Asset vulnerability repair priority evaluation method based on attack graph

Through the asset vulnerability repair priority evaluation method based on the attack graph, considering the accessibility of network access relationships, the problem of time spent on vulnerability scanning and inaccurate repair priority evaluation in large-scale digital assets is solved, and more accurate vulnerability repair priority evaluation is achieved.

CN119996056APending Publication Date: 2025-05-13QIMING INFORMATION TECH +1

Patent Information

Application Number
CN202510312907.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-17
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

In the case where the enterprise's digital assets are huge and the update speed is fast, it takes a long time to scan vulnerabilities and it is difficult to fix all vulnerabilities within one scan cycle. The existing technology fails to effectively consider the accessibility of network access relationships, resulting in inaccurate evaluation of vulnerability repair priorities.

Method used

The asset vulnerability repair priority evaluation method is adopted based on the attack graph, and by detecting assets, scanning vulnerabilities, obtaining network access relationships and access relationship graphs, the external reachable vertices are extracted and the asset importance is calculated, and the vulnerability priority is sorted according to the asset importance.

Benefits of technology

By considering the accessibility of network access relationships, it is possible to more comprehensively and accurately reflect various attack paths that may exist in the network, thereby more accurately evaluating the priority of repairing asset vulnerabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119996056A_ABST
    Figure CN119996056A_ABST
Patent Text Reader

Abstract

The invention discloses an asset vulnerability repair priority evaluation method based on an attack graph, and the method comprises the following steps: S1, carrying out the detection of all assets, and carrying out the vulnerability scanning of the detected assets; s2, obtaining a network access relation of the detected assets; s3, constructing an asset access relation graph based on the network access relation; s4, extracting external reachable vertexes based on the asset access relation graph; s5, carrying out asset importance calculation on the extracted vertexes; and S6, performing vulnerability priority ranking according to asset importance. According to the method, the accessibility of the network access relation is considered when the vulnerabilities are subjected to priority ranking, various attack paths possibly existing in the network can be fully reflected, and therefore the asset vulnerability repair priority can be more comprehensively and accurately reflected.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to an asset vulnerability repair priority assessment method based on an attack graph. Background Art

[0002] Enterprises or organizations have digital assets, which may have vulnerabilities. When the vulnerabilities of assets are exploited by attackers, it will not only harm the digital assets of the enterprise, but also affect the production and operation of the enterprise. Therefore, enterprises need to repair the vulnerabilities before they are exploited by attackers to avoid losses caused by the exploitation of vulnerabilities.

[0003] When the scale of enterprise digital assets is large and the update speed is fast, it takes a long time to conduct a vulnerability scan, and it is difficult to fix all vulnerabilities in one scanning cycle. Therefore, it is necessary to sort the priorities of the vulnerabilities so as to fix the high-priority vulnerabilities.

[0004] The patent with application number 202410166425.3 first obtains the vulnerability data of the vulnerabilities existing in the assets, and then evaluates the asset danger level of the assets and the risk level of the vulnerabilities. During the evaluation process, based on the vulnerable ports and the asset exposed ports, an evaluation value of whether the asset is exploited by the vulnerability is obtained. In actual situations, although assets expose a large number of ports, most ports are irrelevant to the vulnerabilities to be evaluated. In addition, the patent uses the asset exposed port information without considering the reachability constraints between network access. Even if an asset exposes a port that can be exploited, it still has a lower priority if it cannot be accessed. Summary of the invention

[0005] In order to solve the above problems, the present invention provides an asset vulnerability repair priority assessment method based on an attack graph, comprising the following steps: S1. Detecting all assets and performing vulnerability scanning on the detected assets; S2. Acquiring network access relationships for the detected assets; S3. Constructing an asset access relationship graph based on the network access relationship; S4. Extracting externally reachable vertices based on the asset access relationship graph; S5. Calculating the asset importance of the extracted vertices; S6. Sort vulnerability priorities according to asset importance.

[0006] Furthermore, the network access relationship is obtained in step S2 by using firewalls, switches, and routers.

[0007] Furthermore, the step S4 specifically includes the following sub-steps: S41. Select a vertex with an external IP as the initial node, and search for all reachable vertices along the edges; S42. Delete unreachable vertices and their corresponding edges in the asset access relationship graph.

[0008] Furthermore, when deleting in step S42, if the deleted vertex contains a vulnerability, it indicates that the vulnerability cannot be exploited by the external network, the priority of repairing the vulnerability is low, and the importance value of the vulnerability is 0.

[0009] Furthermore, the calculation formula for calculating the importance in step S5 is: ; In the formula, PageRank(p i ) represents node p i The importance value of; q represents the damping coefficient; k represents the number of vertices with external IP; the elements in the vertex vector W are specifically 1 or 0: the vertex value with external IP is 1, and the rest are 0, and there are k 1s in W; p j Indicates p i The predecessor vertex of L(p j ) represents the vertex p j The out-degree of .

[0010] Furthermore, the priority sorting rule in step S6 is specifically: the greater the importance of the asset, the higher the priority of the vulnerability.

[0011] The present invention provides an asset vulnerability repair priority assessment method based on an attack graph, which has the following beneficial effects: The present invention constructs an asset access relationship graph with assets, vulnerabilities, and access relationships, finds assets and vulnerabilities that can be attacked externally by extracting externally reachable attack subgraphs, and prioritizes assets and vulnerabilities using the node importance algorithm in the graph. The present invention considers the accessibility of network access relationships when prioritizing vulnerabilities, and can fully reflect various attack paths that may exist in the network, thus more comprehensively and accurately reflecting the priority of asset vulnerability repair. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the structures shown in these drawings without paying creative work.

[0013] Figure 1 A flow chart of the method provided by the present invention; Figure 2 The present invention provides a flow chart of an embodiment. DETAILED DESCRIPTION

[0014] It should be understood that the specific embodiments described herein are only used to explain the present invention, and are not used to limit the present invention.

[0015] The following is a detailed description of the implementation method of the present invention in conjunction with the accompanying drawings. Only some embodiments are described, not all embodiments. For the purpose of clarity, representations and descriptions that are not related to the present invention are omitted in the drawings and descriptions.

[0016] In order to have a clearer understanding of the technical features, purposes and beneficial effects of the present invention, the technical solution of the present invention is now described in detail below. Obviously, the implementation cases described are part of the embodiments of the present invention, not all of the embodiments, and cannot be understood as limiting the scope of the implementation of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work belong to the protection scope of the present invention.

[0017] When external attackers attack corporate assets, they will conduct a series of attack behaviors such as asset detection, vulnerability scanning, vulnerability exploitation, lateral penetration, data backhaul, etc. The accessibility of assets limits the attacker's attack range, and therefore also affects the priority of vulnerability repair.

[0018] like Figure 1 As shown, the present invention provides an asset vulnerability repair priority assessment method based on an attack graph, comprising the following steps: S1. Detect all assets and scan for vulnerabilities. Detect all digital assets in the enterprise and scan for vulnerabilities. Each asset is a vertex in the graph, and vulnerability information is the attribute of the vertex.

[0019] S2. Obtain the network access relationship of the detected assets. Obtain the network access relationship of the assets within the enterprise from firewalls, switches, routers and other devices.

[0020] S3. Build an asset access relationship graph based on network access relationships.

[0021] S4. Extract externally reachable vertices based on the asset access relationship graph: S41. Select the vertex with an external IP as the initial node, and search for all reachable vertices along the edges; S42. Delete the unreachable vertices and their corresponding edges in the asset access relationship graph: When deleting, if the deleted vertex contains a vulnerability, it means that the vulnerability cannot be exploited by the external network, the priority of vulnerability repair is low, and the vulnerability importance value is 0.

[0022] S5. Calculate the asset importance of the extracted vertices. The calculation formula is: ; In the formula, PageRank(p i ) represents node p iThe importance value of; q represents the damping coefficient; k represents the number of vertices with external IP; the elements in the vertex vector W are specifically 1 or 0: the vertex value with external IP is 1, and the rest are 0, and there are k 1s in W; p j Indicates p i The predecessor vertex of L(p j ) represents the vertex p j After the above calculation, the importance value of the vertex is used to represent the importance of the asset.

[0023] S6. Prioritize vulnerabilities according to asset importance: For assets with vulnerabilities, prioritize them according to the asset importance in steps 4 and 5. The more important the asset is, the higher the priority of its vulnerabilities. For vulnerabilities on the same asset, prioritize them according to the Base Score value of the CVSS (Common Vulnerability Scoring System) corresponding to the vulnerability.

[0024] Example: Figure 2 As shown in the figure, solid ellipses represent assets, dotted ellipses represent asset attributes, solid lines with arrows represent directed edges, and dotted lines without arrows represent node attributes. The left side is the DMZ area, where D1, D2, ..., Dm are assets that can be directly accessed by the external network and have external and internal network IP addresses; the right side is the internal network area, where A1, A2, ..., An are internal network assets and have internal network IP addresses; V1 and V2 represent vulnerabilities.

[0025] Through steps S1, S2 and S3, we get Figure 2 Results shown.

[0026] S4, taking D1, D2 and Dm as initial points, obtains the attack subgraph through directed edges passing through A1, A2, A4 and A5; the importance of those vertices that have vulnerabilities and are not in the attack subgraph is 0, such as A3.

[0027] S5, calculate the importance value of each fixed point in the attack subgraph according to the given PageRank formula.

[0028] S6, merge the asset importance of S4 and S5. Let the sorting result be D2>A2>A1>A3=0. Substitute the vulnerability into D2(V1)>A2(V1,V2)>A1(V1,V3)>A3(V1). Based on the Base Score value of CVSS, assuming V2>V1>V3, the priority ranking of the vulnerability is (D2,V1)>(A2,V2)>(A2,V1)>(A1,V1)>(A1,V3)>(A3,V1). The above S6 can adopt other vulnerability priority methods.

[0029] The present invention constructs an asset access relationship graph with assets, vulnerabilities, and access relationships, finds assets and vulnerabilities that can be attacked externally by extracting externally reachable attack subgraphs, and prioritizes assets and vulnerabilities using the node importance algorithm in the graph. The present invention considers the accessibility of network access relationships when prioritizing vulnerabilities, and can fully reflect various attack paths that may exist in the network, thus more comprehensively and accurately reflecting the priority of asset vulnerability repair.

[0030] The above is only a preferred embodiment of the present invention. It should be understood that the present invention is not limited to the form disclosed herein, and should not be regarded as excluding other embodiments, but can be used in various other combinations, modifications and environments, and can be modified within the scope of the concept described herein through the above teachings or the technology or knowledge of the relevant field. The changes and modifications made by those skilled in the art shall not deviate from the spirit and scope of the present invention, and shall be within the scope of protection of the claims attached to the present invention.

Claims

1. A method for assessing asset vulnerability repair priority based on attack graph, characterized in that: The following steps are involved: S1. Detect all assets and scan for vulnerabilities on the detected assets; S2. Obtain network access relationships for detected assets; S3. Construct an asset access relationship graph based on network access relationships; S4. extracting externally reachable vertices based on the asset access relationship graph; S5. Calculate the asset importance of the extracted vertices; S6. Prioritize vulnerabilities according to asset importance.

2. The asset vulnerability repair priority assessment method based on attack graph according to claim 1 is characterized in that: The methods for acquiring the network access relationship in step S2 include: firewall, switch, and router.

3. The asset vulnerability repair priority assessment method based on attack graph according to claim 1 is characterized in that: The S4 step specifically includes the following sub-steps: S41. Select the vertex with external IP as the initial node, and search for all reachable vertices along the edge; S42. Delete unreachable vertices and their corresponding edges in the asset access relationship graph.

4. The asset vulnerability repair priority assessment method based on attack graph according to claim 3 is characterized in that: When deleting in step S42, if the deleted vertex contains a vulnerability, it means that the vulnerability cannot be exploited by the external network, the priority of repairing the vulnerability is low, and the importance value of the vulnerability is 0.

5. The asset vulnerability repair priority assessment method based on attack graph according to claim 1 is characterized in that: The calculation formula for importance calculation in step S5 is: ; In the formula, PageRank(p i ) represents node p i The importance value of; q represents the damping coefficient; k represents the number of vertices with external IP; the elements in the vertex vector W are specifically 1 or 0: the vertex value with external IP is 1, and the rest are 0, and there are k 1s in W; p j Indicates p i The predecessor vertex of L(p j ) represents the vertex p j The out-degree of .

6. The asset vulnerability repair priority assessment method based on attack graph according to claim 1 is characterized in that: The specific rule for prioritization in step S6 is: the greater the importance of the asset, the higher the priority of the vulnerability.

Citation Information

Patent Citations

  • Vulnerability assessment method and device

    CN118133288A

Cited By

  • Vulnerability closed-loop processing method and system based on intelligent collaboration

    CN120579194A

  • Network attack surface identification optimization method based on network topology and security simulation calculation

    CN121441563A