Software repair processing method and device

By obtaining terminal lists, determining vulnerabilities and comparing differences levels, and performing software repairs based on these levels, the problem of inefficient software repair in enterprise information environments is solved, and more efficient software repair and enterprise information security guarantees are achieved.

CN119989352APending Publication Date: 2025-05-13INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202410693876.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-05-31
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

In an enterprise information environment, due to the diversified operating system types and numerous software versions, software repair and processing efficiency is inefficient, and some software with greater security risks cannot be repaired in time, which brings serious hidden dangers to enterprise information security.

Method used

Provide a software repair method, by obtaining terminal inventory, determining the level of vulnerability high-risk levels and comparing differences, determining warning levels based on these levels, and using delivery software packages to repair, ensuring the repair priority of associated software.

Benefits of technology

Improve the efficiency of software repair processing, ensure the security of enterprise information, and reduce the potential risks caused by software vulnerabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119989352A_ABST
    Figure CN119989352A_ABST
Patent Text Reader

Abstract

The invention provides a software repair processing method and device, relates to the technical field of intelligent operation and maintenance, and can be applied to the financial field or other technical fields. The method comprises the following steps: acquiring a terminal list; determining a vulnerability high risk level according to the target software vulnerability information of the target software corresponding to each terminal, and determining a comparison difference level according to a comparison result of a target software version of the target software corresponding to each terminal and a baseline; determining a warning level according to the vulnerability high-risk level and the comparison difference level, and repairing associated software related to the target software according to a delivered software package, a repairing time limit corresponding to the warning level and a software version installed in an operating system of each terminal. The device executes the method. According to the method and the device provided by the embodiment of the invention, the software repair processing efficiency can be improved, and the enterprise information security is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of intelligent operation and maintenance technology, and in particular to a software repair processing method and device. Background Art

[0002] With the development of enterprise informatization, a large number of terminal devices are needed, such as office computers with various operating systems. Affected by the diversity of operating system types, different security protection software is installed. By running the security protection software, the security status of the terminal can be detected. For example, some software installed on the terminal has vulnerabilities, etc. However, there are many software versions with vulnerabilities and other security issues, and the operating system types are diverse, resulting in different software repair tasks for each terminal. Relevant staff are required to repair each software in each terminal one by one, resulting in low efficiency of software repair. In addition, if there are many software that need to be repaired, some software with greater security risks cannot be repaired in time, which brings serious risks to enterprise information security. Summary of the invention

[0003] In view of the problems in the prior art, an embodiment of the present invention provides a software repair processing method and device, which can at least partially solve the problems in the prior art.

[0004] In one aspect, the present invention provides a software repair processing method, comprising:

[0005] Obtain a terminal list; each terminal in the terminal list contains target software vulnerability information of target software that does not meet the baseline requirements;

[0006] Determine the vulnerability high-risk level according to the target software vulnerability information of the target software corresponding to each terminal, and determine the comparison difference level according to the comparison result between the target software version of the target software corresponding to each terminal and the baseline;

[0007] The warning level is determined according to the vulnerability high-risk level and the comparison difference level, and the associated software related to the target software is repaired according to the delivery software package, the repair time limit corresponding to the warning level, and the software version installed in the operating system of each terminal.

[0008] Wherein, determining the vulnerability high-risk level according to the target software vulnerability information of the target software corresponding to each terminal includes:

[0009] Determine the target software vulnerability level corresponding to each target software vulnerability information according to the first preset corresponding relationship;

[0010] Wherein, the first preset corresponding relationship includes the corresponding relationship between preset software vulnerability information and preset software vulnerability level;

[0011] The sum of each target software vulnerability level is determined as the target software risk level corresponding to each target software, and the sum of each software risk level is determined as the vulnerability high-risk level.

[0012] The step of determining the comparison difference level according to the comparison result between the target software version of the target software corresponding to each terminal and the baseline includes:

[0013] Determine the comparison result level corresponding to each comparison result according to the second preset corresponding relationship;

[0014] Wherein, the second preset corresponding relationship includes a corresponding relationship between a preset comparison result and a preset comparison result level;

[0015] The sum of each comparison result level is determined as the comparison difference level.

[0016] The repairing of associated software related to the target software according to the delivered software package, the repair time limit corresponding to the warning level, and the software version installed in the operating system of each terminal includes:

[0017] Determining the associated software according to the software version and the target software within the repair time limit;

[0018] The associated software is repaired according to the software installation priority of the associated software and using the delivery software package.

[0019] Wherein, after the step of repairing the associated software related to the target software according to the delivered software package, the repair time limit corresponding to the warning level, and the software version installed in the operating system of each terminal, the software repair processing method further includes:

[0020] If it is determined that there is abnormal software that cannot be repaired, a reminder message is generated; the reminder message carries an uninstall selection confirmation item corresponding to the abnormal software.

[0021] After completing the processing action in response to the reminder message, the software repair processing method further includes:

[0022] Output the execution results of the software repair task and verify the software version;

[0023] According to the software version verification result, target software vulnerability information of target software that does not meet the baseline requirement contained in each terminal in the terminal list is updated.

[0024] The software repair processing method further includes:

[0025] The target terminal containing the software that has met all the baseline requirements is deleted from the terminal list.

[0026] In one aspect, the present invention provides a software repair processing device, comprising:

[0027] An acquisition unit, used to acquire a terminal list; each terminal in the terminal list contains target software vulnerability information of target software that does not meet the baseline requirements;

[0028] A determination unit, configured to determine a vulnerability high risk level according to target software vulnerability information of the target software corresponding to each terminal, and determine a comparison difference level according to a comparison result between a target software version of the target software corresponding to each terminal and a baseline;

[0029] A repair unit is used to determine a warning level according to the vulnerability high-risk level and the comparison difference level, and repair associated software related to the target software according to the delivery software package, the repair time limit corresponding to the warning level, and the software version installed in the operating system of each terminal.

[0030] In another aspect, an embodiment of the present invention provides an electronic device, including: a processor, a memory, and a bus, wherein:

[0031] The processor and the memory communicate with each other via the bus;

[0032] The memory stores program instructions that can be executed by the processor, and the processor calls the program instructions to execute the following method:

[0033] Obtain a terminal list; each terminal in the terminal list contains target software vulnerability information of target software that does not meet the baseline requirements;

[0034] Determine the vulnerability high-risk level according to the target software vulnerability information of the target software corresponding to each terminal, and determine the comparison difference level according to the comparison result between the target software version of the target software corresponding to each terminal and the baseline;

[0035] The warning level is determined according to the vulnerability high-risk level and the comparison difference level, and the associated software related to the target software is repaired according to the delivery software package, the repair time limit corresponding to the warning level, and the software version installed in the operating system of each terminal.

[0036] An embodiment of the present invention provides a non-transitory computer-readable storage medium, including:

[0037] The non-transitory computer-readable storage medium stores computer instructions, which cause the computer to execute the following method:

[0038] Obtain a terminal list; each terminal in the terminal list contains target software vulnerability information of target software that does not meet the baseline requirements;

[0039] Determine the vulnerability high-risk level according to the target software vulnerability information of the target software corresponding to each terminal, and determine the comparison difference level according to the comparison result between the target software version of the target software corresponding to each terminal and the baseline;

[0040] The warning level is determined according to the vulnerability high-risk level and the comparison difference level, and the associated software related to the target software is repaired according to the delivery software package, the repair time limit corresponding to the warning level, and the software version installed in the operating system of each terminal.

[0041] The software repair processing method and device provided by the embodiment of the present invention obtain a terminal list; each terminal in the terminal list contains target software vulnerability information of target software that does not meet the baseline requirements; the vulnerability high-risk level is determined according to the target software vulnerability information of the target software corresponding to each terminal, and the comparison difference level is determined according to the comparison result of the target software version of the target software corresponding to each terminal and the baseline; the warning level is determined according to the vulnerability high-risk level and the comparison difference level, and the associated software related to the target software is repaired according to the delivery software package, the repair time limit corresponding to the warning level, and the software version installed in the operating system of each terminal, which can improve the software repair processing efficiency and ensure the security of enterprise information. BRIEF DESCRIPTION OF THE DRAWINGS

[0042] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the prior art descriptions. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work. In the drawings:

[0043] Figure 1 The figure is a flowchart of a software repair processing method provided by an embodiment of the present invention.

[0044] Figure 2 It is a structural diagram of a software repair processing device provided by an embodiment of the present invention.

[0045] Figure 3 A schematic diagram of the physical structure of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0046] In order to make the purpose, technical scheme and advantages of the embodiments of the present invention more clear, the embodiments of the present invention are further described in detail below in conjunction with the accompanying drawings. Here, the illustrative embodiments of the present invention and their descriptions are used to explain the present invention, but are not intended to limit the present invention. It should be noted that, in the absence of conflict, the embodiments in this application and the features in the embodiments can be combined with each other arbitrarily.

[0047] Figure 1 FIG. 1 is a flow chart of a software repair processing method provided by an embodiment of the present invention. Figure 1 As shown, the software repair processing method provided by the embodiment of the present invention includes:

[0048] Step S1: Obtain a terminal list; each terminal in the terminal list contains target software vulnerability information of target software that does not meet the baseline requirements.

[0049] Step S2: determining the vulnerability high-risk level according to the target software vulnerability information of the target software corresponding to each terminal, and determining the comparison difference level according to the comparison result between the target software version of the target software corresponding to each terminal and the baseline.

[0050] Step S3: Determine a warning level according to the vulnerability high-risk level and the comparison difference level, and repair the associated software related to the target software according to the delivered software package, the repair time limit corresponding to the warning level, and the software version installed in the operating system of each terminal.

[0051] In the above step S1, the device obtains a terminal list; each terminal in the terminal list contains target software vulnerability information of target software that does not meet the baseline requirements. The device can be a computer device that executes the method, etc. It should be noted that the information collected in the embodiment of the present invention is information and data authorized by the user or fully authorized by all parties, and the collection, storage, use, processing, transmission, provision, disclosure and application of relevant data comply with the relevant laws, regulations and standards of relevant countries and regions, take necessary confidentiality measures, do not violate public order and good customs, and provide corresponding operation entrances for users to choose to authorize or refuse.

[0052] Provide users with corresponding operation entrances for them to choose to agree or reject the automated decision-making results; if the user chooses to reject, the expert decision-making process will be entered.

[0053] A baseline refers to a software version used as a comparison benchmark, such as the 2019 official version of a certain office software.

[0054] The log information of various terminals can be obtained. The log information includes the operating system version and software information details. The above log information is cleaned, and then the software information details corresponding to the operating system version are compared with the baseline. If there is target software that is inconsistent with the baseline, the terminals containing these target software will be added to the terminal list. Each terminal in the terminal list also contains the target software vulnerability information of these target software, and can also include the correspondence between the target software that does not meet the baseline requirements and the target software vulnerability information.

[0055] The above-mentioned various terminals may include network access control and patch distribution management clients, anti-virus clients, document security protection clients, etc.

[0056] In the above step S2, the device determines the vulnerability high-risk level according to the target software vulnerability information of the target software corresponding to each terminal, and determines the comparison difference level according to the comparison result between the target software version of the target software corresponding to each terminal and the baseline. Determining the vulnerability high-risk level according to the target software vulnerability information of the target software corresponding to each terminal includes:

[0057] Determine the target software vulnerability level corresponding to each target software vulnerability information according to the first preset corresponding relationship;

[0058] Among them, the first preset correspondence includes the correspondence between preset software vulnerability information and preset software vulnerability level; the preset software vulnerability information may include a specific preset software vulnerability name, and the preset software vulnerability level may reflect the software vulnerability level, which is recorded as A1-An. As the software vulnerability level increases successively, the software vulnerability risk degree also increases successively. A1-An can be numerically processed respectively, for example, assigned values ​​of 1-n respectively.

[0059] It can be understood that each target software vulnerability name may correspond to a target software vulnerability level, and then a numerical value (one of 1-n) may be determined.

[0060] The sum of each target software vulnerability level is determined as the target software risk level corresponding to each target software, and the sum of each software risk level is determined as the vulnerability high risk level. All target software vulnerability levels of the i-th target software are traversed, and the sum of the values ​​corresponding to all target software vulnerability levels is used as the target software risk level corresponding to the i-th target software, where i is between (1, x), and x is the total number of target software of the terminal.

[0061] The total number of target software is traversed, and the sum of the target software risk levels of the i-th target software is used as the vulnerability high-risk level corresponding to the terminal.

[0062] It can be understood that the vulnerability severity level reflects the vulnerability severity of this terminal, and the target software risk level reflects the vulnerability severity of the target software.

[0063] The determining of the comparison difference level according to the comparison result between the target software version of the target software corresponding to each terminal and the baseline includes:

[0064] Determine the comparison result level corresponding to each comparison result according to the second preset corresponding relationship;

[0065] Among them, the second preset corresponding relationship includes the corresponding relationship between the preset comparison result and the preset comparison result level; for the sake of convenience, taking the 2019 official version of the above-mentioned office software as the baseline, the preset comparison result between it and the 2018 official version of the office software is recorded as 1, and the corresponding preset comparison result level is recorded as B1, and the preset comparison result between it and the 2017 official version of the office software is recorded as 2, and the corresponding preset comparison result level is recorded as B2, and so on to obtain the preset comparison result levels B1-Bm, where m and n can be the same or different.

[0066] As the comparison result values ​​increase, the degree of difference from the benchmark also increases. B1-Bm may be numerically processed, for example, assigned values ​​of 1-m, respectively.

[0067] It can be understood that each comparison result may correspond to a comparison result level, and then a value (one of 1-m) may be determined.

[0068] The sum of the comparison result levels is determined as the comparison difference level. Referring to the above description, the ith target software corresponds to one comparison result, the total number of target software is traversed, and the sum of the comparison result levels of the ith target software is used as the comparison difference level corresponding to the terminal.

[0069] It can be understood that the comparison difference level reflects the overall comparison difference degree of all target software in this terminal relative to the baseline, and the comparison result level reflects the comparison difference degree of the target software alone relative to the baseline.

[0070] In the above step S3, the device determines the warning level according to the vulnerability high-risk level and the comparison difference level, and repairs the associated software related to the target software according to the delivered software package, the repair time limit corresponding to the warning level, and the software version installed in the operating system of each terminal. The above vulnerability high-risk level is recorded as A, and the above comparison difference level is recorded as B. The warning level is determined according to the vulnerability high-risk level and the comparison difference level, including:

[0071] The warning value T is determined according to the following expression:

[0072] T=a×A+b×B

[0073] Among them, a is the weight corresponding to the high-risk level of the vulnerability, b is the weight corresponding to the comparison difference level, and a+b=1.

[0074] If the value of T is within the first preset value interval, the warning level is determined to be an early warning.

[0075] If the value of T is within the second preset value interval, the warning level is determined to be alarm. The left endpoint value of the second preset value interval is equal to the right endpoint value of the first preset value interval.

[0076] If the value of T is within the third preset value interval, the warning level is determined to be isolation. The left endpoint value of the third preset value interval is equal to the right endpoint value of the second preset value interval. The first preset value interval, the second preset value interval and the third preset value interval can be set independently according to actual conditions.

[0077] The repair time limits corresponding to the warning levels are as follows:

[0078] The lowest level is early warning, and there is no control over the repair time limit (can be set to 1 month); the intermediate level is alarm, and the repair time limit is controlled (can be set to 1 day). If the time limit is exceeded, a weighted reminder or upgrade will be issued. Early warnings and alarms only provide reminders, and there is no network disconnection.

[0079] At the highest level, the repair time limit is strictly controlled (can be set to immediate), and the terminal is added to the isolation zone for isolation. By setting up the isolation zone, the isolation zone blocks the basic network and only allows software version and vulnerability repairs.

[0080] The delivery software package can be a patch package or software installation package provided by the software development delivery personnel. The delivery software package is a version iteration product delivered in the form of a version package by the software development delivery personnel to optimize software vulnerabilities and functions.

[0081] To ensure data security, the delivered software package can be digitally signed and encrypted and decrypted. The software development organization uses the private key of the digital signature to sign the summary information of the software version package. When the software version package is received, the public key of the digital signature will be used to verify the signature first. After the verification is passed, the software version package will be stored and managed.

[0082] Associated software related to the target software can be understood as software that may affect other software when a vulnerability occurs in the target software.

[0083] The repairing of associated software related to the target software according to the delivered software package, the repair time limit corresponding to the warning level, and the software version installed in the operating system of each terminal includes:

[0084] The associated software is determined according to the software version and the target software within the repair time limit; the knowledge graph can be used to establish an association relationship between the preset software version and the preset software, and the above association relationship can be reflected in the form of software branches, and the above association relationship can be called to sort out all branches of the software that needs to be installed or upgraded.

[0085] According to the software installation priority of the associated software, the associated software is repaired using the delivered software package. In conjunction with the software information library (including the software name), a software repair task list is generated according to the software installation priority (i.e., the front-end and back-end relationship). For example, the installation prerequisite of a business system software is that a security plug-in needs to be pre-installed. Therefore, the installation priority of a security plug-in is higher than the installation priority of a business system software. A security plug-in is the upper-level software branch of a business system software.

[0086] Traverse each software repair task in the software repair task list and repair the associated software. The administrator can also manually intervene in the generation of tasks in the software repair task list.

[0087] After the step of repairing the associated software related to the target software according to the delivered software package, the repair time limit corresponding to the warning level, and the software version installed in the operating system of each terminal, the software repair processing method further includes:

[0088] If it is determined that there is abnormal software that cannot be repaired, a reminder message is generated; the reminder message carries an uninstall selection confirmation item corresponding to the abnormal software. For abnormal software that cannot be repaired, employees can be reminded and an optional uninstall confirmation can be performed. If the employee chooses to uninstall, an uninstall task can be triggered to uninstall the software and delete the registry.

[0089] After completing the processing action in response to the reminder message, the software repair processing method further includes:

[0090] Output the execution result of the software repair task and verify the software version; the execution result of the software repair task may include the first execution result in which all the software is successfully repaired, or may include the second execution result in which part of the software is not successfully repaired. For the part of the software that is not successfully repaired in the second execution result, further manual intervention can be performed. For the other part of the software that is successfully repaired in the first execution result and the second execution result, the software version can be verified to verify whether it meets the baseline requirements.

[0091] According to the software version verification result, the target software vulnerability information of the target software that does not meet the baseline requirements contained in each terminal in the terminal list is updated. Thereafter, the same method steps as above can be continued for the target software vulnerability information of the updated target software, which will not be repeated.

[0092] The software repair processing method also includes:

[0093] The target terminal containing all the software that meets the baseline requirements is deleted from the terminal list. Referring to the above description, as the same method steps are periodically executed, more and more target software that did not meet the baseline requirements will meet the baseline requirements after being repaired. If all the software in the jth terminal meets the baseline requirements, the terminal can be used as a target terminal and deleted from the terminal list. It can be understood that as the same method steps are periodically executed and appropriate manual intervention is performed, the number of terminals in the terminal list will eventually be zero. Where j is between (1, y), and y is the total number of terminals in the terminal list.

[0094] The software repair processing method provided in the embodiment of the present invention can overcome the problems of management difficulties, low security levels, and software repair difficulties in the increasing number of operating system parallel office scenarios, and can achieve unified version baseline management, security level assessment and monitoring alarm isolation mechanism, system self-repair and notification mechanism for multiple operating systems, ensure unified security management of operating system transformation and version iteration processes, and improve the security of the office environment and management efficiency.

[0095] The software repair processing method provided by the embodiment of the present invention obtains a terminal list; each terminal in the terminal list contains target software vulnerability information of target software that does not meet the baseline requirements; the vulnerability high-risk level is determined according to the target software vulnerability information of the target software corresponding to each terminal, and the comparison difference level is determined according to the comparison result of the target software version of the target software corresponding to each terminal and the baseline; the warning level is determined according to the vulnerability high-risk level and the comparison difference level, and the associated software related to the target software is repaired according to the delivery software package, the repair time limit corresponding to the warning level, and the software version installed in the operating system of each terminal, which can improve the software repair processing efficiency and ensure the security of enterprise information.

[0096] Further, determining the vulnerability high-risk level according to the target software vulnerability information of the target software corresponding to each terminal includes:

[0097] The target software vulnerability level corresponding to each target software vulnerability information is determined according to the first preset corresponding relationship; the description may refer to the above embodiment and will not be repeated here.

[0098] Among them, the first preset corresponding relationship includes the corresponding relationship between preset software vulnerability information and preset software vulnerability level; it can be described with reference to the above embodiment and will not be repeated here.

[0099] The sum of each target software vulnerability level is determined as the target software risk level corresponding to each target software, and the sum of each software risk level is determined as the vulnerability high risk level.

[0100] The software repair processing method provided by the embodiment of the present invention can accurately determine the high-risk level of a vulnerability.

[0101] Further, the determining of the comparison difference level according to the comparison result between the target software version of the target software corresponding to each terminal and the baseline includes:

[0102] The comparison result level corresponding to each comparison result is determined according to the second preset corresponding relationship; the description may refer to the above embodiment and will not be repeated here.

[0103] The second preset corresponding relationship includes a corresponding relationship between a preset comparison result and a preset comparison result level; the above-mentioned embodiment can be referred to for description and will not be described in detail.

[0104] The sum of the levels of each comparison result is determined as the comparison difference level. The above description can be referred to in the above embodiment and will not be repeated here.

[0105] The software repair processing method provided by the embodiment of the present invention can accurately determine the comparison difference level.

[0106] Further, the repairing of associated software related to the target software according to the delivered software package, the repair time limit corresponding to the warning level, and the software version installed in the operating system of each terminal includes:

[0107] The associated software is determined according to the software version and the target software within the repair time limit; this can be described with reference to the above embodiment and will not be described in detail.

[0108] According to the software installation priority of the associated software, the associated software is repaired using the delivered software package. The above-mentioned embodiment can be referred to for description and will not be described in detail.

[0109] The software repair processing method provided by the embodiment of the present invention can repair the associated software in a reasonable order.

[0110] Furthermore, after the step of repairing the associated software related to the target software according to the delivered software package, the repair time limit corresponding to the warning level, and the software version installed in the operating system of each terminal, the software repair processing method further includes:

[0111] If it is determined that there is abnormal software that cannot be repaired, a reminder message is generated; the reminder message carries an uninstall selection confirmation item corresponding to the abnormal software. The above embodiment can be referred to for description and will not be repeated here.

[0112] The software repair processing method provided by the embodiment of the present invention can promptly hand over abnormal situations to manual processing.

[0113] Furthermore, after completing the processing action in response to the reminder message, the software repair processing method further includes:

[0114] Output the execution result of the software repair task and verify the software version; refer to the above embodiment for description and no further details will be given.

[0115] According to the software version verification result, the target software vulnerability information of the target software that does not meet the baseline requirement contained in each terminal in the terminal list is updated.

[0116] The software repair processing method provided by the embodiment of the present invention can timely update the target software vulnerability information of the target software and ensure that the software repair is carried out efficiently.

[0117] Furthermore, the software repair processing method also includes:

[0118] The target terminal containing all the software that meets the baseline requirements is deleted from the terminal list. The above embodiment can be referred to for explanation, which will not be described in detail.

[0119] The software repair processing method provided by the embodiment of the present invention helps to conveniently monitor the completion status of the software repair task in real time by dynamically updating the terminal list.

[0120] It should be noted that the software repair processing method provided in the embodiment of the present invention can be used in the financial field, and can also be used in any technical field other than the financial field. The embodiment of the present invention does not limit the application field of the software repair processing method.

[0121] Figure 2 FIG. 1 is a schematic diagram of the structure of a software repair processing device provided by an embodiment of the present invention. Figure 2 As shown, the software repair processing device provided by the embodiment of the present invention includes an acquisition unit 201, a determination unit 202 and a repair unit 203, wherein:

[0122] The acquisition unit 201 is used to obtain a terminal list; each terminal in the terminal list contains target software vulnerability information of the target software that does not meet the baseline requirements; the determination unit 202 is used to determine the vulnerability high-risk level according to the target software vulnerability information of the target software corresponding to each terminal, and determine the comparison difference level according to the comparison result of the target software version of the target software corresponding to each terminal and the baseline; the repair unit 203 is used to determine the warning level according to the vulnerability high-risk level and the comparison difference level, and repair the associated software related to the target software according to the delivery software package, the repair time limit corresponding to the warning level, and the software version installed in the operating system of each terminal.

[0123] Specifically, the acquisition unit 201 in the device is used to obtain a terminal list; each terminal in the terminal list contains target software vulnerability information of the target software that does not meet the baseline requirements; the determination unit 202 is used to determine the vulnerability high-risk level according to the target software vulnerability information of the target software corresponding to each terminal, and determine the comparison difference level according to the comparison result of the target software version of the target software corresponding to each terminal with the baseline; the repair unit 203 is used to determine the warning level according to the vulnerability high-risk level and the comparison difference level, and repair the associated software related to the target software according to the delivery software package, the repair time limit corresponding to the warning level, and the software version installed in the operating system of each terminal.

[0124] The software repair processing device provided by the embodiment of the present invention obtains a terminal list; each terminal in the terminal list contains target software vulnerability information of target software that does not meet the baseline requirements; the vulnerability high-risk level is determined according to the target software vulnerability information of the target software corresponding to each terminal, and the comparison difference level is determined according to the comparison result of the target software version of the target software corresponding to each terminal and the baseline; the warning level is determined according to the vulnerability high-risk level and the comparison difference level, and the associated software related to the target software is repaired according to the delivery software package, the repair time limit corresponding to the warning level, and the software version installed in the operating system of each terminal, which can improve the software repair processing efficiency and ensure the security of enterprise information.

[0125] Further, the determining unit 202 is specifically configured to:

[0126] Determine the target software vulnerability level corresponding to each target software vulnerability information according to the first preset corresponding relationship;

[0127] Wherein, the first preset corresponding relationship includes the corresponding relationship between preset software vulnerability information and preset software vulnerability level;

[0128] The sum of each target software vulnerability level is determined as the target software risk level corresponding to each target software, and the sum of each software risk level is determined as the vulnerability high-risk level.

[0129] The software repair processing device provided by the embodiment of the present invention can accurately determine the high-risk level of a vulnerability.

[0130] Further, the determining unit 202 is specifically configured to:

[0131] Determine the comparison result level corresponding to each comparison result according to the second preset corresponding relationship;

[0132] Wherein, the second preset corresponding relationship includes a corresponding relationship between a preset comparison result and a preset comparison result level;

[0133] The sum of each comparison result level is determined as the comparison difference level.

[0134] The software repair processing device provided by the embodiment of the present invention can accurately determine the comparison difference level.

[0135] Furthermore, the repair unit 203 is specifically used for:

[0136] Determining the associated software according to the software version and the target software within the repair time limit;

[0137] The associated software is repaired according to the software installation priority of the associated software and using the delivery software package.

[0138] The software repair processing device provided by the embodiment of the present invention can repair the associated software in a reasonable order.

[0139] Further, after the step of repairing the associated software related to the target software according to the delivered software package, the repair time limit corresponding to the warning level, and the software version installed in the operating system of each terminal, the software repair processing device is further used to:

[0140] If it is determined that there is abnormal software that cannot be repaired, a reminder message is generated; the reminder message carries an uninstall selection confirmation item corresponding to the abnormal software.

[0141] The software repair processing device provided by the embodiment of the present invention can promptly hand over abnormal situations to manual processing.

[0142] Further, after completing the processing action in response to the reminder message, the software repair processing device is also used to:

[0143] Output the execution results of the software repair task and verify the software version;

[0144] According to the software version verification result, target software vulnerability information of target software that does not meet the baseline requirement contained in each terminal in the terminal list is updated.

[0145] The software repair processing device provided by the embodiment of the present invention can timely update the target software vulnerability information of the target software, thereby ensuring that the software repair is carried out efficiently.

[0146] Furthermore, the software repair processing device is also used for:

[0147] The target terminal containing the software that has met all the baseline requirements is deleted from the terminal list.

[0148] The software repair processing device provided by the embodiment of the present invention helps to conveniently monitor the completion status of the software repair task in real time by dynamically updating the terminal list.

[0149] The software repair processing device provided in the embodiment of the present invention can be specifically used to execute the processing flow of the above-mentioned method embodiments. Its functions are not described in detail here, and reference can be made to the detailed description of the above-mentioned method embodiments.

[0150] Figure 3 A schematic diagram of the physical structure of an electronic device provided in an embodiment of the present invention, such as Figure 3 As shown, the electronic device includes: a processor (processor) 301, a memory (memory) 302 and a bus 303;

[0151] The processor 301 and the memory 302 communicate with each other via a bus 303;

[0152] The processor 301 is used to call the program instructions in the memory 302 to execute the methods provided by the above method embodiments, for example, including:

[0153] Obtain a terminal list; each terminal in the terminal list contains target software vulnerability information of target software that does not meet the baseline requirements;

[0154] Determine the vulnerability high-risk level according to the target software vulnerability information of the target software corresponding to each terminal, and determine the comparison difference level according to the comparison result between the target software version of the target software corresponding to each terminal and the baseline;

[0155] The warning level is determined according to the vulnerability high-risk level and the comparison difference level, and the associated software related to the target software is repaired according to the delivery software package, the repair time limit corresponding to the warning level, and the software version installed in the operating system of each terminal.

[0156] This embodiment discloses a computer program product, which includes a computer program stored on a non-transitory computer-readable storage medium. The computer program includes program instructions. When the program instructions are executed by a computer, the computer can perform the methods provided by the above method embodiments, for example, including:

[0157] Obtain a terminal list; each terminal in the terminal list contains target software vulnerability information of target software that does not meet the baseline requirements;

[0158] Determine the vulnerability high-risk level according to the target software vulnerability information of the target software corresponding to each terminal, and determine the comparison difference level according to the comparison result between the target software version of the target software corresponding to each terminal and the baseline;

[0159] The warning level is determined according to the vulnerability high-risk level and the comparison difference level, and the associated software related to the target software is repaired according to the delivery software package, the repair time limit corresponding to the warning level, and the software version installed in the operating system of each terminal.

[0160] This embodiment provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, wherein the computer program enables the computer to execute the methods provided by the above method embodiments, for example, including:

[0161] Obtain a terminal list; each terminal in the terminal list contains target software vulnerability information of target software that does not meet the baseline requirements;

[0162] Determine the vulnerability high-risk level according to the target software vulnerability information of the target software corresponding to each terminal, and determine the comparison difference level according to the comparison result between the target software version of the target software corresponding to each terminal and the baseline;

[0163] The warning level is determined according to the vulnerability high-risk level and the comparison difference level, and the associated software related to the target software is repaired according to the delivery software package, the repair time limit corresponding to the warning level, and the software version installed in the operating system of each terminal.

[0164] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, systems, or computer program products. Therefore, the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0165] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0166] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.

[0167] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.

[0168] In the description of this specification, the description with reference to the terms "one embodiment", "a specific embodiment", "some embodiments", "for example", "example", "specific example", or "some examples" means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representation of the above terms does not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described may be combined in any one or more embodiments or examples in a suitable manner.

[0169] The specific embodiments described above further illustrate the objectives, technical solutions and beneficial effects of the present invention in detail. It should be understood that the above description is only a specific embodiment of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.

Claims

1. A software repair processing method, characterized in that: include: Get the terminal list; Each terminal in the terminal list includes target software vulnerability information of target software that does not meet the baseline requirements; Determine the vulnerability high-risk level according to the target software vulnerability information of the target software corresponding to each terminal, and determine the comparison difference level according to the comparison result between the target software version of the target software corresponding to each terminal and the baseline; The warning level is determined according to the vulnerability high-risk level and the comparison difference level, and the associated software related to the target software is repaired according to the delivery software package, the repair time limit corresponding to the warning level, and the software version installed in the operating system of each terminal.

2. The software repair processing method according to claim 1, characterized in that: Determining the vulnerability high-risk level according to the target software vulnerability information of the target software corresponding to each terminal includes: Determine the target software vulnerability level corresponding to each target software vulnerability information according to the first preset corresponding relationship; Wherein, the first preset corresponding relationship includes the corresponding relationship between preset software vulnerability information and preset software vulnerability level; The sum of each target software vulnerability level is determined as the target software risk level corresponding to each target software, and the sum of each software risk level is determined as the vulnerability high-risk level.

3. The software repair processing method according to claim 1, characterized in that: The determining of the comparison difference level according to the comparison result between the target software version of the target software corresponding to each terminal and the baseline includes: Determine the comparison result level corresponding to each comparison result according to the second preset corresponding relationship; Wherein, the second preset corresponding relationship includes a corresponding relationship between a preset comparison result and a preset comparison result level; The sum of each comparison result level is determined as the comparison difference level.

4. The software repair processing method according to claim 1, characterized in that: The repairing of associated software related to the target software according to the delivered software package, the repair time limit corresponding to the warning level, and the software version installed in the operating system of each terminal includes: Determining the associated software according to the software version and the target software within the repair time limit; The associated software is repaired according to the software installation priority of the associated software and using the delivery software package.

5. The software repair processing method according to any one of claims 1 to 4, characterized in that: After the step of repairing the associated software related to the target software according to the delivered software package, the repair time limit corresponding to the warning level, and the software version installed in the operating system of each terminal, the software repair processing method further includes: If it is determined that there is abnormal software that cannot be repaired, a reminder message is generated; the reminder message carries an uninstall selection confirmation item corresponding to the abnormal software.

6. The software repair processing method according to claim 5, characterized in that: After completing the processing action in response to the reminder message, the software repair processing method further includes: Output the execution results of the software repair task and verify the software version; According to the software version verification result, target software vulnerability information of target software that does not meet the baseline requirement contained in each terminal in the terminal list is updated.

7. The software repair processing method according to claim 6, characterized in that: The software repair processing method also includes: The target terminal containing the software that has met all the baseline requirements is deleted from the terminal list.

8. A software repair processing device, characterized in that: include: An acquisition unit, used for acquiring a terminal list; Each terminal in the terminal list includes target software vulnerability information of target software that does not meet the baseline requirements; A determination unit, configured to determine a vulnerability high risk level according to target software vulnerability information of the target software corresponding to each terminal, and determine a comparison difference level according to a comparison result between a target software version of the target software corresponding to each terminal and a baseline; A repair unit is used to determine a warning level according to the vulnerability high-risk level and the comparison difference level, and repair associated software related to the target software according to the delivery software package, the repair time limit corresponding to the warning level, and the software version installed in the operating system of each terminal.

9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.

Citation Information

Patent Citations

  • Software vulnerability detection method and device, and storage medium

    CN111797402A

  • Cluster vulnerability detection and repair method and device

    CN117494138A

  • Vulnerability repairing method and device, equipment and storage medium

    CN117668853A