A Software Supply Chain Side and Full-Lifecycle Network Security Auxiliary Defense System

The intelligent agent-based software supply chain security system addresses the gaps in existing defenses by providing comprehensive, automated risk management across the software lifecycle, enhancing security by identifying and remediating vulnerabilities early in the process.

CN119885209BActive Publication Date: 2025-07-15ZHEJIANG HUADONG ENG DIGITAL TECH CO LTD +1
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510371622.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-27
Publication Date
2025-07-15
Estimated Expiration
2045-03-27

AI Technical Summary

Technical Problem

The existing software network security defense technology has failed to cover all stages of the entire software life cycle, especially the security defense on the software encoding side and the software supply chain side. The data source is relatively single and lacks the ability to intelligently handle risks.

Method used

The network security auxiliary defense system of the software supply chain side is adopted based on the agent, and security risk intelligence is collected through multiple channels, and the agent is used for intelligent processing, including data source modules, information connection subsystems, and vulnerability information analysis and processing subsystems. It provides vulnerability analysis and processing algorithms for a variety of tool functions to achieve intelligent defense on the software supply chain side.

Benefits of technology

It realizes intelligent defense on the software supply chain side, exposes and repairs security risks in advance, improves the network security defense capabilities of the entire life cycle of the software, saves the processing time of network security engineers, and improves work efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119885209B_ABST
    Figure CN119885209B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of network security technology, and particularly relates to a software supply chain side and full-cycle network security auxiliary defense system, including a data source module that stores software basic information and vulnerability information; an intelligent agent configured with a workflow; an information connection subsystem including an information extraction module for connecting the extracted information into the intelligent agent; and a vulnerability information analysis and processing subsystem for executing software protection algorithms. By collecting vulnerability information through multiple channels and managing it, the intelligent agent is used to intelligently process the security risks existing in the software supply chain side and even the entire life cycle, shift security to before the software goes online, and further enhance the network security defense ability of the software full life cycle.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and particularly relates to an agent-based software supply chain side and full-cycle network security auxiliary defense system. Background Art

[0002] With the rapid development of Internet technology, the importance of software network security has become increasingly prominent. In today's digital age, software has become an important tool for enterprises and individuals to conduct information exchange, data storage, and business processing. However, with the wide popularity of software applications, network security threats have also increased, which poses higher requirements for software security.

[0003] Such as Figure 1 As shown, in the full life cycle of software, there are security risks in multiple links, including security vulnerabilities generated from coding in the source code side during the R & D stage, logical vulnerabilities in coding, data boundary vulnerabilities, etc., which will all affect software security; on the supply chain side, there are security risks from component dependency libraries, security risks of middleware, and security risks of integrating third-party software (or private); during software operation, usually in order to ensure the stable operation of the software, the security threats from the operating system where the software runs are ignored; after the software goes online, there are security threats from the Internet side. In the existing situation, information security engineers and R & D operation and maintenance engineers cannot quickly classify and dispose of risks, and it is time-consuming and laborious to locate problems and handling measures.

[0004] The current main defense means for software network security mainly include adding security protection tools on the Internet side after the software goes online, such as firewalls, intrusion detection systems (IDS), and WAF (Web Application Firewall); during software operation, using vulnerability scanning tools to detect the security risks of the operating system where the software runs and the software entry, such as the NSfocus vulnerability scanning system (the NSfocus vulnerability scanning system is a network security vulnerability scanning software, which has characteristics such as high efficiency, accuracy, and security, and can conduct a comprehensive security assessment for multiple targets such as operating systems, and discover and report security vulnerabilities in a timely manner).

[0005] Therefore, the existing software network security defense technologies have the following deficiencies:

[0006] 1. The defense technology fails to cover the network security in all stages of the software's entire life cycle, especially on the software coding side and the software supply chain side. The software supply chain includes the network security defense of component dependency libraries, middleware, and third-party software (or private) on the source code side. Chinese Patent Publication No. CN118316736A discloses a network threat proactive defense system and method based on a large model, which mainly focuses on how to build a network security large model and lacks security defense measures for security risks on the software coding side and the software supply chain side.

[0007] 2. Current network security risk analysis often focuses on network traffic based on user behavior, with a relatively single data source and a lack of multi-channel data sources. For example, Chinese Patent Publication No. CN119011302A discloses a big data analysis and processing method and system for intelligent network security, which mentions the ability to improve network security analysis based on logs and user behavior. The data only comes from logs and user behavior, lacking multi-channel data sources to provide an intelligent solution.

[0008] 3. There is a lack of the ability to intelligently and automatically process various risks quickly, and there is also a lack of the ability to provide intelligent solutions for R & D operation and maintenance engineers and network security engineers when network security risks are discovered. For example, Chinese Patent Publication No. CN114189378A discloses a network security event analysis method, which proposes a method for analyzing and locating the source of network security events by combining threat index information of network security events. However, it lacks the ability to provide intelligent solutions. Summary of the Invention

[0009] In order to overcome the deficiencies of existing network security auxiliary defense methods, such as the inability to cover the defense on the software supply chain side, relatively single data sources, and the lack of the ability to intelligently process risks, the present invention provides a network security auxiliary defense method for the software supply chain side based on agents.

[0010] The technical solution provided by the present invention is as follows: A network security auxiliary defense system for the software supply chain side, comprising:

[0011] A data source module, which stores software basic information and vulnerability information. The software basic information includes software basic attribute information and software supply chain information. The software basic attribute information includes the software responsible person, and the software supply chain information includes the supply chain number and supply chain type. The vulnerability information includes software supply chain vulnerability information;

[0012] An agent, which includes long-term memory based on the data source module and is configured with a workflow;

[0013] An information connection subsystem, including an information extraction module for connecting the extracted information into an intelligent agent, where the extracted information includes the basic software information of the software to be protected, software supply chain information, and software supply chain vulnerability information scanned by a security protection tool;

[0014] A vulnerability information analysis and processing subsystem, at least including an algorithm module one for executing a number matching algorithm, and the number matching algorithm includes the following steps:

[0015] Use the intelligent agent to match the corresponding supply chain number and software responsible person from the information extracted by the information connection subsystem;

[0016] If the software to be protected has not been launched yet, obtain the corresponding supply chain type and software supply chain vulnerability information from the software supply chain information according to the supply chain number and send them to the software responsible person. Otherwise, call a workflow to execute different preset repair plans according to the supply chain type.

[0017] Preferably, the basic software attribute information further includes a software number, the software supply chain information further includes a supply chain URL, and the workflow includes a restricted URL workflow for automatically restricting URL access by calling a firewall, a script upgrade workflow for executing an automated script tool to upgrade the middleware version, and a sending workflow for sending vulnerability information related to the software to be protected to the software responsible person;

[0018] The repair plan includes:

[0019] Repair plan one, if the supply chain type is a component type, match the software number through the long-term memory of the intelligent agent, and call the sending workflow to send the software number and vulnerability information to the software responsible person;

[0020] Repair plan two, if the supply chain type is a middleware type, call the script upgrade workflow through the intelligent agent;

[0021] Repair plan three, if the supply chain type is a third-party software, call the restricted URL workflow through the intelligent agent.

[0022] Preferably, the basic software attribute information includes a list of supply chain numbers one, a software number, the software supply chain information includes a list of software numbers, a list of existing vulnerability numbers, the software supply chain vulnerability information includes a supply chain vulnerability number, a list of supply chain numbers two, the list of supply chain numbers one in the basic software attribute information associates the supply chain numbers of all software supply chains under the same software number, and the list item of software numbers in the software supply chain information associates the software numbers of all software under the same supply chain number;

[0023] The vulnerability number list item of the software supply chain information associates the supply chain vulnerability numbers of all software supply chain vulnerabilities under the same supply chain number. The supply chain number list two of the software supply chain vulnerability information associates the supply chain numbers of all software supply chains under the same supply chain vulnerability number.

[0024] Preferably, the software basic attribute information further includes a software number. The ways for the number matching algorithm to match the corresponding supply chain number and software responsible person include: extracting the corresponding supply chain number and software responsible person according to the software number;

[0025] Extracting the corresponding supply chain number and software responsible person according to the supply chain vulnerability number of the vulnerability information with risks discovered by the security protection tool;

[0026] Extracting the supply chain number and software responsible person of the software to be protected through the information extraction module.

[0027] Preferably, the software supply chain vulnerability information includes a supply chain vulnerability repair suggestion plan. The workflow further includes a supply chain repair plan workflow for executing the supply chain vulnerability repair suggestion plan.

[0028] Preferably, it further includes a data collection module. The ways for the data collection module to collect vulnerability information include any one or more of the following:

[0029] Collecting software supply chain vulnerability information on the open-source vulnerability management website according to the supply chain name and supply chain version of the software using a script;

[0030] Collecting the vulnerability information provided by the subscribed security service manufacturers;

[0031] Collecting the vulnerability information related to the software supply chain tested through penetration testing and using, preferably, the data collection module further includes a scheduled task program for regularly collecting the latest vulnerability information according to the vulnerability information.

[0032] Preferably, the data collection module further includes a scheduled task program for regularly collecting the latest vulnerability information.

[0033] Preferably, in the number matching algorithm, if the vulnerability information with risks discovered by the security protection tool is not collected in the data source module, the vulnerability information is used as a prompt word to generate a vulnerability solution using the short-term memory of the agent.

[0034] In order to overcome the problems that the existing network security auxiliary defense methods cannot cover the entire software life cycle, especially the defense on the software supply chain side, and the data source is relatively single and lacks the ability to intelligently process risks, the present invention also provides a software full-cycle network security auxiliary defense method based on an agent.

[0035] The technical solution provided by the present invention is as follows:

[0036] A software full-cycle network security auxiliary defense system, including the software supply chain side network security auxiliary defense system, the vulnerability information also includes system vulnerability information, and the system vulnerability information includes a system vulnerability repair suggestion plan;

[0037] The workflow includes a system repair plan workflow for executing the system vulnerability repair suggestion plan;

[0038] The information connection subsystem further includes a coding tool module for connecting a software coding tool and an agent, and the coding tool module is used to detect source code vulnerabilities during the coding process and generate a repair plan;

[0039] The extracted information also includes system vulnerability information scanned by a vulnerability scanning tool for the system on which the software to be protected runs.

[0040] Preferably, the vulnerability information further includes an IP blacklist, the extracted information further includes risk IP addresses discovered by a security protection tool, the workflow further includes a banned IP workflow for calling a security protection tool to execute a remote command tool to ban an IP, and the vulnerability information analysis and processing subsystem further includes an algorithm module two for executing an IP analysis algorithm;

[0041] The IP analysis algorithm is to push the risk IP discovered by the security protection tool to the agent, and use the agent to judge whether the risk IP is included in the IP blacklist in the knowledge base. If so, use the agent to execute the banned IP workflow,

[0042] Otherwise, push the risk IP to the threat analysis platform to judge whether it is a high-risk IP. If so, use the agent to execute the banned IP workflow,

[0043] Otherwise, judge whether the access frequency of the risk IP is abnormal. If so, use the agent to execute the banned IP workflow.

[0044] Preferably, the software basic attribute information further includes a URL list, the software supply chain information further includes a supply chain URL, the extracted information further includes risk URLs discovered by a security protection tool, and the vulnerability information analysis and processing subsystem further includes an algorithm module three for executing a URL judgment algorithm;

[0045] The URL judgment algorithm pushes the attacked URLs discovered by the security protection tool to the agent, and the agent analyzes whether the attacked URLs match the URL list items or the supply chain URL items. If so, the agent is used to execute the restricted URL workflow that calls the firewall to automatically restrict access to the supply chain URLs.

[0046] Preferably, the coding tool module includes an IDE plug-in or an IDE configuration file encapsulated by the API interface of the agent.

[0047] Preferably, the collected basic software information, software supply chain vulnerability information, and vulnerability information are used as corpora for the training and parameter tuning of the agent after being entered into the knowledge base.

[0048] Preferably, the vulnerability information analysis and processing subsystem further includes a backup module. When the newly discovered system vulnerability information or supply chain vulnerability information has not been collected or does not contain a vulnerability repair suggestion plan, the system vulnerability information or supply chain vulnerability information is input into the agent as a prompt word, and the system vulnerability repair suggestion plan or supply chain vulnerability repair suggestion plan generated by the short-term memory of the agent is sent to the software responsible person.

[0049] Compared with the prior art, the present invention has the following beneficial effects:

[0050] 1. By collecting security risk intelligence vulnerability information through multiple channels, managing the basic software information, software supply chain vulnerability information, and system vulnerability information, and using the agent to complete the intelligent processing of security risks existing in the software supply chain side and even the entire life cycle, shifting security to before the software goes online, exposing and repairing security risks in advance, assisting R & D engineers to discover and repair security risks earlier, and further strengthening the network security defense ability of the entire software life cycle; saving the time of network security engineers to handle problems and improving work efficiency.

[0051] 2. Providing various vulnerability analysis and processing algorithms based on the tool functions of the agent, including IP analysis algorithms, URL judgment algorithms, and number matching algorithms, to process security risks efficiently and quickly.

[0052] 3. By further strictly judging IPs through external open source websites, the possibility of incorrect IP blocking is reduced.

[0053] 4. When new vulnerabilities emerge, all software containing the vulnerabilities can be counted, and the vulnerability details and vulnerability repair suggestion plans are sent to the software responsible person by email, improving the efficiency of enterprise software vulnerability repair and providing technical support for enterprise software network security. BRIEF DESCRIPTION OF THE DRAWINGS

[0054] Figure 1Schematic diagram of security risk identification for the entire software life cycle;

[0055] Figure 2 Schematic diagram of the correlation relationship between software basic information and vulnerability information;

[0056] Figure 3 Schematic diagram of the agent architecture of Embodiment 1 and Embodiment 2 of the present invention;

[0057] Figure 4 Schematic diagram of the number matching algorithm process of Embodiment 1 of the present invention;

[0058] Figure 5 Schematic diagram of the IP analysis algorithm process of Embodiment 2 of the present invention;

[0059] Figure 6 Schematic diagram of the URL judgment algorithm process of Embodiment 2 of the present invention. Detailed implementation manners

[0060] The present invention will be further described in detail below in conjunction with the accompanying drawings and specific embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the described embodiments of the present invention without creative efforts shall fall within the scope of protection of the present invention. Unless otherwise defined, the technical terms or scientific terms used herein shall have the ordinary meaning as understood by those of ordinary skill in the art to which the present invention pertains.

[0061] To further understand the present invention, some terms mentioned in the present invention and its embodiments will be explained first:

[0062] Vulnerability: A vulnerability refers to a security defect existing in a system, application program, or network protocol, which may be exploited by attackers to access, damage, or bypass normal security controls.

[0063] CVE: CVE (Common Vulnerabilities and Exposures) is a database maintained by MITRE (a division of ManTech International Corporation) in the United States. This database contains information on known information security vulnerabilities in the world. CVE assigns a unique identifier, namely the CVE number (CVE ID), to each known vulnerability. This number is standardized and can uniquely identify a vulnerability globally.

[0064] Shift-Left Security: Shift-Left Security is a software development practice aimed at advancing security measures to earlier stages of the software development life cycle.

[0065] Large model training: Large model training refers to training a complex neural network model through big data, determining the values of weights and biases in the network through a large amount of data training, so that it can adapt to specific functions.

[0066] Large model hyperparameter tuning: Hyperparameter tuning refers to adjusting the parameters of a trained model to further improve its performance on specific tasks. In large model training, hyperparameter tuning usually refers to fine-tuning a pre-trained model.

[0067] Security protection tools: Refers to network security systems used to protect software, systems, and network installations, such as firewalls.

[0068] Software supply chain: The software supply chain refers to all the content that goes into a software and its sources, including code, binaries, other components and their sources (such as repositories or package managers). It is the dependencies and properties of the dependencies that the software relies on, and these dependencies can be of commercial or open-source origin. The software supply chain also includes other parts of the suite besides individual applications, such as build and packaging scripts or software for the infrastructure on which the application runs. This invention mainly relates to software component dependency libraries, middleware, and third-party (or private) software.

[0069] It should be particularly noted that middleware refers to open-source third-party software; third-party (or private) software refers to open-source commercial software, and subsequent vulnerability risks and repair suggestions will be provided by the manufacturer.

[0070] For better understanding Figure 3 , the following terms are explained:

[0071] Short-term memory: Short-term memory means that all context learning utilizes the short-term memory of the large model to learn. The short-term memory described in the embodiments of this invention uses prompt words (i.e., Prompts) as input to generate results.

[0072] Long-term memory: Long-term memory means that it provides the intelligent agent with the ability to retain and recall information for a long time, such as through retrieval using external storage, etc. In the embodiments of this invention, the knowledge base is used as the external storage.

[0073] Tool functions: Tool functions refer to equipping the large model with external tools to expand the model's functions. The tool functions in this embodiment include automated script tools, API interface tools, remote execution script tools, etc.

[0074] Planning: Planning generally refers to the automatic planning and scheduling of tasks or actions performed by an agent, with the aim of optimizing resources. Planning can be represented as a combination of prediction steps and search mechanisms, which combine prediction steps with the search process among alternative actions to achieve an ideal state. In this embodiment, planning includes invoking and executing corresponding tool functions based on different types of vulnerability information.

[0075] To facilitate a better understanding of the present invention by those skilled in the art, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments. The following is merely exemplary and does not limit the protection scope of the present invention.

[0076] Embodiment 1

[0077] This embodiment discloses a software supply chain-side network security auxiliary defense system, including:

[0078] A data source module, which is a knowledge base in this embodiment (a knowledge base refers to a database that uses artificial intelligence technology to systematically organize, classify, and manage a large amount of knowledge and information. It not only stores a large amount of knowledge and information but also realizes functions such as fast knowledge retrieval, intelligent recommendation, and data analysis through intelligent algorithms and technologies. The knowledge base mentioned in this embodiment takes a database as an example, and of course, it can also include a vector knowledge base converted from a list of text files). It stores software basic information and software supply chain vulnerability information. The software basic information includes software basic attribute information and software supply chain information. The software basic attribute information includes software number, software name, static IP address of the server where it runs, URL list, supply chain number list one, and software responsible person, and fields can be added as needed. The software supply chain information includes supply chain number, software number list, supply chain type, existing vulnerability number list, and supply chain URL. The software supply chain vulnerability information includes supply chain vulnerability number, supply chain vulnerability name, supply chain vulnerability details, supply chain affected version, supply chain vulnerability repair suggestion plan, supply chain number list two, etc. It should be noted that the software basic attribute information and software supply chain information may not be limited to the above information and can be added or reduced according to the usage scenario.

[0079] A data collection module, which is used to collect, but not limited to, software basic information and software supply chain vulnerability information, including a timed task program for regularly collecting the latest system vulnerability information and software supply chain vulnerability information, and a supply chain information program for extracting and collecting software supply chain information from software source code.

[0080] An agent, including long-term memory based on a data source module, and configured with a workflow. The workflow is a preset rule chain executed by the agent by calling an API interface or an automation script, which means that when the agent encounters a complex problem, it does not directly process it, but first decomposes the task through planning, selects the tool functions required for each task, and executes according to the content of the prompt. An agent is a computer program based on a large language model, with the abilities of planning and thinking, memory, and using tool functions, and can autonomously complete a given task. The agent described in the embodiments of the present invention is a large language model with the abilities of generating code and text, such as Figure 3 shown, the tool functions mainly include remote execution scripts, remote command execution, and API interfaces.

[0081] The workflow involved in this embodiment includes a restricted URL workflow for automatically restricting access to the supply chain URL by the firewall by calling the remote command execution tool function; a script upgrade workflow for upgrading the middleware version by calling the remote script execution tool function; a sending workflow for sending vulnerability information related to the software to be protected to the software responsible person; a supply chain repair plan workflow for executing the supply chain vulnerability repair suggestion plan according to the content of the prompt; and a system repair plan workflow for executing the system vulnerability repair suggestion plan.

[0082] An information connection subsystem, including an information extraction module for connecting the extracted information into the agent. The extracted information includes the basic software information of the software to be protected, the software supply chain information, and the software supply chain vulnerability information scanned by the security protection tool.

[0083] A vulnerability information analysis and processing subsystem, including an algorithm module one and a backup module for executing a number matching algorithm. The backup module is used to input the supply chain vulnerability information as a prompt into the agent and send the supply chain vulnerability repair suggestion plan generated by the short-term memory of the agent to the software responsible person when the newly discovered supply chain vulnerability information has not been collected or does not contain a vulnerability repair suggestion plan. The number matching algorithm includes the following steps:

[0084] Extract the corresponding supply chain number and software responsible person according to the software number, or extract the corresponding supply chain number and software responsible person according to the supply chain vulnerability number of the risk-bearing vulnerability information discovered by the security protection tool, or extract the supply chain number and software responsible person of the software to be protected through the information extraction module; if the risk-bearing vulnerability information discovered by the security protection tool has not been collected in the data source module, then call the backup module and send the vulnerability information and the supply chain vulnerability repair suggestion plan to the software responsible person.

[0085] If the software to be protected has not been launched yet, obtain the corresponding supply chain type and software supply chain vulnerability information from the software supply chain information according to the supply chain number and send them to the software responsible person. If the software to be protected has been launched, utilize the agent's plan to obtain the corresponding supply chain type from the software supply chain information according to the supply chain number, and execute different repair plans according to the supply chain type:

[0086] Repair plan 1, if the supply chain type is the component type, the agent matches the software number from the knowledge base according to the supply chain number, and calls and sends the workflow to feedback the software number and software supply chain vulnerability information to the software responsible person;

[0087] Repair plan 2, if the supply chain type is the middleware type, call the script upgrade workflow through the agent;

[0088] Repair plan 3, if the supply chain type is third-party (or private) software, call the workflow through the agent, and match the software number, software supply chain vulnerability information and other relevant information from the knowledge base according to the supply chain number and feedback them to the software responsible person.

[0089] Among them, the software basic attribute information, software supply chain information, and software supply chain vulnerability information are respectively made into lists in the data source module, that is, the knowledge base and are associated through the association logic. For example Figure 2 as shown, the association logic includes:

[0090] Association logic 1: In the supply chain number list item of the software basic attribute information, all the supply chain numbers of the software supply chains under the same software number are associated. In the software number list item of the software supply chain information, all the software numbers of the software under the same supply chain number are associated;

[0091] Association logic 2: In the existing vulnerability number list item of the software supply chain information, all the supply chain vulnerability numbers of the supply chain vulnerabilities under the same supply chain number are associated. In the second supply chain number list item of the software supply chain vulnerability information, all the supply chain numbers of the software supply chains under the same supply chain vulnerability number are associated.

[0092] The collected software basic information and software supply chain vulnerability information are used as corpus for the training and parameter tuning of the agent after being entered into the knowledge base.

[0093] The steps for the data collection module to collect data are as follows:

[0094] S101, collect software basic information, including collecting software basic attribute information and collecting software supply chain information.

[0095] Collect the basic software property information through CMDB (Configuration Management Database, which is a database used in IT service management and IT operation and maintenance management to store and manage the detailed information of various components in the IT infrastructure. The components include hardware devices, software applications, network connections, virtual machines, and storage devices).

[0096] Use the command line or script to collect software supply chain information from the software source code, including supply chain number, supply chain name, supply chain version number, software number list, supply chain type, list of existing vulnerability numbers, supply chain URL, etc.

[0097] S102, collect vulnerability information.

[0098] Collection method 1: According to the software supply chain name and supply chain version, use a script to obtain software supply chain vulnerability information and vulnerability repair suggestion solutions on open-source vulnerability management websites such as Full Disclosure Mailing List (FDML, a dedicated information sharing platform in the field of information security, aiming to provide an open, transparent, and timely information sharing environment to help information security professionals keep abreast of the latest security threats and defense methods) and Exploit DB (officially known as Exploit-DB, an online vulnerability exploitation database and platform that focuses on collecting and publishing various computer vulnerabilities and their exploitation codes. It aims to provide users with detailed information about computer vulnerabilities, including vulnerability descriptions, affected ranges, exploitation methods, etc. Through Exploit-DB, users can quickly understand the weaknesses of the system and take corresponding defense measures). The following is a script example of the vulnerability information and vulnerability repair suggestion solutions of a supply chain collected through a script:

[0099] {

[0100] Vulnerability number: "CVE-2013-4547",

[0101] Vulnerability name: "Nginx file name logic vulnerability",

[0102] Vulnerability details: "This vulnerability can lead to directory traversal and code execution. The main reason is that nginx incorrectly parses the requested URI due to a null byte truncation, parses the file name obtained from the user request as the corresponding script program, resulting in collateral effects such as permission bypass and code execution, thus realizing the process of getting a shell",

[0103] Affected versions: "Nginx 0.8.41 ~ 1.4.3 1.5.0 ~ 1.5.7",

[0104] Vulnerability repair suggestion plan: "After upgrading Nginx to 1.5.7",

[0105] ……: ……

[0106] }

[0107] Collection method two:

[0108] Collect by subscribing to the IP blacklist, software supply chain vulnerability information, and vulnerability repair suggestion plans provided by security service providers (such as NSFocus).

[0109] Collection method three: Software supply chain vulnerability information detected through penetration testing, and a vulnerability repair suggestion plan generated using the short-term memory of the agent based on the software supply chain vulnerability information.

[0110] In addition, to further improve the accuracy of the vulnerability repair suggestion plan, the scheduled task program obtains the latest risk information, software supply chain vulnerability information, and supply chain vulnerability repair suggestion plans from the above collection methods, and updates the supply chain vulnerability repair suggestion plan fields in a timely manner. At the same time, the updated data is also used for knowledge base update and agent training and fine-tuning.

[0111] The method for software security assisted defense on the supply chain side of the software to be protected using this embodiment, implementing a number matching algorithm, such as Figure 4 shown, includes the following steps:

[0112] S201: Extract software supply chain information and software responsible persons. Use the agent to match the corresponding supply chain numbers and software responsible persons from the information extracted by the information connection subsystem.

[0113] During software compilation and integration, that is, when the software has not been launched yet, use the information extraction module (such as a script) to automatically extract the software supply chain information in the source code of the software to be protected as a prompt input to the agent, including component dependency library information, middleware information, and third-party (or private) software information. For example, for software written in the Python language, the component dependency library information {certifi==2023.7.22, chardet==4.0.0, idna==2.10, requests==2.24.0, urllib3==1.25.10 (in the format of component dependency library name == version number)} can be obtained through the pip freeze > requirements.txt command; or extract the corresponding software supply chain information and software responsible persons according to the software number;

[0114] After the software is launched, the agent extracts the corresponding supply chain number based on the supply chain vulnerability number and the software responsible person of the vulnerability information with risks discovered by the security protection tool. If the vulnerability information is not collected in the data source module, the backup module is called, and the short-term memory of the agent is used to generate a corresponding vulnerability solution with the vulnerability information as a prompt word, and the send workflow is called to send the vulnerability information and the supply chain vulnerability repair suggestion plan to the software responsible person.

[0115] S202: Use the agent to search for the corresponding supply chain type from the knowledge base according to the supply chain number and association logic one;

[0116] S203: If the software to be protected has not been launched yet, search for software supply chain vulnerability information according to the supply chain number and association logic two, organize the supply chain vulnerability name, supply chain number, supply chain vulnerability details, supply chain affected version, and supply chain vulnerability repair suggestion plan in the software supply chain vulnerability information and send it to the software responsible person by email and end, otherwise continue to the next step.

[0117] S204: Execute different repair plans according to the supply chain type:

[0118] S2041: Repair plan one, if the supply chain type is a component type, the long-term memory of the agent matches the software number and software supply chain vulnerability information from the data source module according to the supply chain number and feedbacks it to the software responsible person;

[0119] S2042: Repair plan two, if the supply chain type is a middleware type, the agent is used to call the script upgrade workflow. For example, for the Nginx file name logic vulnerability with vulnerability number CVE-2013-4547, whose vulnerability repair suggestion plan is to upgrade Nginx to 1.5.7, then the automated script tool will smoothly upgrade Nginx to a version after 1.5.7 to complete the repair of this vulnerability;

[0120] S2043: Repair plan three, if the supply chain type is a third-party (or private) software, the agent is used to call the restricted URL workflow.

[0121] If the supply chain vulnerability repair suggestion plan is included in the vulnerability information with risks discovered by the security protection tool, the supply chain repair plan workflow of the supply chain vulnerability repair suggestion plan can also be directly executed.

[0122] Embodiment 2

[0123] This embodiment discloses a software full-cycle network security auxiliary defense system, including the software supply chain side network security auxiliary defense system of Embodiment 1.

[0124] In addition, the vulnerability information stored in the data source module of this embodiment further includes an IP blacklist and system vulnerability information. The system vulnerability information includes a system vulnerability number, a system vulnerability name, system vulnerability details, affected system versions, and system vulnerability repair suggestion solutions. The knowledge base mentioned in this embodiment is formed by importing software basic information, software supply chain vulnerability information, and system vulnerability information into a database according to an association relationship, and is used to quickly retrieve relevant information on software supply chain vulnerabilities;

[0125] The workflow further includes a workflow for automatically blocking an IP by calling a remote command execution tool function to call a firewall, and a system repair plan workflow for executing a system vulnerability repair suggestion solution according to a prompt.

[0126] The information connection subsystem further includes a coding tool module that connects a software coding tool to an agent. The coding tool module is used to detect source code vulnerabilities during the coding process and generate repair solutions. The coding tool module includes an IDE plugin or an IDE configuration file encapsulated by the API interface of the agent.

[0127] The information extracted by the information extraction module further includes system vulnerability information scanned by a vulnerability scanning tool for the system on which the software to be protected runs, IP addresses and URLs with risks discovered by security protection tools.

[0128] The method for the data collection module to collect system vulnerability information is to obtain vulnerability information and vulnerability repair suggestion solutions scanned by a vulnerability scanning tool, such as the NSFocus vulnerability scanning system. The collected software basic information, software supply chain vulnerability information, and system vulnerability information are used as corpus for the training and parameter tuning of the agent after being entered into the knowledge base.

[0129] The vulnerability information analysis and processing subsystem further includes a standby module. The standby module is used to input system vulnerability information or supply chain vulnerability information as a prompt to the agent when newly discovered system vulnerability information or supply chain vulnerability information has not been collected or does not include a vulnerability repair suggestion solution, and send the system vulnerability repair suggestion solution or supply chain vulnerability repair suggestion solution generated from the short-term memory of the agent to the software responsible person.

[0130] This embodiment adopts different software assisted defense methods according to different life cycle stages of the software, including the steps:

[0131] S3: On the software coding side, encapsulate the API interface of the agent into an IDE (Integrated Development Environment) plugin or configuration file, that is, the coding tool module, enabling the IDE to have the ability to automatically detect source code vulnerabilities during the coding process. Real-time detection of security vulnerabilities is carried out during the coding process. When a security vulnerability is detected, the agent generates reference code for a security vulnerability repair plan in real time based on the coding context information. The configuration file is as follows:

[0132] {

[0133] "models":

[0134] {

[0135] "title": "Network Security Vertical Domain Large Model",

[0136] "provider": "ollama",

[0137] "model": "network-safe-model-v2:130b",

[0138] "apiBase": "https: / / xxx.xxx.xxx:port"

[0139] }

[0140] ,

[0141] "customCommands":

[0142] {

[0143] "name": "checkbugs",

[0144] "prompt": "{{{ input}}} Check for security risks in this code section",

[0145] "description": "Checking Bugs for highlighted code"

[0146] }

[0147] ,

[0148] "tabAutocompleteModel": {

[0149] "title": "network-safe-model-v2:130b",

[0150] "provider": "ollama",

[0151] "model": "network-safe-model-v2:130b",

[0152] "apiBase": "https: / / xxx.xxx.xxx:port"

[0153] },

[0154] "allowAnonymousTelemetry": false,

[0155] "embeddingsProvider": {

[0156] "provider": "ollama",

[0157] "model": "nomic-embed-text:latest",

[0158] "apiBase": "https: / / xxx.xxx.xxx:port"

[0159] }

[0160] }

[0161] On the software supply chain side, the specific method is as follows: steps S201 - S204 in Embodiment 1:

[0162] When the software is running, in order to cope with security threats from the system where the software runs, the software-assisted defense method includes the following steps:

[0163] S401: Invoke a vulnerability scanning tool (such as the NSFocus vulnerability scanning system) to scan the operating system where the software is running, and output a vulnerability scanning report.

[0164] S402: Extract the system vulnerability numbers and corresponding system vulnerability repair suggestion plans from the vulnerability scanning report, and then use the intelligent agent to execute the system repair plan workflow;

[0165] If there is no system vulnerability repair suggestion plan, the intelligent agent will call the backup module, use the system vulnerability details as the prompt words of the intelligent agent to generate a corresponding system vulnerability repair suggestion plan by using short-term memory, and send the system vulnerability information and the system vulnerability repair suggestion plan to the software responsible person by email.

[0166] After the software is launched, since the software is exposed to the Internet side, it will be subject to a large number of cyberattacks. The software-assisted defense method includes the following steps:

[0167] S501: Analyze the type of vulnerability information and call the corresponding algorithm module;

[0168] S5021: When the vulnerability information is a risk IP, call algorithm module two to execute the IP analysis algorithm, as Figure 5 shown, that is,

[0169] Push the risk IP discovered by the security protection tool to the agent, and use the agent to determine whether the risk IP is included in the IP blacklist in the knowledge base. If so, use the agent to execute the IP blocking workflow,

[0170] Otherwise, push the risk IP to the threat analysis platform (such as, Micro Focus Online X Intelligence Community, a well-known domestic pilot demonstration comprehensive threat analysis platform and intelligence sharing community, based on threat data query, analysis and intelligence data sharing, providing convenient one-stop analysis tools for global security practitioners and enterprises, with the website https: / / www.threatbook.cn / prod / api, or other threat analysis platforms can also be used for analysis) to determine whether it is a high-risk IP. If so, use the agent to execute the IP blocking workflow,

[0171] Otherwise, determine whether the access frequency of the risk IP is abnormal (such as exceeding 1000 times). If so, use the agent to execute the IP blocking workflow.

[0172] S5022: When the vulnerability information is an attacked URL (Uniform Resource Locator, which is a concise representation of the location and access method of resources that can be obtained from the Internet, is the address of standard resources on the Internet, and each file on the Internet has a unique URL, which contains information indicating the location of the file and how the browser should handle it), call algorithm module three to execute the URL judgment algorithm, as Figure 6 shown, that is,

[0173] After the security protection tool discovers an attacked URL, use the agent to analyze whether the attacked URL matches the URL list item or the supply chain URL item. If so, use the agent to execute the URL restriction workflow.

[0174] S5023: If the vulnerability information is software supply chain vulnerability information, call algorithm module one to execute the number matching algorithm after the software is launched, that is,

[0175] The agent extracts the corresponding supply chain number and software responsible person according to the supply chain vulnerability number of the vulnerability information with risks discovered by the security protection tool.

[0176] The agent searches for the supply chain type from the knowledge base according to the supply chain number and association logic one;

[0177] Execute different repair solutions according to the supply chain type:

[0178] Repair solution one, if the supply chain type is the component type, the agent matches the software number and software supply chain vulnerability information from the knowledge base according to the supply chain number and feeds them back to the software responsible person;

[0179] Repair solution two, if the supply chain type is the middleware type, the agent calls the script upgrade workflow;

[0180] Repair solution three, if the supply chain type is third-party (i.e., private) software, the agent calls the restricted URL workflow and matches the software number and software supply chain vulnerability information from the knowledge base according to the supply chain number and feeds them back to the software responsible person.

[0181] If the vulnerability information with risks discovered by the security protection tool contains a supply chain vulnerability repair suggestion plan, the supply chain repair plan workflow of the supply chain vulnerability repair suggestion plan can also be directly executed.

[0182] S5024: After the software is launched, in order to further ensure the security of the software, network security engineers usually conduct periodic penetration tests on the software (penetration personnel use various means to test a specific network at different locations in order to discover and dig out the vulnerabilities existing in the system, and then output a penetration test report and submit it to the network owner. According to the penetration test report provided by the penetration personnel, the network owner can clearly know the security hidden dangers and problems existing in the system), and form a penetration test report.

[0183] Taking the vulnerability details of the penetration test report as a prompt word and inputting it into the agent, the agent uses short-term memory to generate a vulnerability repair suggestion plan, which is included in the data source module, and the vulnerability details and the vulnerability repair suggestion plan are sent to the software responsible person by email.

[0184] In this embodiment, when a vulnerability appears, the agent analyzes and identifies the vulnerability information, and uses the short-term memory and long-term memory of the agent to assist in the analysis. For different types of vulnerability risks, different workflows are used to call different tool functions to complete the vulnerability handling, so as to complete the intelligent processing of the security risks existing in the software supply chain side and even the entire life cycle.

[0185] The preferred embodiments of the present invention have been described in detail above in conjunction with the accompanying drawings. However, the present invention is not limited to the specific details in the above embodiments. Within the scope of the technical concept of the present invention, various simple modifications can be made to the technical solution of the present invention, and these simple modifications all fall within the protection scope of the present invention.

Claims

1. A software supply chain side network security auxiliary defense system, characterized in that, Including: A data source module that stores basic software information and vulnerability information. The basic software information includes basic software attribute information and software supply chain information. The basic software attribute information includes the software responsible person and the software number. The software supply chain information includes the supply chain number, the supply chain type, and the supply chain URL. The vulnerability information includes software supply chain vulnerability information; An agent that includes long-term memory based on the data source module and is configured with a workflow; An information connection subsystem that includes an information extraction module for connecting the extracted information into the agent. The extracted information includes the basic software information of the software to be protected and the software supply chain vulnerability information scanned by the security protection tool; A vulnerability information analysis and processing subsystem that at least includes an algorithm module one for executing a number matching algorithm. The number matching algorithm includes the following steps: Using the agent to match the corresponding supply chain number and software responsible person from the information extracted by the information connection subsystem; If the software to be protected has not been launched yet, obtain the corresponding supply chain type and software supply chain vulnerability information from the software supply chain information according to the supply chain number and send them to the software responsible person. Otherwise, call the workflow to execute different preset repair plans according to the supply chain type; The workflow includes a restricted URL workflow for calling the firewall to automatically restrict access to the supply chain URL, a script upgrade workflow for executing an automated script tool to upgrade the middleware version, and a sending workflow for sending the vulnerability information related to the software to be protected to the software responsible person; The repair plan includes: Repair plan one. If the supply chain type is a component type, match the software number through the long-term memory of the agent, and call the sending workflow to send the software number and vulnerability information to the software responsible person; Repair plan two. If the supply chain type is a middleware type, call the script upgrade workflow through the agent; Repair plan three. If the supply chain type is a third-party software, call the restricted URL workflow through the agent.

2. The software supply chain-side network security auxiliary defense system according to claim 1, wherein The basic software attribute information includes a list of supply chain numbers one and the software number. The software supply chain information includes a list of software numbers and a list of existing vulnerability numbers. The software supply chain vulnerability information includes a supply chain vulnerability number and a list of supply chain numbers two. The list of supply chain numbers one in the basic software attribute information associates all the supply chain numbers of the software supply chains under the same software number. The item of the list of software numbers in the software supply chain information associates all the software numbers of the software under the same supply chain number; The item of the list of existing vulnerability numbers in the software supply chain information associates all the supply chain vulnerability numbers of the software supply chain vulnerabilities under the same supply chain number. The list of supply chain numbers two in the software supply chain vulnerability information associates all the supply chain numbers of the software supply chains under the same supply chain vulnerability number.

3. The software supply chain-side network security auxiliary defense system according to claim 2, characterized in that, The basic software attribute information further includes the software number. The ways for the number matching algorithm to match the corresponding supply chain number and software responsible person include: extracting the corresponding supply chain number and software responsible person according to the software number; Extract the corresponding supply chain number and software responsible person according to the supply chain vulnerability number of the vulnerability information with risks discovered by the security protection tool. Extract the supply chain number and software responsible person of the software to be protected through the information extraction module.

4. The software supply chain side network security auxiliary defense system according to claim 1, characterized in that The software supply chain vulnerability information includes a supply chain vulnerability repair suggestion plan, and the workflow further includes a supply chain repair plan workflow for executing the supply chain vulnerability repair suggestion plan.

5. The software supply chain side network security auxiliary defense system according to claim 1, characterized in that It further includes a data collection module, and the data collection module can collect vulnerability information in any one or more of the following ways: Collect software supply chain vulnerability information on the open-source vulnerability management website using a script according to the supply chain name and supply chain version of the software. Collect the vulnerability information provided by the subscribed security service provider. Collect the vulnerability information related to the software supply chain detected through penetration testing and the supply chain vulnerability repair suggestion plan generated using the short-term memory of the agent based on the vulnerability information.

6. The software supply chain side network security auxiliary defense system according to claim 5, characterized in that, It further includes a data collection module, and the data collection module further includes a scheduled task program for regularly collecting the latest vulnerability information.

7. The software supply chain-side network security auxiliary defense system according to claim 1, characterized in that, In the number matching algorithm, if the vulnerability information with risks discovered by the security protection tool is not collected in the data source module, the vulnerability information is used as a prompt word to generate a corresponding vulnerability solution using the short-term memory of the agent.

8. A software full-cycle network security auxiliary defense system, including the software supply chain side network security auxiliary defense system described in any one of claims 1-7, characterized in that, The vulnerability information further includes system vulnerability information, and the system vulnerability information includes a system vulnerability repair suggestion plan. The workflow includes a system repair plan workflow for executing the system vulnerability repair suggestion plan. The information connection subsystem further includes a coding tool module for connecting the software coding tool and the agent, and the coding tool module is used to detect source code vulnerabilities during the coding process and generate a repair plan. The extracted information further includes system vulnerability information scanned by the vulnerability scanning tool for the system where the software to be protected runs.

9. The software full-cycle network security assisted defense system according to claim 8, characterized in that The vulnerability information further includes an IP blacklist, the extracted information further includes the risk IP addresses discovered by the security protection tool, the workflow further includes a banned IP workflow for calling the security protection tool to execute the remote command tool to ban the IP, and the vulnerability information analysis and processing subsystem further includes an algorithm module two for executing the IP analysis algorithm. The IP analysis algorithm is to push the risk IP discovered by the security protection tool to the agent, and use the agent to determine whether the risk IP is included in the IP blacklist in the knowledge base. If so, use the agent to execute the banned IP workflow. Otherwise, push the risk IP to the threat analysis platform to determine whether it is a high-risk IP. If so, use the agent to execute the banned IP workflow. Otherwise, determine whether the access frequency of the risk IP is abnormal. If so, use the agent to execute the banned IP workflow.

10. The software full-cycle network security assisted defense system according to claim 8 or 9, characterized in that The software basic attribute information further includes a URL list, the software supply chain information further includes a supply chain URL, the extracted information further includes the risk URLs discovered by the security protection tool, and the vulnerability information analysis and processing subsystem further includes an algorithm module three for executing the URL judgment algorithm. The URL judgment algorithm pushes the attacked URLs discovered by the security protection tool to the agent, and the agent analyzes whether the attacked URLs match the URL list items or the supply chain URL items. If so, the agent is used to execute the restricted URL workflow that calls the firewall to automatically restrict access to the supply chain URLs.

11. The software full-cycle network security auxiliary defense system according to claim 8 or 9, characterized in that, The coding tool module includes an IDE plugin or an IDE configuration file encapsulated by the API interface of the agent.

12. The software full-cycle network security assisted defense system according to claim 8 or 9, characterized in that, The collected basic software information, software supply chain vulnerability information, and vulnerability information are used as corpus for the training and parameter tuning of the agent after being entered into the knowledge base.

13. The software full-cycle network security auxiliary defense system according to claim 8 or 9, characterized in that, The vulnerability information analysis and processing subsystem further includes a backup module. The backup module is used to input the system vulnerability information or the supply chain vulnerability information as a prompt word into the agent when the newly discovered system vulnerability information or supply chain vulnerability information has not been collected or does not contain a vulnerability repair suggestion plan, and send the system vulnerability repair suggestion plan or the supply chain vulnerability repair suggestion plan generated by the short-term memory of the agent to the software responsible person.

Citation Information

Patent Citations

  • Network security event analysis method and device, electronic equipment and storage medium

    CN114189378A

  • Network threat active defense system and method based on large model

    CN118316736A

  • Big data analysis processing method and system for intelligent network security

    CN119011302A

  • Data security situation awareness system, method and apparatus and storage medium

    CN112000719A

  • Method and system for improving full-life-cycle research and development efficiency of BIM (Building Information Modeling) software

    CN118427820A