Network security vulnerability detection method and device, storage medium and electronic equipment
Through the large language model, vulnerability attack instructions are automatically generated and network security vulnerability detection is automatically carried out, solving the problem of low manual detection efficiency and achieving efficient vulnerability detection.
Patent Information
- Application Number
- CN202510299348.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-13
- Publication Date
- 2025-05-13
AI Technical Summary
The existing technology relies on manual network security vulnerability detection, resulting in low detection efficiency.
Through the large language model, vulnerability attack instructions are automatically generated, and security vulnerability detection is automatically carried out on the servers in the target organization, realizing the automation of vulnerability detection.
It improves the efficiency of vulnerability detection, avoids the inefficiency when manually compiling vulnerability attack instructions, and realizes automatic execution of vulnerability attack instructions for vulnerability detection.
Smart Images

Figure CN119996050A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of artificial intelligence, and in particular to a method, device, storage medium and electronic device for detecting network security vulnerabilities. Background Art
[0002] Financial institutions will regularly conduct network attack and defense drills (commonly known as red and blue attack and defense) to identify network security vulnerabilities in the financial institution system and improve the security of the system. During the drill, the defender is the financial institution's own network security defense, and the attacker usually relies on staff to compile attack instructions to perform attack operations. Due to the fast update speed and large number of network security vulnerabilities, there is a problem of low vulnerability detection efficiency when relying on manual detection of the above vulnerabilities.
[0003] To address the above-mentioned problems, no effective solution has been proposed yet. Summary of the invention
[0004] The embodiments of the present invention provide a method, device, storage medium and electronic device for detecting network security vulnerabilities, so as to at least solve the technical problem that the related technology relies on manual vulnerability detection, resulting in low vulnerability detection efficiency.
[0005] According to one aspect of an embodiment of the present invention, a method for detecting network security vulnerabilities is provided, comprising: determining vulnerability information of a network security vulnerability to be detected; processing the vulnerability information through a large language model to obtain vulnerability attack instructions; and performing security vulnerability detection on a server within a target organization based on the vulnerability attack instructions to obtain a detection result.
[0006] Furthermore, the method for detecting network security vulnerabilities also includes: obtaining vulnerability information newly imported into the target database within a target time period; determining whether the newly imported vulnerability information belongs to a target list, wherein the target list is used to record vulnerability information of network security vulnerabilities that have been repaired within the target organization; if the newly imported vulnerability information does not belong to the target list, determining the newly imported vulnerability information as vulnerability information of the network security vulnerability to be detected.
[0007] Furthermore, the method for detecting network security vulnerabilities also includes: obtaining a target prompt word, wherein the target prompt word is used to guide the large language model to generate vulnerability attack instructions according to vulnerability information; inputting the target prompt word and vulnerability information into the large language model to obtain the vulnerability attack instructions.
[0008] Furthermore, the method for detecting network security vulnerabilities also includes: executing vulnerability attack instructions in the target tool library to perform security vulnerability detection on the server within the target organization to obtain detection results, wherein the vulnerability attack instructions are used to call the security vulnerability attack tool in the target tool library to attack the target server in the target organization.
[0009] Furthermore, the method for detecting network security vulnerabilities also includes: performing security vulnerability detection on a server within a target organization based on vulnerability attack instructions, and after obtaining the detection results, generating first information based on the detection results, wherein the first information is used to instruct the target user to repair the network security vulnerabilities recorded in the detection results; and sending the first information to the target user.
[0010] Furthermore, the method for detecting network security vulnerabilities also includes: after sending the first information to the target user, detecting whether the second information is received, wherein the second information includes vulnerability information of the repaired network security vulnerability; when the second information is received, storing the vulnerability information of the network security vulnerability in the second information to the target list.
[0011] Furthermore, the method for detecting network security vulnerabilities also includes: obtaining a training sample set, wherein the training samples of the training sample set include sample vulnerability information, server configuration information of the target organization, and the real labels of the training samples include sample vulnerability attack instructions; training an initial large language model through the training sample set to obtain a large language model.
[0012] According to another aspect of an embodiment of the present invention, a network security vulnerability detection device is also provided, including: a determination module, used to determine vulnerability information of a network security vulnerability to be detected; a first processing module, used to process the vulnerability information through a large language model to obtain vulnerability attack instructions; and a second processing module, used to perform security vulnerability detection on a server within a target organization based on the vulnerability attack instructions to obtain a detection result.
[0013] According to another aspect of an embodiment of the present invention, a computer-readable storage medium is provided, in which a computer program is stored, wherein the computer program is configured to execute the above-mentioned network security vulnerability detection method when running.
[0014] According to another aspect of an embodiment of the present invention, an electronic device is also provided, which includes one or more processors; a memory for storing one or more programs, so that when the one or more programs are executed by the one or more processors, the one or more processors are implemented to run the programs, wherein the programs are configured to execute the above-mentioned network security vulnerability detection method during runtime.
[0015] According to another aspect of an embodiment of the present invention, a computer program product is provided, including a computer program / instruction, and when the computer program / instruction is executed by a processor, the above-mentioned network security vulnerability detection method is implemented.
[0016] In an embodiment of the present invention, a method of automatically generating vulnerability attack instructions through a large language model for vulnerability detection is adopted. By determining the vulnerability information of the network security vulnerability to be detected, and then processing the vulnerability information through the large language model, the vulnerability attack instructions are obtained, and then security vulnerability detection is performed on the server in the target organization based on the vulnerability attack instructions to obtain the detection result.
[0017] In the above process, vulnerability information is processed by using a large language model to obtain vulnerability attack instructions, thereby realizing automatic generation of vulnerability attack instructions and avoiding the inefficiency of manually compiling vulnerability attack instructions. Security vulnerability detection is performed on servers within the target organization based on vulnerability attack instructions to obtain detection results, thereby realizing automatic execution of vulnerability attack instructions for vulnerability detection and avoiding manual execution of related operations, thereby effectively improving vulnerability detection efficiency.
[0018] It can be seen that the solution provided in the present application achieves the purpose of automatically generating vulnerability attack instructions through a large language model for vulnerability detection, thereby achieving the technical effect of improving the efficiency of vulnerability detection, and further solving the technical problem that the related technology relies on manual vulnerability detection, resulting in low vulnerability detection efficiency. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] The drawings described herein are used to provide a further understanding of the present invention and constitute a part of this application. The exemplary embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation of the present invention. In the drawings:
[0020] Figure 1 Schematic diagram of an optional network security vulnerability detection method according to an embodiment of the present invention Figure 1 ;
[0021] Figure 2 Schematic diagram of an optional network security vulnerability detection method according to an embodiment of the present invention Figure 2 ;
[0022] Figure 3 is a schematic diagram of an optional network security vulnerability detection device according to an embodiment of the present invention;
[0023] Figure 4 is a schematic diagram of an optional electronic device according to an embodiment of the present invention. DETAILED DESCRIPTION
[0024] In order to enable those skilled in the art to better understand the scheme of the present invention, the technical scheme in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present invention.
[0025] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units that are clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0026] It should be noted that the collected information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for display, data for analysis, etc.) involved in this application are information and data authorized by the user or fully authorized by all parties, and the collection, storage, use, processing, transmission, provision, disclosure and application of relevant data are in compliance with relevant laws, regulations and standards, necessary confidentiality measures are taken, and public order and good customs are not violated, and corresponding operation entrances are provided for users to choose to authorize or refuse. For example, an interface is set up between this system and relevant users or institutions to provide users with corresponding operation entrances for users to choose to agree or refuse the results of automated decision-making; if the user chooses to refuse, the expert decision-making process will be entered.
[0027] Example 1
[0028] According to an embodiment of the present invention, an embodiment of a method for detecting network security vulnerabilities is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.
[0029] Figure 1 Schematic diagram of an optional network security vulnerability detection method according to an embodiment of the present invention Figure 1 ,like Figure 1 As shown, the method comprises the following steps:
[0030] Step S101, determining vulnerability information of a network security vulnerability to be detected.
[0031] Optionally, electronic devices, application systems, servers and other devices may be used as the execution subject of the present application. In this embodiment, the target processing system is used as the execution subject to execute the above-mentioned network security vulnerability detection method.
[0032] Optionally, the vulnerability information of a network security vulnerability includes the area of the server where the network security vulnerability may exist, the attack type, the severity score, the estimated repair time, etc., where the attack type refers to the specific way in which the vulnerability may be exploited or the type of attack method, such as buffer overflow, cross-site scripting, SQL injection, etc.
[0033] In an optional embodiment, the target processing system may obtain vulnerability information of a network security vulnerability input by a user, thereby determining the vulnerability information as vulnerability information of a network security vulnerability to be detected.
[0034] In an optional embodiment, the target processing system may also obtain vulnerability information of the network security vulnerability to be detected from a target database, the Internet, or other areas. For example, the target database is a database used to record security vulnerabilities and exposure points in public computer software or hardware. The information in the target database is public and supports anyone to access and query through a website, API or other forms. The target database may contain a detailed description of the vulnerability, the affected software or hardware, the public status of the vulnerability, the relevant severity score, repair suggestions, patch information, and reference links.
[0035] For example, the target processing system can establish a real-time call and query interface for the target database, so as to obtain the latest vulnerability information in the target database in real time and use it as the vulnerability information of the network security vulnerability to be detected.
[0036] In an optional embodiment, the target processing system may also filter the vulnerability information obtained from the target database, the Internet, or other areas, and determine the vulnerability information of the network security vulnerability to be detected from the filtered vulnerability information. For example, the vulnerability information of the network security vulnerability that has been repaired is removed from the obtained vulnerability information.
[0037] Step S102: Process the vulnerability information through a large language model to obtain vulnerability attack instructions.
[0038] Optionally, after determining the vulnerability information of the network security vulnerability to be detected, the target processing system can use the pre-trained large language model to process the information. For example, the vulnerability information and the corresponding prompt words are input into the large language model to guide the large language model to generate vulnerability attack instructions according to the vulnerability information. The vulnerability attack instructions are used to detect the network security vulnerability to which the vulnerability information belongs.
[0039] In an optional embodiment, the vulnerability attack instruction is used to call the security vulnerability attack tool in the target attack library to attack the target server in the target organization. The vulnerability attack instruction includes the identifier of the security vulnerability attack tool to be called and the identifier of the server to be attacked, and the aforementioned target server is the server to be attacked.
[0040] In an optional embodiment, one vulnerability information corresponds to one vulnerability attack instruction, and each vulnerability attack instruction may include one or more lines of instructions, so as to achieve effective detection of network security vulnerabilities through one or more steps of operation.
[0041] Step S103, based on the vulnerability attack instruction, security vulnerability detection is performed on the server in the target organization to obtain the detection result.
[0042] Optionally, after receiving the vulnerability attack instruction, the target processing system can execute the vulnerability attack instruction to simulate an attack on the servers in the target organization based on the vulnerability attack instruction to detect whether there are network security vulnerabilities in these servers. If the attack is successful, it means that the vulnerability exists on the server, and if the attack is unsuccessful, it is determined that the vulnerability does not exist on the server.
[0043] Optionally, the detection results include information for characterizing whether there is a network security vulnerability on the server within the target organization, and in the case of a server with a network security vulnerability, the detection results also include server information of the server with the network security vulnerability and vulnerability information of the vulnerability existing on the server. For example, the detection results include the server IP address of the server with the network security vulnerability, the type of attack on the network security vulnerability on the server, the severity score, the estimated repair time, etc.
[0044] Based on the scheme defined by the above steps S101 to S103, it can be known that in an embodiment of the present invention, a method of automatically generating vulnerability attack instructions through a large language model for vulnerability detection is adopted, by determining the vulnerability information of the network security vulnerability to be detected, and then processing the vulnerability information through a large language model to obtain the vulnerability attack instructions, thereby performing security vulnerability detection on the server in the target organization based on the vulnerability attack instructions to obtain the detection result.
[0045] It is easy to notice that in the above process, by utilizing the large language model to process the vulnerability information and obtain the vulnerability attack instructions, the automatic generation of the vulnerability attack instructions is realized, thus avoiding the problem of inefficiency in manually compiling the vulnerability attack instructions. By performing security vulnerability detection on the servers within the target organization based on the vulnerability attack instructions and obtaining the detection results, the vulnerability attack instructions are automatically executed to perform vulnerability detection, thus avoiding manual execution of related operations, thereby effectively improving the vulnerability detection efficiency.
[0046] It can be seen that the solution provided in the present application achieves the purpose of automatically generating vulnerability attack instructions through a large language model for vulnerability detection, thereby achieving the technical effect of improving the efficiency of vulnerability detection, and further solving the technical problem that the related technology relies on manual vulnerability detection, resulting in low vulnerability detection efficiency.
[0047] In an optional embodiment, in the process of determining vulnerability information of a network security vulnerability to be detected, the target processing system may obtain vulnerability information newly imported into the target database within a target time period; determine whether the newly imported vulnerability information belongs to a target list, wherein the target list is used to record vulnerability information of network security vulnerabilities that have been repaired within the target organization; if the newly imported vulnerability information does not belong to the target list, determine the newly imported vulnerability information as vulnerability information of the network security vulnerability to be detected.
[0048] In an optional embodiment, the starting point of the target time period may be the time point when the vulnerability detection was last performed, and the ending point of the target time period may be the current time point.
[0049] In an optional embodiment, the target time period may be the past 24 hours, or the past week, or the past month.
[0050] Optionally, the target database is a database for recording security vulnerabilities and exposure points in public computer software or hardware. The information in the target database is public and supports access and query by anyone through a website, API or other forms. The target processing system can establish a real-time call and query interface for the target database, so as to obtain new vulnerability information imported into the target database in real time within the target time period.
[0051] Optionally, after acquiring the vulnerability information from the target database, the target processing system may determine whether the newly imported vulnerability information belongs to the target list, that is, determine whether the newly imported vulnerability information has been repaired.
[0052] Optionally, if the newly imported vulnerability information is not in the target list, that is, the network security vulnerabilities to which the vulnerability information belongs have not been repaired by the target organization, then the target processing system can determine that the vulnerability information is vulnerability information of the network security vulnerabilities to be detected. On the contrary, if the newly imported vulnerability information belongs to the target list, then the target processing system can determine that the network security vulnerabilities to which the vulnerability information belongs have been repaired by the target organization. In this case, it is prohibited to determine the vulnerability information as vulnerability information of the network security vulnerabilities to be detected.
[0053] It should be noted that, through the above method, it is possible to exclude known and fixed vulnerability information before vulnerability detection, thereby avoiding waste of resources during vulnerability detection and further improving vulnerability detection efficiency.
[0054] In an optional embodiment, in the process of processing vulnerability information through a large language model to obtain vulnerability attack instructions, the target processing system can obtain a target prompt word, wherein the target prompt word is used to guide the large language model to generate vulnerability attack instructions based on the vulnerability information; the target prompt word and vulnerability information are input into the large language model to obtain vulnerability attack instructions.
[0055] Optionally, the target prompt word is predefined by the user in the target processing system. For example, the target prompt word may be "based on the vulnerability information listed below, generate vulnerability attack instructions corresponding to each vulnerability information."
[0056] After obtaining the target prompt word, the target processing system can input the target prompt word and vulnerability information into the large language model, and the large language model generates vulnerability attack instructions for the network security vulnerability to which the vulnerability information belongs based on the target prompt word and vulnerability information.
[0057] It should be noted that by using predefined target prompt words as the input of the large language model, the large language model can be guided to understand vulnerability information more accurately and understand the task objectives, reducing the possibility of generating irrelevant content, thereby improving the accuracy and efficiency of generating vulnerability attack instructions.
[0058] In an optional embodiment, in the process of performing security vulnerability detection on servers within a target organization based on vulnerability attack instructions to obtain detection results, the target processing system may execute vulnerability attack instructions in a target tool library to perform security vulnerability detection on servers within the target organization to obtain detection results, wherein the vulnerability attack instructions are used to call the security vulnerability attack tools in the target tool library to attack the target server in the target organization.
[0059] Optionally, the target tool library includes multiple security vulnerability attack tools, which can detect and simulate attacks on different vulnerability types. The vulnerability attack instruction is used to call the security vulnerability attack tool in the target tool library to attack the target server in the target organization.
[0060] Optionally, the target processing system may execute vulnerability attack instructions in the target tool library to call the security vulnerability attack tool in the target tool library, thereby detecting security vulnerabilities of servers within the target organization and obtaining detection results.
[0061] Optionally, the target server is the server specified in the vulnerability attack instruction, that is, the server to be attacked.
[0062] It should be noted that, through the above method, the automatic calling of the security vulnerability attack tool in the target tool library is realized, avoiding the manual calling of the attack tool library, thereby improving the vulnerability detection efficiency.
[0063] In an optional embodiment, after performing security vulnerability detection on the server within the target organization based on vulnerability attack instructions and obtaining the detection results, the target processing system can generate first information based on the detection results, wherein the first information is used to instruct the target user to repair the network security vulnerabilities recorded in the detection results; and send the first information to the target user.
[0064] Optionally, the first information may be "Vulnerability detection of the target organization has been completed. The detection results are as follows. Please check and record and repair the network security vulnerabilities therein. [Detection result content]". Among them, "[Detection result content]" is used to fill in the detection result.
[0065] Optionally, the target user may be a staff member of the target organization who is used to repair network security vulnerabilities. After generating the first information, the target processing system may send the first information to the target user via email, an internal messaging system of the target organization, or other communication channels.
[0066] It should be noted that, through the above method, the target user is automatically notified after the detection result is obtained, thereby facilitating the improvement of the timeliness of vulnerability repair.
[0067] In an optional embodiment, after sending the first information to the target user, the target processing system may detect whether the second information is received, wherein the second information includes vulnerability information of the repaired network security vulnerability; if the second information is received, the vulnerability information of the network security vulnerability in the second information is stored in the target list.
[0068] Optionally, the second information may be a confirmation message sent by the target user to the target processing system after the network security vulnerability indicated in the first information is repaired, which includes detailed information of the repaired vulnerability, such as the IP address of the server to which the repaired vulnerability belongs, the attack type of the repaired vulnerability, the severity score, the repair time, etc.
[0069] Optionally, after sending the first information to the target user, the target processing system may continuously detect whether the second information fed back by the target user is received.
[0070] Optionally, upon receiving the second information, the target processing system stores vulnerability information of network security vulnerabilities in the second information into a target list to update the target list.
[0071] Optionally, when the second information is not received, the target processing system does not perform the operation of storing the vulnerability information in the target list.
[0072] It should be noted that by detecting the receipt of the second information and updating the target list, a closed-loop management mechanism for vulnerability repair is provided for the red-blue attack and defense drill based on the large language model. This design not only enhances the real-time and dynamic response capabilities of the system, but also improves the accuracy and timeliness of the target list, thereby facilitating the improvement of the detection efficiency of subsequent vulnerability detection and avoiding the occupation of invalid resources.
[0073] In an optional embodiment, the large language model is trained in the following manner: obtaining a training sample set, wherein the training samples of the training sample set include sample vulnerability information, server configuration information of the target organization, and the true labels of the training samples include sample vulnerability attack instructions; training an initial large language model with the training sample set to obtain a large language model.
[0074] Optionally, the server configuration information of the target organization includes, but is not limited to, network topology, operating system information, business types of business executed by the server, network configuration information, information on middleware and application software running on the server, hardware configuration information, software configuration files, security policies, etc. By using the server configuration information as part of the training sample, the initial large language model can learn the attack objects (i.e., servers) corresponding to different types of network security vulnerabilities during the training process, thereby making the server pointed to in the vulnerability attack instructions output by the large language model in the application more accurate.
[0075] Optionally, after determining the training sample set, the target processing system may input the training sample set into the initial large language model to perform training on the initial large language model, thereby obtaining the large language model.
[0076] It should be noted that, through the above method, effective training of the large language model is achieved, thereby improving the accuracy of determining vulnerability attack instructions.
[0077] In an optional embodiment, Figure 2 Schematic diagram of an optional network security vulnerability detection method according to an embodiment of the present invention Figure 2 ,like Figure 2 As shown, the target processing system can obtain the newly imported vulnerability information of the target database within the target time period in real time, and then exclude the vulnerability information belonging to the target list from the newly imported vulnerability information, and determine the remaining vulnerability information as the vulnerability information of the network security vulnerability to be detected. After that, the target processing system can input the vulnerability information and the target prompt word into the large language model, and generate the vulnerability attack instruction through the large language model. After obtaining the vulnerability attack instruction, the target processing system can execute the vulnerability attack instruction in the target tool library to call the security vulnerability attack tool in the target tool library to attack the server, realize vulnerability detection, and obtain the vulnerability result.
[0078] It can be seen that the solution provided in the present application achieves the purpose of automatically generating vulnerability attack instructions through a large language model for vulnerability detection, thereby achieving the technical effect of improving the efficiency of vulnerability detection, and further solving the technical problem that the related technology relies on manual vulnerability detection, resulting in low vulnerability detection efficiency.
[0079] Example 2
[0080] According to an embodiment of the present invention, an embodiment of a device for detecting network security vulnerabilities is provided, wherein: Figure 3 is a schematic diagram of an optional network security vulnerability detection device according to an embodiment of the present invention, such as Figure 3 As shown, the device comprises:
[0081] A determination module 301 is used to determine vulnerability information of a network security vulnerability to be detected;
[0082] The first processing module 302 is used to process the vulnerability information through a large language model to obtain vulnerability attack instructions;
[0083] The second processing module 303 is used to perform security vulnerability detection on the server in the target organization based on the vulnerability attack instruction to obtain the detection result.
[0084] In the above process, vulnerability information is processed by using a large language model to obtain vulnerability attack instructions, thereby realizing automatic generation of vulnerability attack instructions and avoiding the inefficiency of manually compiling vulnerability attack instructions. Security vulnerability detection is performed on servers within the target organization based on vulnerability attack instructions to obtain detection results, thereby realizing automatic execution of vulnerability attack instructions for vulnerability detection and avoiding manual execution of related operations, thereby effectively improving vulnerability detection efficiency.
[0085] It can be seen that the solution provided in the present application achieves the purpose of automatically generating vulnerability attack instructions through a large language model for vulnerability detection, thereby achieving the technical effect of improving the efficiency of vulnerability detection, and further solving the technical problem that the related technology relies on manual vulnerability detection, resulting in low vulnerability detection efficiency.
[0086] It should be noted that the above-mentioned determination module 301, first processing module 302 and second processing module 303 correspond to steps S101 to S103 in the above-mentioned embodiment, and the examples and application scenarios implemented by the three modules and the corresponding steps are the same, but are not limited to the contents disclosed in the above-mentioned embodiment 1.
[0087] Optionally, the determination module 301 also includes: a first acquisition submodule, used to acquire vulnerability information newly imported into the target database within a target time period; a judgment submodule, used to judge whether the newly imported vulnerability information belongs to a target list, wherein the target list is used to record vulnerability information of network security vulnerabilities that have been repaired in the target organization; and a determination submodule, used to determine the newly imported vulnerability information as vulnerability information of the network security vulnerability to be detected if the newly imported vulnerability information does not belong to the target list.
[0088] Optionally, the first processing module 302 also includes: a second acquisition submodule, used to acquire a target prompt word, wherein the target prompt word is used to guide the large language model to generate a vulnerability attack instruction based on the vulnerability information; and a processing submodule, used to input the target prompt word and the vulnerability information into the large language model to obtain the vulnerability attack instruction.
[0089] Optionally, the second processing module 303 also includes: an execution sub-module, which is used to execute vulnerability attack instructions in the target tool library to perform security vulnerability detection on the server in the target organization to obtain detection results, wherein the vulnerability attack instructions are used to call the security vulnerability attack tool in the target tool library to attack the target server in the target organization.
[0090] Optionally, the network security vulnerability detection device also includes: a generation module, used to generate first information based on the detection result, wherein the first information is used to instruct the target user to repair the network security vulnerability recorded in the detection result; and a sending module, used to send the first information to the target user.
[0091] Optionally, the network security vulnerability detection device also includes: a detection module, used to detect whether second information is received, wherein the second information includes vulnerability information of the repaired network security vulnerability; and a storage module, used to store the vulnerability information of the network security vulnerability in the second information to a target list when the second information is received.
[0092] Optionally, the network security vulnerability detection device also includes: an acquisition module, used to obtain a training sample set, wherein the training samples of the training sample set include sample vulnerability information, server configuration information of the target organization, and the real labels of the training samples include sample vulnerability attack instructions; a training module, used to train an initial large language model through the training sample set to obtain a large language model.
[0093] Example 3
[0094] According to another aspect of an embodiment of the present invention, a computer-readable storage medium is further provided, in which a computer program is stored, wherein the computer program is configured to execute the above-mentioned network security vulnerability detection method when running.
[0095] Example 4
[0096] According to another aspect of an embodiment of the present invention, there is also provided an electronic device, wherein: Figure 4 is a schematic diagram of an optional electronic device according to an embodiment of the present invention, such as Figure 4 As shown, the electronic device includes one or more processors; a memory for storing one or more programs, which, when the one or more programs are executed by the one or more processors, enables the one or more processors to run the programs, wherein the programs are configured to execute the above-mentioned network security vulnerability detection method during operation.
[0097] Among them, the memory can be used to store software programs and modules, such as program instructions / modules corresponding to the methods and devices in the embodiments of the present application, and the processor executes various functional applications and data processing by running the software programs and modules stored in the memory, that is, realizing the above-mentioned method. The memory may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory may further include a memory remotely arranged relative to the processor, and these remote memories may be connected to the terminal via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0098] The processor can call the information and application programs stored in the memory through the transmission device to perform the following steps: determine the vulnerability information of the network security vulnerability to be detected; process the vulnerability information through a large language model to obtain vulnerability attack instructions; perform security vulnerability detection on the server within the target organization based on the vulnerability attack instructions to obtain detection results.
[0099] The processor can also call the information and application programs stored in the memory through the transmission device to perform the following steps: obtain the newly imported vulnerability information of the target database within the target time period; determine whether the newly imported vulnerability information belongs to the target list, wherein the target list is used to record the vulnerability information of the network security vulnerabilities that have been repaired in the target organization; if the newly imported vulnerability information does not belong to the target list, determine the newly imported vulnerability information as the vulnerability information of the network security vulnerability to be detected.
[0100] The processor can also call the information and application stored in the memory through the transmission device to perform the following steps: obtain the target prompt word, wherein the target prompt word is used to guide the large language model to generate vulnerability attack instructions based on the vulnerability information; input the target prompt word and vulnerability information into the large language model to obtain the vulnerability attack instruction.
[0101] The processor can also call the information and applications stored in the memory through the transmission device to perform the following steps: execute vulnerability attack instructions in the target tool library to perform security vulnerability detection on the server within the target organization to obtain detection results, wherein the vulnerability attack instructions are used to call the security vulnerability attack tools in the target tool library to attack the target server in the target organization.
[0102] The processor can also call the information and application programs stored in the memory through the transmission device to perform the following steps: perform security vulnerability detection on the server within the target organization based on the vulnerability attack instruction, and after obtaining the detection result, generate first information according to the detection result, wherein the first information is used to instruct the target user to repair the network security vulnerability recorded in the detection result; send the first information to the target user.
[0103] The processor can also call the information and applications stored in the memory through the transmission device to perform the following steps: after sending the first information to the target user, detect whether the second information is received, wherein the second information includes vulnerability information of the repaired network security vulnerability; if the second information is received, store the vulnerability information of the network security vulnerability in the second information to the target list.
[0104] The processor can also call the information and application programs stored in the memory through the transmission device to perform the following steps: obtain a training sample set, wherein the training samples of the training sample set include sample vulnerability information, server configuration information of the target organization, and the true labels of the training samples include sample vulnerability attack instructions; train the initial large language model through the training sample set to obtain a large language model.
[0105] Example 5
[0106] According to another aspect of an embodiment of the present invention, a computer program product is provided, including a computer program / instruction, and when the computer program / instruction is executed by a processor, the above-mentioned network security vulnerability detection method is implemented.
[0107] The serial numbers of the above embodiments of the present invention are only for description and do not represent the advantages or disadvantages of the embodiments.
[0108] In the above embodiments of the present invention, the description of each embodiment has its own emphasis. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0109] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only schematic. For example, the division of units can be a logical function division. There may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of units or modules, which can be electrical or other forms.
[0110] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed over multiple units. Some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.
[0111] In addition, each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.
[0112] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for a computer device (which can be a personal computer, a server or a network device, etc.) to perform all or part of the steps of the methods of each embodiment of the present invention. The aforementioned storage medium includes: U disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), mobile hard disk, disk or optical disk and other media that can store program codes.
[0113] The above are only preferred embodiments of the present invention. It should be pointed out that, for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present invention. These improvements and modifications should also be regarded as the scope of protection of the present invention.
Claims
1. A method for detecting network security vulnerabilities, characterized in that: include: Determine vulnerability information of network security vulnerabilities to be detected; The vulnerability information is processed by a large language model to obtain vulnerability attack instructions; Based on the vulnerability attack instruction, security vulnerability detection is performed on the server in the target organization to obtain the detection result.
2. The method according to claim 1, characterized in that: Determine vulnerability information of the network security vulnerabilities to be detected, including: Obtain the newly imported vulnerability information of the target database within the target time period; Determining whether the newly imported vulnerability information belongs to a target list, wherein the target list is used to record vulnerability information of network security vulnerabilities that have been repaired in the target organization; If the newly imported vulnerability information does not belong to the target list, the newly imported vulnerability information is determined as vulnerability information of the network security vulnerability to be detected.
3. The method according to claim 1, characterized in that The vulnerability information is processed through a large language model to obtain vulnerability attack instructions, including: Acquire a target prompt word, wherein the target prompt word is used to guide the large language model to generate the vulnerability attack instruction according to the vulnerability information; The target prompt word and the vulnerability information are input into the large language model to obtain the vulnerability attack instruction.
4. The method according to claim 1, characterized in that Based on the vulnerability attack instruction, security vulnerability detection is performed on the server in the target organization to obtain detection results, including: The vulnerability attack instruction is executed in the target tool library to perform security vulnerability detection on the server in the target organization to obtain the detection result, wherein the vulnerability attack instruction is used to call the security vulnerability attack tool in the target tool library to attack the target server in the target organization.
5. The method according to claim 2, characterized in that: After performing security vulnerability detection on the server in the target organization based on the vulnerability attack instruction and obtaining the detection result, the method further includes: Generate first information according to the detection result, wherein the first information is used to instruct the target user to repair the network security vulnerability recorded in the detection result; The first information is sent to a target user.
6. The method according to claim 5, characterized in that After sending the first information to the target user, the method further includes: detecting whether second information is received, wherein the second information includes vulnerability information of the repaired network security vulnerability; When the second information is received, vulnerability information of the network security vulnerability in the second information is stored in the target list.
7. The method according to claim 1, characterized in that The large language model is trained in the following way: Acquire a training sample set, wherein the training samples of the training sample set include sample vulnerability information and server configuration information of the target organization, and the real labels of the training samples include sample vulnerability attack instructions; The initial large language model is trained by using the training sample set to obtain the large language model.
8. A network security vulnerability detection device, characterized in that: include: A determination module, used to determine vulnerability information of a network security vulnerability to be detected; A first processing module, used to process the vulnerability information through a large language model to obtain a vulnerability attack instruction; The second processing module is used to perform security vulnerability detection on the server in the target organization based on the vulnerability attack instruction to obtain the detection result.
9. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, wherein the computer program is configured to execute the method for detecting network security vulnerabilities described in any one of claims 1 to 7 when running.
10. An electronic device, characterized in that: The electronic device includes one or more processors; A memory for storing one or more programs, which, when the one or more programs are executed by the one or more processors, enables the one or more processors to run the programs, wherein the program is configured to execute the method for detecting network security vulnerabilities described in any one of claims 1 to 7 when running.
11. A computer program product comprising a computer program / instructions, characterized in that When the computer program / instructions are executed by a processor, the method for detecting network security vulnerabilities according to any one of claims 1 to 7 is implemented.