Vulnerability evaluation processing method and device, equipment and medium

By using linear regression and random forest models in the network risk assessment system to adjust the weight of the vulnerability evaluation formula, and combining the SOAR target script for vulnerability merge and work ticket distribution, the problems of the availability of vulnerability evaluation results and the efficiency of work ticket distribution are solved, and more efficient vulnerability evaluation and processing are achieved.

CN119989361APending Publication Date: 2025-05-13BEIJING YOUTEJIE INFORMATION TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510062447.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-15
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

The vulnerability assessment results of existing network risk assessment systems are poorly available, and the work order distribution efficiency generated by vulnerability assessment results is low.

Method used

The initial feature weight of the vulnerability evaluation equation is determined based on the vulnerability sample data and the linear regression model to be analyzed, and the weights are fine-tuned based on the random forest model to be analyzed to generate the vulnerability evaluation target equation. Then, obtain the SOAR target script and merge the vulnerability with the work order according to the script and the target formula.

Benefits of technology

It improves the application effect of vulnerability assessment results and the efficiency of work order distribution, and solves the problems of poor availability of vulnerability assessment results and low efficiency of work order distribution.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119989361A_ABST
    Figure CN119989361A_ABST
Patent Text Reader

Abstract

The invention discloses a vulnerability assessment processing method and device, equipment and a medium. The vulnerability assessment processing method comprises the steps of determining a feature initial weight of a vulnerability assessment equation according to vulnerability sample data to be analyzed and a linear regression model, and performing fine adjustment on the feature initial weight based on a random forest model to obtain a feature stable weight; generating a vulnerability assessment target equation according to the feature stability weight and a vulnerability assessment equation; and obtaining an SOAR target script, and performing vulnerability merging and work order distribution according to the SOAR target script and the vulnerability assessment target equation. According to the technical scheme provided by the embodiment of the invention, the application effect of the vulnerability evaluation result and the distribution efficiency of the work order generated by the vulnerability evaluation result can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a vulnerability assessment processing method, device, equipment and medium. Background Art

[0002] Vulnerability risk assessment is a key part of cybersecurity, helping companies or organizations determine which security vulnerabilities need attention and repair. An effective vulnerability risk assessment system can help security teams with limited resources focus their efforts on the vulnerabilities that are most likely to be exploited and have the greatest impact.

[0003] Assessing vulnerabilities through traditional network risk assessment systems and repairing them in sequence cannot truly reflect the actual security situation of the business environment, resulting in poor availability of comprehensive vulnerability assessment results. In addition, work orders generated by comprehensive vulnerability assessment results are mainly issued manually, which results in low efficiency and time-consuming work order issuance. Summary of the invention

[0004] The present invention provides a vulnerability assessment processing method, device, equipment and medium to solve the problems of poor availability of vulnerability assessment results of current network risk assessment systems and low efficiency in dispatching work orders generated by vulnerability assessment results.

[0005] According to one aspect of the present invention, a vulnerability assessment processing method is provided, comprising:

[0006] According to the vulnerability sample data to be analyzed and the linear regression model, the initial feature weights of the vulnerability assessment formula are determined, and the initial feature weights are fine-tuned based on the random forest model to obtain stable feature weights;

[0007] Generate a vulnerability assessment target formula based on the feature stability weight and vulnerability assessment formula;

[0008] Obtain the SOAR target script, and merge vulnerabilities and distribute work orders based on the SOAR target script and vulnerability assessment target formula.

[0009] According to another aspect of the present invention, there is provided a vulnerability assessment processing device, comprising:

[0010] The feature weight determination module is used to determine the initial feature weights of the vulnerability assessment formula based on the vulnerability sample data to be analyzed and the linear regression model, and to fine-tune the initial feature weights based on the random forest model to obtain stable feature weights;

[0011] A vulnerability assessment target formula generation module is used to generate a vulnerability assessment target formula based on feature stability weights and a vulnerability assessment formula;

[0012] The vulnerability assessment processing module is used to obtain the SOAR target script and merge vulnerabilities and distribute work orders based on the SOAR target script and the vulnerability assessment target formula.

[0013] According to another aspect of the present invention, there is provided an electronic device, the electronic device comprising:

[0014] at least one processor; and

[0015] a memory communicatively connected to the at least one processor; wherein,

[0016] The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the vulnerability assessment processing method described in any embodiment of the present invention.

[0017] According to another aspect of the present invention, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the vulnerability assessment processing method described in any embodiment of the present invention when executed.

[0018] The technical solution of the embodiment of the present invention determines the feature initial weight of the vulnerability assessment formula according to the vulnerability sample data to be analyzed and the linear regression model, and fine-tunes the feature initial weight based on the random forest model to obtain the feature stable weight, thereby generating the vulnerability assessment target formula according to the feature stable weight and the vulnerability assessment formula, and then obtaining the SOAR target script, and performing vulnerability merging and work order distribution according to the SOAR target script and the vulnerability assessment target formula. In this solution, the linear regression model and the random forest model can be used to configure the weight of the vulnerability assessment formula, so as to evaluate the threat level of the vulnerability corresponding to the dynamically changing vulnerability business data through the vulnerability assessment target formula after the weight configuration. Unlike the machine learning method, it is not necessary to retrain the data according to the data change, and the SOAR target script is used to automatically merge the vulnerabilities in the business, and generate a work order to notify the operation and maintenance personnel to perform maintenance, which solves the problem of poor availability of the vulnerability assessment results of the current network risk assessment system and the low efficiency of distributing the work orders generated by the vulnerability assessment results, and can improve the application effect of the vulnerability assessment results and the distribution efficiency of the work orders generated by the vulnerability assessment results.

[0019] It should be understood that the contents described in this section are not intended to identify the key or important features of the embodiments of the present invention, nor are they intended to limit the scope of the present invention. Other features of the present invention will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention. For ordinary technicians in this field, other accompanying drawings can be obtained based on these accompanying drawings without paying creative work.

[0021] Figure 1 A flowchart of a vulnerability assessment processing method provided in Embodiment 1 of the present invention;

[0022] Figure 2 A flowchart of a vulnerability assessment processing method provided in Embodiment 2 of the present invention;

[0023] Figure 3 A schematic diagram of the execution logic of a SOAR target script provided in the third embodiment of the present invention;

[0024] Figure 4 A repair time comparison bar graph provided in the third embodiment of the present invention;

[0025] Figure 5 A vulnerability repair time prediction diagram provided by the third embodiment of the present invention;

[0026] Figure 6 A schematic diagram of the structure of a vulnerability assessment processing device provided in Embodiment 4 of the present invention;

[0027] Figure 7 A schematic diagram of the structure of an electronic device that can be used to implement an embodiment of the present invention is shown. DETAILED DESCRIPTION

[0028] In order to enable those skilled in the art to better understand the scheme of the present invention, the technical scheme in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present invention.

[0029] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units that are clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0030] Embodiment 1

[0031] Figure 1 This is a flowchart of a vulnerability assessment processing method provided in the first embodiment of the present invention. This embodiment is applicable to vulnerability risk assessment in a constantly changing vulnerability environment. The method can be executed by a vulnerability assessment processing device. The vulnerability assessment processing device can be implemented in the form of hardware and / or software. The vulnerability assessment processing device can be configured in an electronic device. Figure 1 As shown, the method includes:

[0032] Step 110: Determine the initial feature weights of the vulnerability assessment formula based on the vulnerability sample data to be analyzed and the linear regression model, and fine-tune the initial feature weights based on the random forest model to obtain stable feature weights.

[0033] The vulnerability sample data to be analyzed may be business sample data in a vulnerability environment. The vulnerability assessment formula may be a summation formula of preconfigured vulnerability scoring items. The feature initial weight may be a weight coefficient initially determined for a preconfigured vulnerability scoring item in the vulnerability assessment formula.

[0034] In an embodiment of the present invention, a vulnerability assessment formula can be first obtained, and then a linear regression model can be trained based on each sample data in the vulnerability sample data to be analyzed to obtain the initial feature weights of the vulnerability assessment formula, and then each sample data in the vulnerability sample data to be analyzed can be input into a random forest model to fine-tune the initial feature weights through the random forest model to obtain stable feature weights.

[0035] Step 120: Generate a vulnerability assessment target formula based on the feature stability weight and the vulnerability assessment formula.

[0036] The vulnerability assessment target formula may be a weighted formula of a feature stability weight and a corresponding preconfigured vulnerability scoring item in the vulnerability assessment formula.

[0037] In an embodiment of the present invention, the feature stabilization weight is weighted with the corresponding preconfigured vulnerability scoring item in the vulnerability assessment formula to obtain a vulnerability assessment target formula.

[0038] Step 130: Obtain the SOAR target script, and merge vulnerabilities and distribute work orders according to the SOAR target script and the vulnerability assessment target formula.

[0039] Among them, the SOAR target script can be a script for automating vulnerability merging and work order distribution.

[0040] In an embodiment of the present invention, a SOAR (Security Orchestration, Automation and Response) target script can be obtained, and then vulnerability data occurring during business execution can be obtained based on the SOAR target script, and the vulnerability score corresponding to the vulnerability data can be calculated based on the vulnerability assessment target formula, so that vulnerabilities can be merged according to the vulnerability score corresponding to the vulnerability data and the relevant information of the affected assets, and a vulnerability repair work order can be generated to send the vulnerability repair work order to the corresponding person in charge.

[0041] The technical solution of the embodiment of the present invention determines the feature initial weight of the vulnerability assessment formula according to the vulnerability sample data to be analyzed and the linear regression model, and fine-tunes the feature initial weight based on the random forest model to obtain the feature stable weight, thereby generating the vulnerability assessment target formula according to the feature stable weight and the vulnerability assessment formula, and then obtaining the SOAR target script, and performing vulnerability merging and work order distribution according to the SOAR target script and the vulnerability assessment target formula. In this solution, the linear regression model and the random forest model can be used to configure the weight of the vulnerability assessment formula, so as to evaluate the threat level of the vulnerability corresponding to the dynamically changing vulnerability business data through the vulnerability assessment target formula after the weight configuration. Unlike the machine learning method, it is not necessary to retrain the data according to the data change, and the SOAR target script is used to automatically merge the vulnerabilities in the business, and generate a work order to notify the operation and maintenance personnel to perform maintenance, which solves the problem of poor availability of the vulnerability assessment results of the current network risk assessment system and the low efficiency of distributing the work orders generated by the vulnerability assessment results, and can improve the application effect of the vulnerability assessment results and the distribution efficiency of the work orders generated by the vulnerability assessment results.

[0042] Embodiment 2

[0043] Figure 2 This is a flowchart of a vulnerability assessment processing method provided in the second embodiment of the present invention. This embodiment is specific based on the above embodiment and provides a specific optional implementation method for determining the feature initial weights of the vulnerability assessment formula based on the vulnerability sample data to be analyzed and the linear regression model. Figure 2As shown, the method includes:

[0044] Step 210: Determine the vulnerability assessment dimension, and obtain a vulnerability assessment formula constructed based on the vulnerability assessment dimension.

[0045] The vulnerability assessment dimensions may be pre-set dimensions for vulnerability scoring, and may include a common vulnerability disclosure severity score, a common vulnerability scoring system score, a vulnerability exploitability score, an asset dimension comprehensive score, and an asset importance score.

[0046] Among them, the vulnerability disclosure severity score can be a dimension for vulnerability assessment based on CVE (Common Vulnerabilities & Exposures) data. The common vulnerability scoring system score can be a dimension for vulnerability assessment based on NVD (National Vulnerability Database). The vulnerability exploitation likelihood score can be a dimension for vulnerability assessment based on the likelihood of vulnerability exploitation. The asset dimension comprehensive score can be a dimension for vulnerability assessment based on multiple asset attributes. The asset dimension comprehensive score can be a comprehensive score given from the importance of the asset, the region where the asset is located, and the business system to which the asset belongs. The asset importance score can be a dimension for vulnerability assessment based on the importance of the asset.

[0047] In an embodiment of the present invention, the vulnerability assessment dimensions that affect the real security of the business environment may be determined first, and then a vulnerability assessment formula constructed based on the vulnerability assessment dimensions may be obtained.

[0048] In an optional embodiment of the present invention, obtaining a vulnerability assessment formula constructed based on the vulnerability assessment dimension may include: constructing the following vulnerability assessment formula: Y = R score +EPSS score +Percentile score +CIA score +Assets score .

[0049] Among them, Y represents the comprehensive score of vulnerability assessment; R score EPSS stands for Common Vulnerability Exposure Severity Score score Indicates the Common Vulnerability Scoring System score; Percentile score Indicates the likelihood of vulnerability being exploited; CIA score Indicates the comprehensive score of asset dimension; Assets score Represents the asset importance score. score 、EPSS score 、Percentile score , CIAscore and Assets score It can be understood as a pre-configured vulnerability scoring item.

[0050] Step 220: Determine the initial weights of the features of the vulnerability assessment formula based on the vulnerability sample data to be analyzed and the linear regression model, and fine-tune the initial weights of the features based on the random forest model to obtain stable weights of the features.

[0051] Step 230: Generate a vulnerability assessment target formula based on the feature stability weight and the vulnerability assessment formula.

[0052] Step 240: Obtain the SOAR target script, and merge vulnerabilities and distribute work orders according to the SOAR target script and the vulnerability assessment target formula.

[0053] In an optional embodiment of the present invention, vulnerability merging and work order distribution are performed according to the SOAR target script and the vulnerability assessment target formula, which may include: determining the vulnerability priority assessment results of each security vulnerability to be processed according to the vulnerability assessment target formula; based on the SOAR target script, according to the vulnerability priority assessment results of each security vulnerability to be processed, extracting the target security vulnerability and obtaining the asset information affected by the vulnerability; based on the vulnerability impact asset information and the asset information completeness judgment condition, merging the target security vulnerabilities, and reporting the created merged vulnerability reporting work order.

[0054] Among them, the pending security vulnerability can be a vulnerability that has appeared and been identified during the execution of the business. The vulnerability priority assessment result can be used to indicate the maintenance priority of the vulnerability. The target security vulnerability can be a pending security vulnerability to be merged and processed. The vulnerability-affected asset information can be the asset information of the asset affected by the target security vulnerability. The asset information completeness judgment condition can be used to determine whether the asset information can be associated with the corresponding person in charge of the asset. The merged vulnerability reporting work order can be a work order for the operation and maintenance of the merged vulnerability.

[0055] In an embodiment of the present invention, based on the SOAR target script, the vulnerability data currently appearing and identified during business execution can be obtained, so as to determine the security vulnerabilities to be processed based on the obtained vulnerability data, and then use the vulnerability assessment dimension to query the corresponding score of the pre-configured vulnerability scoring item of the security vulnerabilities to be processed, and then substitute it into the vulnerability assessment target formula to calculate the vulnerability priority assessment result of the security vulnerabilities to be processed, and further based on the SOAR target script, according to the vulnerability priority assessment results of each security vulnerability to be processed, the security vulnerabilities to be processed are screened and extracted to obtain the target security vulnerabilities, so as to query the vulnerability-affected asset information of the target security vulnerabilities, and further use the asset information completeness judgment condition to judge whether the asset information of the asset information affected by the vulnerability is complete, so as to merge the target security vulnerabilities with complete asset information and the target vulnerabilities with incomplete asset information respectively, and then generate a merged vulnerability reporting work order based on the associated data of the merged vulnerabilities, and send the merged vulnerability reporting work order to the corresponding person in charge.

[0056] In an optional embodiment of the present invention, based on the vulnerability impact asset information and asset information completeness judgment conditions, target security vulnerabilities are merged, which may include: when it is judged based on the asset information completeness judgment condition that the vulnerability impact asset information is complete, the target security vulnerabilities are merged based on the current first task name; when it is judged based on the asset information completeness judgment condition that the vulnerability impact asset information is incomplete, the target security vulnerabilities are merged based on the current second task name.

[0057] The current first task name may be the first task name created when the information about the asset information affected by the current vulnerability is complete. The first task name may include asset information and asset manager information, and the current second task name may be the second task name created when the information about the asset information affected by the current vulnerability is incomplete. The second task name may include asset missing vulnerability information and asset manager information. The asset manager information may be the contact information of the person in charge of the asset.

[0058] In an embodiment of the present invention, it is possible to determine whether the information content of the asset information affected by the vulnerability is complete based on the asset information completeness judgment condition. If the asset information of the asset information affected by the vulnerability contains asset manager information, it can be determined that the asset information affected by the vulnerability is complete, and then based on the first task name format, a current first task name corresponding to the asset information affected by the vulnerability is created, and the target security vulnerabilities are merged according to the current first task name. If the asset information of the asset information affected by the vulnerability lacks asset manager information, it can be determined that the asset information affected by the vulnerability is incomplete, and then the current task name is created based on the second task name, and the target security vulnerabilities are merged according to the current second task name.

[0059] In an optional embodiment of the present invention, merging target security vulnerabilities based on the current first task name may include: when the current first task name exists in the created first task name, merging the target security vulnerabilities according to the created first task name; merging target security vulnerabilities based on the current second task name may include: when the current second task name exists in the created second task name, merging the target security vulnerabilities according to the created second task name.

[0060] The created first task name may be a historical first task name. The created second task name may be a historical second task name. The creation rule of each first task name in the created first task names is the same as the creation rule of the current first task name. The creation rule of each second task name in the created second task names is the same as the creation rule of the current second task name.

[0061] In an embodiment of the present invention, the name of the created first task and the name of the created second task can be obtained to determine whether the current first task name exists in the created first task name. When it is determined that the current first task name exists in the created first task name, the security vulnerabilities corresponding to the task names in the created first task names that are identical to the current first task name are merged with the target security vulnerabilities. It can also be determined whether the previous second task name exists in the created second task name. When it is determined that the current second task name exists in the created second task name, the security vulnerabilities corresponding to the task names in the created second task names that are identical to the current second task name are merged with the target security vulnerabilities.

[0062] In an optional embodiment of the present invention, after vulnerability merging and work order dispatching according to the SOAR target script and the vulnerability assessment target formula, any of the following items may also be included: determining the vulnerability repair time of the security vulnerability to be analyzed, and drawing a repair time comparison bar chart based on the vulnerability repair time of the security vulnerability to be analyzed; drawing an asset grouping analysis scatter plot based on the target-associated data to be analyzed and the asset-level grouping data of the security vulnerability to be analyzed; and, based on the Bayesian algorithm and the security vulnerability to be analyzed, drawing a vulnerability repair time prediction chart.

[0063] Among them, the security vulnerability to be analyzed may be a security vulnerability that requires repair performance evaluation. The repair time comparison bar chart may be a bar chart comparing the mean and median of the repair time of the security vulnerability to be analyzed. The target-related data to be analyzed may be data describing the vulnerability repair and impact of the security vulnerability to be analyzed. The target-related data to be analyzed may include but is not limited to at least one of the vulnerability type, repair time, and business impact. The asset level grouping data can be used to describe the results of grouping assets according to their importance. The asset grouping analysis scatter plot may be a cluster analysis diagram of vulnerability processing of grouped assets. The vulnerability repair time prediction graph may be a curve graph describing the estimated repair time of the vulnerability.

[0064] Specifically, after the vulnerability merging and the work order dispatching, any of the following items can also be executed: obtain the security vulnerabilities to be analyzed, and determine the actual vulnerability repair time of the security vulnerabilities to be analyzed, thereby calculating the average repair time and the median repair time based on the actual vulnerability repair time of each vulnerability in the security vulnerabilities to be analyzed, and draw a repair time comparison bar chart based on the average repair time and the median repair time; query the target-associated data to be analyzed of the security vulnerabilities to be analyzed, and the asset-level grouping data of the assets corresponding to the security vulnerabilities to be analyzed, thereby using the target-associated data to be analyzed of the security vulnerabilities to be analyzed and the asset-level grouping data to draw an asset grouping analysis scatter plot from three dimensions of vulnerability repair time, asset level and vulnerability score; and determine the vulnerability repair time of the security vulnerabilities to be analyzed, and the preset normal distribution curve of the security vulnerabilities to be analyzed, thereby based on the Bayesian algorithm, predicting the probability and time of future vulnerability repairs through the vulnerability repair time of the security vulnerabilities to be analyzed and the preset normal distribution curve, and generating a vulnerability repair time prediction chart.

[0065] The technical solution of the embodiment of the present invention determines the vulnerability assessment dimension and obtains the vulnerability assessment formula constructed based on the vulnerability assessment dimension, thereby determining the feature initial weights of the vulnerability assessment formula according to the vulnerability sample data to be analyzed and the linear regression model, and fine-tunes the feature initial weights based on the random forest model to obtain the feature stable weights, and then generates the vulnerability assessment target formula according to the feature stable weights and the vulnerability assessment formula, further obtains the SOAR target script, and performs vulnerability merging and work order dispatching according to the SOAR target script and the vulnerability assessment target formula.

[0066] In this solution, linear regression models and random forest models can be used to configure weights for the vulnerability assessment formula, so that the threat level of the vulnerability corresponding to the dynamically changing vulnerability business data can be evaluated through the vulnerability assessment target formula after weight configuration. Unlike the machine learning method, there is no need to retrain the data according to data changes, and the SOAR target script can be used to automatically merge the vulnerabilities in the business and generate work orders to notify the operation and maintenance personnel to perform maintenance. This solves the problems of poor availability of vulnerability assessment results in the current network risk assessment system and low efficiency in issuing work orders generated by vulnerability assessment results, and can improve the application effect of vulnerability assessment results and the efficiency in issuing work orders generated by vulnerability assessment results.

[0067] Embodiment 3

[0068] Embodiment 3 of the present invention provides an optional embodiment of a vulnerability assessment method, and its specific implementation can be found in the following embodiments. Among them, technical terms that are the same as or corresponding to the above embodiments are not repeated here.

[0069] In a specific example, we can first collect the data of all the vulnerabilities CVE in a certain business scenario, including CVE number, CVSS score, and CVE severity, and then collect the EPSS (predictive scoring system) score of each CVE, and collect asset-related data, including asset importance, CIA (confidentiality, integrity, availability) score of the area where the asset is located, and CIA score of the business system to which the asset belongs. The data sources involved may include: NVD (National Vulnerability Database, comprehensive vulnerability database) official website full CVE data, EPSS official website daily updated CSV format file, Logeasy SIEM (Security Information Event Management, security information and event management platform) platform asset management, etc. The features of the above-mentioned collected data are extracted and normalized into standard fields (EPSS score, vulnerability disclosure severity, whether it is an important asset, etc.), and the vulnerability sample data to be analyzed is obtained.

[0070] The data on NVD may not be updated very frequently, but EPSS data will be updated every day. If only machine learning is used for scoring, the dynamic nature of EPSS cannot be reflected in the model unless the model is retrained every day. Since the vulnerability assessment target formula is fixed and the data is dynamic, the score can be regenerated based on the daily data. The vulnerability threat score can be performed on the vulnerability sample data to be analyzed by technicians or preset score mapping rules, and the vulnerability assessment formula can be preliminarily constructed. Use the linear regression model to input each row of training data of the vulnerability sample data to be analyzed into the model, calculate the weight of each variable in the formula, and obtain the initial weight of the feature. Since the weight factor of the preliminary assessment is not stable enough, the weight of each feature is further optimized through the random forest model, and then fine-tuned to finally obtain a relatively stable weight factor, that is, the feature stable weight.

[0071] The linear regression model is a linear relationship model between features and target variables. In the linear regression model, it is assumed that there is a linear relationship between the input features and the output results, and the weight of the feature is determined by minimizing the error between the predicted value and the true value. This algorithm is used in this solution to obtain the preliminary weight of each feature. The random forest model is a supervised ensemble learning algorithm based on decision trees. It learns multiple estimators through training and combines the results of multiple estimators to obtain the final prediction value, that is, the final weight of each feature.

[0072] The random forest model uses the extraction and replacement algorithm to extract n samples from the vulnerability sample data to be analyzed to generate a decision tree, and generates nodes of the decision tree by extracting d features from the samples, and repeating these two steps to generate k decision numbers. Each decision tree will output an answer, which will be averaged by using a combiner to generate the final answer by averaging the answers of multiple decision trees. The random forest model can evaluate the importance of features, and calculate the average weight of each feature by averaging the contribution of each feature to each tree (Gini index or out-of-bag error rate), so as to determine which features have a higher weight ratio. This solution uses random forests to obtain the weight ratio of features, and fine-tune the weight factor in the vulnerability assessment formula based on the weight ratio. This stage may be repeated many times to obtain a relatively stable scoring formula.

[0073] Optionally, after the weight factor of the vulnerability assessment formula is debugged, the vulnerability assessment target formula is used to score the test data. The score column is displayed, and the default minimum score is 2.0196 points. The final associated display data may include CVE number, device IP (Internet Protocol) address, asset importance, asset location, risk level, CIA score, and score results.

[0074] Figure 3 This is a schematic diagram of the execution logic of a SOAR target script provided in the third embodiment of the present invention. Figure 3 As shown, the SOAR target script can execute the following logic regularly (such as once a day): incrementally obtain the vulnerabilities in the vulnerability center of the LogEasy SIEM platform with medium, high, and severe vulnerability priority scores, that is, obtain the security vulnerabilities to be analyzed, and query the asset information affected by the vulnerabilities in the asset management of the LogEasy SIEM platform through the asset IP affected by the security vulnerabilities to be analyzed, and then determine whether the asset information affected by the vulnerabilities is complete. If it can be associated with the corresponding person in charge, the security vulnerability to be analyzed will be marked as the vulnerability affecting the asset information is complete. Otherwise, it will be marked as the vulnerability affecting the asset information is incomplete. Vulnerabilities with complete vulnerability affecting asset information will first determine whether there is an identical first task name that has been created. Because the first task name is named in the form of (asset IP + person in charge name), it can be judged as long as there is a match in the task management center of the LogEasy SIEM platform to see if there is an identical first task name. If there is no identical first task name, the security vulnerabilities to be analyzed and related information (vulnerability priority score, affected assets, vulnerability ID, etc.) will be uniformly output to a table, and a new task will be created based on the table, that is, the two dimensions of assets affected by the vulnerabilities and asset managers in the table will be merged, and then all merged vulnerabilities will be associated with the created new task, that is, the task will be updated, so as to generate a new work order based on the merged vulnerabilities; otherwise, the vulnerability will be updated into the existing task, that is, the task will be merged.

[0075] The same logic applies to the branch of incomplete asset information due to vulnerability impact, but because the person in charge of the asset is missing, the second task name will be different, and the task should be assigned to the corresponding asset sorter for unified allocation. Therefore, the creation and update of tasks are unified with a name (missing asset vulnerability + asset sorter name). After completing the task update or task merger, the vulnerability score of the security vulnerability to be analyzed is calculated based on the vulnerability assessment target formula, and the field value of the vulnerability custom field is changed based on the calculated score.

[0076] After the security vulnerabilities to be analyzed are prioritized according to the scores calculated by the vulnerability assessment target formula, the vulnerability data is intuitively displayed in the following forms:

[0077] When displaying the vulnerability repair time through the repair time comparison bar chart: draw the average and median of the vulnerability repair time to reflect the distribution characteristics of the data and the impact of extreme values. Figure 4 It can be seen that the mean and median of vulnerability repair time are quite different. Therefore, it can be found that in the process of vulnerability repair, the repair time of some vulnerabilities is significantly higher than that of other vulnerabilities.

[0078] By superimposing the regression line on the scatter plot, we analyze the relationship between the vulnerability score and the repair time, and verify the guiding role of the score on the actual vulnerability repair priority. It can be found that vulnerability repairs are carried out in descending order of vulnerability scores. For vulnerabilities with higher scores, the repair priority is also higher.

[0079] The assets are divided into high, medium and low priority groups through scatter plots, and cluster analysis is performed based on vulnerability type, repair time and business impact. The rationality of the asset grouping results is demonstrated through asset grouping analysis scatter plots. It can be analyzed that high-priority assets have significantly faster repair times for vulnerabilities with higher vulnerability scores.

[0080] According to the entire life cycle of the security vulnerability to be analyzed (detection, assignment, repair, and closure), the time consumption of each stage is displayed in the figure through a stacked bar chart, and the average time consumption line of each stage is drawn to find the longest stage. It can be determined that the repair time is the longest stage.

[0081] The vulnerability repair curve can be used to visually compare the number of vulnerability repairs on different repair dates to analyze the overall progress of vulnerability repairs and evaluate the long-term effectiveness of the system.

[0082] Based on the Bayesian method, the success rate and time of vulnerability repair in the future are predicted. Figure 5 In the figure, the blue dotted line is a curve that follows the normal distribution with a mean of 15 and a standard deviation of 5. After adding the observed data of the time it takes for the security vulnerabilities to be analyzed to be fixed in the actual environment (gray columns), the red solid line is obtained, which is the final predicted value.

[0083] This solution can use a variety of technical means such as histograms, scatter plots, cluster analysis, stacked bar charts, and Bayesian methods to visualize vulnerability data in a multi-dimensional and comprehensive manner. At the same time, through data analysis and prediction models, it can provide accurate predictions of future vulnerability repair trends and provide scientific support for the full life cycle management of vulnerabilities.

[0084] Existing vulnerability priority assessment technologies (such as CVSS, EPSS, etc.) do not take business asset dimensions into account in the scoring criteria, and thus cannot assess vulnerabilities based on the actual business environment. This solution can combine existing vulnerability priority technologies and associate the three dimensions of business assets (region, business system, and asset importance) to score and rank vulnerabilities, and the final score and ranking results can reflect the actual vulnerability risk situation of the business environment.

[0085] Because there are dynamic data in the selected data sources, such as EPSS, asset data, etc., if only machine learning is used, the model needs to be retrained according to the changes in the data, which does not conform to the actual use scenario. The vulnerability assessment target formula is fixed, and the data can be dynamic. Combined with the characteristics of the linear regression model and the feature importance evaluation of the random forest model, the weight factor of the formula is continuously polished to obtain sufficient stability and rationality. If the data changes, you only need to recalculate the score through the formula.

[0086] The data of the vulnerability center, the data of the asset center, and the data of the business system in LogEasy SIEM. For the integrated vulnerability data, it can be sent to the corresponding business system manager according to the asset using the task management function of the LogEasy SIEM platform, thus forming a closed loop for vulnerability management. There are many ways to send work order reminders, such as email, text message or phone reminders. After the work order is sent, the existing vulnerability management system is not able to achieve such a complete full life cycle management, or does not combine so much original data. This solution combines multi-dimensional data such as vulnerability discovery time, vulnerability details, scoring data, and repair time, and through the dashboard function of LogEasy, comprehensively integrates and visualizes the vulnerability information to form a complete closed-loop data view. At the same time, it provides a prediction function for the future trend of vulnerabilities, which can intuitively present the full life cycle information of vulnerabilities through charts and support decision analysis.

[0087] By combining formulas with dynamic data, it can adapt to the ever-changing vulnerability environment without the need to frequently retrain the model. It not only combines vulnerability scoring systems such as CVSS and EPSS, but also integrates the data of the asset center in the SIEM platform of Logeasy (asset data in dimensions such as the importance of enterprise assets, regions, and business systems), which can achieve all-round data integration and analysis, and provide a more comprehensive and accurate vulnerability risk assessment. This integration method enables the final scoring results to better adapt to the complex and changing business environment and improve the accuracy and efficiency of vulnerability repair. User labels will change with variable factors such as business scenarios and user roles, so the continuous optimization of label information is of utmost importance. If the label system cannot be updated and optimized in time to adapt to these changes, the label information will become outdated and unable to accurately reflect the real needs and behavioral characteristics of users. By using the method of this solution, fresh normal user behavior log data can be continuously given to the model for training, thereby continuously correcting the formed user labels, making the baseline of the labels higher, and making the labels more accurate and advanced as time goes by and the training data continues to increase. User abnormal behaviors are diverse and complex, and different users and different scenarios may produce different abnormal behaviors. The original analysis method relies on the construction of rule models to discover specific anomalies, but the number of rule models is always limited, and it is difficult to fully cover and identify various abnormal behaviors, which is likely to lead to missed reports.

[0088] The automated work order distribution system greatly shortens the response time from vulnerability discovery to repair through intelligent processes. The traditional vulnerability repair process often requires manual search for the person in charge of the vulnerability, which is prone to delays in the communication process. The automated system can quickly identify the person in charge of the asset association and directly push the work order to the person in charge. This process not only saves a lot of manual time, but also ensures that high-priority vulnerabilities can be handled in a timely manner, thereby effectively reducing the risk of malicious exploitation of vulnerabilities during the exposure period. This solution ensures that every link in the vulnerability repair process can be effectively executed through email notifications, system tracking, and progress feedback. During the vulnerability repair process, the work order status is continuously tracked, and each step in the repair process is automatically recorded, including key information such as the acceptance, processing, and completion of the work order, forming a complete closed-loop management. Through these real-time feedback mechanisms, possible delays or failures in the repair process can be discovered and handled in a timely manner to ensure that the vulnerability repair task is successfully completed. In addition, closed-loop management also provides enterprises with subsequent statistical analysis support. By analyzing the data of completed work orders, the security team can identify bottlenecks or efficiency issues in the repair process and make corresponding optimizations to further improve the overall vulnerability management capabilities. In this way, not only can the entire process of vulnerability repair be controlled, but the company's response efficiency and protection capabilities in similar incidents in the future can also be improved.

[0089] This solution is very different from the previous rule model judgment method. It is no longer limited to the authority of rule writing, but can simply find deviations from the baseline from the perspective of log data anomalies, and can find some abnormal behaviors that we generally ignored in the past. It has been verified that this solution has strong usability and can achieve the expected functions, solving the problems of poor usability of vulnerability assessment results and low efficiency in dispatching work orders generated by vulnerability assessment results.

[0090] Embodiment 4

[0091] Figure 6 A schematic diagram of the structure of a vulnerability assessment processing device provided in Embodiment 4 of the present invention.

[0092] like Figure 6 As shown, the device comprises:

[0093] The feature weight determination module 310 is used to determine the feature initial weight of the vulnerability assessment formula according to the vulnerability sample data to be analyzed and the linear regression model, and fine-tune the feature initial weight based on the random forest model to obtain the feature stable weight;

[0094] A vulnerability assessment target formula generation module 320 is used to generate a vulnerability assessment target formula according to the feature stability weight and the vulnerability assessment formula;

[0095] The vulnerability assessment processing module 330 is used to obtain the SOAR target script and perform vulnerability merging and work order distribution according to the SOAR target script and the vulnerability assessment target formula.

[0096] The technical solution of the embodiment of the present invention determines the feature initial weight of the vulnerability assessment formula according to the vulnerability sample data to be analyzed and the linear regression model, and fine-tunes the feature initial weight based on the random forest model to obtain the feature stable weight, thereby generating the vulnerability assessment target formula according to the feature stable weight and the vulnerability assessment formula, and then obtaining the SOAR target script, and performing vulnerability merging and work order distribution according to the SOAR target script and the vulnerability assessment target formula. In this solution, the linear regression model and the random forest model can be used to configure the weight of the vulnerability assessment formula, so as to evaluate the threat level of the vulnerability corresponding to the dynamically changing vulnerability business data through the vulnerability assessment target formula after the weight configuration. Unlike the machine learning method, it is not necessary to retrain the data according to the data change, and the SOAR target script is used to automatically merge the vulnerabilities in the business, and generate a work order to notify the operation and maintenance personnel to perform maintenance, which solves the problem of poor availability of the vulnerability assessment results of the current network risk assessment system and the low efficiency of distributing the work orders generated by the vulnerability assessment results, and can improve the application effect of the vulnerability assessment results and the distribution efficiency of the work orders generated by the vulnerability assessment results.

[0097] Optionally, the vulnerability assessment processing device also includes a vulnerability assessment formula acquisition module, which is used to determine the vulnerability assessment dimension and obtain a vulnerability assessment formula constructed based on the vulnerability assessment dimension; wherein the vulnerability assessment dimension includes a common vulnerability disclosure severity score, a common vulnerability scoring system score, a vulnerability exploitation likelihood score, an asset dimension comprehensive score, and an asset importance score.

[0098] Optionally, a vulnerability assessment formula acquisition module is specifically used to construct the following vulnerability assessment formula: Y = R score +EPSS score +Percentile score +CIA score +Assets score ; Where Y represents the comprehensive score of vulnerability assessment; R score Indicates the severity score of the described common vulnerability exposure; EPSS score Represents the Common Vulnerability Scoring System score; Percentile score Indicates the likelihood of the vulnerability being exploited; CIA score Indicates the comprehensive score of the asset dimension; Assets score Represents the asset importance score.

[0099] Optionally, the vulnerability assessment processing module 330 is specifically used to determine the vulnerability priority assessment results of each security vulnerability to be processed according to the vulnerability assessment target formula; based on the SOAR target script, according to the vulnerability priority assessment results of each security vulnerability to be processed, extract the target security vulnerability and obtain the asset information affected by the vulnerability; based on the asset information affected by the vulnerability and the completeness of the asset information judgment condition, merge the target security vulnerabilities and report the created merged vulnerability reporting work order.

[0100] Optionally, the vulnerability assessment processing module 330 is specifically used to merge the target security vulnerabilities based on the current first task name when it is determined based on the asset information completeness judgment condition that the asset information affected by the vulnerability is complete; and to merge the target security vulnerabilities based on the current second task name when it is determined based on the asset information completeness judgment condition that the asset information affected by the vulnerability is incomplete.

[0101] Optionally, the vulnerability assessment processing module 330 is specifically used to merge the target security vulnerabilities according to the created first task name when the current first task name exists in the created first task name; and merge the target security vulnerabilities according to the created second task name when the current second task name exists in the created second task name.

[0102] Optionally, the vulnerability assessment processing device also includes a drawing module, which is used to determine the vulnerability repair time of the security vulnerability to be analyzed, and draw a repair time comparison bar chart based on the vulnerability repair time of the security vulnerability to be analyzed; draw an asset grouping analysis scatter plot based on the target-associated data to be analyzed and the asset level grouping data of the security vulnerability to be analyzed; and, based on the Bayesian algorithm and the security vulnerability to be analyzed, draw any item in the vulnerability repair time prediction graph.

[0103] The vulnerability assessment processing device provided in the embodiment of the present invention can execute the vulnerability assessment processing method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the execution method.

[0104] Embodiment 5

[0105] Figure 7 A schematic diagram of an electronic device that can be used to implement an embodiment of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device may also represent various forms of mobile devices, such as personal digital assistants, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or required herein.

[0106] like Figure 7 As shown, the electronic device 10 includes at least one processor 11, and a memory connected to the at least one processor 11, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc., wherein the memory stores a computer program that can be executed by at least one processor, and the processor 11 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 to the random access memory (RAM) 13. In the RAM 13, various programs and data required for the operation of the electronic device 10 can also be stored. The processor 11, the ROM 12, and the RAM 13 are connected to each other through a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.

[0107] A number of components in the electronic device 10 are connected to the I / O interface 15, including: an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a disk, an optical disk, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.

[0108] The processor 11 may be a variety of general and / or special processing components with processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The processor 11 executes the various methods and processes described above, such as a vulnerability assessment processing method.

[0109] In some embodiments, the vulnerability assessment processing method may be implemented as a computer program, which is tangibly contained in a computer-readable storage medium, such as a storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed on the electronic device 10 via the ROM 12 and / or the communication unit 19. When the computer program is loaded into the RAM 13 and executed by the processor 11, one or more steps of the vulnerability assessment processing method described above may be performed. Alternatively, in other embodiments, the processor 11 may be configured to execute the vulnerability assessment processing method in any other appropriate manner (e.g., by means of firmware).

[0110] Various implementations of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chips (SOCs), load programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various implementations can include: being implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.

[0111] Computer programs for implementing the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, so that when the computer program is executed by the processor, the functions / operations specified in the flow chart and / or block diagram are implemented. The computer program may be executed entirely on the machine, partially on the machine, partially on the machine and partially on a remote machine as a stand-alone software package, or entirely on a remote machine or server.

[0112] In the context of the present invention, a computer-readable storage medium may be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, device, or equipment. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or equipment, or any suitable combination of the foregoing. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. A more specific example of a machine-readable storage medium may include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0113] To provide interaction with a user, the systems and techniques described herein may be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or trackball) through which the user can provide input to the electronic device. Other types of devices may also be used to provide interaction with the user; for example, the feedback provided to the user may be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user may be received in any form (including acoustic input, voice input, or tactile input).

[0114] The systems and techniques described herein may be implemented in a computing system that includes backend components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes frontend components (e.g., a user computer with a graphical user interface or a web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system may be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.

[0115] A computing system may include a client and a server. The client and the server are generally remote from each other and usually interact through a communication network. The client and server relationship is generated by computer programs running on the corresponding computers and having a client-server relationship with each other. The server may be a cloud server, also known as a cloud computing server or cloud host, which is a host product in the cloud computing service system to solve the defects of traditional physical hosts and VPS servers, which are difficult to manage and have weak business scalability.

[0116] It should be understood that the various forms of processes shown above can be used to reorder, add or delete steps. For example, the steps described in the present invention can be executed in parallel, sequentially or in different orders, as long as the desired results of the technical solution of the present invention can be achieved, and this document does not limit this.

[0117] The above specific implementations do not constitute a limitation on the protection scope of the present invention. It should be understood by those skilled in the art that various modifications, combinations, sub-combinations and substitutions can be made according to design requirements and other factors. Any modification, equivalent substitution and improvement made within the spirit and principle of the present invention should be included in the protection scope of the present invention.

Claims

1. A vulnerability assessment processing method, characterized in that: include: According to the vulnerability sample data to be analyzed and the linear regression model, the initial feature weights of the vulnerability assessment formula are determined, and the initial feature weights are fine-tuned based on the random forest model to obtain stable feature weights; Generate a vulnerability assessment target formula according to the feature stability weight and the vulnerability assessment formula; Obtain the security orchestration automation and response SOAR target script, and merge vulnerabilities and distribute work orders based on the SOAR target script and the vulnerability assessment target formula.

2. The method according to claim 1, characterized in that Before determining the initial weight of the features of the vulnerability assessment formula according to the vulnerability sample data to be analyzed and the linear regression model, the method further includes: Determine a vulnerability assessment dimension, and obtain a vulnerability assessment formula constructed based on the vulnerability assessment dimension; Among them, the vulnerability assessment dimensions include the common vulnerability disclosure severity score, the common vulnerability scoring system score, the vulnerability exploitation likelihood score, the asset dimension comprehensive score and the asset importance score.

3. The method according to claim 2, characterized in that The obtaining of a vulnerability assessment formula constructed based on the vulnerability assessment dimension includes: Construct the vulnerability assessment formula as follows: Y=R score +EPSS score +Percentile score +CIA score +Assets score ; Among them, Y represents the comprehensive score of vulnerability assessment; R score Indicates the severity score of the described common vulnerability exposure; EPSS score Represents the Common Vulnerability Scoring System score; Percentile score Indicates the likelihood of the vulnerability being exploited; CIA score Indicates the comprehensive score of the asset dimension; Assets score Represents the asset importance score.

4. The method according to claim 1, characterized in that: The vulnerability merging and work order distribution according to the SOAR target script and the vulnerability assessment target formula include: Determine the vulnerability priority assessment result of each security vulnerability to be processed according to the vulnerability assessment target formula; Based on the SOAR target scenario, according to the vulnerability priority assessment results of each of the security vulnerabilities to be processed, target security vulnerabilities are extracted, and information on assets affected by the vulnerabilities is obtained; Based on the asset information affected by the vulnerability and the completeness of the asset information, the target security vulnerabilities are merged, and the created merged vulnerability reporting work order is reported.

5. The method according to claim 4, characterized in that The merging of the target security vulnerabilities based on the asset information affected by the vulnerabilities and the asset information completeness judgment conditions includes: When it is determined that the asset information affected by the vulnerability is complete based on the asset information completeness determination condition, the target security vulnerabilities are merged based on the current first task name; When it is determined that the asset information affecting the vulnerability is incomplete based on the asset information completeness determination condition, the target security vulnerabilities are merged based on the current second task name.

6. The method according to claim 5, characterized in that The merging of the target security vulnerabilities based on the current first task name includes: When the current first task name exists in the created first task name, merging the target security vulnerability according to the created first task name; The merging of the target security vulnerabilities based on the current second task name includes: When the current second task name exists in the created second task name, the target security vulnerability is merged according to the created second task name.

7. The method according to claim 1, characterized in that After the vulnerability merging and work order dispatching according to the SOAR target script and the vulnerability assessment target formula, any of the following items are also included: Determine the vulnerability repair time of the security vulnerability to be analyzed, and draw a repair time comparison bar chart based on the vulnerability repair time of the security vulnerability to be analyzed; Draw an asset grouping analysis scatter plot based on the target-associated data to be analyzed and the asset-level grouping data of the security vulnerability to be analyzed; and Based on the Bayesian algorithm and the security vulnerabilities to be analyzed, a vulnerability repair time prediction graph is drawn.

8. A vulnerability assessment processing device, characterized in that: include: The feature weight determination module is used to determine the initial feature weights of the vulnerability assessment formula based on the vulnerability sample data to be analyzed and the linear regression model, and to fine-tune the initial feature weights based on the random forest model to obtain stable feature weights; A vulnerability assessment target formula generation module, used to generate a vulnerability assessment target formula according to the feature stability weight and the vulnerability assessment formula; The vulnerability assessment processing module is used to obtain the security orchestration automation and response SOAR target script, and perform vulnerability merging and work order distribution according to the SOAR target script and the vulnerability assessment target formula.

9. An electronic device, characterized in that: The electronic device comprises: at least one processor; and a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can perform the vulnerability assessment processing method according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the vulnerability assessment processing method according to any one of claims 1 to 7 when executed.