Vulnerability information retrieval method and device, electronic equipment and storage medium
By identifying and generating vulnerability information databases, the problem of dispersed vulnerability information is solved, efficient and accurate vulnerability information retrieval is achieved, and operation and maintenance efficiency is improved.
Patent Information
- Application Number
- CN202411699014.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-25
- Publication Date
- 2025-05-06
AI Technical Summary
Massive vulnerability repairs face the problem of information dispersion, which makes it difficult for operation and maintenance personnel to efficiently retrieve and obtain related vulnerability repair information.
Provide a vulnerability information retrieval method, which can obtain the original file of vulnerability information, identify and generate the target vulnerability information database, receive search instructions input by users, and retrieve and output relevant information from the target database.
It improves the efficiency of vulnerability information retrieval, ensures the accuracy and comprehensiveness of the retrieved information, and reduces the time cost of users when locating the vulnerability version.
Smart Images

Figure CN119939587A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network information security, and in particular to a vulnerability information retrieval method, device, electronic device and storage medium. Background Art
[0002] Currently, many released software often have a large number of historical vulnerabilities, which may exist due to design defects, flaws or newly discovered security vulnerabilities during the development process. In order to ensure the availability and security of the software, these vulnerabilities often need to be fixed during the operation and maintenance process.
[0003] However, fixing a large number of vulnerabilities faces a challenge, namely, the dispersion of vulnerability repair information. Official vulnerability repair information is often scattered in multiple channels, such as vulnerability reports, security announcements, and change logs. This dispersion makes it difficult for operation and maintenance personnel to efficiently retrieve and obtain relevant vulnerability repair information during work, and they need to spend a lot of time to locate the version where the vulnerability has been fixed.
[0004] Therefore, how to quickly retrieve vulnerability information has become an urgent problem to be solved. Summary of the invention
[0005] In view of this, the present invention provides a vulnerability information retrieval method, device, electronic device and storage medium to solve the problem of rapid retrieval of vulnerability information.
[0006] In a first aspect, the present invention provides a vulnerability information retrieval method, the method comprising:
[0007] Get the original file of vulnerability information;
[0008] Identify the original vulnerability information files and generate the target vulnerability information library;
[0009] Receive a vulnerability information retrieval instruction input by a target user, retrieve target vulnerability information from a target vulnerability information library, and output the target vulnerability information to the target user.
[0010] The vulnerability information retrieval method provided in the embodiment of the present application obtains the original file of vulnerability information; identifies the original file of vulnerability information and generates a target vulnerability information library, so that the user does not need to manually identify various original files of vulnerability information, thereby ensuring the accuracy and conciseness of the generated target vulnerability information library. Then, the vulnerability information retrieval instruction input by the target user is received, the target vulnerability information is retrieved from the target vulnerability information library, and the target vulnerability information is output to the target user, thereby ensuring the accuracy and comprehensiveness of the retrieved target vulnerability information. Compared with the prior art, the above method does not require the target user to retrieve various original files of vulnerability information, but only requires the target user to input the vulnerability information retrieval instruction, and then retrieve from the generated target vulnerability information library. Therefore, the above method not only improves the efficiency of vulnerability information retrieval, but also ensures the accuracy and comprehensiveness of the retrieved vulnerability information.
[0011] In an optional implementation, identifying the original vulnerability information file and generating a target vulnerability information library includes:
[0012] Identify the original file of vulnerability information and determine the non-text data in the original file of vulnerability information;
[0013] According to the data type corresponding to the non-text data, a preset data conversion method is used to convert the non-text data into text data;
[0014] Generate vulnerability information target file based on the converted text data;
[0015] Identify the target files of vulnerability information and generate a target vulnerability information library.
[0016] The vulnerability information retrieval method provided in the embodiment of the present application identifies the vulnerability information original file, determines the non-text data in the vulnerability information original file, and thus can convert the non-text data in the vulnerability information original file. According to the data type corresponding to the non-text data, a preset data conversion method is used to convert the non-text data into text data, and a vulnerability information target file is generated based on the converted text data, so that the vulnerability information target file can be identified using only the text data identification method, and there is no need to perform multiple identifications for various data types, thereby improving the efficiency of identification. The vulnerability information target file is identified and a target vulnerability information library is generated, thereby ensuring the accuracy and comprehensiveness of the generated target vulnerability information library.
[0017] In an optional implementation, identifying the vulnerability information target file and generating a target vulnerability information library includes:
[0018] Inputting the vulnerability information target file into the first target large language model, the first target large language model recognizes the vulnerability information target file, and based on the preset prompt word, searches the vulnerability information target file for vulnerability information corresponding to the preset prompt word;
[0019] Based on the vulnerability information corresponding to the preset prompt words, a target vulnerability information database is generated.
[0020] The vulnerability information retrieval method provided by the embodiment of the present application inputs the vulnerability information target file into the first target large language model, the first target large language model identifies the vulnerability information target file, and based on the preset prompt word, searches the vulnerability information target file for the vulnerability information corresponding to the preset prompt word, thereby ensuring the relevance of the extracted vulnerability information to the preset prompt word, and ensuring the accuracy and comprehensiveness of the vulnerability information corresponding to the preset prompt word. Based on the vulnerability information corresponding to the preset prompt word, a target vulnerability information library is generated, thereby ensuring the accuracy and comprehensiveness of the generated target vulnerability information library.
[0021] In an optional implementation, the preset prompt word includes an extraction requirement and an extraction field. Based on the preset prompt word, the vulnerability information corresponding to the preset prompt word is searched in the vulnerability information target file, including:
[0022] The preset prompt words are identified, the extraction requirements and extraction fields in the preset extraction words are determined, and according to the extraction requirements, the vulnerability information corresponding to the extraction field is queried from the vulnerability information target file.
[0023] The vulnerability information retrieval method provided in the embodiment of the present application identifies preset prompt words, determines the extraction requirements and extraction fields in the preset extraction words, and queries the vulnerability information corresponding to the extraction fields from the vulnerability information target file according to the extraction requirements, thereby ensuring the relevance of the extracted vulnerability information to the preset prompt words, and ensuring the accuracy and comprehensiveness of the vulnerability information corresponding to the queried preset prompt words.
[0024] In an optional implementation, based on the vulnerability information corresponding to the preset prompt word, a target vulnerability information library is generated, including:
[0025] Fill the vulnerability information corresponding to the extracted field into the preset location to generate an initial vulnerability information library;
[0026] The vulnerability information in the initial vulnerability information database is deduplicated and missing values are removed to generate the target vulnerability information database.
[0027] The vulnerability information retrieval method provided in the embodiment of the present application fills the vulnerability information corresponding to the extracted field into a preset position to generate an initial vulnerability information library; deduplicates and removes missing values from the vulnerability information in the initial vulnerability information library to generate a target vulnerability information library, thereby ensuring that the generated target vulnerability information library is accurate and concise.
[0028] In an optional implementation, receiving a vulnerability information retrieval instruction input by a target user, retrieving target vulnerability information from a target vulnerability information library, and outputting the target vulnerability information to the target user includes:
[0029] The vulnerability information retrieval instruction is input into the second target large language model, the second target large language model recognizes the vulnerability information retrieval instruction, retrieves the target vulnerability information from the target vulnerability information library, and outputs the target vulnerability information to the target user.
[0030] The vulnerability information retrieval method provided in the embodiment of the present application inputs the vulnerability information retrieval instruction into the second target large language model, the second target large language model recognizes the vulnerability information retrieval instruction, retrieves the target vulnerability information from the target vulnerability information library, and outputs the target vulnerability information to the target user, thereby ensuring the accuracy and comprehensiveness of the target vulnerability information corresponding to the retrieved vulnerability information retrieval instruction. Thus, the target user can obtain accurate target vulnerability information, and then perform vulnerability repair according to the accurate target vulnerability information.
[0031] In an optional implementation, the training process of the second target large language model includes:
[0032] Based on the target vulnerability information database, a training data set is generated; the training data set includes training questions and training answers, and the training answers exist in the target vulnerability information database;
[0033] The training data set is input into the second initial large language model, and the second initial large language model identifies the training questions and searches for candidate answers from the target vulnerability information database;
[0034] Compare candidate answers with training answers;
[0035] If the candidate answer is inconsistent with the training answer, modify the system prompt word corresponding to the second initial large language model, and determine the modified second initial large language model as the second target large language model;
[0036] If the candidate answer is consistent with the training answer, the second initial large language model is determined as the second target large language model.
[0037] The vulnerability information retrieval method provided in the embodiment of the present application generates a training data set based on a target vulnerability information repository; the training data set is input into a second initial large language model, the second initial large language model identifies the training question, searches for candidate answers from the target vulnerability information repository, and compares the candidate answers with the training answers; if the candidate answers are inconsistent with the training answers, the system prompt words corresponding to the second initial large language model are modified, and the modified second initial large language model is determined as the second target large language model; if the candidate answers are consistent with the training answers, the second initial large language model is determined as the second target large language model, thereby ensuring the accuracy of the trained second target large language model.
[0038] In a second aspect, the present invention provides a vulnerability information retrieval device, the device comprising:
[0039] Acquisition module, used to obtain the original file of vulnerability information;
[0040] The identification module is used to identify the original vulnerability information file and generate a target vulnerability information database;
[0041] The retrieval module is used to receive a vulnerability information retrieval instruction input by a target user, retrieve target vulnerability information from a target vulnerability information library, and output the target vulnerability information to the target user.
[0042] The vulnerability information retrieval device provided in the embodiment of the present application obtains the original file of vulnerability information; identifies the original file of vulnerability information and generates a target vulnerability information library, so that the user does not need to manually identify various original files of vulnerability information, ensuring the accuracy and simplicity of the generated target vulnerability information library. Then, the vulnerability information retrieval instruction input by the target user is received, the target vulnerability information is retrieved from the target vulnerability information library, and the target vulnerability information is output to the target user, ensuring the accuracy and comprehensiveness of the retrieved target vulnerability information. Compared with the prior art, the above method does not require the target user to retrieve various original files of vulnerability information, but only requires the target user to input the vulnerability information retrieval instruction, and then search from the generated target vulnerability information library. Therefore, the above device not only improves the efficiency of vulnerability information retrieval, but also ensures the accuracy and comprehensiveness of the retrieved vulnerability information.
[0043] In a third aspect, the present invention provides an electronic device, comprising: a memory and a processor, the memory and the processor being communicatively connected to each other, the memory storing computer instructions, and the processor executing the vulnerability information retrieval method of the first aspect or any corresponding embodiment thereof by executing the computer instructions.
[0044] In a fourth aspect, the present invention provides a computer-readable storage medium having computer instructions stored thereon, the computer instructions being used to enable a computer to execute the vulnerability information retrieval method of the first aspect or any corresponding embodiment thereof.
[0045] In a fifth aspect, the present invention provides a computer program product, comprising computer instructions, wherein the computer instructions are used to enable a computer to execute the vulnerability information retrieval method of the first aspect or any corresponding embodiment thereof. BRIEF DESCRIPTION OF THE DRAWINGS
[0046] In order to more clearly illustrate the specific implementation methods of the present invention or the technical solutions in the prior art, the drawings required for use in the specific implementation methods or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are some implementation methods of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0047] Figure 1 is a flow chart of a vulnerability information retrieval method according to an embodiment of the present invention;
[0048] Figure 2 is a flow chart of another vulnerability information retrieval method according to an embodiment of the present invention;
[0049] Figure 3 is a schematic diagram of generating an initial vulnerability information database according to an embodiment of the present invention;
[0050] Figure 4 is a flowchart of another vulnerability information retrieval method according to an embodiment of the present invention;
[0051] Figure 5 is a structural block diagram of a vulnerability information retrieval device according to an embodiment of the present invention;
[0052] Figure 6 It is a schematic diagram of the hardware structure of the electronic device according to an embodiment of the present invention. DETAILED DESCRIPTION
[0053] In order to make the purpose, technical solution and advantages of the embodiments of the present invention clearer, the technical solution in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative work are within the scope of protection of the present invention.
[0054] Currently, many released software often have a large number of historical vulnerabilities, which may exist due to design defects, flaws or newly discovered security vulnerabilities during the development process. In order to ensure the availability and security of the software, these vulnerabilities often need to be fixed during the operation and maintenance process.
[0055] However, fixing a large number of vulnerabilities faces a challenge, namely, the dispersion of vulnerability repair information. Official vulnerability repair information is often scattered in multiple channels, such as vulnerability reports, security announcements, and change logs. This dispersion makes it difficult for operation and maintenance personnel to efficiently retrieve and obtain relevant vulnerability repair information during work, and they need to spend a lot of time to locate the version where the vulnerability has been fixed.
[0056] Therefore, how to quickly retrieve vulnerability information has become an urgent problem to be solved.
[0057] It should be noted that the execution subject of the vulnerability information retrieval method provided in the embodiment of the present application may be a vulnerability information retrieval device, and the vulnerability information retrieval device may be implemented as part or all of an electronic device through software, hardware, or a combination of software and hardware, wherein the electronic device may be a server or a terminal, wherein the server in the embodiment of the present application may be a single server or a server cluster composed of multiple servers, and the terminal in the embodiment of the present application may be a smart phone, a personal computer, a tablet computer, a wearable device, an intelligent robot, or other intelligent hardware devices. In the following method embodiments, the execution subject is an electronic device as an example for explanation.
[0058] According to an embodiment of the present invention, an embodiment of a vulnerability information retrieval method is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.
[0059] In this embodiment, a vulnerability information retrieval method is provided, which can be used for the above-mentioned electronic device. Figure 1 is a flow chart of a vulnerability information retrieval method according to an embodiment of the present invention. Figure 1 As shown, the process includes the following steps:
[0060] Step S101, obtaining the original file of vulnerability information.
[0061] Specifically, the electronic device may receive the original file of vulnerability information input by the user, and may also search for the original file of vulnerability information in the storage space.
[0062] Among them, the original files of vulnerability information include but are not limited to security announcements, vulnerability reports, and manufacturer release information.
[0063] Step S102, identifying the original vulnerability information file and generating a target vulnerability information library.
[0064] Specifically, the electronic device can first identify the original vulnerability information file and determine the file format corresponding to the original vulnerability information file. Then, according to each file format, select the identification and extraction method corresponding to the file format, extract the vulnerability information from the original vulnerability information file, and then generate a target vulnerability information library based on the extracted vulnerability information.
[0065] Among them, the file formats may include: PDF (Portable Document Format), DOC / DOCX (Microsoft Word document), TXT (plain text file), HTML / XML (web page or XML data), PPT / PPTX (Microsoft PowerPoint presentation), JSON (JavaScript Object Notation, a JSON file used to store vulnerability information), etc.
[0066] Vulnerability information may include vulnerability ID, vulnerability name, affected software / system name, vulnerability level (such as high risk, medium risk, low risk), fixed version, related links, vulnerability description, provided patches or mitigation measures, discovery date, publication date, vulnerability type (such as SQL injection, cross-site scripting, privilege escalation, etc.), etc. The embodiments of the present application do not specifically limit the vulnerability information.
[0067] This step will be described in detail below.
[0068] Step S103, receiving a vulnerability information retrieval instruction input by a target user, retrieving target vulnerability information from a target vulnerability information library, and outputting the target vulnerability information to the target user.
[0069] Specifically, the electronic device may receive a vulnerability information search instruction input by a target user, wherein the vulnerability information search instruction may include keywords, vulnerability numbers, vulnerability types, and the like.
[0070] Then, the electronic device can search in the target vulnerability information database according to the vulnerability information retrieval instruction input by the user. The search process may involve technologies such as database query, keyword matching, and natural language processing.
[0071] After the electronic device finds the matching target vulnerability information, it formats and outputs it to the target user.
[0072] This step will be described in detail below.
[0073] The vulnerability information retrieval method provided in the embodiment of the present application obtains the original file of vulnerability information; identifies the original file of vulnerability information and generates a target vulnerability information library, so that the user does not need to manually identify various original files of vulnerability information, thereby ensuring the accuracy and conciseness of the generated target vulnerability information library. Then, the vulnerability information retrieval instruction input by the target user is received, the target vulnerability information is retrieved from the target vulnerability information library, and the target vulnerability information is output to the target user, thereby ensuring the accuracy and comprehensiveness of the retrieved target vulnerability information. Compared with the prior art, the above method does not require the target user to retrieve various original files of vulnerability information, but only requires the target user to input the vulnerability information retrieval instruction, and then retrieve from the generated target vulnerability information library. Therefore, the above method not only improves the efficiency of vulnerability information retrieval, but also ensures the accuracy and comprehensiveness of the retrieved vulnerability information.
[0074] In this embodiment, a vulnerability information retrieval method is provided, which can be used for the above-mentioned electronic device. Figure 2 is a flow chart of a vulnerability information retrieval method according to an embodiment of the present invention. Figure 2 As shown, the process includes the following steps:
[0075] Step S201, obtaining the original file of vulnerability information.
[0076] For details about this step, please refer to the above description of step S101, which will not be elaborated here.
[0077] Step S202, identifying the original vulnerability information file and generating a target vulnerability information library.
[0078] Specifically, the above step S202 includes:
[0079] Step S2021, identifying the original file of vulnerability information and determining the non-text data in the original file of vulnerability information.
[0080] Specifically, the electronic device can first identify the extension of the original file of the vulnerability information (such as .txt, .pdf, .docx, .jpg, .png, etc.), and then use a file attribute analysis tool (such as a file attribute viewer) to obtain more information about the original file of the vulnerability information, including creation time, modification time, file size, etc.
[0081] Then, the electronic device can preview the original file of the vulnerability information. Exemplarily, if the original file of the vulnerability information is in text format (such as .txt, .docx), you can directly open the file to view the content. For image formats (such as .jpg, .png), you can use an image viewer to open the file to see if it contains text information. If the original file of the vulnerability information is a scanned image or PDF document, you can use OCR software (such as Adobe Acrobat) to extract the text. In addition, the electronic device can also check whether there are non-text elements such as tables, charts, or formulas in the text.
[0082] The electronic device can then also use a file signature analysis tool (such as File Identifier) to determine the type of binary data in the original file of the vulnerability information. Optionally, a data visualization tool (such as WinHex) can also be used to view the binary data in the file to look for signs of non-text data.
[0083] Next, the electronic device can analyze the header information of the original file of the vulnerability information to understand the internal structure of the original file of the vulnerability information. Use parsing tools (such as XML parser, JSON parser) to parse the original file content of the vulnerability information and identify non-text data. Exemplarily, the electronic device can use a PDF reader or PDF parsing library (such as PyPDF2) to analyze the content in the PDF file, including text, images, links, etc. Use an Office document parsing library (such as python-docx) to parse Word, Excel and other documents to identify non-text content.
[0084] Finally, the electronic device can determine the non-text data in the original file of the vulnerability information based on the above identification results.
[0085] Among them, non-text data may include images, audio, etc.
[0086] Step S2022: convert the non-text data into text data using a preset data conversion method according to the data type corresponding to the non-text data.
[0087] Specifically, the electronic device may convert the non-text data into text data using a preset data conversion method according to the data type corresponding to the non-text data.
[0088] For example, for non-text data of image type, the electronic device may first perform image preprocessing on the image data, including adjusting the image data to a uniform size for subsequent processing. Then, the color image is converted into a grayscale image to reduce the amount of calculation. Then, the grayscale image is converted into black and white to facilitate character recognition. Noise in the image data is removed to improve recognition accuracy.
[0089] Then, the electronic device uses edge detection, connected region analysis and other methods to segment the characters in the image data. The shape, texture and other features of the characters, such as HOG (Histogram of Oriented Gradients) features, are extracted from the segmented regions. Finally, the segmented characters are recognized using the trained model, and the recognized characters are combined into complete text according to the order in the image, thereby converting the image data into text data.
[0090] Exemplarily, for non-text data of audio type, the electronic device can first remove the background noise in the audio signal, enhance the voice signal, and improve the recognition accuracy. Then, the electronic device divides the audio signal into multiple sub-audio frames for subsequent processing. Then, the electronic device inputs each sub-audio frame into the acoustic model, and the acoustic model extracts features from each sub-audio frame and outputs the spectral features corresponding to each sub-audio frame. Then, based on the language model, the acoustic features are mapped to the probability distribution of the acoustic unit. Then, for each time step, the probabilities of all possible acoustic unit sequences are calculated and optimized using a dynamic programming algorithm. Finally, the generated candidate word sequence is scored using the language model, and the optimal sequence is selected as the final output, thereby realizing the conversion of audio data into text data.
[0091] Step S2023, generating a vulnerability information target file based on the converted text data.
[0092] Specifically, the electronic device may use the converted text data to replace the non-text data in the original vulnerability information file before conversion, thereby generating a vulnerability information target file.
[0093] Step S2024, identifying the vulnerability information target file and generating a target vulnerability information library.
[0094] Specifically, the above step S2024 may include the following steps:
[0095] Step a1: input the vulnerability information target file into the first target large language model. The first target large language model identifies the vulnerability information target file and searches the vulnerability information corresponding to the preset prompt word in the vulnerability information target file based on the preset prompt word.
[0096] Specifically, the preset prompt word includes extraction requirements and extraction fields. The above step a1 of "based on the preset prompt word, querying the vulnerability information corresponding to the preset prompt word in the vulnerability information target file" may include the following steps:
[0097] Step a11, identifying the preset prompt words, determining the extraction requirements and extraction fields in the preset extraction words, and querying the vulnerability information corresponding to the extraction fields from the vulnerability information target file according to the extraction requirements.
[0098] Specifically, the electronic device can divide the vulnerability information target file into batches, or directly input it into the first target large language model at one time. The first target large language model can identify the preset prompt words, determine the extraction requirements and extraction. The extraction field may include extracting specific types of information (such as vulnerability ID, vulnerability name, affected software / system name, vulnerability level (such as: high risk, medium risk, low risk), repair version, related links, vulnerability description, provided patches or mitigation measures, discovery date, publication date, vulnerability type (such as: SQL injection, cross-site scripting, privilege escalation, etc.). The extraction requirement can be that if it is extracted, it will be output to the preset location, and if it is not extracted, it will not be output.
[0099] Then, the first target large language model searches for corresponding extraction fields in the vulnerability information target file according to the extraction requirements.
[0100] Optionally, the first target large language model may use natural language processing (NLP) technology to locate and extract relevant vulnerability information.
[0101] The extraction process may involve the following steps: Use word segmentation techniques to split the text into words or phrases. Apply named entity recognition (NER) techniques to identify entities in the text (such as vulnerability names, version numbers, etc.). Use relationship extraction techniques to determine the relationships between entities. Finally, extract the corresponding information from the text based on the extracted fields.
[0102] Finally, the vulnerability information fields extracted by the first target large language model are output in a structured form, such as JSON, XML or database format.
[0103] Step a2: Generate a target vulnerability information database based on the vulnerability information corresponding to the preset prompt word.
[0104] Specifically, the above step a2 may include the following steps:
[0105] Step a21, fill the vulnerability information corresponding to the extracted field into the preset location to generate an initial vulnerability information library.
[0106] Specifically, the electronic device can fill in the vulnerability information corresponding to the extracted field into a preset location to generate an initial vulnerability information library.
[0107] For example, Figure 3 As shown, this is a schematic diagram of generating an initial vulnerability information database.
[0108] Step a22, removing duplicates and missing values from the vulnerability information in the initial vulnerability information database to generate a target vulnerability information database.
[0109] Specifically, the electronic device can identify vulnerability information in the initial vulnerability information library to determine duplicate vulnerability information and vulnerability information with missing information, and then delete the duplicate vulnerability information and vulnerability information with missing information to generate a target vulnerability information library.
[0110] Step S203, receiving a vulnerability information retrieval instruction input by a target user, retrieving target vulnerability information from a target vulnerability information library, and outputting the target vulnerability information to the target user.
[0111] For details about this step, please refer to the above description of step S103, which will not be elaborated here.
[0112] The vulnerability information retrieval method provided in the embodiment of the present application identifies the original file of vulnerability information, determines the non-text data in the original file of vulnerability information, and thus can convert the non-text data in the original file of vulnerability information. According to the data type corresponding to the non-text data, a preset data conversion method is used to convert the non-text data into text data, and a vulnerability information target file is generated based on the converted text data, so that the vulnerability information target file can be identified only by using the text data identification method, and multiple identifications are not required for various data types, thereby improving the efficiency of identification. The vulnerability information target file is input into the first target large language model, the first target large language model identifies the vulnerability information target file, identifies the preset prompt word, determines the extraction requirements and extraction fields in the preset extraction word, and queries the vulnerability information corresponding to the extraction field from the vulnerability information target file according to the extraction requirements, thereby ensuring the relevance of the extracted vulnerability information and the preset prompt word, and ensuring the accuracy and comprehensiveness of the vulnerability information corresponding to the preset prompt word queried. The vulnerability information corresponding to the extraction field is filled in the preset position to generate an initial vulnerability information library; the vulnerability information in the initial vulnerability information library is deduplicated and de-missing valued to generate a target vulnerability information library, thereby ensuring the accuracy and conciseness of the generated target vulnerability information library.
[0113] In this embodiment, a vulnerability information retrieval method is provided, which can be used for the above-mentioned electronic device. Figure 4 is a flow chart of a vulnerability information retrieval method according to an embodiment of the present invention. Figure 4 As shown, the process includes the following steps:
[0114] Step S301, obtaining the original file of vulnerability information.
[0115] For details about this step, please refer to the above description of step S201, which will not be elaborated here.
[0116] Step S302, identifying the original vulnerability information file and generating a target vulnerability information library.
[0117] For details about this step, please refer to the above description of step S202, which will not be elaborated here.
[0118] Step S303, receiving a vulnerability information retrieval instruction input by a target user, retrieving target vulnerability information from a target vulnerability information library, and outputting the target vulnerability information to the target user.
[0119] Specifically, the above step S303 may include the following steps:
[0120] Step S3031, input the vulnerability information retrieval instruction into the second target large language model, the second target large language model recognizes the vulnerability information retrieval instruction, retrieves the target vulnerability information from the target vulnerability information library, and outputs the target vulnerability information to the target user.
[0121] Specifically, the electronic device can receive a vulnerability information retrieval instruction input by a target user, and then input the vulnerability information retrieval instruction into the second target large language model. After receiving the vulnerability information retrieval instruction, the second target large language model parses and recognizes the vulnerability information retrieval instruction, and extracts key information in the vulnerability information retrieval instruction, such as keywords, vulnerability numbers, and repair versions.
[0122] Then, the second target large language model searches the target vulnerability information database based on the identified key information. The search process may involve database query, keyword matching and other technologies.
[0123] Next, the search results are filtered and sorted to ensure that the output information is the most relevant and useful.
[0124] Finally, the second target large language model outputs the retrieved target vulnerability information to the target user in a target user-friendly format. The output format may include text, table, list, etc., depending on the user's needs and the design of the system.
[0125] Specifically, the training process of the second target large language model includes:
[0126] Step b1: Generate a training data set based on the target vulnerability information database.
[0127] The training data set includes training questions and training answers, and the training answers exist in the target vulnerability information database.
[0128] Specifically, the electronic device can generate training questions and training answers corresponding to the training questions based on the target vulnerability information library, thereby generating a training data set according to the training questions and the training answers.
[0129] Step b2: input the training data set into the second initial large language model, and the second initial large language model identifies the training questions and searches for candidate answers from the target vulnerability information library.
[0130] Specifically, the training data set is input into the second initial large language model, which converts each word in the training question into a vector representation. The second initial large language model then analyzes the context of the entire training question to understand the meaning of the training question. The second initial large language model attempts to identify the intent of the training question, that is, the type of problem the question is intended to solve.
[0131] Then, the second initial large language model searches for possible answers in the target vulnerability information repository. Optionally, the second initial large language model may use keyword search, semantic search or other information retrieval techniques to find information related to the question. The second initial large language model generates one or more candidate answers from the search results.
[0132] Step b3, compare the candidate answers with the training answers.
[0133] Specifically, the second initial large language model can calculate the similarity between the candidate answer and the training answer. Then, based on the similarity between the candidate answer and the training answer, it is determined whether the candidate answer is consistent with the training answer.
[0134] Step b4: if the candidate answer is inconsistent with the training answer, the system prompt word corresponding to the second initial large language model is modified, and the modified second initial large language model is determined as the second target large language model.
[0135] Specifically, if the candidate answer is inconsistent with the training answer, the electronic device determines the reason for the inconsistency between the candidate answer and the training answer. Specifically, the electronic device can check the design of the system prompt words, including its parameters, training data, pre-training methods, etc. It can also analyze whether the system prompt words have problems in understanding input or generating output.
[0136] Then, the electronic device makes specific modifications to the system prompt words according to the evaluation results. The modifications to the system prompt words may include adjusting parameters, updating training data, improving pre-training methods or algorithms, etc. In addition, all modifications are properly recorded for subsequent review and tracking.
[0137] Finally, the electronic device retrains the second initial large language model using the modified system prompt words. Make sure to use the same or similar data sets and training processes to facilitate comparison. Run a series of tests on the modified second initial large language model to evaluate its performance. Compare the improvement in the consistency between the generated candidate answers and the training answers by the models before and after modification. If there are still problems with the modified second initial large language model, the system prompt words or training process may need to be further adjusted. Repeat the process of evaluation, modification, and retraining until a satisfactory performance level is achieved. Once the modified second initial large language model meets the expected performance goals, it can be determined as the second target large language model.
[0138] Step b5: If the candidate answer is consistent with the training answer, the second initial large language model is determined as the second target large language model.
[0139] If the candidate answer is consistent with the training answer, the electronic device determines the second initial large language model as the second target large language model.
[0140] The vulnerability information retrieval method provided in the embodiment of the present application inputs the vulnerability information retrieval instruction into the second target large language model, the second target large language model recognizes the vulnerability information retrieval instruction, retrieves the target vulnerability information from the target vulnerability information library, and outputs the target vulnerability information to the target user, thereby ensuring the accuracy and comprehensiveness of the target vulnerability information corresponding to the retrieved vulnerability information retrieval instruction. Thus, the target user can obtain accurate target vulnerability information, and then perform vulnerability repair according to the accurate target vulnerability information.
[0141] Among them, the training process of the second target large language model includes: generating a training data set based on the target vulnerability information library; inputting the training data set into the second initial large language model, the second initial large language model identifies the training question, searches for candidate answers from the target vulnerability information library, and compares the candidate answers with the training answers; if the candidate answers are inconsistent with the training answers, modifying the system prompt words corresponding to the second initial large language model, and determining the modified second initial large language model as the second target large language model; if the candidate answers are consistent with the training answers, determining the second initial large language model as the second target large language model, thereby ensuring the accuracy of the trained second target large language model.
[0142] In this embodiment, a vulnerability information retrieval device is also provided, which is used to implement the above-mentioned embodiments and preferred implementation modes, and will not be repeated here. As used below, the term "module" can be a combination of software and / or hardware that implements a predetermined function. Although the device described in the following embodiments is preferably implemented in software, the implementation of hardware, or a combination of software and hardware, is also possible and conceivable.
[0143] This embodiment provides a vulnerability information retrieval device, such as Figure 5 As shown, including:
[0144] The acquisition module 401 is used to obtain the original file of vulnerability information;
[0145] Identification module 402, used to identify the original vulnerability information file and generate a target vulnerability information library;
[0146] The retrieval module 403 is used to receive a vulnerability information retrieval instruction input by a target user, retrieve target vulnerability information from a target vulnerability information library, and output the target vulnerability information to the target user.
[0147] In some optional implementations, the identification module 402 is specifically used to identify the vulnerability information original file and determine the non-text data in the vulnerability information original file; according to the data type corresponding to the non-text data, a preset data conversion method is used to convert the non-text data into text data; based on the converted text data, a vulnerability information target file is generated; the vulnerability information target file is identified to generate a target vulnerability information library.
[0148] In some optional implementations, the identification module 402 is specifically used to input the vulnerability information target file into the first target large language model, the first target large language model identifies the vulnerability information target file, and based on the preset prompt word, queries the vulnerability information corresponding to the preset prompt word in the vulnerability information target file; based on the vulnerability information corresponding to the preset prompt word, generates a target vulnerability information library.
[0149] In some optional implementations, the preset prompt words include extraction requirements and extraction fields. The identification module 402 is specifically used to identify the preset prompt words, determine the extraction requirements and extraction fields in the preset extraction words, and query the vulnerability information corresponding to the extraction field from the vulnerability information target file according to the extraction requirements.
[0150] In some optional implementations, the identification module 402 is specifically used to fill in the vulnerability information corresponding to the extracted field into a preset position to generate an initial vulnerability information library; deduplicate and remove missing values from the vulnerability information in the initial vulnerability information library to generate a target vulnerability information library.
[0151] In some optional implementations, the retrieval module 403 is specifically used to input the vulnerability information retrieval instruction into the second target large language model, the second target large language model recognizes the vulnerability information retrieval instruction, retrieves the target vulnerability information from the target vulnerability information library, and outputs the target vulnerability information to the target user.
[0152] In some optional implementations, the retrieval module 403 is specifically used to generate a training data set based on a target vulnerability information repository; the training data set includes training questions and training answers, and the training answers exist in the target vulnerability information repository; the training data set is input into a second initial large language model, the second initial large language model identifies the training questions, and searches for candidate answers from the target vulnerability information repository; the candidate answers are compared with the training answers; if the candidate answers are inconsistent with the training answers, the system prompt words corresponding to the second initial large language model are modified, and the modified second initial large language model is determined as the second target large language model; if the candidate answers are consistent with the training answers, the second initial large language model is determined as the second target large language model.
[0153] The further functional description of each of the above modules and units is the same as that of the above corresponding embodiments and will not be repeated here.
[0154] The vulnerability information retrieval device in this embodiment is presented in the form of a functional unit, where the unit refers to an ASIC (Application Specific Integrated Circuit) circuit, a processor and memory that executes one or more software or fixed programs, and / or other devices that can provide the above functions.
[0155] The embodiment of the present invention also provides an electronic device having the above Figure 5 The vulnerability information retrieval device shown.
[0156] See also Figure 6 , Figure 6 is a schematic diagram of the structure of an electronic device provided by an optional embodiment of the present invention, such as Figure 6 As shown, the electronic device includes: one or more processors 10, a memory 20, and interfaces for connecting various components, including high-speed interfaces and low-speed interfaces. The various components are connected to each other using different buses for communication, and can be installed on a common mainboard or installed in other ways as needed. The processor can process instructions executed in the electronic device, including instructions stored in or on the memory to display graphical information of the GUI on an external input / output device (such as a display device coupled to the interface). In some optional embodiments, if necessary, multiple processors and / or multiple buses can be used together with multiple memories and multiple memories. Similarly, multiple electronic devices can be connected, and each device provides some necessary operations (for example, as a server array, a group of blade servers, or a multi-processor system). Figure 6 A processor 10 is taken as an example.
[0157] The processor 10 may be a central processing unit, a network processor or a combination thereof. The processor 10 may further include a hardware chip. The hardware chip may be a dedicated integrated circuit, a programmable logic device or a combination thereof. The programmable logic device may be a complex programmable logic device, a field programmable gate array, a general purpose array logic or any combination thereof.
[0158] The memory 20 stores instructions executable by at least one processor 10, so that at least one processor 10 executes the method shown in the above embodiment.
[0159] The memory 20 may include a program storage area and a data storage area, wherein the program storage area may store an operating system, an application required for at least one function; the data storage area may store data created according to the use of the electronic device, etc. In addition, the memory 20 may include a high-speed random access memory, and may also include a non-transient memory, such as at least one disk storage device, a flash memory device, or other non-transient solid-state storage device. In some optional embodiments, the memory 20 may optionally include a memory remotely arranged relative to the processor 10, and these remote memories may be connected to the electronic device via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0160] The memory 20 may include a volatile memory, such as a random access memory; the memory may also include a non-volatile memory, such as a flash memory, a hard disk or a solid state drive; the memory 20 may also include a combination of the above types of memory.
[0161] The electronic device further includes an input device 30 and an output device 40. The processor 10, the memory 20, the input device 30 and the output device 40 may be connected via a bus or other means. Figure 6 The example of connecting through bus is taken in the following.
[0162] The input device 30 can receive input digital or character information, and generate key signal input related to the user settings and function control of the electronic device, such as a touch screen, a keypad, a mouse, a track pad, a touch pad, an indicator rod, one or more mouse buttons, a trackball, a joystick, etc. The output device 40 may include a display device, an auxiliary lighting device (e.g., an LED) and a tactile feedback device (e.g., a vibration motor), etc. The above-mentioned display device includes but is not limited to a liquid crystal display, a light emitting diode, a display and a plasma display. In some optional embodiments, the display device can be a touch screen.
[0163] The embodiment of the present invention also provides a computer-readable storage medium. The method according to the embodiment of the present invention can be implemented in hardware, firmware, or can be implemented as a computer code that can be recorded in a storage medium, or can be implemented as a computer code that is originally stored in a remote storage medium or a non-temporary machine-readable storage medium and will be stored in a local storage medium through a network download, so that the method described herein can be stored in such software processing on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only storage memory, a random access memory, a flash memory, a hard disk or a solid-state hard disk, etc.; further, the storage medium can also include a combination of the above types of memories. It can be understood that a computer, a processor, a microprocessor controller, or programmable hardware includes a storage component that can store or receive software or computer code. When the software or computer code is accessed and executed by a computer, a processor, or hardware, the method shown in the above embodiment is implemented.
[0164] A part of the present invention may be applied as a computer program product, such as a computer program instruction, which, when executed by a computer, can call or provide the method and / or technical solution according to the present invention through the operation of the computer. Those skilled in the art should understand that the existence of the computer program instruction in a computer-readable medium includes, but is not limited to, a source file, an executable file, an installation package file, etc., and accordingly, the way in which the computer program instruction is executed by the computer includes, but is not limited to: the computer directly executes the instruction, or the computer compiles the instruction and then executes the corresponding compiled program, or the computer reads and executes the instruction, or the computer reads and installs the instruction and then executes the corresponding installed program. Here, the computer-readable medium may be any available computer-readable storage medium or communication medium accessible to the computer.
[0165] Although the embodiments of the present invention have been described in conjunction with the accompanying drawings, those skilled in the art may make various modifications and variations without departing from the spirit and scope of the present invention, and such modifications and variations are all within the scope defined by the appended claims.
Claims
1. A vulnerability information retrieval method, characterized in that: The method comprises: Get the original file of vulnerability information; Identify the original vulnerability information file and generate a target vulnerability information library; A vulnerability information retrieval instruction input by a target user is received, target vulnerability information is retrieved from the target vulnerability information library, and the target vulnerability information is output to the target user.
2. The method according to claim 1, characterized in that The identifying the original vulnerability information file and generating a target vulnerability information library includes: Identify the original file of vulnerability information and determine the non-text data in the original file of vulnerability information; According to the data type corresponding to the non-text data, a preset data conversion method is used to convert the non-text data into text data; Based on the converted text data, generating a vulnerability information target file; The vulnerability information target file is identified to generate the target vulnerability information library.
3. The method according to claim 2, characterized in that The step of identifying the vulnerability information target file and generating the target vulnerability information library includes: Inputting the vulnerability information target file into a first target large language model, the first target large language model recognizes the vulnerability information target file, and based on a preset prompt word, searches the vulnerability information target file for vulnerability information corresponding to the preset prompt word; Based on the vulnerability information corresponding to the preset prompt word, the target vulnerability information library is generated.
4. The method according to claim 3, characterized in that The preset prompt word includes extraction requirements and extraction fields. Based on the preset prompt word, the vulnerability information corresponding to the preset prompt word is searched in the vulnerability information target file, including: The preset prompt word is identified, the extraction requirement and the extraction field in the preset extraction word are determined, and according to the extraction requirement, the vulnerability information corresponding to the extraction field is queried from the vulnerability information target file.
5. The method according to claim 4, characterized in that The generating the target vulnerability information library based on the vulnerability information corresponding to the preset prompt word includes: Fill the vulnerability information corresponding to the extracted field into a preset position to generate an initial vulnerability information library; The vulnerability information in the initial vulnerability information database is deduplicated and de-missing to generate the target vulnerability information database.
6. The method according to claim 1, characterized in that The receiving a vulnerability information retrieval instruction input by a target user, retrieving target vulnerability information from the target vulnerability information library, and outputting the target vulnerability information to the target user includes: The vulnerability information retrieval instruction is input into a second target large language model, the second target large language model recognizes the vulnerability information retrieval instruction, retrieves target vulnerability information from the target vulnerability information library, and outputs the target vulnerability information to the target user.
7. The method according to claim 6, characterized in that The training process of the second target large language model includes: Based on the target vulnerability information database, a training data set is generated; the training data set includes training questions and training answers, and the training answers exist in the target vulnerability information database; Inputting the training data set into a second initial large language model, the second initial large language model identifies the training question and searches for candidate answers from the target vulnerability information database; Comparing the candidate answer with the training answer; If the candidate answer is inconsistent with the training answer, modifying the system prompt word corresponding to the second initial large language model, and determining the modified second initial large language model as the second target large language model; If the candidate answer is consistent with the training answer, the second initial large language model is determined as the second target large language model.
8. A vulnerability information retrieval device, characterized in that: The device comprises: Acquisition module, used to obtain the original file of vulnerability information; An identification module, used to identify the original vulnerability information file and generate a target vulnerability information library; The retrieval module is used to receive a vulnerability information retrieval instruction input by a target user, retrieve target vulnerability information from the target vulnerability information library, and output the target vulnerability information to the target user.
9. An electronic device, characterized in that: include: A memory and a processor, wherein the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the vulnerability information retrieval method according to any one of claims 1 to 7 by executing the computer instructions.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a computer to execute the vulnerability information retrieval method according to any one of claims 1 to 7.