Full-life-cycle vulnerability security management method and system
Through the full life cycle vulnerability security management method, the Transformer model is used to formulate vulnerability prediction and repair strategies, which solves the problems of low accuracy of vulnerability analysis and low repair efficiency, and realizes accurate prediction and comprehensive repair management of potential security vulnerabilities, reducing security risks and improving the security protection capabilities of the system.
Patent Information
- Application Number
- CN202411953062.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-27
- Publication Date
- 2025-05-16
AI Technical Summary
The accuracy of vulnerability analysis and the efficiency of vulnerability repair are mainly due to the complex methods of cyber attacks, diversified vulnerability types, increased prediction difficulty, and increased communication costs and complex repair processes caused by information asymmetry and unclear responsibilities among different departments.
The full life cycle vulnerability security management method is adopted to identify potential security vulnerabilities through active scanning and passive monitoring, and the Transformer model is used to extract features in combination with the self-attention mechanism, to predict time series, affected asset types and vulnerability types, generate vulnerability prediction reports, and formulate repair strategies based on the report, and combine automation tools and manual confirmation for repair verification.
It realizes accurate prediction and comprehensive repair management of potential security vulnerabilities, reduces security risks, improves the system's security protection capabilities, and ensures the stable operation of the system and the sustainable development of business.
Smart Images

Figure CN120012100A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of vulnerability management, and in particular to a full life cycle vulnerability security management method and system. Background Art
[0002] Vulnerability security management refers to a collection of strategies, processes and technical measures taken by enterprises or organizations to identify, evaluate, handle and prevent security vulnerabilities in information systems. Its purpose is to protect the confidentiality, integrity and availability of information systems and prevent security incidents such as data leakage, system failures and business interruptions caused by the exploitation of vulnerabilities.
[0003] At present, there are some technical problems in vulnerability security management. On the one hand, due to the increasing complexity of network attack methods, the types and generation methods of vulnerabilities are becoming more and more diverse, and new vulnerabilities are constantly emerging. These vulnerabilities have no historical data for reference, and it is difficult to accurately estimate them through existing prediction models. In addition, the way vulnerabilities are exploited is also constantly changing. Attackers may use new technical combinations to exploit known vulnerabilities, making it more difficult to predict whether vulnerabilities will be exploited and how they will be exploited. On the other hand, vulnerability repair involves the collaboration of multiple departments, including security teams, operation and maintenance teams, development teams, etc. There may be information asymmetry and unclear responsibilities between different departments, resulting in increased communication costs, obstructed repair processes, and some companies' vulnerability repair processes are too complicated, involving multiple approval links and document record requirements. As a result, the accuracy of vulnerability analysis is low and the efficiency of vulnerability repair is low. Summary of the invention
[0004] The embodiments of the present application provide a full life cycle vulnerability security management method and system for solving the problems of low vulnerability analysis accuracy and low vulnerability repair efficiency.
[0005] The first aspect of the embodiment of the present application provides a full life cycle vulnerability security management method, including:
[0006] Identify potential security vulnerabilities in the system based on active scanning and passive monitoring;
[0007] The data related to the identified potential security vulnerabilities are pre-processed and then input into the trained Transformer model. After extracting features using the self-attention mechanism, predictions are made based on time series, affected asset types, and vulnerability types to obtain a vulnerability prediction report.
[0008] Formulate a vulnerability repair strategy based on the vulnerability prediction report and then perform repairs according to the formulated strategy;
[0009] Use automated tools combined with manual confirmation to verify fixed vulnerabilities and generate a comprehensive vulnerability prevention management strategy.
[0010] Furthermore, the data related to the identified potential security vulnerabilities are pre-processed and then input into the trained Transformer model. After extracting features using the self-attention mechanism, predictions are made from the time series, the type of affected assets, and the type of vulnerability to obtain a vulnerability prediction report, including:
[0011] Perform one-hot encoding and vectorization on the time series, the type of affected assets, and the vulnerability type, and concatenate them in sequence to generate a comprehensive input vector;
[0012] Input the comprehensive input vector into the trained Transformer model, and use the self-attention mechanism and multi-layer stacking structure in the Encoder part of the model to extract features of the comprehensive input vector, determine the correlation between the time series, the type of affected assets, and the type of vulnerability, and generate a hidden representation vector containing rich semantics and context information;
[0013] In the output layer of the Transformer model, output nodes are set for time series, affected asset types, and vulnerability types respectively. The predicted probability distribution of time series, affected asset types, and vulnerability types is calculated through linear transformation and softmax function. The prediction results are integrated and a vulnerability prediction report is generated.
[0014] Furthermore, the time series, the affected asset type, and the vulnerability type are individually one-hot encoded and vectorized, and sequentially concatenated to generate a comprehensive input vector, including:
[0015] Generate the corresponding cross feature vectors by multiplying the one-hot encoded vectors of time series and asset type, time series and vulnerability type, and asset type and vulnerability type respectively;
[0016] Linearly transform the time series, asset type, and vulnerability type vectors into query, key, and value vectors respectively, and calculate the attention weight matrix between different dimensions;
[0017] According to the attention weight matrix, weighted summation of corresponding value vectors is performed to obtain a fusion feature vector between different dimensions;
[0018] The fused feature vectors are concatenated to generate a vector of fused feature interaction information as a comprehensive input vector.
[0019] Furthermore, the time series, the affected asset type, and the vulnerability type are individually one-hot encoded and vectorized, and sequentially concatenated to generate a comprehensive input vector, including:
[0020] Generate the corresponding cross feature vectors by multiplying the one-hot encoded vectors of time series and asset type, time series and vulnerability type, and asset type and vulnerability type respectively;
[0021] Linearly transform the time series, asset type, and vulnerability type vectors into query, key, and value vectors respectively, and calculate the attention weight matrix between different dimensions;
[0022] According to the attention weight matrix, weighted summation of corresponding value vectors is performed to obtain a fusion feature vector between different dimensions;
[0023] The fused feature vectors are concatenated to generate a vector of fused feature interaction information as a comprehensive input vector.
[0024] Furthermore, the Transformer model architecture is constructed, and the model includes an input layer for receiving input vectors, an Encoder part for extracting features using a self-attention mechanism and a feedforward neural network, and an output layer for setting output nodes for three dimensions to obtain prediction results, including:
[0025] Time series dimension output:
[0026] y t =W t H+b t
[0027]
[0028] Where: y t is the output vector of the time series dimension, W t is the weight matrix corresponding to time series prediction, H is the hidden representation vector, b t is the bias vector of the time series dimension, T is the total time period, To predict the probability of a vulnerability occurring in the i-th time interval, y t (i) is y t The i-th element in the vector;
[0029] Affected asset type dimension output:
[0030] y a =W a H+b a
[0031]
[0032] Where: y a is the output vector of the affected asset type dimension, W a is the weight matrix corresponding to the prediction of the affected asset type, b ais the bias vector of the affected asset type dimension, N is the number of asset types, To predict the probability of a vulnerability affecting the jth asset type, y a (j) is y a The jth element in the vector;
[0033] Vulnerability type dimension output:
[0034] y v =W v H+b v
[0035]
[0036] Where: y v is the output vector of vulnerability type dimension, W v is the weight matrix corresponding to the vulnerability type prediction, b v is the bias vector of vulnerability type dimension, M is the number of vulnerability types, To predict the probability that a vulnerability belongs to the kth type, y v (k) is y v The kth element in the vector.
[0037] Furthermore, the loss function of setting the three-dimensional cross entropy loss, selecting the optimizer, and optimizing the model through forward propagation, loss calculation, gradient solution and parameter update in the training cycle include:
[0038]
[0039] L=L t +L a +L v
[0040] Where: L t , L a and L v are the cross entropy losses of the three dimensions of time series, affected asset type, and vulnerability type, and L is the comprehensive loss function.
[0041] Furthermore, the data related to the identified potential security vulnerabilities are pre-processed and then input into the trained Transformer model. After extracting features using the self-attention mechanism, predictions are made from the time series, the type of affected assets, and the type of vulnerability to obtain a vulnerability prediction report, including:
[0042] Perform secondary vulnerability identification based on the prediction results of time series, affected asset types, and vulnerability types. The secondary vulnerability identification is to formulate a rule set based on the characteristics of different dimensions, and match vulnerability detail data information based on the formulated rule base;
[0043] A vulnerability prediction report is generated by combining the prediction results and the corresponding matching vulnerability detail data information.
[0044] Furthermore, formulating a vulnerability repair strategy based on the vulnerability prediction report and then repairing the vulnerability according to the formulated strategy includes:
[0045] Analyze vulnerability prediction reports, sort out key information such as time, asset type, vulnerability type, and determine repair priorities based on time urgency, asset importance, and vulnerability severity;
[0046] Develop repair strategies based on different vulnerability types and the characteristics of affected assets;
[0047] Vulnerability repair is performed based on the established repair strategy, and the repair effect is verified through functional testing, security testing and continuous monitoring after repair.
[0048] Furthermore, the repair strategy is formulated according to different vulnerability types and the characteristics of the affected assets, including:
[0049] Locate and review the affected code, and modify the code using secure programming practices;
[0050] Check system and service configurations, adjust parameters and enable security features against security baselines;
[0051] Evaluate and upgrade protocol versions, optimize protocol parameters and authentication authorization, build monitoring mechanisms and formulate emergency response plans;
[0052] Update device firmware, optimize access control policies, configure and strengthen security functions and log management;
[0053] Strengthen the operating system, update and repair applications and services, and optimize data backup and recovery strategies;
[0054] Security optimization and vulnerability repair are performed on the front-end and back-end codes respectively, while the architecture is optimized and the security mechanism is enhanced.
[0055] A second aspect of the embodiment of the present application provides a full life cycle vulnerability security management system, including:
[0056] A potential security vulnerability identification unit is used to identify potential security vulnerabilities in the system based on active scanning and passive monitoring;
[0057] The vulnerability prediction report determination unit is used to pre-process the relevant data of the identified potential security vulnerabilities and input them into the trained Transformer model. After extracting features using the self-attention mechanism, predictions are made based on the time series, the type of affected assets, and the type of vulnerabilities to obtain a vulnerability prediction report.
[0058] A vulnerability repair unit, configured to formulate a vulnerability repair strategy based on the vulnerability prediction report and then perform repairs according to the formulated strategy;
[0059] The vulnerability prevention management strategy generation unit is used to verify the repaired vulnerabilities by combining automated tools with manual confirmation to generate a comprehensive vulnerability prevention management strategy.
[0060] It can be seen from the above technical solutions that the embodiments of the present application have the following advantages:
[0061] The present invention identifies potential security vulnerabilities in the system based on active scanning and passive monitoring, which can comprehensively cover all levels and corners of the system, discover potential security vulnerabilities to the greatest extent and avoid omissions; the relevant data of the identified potential security vulnerabilities are pre-processed and input into the trained Transformer model, and the self-attention mechanism is used to extract features and then predict from time series, affected asset types and vulnerability types to obtain a vulnerability prediction report, and deeply explore the complex correlation between multi-dimensional features such as time series, affected asset types and vulnerability types in the data, so as to accurately predict the occurrence of vulnerabilities in the future; after formulating a vulnerability repair strategy based on the vulnerability prediction report, the vulnerability is repaired according to the formulated strategy, and the repaired vulnerability is verified by combining automated tools with manual confirmation to generate a comprehensive vulnerability prevention management strategy, which covers the whole life cycle management from vulnerability discovery, prediction, repair to subsequent prevention, forming a closed-loop security management system, continuously strengthening the security protection capability of the system, effectively preventing possible security vulnerabilities in the future, reducing security risks, and providing strong guarantees for the stable operation of the system and the sustainable development of the business.
[0062] Other advantages, objectives, and features of the present invention will be set forth in part in the following description, and in part will be apparent to those skilled in the art based on an examination of the following or may be taught from the practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0063] Figure 1 The figure is a flow chart of an embodiment of a full life cycle vulnerability security management method in the present invention. DETAILED DESCRIPTION
[0064] The terms "first", "second", "third", "fourth", etc. (if any) in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein, for example. In addition, the terms "including" and "corresponding to" and any of their variations are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units that are clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0065] Embodiment 1
[0066] The implementation method in this embodiment can be implemented in the system, can be implemented in the server, and can also be implemented in the terminal, without specific limitation. The following introduces the full life cycle vulnerability security management method in this application from the perspective of system implementation. Figure 1 , the method provided in the embodiment of the present application comprises the following steps:
[0067] S11. Identify potential security vulnerabilities in the system based on active scanning and passive monitoring;
[0068] Active scanning specifically includes: clarifying the target system to be scanned, including network devices, servers, applications, and related network topology structures; selecting appropriate active scanning tools based on the scanning scope and characteristics of the target system; and determining the frequency of active scanning based on the system's business busyness, change frequency, and security policy requirements. Use network scanning tools to discover hosts on the target network and identify surviving hosts in the network. Then perform a port scan to detect open ports on each surviving host and obtain service information. After determining the open ports and services, further detect the version information of the operating system and services on the target host. For Web applications, use professional Web scanning tools for comprehensive scanning. For non-Web applications, such as desktop applications, mobile applications, etc., select an appropriate scanning method based on the application type and platform. Manually verify potential vulnerabilities reported by scanning tools, as scanning tools may generate false positives.
[0069] Passive monitoring specifically includes: deploying network traffic monitoring tools at key network nodes, configuring logging functions on servers, network devices, and applications, and ensuring that sufficiently detailed system activity information is recorded, including user logins, file accesses, service startup and shutdown, etc. For applications, deploy application performance monitoring tools, which can not only monitor application performance indicators, but also track the call relationships and execution processes within the application. Use network traffic monitoring tools to analyze network traffic data in real time, and on the log management platform, perform real-time analysis on the collected system logs. By associating logs from different devices and applications, abnormal behaviors across systems can be discovered. Application performance monitoring tools continuously track application performance indicators. Subscribe to professional security threat intelligence services to obtain the latest security threat information, including global network attack trends, emerging vulnerability exploits, malware activities, etc. Finally, integrate potential security vulnerability information discovered through multiple channels such as network traffic monitoring, system log analysis, and application performance monitoring.
[0070] S12. Preprocess the relevant data of the identified potential security vulnerabilities and input them into the trained Transformer model. Use the self-attention mechanism to extract features and make predictions based on time series, affected asset types, and vulnerability types to obtain a vulnerability prediction report.
[0071] In this embodiment, step S12 includes:
[0072] 1. Perform one-hot encoding and vectorization on the time series, the type of affected assets, and the vulnerability type, and concatenate them in order to generate a comprehensive input vector;
[0073] This step also includes the following:
[0074] (1) Generate corresponding cross feature vectors by multiplying the one-hot encoded vectors of time series and asset type, time series and vulnerability type, and asset type and vulnerability type respectively;
[0075] Assume that the one-hot encoded vector x of the time series t ∈{0, 1} T , of length T, representing the one-hot encoded vector x of T time intervals and the affected asset types a ∈{0, 1} T , with a length of N, representing N asset types. In order to generate the cross feature vector x of time and asset type ta , for x t Each element in x a Each element in performs a pairwise multiplication operation. Similarly, for the time series vector x t and vulnerability type one-hot encoded vector x v ∈{0, 1}M , with a length of M, indicating M types of vulnerabilities. t Each element in x v Each element in is multiplied by two to generate the cross feature vector x of time and vulnerability type. tv For an asset type vector x a and vulnerability type vector x v , for x a Each element in x v Each element in is multiplied pairwise to generate the cross feature vector x of asset type and vulnerability type. av .
[0076] The original time series vector x t , asset type vector x a , vulnerability type vector x v And the generated cross eigenvector x ta 、x tv 、x av Connect them in a certain order to form a new comprehensive input vector x new One possible concatenation order is to place the original three vectors first, and then place the three cross eigenvectors in sequence, that is, x new =[x t , x a , x v , x ta , x tv , x av ]. The dimension of the concatenated vector will increase, containing more feature interaction information, which can provide richer input data for the subsequent Transformer model, enabling it to better learn the complex relationship between time, asset type, and vulnerability type, and improve the accuracy of vulnerability prediction.
[0077] (2) Linearly transform the time series, asset type, and vulnerability type vectors into query, key, and value vectors, respectively, and calculate the attention weight matrix between different dimensions;
[0078] The time series vector x t , asset type vector x a and vulnerability type vector x v As input, it is passed to the attention-based interaction module. Assume x t ∈R T , x a ∈R N , x v ∈R M , where T, N, and M are the dimensions of the three vectors, corresponding to the number of time intervals, the number of asset types, and the number of vulnerability types.
[0079] The specific calculation of the attention mechanism is as follows: First, the input vector is converted into a query vector Q, a key vector K, and a value vector V through linear transformation. In order to distinguish Q, K, and V generated by different input vectors, Q t , K t 、V t Indicated by x t Generated, Q a , K a 、V a Indicated by x a Generated, Q v , K v 、V v Indicated by x v The generated calculation formula is as follows:
[0080]
[0081] in: is a learnable weight matrix.
[0082] Then, the attention weights are calculated, and the attention weight matrices between time series and asset types, time series and vulnerability types, and asset types and vulnerability types are calculated respectively. Taking the attention weight calculation between time series and asset types as an example, the formula is:
[0083]
[0084] Here Is to calculate the query vector Q t With the key vector K a The dot product of , we get a matrix representing the degree of correlation between the time series and the asset type elements, divided by In order to scale and prevent problems such as gradient disappearance or explosion, the softmax function converts these correlation values into probability distributions, namely attention weights, which indicate the degree of attention each time series element pays to the asset type element, and vice versa. Similarly, A can be calculated tv and A av .
[0085] In the above formula, for example, A ta (i, j) represents the attention weight value of the i-th time series element to the j-th asset type element in the attention weight matrix of time series and asset type. The larger this value is, the greater the influence of the i-th time-related feature on the j-th asset type feature is in the current model learning process, and the model will pay more attention to this time-asset type correlation relationship.
[0086] (3) According to the attention weight matrix, the corresponding value vectors are weighted and summed to obtain the feature vector after mutual fusion between different dimensions;
[0087] (4) The fused feature vectors are concatenated to generate a vector of fused feature interaction information as a comprehensive input vector.
[0088] According to the calculated attention weight matrix, the corresponding value vectors are weighted and summed to obtain the fused feature vector. Taking the feature fusion of time series and asset type as an example, the calculation formula is:
[0089] Z ta =A ta V a
[0090]
[0091] Here Z ta Represents the vector after the time series is fused with the asset type features according to the attention weight of the asset type, Z at It represents the vector of asset type after integrating time series features according to the attention weight of time series. Similarly, Z can be calculated tv and Z vt and Z av and Z va .
[0092] Finally, these fused feature vectors are concatenated or further processed to obtain the final vector that integrates the feature interaction information, which is passed to the subsequent Transformer model as an improved comprehensive input vector.
[0093] The above steps can effectively integrate feature interaction and combination information into the comprehensive input vector, providing the Transformer model with richer and more informative input data, which helps to improve the model's ability and accuracy in predicting potential security vulnerabilities.
[0094] 2. Input the comprehensive input vector into the trained Transformer model. In the Encoder part of the model, the self-attention mechanism and multi-layer stacking structure are used to extract features of the comprehensive input vector, determine the correlation between time series, affected asset types, and vulnerability types, and generate a hidden representation vector containing rich semantic and contextual information;
[0095] 3. The output layer of the Transformer model sets output nodes for time series, affected asset types, and vulnerability types respectively, calculates the predicted probability distribution of time series, affected asset types, and vulnerability types through linear transformation and softmax function, integrates the prediction results and generates a vulnerability prediction report.
[0096] The training process of the Transformer model includes:
[0097] Collect historical vulnerability data from multiple channels and perform data preprocessing. Perform one-hot encoding and vector division on the three dimensions of preprocessed time series, affected asset type, and vulnerability type. Sequence them together to form a comprehensive input vector. At the same time, determine the label and divide the data into training set, validation set, and test set.
[0098] Build the Transformer model architecture, which includes an input layer that receives input vectors, an Enncoder part that uses self-attention mechanism and feedforward neural network for feature extraction, and an output layer that sets output nodes for three dimensions to obtain prediction results;
[0099] Time series dimension output:
[0100] y t =W t H+b t
[0101]
[0102] Where: y t is the output vector of the time series dimension, W t is the weight matrix corresponding to time series prediction, H is the hidden representation vector, b t is the bias vector of the time series dimension, T is the total time period, To predict the probability of a vulnerability occurring in the i-th time interval, y t (i) is y t The i-th element in the vector;
[0103] Affected asset type dimension output:
[0104] y a =W a H+b a
[0105]
[0106] Where: y a is the output vector of the affected asset type dimension, W a is the weight matrix corresponding to the prediction of the affected asset type, b a is the bias vector of the affected asset type dimension, N is the number of asset types, To predict the probability of a vulnerability affecting the jth asset type, y a (j) is y a The jth element in the vector;
[0107] Vulnerability type dimension output:
[0108] y v =W v H+b v
[0109]
[0110] Where: y v is the output vector of vulnerability type dimension, W v is the weight matrix corresponding to the vulnerability type prediction, b v is the bias vector of vulnerability type dimension, M is the number of vulnerability types, To predict the probability that a vulnerability belongs to the kth type, y v (k) is y v The kth element in the vector.
[0111] Set the loss function of the three-dimensional cross entropy loss, select the optimizer, and optimize the model through forward propagation, loss calculation, gradient solution, and parameter update in the training loop.
[0112]
[0113] L=L t +L a +L v
[0114] Where: L t , L a and L v are the cross entropy losses of the three dimensions of time series, affected asset type, and vulnerability type, and L is the comprehensive loss function.
[0115] Finally, the vulnerability prediction report also includes the following:
[0116] Perform secondary vulnerability identification based on the prediction results of time series, affected asset types, and vulnerability types. The secondary vulnerability identification is to formulate a rule set based on the characteristics of different dimensions, and match vulnerability detail data information based on the formulated rule base;
[0117] A vulnerability prediction report is generated by combining the prediction results and the corresponding matching vulnerability detail data information.
[0118] Specifically, collect and organize the vulnerability occurrence time data of the past years, as well as relevant information such as business activities, system changes, and external environment during the same period. Use time series analysis technology to find out the periodic laws, trend changes, and associations with specific events of vulnerability occurrence, and formulate a set of rules for time series based on analysis. During the determined high-risk time period, collect various types of data related to the system operation status, including server logs, network traffic data, and system performance indicators, and match the collected data with the formulated time rules. Classify various types of assets within the enterprise in detail, and analyze the vulnerability type, attack surface, and key security configuration parameters for each type of asset. According to the results of asset classification and feature analysis, formulate rule sets for different asset types. Collect detailed asset information for asset types that are predicted to be affected, and match the collected asset information with the corresponding asset rules.
[0119] In summary, the details of various vulnerabilities are classified and corresponding rule sets are formulated. The characteristics and detection points of various common and detailed vulnerability types are collected around the possible vulnerability types, including code, operating environment, security protection and other data, and in-depth analysis is carried out one by one to accurately determine the vulnerability details, such as the attack points and methods of specific vulnerabilities. The secondary vulnerability identification results of the three dimensions are integrated and sorted, and associations are established, duplicates are removed and sorted. The report structure is designed, covering the introduction, main body, conclusion and appendix. It is written in clear and accurate language, supplemented by charts to enhance intuitiveness, and detailed descriptions of various aspects of the vulnerability are provided to provide a comprehensive and practical basis for security prevention.
[0120] S13. Formulate a vulnerability repair strategy based on the vulnerability prediction report and then perform repairs according to the formulated strategy;
[0121] In this embodiment, step S13 further includes:
[0122] 1. Analyze the vulnerability prediction report, sort out key information such as time, asset type, vulnerability type, etc., and determine the repair priority based on time urgency, asset importance and vulnerability damage degree;
[0123] Prioritize vulnerabilities that may appear in the near future, such as in the next week or month, especially those that may appear during business peak periods or time periods related to key business processes. They should be listed as high priority to ensure that they are repaired in time before the problem occurs to avoid serious consequences such as business interruption or data leakage. Analyze the importance of the affected assets in the entire business system. For vulnerabilities in key assets that the core business system relies on, regardless of the type of vulnerability, they should be given a higher priority for repair. Determine the priority based on the potential harm of different vulnerability types. High-risk vulnerabilities that can directly lead to serious consequences such as remote code execution, sensitive data leakage, and system permission bypass should be handled first; while some relatively small-impact information display vulnerabilities can be arranged for repair later.
[0124] 2. Develop repair strategies based on different vulnerability types and the characteristics of affected assets;
[0125] Specifically, the steps include:
[0126] Locate and review the affected code, and modify the code using secure programming practices;
[0127] Check system and service configurations, adjust parameters and enable security features against security baselines;
[0128] Evaluate and upgrade protocol versions, optimize protocol parameters and authentication authorization, build monitoring mechanisms and formulate emergency response plans;
[0129] Update device firmware, optimize access control policies, configure and strengthen security functions and log management;
[0130] Strengthen the operating system, update and repair applications and services, and optimize data backup and recovery strategies;
[0131] Security optimization and vulnerability repair are performed on the front-end and back-end codes respectively, while the architecture is optimized and the security mechanism is enhanced.
[0132] 3. Perform vulnerability repair based on the established repair strategy, and verify the repair effect through functional testing, security testing and continuous monitoring after repair.
[0133] According to the established repair strategy, clarify the repair responsibilities of each team or person. After the repair is completed, conduct comprehensive functional testing on the affected systems, applications or network equipment, simulate normal business operations, check whether various business functions can operate normally, and ensure that the operation of repairing the vulnerability does not destroy the original business logic and functional integrity. Use professional security testing tools and technologies to conduct security testing on the repaired targets to check whether the vulnerability is actually repaired and whether new security risks are introduced. For a period of time after the repair, continue to monitor the system, and observe whether the system has abnormal behavior or performance degradation through system log analysis, performance indicator monitoring and other means, so as to promptly discover potential problems that may exist, and further optimize the repair measures or take other preventive measures based on the monitoring results to ensure the long-term stable operation of the system.
[0134] S14. Use automated tools combined with manual confirmation to verify the fixed vulnerabilities and generate a comprehensive vulnerability prevention management strategy.
[0135] Use a combination of automated tools and manual confirmation to verify the repaired vulnerabilities and generate a comprehensive vulnerability prevention management strategy; summarize lessons learned based on the verification results, improve security management systems and processes, including regular scanning and repair plans, security awareness training, emergency response processes, etc., and strengthen the construction of technical protection measures; establish a continuous monitoring mechanism to track the security status of the system, optimize the vulnerability prevention management strategy based on security dynamics and technological trends, ensure system stability and security, adapt to the ever-changing security threat environment, and effectively reduce vulnerability risks.
[0136] Embodiment 2
[0137] An embodiment of a full life cycle vulnerability security management system of the present invention includes the following steps:
[0138] A potential security vulnerability identification unit is used to identify potential security vulnerabilities in the system based on active scanning and passive monitoring;
[0139] The vulnerability prediction report determination unit is used to pre-process the relevant data of the identified potential security vulnerabilities and input them into the trained Transformer model. After extracting features using the self-attention mechanism, predictions are made based on the time series, the type of affected assets, and the type of vulnerabilities to obtain a vulnerability prediction report.
[0140] The vulnerability repair unit is used to formulate a vulnerability repair strategy based on the vulnerability prediction report and then perform repairs according to the formulated strategy;
[0141] The vulnerability prevention management strategy generation unit is used to verify the repaired vulnerabilities by combining automated tools with manual confirmation to generate a comprehensive vulnerability prevention management strategy.
[0142] Those of ordinary skill in the art will appreciate that the units of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the composition of each example has been generally described in terms of function in the above description. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of the present invention.
[0143] In the embodiments provided by the present invention, it should be understood that the division of units is only a logical function division, and there may be other division methods in actual implementation, such as multiple units can be combined into one unit, one unit can be split into multiple units, or some features can be ignored. In addition, each functional unit in each embodiment of the present invention can be integrated into a processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of software functional units.
[0144] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product, which is stored in a storage medium and includes several instructions for a computer device (which can be a personal computer, a server or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: U disk, read-only memory (ROM, Read-0nlyMemory), random access memory (RAM, RandomAccessMemory), mobile hard disk, magnetic disk or optical disk, etc., which can store program code.
[0145] It can be understood that the above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the above embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the above embodiments, or replace some or all of the technical features therein by equivalents. These modifications or replacements do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of the embodiments of the present invention, and they should all be included in the scope of the claims and specification of the present invention.
Claims
1. A full life cycle vulnerability security management method, characterized in that: include: Identify potential security vulnerabilities in the system based on active scanning and passive monitoring; The data related to the identified potential security vulnerabilities are pre-processed and then input into the trained Transformer model. After extracting features using the self-attention mechanism, predictions are made based on time series, affected asset types, and vulnerability types to obtain a vulnerability prediction report. Formulate a vulnerability repair strategy based on the vulnerability prediction report and then perform repairs according to the formulated strategy; Use automated tools combined with manual confirmation to verify fixed vulnerabilities and generate a comprehensive vulnerability prevention management strategy.
2. The full life cycle vulnerability security management method according to claim 1 is characterized in that: The data related to the identified potential security vulnerabilities are preprocessed and then input into the trained Transformer model. After extracting features using the self-attention mechanism, predictions are made from the time series, the type of affected assets, and the type of vulnerability to obtain a vulnerability prediction report, including: Perform one-hot encoding and vectorization on the time series, the type of affected assets, and the vulnerability type, and concatenate them in sequence to generate a comprehensive input vector; Input the comprehensive input vector into the trained Transformer model, and use the self-attention mechanism and multi-layer stacking structure in the Encoder part of the model to extract features of the comprehensive input vector, determine the correlation between the time series, the type of affected assets, and the type of vulnerability, and generate a hidden representation vector containing rich semantics and context information; In the output layer of the Transformer model, output nodes are set for time series, affected asset types, and vulnerability types respectively. The predicted probability distribution of time series, affected asset types, and vulnerability types is calculated through linear transformation and softmax function. The prediction results are integrated and a vulnerability prediction report is generated.
3. The full life cycle vulnerability security management method according to claim 2 is characterized in that: The time series, the affected asset type, and the vulnerability type are individually one-hot encoded and vectorized, and sequentially concatenated to generate a comprehensive input vector, including: Generate the corresponding cross feature vectors by multiplying the one-hot encoded vectors of time series and asset type, time series and vulnerability type, and asset type and vulnerability type respectively; Linearly transform the time series, asset type, and vulnerability type vectors into query, key, and value vectors respectively, and calculate the attention weight matrix between different dimensions; According to the attention weight matrix, weighted summation of corresponding value vectors is performed to obtain a fusion feature vector between different dimensions; The fused feature vectors are concatenated to generate a vector of fused feature interaction information as a comprehensive input vector.
4. The full life cycle vulnerability security management method according to claim 2 is characterized in that: The training process of the Transformer model includes: Collect historical vulnerability data from multiple channels and perform data preprocessing. Perform one-hot encoding and vector division on the three dimensions of preprocessed time series, affected asset type, and vulnerability type. Sequence them together to form a comprehensive input vector. At the same time, determine the label and divide the data into training set, validation set, and test set. Build the Transformer model architecture, which includes an input layer that receives input vectors, an encoder that uses self-attention and feedforward neural networks to extract features, and an output layer that sets output nodes for three dimensions to get prediction results. Set the loss function of the three-dimensional cross entropy loss, select the optimizer, and optimize the model through forward propagation, loss calculation, gradient solution, and parameter update in the training loop.
5. The full life cycle vulnerability security management method according to claim 4 is characterized in that: The Transformer model architecture is constructed, and the model includes an input layer for receiving input vectors, an Encoder part for feature extraction using a self-attention mechanism and a feedforward neural network, and an output layer for setting output nodes for three dimensions to obtain prediction results, including: Time series dimension output: y t =W t H+b t Where: y t is the output vector of the time series dimension, W t is the weight matrix corresponding to time series prediction, H is the hidden representation vector, b t is the bias vector of the time series dimension, T is the total time period, To predict the probability of a vulnerability occurring in the i-th time interval, y t (i) is y t The i-th element in the vector; Affected asset type dimension output: y a =W a H+b a Where: y a is the output vector of the affected asset type dimension, W a is the weight matrix corresponding to the prediction of the affected asset type, b a is the bias vector of the affected asset type dimension, N is the number of asset types, To predict the probability of a vulnerability affecting the jth asset type, y a (j) is y a The jth element in the vector; Vulnerability type dimension output: y v =W v H+b v Where: y v is the output vector of vulnerability type dimension, W v is the weight matrix corresponding to the vulnerability type prediction, b v is the bias vector of vulnerability type dimension, M is the number of vulnerability types, To predict the probability that a vulnerability belongs to the kth type, y v (k) is y v The kth element in the vector.
6. The full life cycle vulnerability security management method according to claim 5 is characterized in that: The loss function of setting the three-dimensional cross entropy loss, selecting the optimizer, and optimizing the model through forward propagation, loss calculation, gradient solution and parameter update in the training cycle include: L=L t +L a +L v Where: L t , L a and L v are the cross entropy losses of the three dimensions of time series, affected asset type, and vulnerability type, and L is the comprehensive loss function.
7. The full life cycle vulnerability security management method according to any one of claims 1 to 6, characterized in that: The data related to the identified potential security vulnerabilities are preprocessed and then input into the trained Transformer model. After extracting features using the self-attention mechanism, predictions are made from the time series, the type of affected assets, and the type of vulnerability to obtain a vulnerability prediction report, including: Perform secondary vulnerability identification based on the prediction results of time series, affected asset types, and vulnerability types. The secondary vulnerability identification is to formulate a rule set based on the characteristics of different dimensions, and match vulnerability detail data information based on the formulated rule base; A vulnerability prediction report is generated by combining the prediction results and the corresponding matching vulnerability detail data information.
8. The full life cycle vulnerability security management method according to claim 1 is characterized in that: The step of formulating a vulnerability repair strategy based on the vulnerability prediction report and then repairing the vulnerability according to the formulated strategy includes: Analyze vulnerability prediction reports, sort out key information such as time, asset type, vulnerability type, and determine repair priorities based on time urgency, asset importance, and vulnerability severity; Develop repair strategies based on different vulnerability types and the characteristics of affected assets; Vulnerability repair is performed based on the established repair strategy, and the repair effect is verified through functional testing, security testing and continuous monitoring after repair.
9. The full life cycle vulnerability security management method according to claim 7 is characterized in that: The repair strategy is formulated according to different vulnerability types and the characteristics of the affected assets, including: Locate and review the affected code, and modify the code using secure programming practices; Check system and service configurations, adjust parameters and enable security features against security baselines; Evaluate and upgrade protocol versions, optimize protocol parameters and authentication authorization, build monitoring mechanisms and formulate emergency response plans; Update device firmware, optimize access control policies, configure and strengthen security functions and log management; Strengthen the operating system, update and repair applications and services, and optimize data backup and recovery strategies; Security optimization and vulnerability repair are performed on the front-end and back-end codes respectively, while the architecture is optimized and the security mechanism is enhanced.
10. A full life cycle vulnerability security management system, characterized in that: include: A potential security vulnerability identification unit is used to identify potential security vulnerabilities in the system based on active scanning and passive monitoring; The vulnerability prediction report determination unit is used to pre-process the relevant data of the identified potential security vulnerabilities and input them into the trained Transformer model. After extracting features using the self-attention mechanism, predictions are made based on the time series, the type of affected assets, and the type of vulnerabilities to obtain a vulnerability prediction report. A vulnerability repair unit, configured to formulate a vulnerability repair strategy based on the vulnerability prediction report and then perform repairs according to the formulated strategy; The vulnerability prevention management strategy generation unit is used to verify the repaired vulnerabilities by combining automated tools with manual confirmation to generate a comprehensive vulnerability prevention management strategy.
Citation Information
Cited By
Vulnerability closed-loop processing method and system based on intelligent collaboration
CN120579194A
Method and system for predicting life stage of vulnerability, storage medium and electronic equipment
CN121145219A
Methods, systems, storage media, and electronic devices for predicting a vulnerability life stage
CN121145219B