A vulnerability closed-loop processing method and system based on vulnerability scanning
By introducing a closed-loop vulnerability processing method and system based on vulnerability scanning into the vulnerability processing system, the problem of high pressure in existing systems when multiple types of vulnerabilities exist at the same time is solved, and customized vulnerability processing order and system stability are achieved.
Patent Information
- Application Number
- CN202410159650.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-02-04
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2044-02-04
AI Technical Summary
The existing vulnerability handling system is not targeted when managing and repairing vulnerabilities, resulting in high pressure on the system and prone to crashes when multiple types of vulnerabilities exist at the same time.
Vulnerability closed-loop processing methods and systems are adopted based on vulnerability scanning, and scan records are generated through fixed-cycle vulnerability scanning, and priority ranking of vulnerability processing and scanning cycle adjustment are carried out according to the records to ensure the targetedness of vulnerability processing and system stability.
It realizes a vulnerability processing sequence customized according to vulnerability type and frequency, reduces system pressure, avoids the risk of crashes, and improves the efficiency and stability of vulnerability management.
Smart Images

Figure CN119128890B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of vulnerability handling, and more specifically, it relates to a vulnerability closed-loop handling method and system based on vulnerability scanning. Background Art
[0002] A vulnerability is a defect in the specific implementation of hardware, software, protocols, or system security policies, which enables an attacker to access or damage the system without authorization. Currently, the vulnerability handling system has low pertinence in vulnerability management and repair, and the vulnerability management for all users has the same standard. When multiple types of vulnerabilities appear in a user's assets simultaneously, the current vulnerability handling system will repair different types of vulnerabilities simultaneously, resulting in a large pressure on the handling system for vulnerability management and repair methods, and thus it is prone to system crashes. Summary of the Invention
[0003] Aiming at the deficiencies of the existing technology, the purpose of the present invention is to provide a vulnerability closed-loop handling method and system based on vulnerability scanning.
[0004] To achieve the above purpose, the present invention provides the following technical solutions:
[0005] A vulnerability closed-loop handling method based on vulnerability scanning includes the following steps:
[0006] Step 1: Scan the user's assets based on a fixed period, obtain the user's asset information, scan the user's asset information for vulnerabilities, and generate a vulnerability scan record after each scan;
[0007] Step 2: Sort the subsequent vulnerability handling priorities of users based on the vulnerability scan record;
[0008] Step 3: Adjust the fixed period of the user's asset vulnerabilities based on the vulnerability scan record.
[0009] Furthermore, a vulnerability closed-loop handling system based on vulnerability scanning includes a vulnerability scanning module, a closed-loop handling module, and a scan adjustment module;
[0010] The vulnerability scanning module is used to scan the user's assets based on a fixed period, obtain the user's asset information, scan the user's asset information for vulnerabilities, and generate a vulnerability scan record after each scan;
[0011] The closed-loop handling module is used to process the scanned vulnerability types in sequence, specifically:
[0012] Obtain all vulnerability scan records of the user before the current system time. Mark the vulnerability scan records with the same vulnerability type as the same type of vulnerability records. Sort all the same type of vulnerability records in chronological order of the vulnerability scan time. Calculate the time difference between the vulnerability scan times of two adjacent same type of vulnerability records after sorting to obtain the same type of vulnerability interval. Set each same type of vulnerability interval to correspond to a standard vulnerability interval. When the same type of vulnerability interval < the standard vulnerability interval, mark this same type of vulnerability interval as a high-frequency vulnerability interval and obtain the high-frequency vulnerability value Fp. When the same type of vulnerability interval ≥ the standard vulnerability interval, mark this same type of vulnerability interval as a normal-frequency vulnerability interval and obtain the normal-frequency vulnerability value Dq. Obtain the closed-loop repair value Rw of this type of vulnerability. Sort all vulnerability types in descending order according to the value of the closed-loop repair value Rw. After performing a vulnerability scan on the user's asset information in the next fixed cycle, process the scanned vulnerability types in the sorted order;
[0013] The scanning adjustment module is used to adjust the fixed cycle for scanning the user's asset vulnerabilities, specifically:
[0014] Obtain all vulnerability scan records of the user before the current system time. Set the vulnerability type quantity threshold. When the number of vulnerability types in the vulnerability scan record ≥ the vulnerability type quantity threshold, mark this vulnerability scan record as a crisis scan record and obtain the crisis scan value Bc. When the number of vulnerability types in the vulnerability scan record < the vulnerability type quantity threshold, mark this vulnerability scan record as a normal scan record and obtain the normal scan value Wb. Obtain the scanning adjustment value Sy. Set the high scanning adjustment value as Cp and the low scanning adjustment value as Ea. When the scanning adjustment value Sy ≥ the high scanning adjustment value Cp, shorten the fixed cycle for the vulnerability scanning module to scan this user's assets. When the low scanning adjustment value Ea ≤ the scanning adjustment value Sy < the high scanning adjustment value Cp, do nothing. When the scanning adjustment value Sy < the low scanning adjustment value Ea, extend the fixed cycle for the vulnerability scanning module to scan this user's assets.
[0015] Further, the vulnerability scan record includes the number of vulnerability types and the vulnerability scan time.
[0016] Further, the high-frequency vulnerability value Fp is obtained through the following steps: Calculate the difference between the standard vulnerability interval and the high-frequency vulnerability interval to obtain the high-frequency interval difference. Sum up all the high-frequency interval differences to obtain the total high-frequency interval difference, which is marked as Wk. Obtain the total number of times that the same type of vulnerability interval is marked as a high-frequency vulnerability interval, which is marked as Hs. Use the formula Fp = Wk × a1 + Hs × a2 to obtain the high-frequency vulnerability value Fp, where a1 is the high-frequency interval total difference coefficient and a2 is the high-frequency vulnerability times coefficient.
[0017] Further, the general frequency vulnerability value Dq is obtained through the following steps: Calculate the difference between the general frequency vulnerability interval and the standard vulnerability interval to obtain the general frequency interval difference. Sum up all the general frequency interval differences to obtain the total general frequency interval difference, which is marked as Ty. Obtain the total number of times the same type of vulnerability interval is marked as the general frequency vulnerability interval, which is marked as Sn. Use the formula Dq = Ty×b1 + Sn×b2 to obtain the general frequency vulnerability value Dq, where b1 is the general frequency interval total difference coefficient and b2 is the general frequency vulnerability times coefficient.
[0018] Further, the closed-loop repair value Rw is obtained through the following steps: Obtain the total number of vulnerability scan records of this user before the current time of the system, which is marked as Lb. Obtain the total number of records of the same type of vulnerability of this vulnerability type of this user before the current time of the system, which is marked as Mz. Use the formula to obtain the closed-loop repair value Rw of this type of vulnerability, where c1 is the vulnerability scan quantity coefficient, c2 is the same type of vulnerability quantity coefficient, c3 is the high-frequency vulnerability value coefficient, and c4 is the general frequency vulnerability value coefficient.
[0019] Further, the crisis scan value Bc is obtained through the following steps: Calculate the difference between the number of vulnerability types in the crisis scan records and the vulnerability type quantity threshold to obtain the crisis vulnerability difference. Sum up all the crisis vulnerability differences and take the average to obtain the average crisis vulnerability difference, which is marked as Gz. Sort all the crisis scan records in chronological order of the vulnerability scan time. Calculate the time difference between two adjacent vulnerability scan times after sorting to obtain the crisis scan interval. Sum up all the crisis scan intervals and take the average to obtain the average crisis scan interval, which is marked as Ue. Use the formula to obtain the crisis scan value Bc, where d1 is the average crisis vulnerability difference coefficient and d2 is the average crisis scan interval coefficient.
[0020] Further, the normal scan value Wb is obtained through the following steps: Calculate the difference between the vulnerability type quantity threshold and the number of vulnerability types in the normal scan records to obtain the normal vulnerability difference. Sum up all the normal vulnerability differences and take the average to obtain the average normal vulnerability difference, which is marked as Fe. Sort all the normal scan records in chronological order of the vulnerability scan time. Calculate the time difference between two adjacent vulnerability scan times after sorting to obtain the normal scan interval. Sum up all the normal scan intervals and take the average to obtain the average normal scan interval, which is marked as Jt. Use the formula to obtain the normal scan value Wb, where e1 is the average normal vulnerability difference coefficient and e2 is the average normal scan interval coefficient.
[0021] Further, the scanning adjustment value Sy is obtained through the following steps: The scanning adjustment value Sy is obtained by using the formula Sy = Bc × z1 - Wb × z2, where z1 is the crisis scanning value coefficient and z2 is the normal scanning value coefficient.
[0022] Compared with the prior art, the present invention has the following beneficial effects:
[0023] 1. By setting up a closed-loop processing module, the priority of subsequent users' vulnerability handling can be sorted according to the vulnerability scanning records. On the basis of ensuring the closed-loop processing of the entire vulnerability cycle, a reasonable vulnerability handling order can be customized for the asset vulnerabilities of different users.
[0024] 2. By setting up a scanning adjustment module, the fixed cycle for scanning users' asset vulnerabilities can be adjusted based on the vulnerability scanning records. On the basis of ensuring the closed-loop processing of users' asset vulnerabilities, the scanning frequency of the system for different users' assets can be reasonably allocated. BRIEF DESCRIPTION OF THE DRAWINGS
[0025] Figure 1 is the principle block diagram of the closed-loop processing module of the present invention;
[0026] Figure 2 is the principle block diagram of the scanning adjustment module of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0027] Embodiment 1
[0028] Refer to Figure 1 , a vulnerability closed-loop processing system based on vulnerability scanning, including a vulnerability scanning module and a closed-loop processing module.
[0029] The vulnerability scanning module is used to scan the assets of users based on a fixed cycle, obtain the asset information of users, perform vulnerability scanning on the user asset information, and generate a vulnerability scanning record after each scan. The vulnerability scanning record includes the number of vulnerability types and the vulnerability scanning time. For example, the number of vulnerability types in the vulnerability scanning record 1 of user A is 3 (types a, b, and c respectively), and the vulnerability scanning time is 08:00:00 on July 13, 2023. The number of vulnerability types in the vulnerability scanning record 2 of user A is 2 (types c and d respectively), and the vulnerability scanning time is 08:00:00 on July 14, 2023.
[0030] The closed-loop processing module is used to process the scanned vulnerability types in sequence, specifically:
[0031] Obtain all vulnerability scanning records of the user before the current system time. Mark the vulnerability scanning records with the same vulnerability type as the same type of vulnerability records (for example, mark the vulnerability scanning records with vulnerability type a as the same type of vulnerability records). Sort all the same type of vulnerability records in the order of vulnerability scanning time. Calculate the time difference between the vulnerability scanning times of two adjacent same type of vulnerability records after sorting to obtain the same type of vulnerability interval. Set each same type of vulnerability interval to correspond to a standard vulnerability interval. When the same type of vulnerability interval < standard vulnerability interval, mark this same type of vulnerability interval as a high-frequency vulnerability interval, and obtain the high-frequency vulnerability value Fp. The high-frequency vulnerability value Fp is obtained through the following steps: Calculate the difference between the standard vulnerability interval and the high-frequency vulnerability interval to obtain the high-frequency interval difference. Sum up all the high-frequency interval differences to obtain the total high-frequency interval difference, which is marked as Wk. Obtain the total number of times that the same type of vulnerability interval is marked as a high-frequency vulnerability interval, which is marked as Hs. Use the formula Fp = Wk × a1 + Hs × a2 to obtain the high-frequency vulnerability value Fp, where a1 is the high-frequency interval total difference coefficient, a2 is the high-frequency vulnerability times coefficient, the value of a1 is 0.71, and the value of a2 is 0.48. When the same type of vulnerability interval ≥ standard vulnerability interval, mark this same type of vulnerability interval as a normal-frequency vulnerability interval, and obtain the normal-frequency vulnerability value Dq. The normal-frequency vulnerability value Dq is obtained through the following steps: Calculate the difference between the normal-frequency vulnerability interval and the standard vulnerability interval to obtain the normal-frequency interval difference. Sum up all the normal-frequency interval differences to obtain the total normal-frequency interval difference, which is marked as Ty. Obtain the total number of times that the same type of vulnerability interval is marked as a normal-frequency vulnerability interval, which is marked as Sn. Use the formula Dq = Ty × b1 + Sn × b2 to obtain the normal-frequency vulnerability value Dq, where b1 is the normal-frequency interval total difference coefficient, b2 is the normal-frequency vulnerability times coefficient, the value of b1 is 0.72, and the value of b2 is 0.47. Obtain the closed-loop repair value Rw of this type of vulnerability. The closed-loop repair value Rw is obtained through the following steps: Obtain the total number of vulnerability scanning records of the user before the current system time, which is marked as Lb. Obtain the total number of the same type of vulnerability records of this vulnerability type of the user before the current system time, which is marked as Mz. Use the formula Obtain the closed-loop repair value Rw for this type of vulnerability. Among them, c1 is the vulnerability scanning quantity coefficient, c2 is the coefficient of the number of similar vulnerabilities, c3 is the coefficient of high-frequency vulnerability values, c4 is the coefficient of medium-frequency vulnerability values. The value of c1 is 0.42, the value of c2 is 0.37, the value of c3 is 0.85, and the value of c4 is 0.84. Sort all vulnerability types in descending order according to the value of the closed-loop repair value Rw. After scanning the user asset information for vulnerabilities in the next fixed period, process the scanned vulnerability types in the sorted order. For example, if there are a total of 5 vulnerability types, namely a vulnerability type, b vulnerability type, c vulnerability type, d vulnerability type, and e vulnerability type, and all vulnerability types of user A are sorted in descending order of the value of the closed-loop repair value Rw as a vulnerability type, c vulnerability type, e vulnerability type, b vulnerability type, d vulnerability type. After scanning the user asset information for vulnerabilities in the next fixed period, it is found that the assets of user A have a vulnerability type and b vulnerability type, then the a vulnerability type will be processed first. By setting up a closed-loop processing module, the priority of subsequent user vulnerability processing can be sorted according to the vulnerability scanning records, and on the basis of ensuring the full-cycle closed-loop processing of vulnerabilities, a reasonable vulnerability processing order can be customized for the asset vulnerabilities of different users.
[0032] Embodiment 2
[0033] Refer to Figure 2 , on the basis of Embodiment 1, it further includes a scanning adjustment module. The scanning adjustment module is used to adjust the fixed period for scanning the user asset vulnerabilities, specifically as follows:
[0034] Obtain all the vulnerability scanning records of this user before the current time of the system, set the vulnerability type quantity threshold. When the number of vulnerability types in the vulnerability scanning record ≥ the vulnerability type quantity threshold, mark this vulnerability scanning record as a crisis scanning record, and obtain the crisis scanning value Bc. The crisis scanning value Bc is obtained through the following steps: Calculate the difference between the number of vulnerability types in the crisis scanning record and the vulnerability type quantity threshold to obtain the crisis vulnerability difference. Sum up all the crisis vulnerability differences and take the average value to obtain the average crisis vulnerability difference, which is marked as Gz. Sort all the crisis scanning records in chronological order according to the vulnerability scanning time. Calculate the time difference between two adjacent vulnerability scanning times after sorting to obtain the crisis scanning interval. Sum up all the crisis scanning intervals and take the average value to obtain the average crisis scanning interval, which is marked as Ue. Use the formula Obtain the crisis scan value Bc, where d1 is the crisis vulnerability average difference coefficient, d2 is the crisis scan average interval coefficient, the value of d1 is 0.62, and the value of d2 is 0.57. When the number of vulnerability types in the vulnerability scan record < the vulnerability type number threshold, mark this vulnerability scan record as a normal scan record, and obtain the normal scan value Wb. The normal scan value Wb is obtained through the following steps: Calculate the difference between the vulnerability type number threshold and the number of vulnerability types in the normal scan record to obtain the normal vulnerability difference. Sum up all the normal vulnerability differences and take the average to obtain the normal vulnerability average difference, which is marked as Fe. Sort all the normal scan records in chronological order of the vulnerability scan time, calculate the time difference between two adjacent vulnerability scan times after sorting to obtain the normal scan interval. Sum up all the normal scan intervals and take the average to obtain the normal scan average interval, which is marked as Jt. Use the formula Obtain the normal scan value Wb, where e1 is the normal vulnerability average difference coefficient, e2 is the normal scan average interval coefficient, the value of e1 is 0.61, and the value of e2 is 0.56. Obtain the scan adjustment value Sy. The scan adjustment value Sy is obtained through the following steps: Use the formula Sy = Bc×z1 - Wb×z2 to obtain the scan adjustment value Sy, where z1 is the crisis scan value coefficient, z2 is the normal scan value coefficient, the value of z1 is 0.23, and the value of z2 is 0.22. Set the scan adjustment high value as Cp and the scan adjustment low value as Ea. When the scan adjustment value Sy ≥ the scan adjustment high value Cp, shorten the fixed cycle for the vulnerability scan module to scan this user's assets. When the scan adjustment low value Ea ≤ the scan adjustment value Sy < the scan adjustment high value Cp, do nothing. When the scan adjustment value Sy < the scan adjustment low value Ea, extend the fixed cycle for the vulnerability scan module to scan this user's assets. Set up a scan adjustment module, which can adjust the fixed cycle for scanning the user's asset vulnerabilities based on the vulnerability scan records, and reasonably allocate the scanning frequencies of the system for different user assets on the basis of ensuring the closed-loop processing of the user's asset vulnerabilities.
[0035] Working principle:
[0036] A vulnerability closed-loop processing method based on vulnerability scanning includes the following steps:
[0037] Step 1: Scan the user's assets based on a fixed cycle, obtain the user's asset information, perform a vulnerability scan on the user asset information, and generate a vulnerability scan record after each scan;
[0038] Step 2: Sort the subsequent user's vulnerability handling priorities based on the vulnerability scan records;
[0039] Step 3: Adjust the fixed cycle of user asset vulnerabilities based on the vulnerability scanning records.
[0040] The above are only the preferred embodiments of the present invention, and the protection scope of the present invention is not limited to the above embodiments. All technical solutions falling within the concept of the present invention belong to the protection scope of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and refinements should also be regarded as within the protection scope of this template.
[0041] The above has described in detail an embodiment of the present invention, but the content described is only the preferred embodiment of the present invention and cannot be considered as limiting the implementation scope of the present invention. All equal changes and improvements made according to the scope of the present invention application should still fall within the scope covered by the patent of the present invention.
Claims
1. A vulnerability closed-loop processing method based on vulnerability scanning, characterized in that: The steps include: Step 1: Scan the user's assets based on a fixed period, obtain the user's asset information, perform vulnerability scans on the user's asset information, and generate vulnerability scan records after each scan; Step 2: Sort the vulnerability handling priorities of subsequent users based on the vulnerability scanning records; Step 3: Adjust the fixed period of user asset vulnerabilities based on vulnerability scanning records; The method is applied to a vulnerability closed-loop processing system based on vulnerability scanning, which includes a vulnerability scanning module, a closed-loop processing module, and a scanning adjustment module; The vulnerability scanning module is used to scan the user's assets based on a fixed period, obtain the user's asset information, perform vulnerability scanning on the user's asset information, and generate a vulnerability scanning record after each scan; The closed-loop processing module is used to process the scanned vulnerability types in sequence, specifically: Obtain all vulnerability scan records of the user before the current time of the system, mark vulnerability scan records with the same vulnerability type as similar vulnerability records, sort all similar vulnerability records in the order of vulnerability scan time, calculate the time difference between the vulnerability scan times of two adjacent similar vulnerability records after sorting, obtain similar vulnerability intervals, set each similar vulnerability interval to correspond to a standard vulnerability interval, when the similar vulnerability interval is less than the standard vulnerability interval, mark the similar vulnerability interval as a high-frequency vulnerability interval, and obtain a high-frequency vulnerability value Fp, when the similar vulnerability interval is greater than or equal to the standard vulnerability interval, mark the similar vulnerability interval as a common-frequency vulnerability interval, and obtain a common-frequency vulnerability value Dq, obtain a closed-loop repair value Rw of this type of vulnerability, sort all vulnerability types from large to small according to the numerical value of the closed-loop repair value Rw, and after performing vulnerability scanning on user asset information in the next fixed period, process the scanned vulnerability types in the sorted order; The scanning adjustment module is used to adjust the fixed period of scanning user asset vulnerabilities, specifically: Obtain all vulnerability scan records of the user before the current time of the system, set a threshold for the number of vulnerability types, when the number of vulnerability types in the vulnerability scan record ≥ the threshold for the number of vulnerability types, mark the vulnerability scan record as a crisis scan record, and obtain a crisis scan value Bc, when the number of vulnerability types in the vulnerability scan record < the threshold for the number of vulnerability types, mark the vulnerability scan record as a normal scan record, and obtain a normal scan value Wb, obtain a scan adjustment value Sy, set the scan adjustment high value to Cp, and set the scan adjustment low value to Ea, when the scan adjustment value Sy ≥ the scan adjustment high value Cp, shorten the fixed period for the vulnerability scan module to scan the user's assets, when the scan adjustment low value Ea ≤ the scan adjustment value Sy < the scan adjustment high value Cp, do not process, when the scan adjustment value Sy < the scan adjustment low value Ea, extend the fixed period for the vulnerability scan module to scan the user's assets; Vulnerability scanning records include the number of vulnerability types and vulnerability scanning time; The high-frequency vulnerability value Fp is obtained by the following steps: the standard vulnerability interval and the high-frequency vulnerability interval are calculated to obtain the high-frequency interval difference, all the high-frequency interval differences are summed up to obtain the total high-frequency interval difference, and marked as Wk, the total number of times the same type of vulnerability interval is marked as the high-frequency vulnerability interval is obtained, and marked as Hs, and the high-frequency vulnerability value Fp is obtained by using the formula Fp=Wk×a1+Hs×a2, where a1 is the high-frequency interval total difference coefficient, and a2 is the high-frequency vulnerability number coefficient; The common frequency vulnerability value Dq is obtained by the following steps: the common frequency vulnerability interval and the standard vulnerability interval are calculated to obtain the common frequency interval difference, all the common frequency interval differences are summed up to obtain the total common frequency interval difference and marked as Ty, the total number of times the same type of vulnerability interval is marked as the common frequency vulnerability interval and marked as Sn, and the common frequency vulnerability value Dq is obtained by using the formula Dq=Ty×b1+Sn×b2, where b1 is the common frequency interval total difference coefficient and b2 is the common frequency vulnerability number coefficient; The closed-loop repair value Rw is obtained by the following steps: obtain the total number of vulnerability scan records of the user before the current system time, and mark it as Lb; obtain the total number of vulnerability records of the same vulnerability type of the user before the current system time, and mark it as Mz; use the formula Get the closed-loop repair value Rw of this type of vulnerability, where c1 is the coefficient of vulnerability scanning quantity, c2 is the coefficient of the number of similar vulnerabilities, c3 is the coefficient of high-frequency vulnerability value, and c4 is the coefficient of general frequency vulnerability value; The crisis scan value Bc is obtained by the following steps: the difference between the number of vulnerability types recorded in the crisis scan and the threshold of the number of vulnerability types is calculated to obtain the crisis vulnerability difference, all the crisis vulnerability differences are summed and averaged to obtain the crisis vulnerability average difference, which is marked as Gz, all the crisis scan records are sorted in the order of the vulnerability scan time, the time difference between the two adjacent vulnerability scan times after sorting is calculated to obtain the crisis scan interval, all the crisis scan intervals are summed and averaged to obtain the crisis scan average interval, which is marked as Ue, and the formula is used. The crisis scanning value Bc is obtained, where d1 is the crisis vulnerability mean difference coefficient, and d2 is the crisis scanning mean interval coefficient; The normal scan value Wb is obtained by the following steps: the difference between the vulnerability type number threshold and the vulnerability type number of the normal scan record is calculated to obtain the normal vulnerability difference, all the normal vulnerability differences are summed and averaged to obtain the normal vulnerability average difference, which is marked as Fe, all the normal scan records are sorted in the chronological order of the vulnerability scan time, the time difference between the two adjacent vulnerability scan times after sorting is calculated to obtain the normal scan interval, all the normal scan intervals are summed and averaged to obtain the normal scan average interval, which is marked as Jt, and the formula is used. The normal scanning value Wb is obtained, where e1 is the normal vulnerability average difference coefficient, and e2 is the normal scanning average interval coefficient; The scanning adjustment value Sy is obtained by the following steps: the scanning adjustment value Sy is obtained by using the formula Sy=Bc×z1-Wb×z2, wherein z1 is the crisis scanning value coefficient, and z2 is the normal scanning value coefficient.
Citation Information
Patent Citations
Situation awareness network vulnerability defense method, device and system
CN114189360A
Vulnerability priority determination method and device
CN116389034A