Vulnerability protection method, device, equipment, medium and product

By uploading vulnerability detection reports to the blockchain network and using smart contracts to generate remediation tasks, combined with a multi-signature mechanism for security testing, the single point of failure and data tampering problems of traditional vulnerability management systems are solved, thereby improving the security of vulnerability information and the stability of the system.

CN119276625BActive Publication Date: 2025-11-21CHINA CONSTRUCTION BANK +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411675054.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-21
Publication Date
2025-11-21
Estimated Expiration
2044-11-21

AI Technical Summary

Technical Problem

Traditional vulnerability management systems have the risk of single point of failure, vulnerability information is easily tampered with, manual repair is slow and may introduce new problems, resulting in low system stability.

Method used

The vulnerability detection report is uploaded to the blockchain network, and a vulnerability remediation task is generated using a smart contract. Security testing is then performed using the blockchain network's multi-signature mechanism and the smart contract's preset rules to ensure the accuracy of the vulnerability remediation results and the system's stability.

Benefits of technology

It improves the security of vulnerability information and the stability of the system, avoids introducing new problems due to vulnerability patching, and ensures the immutability and transparency of data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119276625B_ABST
    Figure CN119276625B_ABST
Patent Text Reader

Abstract

The application provides a vulnerability protection method, device, equipment, medium and product. It belongs to the technical field of network security. The method comprises the following steps: obtaining a vulnerability detection report; uploading the vulnerability detection report to a block chain network, wherein the block chain network is deployed with a smart contract; obtaining at least one vulnerability repair task, wherein the vulnerability repair task comprises a difficulty level of vulnerability repair; determining a task execution end of the at least one vulnerability repair task according to the difficulty level, and issuing the corresponding vulnerability repair task to the task execution end; obtaining a vulnerability repair result returned by the task execution end; performing security detection on the vulnerability repair result according to a multi-signature mechanism of the block chain network and a preset rule of the smart contract; and determining that the vulnerability repair is completed in the case that the vulnerability repair result passes the security detection. The technical problems of low security of vulnerability information and low stability of the system caused by vulnerability repair in the related art are solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of network security technology, and in particular relates to a vulnerability protection method, device, equipment, medium and product. Background Technology

[0002] With the rapid development of the Internet, the security of network systems has become particularly important.

[0003] Traditional vulnerability management systems rely on a centralized architecture, with all vulnerability reports and patches stored on a central server, posing a single point of failure risk. Furthermore, vulnerability information is managed through traditional databases, which carries the risk of data tampering.

[0004] In addition, existing methods for verifying vulnerability remediation results are limited and usually rely on manual remediation. This method is not only slow to respond, but also prone to introducing new problems during the remediation process, affecting system stability. Summary of the Invention

[0005] This application provides a vulnerability protection method, apparatus, device, storage medium, and computer program product to solve the technical problems of low security of vulnerability information and low system stability caused by vulnerability patching in related technologies.

[0006] In a first aspect, embodiments of this application provide a vulnerability protection method, the method comprising:

[0007] Obtain a vulnerability detection report, which includes the vulnerability type, location, and threat level of the vulnerabilities found in the system.

[0008] The vulnerability detection report is uploaded to the blockchain network, which is equipped with smart contracts. The smart contracts are used to represent the automatic execution of contract content according to preset rules.

[0009] Obtain at least one vulnerability remediation task, which is to generate a smart contract parsing vulnerability detection report. The vulnerability remediation task includes the difficulty level of the vulnerability remediation.

[0010] Based on the difficulty level, at least one task execution terminal for each vulnerability remediation task is determined, and the corresponding vulnerability remediation task is issued to the task execution terminal.

[0011] Obtain the vulnerability remediation results returned by the task execution terminal;

[0012] The vulnerability remediation results are subjected to security testing based on the multi-signature mechanism of the blockchain network and the preset rules of the smart contract.

[0013] If the vulnerability remediation results pass the security test, the vulnerability is considered to have been remediated.

[0014] Secondly, embodiments of this application provide a vulnerability protection device, which includes:

[0015] The acquisition module is used to acquire vulnerability detection reports, which include the vulnerability type, vulnerability location, and vulnerability threat level of the vulnerabilities found in the system.

[0016] The upload module is used to upload vulnerability detection reports to the blockchain network. The blockchain network is deployed with smart contracts, which are used to represent the automatic execution of contract content according to preset rules.

[0017] The acquisition module is also used to acquire at least one vulnerability remediation task, which is to generate a smart contract parsing vulnerability detection report. The vulnerability remediation task includes the difficulty level of vulnerability remediation.

[0018] The determination module is used to determine the task execution end of at least one vulnerability remediation task according to the difficulty level, and to issue the corresponding vulnerability remediation task to the task execution end.

[0019] The acquisition module is also used to acquire vulnerability remediation results returned by the task execution end;

[0020] The monitoring module is used to perform security checks on the vulnerability remediation results based on the multi-signature mechanism of the blockchain network and the preset rules of smart contracts.

[0021] The determination module is also used to confirm that the vulnerability has been fixed if the vulnerability fix results pass the security test.

[0022] Thirdly, embodiments of this application provide an electronic device, the device comprising:

[0023] Processor and memory storing programs or instructions;

[0024] The processor implements the above methods when executing programs or instructions.

[0025] Fourthly, embodiments of this application provide a computer-readable storage medium storing a program or instructions that, when executed by a processor, implement the method described above.

[0026] Fifthly, embodiments of this application provide a computer program product in which instructions, when executed by a processor of an electronic device, cause the electronic device to perform the above-described method.

[0027] In this embodiment, by uploading the obtained vulnerability detection report to the blockchain network, the smart contract of the blockchain network generates a vulnerability repair task. By utilizing the immutability of the blockchain network, the technical problem that vulnerability information is easily tampered with due to storage in traditional databases in related technologies is solved, thereby improving the security of vulnerability information. By performing security checks on the vulnerability repair results according to the multi-signature mechanism of the blockchain network and the preset rules of the smart contract, the introduction of new problems into the system due to vulnerability repair is avoided, thereby improving the stability of the system. Attached Figure Description

[0028] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments of this application will be briefly introduced below. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0029] Figure 1 This is a flowchart illustrating a vulnerability protection method according to an embodiment of the present invention;

[0030] Figure 2 This is a schematic diagram of the structure of a vulnerability protection device according to an embodiment of the present invention;

[0031] Figure 3 This is a schematic diagram of the overall process of a vulnerability protection method according to an embodiment of the present invention;

[0032] Figure 4 This is a structural block diagram of a vulnerability protection device according to an embodiment of the present invention;

[0033] Figure 5 This is a schematic diagram of the structure of an electronic device according to an embodiment of the present invention. Detailed Implementation

[0034] The features and exemplary embodiments of various aspects of this application will be described in detail below. To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings and specific embodiments. It should be understood that the specific embodiments described herein are only intended to explain this application and not to limit it. For those skilled in the art, this application can be implemented without some of these specific details. The following description of the embodiments is merely to provide a better understanding of this application by illustrating examples.

[0035] It should be noted that, in this document, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising..." does not exclude the presence of additional identical elements in the process, method, article, or apparatus that includes the element.

[0036] Furthermore, it should be noted that the acquisition, storage, use, and processing of data in this application embodiment all comply with the relevant provisions of national laws and regulations.

[0037] It should be noted that in the embodiments of this application, certain software, components, models and other existing solutions in the industry may be mentioned. These should be regarded as exemplary and are only intended to illustrate the feasibility of implementing the technical solution of this application. However, it does not mean that the applicant has used or necessarily used the solution.

[0038] In related technologies, if vulnerability remediation reports and patches are stored in traditional databases for management, the information is susceptible to data tampering and lacks transparency, resulting in low security. Manual handling of vulnerability remediation and detection is slow, and remediation may introduce new problems, leading to low system stability. Furthermore, if remediation information is stored on a central server, successful remediation experiences are difficult to share, resulting in reinventing the wheel; cross-platform information sharing is inefficient, impacting overall security.

[0039] To address the technical problems of low security of vulnerability information and low system stability caused by vulnerability patching in existing technologies, this application provides a vulnerability protection method that can be applied in a vulnerability management system for the discovery and patching of system vulnerabilities. Figure 1 This is a flowchart illustrating a vulnerability protection method according to an embodiment of the present invention, such as... Figure 1 As shown, this vulnerability protection method may include the following steps:

[0040] S110, obtain the vulnerability detection report, which includes the vulnerability type, vulnerability location, and vulnerability threat level of the system.

[0041] In S110, various methods can be used to obtain system vulnerability detection reports. For example, automated scanning tools, manual penetration testing, and comprehensive security assessments can be used to obtain vulnerability detection reports. The system can be an information system, network system, operating system, database system, or Internet of Things system, etc.

[0042] Automated scanning tools can utilize professional vulnerability scanning software currently available on the market, such as Nessus, OpenVAS, and AppScan, to quickly scan the system and generate vulnerability reports. Manual penetration testing can be conducted by hiring professional security testers. These testers can simulate hacker attack behaviors, attempt to discover vulnerabilities in the system, and then generate vulnerability reports.

[0043] A comprehensive security assessment can be conducted by acquiring system data, inputting the data into a model for vulnerability detection, analyzing the vulnerabilities found in the system, and then obtaining an initial detection report.

[0044] The model can be a vulnerability detection model based on machine learning or deep neural networks, and the analysis can be static or dynamic.

[0045] Taking an Enterprise Resource Planning (ERP) system as an example, a vulnerability detection report can include the following detailed information:

[0046] Various types of vulnerabilities exist in Enterprise Resource Planning (ERP) systems, such as: Structured Query Language (SQL) injection vulnerabilities; Cross-Site Scripting (XSS) attacks; Cross-Site Request Forgery (XSS), etc.

[0047] The specific locations of vulnerabilities in the Enterprise Resource Planning (ERP) system include: URL paths; source code files; database tables; server configuration.

[0048] The threat level of vulnerabilities in Enterprise Resource Planning (ERP) systems can be categorized based on factors such as severity, scope of impact, and exploitability. For example, vulnerability threat levels can be classified as follows: High: Vulnerabilities may lead to system crashes, data breaches, or serious security threats. Examples include SQL injection vulnerabilities and remote code execution vulnerabilities. Medium: Vulnerabilities may cause system performance degradation, partial functional failure, or lower security threats. Examples include CSRF vulnerabilities and insecure file upload vulnerabilities. Low: Vulnerabilities have a relatively minor impact on the system, but still require attention. Examples include information disclosure vulnerabilities and weak password policies.

[0049] S120 uploads the vulnerability detection report to the blockchain network. The blockchain network is equipped with smart contracts, which are used to represent the automatic execution of contract content according to preset rules.

[0050] In S120, the blockchain network can be a well-known blockchain network such as Ethereum or Bitcoin, or an enterprise blockchain network such as Hyperledger.

[0051] In this embodiment, when the blockchain network uses the Ethereum blockchain network, the smart contract can be a piece of code written in the Solidity language on the blockchain network. Developers can use Solidity to create custom smart contracts.

[0052] Vulnerability detection reports can be uploaded to the blockchain network. The specific upload time can be set as needed, including immediate upload, periodic upload, and on-demand upload. For example, after a major system update or upgrade, or when a specific type of vulnerability is discovered, the system administrator can choose to upload the corresponding report.

[0053] S130, Obtain at least one vulnerability remediation task, wherein at least one vulnerability remediation task is to generate a smart contract parsing vulnerability detection report, and the vulnerability remediation task includes the difficulty level of vulnerability remediation.

[0054] In S130, the smart contract's default rules include parsing vulnerability detection reports and generating at least one vulnerability remediation task.

[0055] For example, a smart contract can first parse the vulnerability detection report and extract key fields, such as vulnerability ID, vulnerability description, and the code segment where the vulnerability is located.

[0056] Furthermore, based on the parsed vulnerability information, the smart contract creates a remediation task for each vulnerability. These vulnerability remediation tasks can be organized into a list, and each task can contain detailed information about the vulnerability and a remediation difficulty level, which can be low, medium, or high.

[0057] For example, each vulnerability remediation task can include the following elements: Task Identifier (ID): A unique ID that identifies each remediation task; Vulnerability ID: Corresponds to the vulnerability ID in the vulnerability detection report; Vulnerability Description: Briefly describes the nature and impact of the vulnerability; Remediation Difficulty Level: Indicates the difficulty and resources required to remediate the vulnerability; Remediation Suggestions: Based on the vulnerability type and remediation experience, the smart contract can provide some remediation suggestions or reference solutions; Task Status: Indicates the current status of the task, such as "Pending", "In Progress", "Completed", etc.

[0058] Example Task ID: 002; Vulnerability ID: VULN-002; Vulnerability Description: Unauthorized access vulnerability, attackers can bypass permission checks to access sensitive data; Remediation Difficulty Level: High; Remediation Recommendation: Strengthen access control to ensure that only authorized users can access sensitive data; May require modification of the contract's access control logic; Task Status: Pending.

[0059] S140: Determine at least one task execution terminal for each vulnerability remediation task based on the difficulty level, and issue the corresponding vulnerability remediation task to the task execution terminal.

[0060] In S140, the task execution end can include development teams, operations teams, security service providers, automated remediation systems, etc.

[0061] When determining the execution platform for a vulnerability remediation task, several factors can be considered, including the difficulty level of remediation, the location of the vulnerability, the type of vulnerability, and the threat level of the vulnerability. By comprehensively considering these factors, it can be ensured that the vulnerability remediation task is assigned to the most suitable execution platform, thereby improving remediation efficiency and success rate.

[0062] For example, if the difficulty level of the vulnerability remediation task is low, the vulnerability type is cross-site scripting vulnerability, the vulnerability location is on the product details page, and the vulnerability threat level is medium, the task execution end of this vulnerability remediation task can be determined to be the automated remediation system, and the vulnerability remediation task can be sent to the automated remediation system for execution.

[0063] Furthermore, it is understandable that when issuing vulnerability remediation tasks to the task execution end, detailed vulnerability information, remediation suggestions, and necessary resource and tool support can be provided. This helps the execution end to better understand and remediate the vulnerability.

[0064] S150 retrieves the vulnerability remediation results returned by the task execution end.

[0065] In S150, after executing the corresponding vulnerability remediation task on the task execution end, the vulnerability remediation result returned by the task execution end is obtained.

[0066] S160 performs security checks on the vulnerability remediation results based on the blockchain network's multi-signature mechanism and the smart contract's preset rules.

[0067] In S160, the default rules for smart contracts can be to use multiple methods to perform security checks on the vulnerability remediation results, including automated security checks and non-automated security checks.

[0068] Automated security testing includes regression testing, vulnerability reproduction testing, integration testing, deployment verification, predefined rule verification, multi-signature mechanisms, anomaly detection, and intelligent monitoring.

[0069] For example, when the vulnerability remediation result is jointly signed by multiple preset management terminals, regression testing and / or vulnerability reproduction testing are performed on the vulnerability remediation result.

[0070] In this example, regression testing could be rerunning previous test cases after code modifications to ensure that the modifications have not introduced new problems; reproducibility testing could be re-triggering a fixed vulnerability to verify that the vulnerability has indeed been resolved.

[0071] The choice of regression and reproduction testing tools depends on the specific testing requirements, the type of system under test, and the testing team's technology stack. For example, tools such as Selenium, Watir, and Serenity BDD can be used for regression testing of vulnerability remediation results; Postman, custom scripts, and tools can be used for reproduction testing of vulnerability remediation results.

[0072] In this way, by combining the multi-signature mechanism of the blockchain network with the preset rules of smart contracts, this security detection method can ensure that the vulnerability repair results are not only recognized by multiple management ends, but also have undergone rigorous testing and verification, thereby improving the security and stability of the system.

[0073] S170: If the vulnerability remediation results pass the security test, it is determined that the vulnerability has been remediated.

[0074] In this embodiment, by uploading the obtained vulnerability detection report to the blockchain network, the smart contract of the blockchain network generates a vulnerability repair task. By utilizing the immutability of the blockchain network, the technical problem that vulnerability information is easily tampered with due to storage in traditional databases in related technologies is solved, thereby improving the security of vulnerability information. By performing security checks on the vulnerability repair results according to the multi-signature mechanism of the blockchain network and the preset rules of the smart contract, the introduction of new problems into the system due to vulnerability repair is avoided, thereby improving the stability of the system.

[0075] In some embodiments, obtaining a vulnerability detection report includes:

[0076] The system's behavioral and status data are acquired based on preset time intervals;

[0077] Behavioral and state data are input into a machine learning model for vulnerability detection to obtain detection results.

[0078] If the detection results show that the system has vulnerabilities, perform static and / or dynamic analysis on the vulnerabilities to obtain an initial detection report;

[0079] A test management and visualization platform is used to extract in-depth information from the initial detection report, including vulnerability type, vulnerability location, and vulnerability threat level, to obtain a vulnerability detection report.

[0080] In this embodiment, the preset time interval can be set to hourly, daily, weekly, etc.; the system can be a bank transaction system, which needs to process a large amount of customer transaction data, including deposit, withdrawal, transfer, and other data.

[0081] Behavioral data can include system logs, user operation records, network traffic data, etc.; status data can include system configuration, operating parameters, resource usage, etc.

[0082] A machine learning model can be a vulnerability detection model based on deep neural networks. This model learns the characteristics and patterns of vulnerabilities by training on a large amount of historical vulnerability data. Upon receiving behavioral and state data from the system, the model processes and analyzes this data to detect potential vulnerabilities. The model's design can take into account the system's characteristics and common vulnerability types, such as SQL injection and cross-site scripting attacks.

[0083] Static analysis identifies vulnerabilities by analyzing static resources such as the system's source code and configuration files. Dynamic analysis detects vulnerabilities by monitoring the system's behavior and interactions during operation. For example, this application may use SonarQube static analysis and OWASP ZAP dynamic analysis.

[0084] For test management and visualization platforms, a combination of JIRA and Tableau can be used.

[0085] Understandably, by statically analyzing a system's source code and configuration files, and dynamically analyzing the system's behavior and interactions during operation, vulnerabilities can be discovered more deeply, reducing false negatives and false negatives. Visualizing vulnerability reports through platforms in the form of charts and tables allows relevant personnel to quickly understand the system's security status and develop targeted remediation measures.

[0086] In this way, the vulnerability detection report obtained is more accurate than the vulnerability detection reports of existing technologies.

[0087] In some embodiments, uploading vulnerability detection reports to a blockchain network includes:

[0088] Obtain the preset upload rules of the blockchain network, which are based on smart contract settings;

[0089] The vulnerability detection report is formatted according to preset upload rules;

[0090] The vulnerability detection report, after being converted to the correct format, is uploaded to the blockchain network.

[0091] In this embodiment, the preset upload rules may include data format requirements, data size limits, encryption requirements, etc. These rules are set based on smart contracts and are used to guide how to correctly upload vulnerability detection reports to the blockchain network.

[0092] The vulnerability detection report may initially exist in binary, CSV, JSON, or XML format.

[0093] The vulnerability detection report is formatted according to preset upload rules;

[0094] In this step, it is important to ensure that the converted data fully and accurately reflects the information in the original vulnerability detection report.

[0095] For example, if a blockchain network requires data in JSON format, but the vulnerability report was originally in XML format, then an XML-to-JSON conversion is needed. This conversion can be achieved using libraries in programming languages ​​such as Python (e.g., xml.etree.ElementTree and JSON).

[0096] Upload the converted vulnerability detection report to the blockchain network;

[0097] In this step, the upload process involves communicating with nodes on the blockchain network to write data into the blockchain's distributed ledger. Once the data is successfully written to the blockchain, it is permanently stored and can be verified and viewed by anyone authorized to access the blockchain.

[0098] In this way, by selecting appropriate conversion methods and tools, it can be ensured that vulnerability detection reports meet the upload requirements of blockchain networks and facilitate their storage and sharing on the blockchain.

[0099] In some embodiments, the task execution end includes an automated remediation end and an engineer end; at least one task execution end for a vulnerability remediation task is determined according to the difficulty level, including:

[0100] For each vulnerability remediation task in at least one vulnerability remediation task, if the vulnerability difficulty level is low, the task execution end of the vulnerability remediation task is determined to be an automated remediation end; if the vulnerability difficulty level is medium or high, the task execution end of the vulnerability remediation task is determined to be an engineer end.

[0101] In this embodiment, the task execution end may include an automated repair end and an engineer end. The engineer end includes development teams, operation and maintenance teams, security service providers, etc., and the automated repair end may be an automated repair system.

[0102] When determining the execution platform for a vulnerability remediation task, several factors can be considered, including the difficulty level of remediation, the location of the vulnerability, the type of vulnerability, and the threat level of the vulnerability. By comprehensively considering these factors, it can be ensured that the vulnerability remediation task is assigned to the most suitable execution platform, thereby improving remediation efficiency and success rate.

[0103] Specifically, when the vulnerability difficulty level is low, the task execution end of the vulnerability remediation task can be determined to be an automated remediation end; when the vulnerability difficulty level is medium or high, the task execution end of the vulnerability remediation task can be determined to be an engineer end.

[0104] For example, the vulnerability has a low remediation difficulty level, is a cross-site scripting vulnerability, is located on the product details page, has a medium threat level, and is assigned to the automated remediation system.

[0105] In this way, by intelligently allocating vulnerability remediation tasks to the automated remediation end or the engineer end based on factors such as the vulnerability difficulty level, the efficiency of vulnerability remediation is improved while ensuring that the vulnerability can be remedied.

[0106] In some embodiments, the default rules of the smart contract include performing regression testing and / or reproduction testing on the vulnerability remediation results, and conducting security checks on the vulnerability remediation results based on the multi-signature mechanism of the blockchain network and the default rules of the smart contract, including:

[0107] Determine whether the vulnerability remediation result has been jointly signed by multiple preset management terminals;

[0108] When the vulnerability remediation results are jointly signed by multiple preset management terminals, regression testing and / or vulnerability reproduction testing are performed on the vulnerability remediation results.

[0109] In this embodiment, regression testing can be performed by rerunning previous test cases after code modifications to ensure that the modifications have not introduced new problems; reproducibility testing can be performed by re-triggering the fixed vulnerability to verify whether the vulnerability has indeed been resolved.

[0110] First, the system can determine whether the vulnerability remediation result has been jointly signed by multiple preset management terminals.

[0111] In this step, the multi-signature mechanism in the blockchain network can require a transaction or data change to be approved or signed by multiple pre-defined management terminals;

[0112] If the vulnerability remediation result is not jointly signed by these preset management terminals, then the vulnerability remediation result will be considered invalid or untrusted, and the vulnerability needs to be re-remediated.

[0113] When the vulnerability remediation results are jointly signed by multiple preset management terminals, regression testing and / or vulnerability reproduction testing are performed on the vulnerability remediation results.

[0114] In this step, regression testing aims to ensure that no new bugs were introduced during the patching process, while also verifying that the surrounding code of the patched vulnerability still functions as expected. Vulnerability reproduction testing, on the other hand, attempts to re-trigger the vulnerability under the same conditions to verify that it has indeed been successfully patched.

[0115] The choice of regression and reproduction testing tools depends on the specific testing requirements, the type of system under test, and the testing team's technology stack. For example, tools such as Selenium, Watir, and Serenity BDD can be used for regression testing of vulnerability remediation results; Postman, custom scripts, and tools can be used for reproduction testing of vulnerability remediation results.

[0116] Thus, by combining the multi-signature mechanism of the blockchain network with the preset rules of smart contracts, this security detection method can ensure that the vulnerability repair results are not only recognized by multiple management ends, but also undergo rigorous testing and verification, thereby greatly improving the security and stability of the system.

[0117] In some embodiments, at least one vulnerability remediation task is obtained, wherein the at least one vulnerability remediation task is for generating a smart contract parsing vulnerability detection report, including:

[0118] Control the smart contract to parse the vulnerability detection report and obtain the vulnerability type, vulnerability location, and vulnerability threat level;

[0119] A remediation plan is generated based on the vulnerability type, vulnerability location, and vulnerability threat level. The remediation plan includes the resources required to remediate the vulnerability, the expected remediation time, and the difficulty level of the vulnerability remediation.

[0120] Generate at least one vulnerability remediation task based on the vulnerability remediation plan.

[0121] In this embodiment, the smart contract is controlled to parse the vulnerability detection report to obtain the vulnerability type, vulnerability location, and vulnerability threat level;

[0122] In this step, by parsing the report, the smart contract can extract the type of vulnerability (such as buffer overflow, SQL injection, etc.), the specific location of the vulnerability in the code (such as file name, line number, etc.), and the threat level of the vulnerability (such as high, medium, low, etc.).

[0123] A remediation plan is generated based on the vulnerability type, vulnerability location, and vulnerability threat level. The remediation plan includes the resources required to remediate the vulnerability, the expected remediation time, and the difficulty level of the vulnerability remediation.

[0124] In this step, the remediation plan will list in detail the resources required to fix the vulnerability (such as human resources, tools, permissions, specific version patches, etc.), the expected remediation time (such as emergency remediation, on-schedule remediation, etc.), and the difficulty level of the vulnerability remediation (such as simple, medium, complex, etc.).

[0125] Generate at least one vulnerability remediation task based on the vulnerability remediation plan.

[0126] For example, if the vulnerability detection report records that the vulnerability type is SQL injection, the vulnerability location is in the user login module, the vulnerability threat level is high, then the proposed remediation plan is to use the latest patch provided by the application's official website, the expected remediation time is immediate, the difficulty level is medium, and it is assigned to security engineer A for handling.

[0127] For example, if the vulnerability detection report records a cross-site scripting vulnerability, the vulnerability location is on the product details page, the vulnerability threat level is medium, then the proposed vulnerability remediation plan is to modify the front-end code, implement strict validation and escaping of input, the expected remediation time is during the maintenance window next Monday, the difficulty level is easy, and it is assigned to front-end development engineer B.

[0128] This approach not only enables efficient vulnerability remediation and improves system security, but also ensures data immutability and transparency because the entire process is based on blockchain and smart contracts.

[0129] Figure 2 This is a schematic diagram of the structure of a vulnerability protection device according to an embodiment of the present invention, such as... Figure 2 As shown, the vulnerability protection device includes a vulnerability detection module 210, a vulnerability reporting module 220, a vulnerability repair module 230, a vulnerability verification module 240, and a consensus incentive module 250. The vulnerability detection module 210 generates a vulnerability detection report; the vulnerability reporting module 220 reports discovered vulnerabilities to the system and forwards the vulnerability detection report; the vulnerability repair module 230 uploads the vulnerability detection report to the blockchain network and receives vulnerability repair tasks sent by the blockchain network; the vulnerability verification module 240 verifies the vulnerability repair results; and the consensus incentive module 250 forwards the vulnerability repair task and provides a reward when the task execution terminal fails to return the vulnerability repair result within a preset time, so that other execution terminals can process the vulnerability repair task.

[0130] Figure 3This is a schematic diagram of the overall process of a vulnerability protection method according to an embodiment of the present invention, such as... Figure 3 As shown, it includes the following steps:

[0131] S310, vulnerability detection.

[0132] In S310, the system can perform vulnerability detection based on preset time intervals.

[0133] S320 generates a vulnerability detection report.

[0134] In S320, various methods can be used to obtain system vulnerability detection reports. For example, automated scanning tools, manual penetration testing, and comprehensive security assessments can be used to obtain vulnerability detection reports. The system can be an information system, network system, operating system, database system, or Internet of Things system, etc.

[0135] S330, submit a vulnerability report.

[0136] In S330, vulnerability detection reports are uploaded to the blockchain network.

[0137] S340, Smart Contract Repair.

[0138] In S340, smart contracts are mounted on the blockchain network. These smart contracts can parse vulnerability detection reports and generate at least one vulnerability remediation task.

[0139] S350, distribute repair tasks.

[0140] In S350, if at least one vulnerability remediation task generated by a smart contract is obtained, at least one vulnerability remediation task can be sent to the task execution end.

[0141] S360, performing a repair task.

[0142] In S360, the task execution end executes the obtained vulnerability remediation task.

[0143] S370, verify the repair results.

[0144] In S370, security checks can be performed on vulnerability remediation results based on the blockchain network's multi-signature mechanism and the smart contract's preset rules.

[0145] S380, stored on the blockchain.

[0146] In S380, once the vulnerability fix is ​​verified, all information related to the fixed vulnerability is uploaded to the blockchain for backup.

[0147] Figure 4A schematic diagram of a vulnerability protection device provided in another embodiment of this application is shown. For ease of explanation, only the parts related to the embodiments of this application are shown.

[0148] Reference Figure 4 The vulnerability protection device 400 may include:

[0149] The acquisition module 401 is used to acquire vulnerability detection reports, which include the vulnerability type, vulnerability location, and vulnerability threat level of the vulnerabilities found in the system.

[0150] Upload module 402 is used to upload vulnerability detection reports to the blockchain network. The blockchain network is deployed with smart contracts, which are used to represent the automatic execution of contract content according to preset rules.

[0151] The acquisition module 401 is also used to acquire at least one vulnerability remediation task, wherein the at least one vulnerability remediation task is the generation of a smart contract parsing vulnerability detection report, and the vulnerability remediation task includes the difficulty level of vulnerability remediation.

[0152] The determination module 403 is used to determine at least one task execution terminal for a vulnerability remediation task according to the difficulty level, and to issue the corresponding vulnerability remediation task to the task execution terminal.

[0153] The 401 module is also used to obtain the vulnerability remediation results returned by the task execution end;

[0154] The detection module 404 is used to perform security checks on the vulnerability remediation results based on the multi-signature mechanism of the blockchain network and the preset rules of the smart contract.

[0155] The determination module 403 is also used to determine that the vulnerability has been fixed if the vulnerability fix results pass the security test.

[0156] In some embodiments, the acquisition module 401 may include the following units:

[0157] The acquisition unit is used to acquire the system's behavioral and status data based on a preset time interval.

[0158] The input unit is used to input behavioral and state data into the machine learning model for vulnerability detection and obtain the detection results.

[0159] The analysis unit is used to perform static and / or dynamic analysis on the vulnerabilities when the detection results show that there are vulnerabilities in the system, and to obtain an initial detection report;

[0160] The extraction unit is used to extract in-depth information from the initial detection report using a test management and visualization platform. The in-depth information includes vulnerability type, vulnerability location, and vulnerability threat level, resulting in a vulnerability detection report.

[0161] In some embodiments, the upload module 402 may include the following units:

[0162] The acquisition unit is used to acquire the preset upload rules of the blockchain network. The preset upload rules are set based on smart contracts.

[0163] The processing unit is used to convert the format of the vulnerability detection report according to preset upload rules;

[0164] The upload unit is used to upload the converted vulnerability detection report to the blockchain network.

[0165] In some embodiments, the determining module 403 described above can also be used for:

[0166] For each vulnerability remediation task in at least one vulnerability remediation task, if the vulnerability difficulty level is low, the task execution end of the vulnerability remediation task is determined to be an automated remediation end; if the vulnerability difficulty level is medium or high, the task execution end of the vulnerability remediation task is determined to be an engineer end.

[0167] In some embodiments, the detection module 404 described above may include the following units:

[0168] The judgment unit is used to determine whether the vulnerability remediation result has been jointly signed by multiple preset management terminals;

[0169] The testing unit is used to perform regression testing and / or vulnerability reproduction testing on the vulnerability remediation results when the vulnerability remediation results are jointly signed by multiple preset management terminals.

[0170] In some embodiments, the acquisition module 401 may include the following units:

[0171] The control unit is used to control the parsing of smart contract vulnerability detection reports to obtain the vulnerability type, vulnerability location, and vulnerability threat level.

[0172] The generation unit is used to generate a remediation plan for a vulnerability based on the vulnerability type, vulnerability location, and vulnerability threat level. The remediation plan includes the resources required to remediate the vulnerability, the expected remediation time, and the difficulty level of the vulnerability remediation.

[0173] Generate at least one vulnerability remediation task based on the vulnerability remediation plan.

[0174] It should be noted that the information interaction and execution process between the above-mentioned devices / units are based on the same concept as the method embodiments of this application, and are devices corresponding to the above-mentioned vulnerability protection methods. All implementation methods in the above-mentioned method embodiments are applicable to the embodiments of this device. For details on its specific functions and the technical effects it brings, please refer to the method embodiment section, which will not be repeated here.

[0175] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the above-described division of functional units and modules is merely an example. In practical applications, the above functions can be assigned to different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiments can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit. Furthermore, the specific names of the functional units and modules are only for easy differentiation and are not intended to limit the scope of protection of this application. The specific working process of the units and modules in the above system can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.

[0176] Figure 5 This is a schematic diagram of the structure of an electronic device according to an embodiment of the present invention, such as... Figure 5 As shown:

[0177] The device may include a processor 501 and a memory 502 storing programs or instructions.

[0178] When processor 501 executes the program, it implements the steps in any of the above method embodiments.

[0179] For example, the program can be divided into one or more modules / units, one or more of which are stored in memory 502 and executed by processor 501 to complete this application. One or more modules / units can be a series of program instruction segments capable of performing a specific function, which describe the program's execution process in the device.

[0180] Specifically, the processor 501 may include a central processing unit (CPU), an application-specific integrated circuit (ASIC), or one or more integrated circuits that can be configured to implement the embodiments of this application.

[0181] Memory 502 may include mass storage for data or instructions. For example, and not limitingly, memory 502 may include a hard disk drive (HDD), floppy disk drive, flash memory, optical disk, magneto-optical disk, magnetic tape, or Universal Serial Bus (USB) drive, or a combination of two or more of these. Where appropriate, memory 502 may include removable or non-removable (or fixed) media. Where appropriate, memory 502 may be internal or external to the integrated gateway disaster recovery device. In a particular embodiment, memory 502 is non-volatile solid-state memory.

[0182] Memory may include read-only memory (ROM), random access memory (RAM), disk storage media devices, optical storage media devices, flash memory devices, and electrical, optical, or other physical / tangible memory storage devices. Therefore, typically, memory includes one or more tangible (non-transitory) computer-readable storage media (e.g., memory devices) encoded with software including computer-executable instructions, and when the software is executed (e.g., by one or more processors), it is operable to perform the operations described with reference to the methods according to one aspect of this disclosure.

[0183] The processor 501 implements any of the methods described above by reading and executing programs or instructions stored in the memory 502.

[0184] In one example, the electronic device may also include a communication interface 503 and a bus 504. The processor 501, memory 502, and communication interface 503 are connected via the bus 504 and communicate with each other.

[0185] The communication interface 503 is mainly used to realize communication between various modules, devices, units and / or equipment in the embodiments of this application.

[0186] Bus 504 includes hardware, software, or both, that couples components of an online data traffic metering device together. For example, and not limitingly, the bus may include an Accelerated Graphics Port (AGP) or other graphics bus, an Enhanced Industry Standard Architecture (EISA) bus, a Front Side Bus (FSB), HyperTransport (HT) interconnect, an Industry Standard Architecture (ISA) bus, an Infinite Bandwidth Interconnect, a Low Pin Count (LPC) bus, a memory bus, a Microchannel Architecture (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (PCI-X) bus, a Serial Advanced Technology Attachment (SATA) bus, a Video Electronics Standards Association Local (VLB) bus, or other suitable buses, or combinations of two or more of these. Where appropriate, bus 504 may include one or more buses. Although specific buses are described and illustrated in embodiments of this application, this application contemplates any suitable bus or interconnect.

[0187] Furthermore, in conjunction with the methods in the above embodiments, this application embodiment can provide a computer-readable storage medium for implementation. This computer-readable storage medium stores a program or instructions; when executed by a processor, the program or instructions implement any of the methods in the above embodiments. This computer-readable storage medium can be read by a machine such as a computer.

[0188] This application also provides a chip, which includes a processor and a communication interface. The communication interface and the processor are coupled. The processor is used to run programs or instructions to implement the various processes of the above method embodiments and achieve the same technical effect. To avoid repetition, it will not be described again here.

[0189] It should be understood that the chip mentioned in the embodiments of this application may also be referred to as a system-on-a-chip, system chip, chip system, or system-on-a-chip, etc.

[0190] This application provides a computer program product stored in a computer-readable storage medium. The program product is executed by at least one processor to implement the various processes of the above method embodiments and achieve the same technical effects. To avoid repetition, it will not be described again here.

[0191] It should be clarified that this application is not limited to the specific configurations and processes described above and shown in the figures. For the sake of brevity, detailed descriptions of known methods are omitted here. In the above embodiments, several specific steps are described and shown as examples. However, the method process of this application is not limited to the specific steps described and shown. Those skilled in the art can make various changes, modifications, and additions, or change the order of steps, after understanding the spirit of this application.

[0192] The functional modules shown in the above block diagram can be implemented as hardware, software, firmware, or a combination thereof. When implemented in hardware, they can be, for example, electronic circuits, application-specific integrated circuits (ASICs), appropriate firmware, plug-ins, function cards, etc. When implemented in software, the elements of this application are programs or code segments used to perform the required tasks. Programs or code segments can be stored on machine-readable media or transmitted over a transmission medium or communication link via data signals carried on a carrier wave. "Machine-readable media" can include any medium capable of storing or transmitting information. Examples of machine-readable media include electronic circuits, semiconductor memory devices, ROM, flash memory, erasable ROM (EROM), floppy disks, CD-ROMs, optical disks, hard disks, fiber optic media, radio frequency (RF) links, etc. Code segments can be downloaded via computer grids such as the Internet, intranets, etc.

[0193] It should also be noted that the exemplary embodiments mentioned in this application describe methods or systems based on a series of steps or apparatus. However, this application is not limited to the order of the above steps; that is, the steps can be performed in the order mentioned in the embodiments, or in a different order, or several steps can be performed simultaneously.

[0194] The aspects of this disclosure have been described above with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and program products according to embodiments of this disclosure. It should be understood that each block in the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by a computer program or instructions. These programs or instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce a machine such that these instructions, executable via the processor of the computer or other programmable data processing apparatus, enable the implementation of the functions / actions specified in one or more blocks of the flowchart illustrations and / or block diagrams. Such a processor can be, but is not limited to, a general-purpose processor, a special-purpose processor, a special application processor, or a field-programmable logic circuit. It is also understood that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can also be implemented by special-purpose hardware performing the specified functions or actions, or can be implemented by a combination of special-purpose hardware and computer instructions.

[0195] The above are merely specific embodiments of this application. Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, modules, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here. It should be understood that the protection scope of this application is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in this application, and these modifications or substitutions should all be covered within the protection scope of this application.

Claims

1. A vulnerability protection method, characterized in that, The method includes: Obtain a vulnerability detection report, which includes the vulnerability type, vulnerability location, and vulnerability threat level of the vulnerabilities found in the system; The vulnerability detection report is uploaded to a blockchain network, which is equipped with smart contracts. The smart contracts are used to represent the automatic execution of contract content according to preset rules. Obtain at least one vulnerability remediation task, wherein the at least one vulnerability remediation task is generated by the smart contract parsing the vulnerability detection report, and the vulnerability remediation task includes the difficulty level of vulnerability remediation; Based on the difficulty level, the task execution terminal of the at least one vulnerability remediation task is determined, and the corresponding vulnerability remediation task is sent to the task execution terminal. Obtain the vulnerability remediation results returned by the task execution terminal; The vulnerability repair results are subjected to security testing based on the multi-signature mechanism of the blockchain network and the preset rules of the smart contract; If the vulnerability remediation result passes the security test, the vulnerability is determined to be remediated.

2. The method according to claim 1, characterized in that, The process of obtaining the vulnerability detection report includes: The system's behavior data and status data are acquired based on a preset time interval; The behavioral data and the state data are input into a machine learning model for vulnerability detection to obtain the detection results. If the detection results indicate that the system has vulnerabilities, static and / or dynamic analysis is performed on the vulnerabilities to obtain an initial detection report; The initial detection report is subjected to in-depth information extraction using a test management and visualization platform. The in-depth information includes vulnerability type, vulnerability location, and vulnerability threat level, resulting in the vulnerability detection report.

3. The method according to claim 1, characterized in that, Uploading the vulnerability detection report to the blockchain network includes: Obtain the preset upload rules of the blockchain network, the preset upload rules being set based on the smart contract; The vulnerability detection report is formatted according to the preset upload rules; The vulnerability detection report, after being converted to the specified format, is uploaded to the blockchain network.

4. The method according to claim 1, characterized in that, The task execution end includes an automated repair end and an engineer end; The step of determining the task execution end for each of the at least one vulnerability remediation task based on the difficulty level includes: For each of the at least one vulnerability remediation task, if the vulnerability difficulty level is low, the task execution end of the vulnerability remediation task is determined to be the automated remediation end; if the vulnerability difficulty level is medium or high, the task execution end of the vulnerability remediation task is determined to be the engineer end.

5. The method according to claim 1, characterized in that, The smart contract's preset rule is to perform regression testing and / or reproduction testing on the vulnerability remediation results. The security testing of the vulnerability remediation results based on the blockchain network's multi-signature mechanism and the smart contract's preset rule includes: Determine whether the vulnerability remediation result has been jointly signed by multiple preset management terminals; When the vulnerability remediation result is jointly signed by the multiple preset management terminals, regression testing and / or vulnerability reproduction testing are performed on the vulnerability remediation result.

6. The method according to claim 1, characterized in that, The step of obtaining at least one vulnerability remediation task, wherein the at least one vulnerability remediation task is generated by the smart contract parsing the vulnerability detection report, includes: The smart contract is controlled to parse the vulnerability detection report to obtain the vulnerability type, vulnerability location, and vulnerability threat level. A remediation plan for the vulnerability is generated based on the vulnerability type, the vulnerability location, and the vulnerability threat level. The remediation plan includes the resources required to remediate the vulnerability, the expected remediation time, and the difficulty level of the vulnerability remediation. The at least one vulnerability remediation task is generated according to the vulnerability remediation plan.

7. A vulnerability protection device, characterized in that, The device includes: The acquisition module is used to acquire vulnerability detection reports, which include the vulnerability type, vulnerability location, and vulnerability threat level of the vulnerabilities found in the system. An upload module is used to upload the vulnerability detection report to a blockchain network, which is equipped with a smart contract. The smart contract is used to represent the automatic execution of contract content according to preset rules. The acquisition module is also used to acquire at least one vulnerability remediation task, wherein the at least one vulnerability remediation task is generated by the smart contract parsing the vulnerability detection report, and the vulnerability remediation task includes the difficulty level of vulnerability remediation; The determination module is used to determine the task execution terminal of the at least one vulnerability remediation task according to the difficulty level, and to issue the corresponding vulnerability remediation task to the task execution terminal. The acquisition module is also used to acquire the vulnerability remediation results returned by the task execution terminal; The monitoring module is used to perform security checks on the vulnerability remediation results based on the multi-signature mechanism of the blockchain network and the preset rules of the smart contract. The determination module is also used to determine that the vulnerability has been repaired if the vulnerability repair result passes the security test.

8. An electronic device, characterized in that, The device includes: a processor and a memory storing computer program instructions; When the processor executes the computer program instructions, it implements the method as described in any one of claims 1-6.

9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer program instructions that, when executed by a processor, implement the method as described in any one of claims 1-6.

10. A computer program product, characterized in that, When the instructions in the computer program product are executed by the processor of the electronic device, the electronic device causes the electronic device to perform the method as described in any one of claims 1-6.

Citation Information

Patent Citations

  • Managing cybersecurity vulnerabilities using blockchain networks

    CN111164948A

  • Vulnerability repairing method and device based on block chain, electronic equipment and storage medium

    CN117313162A