A Method, Device, Terminal Device and Storage Medium for Mining Firmware Vulnerabilities of a Distribution Edge Gateway

By building a firmware vulnerability data classification matrix and using a firmware vulnerability mining model, vulnerability analysis of the power distribution edge gateway firmware is solved, and the accuracy and security of vulnerability mining are improved.

CN118886022BActive Publication Date: 2025-06-20GUANGDONG POWER GRID CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411267872.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-09-11
Publication Date
2025-06-20
Estimated Expiration
2044-09-11

AI Technical Summary

Technical Problem

The existing power distribution edge gateway vulnerability mining method has the problem of incomplete vulnerability analysis, which leads to the inaccurate firmware vulnerabilities being discovered accurately, reducing the security of power distribution edge gateways.

Method used

By constructing a firmware vulnerability data classification matrix, classify the firmware data to be mined, determine the firmware type and firmware data value, and input it into the firmware vulnerability mining model, and output the vulnerability mining results based on the firmware standard data value and the firmware data to be mined.

Benefits of technology

It improves the accuracy of firmware vulnerability mining of distribution edge gateways, enhances the security of distribution edge gateways, and ensures comprehensive and accurate vulnerabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118886022B_ABST
    Figure CN118886022B_ABST
Patent Text Reader

Abstract

The present invention discloses a method, device, terminal device and storage medium for firmware vulnerability mining of a distribution edge gateway. The method includes: obtaining firmware data to be mined; classifying the firmware data to be mined with a firmware vulnerability data classification matrix to determine the firmware information of the firmware data to be mined; wherein the firmware information includes the firmware type and the firmware data value; inputting the firmware data to be mined into a firmware vulnerability mining model, so that the firmware vulnerability mining model obtains the firmware standard data value of the corresponding firmware type according to the firmware information of the firmware data to be mined, and outputs a vulnerability mining result according to the firmware standard data value and the firmware data value of the firmware data to be mined; wherein the construction of the firmware vulnerability data classification matrix includes: obtaining a firmware vulnerability sample data set; constructing an initial firmware vulnerability mining model and determining the loss function of the initial firmware vulnerability mining model; constructing a firmware vulnerability data classification matrix based on the loss function and the firmware vulnerability sample data set.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of distribution edge gateway security testing, and particularly to a method, device, terminal device and storage medium for mining firmware vulnerabilities of a distribution edge gateway. Background Art

[0002] With the intelligent and networked development of the power system, the distribution edge gateway firmware, as an important part of the power system, its security is crucial for the stable operation of the entire power system. However, with the increase in hacker attacks and malware, the vulnerabilities of the distribution edge gateway firmware have become an increasingly serious problem. Therefore, it has become an urgent problem to mine and check the vulnerabilities of the distribution edge gateway firmware and then repair the firmware vulnerabilities. The existing methods for mining distribution edge gateway vulnerabilities are mainly achieved by static code analysis or fuzz testing. Such vulnerability mining methods are only applicable to specific scenarios, and there are some codes that need to be dynamically executed during the static code analysis process, making it difficult to achieve vulnerability analysis. During the analysis process of the fuzz testing method, only some data contents are selected for vulnerability analysis. Both of these two vulnerability analysis methods have the problem of incomplete vulnerability analysis, resulting in the inability to accurately mine the firmware vulnerabilities of the distribution edge gateway and the low security of the distribution edge gateway. Summary of the Invention

[0003] Embodiments of the present invention provide a method, device, terminal device and storage medium for mining firmware vulnerabilities of a distribution edge gateway, which can improve the accuracy of mining firmware vulnerabilities of the distribution edge gateway and thus improve the security of the distribution edge gateway.

[0004] An embodiment of the present invention provides a method for mining firmware vulnerabilities of a distribution edge gateway, including:

[0005] Obtaining firmware data to be mined;

[0006] Classifying the firmware data to be mined with a firmware vulnerability data classification matrix to determine the firmware information of the firmware data to be mined; wherein, the firmware information includes firmware type and firmware data value;

[0007] Inputting the firmware data to be mined into a firmware vulnerability mining model, so that the firmware vulnerability mining model obtains the firmware standard data value of the corresponding firmware type according to the firmware information of the firmware data to be mined, and outputs a vulnerability mining result according to the firmware standard data value and the firmware data value of the firmware data to be mined; wherein, the vulnerability mining result includes: there are exploitable vulnerabilities and there are no exploitable vulnerabilities;

[0008] The construction of the firmware vulnerability data classification matrix includes:

[0009] Obtaining a firmware vulnerability sample data set;

[0010] Construct an initial firmware vulnerability mining model and determine the loss function of the initial firmware vulnerability mining model;

[0011] Construct a firmware vulnerability data classification matrix based on the loss function and the firmware vulnerability sample data set.

[0012] Further, the obtaining of the firmware vulnerability sample data set includes:

[0013] Obtain a number of initial firmware vulnerability samples;

[0014] Convert a number of initial firmware vulnerability samples into sample vectors;

[0015] Obtain a feature vector matrix according to a number of sample vectors;

[0016] Calculate the covariance matrix according to the feature vector matrix;

[0017] Solve the covariance matrix to obtain the feature data of a number of initial firmware vulnerability samples; wherein, the feature data includes eigenvalues and eigenvectors;

[0018] Sort a number of eigenvectors in descending order to obtain a number of sorted firmware vulnerability samples;

[0019] Dimensionality reduction is performed on a number of sorted initial firmware vulnerability samples to obtain a number of low-dimensional firmware vulnerability samples;

[0020] Generate a firmware vulnerability sample data set according to a number of low-dimensional firmware vulnerability samples.

[0021] Further, the constructing of the initial firmware vulnerability mining model and determining the loss function of the initial firmware vulnerability mining model includes:

[0022] Construct an initial firmware vulnerability mining model based on a fully connected neural network and determine the network structure and network parameters of the initial firmware vulnerability mining model; wherein, the network structure includes the number of network layers and the number of neurons in each network layer; the network parameters include weight matrices, bias vectors, activation functions and activation value vectors;

[0023] Determine the forward propagation matrix of the initial firmware vulnerability mining model according to the network structure and network parameters;

[0024] Determine the loss function of the initial firmware vulnerability mining model based on the forward propagation matrix.

[0025] Further, the forward propagation matrix is specifically:

[0026]

[0027] Among them, Z represents the forward propagation matrix of the initial firmware vulnerability mining model; w represents the weight matrix; represents the activation function; a represents the activation value vector; b represents the bias vector; L represents the number of network layers is L layers; n represents that there are n neurons on each layer of the network;

[0028] The loss function is specifically:

[0029]

[0030] Among them, J represents the loss function of the initial firmware vulnerability mining model; Z represents the forward propagation matrix of the initial firmware vulnerability mining model; m represents the number of samples input into the initial firmware vulnerability mining model; y represents the output of the initial firmware vulnerability mining model; a∧L represents the output layer of the initial firmware vulnerability mining model.

[0031] Furthermore, constructing the firmware vulnerability data classification matrix based on the loss function and the firmware vulnerability sample data set includes:

[0032] Determine the number of firmware labels according to the firmware vulnerability sample data set;

[0033] Determine the firmware data mining function based on the number of firmware labels and the loss function;

[0034] Determine the firmware fault data extraction function according to the firmware vulnerability sample data set and the firmware data mining function;

[0035] Determine the vulnerability eigenvalue distance function based on the firmware fault data extraction function and the firmware vulnerability sample data set;

[0036] Determine the firmware vulnerability data classification matrix according to the vulnerability eigenvalue distance function and the firmware vulnerability sample data set.

[0037] Furthermore, the outputting the vulnerability mining result according to the firmware standard data value and the firmware data value of the firmware to be mined includes:

[0038] Calculate the difference according to the firmware standard data value and the firmware data value of the firmware to be mined;

[0039] If the difference is greater than the preset difference threshold, it is determined that there are vulnerabilities to be mined in the firmware data to be mined; among them, the preset difference threshold corresponds to the firmware type;

[0040] If the difference is not greater than the preset difference threshold, it is determined that there are no vulnerabilities to be mined in the firmware data to be mined.

[0041] Furthermore, the construction of the firmware vulnerability mining model includes:

[0042] Process each firmware vulnerability sample in the firmware vulnerability sample dataset according to the firmware vulnerability data classification matrix to obtain each firmware vulnerability sample containing firmware information;

[0043] Use each firmware vulnerability sample containing firmware information as a training sample to train the initial firmware vulnerability mining model. When the initial firmware vulnerability mining model reaches the preset convergence condition, generate a firmware vulnerability mining model.

[0044] Based on the above method embodiments, the present invention correspondingly provides device embodiments;

[0045] An embodiment of the present invention correspondingly provides a device for mining firmware vulnerabilities of a distribution edge gateway, including: a data acquisition module, a classification module, a vulnerability analysis module, and a classification function construction module;

[0046] The data acquisition module is used to acquire the firmware data to be mined;

[0047] The classification module is used to classify the firmware data to be mined according to the firmware vulnerability data classification matrix, and determine the firmware information of the firmware data to be mined; wherein, the firmware information includes the firmware type and the firmware data value;

[0048] The vulnerability analysis module is used to input the firmware data to be mined into the firmware vulnerability mining model, so that the firmware vulnerability mining model obtains the firmware standard data value of the corresponding firmware type according to the firmware information of the firmware data to be mined, and outputs a vulnerability mining result according to the firmware standard data value and the firmware data value of the firmware data to be mined; wherein, the vulnerability mining result includes: there is a vulnerability to be mined and there is no vulnerability to be mined;

[0049] The classification function construction module is used to obtain the firmware vulnerability sample dataset; construct an initial firmware vulnerability mining model, and determine the loss function of the initial firmware vulnerability mining model; construct a firmware vulnerability data classification matrix based on the loss function and the firmware vulnerability sample dataset.

[0050] Another embodiment of the present invention provides a terminal device, including a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, it implements the method for mining firmware vulnerabilities of a distribution edge gateway described in the above embodiments of the present invention.

[0051] Another embodiment of the present invention provides a storage medium, which includes a stored computer program. When the computer program runs, it controls the device where the storage medium is located to execute the method for mining firmware vulnerabilities of a distribution edge gateway described in the above embodiments of the present invention.

[0052] By implementing the present invention, the following beneficial effects are achieved:

[0053] The present invention provides a method, apparatus, terminal device, and storage medium for mining firmware vulnerabilities of a distribution edge gateway. The method classifies the firmware data to be mined through a firmware vulnerability data classification matrix to obtain the firmware type and firmware data value of the firmware data to be mined. Then, the firmware data to be mined with the determined firmware type and firmware data value is input into a firmware vulnerability mining model, so that the firmware vulnerability mining model obtains the firmware standard data value under this firmware type according to the firmware type, and determines the vulnerability mining result of the firmware data to be mined based on the firmware standard data value and the current firmware data value. Through the firmware vulnerability data classification matrix, the firmware type and firmware data value are determined in advance, and then the standard data value is obtained through the firmware vulnerability mining model and compared with the current data value. Whether the firmware data to be mined has changed is determined based on the gap between the current data value and the standard data value, so as to determine whether it is data with exploitable vulnerabilities. This method of classifying and then comparing the corresponding standard data value with the current data value for the classification result can accurately check the firmware vulnerability data, improve the comprehensiveness and accuracy of firmware vulnerability mining, and further improve the security of the operation of the distribution edge gateway. Description of the Drawings

[0054] Figure 1 is a schematic flowchart of a method for mining firmware vulnerabilities of a distribution edge gateway provided by an embodiment of the present invention.

[0055] Figure 2 is a schematic structural diagram of a device for mining firmware vulnerabilities of a distribution edge gateway provided by an embodiment of the present invention. Detailed Embodiments

[0056] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0057] As Figure 1 shown, a method for mining firmware vulnerabilities of a distribution edge gateway provided by an embodiment of the present invention includes:

[0058] Step S1: Obtain the firmware data to be mined;

[0059] Step S2: Classify the firmware data to be mined with a firmware vulnerability data classification matrix to determine the firmware information of the firmware data to be mined; wherein, the firmware information includes a firmware type and firmware data;

[0060] Step S3: Input the firmware data to be mined into the firmware vulnerability mining model, so that the firmware vulnerability mining model obtains the firmware standard data of the corresponding firmware type according to the firmware information of the firmware data to be mined, and outputs a vulnerability judgment result based on the firmware standard data and the firmware data of the firmware data to be mined;

[0061] Among them, the construction of the firmware vulnerability data classification matrix includes: obtaining a firmware vulnerability sample data set; constructing an initial firmware vulnerability mining model and determining the loss function of the initial firmware vulnerability mining model; constructing a firmware vulnerability data classification matrix based on the loss function and the firmware vulnerability sample data set.

[0062] For step S1, obtain the firmware data to be mined in the distribution edge gateway; the firmware data to be mined belongs to any one of the following firmware types: driver, operating system, container, application APP, configuration file, and configuration data. For the driver, the possible vulnerable places include the manufacturer, driver version number, and the attached vulnerability code number; for the operating system, the possible vulnerable places include the operating system version number, some service names attached to the operating system version number, and the open port numbers, etc.; for the container, the possible vulnerable places include the public container name, container version number, and the code segments and keyword interfaces with vulnerabilities in the container; for the application APP, the possible vulnerable places include the public application APP name, application APP version number, and the code segments and keyword interfaces with vulnerabilities in the application APP; for the configuration file and configuration data, the possible vulnerable places include the user-defined requirements that cannot be stored in plain text, keywords, and sensitive word data, etc. In principle, the analysis of whether there are vulnerabilities to be mined in the firmware vulnerability data to be mined in the present invention is to obtain the firmware data values under the above firmware types of the firmware data to be mined, and then compare them with the standard values to determine whether there is a possibility of being tampered with.

[0063] For step S2, classify the firmware data to be mined with the firmware vulnerability data classification matrix to determine the firmware type and firmware data value of the firmware data to be mined. Among them, the construction of the firmware vulnerability data classification matrix includes the following steps:

[0064] Step S101: Obtain a firmware vulnerability sample data set;

[0065] Step S201: Construct an initial firmware vulnerability mining model and determine the loss function of the initial firmware vulnerability mining model;

[0066] Step S301: Construct a firmware vulnerability data classification matrix based on the loss function and the firmware vulnerability sample data set.

[0067] For step S101, in a preferred embodiment, the obtaining of the firmware vulnerability sample dataset includes: obtaining a number of initial firmware vulnerability samples; converting the number of initial firmware vulnerability samples into sample vectors; obtaining a feature vector matrix according to the number of sample vectors; calculating a covariance matrix according to the feature vector matrix; solving the covariance matrix to obtain the feature data of the number of initial firmware vulnerability samples; wherein the feature data includes eigenvalues and eigenvectors; sorting the number of eigenvectors in a descending order to obtain the sorted number of initial firmware vulnerability samples; performing dimensionality reduction on the sorted number of firmware vulnerability samples to obtain a number of low-dimensional firmware vulnerability samples; and generating a firmware vulnerability sample dataset according to the number of low-dimensional firmware vulnerability samples.

[0068] Specifically, after obtaining a number of initial firmware vulnerability samples, it is first necessary to perform dimensionality reduction processing on the initial firmware vulnerability samples. Convert the number of initial firmware vulnerability samples into sample vectors, obtain a feature vector matrix according to the number of sample vectors, calculate a covariance matrix through the feature vector matrix, solve the covariance matrix to obtain the eigenvalues and eigenvectors of each firmware vulnerability sample, and sort the eigenvectors in a descending order. After sorting, while ensuring that no information is lost, perform dimensionality reduction on the feature data of the initial firmware vulnerability samples to obtain the projection of the original feature data in the new feature space. The corresponding dimensionality reduction processing formula is as follows:

[0069] x m×T = x m×n e n×T ;

[0070] wherein, x m×T represents the expression of the original feature data in the new feature space, that is, the feature data after dimensionality reduction; x m×n represents the original feature data; e n×T represents the energy of the eigenvector; T represents the dimension of the feature space; x n represents the nth original feature data.

[0071] Project the feature data of the initial firmware vulnerability samples in the original high-dimensional space into the new low-dimensional space through the above formula, and generate a firmware vulnerability sample dataset according to the number of low-dimensional firmware vulnerability samples after dimensionality reduction, which helps with feature visualization and subsequent vulnerability mining.

[0072] For step S201, in a preferred embodiment, constructing an initial firmware vulnerability mining model and determining the loss function of the initial firmware vulnerability mining model includes: constructing an initial firmware vulnerability mining model based on a fully connected neural network, and determining the network structure and network parameters of the initial firmware vulnerability mining model; wherein, the network structure includes the number of network layers and the number of neurons in each network layer; the network parameters include a weight matrix, a bias vector, an activation function, and an activation value vector; determining the forward propagation matrix of the initial firmware vulnerability mining model according to the network structure and network parameters; and determining the loss function of the initial firmware vulnerability mining model based on the forward propagation matrix.

[0073] Specifically, construct an initial firmware vulnerability mining model based on a fully connected neural network. When constructing the initial firmware vulnerability mining model, define the network structure and network parameters of the model; the network structure includes the number of network layers and the number of neurons in each network layer; the network parameters include a weight matrix, a bias vector, an activation function, and an activation value vector. Determine the forward propagation matrix and the loss function of the initial firmware vulnerability mining model in sequence according to the defined network structure and network parameters.

[0074] In a preferred embodiment, the forward propagation matrix is specifically:

[0075]

[0076] Wherein, Z represents the forward propagation matrix of the initial firmware vulnerability mining model; w represents the weight matrix; represents the activation function; a represents the activation value vector; b represents the bias vector; L represents that the number of network layers is L layers; n represents that there are n neurons on each layer of the network; * represents matrix multiplication;

[0077] According to the calculation result of the above forward propagation matrix, make the gap between the output y of the initial firmware vulnerability mining model and the true value the smallest. To ensure the smallest gap, design the loss function as follows:

[0078] The loss function is specifically:

[0079]

[0080] Wherein, J represents the loss function of the initial firmware vulnerability mining model; Z represents the forward propagation matrix of the initial firmware vulnerability mining model; m represents the number of samples input into the initial firmware vulnerability mining model; y represents the output of the initial firmware vulnerability mining model; a∧L represents the output layer of the initial firmware vulnerability mining model.

[0081] For step S301: In a preferred embodiment, constructing the firmware vulnerability data classification matrix based on the loss function and the firmware vulnerability sample data set includes: determining the number of firmware tags according to the firmware vulnerability sample data set; determining the firmware data mining function based on the number of firmware tags and the loss function; determining the firmware fault data extraction function according to the firmware vulnerability sample data set and the firmware data mining function; determining the vulnerability eigenvalue distance function based on the firmware fault data extraction function and the firmware vulnerability sample data set; and determining the firmware vulnerability data classification matrix according to the vulnerability eigenvalue distance function and the firmware vulnerability sample data set.

[0082] Specifically, to minimize the loss function and update the weight matrix and bias vector, by continuously iterating and updating the weight matrix and bias vector, the firmware data mining function can be constructed.

[0083] When constructing the firmware data mining function, the number of firmware tags is involved. Therefore, the number of firmware tags needs to be determined in advance. The number of firmware tags is determined by the operating system version number, driver version number, container version number, and application APP version number in the firmware vulnerability sample data set.

[0084] The formula for the firmware data mining function is as follows:

[0085]

[0086] Where M represents the firmware data mining function; J represents the loss function of the initial firmware vulnerability mining model; A represents the number of firmware tags; P1 represents the initial centroid vector; and P2 represents the actual centroid vector.

[0087] Set the attribute dimension of different firmware vulnerability sample data in the firmware vulnerability sample data set as R(z), where z is the firmware vulnerability sample data. The following firmware fault data extraction function can be obtained:

[0088]

[0089] Where F represents the firmware fault data extraction function; M represents the firmware data mining function; R(z) represents the attribute dimension of the firmware vulnerability sample data z; φ(I z ) represents the threshold for measuring the correlation degree between firmware vulnerabilities, and this value is a set empirical value. According to the above calculation results, assuming that the discrete attribute vector of the distribution edge gateway device operation data is in the existing discrete value set, the formula for obtaining the correlation degree between data is:

[0090]

[0091] Where H represents the correlation degree between data; F represents the firmware fault data extraction function; W iIt is the continuous power distribution edge gateway firmware data vector value; W I It is the discrete power distribution gateway firmware data vector value. These two parameters are the internal empirical coefficients of the fully connected neural network.

[0092] Combined with the above formula, the vulnerability eigenvalue distance function is determined as follows:

[0093]

[0094] Among them, D represents the vulnerability eigenvalue distance function; the respective corresponding symbol feature numbers in the power distribution gateway firmware dataset are u1 and u2. These two parameters are the internal empirical coefficients.

[0095] Furthermore, combined with the above content, the data continuity attribute formula can be determined as:

[0096] Q = δD+(1 - δ)×D;

[0097] Among them, δ represents the weight factor.

[0098] Furthermore, combined with the above content, the firmware vulnerability data classification matrix formula can be determined as:

[0099] G = Q|(L1 - L2)|;

[0100] Among them, G represents the firmware vulnerability data classification matrix; L1 and L2 represent different attributes of the samples; in the present invention, the samples refer to the operating system version number, as well as some service names and open port numbers attached to the operating system version number; for the driver, it includes the manufacturer, version number, and the attached vulnerability code number; for the container and application APP, it includes the public name, version number, and the code segments and keyword interfaces with vulnerabilities. The attribute refers to the operating system, driver, and container and application APP.

[0101] After completing the construction of the above firmware vulnerability data classification matrix, the firmware data to be mined can be classified through the firmware vulnerability data classification matrix, so as to determine its firmware type and firmware data value.

[0102] The obtained matrix G is a matrix containing rows and columns. The rows represent the firmware classification, and the columns represent the specific firmware data values; for example, for the matrix [1 2 3], 1 represents that the firmware data value (operating system version number) of the operating system is 1, 2 represents that the firmware data value of the driver is 2, and 3 represents that the firmware data value of the container and APP is 3.

[0103] For step S3, in a preferred embodiment, the construction of the firmware vulnerability mining model includes: processing each firmware vulnerability sample in the firmware vulnerability sample dataset according to the firmware vulnerability data classification matrix to obtain each firmware vulnerability sample containing firmware information; using each firmware vulnerability sample containing firmware information as a training sample to train the initial firmware vulnerability mining model, and generating a firmware vulnerability mining model when the initial firmware vulnerability mining model reaches the preset convergence condition.

[0104] Specifically, since the initial firmware vulnerability data mining model has been constructed when determining the loss function, there is no need to repeat the construction here. It is necessary to process the input data of the initial firmware vulnerability data mining model through the determined firmware vulnerability data classification matrix to determine the firmware type and firmware data value corresponding to each firmware vulnerability sample; using the firmware vulnerability sample as the input and whether there is a vulnerability to be mined as the output, training the initial firmware vulnerability data mining model, and generating a firmware vulnerability data mining model when reaching the preset convergence condition, such as when the loss function is the smallest.

[0105] After completing the construction of the firmware vulnerability data mining model, input the firmware data to be mined into the firmware vulnerability mining model. The firmware vulnerability mining model obtains the firmware standard data value corresponding to the firmware type according to the firmware type of the firmware data to be mined, extracts the current firmware data value, and then detects the similarity between the current firmware data value and the firmware standard data value through the firmware vulnerability mining model to determine whether there is a vulnerability to be mined.

[0106] In a preferred embodiment, the output of the vulnerability mining result according to the firmware standard data value and the firmware data value of the firmware data to be mined includes: calculating the difference according to the firmware standard data value and the firmware data value of the firmware data to be mined; if the difference is greater than the preset difference threshold, it is determined that the firmware data to be mined has a vulnerability to be mined; where the preset difference threshold corresponds to the firmware type; if the difference is not greater than the preset difference threshold, it is determined that the firmware data to be mined does not have a vulnerability to be mined.

[0107] Specifically, before mining, according to the actual situation of different firmware types, a preset difference threshold is set for each firmware type. Calculate the difference between the firmware standard data value and the firmware data value of the firmware data to be mined, and compare this difference with the preset difference threshold of this firmware type. If the difference is greater than the preset difference threshold, it is determined that the firmware data to be mined has a vulnerability to be mined. If the difference is not greater than the preset difference threshold, it is determined that the firmware data to be mined does not have a vulnerability to be mined. Preferably, the vulnerability mining report is output in a visual way, so that the report includes whether there is a vulnerability to be mined, the location of the vulnerability, and the specific information of the vulnerability, etc., so that the operation and maintenance personnel of the distribution edge gateway can troubleshoot the vulnerability according to the report result and improve the security of the distribution edge gateway.

[0108] Based on the above method item embodiments, the present invention correspondingly provides device item embodiments.

[0109] As Figure 2 shown, an embodiment of the present invention provides a device for mining firmware vulnerabilities of a distribution edge gateway, including: a data acquisition module, a classification module, a vulnerability analysis module, and a classification function construction module;

[0110] The data acquisition module is used to acquire firmware data to be mined;

[0111] The classification module is used to classify the firmware data to be mined with a firmware vulnerability data classification matrix to determine the firmware information of the firmware data to be mined; wherein, the firmware information includes firmware type and firmware data value;

[0112] The vulnerability analysis module is used to input the firmware data to be mined into a firmware vulnerability mining model, so that the firmware vulnerability mining model obtains the firmware standard data value of the corresponding firmware type according to the firmware information of the firmware data to be mined, and outputs a vulnerability mining result according to the firmware standard data value and the firmware data value of the firmware data to be mined; wherein, the vulnerability mining result includes: there are vulnerabilities to be mined and there are no vulnerabilities to be mined;

[0113] The classification function construction module is used to acquire a firmware vulnerability sample data set; construct an initial firmware vulnerability mining model, and determine the loss function of the initial firmware vulnerability mining model; construct a firmware vulnerability data classification matrix based on the loss function and the firmware vulnerability sample data set.

[0114] It should be noted that the device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. In addition, in the attached drawings of the device embodiments provided by the present invention, the connection relationship between modules indicates that they have a communication connection, which can be specifically implemented as one or more communication buses or signal lines. Those of ordinary skill in the art can understand and implement without creative work.

[0115] Those skilled in the art can clearly understand that for the convenience and conciseness, the specific working process of the device described above can refer to the corresponding process in the foregoing method embodiments, and will not be repeated here.

[0116] Based on the above method item embodiments, the present invention correspondingly provides terminal device item embodiments.

[0117] An embodiment of the present invention provides a terminal device, including a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, a method for mining firmware vulnerabilities of a distribution edge gateway described in any one of the present invention is implemented.

[0118] The terminal device may be a computing device such as a desktop computer, a notebook, a palm computer, and a cloud server. The terminal device may include, but is not limited to, a processor and a memory.

[0119] The so-called processor may be a Central Processing Unit (CPU), or may also be other general-purpose processors, Digital Signal Processors (DSPs), Application Specific Integrated Circuits (ASICs), Field-Programmable Gate Arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The processor is the control center of the terminal device, connecting various parts of the entire terminal device through various interfaces and lines.

[0120] The memory may be used to store the computer program. The processor realizes various functions of the terminal device by running or executing the computer program stored in the memory and calling the data stored in the memory. The memory may mainly include a program storage area and a data storage area. Among them, the program storage area may store an operating system, application programs required for at least one function, etc.; the data storage area may store data created according to the use of the mobile phone, etc. In addition, the memory may include high-speed random access memory, and may also include non-volatile memory, such as a hard disk, a memory, a plug-in hard disk, a Smart Media Card (SMC), a Secure Digital (SD) card, a Flash Card, at least one magnetic disk storage device, a flash memory device, or other volatile solid-state storage devices.

[0121] Based on the above method item embodiment, the present invention correspondingly provides a storage medium item embodiment.

[0122] An embodiment of the present invention provides a storage medium, which includes a stored computer program. When the computer program runs, it controls the device where the storage medium is located to execute any one of the power distribution edge gateway firmware vulnerability mining methods described in the present invention.

[0123] The storage medium is a computer-readable storage medium, and the computer program is stored in the computer-readable storage medium. When the computer program is executed by a processor, the steps of the above-mentioned various method embodiments can be implemented. Among them, the computer program includes computer program code, and the computer program code can be in the form of source code, object code, executable file or some intermediate form, etc. The computer-readable medium can include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), electrical carrier signal, telecommunication signal, and software distribution medium, etc.

[0124] The above is the preferred embodiment of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and refinements can be made, and these improvements and refinements are also regarded as the protection scope of the present invention.

Claims

1. A method for mining firmware vulnerabilities in a power distribution edge gateway, characterized in that: include: Obtain the firmware data to be mined; Classifying the firmware data to be mined using a firmware vulnerability data classification matrix to determine firmware information of the firmware data to be mined; wherein the firmware information includes a firmware type and a firmware data value; Inputting the firmware data to be mined into the firmware vulnerability mining model, so that the firmware vulnerability mining model obtains the firmware standard data value of the corresponding firmware type according to the firmware information of the firmware data to be mined, and outputs the vulnerability mining result according to the firmware standard data value and the firmware data value of the firmware data to be mined; wherein the vulnerability mining result includes: the existence of a vulnerability that can be mined and the absence of a vulnerability that can be mined; The construction of the firmware vulnerability data classification matrix includes: Obtain a firmware vulnerability sample dataset; Constructing an initial firmware vulnerability mining model and determining the loss function of the initial firmware vulnerability mining model; Determine the number of firmware tags according to the firmware vulnerability sample data set; A firmware data mining function is determined based on the number of firmware tags and the loss function, wherein the firmware data mining function is specifically: Wherein, M represents the firmware data mining function; J represents the loss function of the initial firmware vulnerability mining model; A represents the number of firmware tags; P1 represents the initial centroid vector; P2 represents the actual centroid vector; A firmware fault data extraction function is determined according to the firmware vulnerability sample data set and the firmware data mining function. The firmware fault data extraction function is specifically: Wherein, F represents the firmware fault data extraction function; M represents the firmware data mining function; R(z) represents the attribute dimension of the firmware vulnerability sample data z; Indicates the threshold for measuring the correlation between firmware vulnerabilities. This value is a set empirical value. The vulnerability feature value distance function is determined based on the firmware fault data extraction function and the firmware vulnerability sample data set. The vulnerability feature value distance function is specifically: Among them, D represents the vulnerability feature value distance function; the corresponding symbol feature numbers in the distribution gateway firmware data set are u1 and u2, and these two parameters are internal empirical coefficients; H represents the correlation between data, F represents the firmware fault data extraction function; W i The continuous power distribution edge gateway firmware data vector value; W I It is the discrete power distribution gateway firmware data vector value; The firmware vulnerability data classification matrix is ​​determined according to the vulnerability feature value distance function and the firmware vulnerability sample data set. The firmware vulnerability data classification matrix is ​​specifically: G = Q|(L1-L2)|; Q = δD + (1-δ) × D; Among them, G represents the firmware vulnerability data classification matrix; L1 and L2 represent different attributes of samples; Q represents the data continuity attribute formula; δ represents the weight factor.

2. A method for mining a firmware vulnerability of a power distribution edge gateway according to claim 1, characterized in that: The step of obtaining a firmware vulnerability sample data set includes: Obtain several initial firmware vulnerability samples; Convert several initial firmware vulnerability samples into sample vectors; Obtain a eigenvector matrix based on a number of sample vectors; Calculate a covariance matrix based on the eigenvector matrix; Solving the covariance matrix to obtain characteristic data of a number of initial firmware vulnerability samples; wherein the characteristic data includes eigenvalues ​​and eigenvectors; Sorting a number of feature vectors in descending order to obtain a number of sorted initial firmware vulnerability samples; Perform dimensionality reduction on the sorted initial firmware vulnerability samples to obtain several low-dimensional firmware vulnerability samples; A firmware vulnerability sample dataset is generated based on several low-dimensional firmware vulnerability samples.

3. A method for mining firmware vulnerabilities in a power distribution edge gateway according to claim 1, characterized in that: The constructing of the initial firmware vulnerability mining model and determining the loss function of the initial firmware vulnerability mining model include: An initial firmware vulnerability mining model is constructed based on a fully connected neural network, and a network structure and network parameters of the initial firmware vulnerability mining model are determined; wherein the network structure includes the number of network layers and the number of neurons in each network layer; and the network parameters include a weight matrix, a bias vector, an activation function, and an activation value vector; Determine a forward propagation matrix of an initial firmware vulnerability mining model according to the network structure and network parameters; A loss function of an initial firmware vulnerability mining model is determined based on the forward propagation matrix.

4. A method for mining firmware vulnerabilities in a power distribution edge gateway as claimed in claim 3, characterized in that: The forward propagation matrix is ​​specifically: Where Z represents the forward propagation matrix of the initial firmware vulnerability mining model; w represents the weight matrix; represents the activation function; a represents the activation value vector; b represents the bias vector; L represents the number of network layers; n represents that there are n neurons in each layer of the network; The loss function is specifically: Among them, J represents the loss function of the initial firmware vulnerability mining model; Z represents the forward propagation matrix of the initial firmware vulnerability mining model; m represents the number of samples input into the initial firmware vulnerability mining model; y represents the output of the initial firmware vulnerability mining model; a∧L represents the output layer of the initial firmware vulnerability mining model.

5. A method for mining firmware vulnerabilities in a power distribution edge gateway according to claim 1, characterized in that: The outputting vulnerability mining results according to the firmware standard data value and the firmware data value of the firmware data to be mined includes: Calculate the difference between the firmware standard data value and the firmware data value of the firmware data to be mined; If the difference is greater than a preset difference threshold, it is determined that there are exploitable vulnerabilities in the firmware data to be mined; wherein the preset difference threshold corresponds to the firmware type; If the difference is not greater than the preset difference threshold, it is determined that there is no exploitable vulnerability in the firmware data to be mined.

6. A method for mining firmware vulnerabilities in a power distribution edge gateway according to claim 1, characterized in that: The construction of the firmware vulnerability mining model includes: Processing each firmware vulnerability sample in the firmware vulnerability sample data set according to the firmware vulnerability data classification matrix to obtain each firmware vulnerability sample containing firmware information; The initial firmware vulnerability mining model is trained by taking the firmware vulnerability samples containing firmware information as training samples, and when the initial firmware vulnerability mining model reaches a preset convergence condition, a firmware vulnerability mining model is generated.

7. A device for discovering firmware vulnerabilities in a power distribution edge gateway, characterized in that: include: Data acquisition module, classification module, vulnerability analysis module and classification function construction module; The data acquisition module is used to acquire the firmware data to be mined; The classification module is used to classify the firmware data to be mined using a firmware vulnerability data classification matrix to determine the firmware information of the firmware data to be mined; wherein the firmware information includes a firmware type and a firmware data value; The vulnerability analysis module is used to input the firmware data to be mined into the firmware vulnerability mining model, so that the firmware vulnerability mining model obtains the firmware standard data value of the corresponding firmware type according to the firmware information of the firmware data to be mined, and outputs the vulnerability mining result according to the firmware standard data value and the firmware data value of the firmware data to be mined; wherein the vulnerability mining result includes: the existence of a vulnerability that can be mined and the absence of a vulnerability that can be mined; The classification function construction module is used to obtain a firmware vulnerability sample data set; construct an initial firmware vulnerability mining model and determine the loss function of the initial firmware vulnerability mining model; determine the number of firmware tags according to the firmware vulnerability sample data set; A firmware data mining function is determined based on the number of firmware tags and the loss function, wherein the firmware data mining function is specifically: Wherein, M represents the firmware data mining function; J represents the loss function of the initial firmware vulnerability mining model; A represents the number of firmware tags; P1 represents the initial centroid vector; P2 represents the actual centroid vector; A firmware fault data extraction function is determined according to the firmware vulnerability sample data set and the firmware data mining function. The firmware fault data extraction function is specifically: Where F represents the firmware fault data extraction function; M represents the firmware data mining function; R(z) represents the attribute dimension of the firmware vulnerability sample data z; φ(I z ) represents the threshold value for measuring the correlation between firmware vulnerabilities, which is a set empirical value; The vulnerability feature value distance function is determined based on the firmware fault data extraction function and the firmware vulnerability sample data set. The vulnerability feature value distance function is specifically: Among them, D represents the vulnerability feature value distance function; the corresponding symbol feature numbers in the distribution gateway firmware data set are u1 and u2, and these two parameters are internal empirical coefficients; H represents the correlation between data, F represents the firmware fault data extraction function; W i The continuous power distribution edge gateway firmware data vector value; W I It is the discrete power distribution gateway firmware data vector value; The firmware vulnerability data classification matrix is ​​determined according to the vulnerability feature value distance function and the firmware vulnerability sample data set. The firmware vulnerability data classification matrix is ​​specifically: G = Q|(L1-L2)|; Q = δD + (1-δ) × D; Among them, G represents the firmware vulnerability data classification matrix; L1 and L2 represent different attributes of samples; Q represents the data continuity attribute formula; δ represents the weight factor.

8. A terminal device, characterized in that: It includes a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, it implements a method for discovering firmware vulnerabilities of a power distribution edge gateway as described in any one of claims 1 to 6.

9. A storage medium, characterized in that: The storage medium includes a stored computer program, wherein when the computer program is running, the device where the storage medium is located is controlled to execute a method for discovering firmware vulnerabilities in a power distribution edge gateway as described in any one of claims 1 to 6.

Citation Information

Patent Citations

  • Fault detection method, device and equipment of industrial control system and storage medium

    CN115309134A

  • Training method, device and equipment for vulnerability scanning strategy matching model

    CN115643075A