vulnerability environment factor score and the virtual resource factor score of the virtual resource according to the vulnerability base information respectively comprises:

[0021] obtaining a plurality of vulnerability time factors according to the vulnerability base information, determining scores corresponding to the plurality of vulnerability time factors according to time factor scores pre-set for each time factor, and determining the vulnerability time factor score according to the scores of the plurality of vulnerability time factors;

[0022] According to the vulnerability basic information, a plurality of vulnerability environment factors are acquired, scores corresponding to the plurality of vulnerability environment factors are determined according to environment factor scores previously set for each vulnerability environment factor, and the vulnerability environment factor score is determined according to the scores of the plurality of vulnerability environment factors.

[0023] According to the vulnerability basic information, a plurality of virtual resource factors are acquired, scores corresponding to the plurality of virtual resource factors are determined according to virtual resource factor scores previously set for each virtual resource factor, and the virtual resource factor score is determined according to the scores of the plurality of virtual resource factors.

[0024] In an embodiment, acquiring a plurality of vulnerability environment factors according to the vulnerability basic information comprises:

[0025] According to the vulnerability basic information, it is determined whether the vulnerability environment factors have been analyzed;

[0026] In a case where the determination result is no, the vulnerability environment factors are prompted to be perfected according to the asset basic information of the virtual resource, and the plurality of vulnerability environment factors after perfection are acquired;

[0027] In a case where the determination result is yes, the plurality of vulnerability environment factors are acquired.

[0028] In an embodiment, the method further comprises:

[0029] According to the basic score, the vulnerability time factor score, the vulnerability environment factor score, and the virtual resource factor score, the virtual resource is subjected to secondary vulnerability grading, and a secondary grading result is obtained, by:

[0030] ;

[0031] wherein, the secondary grading result is the product of the basic score, the vulnerability time factor score, and the vulnerability environment factor score, the virtual resource factor score, a threat coefficient, a specified number of digits, is a function of rounding up the position according to the specified number of digits.

[0032] According to another embodiment of the present application, a vulnerability evaluation device for a virtual resource is also provided, and the device comprises:

[0033] A first acquisition module is configured to acquire vulnerability basic information of a virtual resource, and to perform basic score grading on the virtual resource according to the vulnerability basic information, and to obtain a basic score. ​

[0034] The first determining module is configured to determine a vulnerability time factor score, a vulnerability environment factor score and a virtual resource factor score of the virtual resource according to the basic vulnerability information respectively.

[0035] The secondary grading module is configured to perform secondary vulnerability grading on the virtual resource according to the basic score, the vulnerability time factor score, the vulnerability environment factor score and the virtual resource factor score, and obtain a secondary grading result.

[0036] The generating module is configured to generate a vulnerability evaluation result of the virtual resource according to the secondary grading result.

[0037] In an embodiment, the apparatus further comprises:

[0038] The second obtaining module is configured to obtain project version information and component version information of the open source component in which the virtual resource is located.

[0039] The second determining module is configured to determine that corresponding vulnerability information does not exist in a vulnerability information library according to the project version information and the component version information, wherein the vulnerability information library stores vulnerability information of open source components corresponding to component versions and project versions.

[0040] In an embodiment, the apparatus further comprises:

[0041] The third obtaining module is configured to, when it is determined that corresponding vulnerability information exists in the vulnerability information library according to the project version and the component version, obtain a vulnerability evaluation result of the vulnerability information of the open source component from the vulnerability information library.

[0042] The third determining module is configured to determine the vulnerability evaluation result of the vulnerability information of the open source component as the vulnerability evaluation result of the virtual resource.

[0043] In an embodiment, the first obtaining module is further configured to obtain asset basic information of the open source component in which the virtual resource is located; and obtain the basic vulnerability information of the virtual resource according to the project version information of the open source component in which the virtual resource is located and the asset basic information.

[0044] In an embodiment, the first determining module comprises:

[0045] The first determining submodule is configured to obtain a plurality of vulnerability time factors according to the basic vulnerability information, determine scores corresponding to the plurality of vulnerability time factors according to time factor scores pre-set for each time factor, and determine the vulnerability time factor score according to the scores of the plurality of vulnerability time factors.

[0046] a second determining sub-module, configured to acquire a plurality of vulnerability environment factors according to the vulnerability basic information, determine scores corresponding to the plurality of vulnerability environment factors according to environment factor scores pre-set for each of the vulnerability environment factors, and determine the vulnerability environment factor score according to the scores of the plurality of vulnerability environment factors;

[0047] a third determining sub-module, configured to acquire a plurality of virtual resource factors according to the vulnerability basic information, determine scores corresponding to the plurality of virtual resource factors according to virtual resource factor scores pre-set for each of the virtual resource factors, and determine the virtual resource factor score according to the scores of the plurality of virtual resource factors.

[0048] In an embodiment, the second determining module is further configured to

[0049] determine whether the vulnerability environment factors have been analyzed according to the vulnerability basic information;

[0050] if the determination result is no, prompt to perfect the vulnerability environment factors according to the asset basic information of the virtual resource, and acquire the plurality of vulnerability environment factors after the perfection;

[0051] if the determination result is yes, acquire the plurality of vulnerability environment factors.

[0052] In an embodiment, the twice grading module is further configured to perform twice vulnerability grading on the virtual resource according to the basic score, the vulnerability time factor score, the vulnerability environment factor score and the virtual resource factor score to obtain a twice grading result, in the following manner:

[0053] ;

[0054] wherein, the twice grading result is the product of the basic score, the vulnerability time factor score and the vulnerability environment factor score, the virtual resource factor score, a threat coefficient, a specified number of digits, a function of rounding up the position according to the specified number of digits.

[0055] According to still another embodiment of the present application, a computer readable storage medium is provided, in which a computer program is stored, wherein the computer program is configured to execute the steps in any of the above method embodiments when running.

[0056] ​According to another embodiment of the present application, an electronic device is also provided, comprising a memory and a processor, the memory storing a computer program, and the processor is configured to run the computer program to perform the steps in any of the above method embodiments.

[0057] According to the embodiment of the present application, the vulnerability basic information of the virtual resource is acquired, and the virtual resource is basic score graded according to the vulnerability basic information to obtain a basic score; the vulnerability time factor score, the vulnerability environment factor score and the virtual resource factor score of the virtual resource are respectively determined according to the vulnerability basic information; the virtual resource is twice vulnerability graded according to the basic score, the vulnerability time factor score, the vulnerability environment factor score and the virtual resource factor score to obtain a twice grading result; and the vulnerability evaluation result of the virtual resource is generated according to the twice grading result, which can solve the problem that the CVSS vulnerability score cannot objectively reflect the influence of the vulnerability on the real environment in the related art, and through twice vulnerability grading on the basic score, the vulnerability evaluation result is finally obtained, the risk of open source software supply chain attack is alleviated, and the efficiency of open source governance is improved. BRIEF DESCRIPTION OF DRAWINGS

[0058] Figure 1 is a hardware structure block diagram of a mobile terminal of the vulnerability evaluation method of the virtual resource according to the embodiment of the present application;

[0059] Figure 2 is a flowchart of the vulnerability evaluation method of the virtual resource according to the embodiment of the present application;

[0060] Figure 3 is a logical architecture diagram of the vulnerability risk analysis system according to the embodiment;

[0061] Figure 4 is a schematic diagram of the vulnerability risk analysis scene according to the embodiment;

[0062] Figure 5 is a schematic diagram of the vulnerability risk twice grading according to the embodiment;

[0063] Figure 6 is a schematic diagram of the basic score grading according to the embodiment;

[0064] Figure 7 is a flowchart of the vulnerability evaluation according to the embodiment;

[0065] Figure 8 is a block diagram of the vulnerability evaluation device of the virtual resource according to the embodiment. DETAILED DESCRIPTION

[0066] Hereinafter, the embodiments of the present application will be described in detail with reference to the accompanying drawings and in conjunction with the embodiments.

[0067] It should be noted that the terms "first", "second", etc. in the description and claims of the present application and in the above drawings are used to distinguish similar objects, and do not necessarily have to describe a specific order or sequence.

[0068] The method embodiments provided in the embodiments of the present application can be executed in a mobile terminal, a computer terminal or a similar computing device. Taking the case of running on a mobile terminal, Figure 1 is a hardware structure block diagram of the mobile terminal of the vulnerability assessment method of the virtual resource of the embodiments of the present application, as Figure 1 shown, the mobile terminal can include one or more (only one is shown in Figure 1 The processor 102 (the processor 102 can include but not limited to a processing device such as a microprocessor MCU or a programmable logic device FPGA) and a memory 104 for storing data, wherein the above-mentioned mobile terminal can also include a transmission device 106 for communication function and an input and output device 108. Those skilled in the art can understand that Figure 1 The structure shown is only schematic, which does not limit the structure of the above-mentioned mobile terminal. For example, the mobile terminal can also include more or less components than Figure 1 shown, or have a different configuration from Figure 1 shown.

[0069] The memory 104 can be used to store computer programs, for example, software programs and modules of application software, such as the computer program corresponding to the vulnerability assessment method of the virtual resource of the embodiments of the present application, and the processor 102 executes various functions and business chain address pool slicing processing by running the computer program stored in the memory 104, that is, implements the above-mentioned method. The memory 104 can include a high-speed random access memory, and can also include a non-volatile memory, such as one or more magnetic storage devices, flash memories, or other non-volatile solid-state memories. In some examples, the memory 104 can further include a memory remotely arranged with respect to the processor 102, which can be connected to the mobile terminal through a network. Examples of the above-mentioned network include but are not limited to the Internet, an intranet, a local area network, a mobile communication network and a combination thereof.

[0070] The transmission device 106 is used to receive or send data via a network. Specific examples of the network described above may include a wireless network provided by the mobile terminal's communication provider. In one example, the transmission device 106 includes a Network Interface Controller (NIC), which can connect to other network devices via a base station to communicate with the Internet. In another example, the transmission device 106 may be a Radio Frequency (RF) module, used for wireless communication with the Internet.

[0071] This embodiment provides a vulnerability assessment method for virtual resources running on the aforementioned mobile terminal or network architecture. Figure 2 This is a flowchart of a vulnerability assessment method for virtual resources according to an embodiment of this application, such as... Figure 2 As shown, the process includes the following steps:

[0072] Step S202: Obtain basic vulnerability information of virtual resources, and assign a basic score to the virtual resources based on the basic vulnerability information to obtain a basic score.

[0073] In this embodiment, step S202 above, obtaining basic vulnerability information of virtual resources may specifically include: obtaining basic asset information of the open-source component where the virtual resource is located; and obtaining basic vulnerability information of the virtual resource based on the project version information of the open-source component where the virtual resource is located and the basic asset information.

[0074] Step S204: Determine the vulnerability time factor score, vulnerability environment factor score, and virtual resource factor score of the virtual resource based on the basic vulnerability information.

[0075] Step S206: Perform secondary vulnerability classification on the virtual resource based on the basic score, the vulnerability time factor score, the vulnerability environment factor score, and the virtual resource factor score to obtain the secondary classification result;

[0076] In this embodiment, step S206 can be specifically performed by secondary vulnerability classification of the virtual resource based on the basic score, the vulnerability time factor score, the vulnerability environment factor score, and the virtual resource factor score, to obtain the secondary classification result:

[0077] ;

[0078] in, The result of the secondary grading is... It is the product of the base score, the vulnerability time factor score, and the vulnerability environment factor score. Score the virtual resource factor. Threat level, For a specified number of bits, It is based on the specified number of bits. A function that rounds the position upwards.

[0079] Step S208: Generate vulnerability assessment results for the virtual resources based on the secondary classification results.

[0080] Through the above steps S202 to S208, the problem that CVSS vulnerability scores in related technologies cannot objectively reflect the impact of vulnerabilities on the real environment can be solved. By performing secondary vulnerability classification on the basic score, the vulnerability assessment result is finally obtained, which can mitigate the risk of open source software supply chain attacks and improve the efficiency of open source governance.

[0081] In an optional embodiment, the method further includes: obtaining project version information and component version information of the open-source component where the virtual resource is located; determining, based on the project version information and the component version information, that there is no corresponding vulnerability information in the vulnerability information database, wherein the vulnerability information database stores vulnerability information of open-source components corresponding to the component version and the project version.

[0082] Furthermore, based on the project version and the component version, it is determined that there is corresponding vulnerability information in the vulnerability information database. The vulnerability assessment result of the vulnerability information of the open source component is obtained from the vulnerability information database. The vulnerability assessment result of the vulnerability information of the open source component is determined as the vulnerability assessment result of the virtual resource, and the vulnerability assessment result is obtained directly, which improves the efficiency of the assessment.

[0083] In this embodiment, step S202 may specifically include: obtaining multiple vulnerability time factors based on the basic vulnerability information; determining the scores corresponding to the multiple vulnerability time factors based on the time factor scores pre-set for each time factor; and determining the vulnerability time factor score based on the scores of the multiple vulnerability time factors; obtaining multiple vulnerability environment factors based on the basic vulnerability information; determining the scores corresponding to the multiple vulnerability environment factors based on the environment factor scores pre-set for each vulnerability environment factor; and determining the vulnerability environment factor score based on the scores of the multiple vulnerability environment factors; obtaining multiple virtual resource factors based on the basic vulnerability information; determining the scores corresponding to the multiple virtual resource factors based on the virtual resource factor scores pre-set for each virtual resource factor; and determining the virtual resource factor score based on the scores of the multiple virtual resource factors.

[0084] Furthermore, obtaining multiple vulnerability environment factors based on the basic vulnerability information may specifically include: determining whether the vulnerability environment factors have been analyzed based on the basic vulnerability information; if the determination result is negative, improving the vulnerability environment factors based on the basic asset information of the virtual resource to obtain the improved multiple vulnerability environment factors; if the determination result is positive, obtaining the multiple vulnerability environment factors.

[0085] In this embodiment, the vulnerability time factor may specifically include: the degree of vulnerability exploitation, the vulnerability remediation method, the number of days the vulnerability has been publicly disclosed, and the vulnerability attack trend; the vulnerability environment factor may specifically include: the type of open source component used, the required modification permissions, the modified attack vector, the probability of occurrence in the actual environment, network threat intelligence, and the modified user interaction; the virtual resource factor may specifically include: the importance of the asset, the degree of asset loss, and the impact of the recovery process.

[0086] The application environment of this embodiment can include business scenarios such as software artifact release, pre-supply chain security assessment, compliance audit, and vulnerability and security incident response. Figure 3 This is a logical architecture diagram of the vulnerability risk analysis system according to this embodiment, such as... Figure 3 As shown, it includes: an asset (specifically referring to the information systems and devices deployed by open-source components) management platform, a vulnerability information database, and a vulnerability scoring system.

[0087] The asset management platform centrally manages project assets. During the project initiation and requirements analysis phases, the platform accurately identifies relevant assets and confirms their types and application scenarios. Basic asset information is entered into the system, which automatically converts this information into various indicator options for asset factors.

[0088] It possesses data asset management capabilities, enabling asset visualization and meeting security requirements for project asset management. It achieves standardized management of all assets, recording basic information such as asset number, asset category, deployed product version, network environment, and historical attack events. It automatically assesses the impact of vulnerabilities based on asset importance and threat descriptions.

[0089] The asset management platform supports the construction of asset standard systems in other industries. Asset information has the capability for layered and open data models, and asset standards and asset layering support multiple scenarios. Standard-related configurations, modeling, monitoring, etc., are adjusted and supported synchronously.

[0090] Table 1

[0091]

[0092] As shown in Table 1, the vulnerability assessment system combines product-related information of open-source components obtained from the asset management platform to automatically classify asset importance (AIR), asset loss level (LAR), etc., and calculate the final asset factor score.

[0093] The vulnerability database stores vulnerability information for open-source components using two key-value pairs: component version and project version. Basic vulnerability information is sourced from the open-source community, fuzzing, industry-recognized open-source component scanning tools, and public vulnerability information networks. The system periodically extracts information from the public internet and updates vulnerability time-factor parameters in real time. General vulnerability information can be synchronized in real time based on adjustments made by open-source component manufacturers. Vulnerability experts regularly adjust and optimize the original data based on vulnerability information, creating a vulnerability database adapted to the R&D industry.

[0094] Based on the open-source component information used in the project version, the project team matches the specific R&D project's usage files, analyzes the vulnerabilities, identifies the impact of open-source vulnerabilities, and stores the project's analysis conclusions in a vulnerability database. All analysis conclusions from the project are inheritable and retrievable. For the environmental factors of the vulnerability, the project can select a matching version baseline to migrate and inherit historical data.

[0095] Vulnerability scoring system Figure 4 This is a schematic diagram of a vulnerability risk analysis scenario according to this embodiment, such as... Figure 4 As shown, firstly, users identify assets vulnerable to open-source component vulnerabilities and determine their vulnerabilities based on specific assets. The threat level of an asset is assessed based on its importance and the extent of potential damage, thus clarifying the threat posed by the vulnerability. The impact of the threat and asset risk is analyzed, resulting in a secondary risk assessment of the vulnerability, including time factor analysis, environmental factor analysis, and asset factor analysis. A risk assessment report is generated based on the secondary assessment results, suggesting risk mitigation measures, including risk resolution, risk acceptance, and risk mitigation. The impact of the time factor on vulnerability risk is analyzed; for example, the exploitability of a vulnerability changes over time. Then, based on the actual use of the open-source component in a project, the impact of environmental factors on risk is modified. The impact of open-source component vulnerabilities has actual triggering scenarios; some vulnerabilities only have a real impact when specific scenarios are met.

[0096] Risk is the probability that a threat will exploit a vulnerability to harm an asset. It is an assessment of probability, likelihood, or chance. The greater the likelihood of a threat event occurring, the greater the risk. Expressed as a formula, risk can be defined as: Risk = Threat Vulnerability.

[0097] Reducing threat actors or vulnerabilities directly mitigates risk. When a risk occurs, a threat actor, threat actor, or threat event has already exploited a vulnerability to damage or compromise one or more assets. Risk is prevented from becoming a reality by eliminating vulnerabilities and preventing threat actors and threat events from harming assets.

[0098] Figure 5 This is a schematic diagram illustrating the secondary risk assessment of vulnerabilities according to this embodiment, as shown below. Figure 5 As shown, this includes a secondary classification of vulnerability risk based on scores from a base score, time factor, environmental factor, and asset factor.

[0099] Figure 6 This is a schematic diagram of the basic classification system according to this embodiment, as shown below. Figure 6 As shown, the base score can be adjusted. By providing the adjustment vector, a new base score is calculated using CVSS.

[0100] 1. The time factors are shown in Table 2.

[0101] Table 2

[0102]

[0103] 2. Environmental factors are shown in Table 3.

[0104] Table 3

[0105]

[0106]

[0107] 3. Asset factors are shown in Table 4.

[0108] Table 4

[0109]

[0110] The secondary classification result can be obtained by sending the following message:

[0111]

[0112] in, This is the result of the second rating. It is the product of the base score, the vulnerability time factor score, and the vulnerability environment factor score. Score the virtual resource factor. Threat level, For a specified number of bits, It is based on the specified number of bits. Functions for rounding up, such as: m=3, RoundUp(3.14159, 3) rounds 3.14159 up to three decimal places (3.142), m=1, RoundUp(3.14159, 1) rounds 3.14159 up to one decimal place (3.1).

[0113] Figure 7 This is a flowchart of the vulnerability assessment according to this embodiment, such as... Figure 7 As shown, it includes:

[0114] S701, a vulnerability was found in an open-source component in the project version;

[0115] S702, analyze basic vulnerability information and project version information;

[0116] S703, check if the vulnerability exists in the vulnerability information database. If the query result is no, proceed to step S704. If the query result is yes, proceed to step S710.

[0117] S704 automatically crawls various time factor indicators based on basic vulnerability information;

[0118] S705: Obtain asset information from the asset management platform based on project version information;

[0119] Determine whether the vulnerability environment factor has been analyzed. If the result is no, proceed to step S707. If the result is yes, proceed to step S708.

[0120] S707, based on asset information prompts, R&D personnel improve environmental factor information;

[0121] S708 matches asset information with the asset management platform and improves asset factors (i.e., virtual resource factors).

[0122] S709 provides recommendations for handling vulnerabilities by calculating the secondary classification result through secondary vulnerability classification.

[0123] S710 generates vulnerability assessment results;

[0124] S711, push the report to relevant parties.

[0125] This embodiment applies to scenarios in the cybersecurity field, specifically software supply chain lifecycle security management. It includes, but is not limited to, IT application scenarios relying on third-party open-source components, identifying and assessing the impact of vulnerabilities on real assets. This embodiment significantly enhances risk assessment of open-source component supply chain attacks, effectively identifying the true impact of open-source component vulnerabilities on associated assets and helping developers fix truly high-risk software defects.

[0126] According to another embodiment of this application, a vulnerability assessment apparatus for virtual resources is also provided. Figure 8 This is a block diagram of a virtual resource vulnerability assessment device according to this embodiment, such as... Figure 8 As shown, the device includes:

[0127] The first acquisition module 82 is used to acquire basic vulnerability information of virtual resources, and to perform basic scoring and grading of the virtual resources based on the basic vulnerability information to obtain a basic score.

[0128] The first determining module 84 is used to determine the vulnerability time factor score, vulnerability environment factor score and virtual resource factor score of the virtual resource based on the vulnerability basic information.

[0129] The secondary classification module 86 is used to perform secondary vulnerability classification on the virtual resource based on the basic score, the vulnerability time factor score, the vulnerability environment factor score and the virtual resource factor score, and obtain the secondary classification result.

[0130] The generation module 88 is used to generate the vulnerability assessment result of the virtual resource based on the secondary classification result.

[0131] In one embodiment, the device further includes:

[0132] The second acquisition module is used to acquire the project version information and component version information of the open source component where the virtual resource is located.

[0133] The second determining module is used to determine, based on the project version information and the component version information, that there is no corresponding vulnerability information in the vulnerability information database, wherein the vulnerability information database stores vulnerability information of open-source components corresponding to the component version and the project version.

[0134] In one embodiment, the device further includes:

[0135] The third acquisition module is used to determine the existence of corresponding vulnerability information in the vulnerability information database based on the project version and the component version, and to acquire the vulnerability assessment result of the vulnerability information of the open source component from the vulnerability information database.

[0136] The third determining module is used to determine the vulnerability assessment result of the vulnerability information of the open source component as the vulnerability assessment result of the virtual resource.

[0137] In one embodiment, the first acquisition module is further configured to acquire basic asset information of the open-source component where the virtual resource is located; and acquire basic vulnerability information of the virtual resource based on the project version information of the open-source component where the virtual resource is located and the basic asset information.

[0138] In one embodiment, the first determining module 84 includes:

[0139] The first determining submodule is used to obtain multiple vulnerability time factors based on the basic vulnerability information, determine the scores corresponding to the multiple vulnerability time factors based on the time factor scores set in advance for each time factor, and determine the vulnerability time factor score based on the scores of the multiple vulnerability time factors.

[0140] The second determining submodule is used to obtain multiple vulnerability environment factors based on the basic vulnerability information, determine the scores corresponding to the multiple vulnerability environment factors based on the environment factor scores set in advance for each vulnerability environment factor, and determine the vulnerability environment factor score based on the scores of the multiple vulnerability environment factors.

[0141] The third determining submodule is used to obtain multiple virtual resource factors based on the basic vulnerability information, determine the scores corresponding to the multiple virtual resource factors based on the virtual resource factor scores set in advance for each virtual resource factor, and determine the virtual resource factor score based on the scores of the multiple virtual resource factors.

[0142] In one embodiment, the second determining module is further configured to

[0143] Determine whether the environmental factors of the vulnerability have been analyzed based on the basic information about the vulnerability.

[0144] If the judgment result is negative, the vulnerability environment factors are improved based on the basic asset information of the virtual resources, and the improved multiple vulnerability environment factors are obtained.

[0145] If the determination result is yes, obtain the multiple vulnerability environment factors.

[0146] In one embodiment, the secondary classification module 86 is further configured to perform secondary vulnerability classification on the virtual resource based on the basic score, the vulnerability time factor score, the vulnerability environment factor score, and the virtual resource factor score, to obtain a secondary classification result:

[0147] ;

[0148] in, The result of the secondary grading is... It is the product of the base score, the vulnerability time factor score, and the vulnerability environment factor score. Score the virtual resource factor. Threat level, For a specified number of bits, It is based on the specified number of bits. A function that rounds the position upwards.

[0149] Embodiments of this application also provide a computer-readable storage medium storing a computer program, wherein the computer program is configured to execute the steps in any of the above method embodiments when run.

[0150] In one exemplary embodiment, the aforementioned computer-readable storage medium may include, but is not limited to, various media capable of storing computer programs, such as a USB flash drive, read-only memory (ROM), random access memory (RAM), portable hard disk, magnetic disk, or optical disk.

[0151] Embodiments of this application also provide an electronic device including a memory and a processor, wherein the memory stores a computer program and the processor is configured to run the computer program to perform the steps in any of the above method embodiments.

[0152] In one exemplary embodiment, the electronic device may further include a transmission device and an input / output device, wherein the transmission device is connected to the processor and the input / output device is connected to the processor.

[0153] Specific examples in this embodiment can be found in the examples described in the above embodiments and exemplary implementations, and will not be repeated here.

[0154] Obviously, those skilled in the art should understand that the modules or steps of this application described above can be implemented using general-purpose computing devices. They can be centralized on a single computing device or distributed across a network of multiple computing devices. They can be implemented using computer-executable program code, and thus can be stored in a storage device for execution by a computing device. In some cases, the steps shown or described can be performed in a different order than those presented here, or they can be fabricated as separate integrated circuit modules, or multiple modules or steps can be fabricated as a single integrated circuit module. Thus, this application is not limited to any particular combination of hardware and software.

[0155] The above description is merely a preferred embodiment of this application and is not intended to limit this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the principles of this application should be included within the protection scope of this application.

Claims

1. A method for vulnerability assessment of virtual resources, characterized in that, The method includes: Obtain basic vulnerability information of virtual resources, and assign a basic score to the virtual resources based on the basic vulnerability information to obtain a basic score; Determining the vulnerability time factor score, vulnerability environment factor score, and virtual resource factor score of the virtual resource based on the basic vulnerability information includes: obtaining multiple vulnerability time factors based on the basic vulnerability information; determining the corresponding score of the multiple vulnerability time factors based on the pre-set time factor scores for each time factor; and determining the vulnerability time factor score based on the scores of the multiple vulnerability time factors. It also includes obtaining multiple vulnerability environment factors based on the basic vulnerability information; determining the corresponding score of the multiple vulnerability environment factors based on the pre-set environment factor scores for each vulnerability environment factor; and determining the vulnerability environment factor score based on the scores of the multiple vulnerability environment factors. Finally, it includes obtaining multiple virtual resource factors based on the basic vulnerability information; determining the corresponding score of the multiple virtual resource factors based on the pre-set virtual resource factor scores for each virtual resource factor; and determining the virtual resource factor score based on the scores of the multiple virtual resource factors. The virtual resource is subjected to a secondary vulnerability rating based on the base score, the vulnerability time factor score, the vulnerability environment factor score, and the virtual resource factor score, resulting in a secondary rating result. Based on the secondary rating results, a vulnerability assessment result for the virtual resource is generated.

2. The method according to claim 1, characterized in that, The method further includes: Obtain the project version information and component version information of the open-source component containing the virtual resource; Based on the project version information and the component version information, it is determined that there is no corresponding vulnerability information in the vulnerability information database, wherein the vulnerability information database stores vulnerability information of open source components corresponding to component versions and project versions.

3. The method according to claim 2, characterized in that, The method further includes: Based on the project version and the component version, it is determined that there is corresponding vulnerability information in the vulnerability information database, and the vulnerability assessment result of the vulnerability information of the open source component is obtained from the vulnerability information database. The vulnerability assessment results of the vulnerability information of the open-source component are determined as the vulnerability assessment results of the virtual resource.

4. The method according to claim 1, characterized in that, Basic information about vulnerabilities in obtaining virtual resources includes: Obtain basic asset information of the open-source component where the virtual resource is located; Based on the project version information of the open-source component where the virtual resource is located and the basic asset information, obtain the basic vulnerability information of the virtual resource.

5. The method according to claim 1, characterized in that, Based on the basic vulnerability information, several vulnerability environmental factors are obtained, including: Determine whether the environmental factors of the vulnerability have been analyzed based on the basic information about the vulnerability. If the judgment result is negative, the vulnerability environment factors are improved based on the basic asset information of the virtual resources, and the improved multiple vulnerability environment factors are obtained. If the determination result is yes, obtain the multiple vulnerability environment factors.

6. The method according to any one of claims 1 to 5, characterized in that, The method further includes: The virtual resource is subjected to secondary vulnerability classification based on the base score, the vulnerability time factor score, the vulnerability environment factor score, and the virtual resource factor score, to obtain the secondary classification result: ; in, The result of the secondary grading is... It is the product of the base score, the vulnerability time factor score, and the vulnerability environment factor score. Score the virtual resource factor. Threat level, For a specified number of bits, It is based on the specified number of bits. A function that rounds the position upwards.

7. A vulnerability assessment device for virtual resources, characterized in that, The device includes: The first acquisition module is used to acquire basic vulnerability information of virtual resources, and to assign a basic score to the virtual resources based on the basic vulnerability information to obtain a basic score. The first determining module is configured to determine, based on the basic vulnerability information, the vulnerability time factor score, the vulnerability environment factor score, and the virtual resource factor score of the virtual resource, respectively. This includes: obtaining multiple vulnerability time factors based on the basic vulnerability information; determining the score corresponding to each of the multiple vulnerability time factors based on pre-set time factor scores for each time factor; and determining the vulnerability time factor score based on the scores of the multiple vulnerability time factors. It also includes: obtaining multiple vulnerability environment factors based on the basic vulnerability information; determining the score corresponding to each of the multiple vulnerability environment factors based on pre-set environment factor scores for each vulnerability environment factor; and determining the vulnerability environment factor score based on the scores of the multiple vulnerability environment factors. Finally, it includes: obtaining multiple virtual resource factors based on the basic vulnerability information; determining the score corresponding to each of the multiple virtual resource factors based on pre-set virtual resource factor scores for each virtual resource factor; and determining the virtual resource factor score based on the scores of the multiple virtual resource factors. The secondary classification module is used to perform secondary vulnerability classification on the virtual resource based on the basic score, the vulnerability time factor score, the vulnerability environment factor score, and the virtual resource factor score, and obtain the secondary classification result. The generation module is used to generate vulnerability assessment results for the virtual resources based on the secondary classification results.

8. A computer-readable storage medium storing a computer program, wherein, The computer program is configured to execute the method described in any one of claims 1 to 6 when it is run.

9. An electronic device comprising a memory and a processor, the memory storing a computer program, the processor being configured to run the computer program to perform the method of any one of claims 1 to 6.

Citation Information

Patent Citations

  • Multilayer impact factor-based security vulnerability threat quantification method

    CN107292178A