Cloud platform vulnerability handling method and related device based on vulnerability classification

By building a vulnerability classification model and knowledge graph, vulnerability repair priorities are solved, and the number of vulnerabilities in the cloud platform is huge and difficult to manage, improving vulnerability repair efficiency and security.

CN119760731BActive Publication Date: 2025-05-23STATE GRID SHANGHAI MUNICIPAL ELECTRIC POWER CO
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510262963.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-06
Publication Date
2025-05-23
Estimated Expiration
2045-03-06

AI Technical Summary

Technical Problem

The number of vulnerabilities in cloud platforms is huge, difficult to classify and manage, and the efficiency of manual analysis and repair is low, resulting in challenges in vulnerability management methods and levels.

Method used

By building a vulnerability classification model based on the historical vulnerability data of the cloud platform, obtain real-time vulnerability data for classification, build a vulnerability knowledge graph, output the correlation rules between vulnerabilities, and determine the priority of vulnerability repair based on these rules to perform vulnerability repair.

Benefits of technology

It improves the efficiency and accuracy of vulnerability management, ensures priority repair of high-risk vulnerabilities, avoids duplication and omissions in the repair process, and provides strong guarantees for the safe operation of the cloud platform.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119760731B_ABST
    Figure CN119760731B_ABST
Patent Text Reader

Abstract

The present invention belongs to the technical field of cloud platform vulnerability handling, and provides a cloud platform vulnerability handling method based on vulnerability classification and related devices, the method comprising: based on the cloud platform historical vulnerability data, constructing a vulnerability classification model after preprocessing, obtaining the cloud platform real-time vulnerability data, classifying the cloud platform real-time vulnerability data based on the vulnerability classification model, and obtaining the classified vulnerability data; based on the classified vulnerability data, constructing a vulnerability knowledge graph, and outputting the association rules between the vulnerabilities; based on the classified vulnerability data and the association rules between the vulnerabilities, determining the priority of vulnerability repair, and performing cloud platform vulnerability repair. The technical solution improves the efficiency and accuracy of vulnerability management by constructing a vulnerability classification model, a vulnerability knowledge graph, and association rule mining; by determining the priority of vulnerability repair and providing a specific repair method, the rapid repair and verification of the vulnerability is achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of cloud platform vulnerability handling, and in particular relates to a cloud platform vulnerability handling method based on vulnerability classification and related devices. Background Art

[0002] With the development of Internet technology, various information systems have been widely promoted on the State Grid Cloud, and the rapid development of other network applications has led to an endless stream of network security vulnerabilities, which constantly threaten the security of the power grid. In the process of cloud platform construction and operation, there are problems such as complex vulnerability troubleshooting methods, diverse repair methods, and difficulty in verification after repair due to the large number of vulnerabilities, which poses challenges to vulnerability management methods and levels. According to the "GB / T 30279-2020 Guidelines for Classification and Grading of Network Security Vulnerabilities", the classification method and grading indicators of network security vulnerabilities are provided, and recommendations for grading methods are given. It is applicable to vulnerability classification and hazard level assessment conducted by network product and service providers, network operators, vulnerability collection organizations, and vulnerability emergency response organizations in vulnerability management, product production, technology research and development, network operations and other related activities.

[0003] Faced with the endless emergence of vulnerabilities and real-time updates, if you want to control the vulnerabilities of a certain device in real time, you need to rescan and manually count them each time, wasting a lot of time and human resources; vulnerability repair relies on manual intervention and takes the form of machine-by-machine repair, which will increase linearly due to the increase of devices or systems; some vulnerabilities that are repaired by modifying configuration parameters or fields are difficult to verify in a convenient and intuitive way afterwards. When a large number of devices need to be repaired in a short period of time, it is easy to have multiple problems such as duplication or omission. In summary, vulnerabilities emerge in an endless stream, are updated in real time, and are huge in number. There is a lack of a classification framework for security vulnerabilities, which makes it difficult to classify and manage vulnerabilities. Vulnerability repair relies on manual analysis, and it is impossible to automatically analyze vulnerability data from multiple sources, resulting in low repair efficiency. Summary of the invention

[0004] The purpose of the present invention is to provide a cloud platform vulnerability handling method and related devices based on vulnerability classification, so as to solve the problem that the number of vulnerabilities is huge and difficult to classify and manage, and the efficiency of manual analysis and repair is low.

[0005] To achieve the above object, the present invention adopts the following technical solutions:

[0006] In a first aspect, the present invention provides a cloud platform vulnerability handling method based on vulnerability classification, comprising:

[0007] Based on the historical vulnerability data of the cloud platform, a vulnerability classification model is constructed after preprocessing to obtain the real-time vulnerability data of the cloud platform. The real-time vulnerability data of the cloud platform is classified based on the vulnerability classification model to obtain the classified vulnerability data;

[0008] Based on the classified vulnerability data, a vulnerability knowledge graph is constructed to output the association rules between vulnerabilities;

[0009] Based on the classified vulnerability data and the association rules between vulnerabilities, the priority of vulnerability repair is determined, and cloud platform vulnerabilities are repaired.

[0010] Furthermore, the obtaining of cloud platform vulnerability data and preprocessing of the cloud platform vulnerability data include:

[0011] Vulnerability data is obtained from a multi-source security vulnerability database, and preprocessed by cleaning, merging, deduplication and normalization to obtain preprocessed vulnerability data.

[0012] Furthermore, the vulnerability classification model is constructed to obtain classified vulnerability data, including:

[0013] For the preprocessed vulnerability data, multidimensional features including vulnerability name, vulnerability description, vulnerability priority and vulnerability impact range are extracted. The multidimensional features are combined with the graph neural network to train the vulnerability classification model. The gradient descent method is used to train the neural network weights. The neural network weights are updated in the opposite direction of the gradient. The vulnerability classification model gradually converges to the optimal solution and completes the automatic classification of vulnerabilities suitable for changes in graph structure.

[0014] Furthermore, the vulnerability knowledge graph is constructed based on the classified vulnerability data, and the association rules between the vulnerabilities are outputted, including:

[0015] Using rule-based and machine learning knowledge extraction methods, we extract subjects from the classified vulnerability data and extract vulnerability concepts and attribute information;

[0016] On the basis of subject extraction, the association relationships between the extracted vulnerabilities, including the exploitation relationship, repair relationship, and similarity relationship, are extracted;

[0017] The extracted vulnerability concepts and attribute information are integrated to obtain integrated vulnerability knowledge;

[0018] Based on the association relationship, the mining algorithm is used to mine the fused vulnerability knowledge to obtain the association rules between the vulnerabilities, which are expressed as:

[0019] Co-occurrence rule: Vulnerability A co-occurs with vulnerability B;

[0020] Dependency rule: vulnerability A depends on vulnerability B;

[0021] Cause and effect rule: vulnerability A leads to vulnerability B;

[0022] Timing rule: vulnerability A precedes vulnerability B;

[0023] Attribute association rule: Vulnerability type A is associated with the impact scope of vulnerability B.

[0024] Furthermore, the association rules between the vulnerabilities are evaluated, and the confidence and support indicators of the association rules are evaluated; the association rules are optimized according to the evaluation results, redundant rules are removed, similar rules are merged, and the optimized association rules are visualized.

[0025] Furthermore, the priority of vulnerability repair is determined based on the classified vulnerability data and the association rules between the vulnerabilities, and the cloud platform vulnerability repair is performed, including:

[0026] Conduct risk assessment on each vulnerability based on the severity, impact scope, and difficulty of exploitation of the classified vulnerability data. Analyze the potential risk transfer paths between vulnerabilities using vulnerability association rules to assess the overall risk of the vulnerability chain.

[0027] Determine the order in which vulnerabilities should be repaired based on the risk assessment results and the overall risk of the vulnerability chain, with higher-risk vulnerabilities being repaired first.

[0028] Furthermore, we will repair the vulnerabilities of the cloud platform, including:

[0029] Obtain relevant information about historical vulnerabilities, generate a secure version number, and then use the package manager to update the vulnerabilities under the preset component version number, and finally merge the code;

[0030] Obtain a program from the program code repository that can simultaneously satisfy two samples, one that can cause the target program to crash and the other that will not, compare the execution paths of the two samples to locate the error location, generate the corresponding patch code, and then insert it into the error location for repair.

[0031] In a second aspect, the present invention provides a cloud platform vulnerability handling system based on vulnerability classification, comprising:

[0032] The data acquisition module is used to construct a vulnerability classification model based on the historical vulnerability data of the cloud platform after preprocessing, obtain the real-time vulnerability data of the cloud platform, classify the real-time vulnerability data of the cloud platform based on the vulnerability classification model, and obtain the classified vulnerability data;

[0033] The association rule acquisition module is used to build a vulnerability knowledge graph based on the classified vulnerability data and output the association rules between vulnerabilities;

[0034] The repair module is used to determine the priority of vulnerability repair based on the classified vulnerability data and the association rules between vulnerabilities, and to repair the vulnerabilities of the cloud platform.

[0035] In a third aspect, the present invention provides a computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the cloud platform vulnerability handling method based on vulnerability classification when executing the computer program.

[0036] In a fourth aspect, the present invention provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the cloud platform vulnerability handling method based on vulnerability classification are implemented.

[0037] Compared with the prior art, the present invention has the following technical effects:

[0038] The present invention obtains vulnerability data on the cloud platform, and constructs a vulnerability classification model based on the historical vulnerability data of the cloud platform after preprocessing. The model can perform refined classification management of vulnerabilities according to multiple dimensions such as the characteristics, impact range, and severity of the vulnerability. Based on the classified vulnerability data, a vulnerability knowledge graph is further constructed. By deeply mining and analyzing these associations, these association rules provide reference information for vulnerability managers to better obtain the mutual influence and potential risks between vulnerabilities.

[0039] According to these association rules and classification data, the priority of vulnerability repair is determined. By comprehensively considering multiple factors such as the severity of the vulnerability, the scope of impact, the difficulty of exploitation, and the association with other vulnerabilities, the priority repair of high-risk vulnerabilities is ensured, and the mutual influence between vulnerabilities is also considered to avoid duplication and omission in the repair process. The present invention improves the efficiency and accuracy of vulnerability management by obtaining cloud platform vulnerability data, building a vulnerability classification model, building a vulnerability knowledge graph, and determining the priority of vulnerability repair, and also provides a strong guarantee for the safe operation of the cloud platform.

[0040] The present invention obtains vulnerability data from a multi-source security vulnerability database and performs pre-processing operations such as cleaning, merging, deduplication and normalization to ensure the accuracy and consistency of vulnerability data, which provides a reliable data basis for subsequent vulnerability classification and association rule mining.

[0041] The present invention extracts multi-dimensional features of vulnerabilities (such as vulnerability name, description, priority, and impact range), and combines graph neural network and gradient descent method to train vulnerability classification model. This model can automatically adapt to changes in graph structure and realize automatic classification of vulnerabilities. It improves the efficiency and accuracy of vulnerability classification and provides strong support for vulnerability management.

[0042] The present invention uses a knowledge extraction method based on rules and machine learning to extract vulnerability concepts and attribute information from classified vulnerability data, and further extracts the association relationships between vulnerabilities (such as utilization relationships, repair relationships, similarity relationships, etc.). By integrating this information, a vulnerability knowledge graph is constructed, and the association rules between vulnerabilities are mined. This helps to reveal the internal connections between vulnerabilities and provides a basis for vulnerability repair.

[0043] The present invention can determine the reliability and effectiveness of association rules by evaluating the confidence and support indexes of association rules. The association rules are optimized according to the evaluation results, redundant rules are removed, similar rules are merged, and the optimized association rules are visualized. This improves the availability and ease of use of association rules, allowing vulnerability managers to more intuitively understand the association relationship between vulnerabilities.

[0044] The present invention conducts risk assessment on each vulnerability according to the severity, impact scope, and difficulty of exploitation of the vulnerability data after classification. At the same time, the vulnerability association rules are used to analyze the potential risk transmission paths between the vulnerabilities and evaluate the overall risk of the vulnerability chain. According to the risk assessment results and the overall risk of the vulnerability chain, the order of vulnerability repair is determined, and vulnerabilities with higher risks are repaired first. This ensures the pertinence and effectiveness of vulnerability repair and improves the security of the cloud platform.

[0045] Specific vulnerability repair methods: obtain relevant information about historical vulnerabilities, generate a safe version number, then update the vulnerability through the package manager, and finally merge the code. This method is suitable for vulnerabilities that need to be repaired through version updates. Another method is to obtain two sample programs from the program code repository (one that can cause a crash and one that cannot), locate the error location by comparing the execution path, and generate patch code for repair. This method is suitable for vulnerabilities that need to be repaired by modifying the program code. These two repair methods provide flexible and diverse vulnerability repair methods to meet the repair needs of different vulnerabilities.

[0046] In summary, this technical solution improves the efficiency and accuracy of vulnerability management by building vulnerability classification models, vulnerability knowledge graphs, and association rule mining. It also achieves rapid vulnerability repair and verification by determining the priority of vulnerability repair and providing specific repair methods. This technical solution provides a comprehensive, systematic, and scientific solution for cloud platform vulnerability management. BRIEF DESCRIPTION OF THE DRAWINGS

[0047] Figure 1 It is a flow chart of the present invention. DETAILED DESCRIPTION

[0048] The present invention is further described below in conjunction with the accompanying drawings:

[0049] Example 1, please refer to Figure 1 The present invention provides a cloud platform vulnerability handling method based on vulnerability classification, including:

[0050] Obtain cloud platform vulnerability data, build a vulnerability classification model after preprocessing the cloud platform vulnerability data, and obtain classified vulnerability data;

[0051] Based on the classified vulnerability data, a vulnerability knowledge graph is constructed to output the association rules between vulnerabilities;

[0052] Based on the classified vulnerability data and the association rules between vulnerabilities, the priority of vulnerability repair is determined, and cloud platform vulnerabilities are repaired.

[0053] This method obtains cloud platform vulnerability data, builds a vulnerability classification model, and manages vulnerabilities by category. Subsequently, a vulnerability knowledge graph is constructed based on the classified vulnerability data, and the association rules between vulnerabilities are output. Finally, the priority of vulnerability repair is determined based on these association rules and classification data, and targeted cloud platform vulnerability repair is carried out, which effectively improves the efficiency and accuracy of cloud platform vulnerability management.

[0054] Embodiment 2, the present invention provides a cloud platform vulnerability handling method based on vulnerability classification, specifically comprising:

[0055] S1, obtaining cloud platform vulnerability data, preprocessing the cloud platform vulnerability data to build a vulnerability classification model, and classifying the preprocessed vulnerability data based on the vulnerability classification model to obtain classified vulnerability data;

[0056] Based on a multi-source security vulnerability library, public vulnerability libraries, attack rule libraries and other data sources are used to obtain computer-related knowledge, network security-related knowledge, attack rules, software vulnerability samples, network threat intelligence, attack rules and vulnerability data; among them, the attack rules contain detailed information about existing attacks, including attack name, attack type, protocol, attack characteristics, attack description, and severity; vulnerability data contains detailed information about discovered vulnerabilities, including vulnerability name, vulnerability description, vulnerability priority, destruction method, and homology characteristics; manual labeling methods are also used to label vulnerabilities in sample software, and the execution path where the vulnerability exists is marked as a vulnerable path, and then a genetic algorithm is used to perform vulnerable path-guided testing to obtain vulnerability discovery sample data containing software vulnerable paths and test cases.

[0057] The above data are first merged, deduplicated, and normalized; since most of these source data are unstructured data, they need to be further processed in order to extract knowledge from them and form a structured knowledge base that can be used by computers, and to structure the scattered knowledge into a knowledge base that can be understood by computers. In this step, in order to ensure the accuracy, completeness, consistency, and uniqueness of vulnerability knowledge, the original data is preprocessed and aggregated, compressed, and sorted, duplicate information is deleted, existing errors are corrected, and data consistency processing is provided. Cloud platform-related vulnerabilities are classified, high-quality vulnerability knowledge is written into storage, and the main vulnerability types in cloud platform operation and maintenance are summarized.

[0058] A vulnerability classification modeling method based on graph neural network is proposed, and a multi-layer graph convolutional network with scalable graph structure is constructed. The gradient descent method is used to train the neural network weights, and a semi-supervised learning method based on the feature vector matrix and the description of the point-edge relationship structure is designed. Graph SAGE (graph neural network, graph sample and aggregate) is applied to get rid of the dependence on the Laplace matrix and realize automatic vulnerability classification suitable for graph structure changes.

[0059] Based on the evaluation scores of the vulnerabilities, the vulnerabilities are divided into high risk: the vulnerability can easily cause serious consequences to the target object; medium risk: the vulnerability can cause general consequences to the target object, or it is relatively difficult to cause serious consequences to the target; low risk: the vulnerability can cause minor consequences to the target object, or it is relatively difficult to cause general serious consequences to the target object, or it is very difficult to cause serious consequences to the target object.

[0060] The vulnerability security level assessment indicators include duration and impact range. Through deep learning technology, the vulnerability level can be automatically identified.

[0061] Based on vulnerability behaviors and cloud platform traffic data, vulnerability types are identified, including code errors, configuration defects, environmental vulnerabilities, and other vulnerabilities. Machine learning and knowledge graph-related identification identifies vulnerabilities based on behaviors triggered by vulnerabilities, such as malicious authorization, script injection, information leakage, and other different attack behaviors or user abuse.

[0062] S2, based on the classified vulnerability data, builds a vulnerability knowledge graph and outputs association rules between vulnerabilities;

[0063] The knowledge graph includes the type of design subject, the attributes that the subject may have, and the relationship between subjects. The data used to construct the knowledge graph is classified vulnerability data. These data are extracted, fused, and calculated, and finally unified into concepts to form knowledge storage.

[0064] The construction of the knowledge graph includes two different stages. The first stage is the process of extracting knowledge from the data source, which is called subject extraction and attribute extraction. The second stage is the process of aggregating knowledge, which is called relationship extraction. This step focuses on the subject extraction process in the first stage. This process uses rule-based and machine learning-based knowledge extraction methods to extract conceptual information that can be used for knowledge from the collected massive data. It is divided into the following five steps:

[0065] Firstly, the concepts and the relationships between concepts in the field of computer vulnerabilities are defined; and the rules for the relationships between concepts and the relationships are described using a generative grammar containing context operators and Boolean relation operators.

[0066] Secondly, based on the rules generated above, knowledge is extracted from massive data to extract texts that match concepts and the relationships between concepts, including numbers, source codes, sensitive files, database configuration files, website source codes, sensitive file directories, and email naming rules.

[0067] Third, based on the text of matching concepts and relationships between concepts extracted in the above steps, the machine learning method is trained to obtain more concepts and relationships between concepts, and various entities and entity relationships are continuously extracted and generated in real time, and a flexible and real-time entity drill-down function is provided. The entity drill-down means that it can continuously expand the analysis of other entities related to an entity with one entity as the center.

[0068] Fourth, based on the more concepts and relationships between concepts obtained in the above steps, knowledge extraction is performed, the extraction results are labeled, and the precision and recall rates during knowledge extraction are judged, using the precision and recall rates as evaluation criteria.

[0069] Fifth, repeating the third and fourth steps until the evaluation criteria reach the preset standard;

[0070] The process of relation extraction is to extract the relationship between entities, in which the word sequence composite kernel function is used to achieve knowledge aggregation to maximize the use of multi-source information and improve the accuracy of relation extraction. Specifically, the idea of ​​the word sequence composite kernel function is to measure the similarity between two word sequences based on the number of common subsequences in the two word sequences. The subsequences may contain interval items, and different weights are set for each common subsequence using the attenuation factor.

[0071] The fused vulnerability knowledge is mined using the association mining algorithm to obtain a series of rules describing the associations between vulnerabilities. These rules are usually expressed in the form of triples or more complex graph structures, describing the co-occurrence, dependency, causality and other relationships between vulnerabilities.

[0072] Specifically, the following types of rules can be output:

[0073] Co-occurrence rule: describes which vulnerabilities often appear together, vulnerability A co-occurs with vulnerability B.

[0074] Dependency rule: describes whether the existence of a vulnerability depends on the existence or repair of another vulnerability. Vulnerability A depends on vulnerability B, which means that the existence of vulnerability A depends on the repair of vulnerability B.

[0075] Causal rule: describes whether the emergence of a vulnerability will lead to the emergence or disappearance of another vulnerability. Vulnerability A leads to vulnerability B, which means that the emergence of vulnerability A will lead to the emergence of vulnerability B.

[0076] Timing rule: describes the time sequence of vulnerability occurrence. Vulnerability A precedes vulnerability B, which means that vulnerability A appears before vulnerability B.

[0077] Attribute association rule: describes the association relationship between vulnerability attributes. The type of vulnerability A is associated with the impact range of vulnerability B, indicating that the type of vulnerability A is associated with the impact range of vulnerability B.

[0078] S3, determines the priority of vulnerability repair based on the classified vulnerability data and the association rules between vulnerabilities, and repairs the vulnerabilities on the cloud platform.

[0079] (1) Automatic vulnerability repair method based on dependent component version

[0080] Research on automatic vulnerability repair methods based on dependent component versions, obtain relevant information of historical vulnerabilities based on the vulnerability association analysis model of the multi-source data knowledge graph, and produce a safe version number. Then, through the package manager, specify the component version number to update the vulnerability, and finally merge the code.

[0081] (2) Automatic vulnerability repair method based on program transplantation.

[0082] By inputting one sample that can cause the target program to crash and another that cannot, we search for a program that can satisfy both sample conditions from the program code repository. We compare the execution paths of the two samples to locate the error location, extract the processing logic of the input data, generate the corresponding patch code, insert it into the error location for repair, collect context information to adapt and convert the patch code, and finally verify whether the patch is eliminated.

[0083] The present invention obtains a wealth of computer-related knowledge, network security-related knowledge, attack rules, software vulnerability samples, network threat intelligence, etc. from data sources such as multi-source security vulnerability libraries, public vulnerability libraries, and attack rule libraries. These data provide a solid foundation for subsequent vulnerability classification and knowledge graph construction.

[0084] The acquired data was cleaned by merging, deduplication, and normalization to ensure the accuracy and consistency of the data. At the same time, the unstructured data was further processed to transform it into a structured knowledge base that can be used by computers.

[0085] A vulnerability classification modeling method based on graph neural network is proposed, and a multi-layer graph convolutional network with scalable graph structure is constructed. This method can automatically adapt to changes in graph structure and realize automatic classification of vulnerabilities.

[0086] The gradient descent method is used to train the weights of the neural network, and a semi-supervised learning method based on the feature vector matrix and the description of the point-edge relationship structure is designed. By applying the Graph SAGE algorithm, the dependence on the Laplace matrix is ​​eliminated, and the flexibility and accuracy of vulnerability classification are improved.

[0087] Vulnerabilities are classified into grades based on their assessment scores, providing a basis for determining the priority of subsequent vulnerability repairs.

[0088] Through deep learning technology, automatic identification of vulnerability levels is achieved, improving assessment efficiency and accuracy.

[0089] Based on vulnerability behaviors and cloud platform traffic data, vulnerability types are identified, including code errors, configuration defects, and environmental vulnerabilities.

[0090] Through the recognition method of machine learning and knowledge graph association, the vulnerabilities are identified in a refined manner according to the behaviors triggered by the vulnerabilities, improving the accuracy and coverage of identification.

[0091] Through the steps of knowledge extraction, knowledge fusion, knowledge calculation, etc., the classified vulnerability data is converted into knowledge and stored, forming a complete vulnerability knowledge graph.

[0092] A knowledge extraction method based on rules and machine learning is used to extract conceptual information that can be used as knowledge from massive data. By defining the relationship rules between concepts and concepts, knowledge is extracted from massive data to extract texts that match concepts and relationships. Machine learning methods are used to train and optimize the extraction results to continuously improve the accuracy and coverage of knowledge extraction.

[0093] The word sequence composite kernel function is used to achieve knowledge aggregation, maximize the use of multi-source information, and improve the accuracy of relationship extraction. By setting a decay factor and setting different weights for each common subsequence, the similarity between two word sequences is measured more accurately.

[0094] Automatic repair of vulnerabilities is achieved by producing a safe version number, specifying component version numbers to update vulnerabilities, merging codes, and other steps.

[0095] By inputting a sample program that can cause the target program to crash and a sample program that will not crash, a program that can satisfy the two sample conditions is searched from the program code repository.

[0096] Automatic repair and verification of vulnerabilities are achieved by comparing execution paths to locate error locations, extracting processing logic to generate patch code, and inserting code into error locations for repair.

[0097] The priority of vulnerability repair is determined to ensure that high-risk vulnerabilities are repaired first.

[0098] It provides two specific automatic vulnerability repair methods, which improve the efficiency and accuracy of vulnerability repair, realize the rapid repair and verification of vulnerabilities, and provide strong protection for the safe operation of the cloud platform.

[0099] The present invention in Example 2 realizes the systematization and scientificization of vulnerability management through a series of technical means such as obtaining cloud platform vulnerability data, building a vulnerability classification model, building a vulnerability knowledge graph, and determining the priority of vulnerability repair. This not only improves the efficiency and accuracy of vulnerability management, but also provides a strong guarantee for the safe operation of the cloud platform.

[0100] In yet another embodiment of the present invention, a cloud platform vulnerability handling system based on vulnerability classification is provided, which can be used to implement the above-mentioned cloud platform vulnerability handling method based on vulnerability classification. Specifically, the system includes:

[0101] The data acquisition module is used to construct a vulnerability classification model based on the historical vulnerability data of the cloud platform after preprocessing, obtain the real-time vulnerability data of the cloud platform, classify the real-time vulnerability data of the cloud platform based on the vulnerability classification model, and obtain the classified vulnerability data;

[0102] The association rule acquisition module is used to build a vulnerability knowledge graph based on the classified vulnerability data and output the association rules between vulnerabilities;

[0103] The repair module is used to determine the priority of vulnerability repair based on the classified vulnerability data and the association rules between vulnerabilities, and to repair the vulnerabilities of the cloud platform.

[0104] The division of modules in the embodiments of the present invention is schematic and is only a logical function division. There may be other division methods in actual implementation. In addition, each functional module in each embodiment of the present invention may be integrated into one processor, or may exist physically separately, or two or more modules may be integrated into one module. The above-mentioned integrated modules may be implemented in the form of hardware or in the form of software functional modules.

[0105] In another embodiment of the present invention, a computer device is provided, the computer device including a processor and a memory, the memory is used to store a computer program, the computer program includes program instructions, and the processor is used to execute the program instructions stored in the computer storage medium. The processor may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc., which are the computing core and control core of the terminal, which are suitable for implementing one or more instructions, and are specifically suitable for loading and executing one or more instructions in the computer storage medium to implement the corresponding method flow or corresponding function; the processor described in the embodiment of the present invention can be used for the operation of the cloud platform vulnerability disposal method based on vulnerability classification.

[0106] In another embodiment of the present invention, the present invention further provides a storage medium, specifically a computer-readable storage medium (Memory), which is a memory device in a computer device for storing programs and data. It is understandable that the computer-readable storage medium here can include both built-in storage media in a computer device and, of course, extended storage media supported by the computer device. The computer-readable storage medium provides a storage space, which stores the operating system of the terminal. In addition, one or more instructions suitable for being loaded and executed by a processor are also stored in the storage space, and these instructions can be one or more computer programs (including program codes). It should be noted that the computer-readable storage medium here can be a high-speed RAM memory or a non-volatile memory, such as at least one disk memory. The processor can load and execute one or more instructions stored in the computer-readable storage medium to implement the corresponding steps of the cloud platform vulnerability handling method based on vulnerability classification in the above embodiment.

[0107] It will be appreciated by those skilled in the art that embodiments of the present invention may be provided as methods, systems, or computer program products. Therefore, the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0108] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0109] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.

[0110] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.

[0111] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the above embodiments, ordinary technicians in the relevant field should understand that the specific implementation methods of the present invention can still be modified or replaced by equivalents. Any modification or equivalent replacement that does not depart from the spirit and scope of the present invention should be covered within the scope of protection of the claims of the present invention.

Claims

1. A cloud platform vulnerability handling method based on vulnerability classification, characterized in that: include: Based on the historical vulnerability data of the cloud platform, a vulnerability classification model is constructed after preprocessing to obtain the real-time vulnerability data of the cloud platform. The real-time vulnerability data of the cloud platform is classified based on the vulnerability classification model to obtain the classified vulnerability data; Based on the classified vulnerability data, a vulnerability knowledge graph is constructed to output the association rules between vulnerabilities; Determine the priority of vulnerability repair based on the classified vulnerability data and the association rules between vulnerabilities, and repair the vulnerabilities on the cloud platform; The vulnerability knowledge graph is constructed based on the classified vulnerability data, and the association rules between the vulnerabilities are output, including: Using the knowledge extraction method based on rules and machine learning, the subject is extracted from the classified vulnerability data to obtain the vulnerability concept and attribute information; On the basis of subject extraction, the association relationships between the extracted vulnerabilities, including the exploitation relationship, repair relationship, and similarity relationship, are extracted; The extracted vulnerability concepts and attribute information are integrated to obtain integrated vulnerability knowledge; Based on the association relationship, the mining algorithm is used to mine the fused vulnerability knowledge to obtain the association rules between the vulnerabilities, which are expressed as: Co-occurrence rule: Vulnerability A co-occurs with vulnerability B; Dependency rule: vulnerability A depends on vulnerability B; Cause and effect rule: vulnerability A leads to vulnerability B; Timing rule: vulnerability A precedes vulnerability B; Attribute association rule: Vulnerability type A is associated with the impact scope of vulnerability B; The obtaining of cloud platform vulnerability data and preprocessing of the cloud platform vulnerability data include: Acquire vulnerability data from a multi-source security vulnerability database, and perform preprocessing operations such as cleaning, merging, deduplication, and normalization on the vulnerability data to obtain preprocessed vulnerability data; The preprocessed vulnerability data is classified based on the vulnerability classification model to obtain the classified vulnerability data, including: For the preprocessed vulnerability data, multidimensional features including vulnerability name, vulnerability description, vulnerability priority and vulnerability impact range are extracted. The multidimensional features are combined with the graph neural network to train the vulnerability classification model. The gradient descent method is used to train the neural network weights. The neural network weights are updated in the opposite direction of the gradient. The vulnerability classification model gradually converges to the optimal solution and completes the automatic classification of vulnerabilities suitable for changes in graph structure.

2. The cloud platform vulnerability handling method based on vulnerability classification according to claim 1 is characterized in that: Evaluate the association rules between vulnerabilities, and evaluate the confidence and support indicators of the association rules; optimize the association rules based on the evaluation results, remove redundant rules, merge similar rules, and visualize the optimized association rules.

3. The cloud platform vulnerability handling method based on vulnerability classification according to claim 1 is characterized in that: Determining the priority of vulnerability repair based on the classified vulnerability data and the association rules between the vulnerabilities, and repairing the cloud platform vulnerabilities, includes: Conduct risk assessment on each vulnerability based on the severity, impact scope, and difficulty of exploitation of the classified vulnerability data. Analyze the potential risk transfer paths between vulnerabilities using vulnerability association rules to assess the overall risk of the vulnerability chain. Determine the order in which vulnerabilities should be repaired based on the risk assessment results and the overall risk of the vulnerability chain, with higher-risk vulnerabilities being repaired first.

4. The cloud platform vulnerability handling method based on vulnerability classification according to claim 3 is characterized in that: Repair cloud platform vulnerabilities, including: Obtain relevant information about historical vulnerabilities, generate a secure version number, and then use the package manager to update the vulnerabilities under the preset component version number, and finally merge the code; Obtain from the program code repository a program that can simultaneously satisfy two samples, one that can cause the target program to crash and the other that will not, compare the execution paths of the two sample programs to locate the error location, generate the corresponding patch code, and then insert the patch code into the error location for repair.

5. A cloud platform vulnerability handling system based on vulnerability classification, characterized in that: include: The data acquisition module is used to construct a vulnerability classification model based on the historical vulnerability data of the cloud platform after preprocessing, obtain the real-time vulnerability data of the cloud platform, classify the real-time vulnerability data of the cloud platform based on the vulnerability classification model, and obtain the classified vulnerability data; The association rule acquisition module is used to build a vulnerability knowledge graph based on the classified vulnerability data and output the association rules between vulnerabilities; The repair module is used to determine the priority of vulnerability repair based on the classified vulnerability data and the association rules between vulnerabilities, and to repair the vulnerabilities of the cloud platform; The vulnerability knowledge graph is constructed based on the classified vulnerability data, and the association rules between the vulnerabilities are output, including: Using the knowledge extraction method based on rules and machine learning, the subject is extracted from the classified vulnerability data to obtain the vulnerability concept and attribute information; On the basis of subject extraction, the association relationships between the extracted vulnerabilities, including the exploitation relationship, repair relationship, and similarity relationship, are extracted; The extracted vulnerability concepts and attribute information are integrated to obtain integrated vulnerability knowledge; Based on the association relationship, the mining algorithm is used to mine the fused vulnerability knowledge to obtain the association rules between the vulnerabilities, which are expressed as: Co-occurrence rule: Vulnerability A co-occurs with vulnerability B; Dependency rule: vulnerability A depends on vulnerability B; Cause and effect rule: vulnerability A leads to vulnerability B; Timing rule: vulnerability A precedes vulnerability B; Attribute association rule: Vulnerability type A is associated with the impact scope of vulnerability B; The obtaining of cloud platform vulnerability data and preprocessing of the cloud platform vulnerability data include: Acquire vulnerability data from a multi-source security vulnerability database, and perform preprocessing operations such as cleaning, merging, deduplication, and normalization on the vulnerability data to obtain preprocessed vulnerability data; The preprocessed vulnerability data is classified based on the vulnerability classification model to obtain the classified vulnerability data, including: For the preprocessed vulnerability data, multidimensional features including vulnerability name, vulnerability description, vulnerability priority and vulnerability impact range are extracted. The multidimensional features are combined with the graph neural network to train the vulnerability classification model. The gradient descent method is used to train the neural network weights. The neural network weights are updated in the opposite direction of the gradient. The vulnerability classification model gradually converges to the optimal solution and completes the automatic classification of vulnerabilities suitable for changes in graph structure.

6. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the steps of the cloud platform vulnerability handling method based on vulnerability classification as described in any one of claims 1 to 4 are implemented.

7. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the steps of the cloud platform vulnerability handling method based on vulnerability classification as described in any one of claims 1 to 4 are implemented.

Citation Information

Patent Citations

  • Vulnerability data mining method based on classification and association analysis

    CN101853277A

  • Method, device and equipment for generating vulnerability repair sequence table based on knowledge graph

    CN116383332A

  • Vulnerability relationship mining method and device based on large model, equipment and medium

    CN117390634A