A vulnerability accessibility rating method based on EPSS
By analyzing multimodal threat intelligence, network topology analysis and attack path simulation, dynamically assessing and optimizing the multi-dimensional characteristics and priorities of vulnerabilities, the problem of zero-day vulnerability assessment is solved, and more accurate and efficient vulnerability management and repair are achieved.
Patent Information
- Application Number
- CN202510038277.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-10
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2045-01-10
AI Technical Summary
The existing vulnerability scoring mechanism based on the EPSS model is difficult to provide accurate risk assessment when facing zero-day vulnerabilities, resulting in vulnerability priorities that may be underestimated or misjudged, affecting the timeliness and effectiveness of security protection strategies.
By analyzing multimodal data in threat intelligence, combining feature quantization and time correction strategies, a unified vulnerability multidimensional feature vector is generated; combining network topology analysis and protection strategy evaluation, environmental sensitivity scores are quantified; through attack path simulation, vulnerability priority is dynamically adjusted; based on vulnerability priority and repair dependencies, a repair task optimization model under resource and time constraints is established.
It significantly improves the accuracy and dynamicity of vulnerability accessibility ratings, provides a scientific basis for vulnerability repair prioritization and resource allocation, and improves the efficiency and actual protection effect of vulnerability management.
Smart Images

Figure CN119484153B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and more specifically, to a vulnerability accessibility rating method based on EPSS. Background Art
[0002] EPSS (Exploit Prediction Scoring System) is a scoring system that predicts the possibility of vulnerability exploitation. It aims to help security managers and researchers quickly identify high-risk vulnerabilities. EPSS evaluates the possibility of vulnerability exploitation by analyzing the technical characteristics, exploitation history, and external environmental factors of the vulnerability, and provides a scientific basis for vulnerability repair and prioritization. Vulnerability accessibility refers to the possibility of an attacker successfully reaching and exploiting a vulnerability in a specific network and system environment.
[0003] Deficiencies in existing technologies: Zero-day vulnerabilities refer to security vulnerabilities that have been discovered in systems, software or hardware but have not yet been fixed by developers. Due to the lack of historical data, attack samples and sufficient utilization information, the scoring mechanism based on the EPSS model is difficult to provide accurate risk assessment when facing zero-day vulnerabilities. This may lead to the vulnerability priority being underestimated or misjudged, which in turn affects the timeliness and effectiveness of security protection strategies. In actual applications, zero-day vulnerabilities are often highly uncertain, and attackers may quickly develop and exploit tools and launch attacks. Traditional models based on historical data and static features cannot quickly adapt to these sudden risks. This lack of responsiveness will cause high-risk zero-day vulnerabilities to be exposed in the production environment in a short period of time, increasing the possibility of the system being compromised, and may prolong the vulnerability exposure cycle due to improper repair priorities, posing a serious threat to the organization's information assets and business continuity. Summary of the invention
[0004] In order to overcome the above defects of the prior art, there is a solution as follows to solve the problem of unclear vulnerability path analysis in the above background technology.
[0005] To achieve the above object, the present invention provides the following technical solutions:
[0006] A vulnerability accessibility rating method based on EPSS includes the following steps:
[0007] Analyze the multimodal data in threat intelligence and generate a unified multi-dimensional feature vector of vulnerabilities through feature quantification and time correction strategies to determine the exploitation of vulnerabilities;
[0008] Combine network topology analysis with protection strategy assessment to extract vulnerability environment context characteristics, and quantify environmental sensitivity scores through network exposure, asset dependency, and protection effectiveness to assess vulnerability risks;
[0009] Construct network attack paths, dynamically adjust vulnerability priorities based on path weights and protection measures, quantify the contribution of vulnerabilities in the attack chain through path importance, and determine vulnerability priorities in critical paths;
[0010] Combining vulnerability priorities with repair dependencies, an optimization model for repair tasks under resource and time constraints is established, and the task execution sequence is allocated and generated for vulnerability repair.
[0011] In a preferred embodiment, the multimodal data in the threat intelligence is parsed, and a unified vulnerability multidimensional feature vector is generated through feature quantification and time correction strategy to determine the exploitation of the vulnerability. The specific steps are as follows:
[0012] Acquire and parse multimodal data, which includes vulnerability description text, exploit code status, propagation rate, and impact range. Parse the multimodal data to obtain semantic feature representation, exploit code status score, propagation rate score, and impact range score.
[0013] Integrate the parsed multimodal data into a unified vulnerability multidimensional feature vector;
[0014] The multidimensional feature vector of the vulnerability is time-corrected, and the feature weight of the multidimensional feature vector of the vulnerability is adjusted based on the disclosure time difference.
[0015] In a preferred embodiment, network topology analysis and protection strategy evaluation are combined to extract vulnerability environment context characteristics, and the environmental sensitivity score is quantified by network exposure, asset dependency and protection effectiveness. The specific steps include:
[0016] Perform network exposure analysis to obtain the exposure of the marked device to the external network and express it as , get the number of ports open on the device and express it as ; Get the number of connections between the device and the node and express it as , the network exposure calculation formula is: ;
[0017] Calculate the importance of network topology and obtain the center value Used to measure the potential of a device as a critical path or hub node. The central value calculation formula is: , Indicates the device The number of connections;
[0018] Business importance scoring, each asset The importance of Indicates that, combined with the scope of vulnerability impact Calculate the business importance score: ,in, Representing assets The weighting of the business; Indicates that vulnerability i is in the asset The impact factor on
[0019] To perform asset dependency score calculation: ,in, Depends on assets The node set of Representing assets The number of connections;
[0020] Firewall rules are matched. If the vulnerable traffic is blocked, it is marked as 1. If the vulnerable traffic is not blocked, it is marked as 0.
[0021] Check whether the device where vulnerability i is located is in the isolated partition and evaluate the isolation strength: , Indicates the strength of the isolation strategy;
[0022] Perform sensitivity score calculation to calculate the environmental sensitivity score of the vulnerability : ,in, Score your network exposure. is the topological importance of the device in the network, Score the business impact of the vulnerability, To check whether the protection measures have blocked the vulnerability, is the isolation strength, Score asset dependencies.
[0023] In a preferred embodiment, the vulnerability risk is assessed in the following specific steps:
[0024] Obtain the EPSS score of the vulnerability and the environmental sensitivity score of the vulnerability, and calculate the comprehensive risk score;
[0025] Based on the comprehensive risk score, vulnerabilities are divided into different risk levels. When the comprehensive risk score is greater than the high risk threshold, the risk level is high risk level;
[0026] When the comprehensive risk score is greater than or equal to the low risk threshold and less than or equal to the high risk threshold, the risk level is medium risk level;
[0027] When the comprehensive risk score is less than the low risk threshold, the risk level is low risk level.
[0028] In a preferred embodiment, a network attack path is constructed, and vulnerability priorities are dynamically adjusted in combination with path weights and protection measures. The contribution of vulnerabilities in the attack chain is quantified by path importance, and vulnerability priorities in the critical path are determined, including the following steps:
[0029] Based on the network structure, an attack path map is constructed and all paths from the attack starting point to the target asset are generated. The attack path map includes the starting point and the end point.
[0030] Evaluate the contribution of each vulnerability in the path, including its sensitivity and the criticality of its position in the path, and the vulnerability weight Indicates that vulnerability i is in the path Contributions in: ,in, Score the environmental sensitivity of the vulnerability; is the distance from vulnerability i to the target asset;
[0031] Path Weight Indicates the path Overall importance: ,in, For path The set of vulnerable nodes in ;
[0032] Based on the path weights and protection measures, the priority of the vulnerabilities is adjusted to tilt the repair resources towards the vulnerabilities. The comprehensive score of vulnerability i According to the contribution of all paths, we can get: ,in, For path The weight of is the path length.
[0033] In a preferred embodiment, the vulnerability priority and repair dependency are combined to establish a repair task optimization model under resource and time constraints, and the task execution order is allocated and generated to repair the vulnerability, including the following steps:
[0034] Build a quantitative model for each vulnerability repair task to determine resource requirements, time costs, and repair dependencies;
[0035] Determine the objective function and constraints for the repair task optimization and establish a complete optimization problem;
[0036] The optimization goal of the objective function is to minimize the total risk of unfixed vulnerabilities when the total amount of resources is determined;
[0037] The constraint definition includes that the total allocated resources do not exceed the set resources, the total allocated time does not exceed the set time, and the dependency relationship satisfies the order;
[0038] The ant colony optimization algorithm is used to solve the task allocation, the pheromone trajectory is updated according to the priority and completion of the repair task, the sequential allocation of the repair task is simulated, the task allocation path is generated, and the repair allocation plan for each vulnerability is output according to the task allocation path, including the allocated resources and the allocated repair time.
[0039] Technical effects and advantages of the EPSS-based vulnerability accessibility rating method of the present invention:
[0040] The present invention analyzes multimodal data in threat intelligence, combines feature quantification with time correction strategies, dynamically generates a unified multi-dimensional feature vector of vulnerabilities, and accurately evaluates vulnerability exploitation; combines network topology analysis with protection strategy evaluation, quantifies environmental sensitivity scores, and comprehensively analyzes the risks of vulnerabilities in actual scenarios; through attack path simulation, dynamically adjusts vulnerability priorities in combination with path weights and protection measures, quantifies the criticality of vulnerabilities in the attack chain, and ensures that high-risk vulnerabilities in critical paths are given priority; based on vulnerability priorities and repair dependencies, establishes a repair task optimization model under resource and time constraints, scientifically allocates repair resources and time, and generates an optimal repair task sequence, which significantly improves the accuracy and dynamics of vulnerability accessibility ratings, provides a basis for vulnerability repair priority sorting and resource allocation, and improves the efficiency of vulnerability management and the actual protection effect. BRIEF DESCRIPTION OF THE DRAWINGS
[0041] Figure 1 The present invention is a flowchart of a vulnerability accessibility rating method based on EPSS. DETAILED DESCRIPTION
[0042] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0043] In order to achieve the above objectives, Figure 1 A structural diagram of a vulnerability accessibility rating method based on EPSS of the present invention is given, which specifically includes the following steps:
[0044] Analyze the multimodal data in threat intelligence and generate a unified multi-dimensional feature vector of vulnerabilities through feature quantification and time correction strategies to determine the exploitation of vulnerabilities;
[0045] Combine network topology analysis with protection strategy assessment to extract vulnerability environment context characteristics, and quantify environmental sensitivity scores through network exposure, asset dependency, and protection effectiveness to assess vulnerability risks;
[0046] Construct network attack paths, dynamically adjust vulnerability priorities based on path weights and protection measures, quantify the contribution of vulnerabilities in the attack chain through path importance, and determine vulnerability priorities in critical paths;
[0047] Combining vulnerability priorities with repair dependencies, an optimization model for repair tasks under resource and time constraints is established, and the task execution sequence is allocated and generated for vulnerability repair.
[0048] Step 1: Conduct multi-dimensional feature modeling of zero-day vulnerabilities, analyze the complex and diverse data forms in threat intelligence, and convert unstructured and structured data into quantitative features. The specific steps are as follows:
[0049] Zero-day vulnerabilities lack historical exploitation data, so their feature modeling needs to rely on multi-source intelligence to extract the technical characteristics, exploitation potential, and spread impact of the vulnerability. Intelligence sources include vulnerability databases (such as CVE, NVD), security reports, PoC platforms, and network traffic logs. The data may be in the form of text descriptions, numerical features, and time series. Multimodal data collected from various data sources is parsed to extract basic features, including: vulnerability description text , using the code status (Statistics from threat intelligence platforms, vulnerability databases such as Exploit-DB, or security communities), propagation rate (number of propagation events per unit time), impact range (Number of target systems);
[0050] The vulnerability description text contains key information such as the vulnerability type, triggering conditions, impact scope, and repair difficulty. In order to build technical features, it is necessary to convert unstructured text into semantic feature representation: ,in, is the word vector of the tth word, which is used to capture the semantic information of technical keywords; is the frequency of the tth word, which is used to measure the importance of the word in the vulnerability description. The denominator limits the impact of high-frequency words on the feature vector. T is the total number of words. By taking the logarithm of the word frequency and normalizing it, the interference of high-frequency words is avoided, while highlighting the contribution of technology-related words.
[0051] Vulnerability description text is the most direct source of information in threat intelligence. By parsing the text description, technical terms, vulnerability types and their details can be extracted to form a preliminary characterization of the technical characteristics of the vulnerability. For example, keywords such as "remote code execution" can significantly improve the technical score of the vulnerability.
[0052] PoC code (proof of concept code) is an important indicator of the potential for vulnerability exploitation. The code status scoring formula is: ,in, It is a range-limiting function, which means limiting the score to the range [−1, 1] to prevent the influence of extreme values; Indicates the sensitivity of the impact of the number of PoC codes on the score; Indicates the number of proof-of-concept codes (PoCs) disclosed for vulnerability i, which strengthens the nonlinear contribution of the number of PoCs to the score;
[0053] PoC code is an important starting point for attackers to develop exploit tools. The existence of multiple PoC codes not only increases the possibility of vulnerability exploitation, but also reflects the attention paid to the vulnerability in the attacker community. For example, a vulnerability with dozens of PoC codes is significantly more risky than a vulnerability without PoC.
[0054] The propagation rate score indicates the intelligence propagation rate, reflecting the degree of spread of the vulnerability in the intelligence network. The propagation rate score formula is: ,in, It indicates the speed at which information related to vulnerability i spreads in the network per unit time. , To regulate the periodicity and growth amplitude of the dissemination rate, the sine function captures the volatility of intelligence dissemination (such as sudden dissemination peaks);
[0055] The faster the intelligence spreads, the more attention the vulnerability receives, and attack tools may be developed more quickly. For example, a vulnerability whose spread rate increases rapidly in a short period of time (such as a zero-day vulnerability) usually requires a higher score weight.
[0056] Impact Scoring Indicates the number of target assets that may be affected by the vulnerability, which needs to be quantified nonlinearly to balance the impact. The formula is: ,in, Indicates the number of target assets that vulnerability i may affect. is the score attenuation factor, which indicates the nonlinear contribution strength of the number of assets to the score. It is expressed as a weight decay term, which is used to suppress the number of assets with low score impact;
[0057] Specifically, the more target systems a vulnerability affects, the greater its potential risk. However, simply adding up the number of assets may lead to distorted scoring, especially when the number of assets is extremely large or small. The above impact range scoring formula balances the scoring effect of the number of assets through nonlinear modeling.
[0058] The parsed independent features are integrated into a unified vector representation, that is, the above independently extracted features are vectorized to construct a multi-dimensional representation of vulnerability i: vulnerability multi-dimensional feature vector , including technical characteristics, propagation characteristics and impact characteristics: ;
[0059] The characteristics of vulnerabilities are distributed in four dimensions: technology, exploitation, propagation, and impact. The comprehensive representation of each dimension is the basis for vulnerability risk rating. For example, a high technical complexity ( High), rapid spread ( high) and has a wide impact ( Vulnerabilities with a high level of security risk are bound to have a high risk.
[0060] Time correction and dynamic adjustment are performed because the timeliness of vulnerability intelligence directly affects its exploitability. Vulnerabilities with newer disclosure times are often more risky, while older intelligence needs to be dynamically adjusted to reduce priority. Therefore, time correction is performed on the vulnerability multidimensional feature vector, combining the disclosure time difference Adjust the feature weight of the vulnerability multidimensional feature vector. The correction formula is: ,in, The difference between the vulnerability intelligence disclosure time and the current time, in hours. Smaller) will receive a higher correction weight, and as time increases, the correction weight gradually weakens, so that the score reflects the actual possibility of utilization.
[0061] In summary, through text parsing, feature quantification, vector combination and time correction, this step constructs a complete zero-day vulnerability multi-dimensional feature modeling process to ensure that the technical characteristics, exploitation potential, propagation dynamics and asset impact of the vulnerability are fully characterized. The final generated feature vector correction provides a scientific basis for subsequent environmental sensitivity analysis and comprehensive scoring, while enhancing the model's adaptability to real-time intelligence.
[0062] Step 2: Analyze the vulnerability environment context characteristics and evaluate the sensitivity. After completing the multi-dimensional feature modeling of the vulnerability, it is necessary to further combine the network environment, asset location and protection strategy where the vulnerability is located to evaluate its actual exploitation risk in a specific context. By analyzing the environmental context characteristics of the vulnerability, the sensitivity score is calculated to reflect the importance and ease of exploitation of the vulnerability in the current scenario. The specific steps are as follows:
[0063] Analyze the network environment characteristics, evaluate the network exposure of the device where the vulnerability is located and its importance in the network, and quantify the risk of the device being used in the entire network environment. The specific steps are as follows:
[0064] Conduct network exposure analysis, device The exposure of the vulnerability directly affects the possibility of being exploited by external attackers. The device is directly exposed to the external network (1 means exposed) and expressed as , get the number of ports open on the device and express it as , determine whether more ports may increase the attack surface; get the number of connections between the device and other nodes and express it as , used to analyze the impact on its value as a springboard, obtained through network scanning tools (such as Nmap), the network exposure calculation formula is: ;
[0065] Even if the vulnerability technology complexity of an external network device is relatively low, it is more likely to be attacked than an internal network device. The database server exposed to the Internet has multiple open ports that may become attack entry points;
[0066] Calculate the importance of network topology. In the network topology G(V, E), it is constructed through the network traffic monitoring system or CMDB (configuration management database). V represents the network node, and E represents the connection between network nodes. The connection status of the device node determines its role and importance in the network. The central value It is used to measure the potential of a device as a critical path or hub node, reflecting the relative importance of the device in the overall network. The central value calculation formula is: , Indicates the device The number of connections (degree).
[0067] Asset characteristic analysis, that is, combining the asset type and business relevance affected by the vulnerability to assess the potential business risk of the vulnerability;
[0068] Business importance scoring is performed. Different assets contribute differently to the business. When key assets are affected by vulnerabilities, serious business interruptions may occur. The importance of Indicates that, combined with the scope of vulnerability impact Calculate the business importance score: ,in, Representing assets The weight of the business can be determined by the scores of business department experts or by the analysis of historical events; Indicates that vulnerability i is in the asset The impact factor on is provided by the vulnerability scanning tool;
[0069] Whether the asset affected by a vulnerability is a critical business system is the key to determining its priority. For example, if the vulnerability only affects the test server, the risk is relatively low; but if it involves the financial system, the risk is extremely high.
[0070] Calculate asset dependency score, assets Dependencies in the network reflect the degree to which other assets rely on it, affecting the associated risks of vulnerabilities: ,in, Depends on assets A collection of nodes, which can analyze the dependencies between assets through network topology. Representing assets degree;
[0071] If a vulnerability affects a high-dependency asset, such as a domain controller, the risk will be much higher than an isolated, non-critical asset. The dependency score helps quantify this indirect risk.
[0072] Conduct protection strategy analysis, evaluate the blocking effect of existing security measures (such as firewall rules and logical isolation) on vulnerability exploitation, and quantify the effectiveness of protection measures;
[0073] Perform firewall rule matching, that is, check whether the vulnerability-related traffic complies with the existing firewall rules. If the vulnerability traffic is blocked, it is marked as 1, and if the vulnerability traffic is not blocked, it is marked as 0. This can be obtained through the security configuration management tool;
[0074] At the same time, check whether the device where vulnerability i is located is located in the isolated partition and evaluate its isolation strength: , Indicates the strength of the isolation policy (such as the number of hops in the isolated network), which is obtained through the security configuration management tool;
[0075] The degree of device isolation directly affects the possibility of vulnerability exploitation. For example, even if an isolated network in an industrial control system has a high-risk vulnerability, its actual risk may be significantly reduced due to isolation measures;
[0076] Calculate the sensitivity score by integrating the analysis results of network exposure, asset characteristics and protection strategies to calculate the environmental sensitivity score of the vulnerability : ,in, Score your network exposure. is the topological importance of the device in the network, Score the business impact of the vulnerability, The blocking status of the vulnerability by the protection measures (0 or 1). is the isolation strength, Scoring asset dependencies;
[0077] The technical characteristic score (such as EPSS score) and the environmental sensitivity score are combined to reflect the overall risk of the vulnerability, as follows:
[0078] Get the EPSS score of vulnerability i , get the environmental sensitivity score of vulnerability i , calculate the comprehensive risk score: ,in, , is the weight coefficient, which indicates the relative importance of technical characteristics and environmental context, and can be adjusted through historical data or actual scenarios;
[0079] Based on the comprehensive risk score, vulnerabilities are divided into different risk levels to facilitate management and repair decisions. The threshold segmentation method can be used: When When , the risk level is medium risk level; when , the risk level is low risk level, among which, represents a low risk threshold, Indicates a high risk threshold;
[0080] High-risk vulnerabilities should be repaired first, while low-risk vulnerabilities can be temporarily ignored or observed. Risk classification can help clarify the priority of repair.
[0081] In summary, this step dynamically evaluates the sensitivity score of the vulnerability in a specific scenario through a comprehensive analysis of the network environment, asset characteristics, and protection strategy, and quantifies the contextual risk of the vulnerability.
[0082] Step 3: Exploitation priority adjustment based on attack path simulation. After completing the vulnerability environment context sensitivity score, it is necessary to further analyze the role of the vulnerability in the attack path to determine its actual utilization priority. The attack path simulation quantifies the possibility of vulnerability exploitation and its criticality in the attack chain through network topology analysis, attacker behavior modeling and vulnerability feature integration. The specific steps are as follows:
[0083] Based on the network structure, an attack path graph P(V, E) is constructed, and all possible paths from the attack starting point to the target asset are generated. The network topology consists of a node set V (network devices) and an edge set E (connection relationships between network devices);
[0084] The specific contents of the generated path are as follows: the starting point, i.e., the device exposed to the external network, is determined as a potential entry point of the attack path; the end point, i.e., the key assets (such as databases, domain control servers, etc.);
[0085] Use the depth-first search (DFS) algorithm to generate all possible paths from the attack starting point (such as a node exposed to the external network) to the target asset. , record the path length (all device nodes passed in the path) and the set of intermediate nodes (all device nodes passed in the path);
[0086] A complex network may have multiple paths, and attackers can choose the shortest path or the path that is easiest to break through. The path from the external network server through the intermediate springboard to the target database may include several weakly protected nodes. Path generation can help analyze these potential threats.
[0087] Evaluate the contribution of each vulnerability in the path, including its sensitivity and the criticality of its position in the path, and the vulnerability weight Indicates that vulnerability i is in the path Contributions in: ,in, Score the vulnerability’s environmental sensitivity (from step 2) to measure the vulnerability’s exploitability; is the distance from vulnerability i to the target asset, reflecting its position in the path;
[0088] Path Weight Indicates the path Overall importance: ,in, For path The set of vulnerable nodes in ;
[0089] Based on path weights and protection measures, the comprehensive priority of vulnerabilities is dynamically adjusted to tilt repair resources toward key vulnerabilities. The comprehensive score of vulnerability i The contribution of all paths is combined to obtain: ,in, For path The weight of is the path length, with the effect of longer paths diminishing;
[0090] A vulnerability may appear in multiple paths at the same time, and its total score is a comprehensive measure of the risks of all paths. If a high-sensitivity vulnerability appears in two important paths at the same time, its overall score will increase significantly.
[0091] Furthermore, the priority of the vulnerabilities is adjusted according to the protection measures. If the protection measures are strong, the priority is lowered; if the protection measures are weak, the priority is kept high.
[0092] An attacker may try to reach the target asset through multiple paths. The vulnerabilities in the paths are nodes that the attacker can exploit. The weight of the attack path depends on the sensitivity of the vulnerabilities in the path and the overall characteristics of the path. Dynamically adjusting the vulnerability priority not only reflects its technical characteristics, but also comprehensively considers its position in the path and the existing protection measures;
[0093] The web server exposed on the external network has vulnerability v1, which directly leads to the intermediate springboard server v2 and finally reaches the database v3. If v3 is the end point of the critical path, its priority needs to be significantly increased, even if v1 has a higher technical score;
[0094] If there is a firewall on the path that effectively blocks v2, the importance of the path will be significantly reduced, and the priorities of the corresponding vulnerabilities v1 and v3 will also need to be dynamically adjusted.
[0095] In summary, this step fully analyzes the possibility and criticality of vulnerability exploitation in the actual network through attack path simulation, vulnerability effect quantification and dynamic priority adjustment. Combined with the comprehensive consideration of path risk and protection measures, the priority adjustment is closer to actual needs, providing accurate support for repair decisions.
[0096] Step 4: Optimize the allocation of zero-day vulnerability repair tasks. That is, after completing the exploit priority adjustment based on attack path simulation, it is necessary to allocate repair tasks for high-priority vulnerabilities. The optimization of repair task allocation not only needs to consider the priority of the vulnerability, but also needs to comprehensively consider the limitation of repair resources, task complexity and time constraints to ensure that the repair efficiency is maximized and key vulnerabilities are handled first. The specific steps are as follows:
[0097] Establish a quantitative model for each vulnerability repair task, clarify its resource requirements, time cost and repair dependencies, and build basic data for optimization problems;
[0098] Each vulnerability The repair of the system requires certain resources, including manpower, tools and time. The resource requirements are modeled as follows: ,in The basic complexity of vulnerability repair is determined by the vulnerability type and technical characteristics; It is the familiarity of the repair team with the vulnerability repair task. The lower the value, the less experience and the higher the resource demand. The urgency of the task, which depends on the vulnerability priority (from step 3);
[0099] The repair time is quantified as follows: ,in, For loopholes The baseline time required to fix the vulnerability, taking into account the technical complexity of the vulnerability and the steps required to fix it; To fix the team's vulnerabilities The efficiency factor of repair reflects the team's ability to repair vulnerabilities under current conditions;
[0100] The repair of some vulnerabilities may depend on the previous repair of other vulnerabilities. The dependency relationship is represented by a directed graph D(V, E), where V is the set of vulnerabilities and E is the dependency relationship (if , indicating a vulnerability Fix dependency vulnerabilities The repair is complete);
[0101] At the same time, the objective function and constraints of the repair task optimization are clarified to establish a complete optimization problem;
[0102] The objective function is defined as follows:
[0103] The optimization goal is to minimize the total risk of unfixed vulnerabilities when the total amount of resources is limited: ,in, is the vulnerability priority, For loopholes The residual risk that is not repaired under current conditions is calculated as: ,in, Assign to vulnerability Repair time;
[0104] Constraints are defined as follows: total allocated resources cannot exceed available resources (set resources), total allocated time cannot exceed available time (set time); dependencies must satisfy sequentiality, i.e., repairing the current defect requires repairing the previous defect first;
[0105] Optimize the task of repairing defects, solve the allocation plan of repair tasks through optimization algorithms, and determine the optimal allocation of resources and time;
[0106] The ant colony optimization algorithm is used to solve the task allocation problem. The pheromone trajectory is updated according to the priority and completion of the repair task, the sequential allocation of the repair task is simulated, and the task allocation path is generated. The specific process is as follows:
[0107] Initialization: Initialize the task list according to priority and repair time;
[0108] Path generation: Based on the dependency relationship D(V, E), a feasible repair task sequence is constructed;
[0109] Pheromone update: Dynamically adjust pheromones based on task completion to strengthen the distribution path of high-priority vulnerabilities;
[0110] Output the patch allocation plan for each vulnerability, including the allocated resources and the allocated patch time.
[0111] This step establishes a complete repair task allocation process through three parts: repair task requirement modeling, optimization goal and constraint definition, and task optimization solution. Repair task allocation is carried out based on a comprehensive analysis of resource limitations, time constraints, and vulnerability dependencies.
[0112] This invention comprehensively evaluates the accessibility rating of vulnerabilities through multi-dimensional analysis and dynamic adjustment. Technical characteristics provide basic risk analysis, environmental context and attack chain simulation supplement scenario-based and link-based evaluation, and repair optimization links the rating results with actual repair actions, forming a complete closed loop from risk assessment to resource decision-making.
[0113] It should be noted that the threshold information in this embodiment is pre-set by professionals and will not be explained in detail here. Some parameter English letters in the embodiments have the same situation, but different meanings are explained when used, which will not be explained one by one here.
[0114] The present invention analyzes multimodal data in threat intelligence, combines feature quantification with time correction strategies, dynamically generates a unified multi-dimensional feature vector of vulnerabilities, and accurately evaluates vulnerability exploitation; combines network topology analysis with protection strategy evaluation, quantifies environmental sensitivity scores, and comprehensively analyzes the risks of vulnerabilities in actual scenarios; through attack path simulation, dynamically adjusts vulnerability priorities in combination with path weights and protection measures, quantifies the criticality of vulnerabilities in the attack chain, and ensures that high-risk vulnerabilities in critical paths are given priority; based on vulnerability priorities and repair dependencies, establishes a repair task optimization model under resource and time constraints, scientifically allocates repair resources and time, and generates an optimal repair task sequence, which significantly improves the accuracy and dynamics of vulnerability accessibility ratings, provides a basis for vulnerability repair priority sorting and resource allocation, and improves the efficiency of vulnerability management and the actual protection effect.
[0115] The above formulas are all dimensionless and numerical calculations. The formula is a formula for the most recent real situation obtained by collecting a large amount of data and performing software simulation. The preset parameters in the formula are set by technicians in this field according to actual conditions.
[0116] The above embodiments may be implemented in whole or in part by software, hardware, firmware or any other combination. When implemented by software, the above embodiments may be implemented in whole or in part in the form of a computer program product.
[0117] Those of ordinary skill in the art will appreciate that the modules and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0118] In addition, each functional module in each embodiment of the present application may be integrated into one processing module, or each module may exist physically separately, or two or more modules may be integrated into one module.
[0119] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art who is familiar with the present technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.
[0120] Finally: The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the protection scope of the present invention.
Claims
1. A vulnerability accessibility rating method based on EPSS, characterized by: The steps include: Analyze the multimodal data in threat intelligence and generate a unified multi-dimensional feature vector of vulnerabilities through feature quantification and time correction strategies to determine the exploitation of vulnerabilities; Combine network topology analysis with protection strategy assessment to extract vulnerability environment context characteristics, and quantify environmental sensitivity scores through network exposure, asset dependency, and protection effectiveness to assess vulnerability risks; Construct network attack paths, dynamically adjust vulnerability priorities based on path weights and protection measures, quantify the contribution of vulnerabilities in the attack chain through path importance, and determine vulnerability priorities in critical paths; Combine vulnerability priorities with repair dependencies, establish a repair task optimization model under resource and time constraints, and assign and generate task execution sequences to repair vulnerabilities; Construct a network attack path, dynamically adjust vulnerability priorities based on path weights and protection measures, quantify the contribution of vulnerabilities in the attack chain through path importance, and determine the vulnerability priorities in the critical path, including the following steps: Based on the network structure, an attack path map is constructed and all paths from the attack starting point to the target asset are generated. The attack path map includes the starting point and the end point. Assess the contribution of each vulnerability in the path, including its sensitivity and the criticality of its position in the path, and the vulnerability weight Indicates that vulnerability i is in the path Contributions in: ,in, Score the environmental sensitivity of the vulnerability; is the distance from vulnerability i to the target asset; Path Weight Indicates the path Overall importance: ,in, For path The set of vulnerable nodes in ; Based on the path weights and protection measures, the priority of the vulnerabilities is adjusted to tilt the repair resources towards the vulnerabilities. The comprehensive score of vulnerability i According to the contribution of all paths, we can get: ,in, For path The weight of is the path length.
2. A vulnerability accessibility rating method based on EPSS according to claim 1, characterized in that: Analyze the multimodal data in threat intelligence, and generate a unified multi-dimensional feature vector of the vulnerability through feature quantification and time correction strategy to determine the exploitation of the vulnerability. The specific steps are as follows: Acquire and parse multimodal data, which includes vulnerability description text, exploit code status, propagation rate, and impact range. Parse the multimodal data to obtain semantic feature representation, exploit code status score, propagation rate score, and impact range score. Integrate the parsed multimodal data into a unified vulnerability multidimensional feature vector; The multidimensional feature vector of the vulnerability is time-corrected, and the feature weight of the multidimensional feature vector of the vulnerability is adjusted based on the disclosure time difference.
3. A vulnerability accessibility rating method based on EPSS according to claim 2, characterized in that: Combine network topology analysis with protection strategy assessment to extract vulnerability environment context characteristics and quantify the environmental sensitivity score through network exposure, asset dependency, and protection effectiveness. The specific steps include: Perform network exposure analysis to obtain the exposure of the marked device to the external network and express it as , get the number of ports open on the device and express it as ; Get the number of connections between the device and the node and express it as , the network exposure calculation formula is: ; Calculate the importance of network topology and obtain the center value Used to measure the potential of a device as a critical path or hub node. The central value calculation formula is: , Indicates the device The number of connections; Business importance scoring, each asset The importance of Indicates that, combined with the scope of vulnerability impact Calculate the business importance score: ,in, Representing assets The weighting of the business; Indicates that vulnerability i is in the asset The impact factor on To perform asset dependency score calculation: ,in, Depends on assets The node set of Representing assets The number of connections; Firewall rules are matched. If the vulnerable traffic is blocked, it is marked as 1. If the vulnerable traffic is not blocked, it is marked as 0. Check whether the device where vulnerability i is located is in the isolated partition and evaluate the isolation strength: , Indicates the strength of the isolation strategy; Perform sensitivity score calculation to calculate the environmental sensitivity score of the vulnerability : ,in, Score your network exposure. is the topological importance of the device in the network, Score the business impact of the vulnerability, To check whether the protection measures have blocked the vulnerability, is the isolation strength, Score asset dependencies.
4. The EPSS-based vulnerability accessibility rating method according to claim 3, characterized in that: Assess vulnerability risk. The specific steps are as follows: Obtain the EPSS score of the vulnerability and the environmental sensitivity score of the vulnerability, and calculate the comprehensive risk score; Based on the comprehensive risk score, vulnerabilities are divided into different risk levels. When the comprehensive risk score is greater than the high risk threshold, the risk level is high risk level; When the comprehensive risk score is greater than or equal to the low risk threshold and less than or equal to the high risk threshold, the risk level is medium risk level; When the comprehensive risk score is less than the low risk threshold, the risk level is low risk level.
5. The EPSS-based vulnerability accessibility rating method according to claim 4, characterized in that: Combine vulnerability priorities with repair dependencies, establish a repair task optimization model under resource and time constraints, and allocate and generate task execution sequences for vulnerability repair, including the following steps: Build a quantitative model for each vulnerability repair task to determine resource requirements, time costs, and repair dependencies; Determine the objective function and constraints for the repair task optimization and establish a complete optimization problem; The optimization goal of the objective function is to minimize the total risk of unfixed vulnerabilities when the total amount of resources is determined; The constraint definition includes that the total allocated resources do not exceed the set resources, the total allocated time does not exceed the set time, and the dependency relationship satisfies the order; The ant colony optimization algorithm is used to solve the task allocation, the pheromone trajectory is updated according to the priority and completion of the repair task, the sequential allocation of the repair task is simulated, the task allocation path is generated, and the repair allocation plan for each vulnerability is output according to the task allocation path, including the allocated resources and the allocated repair time.
Citation Information
Patent Citations
Third-party component vulnerability ranking method based on scenarized multiple factors
CN117113363A
Dynamic vulnerability repair priority ranking method and device
CN117692187A